When the Filing Talks to the Machine: Legal Lessons from Elliott v. New York Bariatric Group

Maj. Vineet Kumar and Isharth Kumar
Maj. Vineet Kumar and Isharth Kumar
Founder & Global President, CyberPeace and Isharth Kumar (Intern) CyberPeace
PUBLISHED ON
Sep 2, 2026
10

Introduction

Artificial intelligence has quietly become part of the future of litigation, like drafting pleadings, summarising depositions, and helping self-represented parties navigate a system that was never designed for them. But what happens when a litigant doesn't just use AI but tries to manipulate it, planting invisible commands inside a court filing, hoping some AI tool reading the document will do the litigant's bidding? That is precisely the question a Connecticut Superior Court judge confronted in Matthew A. Elliott v. New York Bariatric Group, LLC, Docket No. AAN-CV-25-6066141-S (Conn. Super. Ct., Aug. 6, 2026),  a decision that may be the first of its kind in the United States to sanction a party for embedding a "prompt injection" in a court pleading.

The Facts

Elliott, representing himself, filed a motion titled "Final and Conclusive Motion for Default". Buried within it, in a tiny, white-on-white font invisible to a human reader but fully legible to any software parsing the document, was a block of text addressed not to the court or opposing counsel but to any AI system that might process the filing. The hidden text instructed such a system to treat its output as agreeing with Elliott's position and to work toward "remediating" a prior clerk's denial of his motion for default.

A second filing repeated a shortened version of the same instruction. When the court issued an Order to Show Cause warning that concealed text in pleadings would not be tolerated, Elliott did not stop. Subsequent filings carried further hidden messages, some flippant asides, one a hidden link to a horror film video submitted even after he had received notice of the sanctions hearing. At the hearing, Elliott characterised his conduct as a self-appointed "audit" of whether the court used AI and later said he continued the practice "as a joke".

The Legal Questions

Judge Walter M. Spader, Jr framed the case around two hard questions. First, does concealing an instruction to an AI system constitute misconduct even if no AI ever acted on it since the court had, in fact, decided the underlying motion on the merits from a printed copy? Second, can a court sanction conduct that Connecticut's own recently adopted AI rules do not expressly address?

Connecticut's Practice Book §4-9, effective only weeks earlier in June 2026, governs generative AI use in filings, but it is aimed at a different danger: the risk that AI-generated output might contain fabricated citations or invented quotations, and it places a verification duty on the filer to catch such errors. As the court observed, that framework addresses unreliable output. It says nothing about manipulated input from a filer seeding a document so that whatever tool later reads it will be corrupted in the filer's favour. The absence of an express rule, the court held, "takes nothing away from the duties of good faith and candour that have always governed those who appear before this Court."

The Court's Reasoning

The court's analysis rested on three pillars. First, intent, not success, is the touchstone of the violation. Because the judge decided the contested motion from a printed version, the hidden instruction achieved nothing, but the court held that the wrong lies in the attempt itself, not its efficacy, drawing an analogy to how the law has long treated attempted corruption of a proceeding as wrongful regardless of the outcome.

Second, the court situated the misconduct within the broader duty of candour owed to tribunals. A pleading, the court reasoned, is a communication to both the court and the opposing party, resting on the premise that what the reader sees is what the filer actually wrote. Hiding a second, machine-readable message beneath that surface breaches this premise. The court drew a memorable comparison: planting an AI-directed instruction in a filing is analogous to an ex parte communication which is a secret message to the decision-making apparatus that the opposing party can neither see nor answer, offending the basic adversarial principle that arguments meant to influence a decision must be made openly, on the record.

Third, the court emphasised that self-represented litigants, while entitled to procedural latitude, remain bound by the same underlying obligations of good faith as represented parties. That solicitude "stops at the misuse of the process itself".

Notably, the court situated Elliott's conduct within a growing pattern well beyond the courtroom, citing reports of job applicants hiding white-text instructions in résumés to manipulate AI screening tools and a professor who caught AI-assisted cheating by embedding a hidden trap word in an exam. Prompt injection, the court noted, has become a documented, catalogued vulnerability recognised across the cybersecurity field, and its migration into litigation was, in the court's words, "unsurprising" given how commonplace the tactic has become elsewhere.

Comparison to Mata v. Avianca

The decision draws a deliberate contrast with the now-famous Mata v. Avianca, Inc. (S.D.N.Y. 2023), where attorneys were sanctioned for submitting briefs citing wholly fictitious cases generated by ChatGPT. Both cases involve AI misuse sanctioned under a court's inherent authority, but the underlying wrongs are different in kind. Mata's concerned negligent reliance on defective AI output;  the lawyers there did not intend to deceive the court, and their candour and contrition were treated as mitigating factors even as sanctions were imposed. Elliott's conduct, by contrast, was deliberate input manipulation aimed at corrupting how any AI reader would process his own filing, and it persisted even after a direct judicial warning. As the court put it, "What may have earned a 'no harm, no foul' sanction when it was first done calls for a firmer response when it is done repeatedly after warning."

The court also cited a Brazilian labour court decision, Elisandro Martins de Barros v. Renato Ribeiro de Lima (2026), where two licensed attorneys used a similar hidden-text technique in a jurisdiction where the tribunal actually deployed AI to process filings  and where the tribunal's system caught and blocked the injection, followed by a referral to attorney-discipline authorities.

The Sanction and Its Significance

Rather than dismissing the case or imposing monetary penalties, the court chose a narrowly tailored remedy: rescinding Elliott's e-filing privileges and requiring all future filings to be made in person on paper, a sanction addressing the specific abuse (concealed digital text) without barring courthouse access altogether. Importantly, the court reaffirmed that generative AI remains welcome as a litigation aid, provided any output is independently verified, consistent with Practice Book §4-9(b).

Conclusion

Elliott is a small case with an outsized signal: courts are beginning to recognise that AI-era misconduct is not limited to fabricated citations but extends to covert attempts to manipulate the tools, including tools opposing counsel, clerks, or even the court itself might someday rely on. For practitioners, the lesson is to treat every incoming AI-processed document, from opposing productions to client materials, with the same scrutiny once reserved for verifying citations. For courts, it is a reminder that inherent authority over the integrity of proceedings can reach conduct that emerging procedural rules have not yet caught up to naming.

References

PUBLISHED ON
Sep 2, 2026
Category
TAGS
No items found.

Related Blogs