The case concerns a legal filing by Matthew Elliott that allegedly contained hidden instructions intended to influence any AI system reviewing the document. The supplied reporting shows that courts increasingly use AI for research and document review and that a Brazilian court has addressed a similar white-on-white prompt-injection attempt, but it does not establish whether Elliott’s prompt reached an AI-assisted judicial system, affected review, or prompted safeguards. Court records and follow-up reporting are therefore needed to resolve both the attempted exploit’s path and any institutional response.
Scott already holds the core position in “Separation of Powers for Cognition,” “Taint Tracking,” and the “Confused Deputy Problem”: untrusted documents must remain data, not gain instructional authority over consequential AI review. The attempted filing is currently an unverified example, but evidence that it reached a judicial AI system—or triggered court ingestion safeguards—would materially strengthen this position in a high-consequence institutional setting.
ip:framework.separation-of-powers-for-cognitionip:concept.taint-trackingip:concept.confused-deputy-problemdev:concept.recommendation-authority-separationradar:concept.prompt-injectionradar:concept.agentic-securityradar:local-rag-poisoned-source-steeringradar:document-borne-ai-worm-copilot-word
queries asked of Scott's wikis
- indirect prompt injection from untrusted documents
- agentic systems trust boundaries and content isolation
- RAG document-ingestion security
- data versus instructions in AI pipelines
- prompt-injection defenses for document agents
- human oversight and audit trails for AI review
2026-08-18T18:58:24Z
The Connecticut court’s statement that it did not use AI to review or decide the filing closes the suspected exploit path, and no institutional safeguard response has emerged. The episode remains an attempted prompt injection caught by humans rather than evidence of compromised judicial AI ingestion.
2026-08-16T18:32:41Z
The attached Reddit post is only another distribution point for the same reporting and adds no independent evidence. The court’s statement that Connecticut did not use AI to review or decide the filing weakens the exploit-path hypothesis; any broader safeguard response remains open but unsupported.
2026-08-16T18:23:12Z
evidence attached: reddit.post.1vq3iec — shared external link with case evidence
2026-08-16T12:31:00Z
Higher engagement remains repetitive amplification rather than corroboration. No new evidence shows that a judicial AI processed the prompt or that courts introduced document-ingestion safeguards.
2026-08-15T12:30:04Z
The refreshed discussion adds no substantive evidence about judicial AI exposure, exploit effect, or new court safeguards. The episode remains a documented injection attempt and sanction whose broader institutional significance is unresolved.
2026-08-15T11:40:39Z
Refreshed discussion adds no evidence that a judicial AI processed the hidden instructions or that courts changed document-ingestion safeguards. This remains a documented injection attempt and sanction, not yet evidence of exploit propagation or institutional response.
2026-08-15T10:30:32Z
Refreshed comments remain general speculation about AI in courts and add no evidence that a judicial AI processed the embedded prompt or that courts adopted ingestion safeguards. The case’s meaning is unchanged pending court records or substantive follow-up reporting.
2026-08-15T09:29:02Z
No substantive evidence has arrived beyond minor engagement growth. The documented injection attempt and sanction remain notable, but whether any judicial AI processed it or whether courts changed ingestion safeguards is still unresolved.
2026-08-15T09:27:23Z
grounded: known/medium — Scott already holds the core position in “Separation of Powers for Cognition,” “Taint Tracking,” and the “Confused Deputy Problem”: untrusted documents must rem
2026-08-15T09:24:48Z
origin walked (codex/luna, conf 0.97): anchor hn.story.49308553 -> echo.other.a4d14308b3 by Matthew Elliott
2026-08-15T09:23:11Z
case created — This is a concrete adversarial-document episode with direct lessons for securing AI systems that ingest untrusted legal text.