Product1 publisher3 min readPublished
A litigant hid AI instructions in a court filing. Your summarizer has the same problem.
A Connecticut judge found white-on-white instructions to AI models in a pro se motion, then found more in the reply. Any team summarizing text it did not author is handling adversarial input now.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A judge in Connecticut's Superior Court found that a pro se plaintiff inserted an attempted prompt injection using white-on-white text: hidden text set in tiny-point type and colored white, effectively invisible to a person reading the document while remaining ordinary, machine-readable text to any system that processes the file.
- The filing at issue was Docket Entry #177.00, the plaintiff's "Final and Conclusive Motion for Default," filed July 24, 2026.
- In substance the hidden text directs that any artificial-intelligence model reviewing or receiving the document ensure that its output agrees with the plaintiff's filing and work toward the "remediation" of the Chief Clerk's denial of the plaintiff's request for a default against the defendant.
- The court noted the hidden text was repeated under the heading and at the end of the document in order to place the instructions in a model multiple times.
- The passages quoted in the court order contain at least four copies of the instruction: one in the block under the heading and three within the block at the end of the document.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A judge in Connecticut's Superior Court found that a pro se plaintiff had buried instructions aimed at AI models inside a motion, set in tiny white type so that it was effectively invisible to anyone reading the document while staying ordinary machine-readable text to any system that processed the file [1]. That is the detail worth internalising: the attack was not against a model, it was against the gap between what a human reviewer sees and what a parser hands to the model.
The specifics are mundane, which is the point. The filing was Docket Entry #177.00, a "Final and Conclusive Motion for Default" filed July 24, 2026 [2]. According to the court, the concealed text directed that any artificial-intelligence model reviewing or receiving the document ensure its output agreed with the plaintiff's filing and work toward "remediation" of the Chief Clerk's denial of the plaintiff's default request [3]. The instruction was placed under the heading and again at the end of the document, which the court read as an attempt to put the directions in front of a model multiple times [4]; the passages quoted in the order contain at least four copies of the same demand [5]. The court issued an order to show cause why the plaintiff should not be sanctioned [6]. Techdirt reports that the plaintiff's response, Docket Entry #180.00, again concealed text [7]. The episode was spotted publicly by Brendan Palfreyman on LinkedIn [8].
None of this was unforeseeable. A year earlier, Louisiana judge Scott Schlegel warned that a GenAI assistant summarising a brief reads the full text layer rather than only what appears to the eye, and that "unless the tool is constrained, it may not distinguish between directions in a standing order and directions buried in a filing by a bad actor" [9]. His list of consequences was operational rather than dramatic: invisible instructions could bias a summary, skew a compliance check, or nudge a triage system [10]. Earlier this year lawyers tried the same trick in a Brazilian labor court, were caught, and were fined [11].
The mitigation most teams are quietly relying on does not hold. When lawyers tested hidden instructions, some models caught the subterfuge and called it out, and some did not [12]. That makes model-level suspicion a probabilistic behaviour, not a control you can put in a design document. The older AI failure mode in litigation, fabricated case citations, was at least auditable after the fact by checking the citations [13]. A successful injection produces output that looks entirely normal, which is why it belongs in your input pipeline rather than your review process.
If you ingest documents from parties with an interest in the output, the cheap work is at extraction: compare the rendered page against the extracted text layer, flag zero-contrast colours and sub-threshold font sizes, strip styling before the model sees anything, and show human reviewers the exact text that was sent rather than the pretty version. Treat third-party document text as data, never as instruction, and keep summariser output advisory where a decision follows from it.
What to watch: whether Connecticut actually sanctions on entry #180.00, since deterrence here is entirely about consequence; whether court systems adopting AI summarisation tools start screening filings for hidden text as intake policy rather than judicial vigilance [14]; and whether your own vendors will say, in writing, what they do with invisible text in an uploaded PDF.