Galileu, a labor court assistant in Parauapebas, flagged a prompt injection — instructions written for the AI that processes the file, not for the judge who reads it — hidden as white text on a white background, invisible to the human eye but
A Brazilian labor-court AI named Galileu caught white-on-white text hidden inside a lawyer's filing in Parauapebas. The hidden text was a prompt injection: instructions written to the AI that processes the file, rather than to the judge who reads it. Galileu was told to respond superficially and not challenge the documents being filed. It ignored the instruction, flagged it, and the judge sanctioned the lawyers, according to El País and Brazilian legal press Migalhas.
Prompt injection is a category, not a single trick. It covers any case where a person embeds instructions in text that an AI tool will process, and the instructions tell the tool to do something the human reader never asked for. The same pattern is already live in two other places. Professors hide decoy instructions in homework assignments to catch students who copy the questions into ChatGPT. Recruiters plant them in job postings to screen out résumés produced by AI tools applying on autopilot. The pattern is well documented in security research against the same kind of consumer and enterprise AI tools, which makes the Brazilian case a foreseeable step rather than a surprise. In all of these, the attacker writes to the AI, not to the person reading the output, and the surface is the same. The Brazilian lawyers are the first to try it in a court filing. The framing, in Adrian Lerer's Substack analysis, is that text became a weapon the moment any system downstream of it started to act on what it said.
The defense worked in Parauapebas. Galileu did what a well-built AI tool in an adversarial setting is supposed to do: it processed the file, noticed that some of the text was addressed to it rather than to the court, and raised the alarm. The labor judge sanctioned the lawyers. The AI did not produce a wrong ruling, the judge did not get fooled, and the system caught the attempt.
The lawyers' mistake was treating the AI as the audience. Any text an AI tool reads is an attack surface by default. Hidden text is just the simplest version of it. "It is not at all something out of a movie, but rather something to be expected," Marcelo Quaglia told El País. "It is not science fiction" and has "already been foreseen by the law," Abel Gende, a Spanish lawyer, told the same outlet.
The pattern matters because courts are scaling AI use faster than they are defending it. In January 2026, Spain's General Council of the Judiciary (CGPJ) issued an order that explicitly permits judges to use AI for the analysis, classification, and structuring of case documents. That is the surface the Parauapebas lawyers tried to exploit. The order, tracked by White & Case's AI Watch, is one of the few national rules anywhere that names the use case and the limits at the same time.
Brazil has now produced the first public sanction for abusing a court AI. Spain has now published a national rulebook for using one. The two countries are responding to the same surface from opposite ends: one as enforcer, one as regulator. Neither answer alone closes the gap. Together, they sketch what a serious institutional response looks like: a tool that can detect the trick, a judge willing to punish it, and a written rule that says where the AI is allowed to be used and where it is not.
The watch item is the next category, not the next case. If prompt injection works on a court summarizer, it works on any AI tool that reads text on behalf of a human decision: a credit model that ingests applications, a benefits portal that reads appeals, a compliance tool that scans whistleblower reports. The Brazilian lawyers tried the simplest version. The next attempts will be harder to spot, and not every system will catch them in real time. Spain's January order treats the surface as a known risk. The rest of the world has not.