AI Prompt Injection & Hidden Text Legal Tracker

Key Takeaway

This AI Prompt Injection Cases Tracker records court cases, sanctions and official guidance concerning hidden or adversarial instructions designed to manipulate an AI system. It includes white-on-white text in court filings, indirect prompt injection through documents and attempts to influence judicial, legal or public-sector AI tools. The AI Prompt Injection Cases Tracker anything that may be relevant to this issue. It includes attempted, alleged, admitted, reported, suspected, blocked and judicially established incidents. Inclusion does not mean that the instruction succeeded, that the target organisation used AI, that the person responsible acted unlawfully or that a court made a finding of dishonesty. Each entry must be read according to its linked report.

Tracker Status: Active/Monitoring
Publication Date: 29 August 2026
Last Verified: 30 August 2026
Latest Case Chronologically: 
Latest Legal Article: 
Other AI Legal Trackers: AI Law Trackers Hub
Author and Contact: Matthew Lee (Barrister) click here for details.

AI Prompt Injection Cases

Ad/Marketing Communication regarding AI Prompt Injection & Hidden Text Legal Tracker

This legal article/report forms part of my ongoing legal commentary on the use of artificial intelligence. Not legal advice. Not Direct/Public Access. All instructions via clerks at Doughty Street Chambers. This legal article concerns the AI Prompt Injection & Hidden Text Legal Tracker.

The AI Prompt Injection & Hidden Text Legal Tracker

Below is the publicly available AI Prompt Injection & Hidden Text Legal Tracker. Read it subject to the important disclaimers below.

DateNameCountryTypeSummaryQuote
13-Feb-2024NCSC: AI and cyber security, what you need to knowUnited KingdomGuidanceEarly official UK guidance identifying prompt injection as a distinctive AI security risk.
10-Feb-2025Artificial Intelligence Playbook for the UK GovernmentUnited KingdomGuidanceThe playbook expressly lists prompt injection among AI-specific threats and requires safeguards for government deployment.
31-Oct-2025Artificial Intelligence Guidance for Judicial Office HoldersUnited KingdomGuidanceThe guidance defines white text as human-invisible but computer-detectable material capable of manipulating search engines or LLMs.
08-Dec-2025NCSC: Prompt injection is not SQL injectionUnited KingdomGuidanceThe NCSC describes LLMs as inherently confusable and warns that prompt-injection risk cannot be fully removed by a single mitigation.
25-Mar-2026Civil Justice Council Interim Report: Use of AI for Preparing Court DocumentsUnited KingdomGuidanceThe CJC recognised white text as capable of manipulating search engines and LLMs and as creating separate authenticity and alteration concerns.
12-May-2026ATOrd 0001062-55.2025.5.08.0130BrazilCaseA labour-court filing reportedly contained white-on-white instructions directed at the court's AI system. The system blocked the attempt and lawyers were sanctioned.
06-Aug-2026Matthew A. Elliott v New York Bariatric Group, LLCUnited StatesCaseThe court found repeated hidden text designed to influence any AI reviewer and imposed filing restrictions.

What the AI Prompt Injection & Hidden Text Legal Tracker Covers

The tracker may include:

  • white font on a white background or text hidden by size, positioning, layers or formatting;
  • instructions embedded in pleadings, exhibits, expert materials, websites, emails or uploaded documents;
  • indirect prompt injection contained in data retrieved by an AI system;
  • adversarial instructions aimed at a court, tribunal, law firm, regulator or public authority;
  • attempts to influence document review, summarisation, classification, ranking, legal analysis or a tool-using AI agent;
  • sanctions, filing restrictions, professional referrals, disciplinary proceedings and evidential rulings;
  • official judicial, governmental and cyber-security guidance;
  • disputes about authenticity, intention, knowledge, causation and whether the target used AI at all; and
  • technical or procedural controls adopted in response to a legal incident.

The tracker does not include ordinary prompt engineering, benign instructions used with the user’s own AI system, or generic demonstrations with no identifiable legal, judicial, governmental or regulatory connection.

Use of AI, Human Review and Corrections

Remember, I may use AI tools to assist with research, checking, drafting, formatting and organisation. Because those tools can themselves be vulnerable to prompt injection and can produce inaccurate material, I try and check against linked human-readable source before publication. However, readers must check themselves for accuracy as mistakes may creep in.

Please report broken links, altered procedural status, missing orders, mistranslations, duplicate entries or technical descriptions that require correction through the Contact page.

Legal Themes Monitored

The tracker monitors AI prompt injection cases involving court integrity, professional conduct, misleading the court, fraud, contempt, abuse of process, document authenticity, disclosure, evidence preservation, cyber security, computer misuse, data protection, confidentiality, contractual restrictions, system design, human oversight, tool permissions and responsibility for automated actions.

Jurisdictions Monitored

The AI prompt injection cases tracker is international. It may include courts, tribunals, professional regulators, governments and cyber-security agencies from any jurisdiction where sufficiently reliable public material is available. Legal consequences will vary significantly between jurisdictions and between court filings, private systems and public-sector deployments.

How to Cite This Tracker

Suggested citation: Matthew Lee, “AI Prompt Injection & Hidden Text Legal Tracker”, Natural & Artificial Law (live tracker, first published 2026).

Frequently Asked Questions

What is prompt injection?

Prompt injection occurs where untrusted content contains an instruction which an AI system may treat as though it came from the system’s developer or authorised user. It may be direct, where a person enters the instruction into the AI interface, or indirect, where the instruction is hidden in a document, webpage, email or other material processed by the system.

What is white text in a court filing?

White text is text formatted so that it is not apparent to the human reader, commonly white font on a white background, while remaining detectable by software. It may contain keywords or instructions intended to influence search, classification or an AI-generated response. Not every instance of hidden text is necessarily malicious, so context and evidence matter.

Does inclusion mean that prompt injection has been proved?

No. The tracker includes proven findings, admissions, allegations, suspicions and official warnings. The status of each entry identifies what the source claims and what remains disputed or unknown. Readers must look at the source and draw their own conclusions.

Must the targeted court or organisation actually have used AI?

No. An attempted injection may be relevant even where the court did not use AI or the instruction was never processed. The attempt may still raise issues about concealment, filing integrity, professional conduct and the security of systems used by other participants.

Is every hidden instruction unlawful?

No. The legal result depends on the context, intention, governing rules and effect. A concealed instruction in litigation may engage duties to the court or procedural sanctions, while an instruction targeting a private system may raise different questions of contract, computer misuse, confidentiality or data protection. The tracker does not label conduct unlawful unless the source supports that conclusion.

Is prompt injection the same as a jailbreak?

These terms are not always used consistently, so its difficult to state precisely. A jailbreak usually involves a user deliberately trying to override a model’s safety or behavioural restrictions in a direct conversation. Prompt injection is broader and often involves untrusted content being confused with authorised instructions, particularly when an AI retrieves or processes third-party material.

Can prompt injection be completely prevented?

At present, I haven’t identified a single dependable safeguard for every generative-AI system. Effective risk reduction normally requires layered controls, including limiting the tools and data the model can access, separating instructions from untrusted content where possible, constraining permissions, validating proposed actions, logging activity and requiring human approval for consequential steps.

How can hidden text or document-based prompt injection be detected?

Depends. Possible controls include extracting and comparing the underlying text with the rendered document, checking font colours and sizes, inspecting layers, comments and metadata, using trusted document-sanitisation processes and treating external documents as untrusted input. Detection does not by itself establish authorship or intention.

Does the tracker include prompt injection against AI agents?

Yes, where the incident has a legal or regulatory connection. If the injection causes or attempts to cause an agent to take an external action, the matter may also be cross-listed in the AI Agents, Autonomous Transactions & Liability Tracker.

Can this tracker be relied upon as legal or cyber-security advice?

No. It is a legal research index and general commentary. Readers should examine the primary source and obtain advice appropriate to the relevant jurisdiction and system. Matthew Lee is not authorised for Public or Direct Access. Instructions may only be provided through his clerks at Doughty Street Chambers.