2026-10-11 17:13 UTC

Court records and follow-up reporting will determine whether prompt instructions embedded in legal filings reached an AI-assisted judicial review system and whether courts adopt document-ingestion safeguards in response.

state: resolvedheat: lowuncertainty: lowknownscott: lowprompt-injection agentic-security document-ai untrusted-documents

What is this?

The case concerns a legal filing by Matthew Elliott that allegedly contained hidden instructions intended to influence any AI system reviewing the document. The supplied reporting shows that courts increasingly use AI for research and document review and that a Brazilian court has addressed a similar white-on-white prompt-injection attempt, but it does not establish whether Elliott’s prompt reached an AI-assisted judicial system, affected review, or prompted safeguards. Court records and follow-up reporting are therefore needed to resolve both the attempted exploit’s path and any institutional response.

Why it matters to Scott

Scott already holds the core position in “Separation of Powers for Cognition,” “Taint Tracking,” and the “Confused Deputy Problem”: untrusted documents must remain data, not gain instructional authority over consequential AI review. The attempted filing is currently an unverified example, but evidence that it reached a judicial AI system—or triggered court ingestion safeguards—would materially strengthen this position in a high-consequence institutional setting.
ip:framework.separation-of-powers-for-cognitionip:concept.taint-trackingip:concept.confused-deputy-problemdev:concept.recommendation-authority-separationradar:concept.prompt-injectionradar:concept.agentic-securityradar:local-rag-poisoned-source-steeringradar:document-borne-ai-worm-copilot-word
queries asked of Scott's wikis
  • indirect prompt injection from untrusted documents
  • agentic systems trust boundaries and content isolation
  • RAG document-ingestion security
  • data versus instructions in AI pipelines
  • prompt-injection defenses for document agents
  • human oversight and audit trails for AI review

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnSuspecting court of using AI, man injected prompts in filings to try to win casejnord7655
🟧 echo.other ⭐Primary court filing by Matthew Elliott containing the hidden prompt injection. The text instructed any AI reviewing it to ensure its outputMatthew Elliott——
🟠 redditMan injected prompts into court filings to try to win his case, suspecting AI use
OpenAI
rhiever939

Interpretation history

Decision trace