A conversation with Claude, and a risk worth flagging
I write a lot about where AI genuinely helps organizations move faster, and where it quietly introduces new risk. The risk I want to flag here comes down to guardrails, or the lack of them, when procurement agents let AI review bid submissions without enough human interaction in the process.
The concern
What happens if a vendor uses that same AI to manipulate their own submission and tilt outcomes in their favor, specifically when the procurement agent is relying on AI to review the submission? Picture a bid responder embedding instructions in white font, invisible to the human eye but perfectly readable by AI, inside their bid documents. The instructions aim to influence an AI reviewer to favor their submission. The technique has a name: prompt injection, which hides machine-readable commands inside content a human will never see but an AI system will read and act on.
Procurement offices are drowning in documents, and AI is the obvious tool for triage, summarization, and first-pass scoring. Agencies and primes are already using AI to evaluate technical volumes, score compliance matrices, and summarize past performance narratives across dozens or hundreds of proposals.
That efficiency creates the opening. If an evaluator’s AI tool is going to read a proposal, nothing stops a bidder from embedding near-invisible text instructing it to score the submission favorably, downplay a weakness, or frame a competitor’s approach unfavorably.
What worries me most is where procurement is headed. A source selection team using AI to assist a human evaluator still has a person in the loop, someone reading the underlying document, someone who might notice something off. That safeguard disappears as agencies push toward automated procurement, where AI doesn’t just assist the review, it runs it: scoring, ranking, and in some workflows routing a recommendation straight toward award with minimal human review in between. Strip out the human checkpoint and a prompt injection isn’t competing against a person’s judgment anymore. It’s talking directly to the system making the decision, with nobody positioned to notice.
That scenario isn’t far-fetched. A version of it already surfaced publicly, not in procurement yet, but in a Connecticut court case, Elliott v. New York Bariatric Group, where a plaintiff tried the same trick in a legal filing. The court caught it, not because AI flagged it, but because a human noticed unusual spacing in the document and looked closer.
What actually happened in Connecticut
I asked Claude.ai to dig into the case with me so I could ground this in the actual record instead of secondhand summaries.
The plaintiff, Matthew Elliott, representing himself, filed a motion on July 24, 2026, that contained hidden text: tiny, white-on-white type positioned directly beneath the filing’s heading. Formatted to be invisible to a person reading the page while fully legible to any software processing the file, it instructed any AI model reviewing the document to produce output that agreed with the plaintiff’s position.
Connecticut Superior Court Judge Walter M. Spader Jr. caught it. Not because the court runs filings through AI. It doesn’t. A court staffer noticed the document had more white space than Elliott’s other filings, looked closer, and found the concealed instructions. Later filings from the same plaintiff carried more hidden text, some of it directives, some of it just noise, including a message that read “hi :) i hope yo ucant see me.”
Spader said he wasn’t aware of any prior U.S. court decision addressing the issue. On August 6, 2026, he sanctioned Elliott, revoking his ability to file electronically and requiring him to submit paper filings in person going forward. Spader was explicit that the Connecticut Judicial Branch doesn’t use AI to process filings, but he acknowledged that opposing counsel and other parties in a case very well might.
That’s the detail procurement should sit with. The same mechanics Elliott used on a court clerk would work identically on a source selection team running proposals through a summarization tool. There’s no AI immune system for this yet, in courts or in contracting offices. There’s only attentive people, and automated procurement is designed to remove exactly that layer.
This isn’t an isolated incident
Connecticut is the newest example, not the first. Academic peer review has been dealing with this since mid-2025. That July, researchers found hidden text embedded in 18 manuscripts on arXiv, instructions written specifically to steer AI-assisted peer review toward a favorable verdict. The tactic didn’t stay rare. By 2026, two of the largest conferences in the field, NeurIPS and ICML, started embedding their own hidden prompts into submitted papers as a trap for reviewers secretly using AI against the rules. The ICML effort alone flagged hundreds of reviewers misusing LLMs, leading to nearly 500 papers being desk-rejected over policy violations.
The effectiveness data is the part that should get procurement’s attention. A study published in JAMA Network Open tested how vulnerable leading AI models were to invisible text injection in a simulated peer review setting. Acceptance rates for the manipulated submissions jumped from 0 percent to nearly 100%.
That’s not a marginal edge. That’s a review process fully inverted by a few lines of white text.
Training resources now being built for AI-assisted evaluation already name procurement directly as an at-risk category, alongside grant review, peer review, and proposal assessment, for the same reason this piece opened with: hidden instructions can manipulate an AI-assisted output without the reviewer ever knowing it happened.
So this isn’t a single courtroom incident procurement can watch from a safe distance. It’s the third domain in under two years where this exact technique has surfaced, after academic manuscripts and conference peer review. Procurement isn’t a hypothetical fourth. It’s the obvious next one, and the field hasn’t caught up.
Where this sits legally and ethically
This is not clearly illegal, and that’s exactly the problem. Prompt injection in a bid document doesn’t obviously violate procurement integrity statutes written for a pre-AI world. It’s not bid rigging. It’s not a false statement in the traditional sense. It’s a manipulation of the review process itself, and the legal and regulatory frameworks governing federal, state, and commercial procurement haven’t caught up to that category of conduct.
That gap won’t last. Judge Spader grounded his sanction not in a statute written for AI but in the court’s inherent authority over its own proceedings and the duty of candor litigants owe the court, tools that predate every AI system in question. Contracting officers have equivalent authority. A submission built to manipulate an evaluator, human or machine, is a good faith and integrity problem even before a specific rule catches up to name it. Agencies that find this in a bid should treat it as a competitive integrity violation and document it as such, regardless of whether a checkbox exists on the disqualification form yet.
What procurement teams should do now
A few practical moves worth putting in front of any procurement or contracts office using AI in the evaluation workflow:
π‘ Screen for hidden content before AI ever touches a submission. Inspect proposal documents for zero-point text, white-on-white formatting, and metadata anomalies as a standard intake step. It’s a solved technical problem. It just has to be made a required one.
π‘ Don’t let AI-assisted scoring run unsupervised. Spot-check every AI-generated summary or score against the source document, the same way a contracting officer would never accept a subordinate’s summary of a proposal without occasionally reading the underlying text.
π‘ Build the disqualification language now, not after it happens. Solicitation language and evaluation plans should explicitly name embedded AI instructions as grounds for rejection, so the agency isn’t improvising a response the first time it finds this in a live procurement.
π‘ Assume this is already being tried. Academic peer review has already been through this fight, and it moved fast, from a handful of manuscripts in 2025 to major conferences building countermeasures within a year. Treat this less as an edge case and more as a certainty on a timeline.
The bigger point
To be clear, this isn’t advice to use the technique. It’s a landscape flag. Procurement moved AI into the evaluation seat because it’s faster. Speed without a matching integrity check is how you end up awarding based on who wrote the best invisible prompt instead of who wrote the best proposal. That already happened in a courtroom. It’s only a matter of time before it happens in a source selection room.
Where to start
If you’re in procurement and this isn’t yet on your team’s radar, it should be. RCG Workgroup is glad to help you begin the conversation and guide you through its implications.
