Lawyers have spent the last two years getting much better at checking what comes out of AI systems. We verify the citation, confirm the case exists, and read the answer before relying on it.
That is exactly what we should be doing. But it guards only one side of the workflow.
A Connecticut sanctions order this month exposed the other one: what gets into the system before the answer is generated.
The sanction was only the beginning
In Elliott v. New York Bariatric Group, LLC, No. AAN-CV-25-6066141-S (Conn. Super. Ct. Aug. 6, 2026), a self-represented plaintiff embedded instructions in his court filings using tiny white text on a white background. A person reading the filing would not see them. Software extracting the text would. The instructions told any AI system reviewing the filing to favor his position.
Judge Walter M. Spader, Jr. sanctioned him and revoked his electronic filing privileges.
But the sanction is not the reason the order matters.
Connecticut's courts had adopted AI rules that took effect six weeks earlier, requiring filers to independently verify what AI produces. Judge Spader then confronted a problem those rules did not reach.
Connecticut Practice Book Section 4-9 addresses the failures lawyers have learned to look for: faulty citations, fabricated quotations, invented evidence. In the court's words, that danger "looks at what comes out of the machine."
Elliott ran the other direction. Someone had manipulated what went in.
The judge put the distinction plainly:
"A framework built to catch unreliable output does not, by its nature, reach a filer who manipulates the input."
That is the point worth carrying beyond this case.
The unread channel
The hidden instruction never affected the court. Connecticut's courts do not use AI to decide filings, and Judge Spader decided the underlying motion from a printed copy.
The instruction was aimed instead at whatever AI tool a reader of the filing might use, including opposing counsel's.
Nor is this only a pro se curiosity. The Elliott order cites a May 2026 Brazilian case in which two attorneys used the same white-on-white technique against a court that actually did use an AI system.
The order then turns the problem around and addresses lawyers themselves. Productions, witness statements, expert reports, and other incoming material may be fed into AI systems before counsel examines every word. A hidden instruction could affect what comes back without producing an obvious sign that anything happened.
And the white-on-white trick is not the real mechanism.
If you delegate the reading of a 100-page contract, discovery production, prior art reference, or technical report to AI, ordinary text on page 40 may already be invisible to you. Nobody has to conceal it. The material reaches the model before it reaches your judgment.
I have started calling that the unread channel: the part of an AI workflow where text reaches the system before anyone on your side has meaningfully inspected it.
A patent lawyer may ask AI to synthesize prior art, published applications, office actions, or technical literature. None of those sources has to be hostile. The exposure follows delegated reading, not the author's intent.
I saw the boundary fail from the other direction
A research agent I run recently fetched a page from a public site and then stopped to flag what it believed was a prompt injection. It identified instruction-shaped text referring to one of its tools and told me it had ignored the hostile instruction.
It had correctly recognized something as an instruction. It was wrong about where the instruction came from.
The language had come from the agent's own control layer immediately after the web result, not from the page it had fetched. When I asked what had happened, the agent became more confident and offered plausible theories about how the supposed injection had entered the external content.
The explanation sounded exactly like what you would want from a security-aware system: specific, cautious, alert to manipulation.
It was also wrong about the fact that mattered most.
In many AI workflows, trusted instructions and untrusted content ultimately enter the same model context. The model cannot reliably determine from the text alone which language is data and which language is trying to control its behavior.
That makes prompt injection more than a bug in one product. It is a structural problem for systems that ask models to reason over material the user has not read. And it is why reviewing the answer afterward can only get you so far.
Human review has a boundary
Real defenses exist. Systems can separate instructions from content, delimit untrusted material, classify inputs, restrict retrieval, and limit which tools an agent may use. Those controls matter. They reduce the risk.
But a clean output does not prove nothing upstream affected the run.
In my law review work, I call failures with this structure verification-resistant failures: the property that matters to reliance sits outside the evidentiary reach of the procedure being used to verify it. The failure is not necessarily unverifiable. Output review simply cannot establish it by itself.
The Elliott order shows the difference. In examples where hidden prompts caused conspicuous output, a person could notice that the machine had done something strange. Human review works well when failures announce themselves.
The harder case is a summary quietly tilted toward one side. It may contain no fake citation, strange phrase, or visible command. It may simply look like a competent summary.
That is the limit of the familiar assurance that "a human reviewed it." Review can catch what the output reveals. It cannot automatically reconstruct everything the model encountered before the reviewer saw the result.
Technology competence requires lawyers to understand the benefits and risks of the tools they use. Model Rule 1.1, Comment 8; ABA Formal Opinion 512 (2024); and, for patent practitioners, 37 C.F.R. 11.101 all point in that direction. If AI is reading material you have not meaningfully inspected yourself, the unread channel belongs in that analysis.
Three questions to ask now
What enters your AI workflow before you inspect it? Think productions, prior art, contracts, data rooms, witness statements, expert reports, attachments, intake documents, and web sources.
If one of those inputs carried an instruction, what could it reach? A chatbot summarizing one isolated document has a smaller blast radius than an agent with access to files, email, tools, or a drafting environment.
What evidence would tell you it happened? "The output looked fine" is not evidence about the unread channel. Could you show, later and to someone skeptical, what entered the system and what instructions governed the run?
The Elliott order ends by expressly allowing parties to use generative AI, provided they independently verify what the tool produces. That is the right rule. The same order explains its boundary.
Keep verifying what comes out. Then start paying attention to what went in.
I write about using AI in legal practice without surrendering judgment, privilege, or the duty of competence at The Agentic Lawyer.
Educational only, not legal advice, and no attorney-client relationship is created. Views are my own. Attorney advertising in some jurisdictions.

