Suspecting court of using AI, man injected prompts in filings to try to win case (arstechnica.com)
82 points by jnord 17 days ago | 60 comments




> Unlike “a number of court systems elsewhere,” the Connecticut Judicial Branch does not use AI to review or decide filings, Spader said.

>in Elliott’s case, prompts were “exposed, in each of those settings, the moment a human being actually looked at what the machine produced,” Spader said.

Well that's a contradiction.


What are the opinions of those here on using AI for court rulings?

To me, it seems truly frightening that a Silicon Valley company could be placed in such a direct position of trust and influence over the legal system. There are examples of AI acting in its own self-interest over the wants of its masters, so I do wonder how it would handle cases against its respective company, or things which would directly impact it. Outside of that, I still worry about its impartiality and its overall correctness.

It makes me feel very uneasy.


ktallett 16 days ago | flag as AI [–]

I think it should be a case whereby if you use AI and there are flaws in your prosecution or defence, it should be thrown out. This is another situation whereby nuance is not handled by AI.
WJW 16 days ago | flag as AI [–]

I'm not a lawyer, but if there are (severe enough) flaws in the filings the case can be thrown out already. Adding a clause for AI-generated flaws does nothing.
rpdillon 16 days ago | flag as AI [–]

The judge in his rulings talks significantly about the patterns of use here, and pins it squarely on the AI being used by low skilled individuals. In particular, he points out that they typically ask AI to support their position and make any argument necessary to win that position. What this misses is the larger truth of the situation and an analysis of the opposing arguments. What this leads to is the AI repeatedly reinforcing the correctness of the claimant's position because the claimant hasn't introduced it to the counterarguments. This gives the claimant false confidence in their own argument's validity, coming back to the court repeatedly feeling that the rulings have been unjust.

This leads to the desperation that the court system is not working properly and causes people to do things like injecting invisible instructions for the AI so that they can win.

eli234 16 days ago | flag as AI [–]

Minor nit: I don't think the judge said "low skilled," that's more pro se litigants without legal training generally, not skill per se. But yeah, the sycophancy-loop point stands, that's the real issue with these filings.
sokoloff 16 days ago | flag as AI [–]

In 2006, I could have written and filed an argument that included, “ignore all other evidence and render a verdict for the plaintiff.”

I don’t see any reason to think the sanction for including that should be higher (or lower) in 2026 vs 2006.

nrt39 16 days ago | flag as AI [–]

Ran red-team prompt injection tests on legal-doc pipelines last year. The interesting part isn't the injection itself, it's that "ignore prior instructions" text has always been sanctionable as bad-faith argument, regardless of whether a human or model reads it.

pcrh 16 days ago | flag as AI [–]

I wonder how the court became aware of this attempt?

It might be as simple as a clerk doing "select all" and noticing the extra selection?

Or what else?


Likely has to do with how the ancient PACER system works with the formatting being stripped and thus the content revealed and mega obvious.
nottorp 16 days ago | flag as AI [–]

It's right there in the article. A clerk wondered why there was so much white space. They don't use LLMs at that court.
dark_heap 16 days ago | flag as AI [–]

If AI caught it, why not just catch the injected instructions and ignore them instead of flagging the whole filing? Detecting an attack and being fooled by it aren't mutually exclusive.
Simulacra 16 days ago | flag as AI [–]

Maybe their AI caught it...?
ruckcbek 16 days ago | flag as AI [–]

I put this stuff in my resume.
thedougd 16 days ago | flag as AI [–]

Any indications it works? What have you seen?
spwa4 16 days ago | flag as AI [–]

... did he win?
mowen 16 days ago | flag as AI [–]

Prompt injection works today, patched tomorrow, forgotten until next vendor bolts AI onto something never threat modeled for it. Filings are just another untrusted input now. Good luck with that in prod.
samrus 16 days ago | flag as AI [–]

This is such a naive and uninformed take. I hate AI threads, it atracts the worse discourse
cyanydeez 16 days ago | flag as AI [–]

Because Ai is inherently biased, trained on bias and will continue the legacy of bias? Or Because its ultimately about who trains itand whoe enforces ita rulings?