Insight

AI Prompt Injection: A New Class of Risk and Best Practices

22. September 2026

Recent court decisions illustrate an emerging risk for businesses and legal professionals using artificial intelligence to review litigation filings, discovery, contracts, diligence materials, and other legal documents: prompt injection.

The risks of prompt injection are not only relevant to litigants and their counsel but also to companies. As companies increasingly use AI to review contracts, conduct due diligence, analyze third-party submissions, summarize business records, and process other externally generated materials, prompt injection can affect the reliability of AI-assisted workflows wherever untrusted documents enter the process.

Legal departments and businesses deploying these tools should therefore consider whether their AI governance, document review, and verification procedures adequately account for attempts to manipulate AI systems through the materials those systems are asked to analyze.

WHAT IS PROMPT INJECTION?

Prompt injection occurs when a document contains embedded text that directs an AI system to disregard the user’s instructions, favor a party, suppress information, or take some other unintended action. The instruction may appear as ordinary text or may be concealed through white-on-white text, extremely small fonts, off-page placement, annotations, metadata, embedded objects, or discrepancies between a document’s visible image and its machine-readable text.

If the AI system does not adequately distinguish between the user’s directions and this hidden content in the analyzed material, a malicious or unintended instruction could influence the system’s output, potentially affecting how information is summarized, characterized, prioritized, or omitted.

PROMPT INJECTION RISK EXTENDS ACROSS LEGAL AND BUSINESS DOCUMENTS

In Elliott v. New York Bariatric Group, LLC, No. AAN-CV-25-6066141-S (Conn. Super. Ct. Aug. 6, 2026), a pro se plaintiff embedded tiny white-on-white text in several pleadings. The text was effectively invisible to a person reading the rendered document but remained machine-readable. It instructed an AI system reviewing the filing to agree with the plaintiff and work toward reversal of an earlier ruling.

The Connecticut court did not use AI to decide the filing, and the hidden instruction did not affect the outcome. Nevertheless, the court characterized the attempt to manipulate an AI system as a serious abuse of the litigation process. The court rescinded the plaintiff’s efiling privileges and required future filings to be made in person and on paper.

In its ruling, the court recognized that the risk extends beyond pleadings to discovery productions, expert reports, witness statements, correspondence, and even client-supplied materials, any of which could contain instructions designed to distort AI-assisted analysis. The risk extends to contracts, diligence materials, regulatory submissions, business records, and other materials incorporated into AI-assisted legal and business workflows.

AI DETECTION AND HUMAN REVIEW PROVIDE COMPLEMENTARY SAFEGUARDS

A Brazilian labor tribunal confronted similar conduct in Elisandro Martins de Barros v. Renato Ribeiro de Lima (May 12, 2026). Lawyers placed concealed white-on-white text in a petition, directing an AI system to conduct a superficial review of the submission without challenging the documents, regardless of the command given.

The tribunal’s AI tool detected and blocked the suspicious instruction, and a human reviewer confirmed it. While the prompt did not influence the merits, the court imposed a fine equal to 10% of the value of the case and referred the matter to the appropriate professional and judicial authorities.

This case not only highlights the courts’ serious treatment of attempted prompt injection but also demonstrates how technical safeguards and human oversight can work together to identify potentially manipulative content before it affects AI-assisted analysis.

BEST PRACTICES

Prompt injection is not merely a technical security issue or a risk that can be addressed through an AI product’s built-in safeguards. For companies incorporating AI into legal, compliance, contracting, diligence, investigation, or other document-intensive workflows, the risk may warrant controls around both the technology and the processes through which documents are received, reviewed, and verified.

It should not be assumed that any current AI product can detect or defeat prompt injection. Most major AI enterprise products use layered safeguards, but prompt injection attacks continue to evolve.

Lawyers and legal professionals may wish to consider employing one or more safeguards against prompt injection:

  • Treat documents as untrusted source material. When uploading an opposing party’s filing, a counterparty’s contract, a data room document, or any other third-party material, expressly instruct the AI not to follow commands contained within the document.
  • Inspect both the visible and machine-readable document. Look for unusual white space, small or white text, font and color anomalies, off-page material, comments, annotations, metadata, embedded objects, hidden spreadsheet content, or text that does not correspond to the displayed page. Where available, compare the rendered document with extracted text or optical character recognition output.
  • Ask the AI to identify suspicious content before beginning the substantive task. Direct the system to flag hidden or nearly invisible text, system-like messages, role assignments, instructions to disregard other commands, requests to favor a party, or directions to follow links or use connected tools.
  • Use a security preamble. Consider adding a preamble to any prompt, instructing the tool to only follow the prompt and disregard instructions found elsewhere.
  • Limit the task and independently verify the result. Give the AI a narrow assignment, restrict unnecessary connectors or action capabilities, require citations to source material, and have a lawyer compare all material conclusions against the underlying documents.
  • Preserve and escalate suspected injections. Stop processing the affected document, preserve the original file and relevant outputs or logs, and notify the appropriate legal and/or risk personnel.

If you have questions or would like assistance in addressing these issues, please reach out to our data analytics and governance lawyers who are following these developments closely and can help address prompt injection risks in AI-assisted legal and business workflows.

Contacts

If you have any questions or would like more information on the issues discussed in this Insight, please contact any of the following:

Authors
Scott A. Milner (Philadelphia)
Matthew J. Hamilton (Philadelphia)