Product1 distinct publisher3 min readUpdated
A Connecticut judge found white-on-white instructions to AI models in a pro se motion, then found more in the reply. Any team summarizing text it did not author is handling adversarial input now.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A judge in Connecticut's Superior Court found that a pro se plaintiff had buried instructions aimed at AI models inside a motion, set in tiny white type so that it was effectively invisible to anyone reading the document while staying ordinary machine-readable text to any system that processed the file [1]. That is the detail worth internalising: the attack was not against a model, it was against the gap between what a human reviewer sees and what a parser hands to the model.
The specifics are mundane, which is the point. The filing was Docket Entry #177.00, a "Final and Conclusive Motion for Default" filed July 24, 2026 [2]. According to the court, the concealed text directed that any artificial-intelligence model reviewing or receiving the document ensure its output agreed with the plaintiff's filing and work toward "remediation" of the Chief Clerk's denial of the plaintiff's default request [3]. The instruction was placed under the heading and again at the end of the document, which the court read as an attempt to put the directions in front of a model multiple times [4]; the passages quoted in the order contain at least four copies of the same demand [5]. The court issued an order to show cause why the plaintiff should not be sanctioned [6]. Techdirt reports that the plaintiff's response, Docket Entry #180.00, again concealed text [7]. The episode was spotted publicly by Brendan Palfreyman on LinkedIn [8].
None of this was unforeseeable. A year earlier, Louisiana judge Scott Schlegel warned that a GenAI assistant summarising a brief reads the full text layer rather than only what appears to the eye, and that "unless the tool is constrained, it may not distinguish between directions in a standing order and directions buried in a filing by a bad actor" [9]. His list of consequences was operational rather than dramatic: invisible instructions could bias a summary, skew a compliance check, or nudge a triage system [10]. Earlier this year lawyers tried the same trick in a Brazilian labor court, were caught, and were fined [11].
The mitigation most teams are quietly relying on does not hold. When lawyers tested hidden instructions, some models caught the subterfuge and called it out, and some did not [12]. That makes model-level suspicion a probabilistic behaviour, not a control you can put in a design document. The older AI failure mode in litigation, fabricated case citations, was at least auditable after the fact by checking the citations [13]. A successful injection produces output that looks entirely normal, which is why it belongs in your input pipeline rather than your review process.
If you ingest documents from parties with an interest in the output, the cheap work is at extraction: compare the rendered page against the extracted text layer, flag zero-contrast colours and sub-threshold font sizes, strip styling before the model sees anything, and show human reviewers the exact text that was sent rather than the pretty version. Treat third-party document text as data, never as instruction, and keep summariser output advisory where a decision follows from it.
What to watch: whether Connecticut actually sanctions on entry #180.00, since deterrence here is entirely about consequence; whether court systems adopting AI summarisation tools start screening filings for hidden text as intake policy rather than judicial vigilance [14]; and whether your own vendors will say, in writing, what they do with invisible text in an uploaded PDF.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A judge in Connecticut's Superior Court found that a pro se plaintiff inserted an attempted prompt injection using white-on-white text: hidden text set in tiny-point type and colored white, effectively invisible to a person reading the document while remaining ordinary, machine-readable text to any system that processes the file.
The filing at issue was Docket Entry #177.00, the plaintiff's "Final and Conclusive Motion for Default," filed July 24, 2026.
In substance the hidden text directs that any artificial-intelligence model reviewing or receiving the document ensure that its output agrees with the plaintiff's filing and work toward the "remediation" of the Chief Clerk's denial of the plaintiff's request for a default against the defendant.
The court noted the hidden text was repeated under the heading and at the end of the document in order to place the instructions in a model multiple times.
The court identified the hidden text, called it out, and issued an order to show cause why the plaintiff should not be sanctioned.
In Docket Entry #180.00, the plaintiff's reply to the order to show cause, the plaintiff again concealed text.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary court order quoted, single outlet
The core facts are anchored in verbatim quotation of a court order, including docket numbers, the filing date, and the hidden text itself, which is stronger than typical single-source reporting. It remains one publisher with no linked primary document in the supplied set, and the supporting generalizations (model detection variance, court adoption of summarizers) are asserted without citation.
Two documented incidents, no measured tool exposure
Real-world occurrence is confirmed but sparse: one Connecticut case with repeat attempts across at least four docket entries, plus one earlier Brazilian labor court case that ended in fines. Nothing in the source quantifies how many courts run AI summarizers or whether any tool actually ingested these documents, so adoption of the attack pattern reads as emergent rather than widespread.
Mechanism proven, impact unproven
The documented facts are solid, but the framing that summarizers are now handling adversarial input outruns what the source shows: the injection was crude, was caught by a human reader, and there is no evidence any court AI system processed the file or produced skewed output. The generalized 'risk is likely to grow' claim and the unspecified model-testing finding push the narrative modestly ahead of the evidence.
Disclosed litigant motive, no vendor stake
Incentives on the record are transparent: the litigant's aim -- getting a default granted -- is quoted from the order, and his post-hoc 'auditing the Court's AI systems' and 'joke' explanations are reported as his own claims. The reporting outlet is an independent commentary blog with no product, vendor, or funding interest visible in the material, and it names no AI vendor that would benefit from the framing. Residual distortion comes from the outlet's editorial appetite for courtroom-AI-failure narratives.
Facts firm, implications thin
Confidence is high on the specific event because the order is quoted with docket-level detail, and moderate overall because everything beyond that event -- prevalence, tool exposure, model susceptibility, outcome of sanctions -- rests on one outlet's unsourced characterizations.
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
A court just sanctioned a prompt injection, and the only control that worked was a human reading the file2 distinct publishers
security
Google's reference agent approved a $10,000 refund on a $149 order, on purpose1 distinct publisher
build
Your agent needs the API call, not the API key1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026