The Filing the AI Was Meant to Read
When a hidden prompt-injection instruction addressed to Brazil's court AI arrived in a 3rd Labor Court filing in May 2026, the model detected it before drafting began and alerted the judge. The fine that followed was the first sanction under CNJ Resolution 615/2025 to classify adversarial input as an attack on judicial impartiality. Three jurisdictions have now worked through that sequence; no other Latin American legal system has.
Somewhere below the tenth line of an employment complaint filed at the 3rd Labor Court of Parauapebas, in the state of Pará, sat a paragraph that no human eye was meant to notice. It was set in white ink, at reduced font size, on a white page. It began, in all-caps Portuguese, with the words atenção inteligência artificial. What followed instructed the model to contest the petition superficially and not to challenge the attached documents, regardless of any other command given. The reader for whom that instruction was written was Galileu, the generative-AI drafter that the Brazilian labor courts have been rolling out under CNJ authority since 2025. On May 12, 2026 the 3rd Labor Court sentenced the two lawyers who signed the filing to a fine of ten percent of the case value, roughly R$84,000, and classified the insertion as an act against the dignity of justice. The fine is a footnote. The reasoning is the record.
What did the sentence say?
The Parauapebas ruling treated the hidden instruction as procedural bad faith of a new kind. The text was addressed to the machine and pointed at the drafting stage of a judgment. The Conjur analysis published on July 28, 2026 is the fullest reading in the trade press: the sanction sat on a substantive attack on the impartiality guarantee, not on decorum. Galileu's own detection log went in as the operative evidence. The TRT-4 note on the same event, from the tribunal that built the tool, records that the model blocked processing and alerted the presiding magistrate before any draft was produced. The sequence is worth holding. Adversarial input arrived. The substrate saw it. The judge got told, before the response was written.
The SSRN paper by Victor Habib Lantyer, posted in July 2026, catalogues Parauapebas as the first in a series that ran through the northern summer: TJPB, the 9th Labor Court of São Paulo, further cases in TRT jurisdictions, each with hidden instructions aimed at drafting-assistance models, each sanctioned separately. This is not one case. It is the shape of a period.
What was the rule already in force?
CNJ Resolution 615/2025, published on March 14, 2025 and in effect since July 14 of that year, is the piece of Brazilian legal-AI regulation the trade press underweights. It is the document that made the Parauapebas sanction land where it did. The resolution reads as an architectural specification more than a policy statement. AI is an auxiliary tool. Human supervision is periodic and effective. No decision is issued by machine alone. Risk classifications apply per system. Impact assessments are mandatory. A National Committee for AI in the Judiciary (CNIAJ), seated with the CNJ, the OAB, the public prosecutors, the public defenders and civil society, coordinates the register.
The TRF3 English legal review puts the load-bearing sentence plainly: the resolution establishes rules for the development, governance, auditing, monitoring and responsible use of AI solutions within the Brazilian Judiciary, on a risk-classification frame that predates the wave of adversarial filings by more than a year. Parauapebas did not reason from silence. It reasoned from a rule already there.
What did the OAB write?
Recomendação 001/2024, approved by the Federal Council of the OAB in November 2024, addresses the other side of the transaction. It is written for the lawyer, not for the court. Four sections: applicable legislation, confidentiality, ethical practice, communication with the client. Item 3.7 is the one that carries in litigation. The lawyer using AI must verify the information provided to the court, and must not present material the model produced without her own review. In April 2026, the São Paulo section's Court of Ethics and Discipline extended that reading to firm-level supervision. Partners must review associate output. Non-lawyer assistants using AI are supervised in accordance with the same standards.
The OAB reads the substrate from above. The CNJ reads it from below. Both arrived at effective human supervision as the load-bearing requirement, from different professional obligations, on different institutional theories of what the model is doing. Parauapebas rested on that double convergence. The judgment did not read as a novelty. It applied two rules that already existed, meeting an attack neither rule had specifically named.
Where does the OAB's authority end?
On September 3, 2026, the 3rd Federal Court of Paraíba overturned an OAB-PB precautionary suspension that had been issued in July against a lawyer under investigation for prompt-injection filings against MinutaIA, the state court's own AI drafter. The federal ruling did not deny the underlying conduct. It said the OAB does not have legal competence to determine suspension of professional practice directly. That authority belongs to the Court of Ethics and Discipline, with prior hearing of the lawyer. The federal court restored the practice license and folded the substantive case back into the OAB's disciplinary process, where it was already headed.
The reversal is a check on procedural overreach, not a defense of the underlying filing. What it settled is which body imposes the professional consequence, not whether the professional consequence is available. It does not touch the CNJ Resolution 615 side of the register at all.
What does the region look like from outside Brazil?
Chile has a draft AI regulation before its Chamber of Deputies, still in the Committee on the Future stage, no binding sectoral rule yet. Mexico ran through its ordinary Senate session in April 2026 without a general AI framework crossing the floor. Colombia's Consejo Superior de la Judicatura and the Superintendencia de Industria y Comercio are working on guidelines that lean on the Constitutional Court's T-323/2024 judgment: AI as an auxiliary tool, subject to transparency, accountability and privacy, no autonomous adjudication. The reasoning is convergent. The operational status is not.
| Jurisdiction | Instrument | Status | Adversarial-input covered |
|---|---|---|---|
| Brazil | CNJ Res. 615/2025 + OAB Rec. 001/2024 | In force | De facto, via case law |
| Chile | AI Systems Bill | Committee stage | No |
| Colombia | Draft AI bill + T-323/2024 | Judicial guidance | No |
| Mexico | Sectoral rules | Draft / partial | No |
Brazil arrived at operational maturity first, not by policy design but by exposure. The Galileu system entered chambers before the adversarial pattern arrived. When the pattern showed up, the tool saw it, and the courts already had a rule to reason from. Chile's tribunals will get there. Mexico's will get there. The gap is that no other Latin American system has yet been forced to detect a specific attack under a specific regulation, on a specific case, and hand a specific fine down. Brazil has done that work three times inside a five-month window, in three different jurisdictions.
Is there a disconfirming voice?
The Federal Court of Paraíba's own reversal is the disconfirming voice worth engaging with on the merits. It says, correctly, that a bar association cannot function as its own tribunal on a professional-practice question. It is a due-process correction to the OAB's speed. Alongside it sits a legitimate market critique, developed in the Ámbito Jurídico analysis of the Colombian debate: too-fast bar-side enforcement risks pushing legitimate professional discretion into a chilling posture, and that cost falls hardest on smaller firms without in-house counsel.
On the merits, the correction stands. Where I would push back is the implication that the Brazilian system is broken. The system worked in the order a healthy one would. The substrate detected the attack. The trial court sanctioned it. The professional-responsibility body moved to protect the courtroom. The federal court corrected the procedural overreach without disturbing the substantive finding. That is a governance chain doing its job across four different tribunals in five months. It is not policy theatre.
The stake
My stake, on legal-AI product design in this region. Every legal-AI system shipped to a Latin American court, bar association, or law firm this quarter should treat input-side adversarial handling as a first-class product property, not a compliance ticket to be closed later. Three specifics.
First, ingestion sanitisation belongs before the drafting model, not after. Galileu detected the white-on-white text because the pipeline around it was looking for it. That was an engineering decision by the TRT-4 team, not a regulatory one. Any legal-AI product operating inside a Brazilian, Chilean or Colombian court should ship with a documented ingestion layer that scans for hidden-format instructions, character-level anomalies, and prompt-shaped payloads, and logs every detection to a channel a magistrate or an ethics reviewer can pull.
Second, adversarial-input testing belongs inside the impact-assessment obligation that Resolution 615 already requires. The template needs concrete red-team evidence in place of the abstract fairness testing that dominates most impact-assessment paperwork. A test set of white-on-white filings, prompt-payload paragraphs, character-fragmentation attacks, and citation-poisoning attempts. The evidence should be published in a form the CNIAJ or its regional equivalents can audit.
Third, the OAB Recomendação 001 will need to name this class of controls in its next revision. A partner running an associate's draft through a review model needs a substrate that refuses to obey any instruction hidden inside the document under review. The professional-responsibility layer and the courtroom layer face the same adversarial-input problem, and the sooner the two revisions of the standards recognise it, the fewer sanction sentences the trade press will need to catalogue next quarter.
Brazil got here on operational exposure. Its neighbors still have the option of getting here by design.
Tarry Singh is the founder and CEO of Real AI, an enterprise AI advisory and deployment firm working with global enterprises on production agent systems, model risk, and AI sovereignty strategy. He also leads Earthscan for Energy AI startup, and is a founding contributor to the EU-funded HCAIM and PANORAIMA programmes for responsible AI education across European universities. He writes at tarrysingh.com.