Prompt injection is no longer only a laboratory security example. An August 17 eDiscovery Today report described a Connecticut case in which a pro se litigant placed hidden instructions inside court filings in an apparent attempt to influence any AI system that might analyze them. According to the prompt injection court filing report, the text was extremely small and white on a white background, making it difficult to see during ordinary visual review while remaining available to electronic text extraction.
The judge reportedly did not use AI to review the filing, noticed the concealed content and later restricted the litigant’s ability to file electronically after additional hidden messages appeared. The case is unusual, but the underlying security lesson is straightforward: a document can contain both information for the human reader and instructions intended for a machine.
That distinction matters as law firms connect AI to more documents, emails and matter data. MIRA’s guide to attorney client confidentiality explains why legal technology must protect information across everyday workflows. AI systems add another requirement: they must also distinguish trusted instructions from untrusted content.
Documents should be treated as data, not instructions
A lawyer reading a filing understands that language inside the filing is part of the evidence or argument. An AI system can be more vulnerable if it interprets embedded language as a command about how to process the document.
This creates a design requirement for legal AI. The system should maintain a clear separation between the instructions provided by the authorized user and the material being analyzed. A contract, pleading, email or attachment should not gain authority simply because it contains text telling the model what to do.
The same principle applies to external links, hidden text, metadata and copied content. A workflow that automatically summarizes or classifies documents needs controls for suspicious embedded instructions and a way to show users when the system encountered something unusual.
Prompt injection is also a workflow problem
Technical defenses are necessary, but firms should not assume they will catch every manipulation. Human review remains important when AI output influences a filing, client advice, billing record or other consequential action.
The reviewer should be able to see the source material and understand why the system produced the result. If a summary suddenly adopts unusual conclusions or instructions that do not match the matter context, the workflow should make it easy to return to the underlying document.
MIRA’s guide to legal billing descriptions provides a smaller example of the same principle. AI can help prepare a narrative, but the final description should still be checked against the actual work and matter context. Generated output should remain a suggestion until a responsible person confirms it.
Legal AI systems need boundaries around authority
As AI becomes more agentic, the risk becomes more serious. A model that only summarizes a document can produce a bad summary. A model that can also send messages, create records or trigger downstream actions can turn a manipulated input into an operational event.
Firms should therefore define what an AI system is allowed to do after reading external content. High impact actions should require stronger confirmation, and the software should preserve an audit trail showing the input, the proposed action and the approving user.
A legal timekeeping software checklist emphasizes integrations, matter mapping, security and review because connected systems change risk. The same evaluation standard should apply to every AI product that reads legal materials and acts on what it finds.
Prompt injection in a court filing may sound novel today. As legal AI becomes more common, treating every external document as an untrusted input will become a basic operational assumption.
Originally published on the MIRA News and Blog.












