Lawyers Caught Deceiving Brazilian Court AI with Prompt Injection Attacks
Key Takeaways
- ▸Brazilian lawyers attempted to manipulate Galileu, a court AI assistant, using prompt injection—hidden instructions typed in white-on-white text designed to bypass evidence review
- ▸The AI system itself detected the attack and flagged it to the judge, who sanctioned the lawyers; similar incidents have since emerged in other Brazilian courts
- ▸Prompt injection attacks represent a new frontier in legal fraud, distinct from earlier AI misuse (fabricated case law) and potentially harder to detect as they silently suppress rather than create false information
Summary
A labor court in northern Brazil exposed an attempt to manipulate its AI-powered case management system, Galileu, when lawyers concealed hidden instructions in white text within their petition—invisible to the human eye but detectable by AI. The system itself flagged the prompt injection attack, prompting the judge to sanction the lawyers. This incident is not an isolated case: similar attempts have already emerged in other Brazilian courts, signaling a growing threat to judicial systems worldwide as they increasingly adopt AI tools for document analysis and case organization.
Prompt injection—a technique of inserting hidden commands into text to manipulate AI behavior—represents a sophisticated new frontier in legal fraud. Unlike earlier cases of lawyers caught fabricating case law with AI tools, prompt injections aim to silently suppress evidence and bypass judicial scrutiny. The Brazilian incident demonstrates both the vulnerability of AI systems and their capacity to self-defend, as Galileu independently detected the deception. However, legal experts warn this is merely the beginning: as courts from Spain to beyond adopt similar AI assistance systems, the temptation and opportunity for such attacks will only grow.
The implications extend beyond Brazil. Spain's General Council of the Judiciary has already issued guidance on judicial AI use, explicitly permitting the kind of document analysis and classification that opened the door to fraud in Brazil. Legal professionals argue this is not science fiction but an foreseeable challenge requiring robust safeguards, oversight mechanisms, and human review—yet the broader judicial system remains unprepared for this new form of forensic manipulation.
- Spain and other jurisdictions are adopting similar AI-assisted case management systems without comprehensive safeguards against prompt injection attacks, creating systemic vulnerability
Editorial Opinion
The Brazilian court system's discovery of prompt injection attacks in the judicial process is a critical wake-up call for the legal industry. While AI can dramatically improve efficiency in document review and case organization, deploying these systems without robust detection mechanisms and mandatory human oversight creates dangerous vulnerabilities to forensic manipulation. The fact that Galileu self-detected this attack is fortunate, but relying on AI to police itself is insufficient—courts must implement strict protocols, regular audits, and legal frameworks that address prompt injection as a new category of fraud before these attacks become sophisticated enough to evade detection.



