What one hidden line of white text reveals about trust, AI, and the future of legal filings.
As artificial intelligence becomes more common in legal workflows, a new challenge is emerging: documents can be written not only for the people reading them, but also for the AI systems analyzing them. Legal professionals are relying on AI to summarize filings, review evidence, and surface relevant information, creating new opportunities for others to attempt to influence those systems.
The case that proved the point
A recent Connecticut case, Elliott v. New York Bariatric Group, LLC, turned a theoretical concern into a real-world example. A self-represented litigant embedded prompt-injection instructions in tiny white text on a white background, making them invisible to human readers but readable to AI systems processing the document. The hidden instructions directed any AI reviewing the filing to favor the litigant’s position.
Perhaps most notably, the hidden text wasn’t discovered by an AI tool or security system. It was found by a person who noticed something unusual about the filing and took a closer look. Judge Walter Spader likened the concealed instructions to an improper ex parte communication: an attempt to influence part of the process through information that was not visible to the other side.
As Judge Scott Schlegel notes in his discussion of the case, the filing was effectively designed to communicate two different messages: one for human readers and another for any AI system that might analyze it later. Regardless of whether an AI ultimately reviewed the document, the incident highlights a growing challenge for legal professionals as AI becomes more integrated into legal workflows.
The risk isn’t limited to judges
The uncomfortable part of Judge Schlegel’s argument is that this isn’t only a courtroom problem. He notes that hidden instructions like these could just as easily target opposing counsel’s AI tools — buried in an adversary’s production, a witness statement, or an expert report, waiting for someone on the other side to run it through a summarizer or review tool. Any legal team using AI to process documents they didn’t create is potentially exposed.
His conclusion is straightforward: tools need to be built so that hidden instructions can’t quietly steer output, and anything suspicious gets surfaced for a human to look at.
Where CoCounsel Next fits in
The good news is that CoCounsel is already designed to avoid this particular type of prompt injection.
When Word and PDF documents are imported into CoCounsel, they are processed through Optical Character Recognition (OCR), which captures only text that is visible to the human eye. As a result, hidden instructions embedded in white-on-white text, extremely small fonts, or other invisible formatting are not read by the system at all.
That distinction matters. In the Connecticut case, the litigant’s goal was to influence any AI tool that might later review the filing by embedding instructions that human readers could not see. Because CoCounsel only processes visible text, those hidden instructions would never reach the AI in the first place and therefore cannot influence its output.
For courts and legal professionals evaluating AI tools, that raises an important question: how does an AI system ensure it isn’t silently acting on instructions hidden inside the documents it analyzes? Trustworthy legal AI should be designed to evaluate the same content a human reviewer sees, not an unseen layer of text intended exclusively for machines.
As AI becomes more common in legal workflows, protections like these will play an important role in maintaining confidence that outputs are based on the actual record, rather than on hidden attempts to manipulate the technology.
The bigger picture
Judge Schlegel is careful to say he’s not a technologist and isn’t positioning himself to be the one who solves this. But he’s right that the window for building in these protections is now, while AI adoption in legal workflows is still early enough that the tooling can get ahead of the problem rather than chase it. As more filings, productions, and reports get run through AI before a human ever reads them closely, the incentive to hide a message in the margins only grows.
The fix isn’t complicated in concept: don’t let a document talk to the machine behind the reader’s back. Flag it, show it, let the human decide. That’s the standard this moment calls for, and it’s the standard we’re building toward.
Hidden prompt injection is a reminder that not all AI systems handle documents the same way. Discover how CoCounsel Legal for Courts is built to help courts use AI with confidence through safeguards designed to support accuracy, transparency, and human review.
