watts.it.com // daily AI micro-learning
Obiter 2026·09·04 · 12 min · opinion

Executed

Obiter is the editor’s opinion column. The content is the opinion of the editor only.

// listen · read by the editor

Read by the editor in his own voice, over an AI-composed score. AI is used throughout this site deliberately and in the open.

There is a phrase that sits at the end of contracts in Australia. Not all of them, but enough for me to confidently state that you have seen it before. It reads something like: “Executed as an agreement pursuant to section 127(1) of the Corporations Act 2001 (Cth).” It is an important phrase. It is everywhere. But outside of the legal profession, it is uncommon for a person to know what it means. The phrase has the function of giving the rest of the words in the contract binding operational effect. If an ostensibly authorised person puts their signature beneath that phrase, all manner of things can be made to happen: property can change hands; corporations can be bound; promises are made. We place a term of art upon the moment that the language in a contract stops being words on a page and takes on the role of an actor. The term is execution.

If you are reading this essay, then I would guess that at some point over the past month, you will have seen an article somewhere else referencing a publication by a security researcher named Håkon Måløy. In July, he published a description of Microsoft Copilot inside Word obeying instructions that were invisible to the human operator. The mechanism is strikingly simple: since Copilot strips formatting before text reaches the model, white-on-white text that is invisible to the user is completely readable for Copilot. In the demonstration by Måløy, white text instructed Copilot to not only alter the content of the document that it was working in (specifically: halving financial figures in a quarterly report), but to also propagate the attack by hiding further instructions in the new document. To state the obvious: this is known as prompt injection.

Måløy’s demonstration was a proof of concept, which was disclosed responsibly by him. I published a practical module about it on this site a few weeks ago (what to check, how to stay vigilant, and why you should review the content before it ships), but this essay is not a rehash of that module. This essay is instead about what pulls at something deeper inside me than the umbrella threat of prompt injections. It’s the fact that Måløy’s demonstration shows that text itself has become an active trigger for the execution of actions. It is no longer only the parties that can execute a contract. The contract can execute.

At first blush, prompt injection is an uncomfortable but familiar risk. Something you can’t see may be able to instruct an AI agent to do something that you don’t control. But let it sit with you for just a bit longer. Setting aside code and the macro viruses that borrowed its tricks, for almost all of human history, text has been an inert carrier of information. When a document lands in my inbox, it is usually drafted, either entirely or in part, by someone who is neither me nor the client I represent. It has never been dangerous because the text could not actually do anything. It could persuade me, or it could inform me, but I was the referee of its meaning. The large language models we now integrate into our workflows have merged the separation of data and code on which modern computer security rests, and when data and control run through the same channel, all text, trusted or not, can run with full privileges. I don’t think of this as a new class of bug. Instead, I think it is a change to what writing actually is. A paragraph can be a program if an AI assistant reads it. We have heard for years about the risks of rogue AI agents, when your first encounter with a malicious agentic action may in fact be a helpful and compliant agent that encounters the wrong piece of prose — given to it, in all likelihood, by you.

Philosopher J. L. Austin gave a name to words that “act”. He called them performatives, and they work only under certain conditions. “I give and bequeath my guitar collection to my wife,” for example. The conditions under which they work require the right person, convention, and circumstances. If a wedding is officiated by the town’s farmer instead of the celebrant, then no marriage has occurred, no matter how confidently or sincerely the words were spoken. This is true of wills, marriages, wagers, deeds, powers of attorney, and more. When we search for words that can act, and that have consequences, we find ourselves squarely in the domain of the law. The formalities, such as the signatures, the witnesses, and the execution representations, are a doctrine of execution for language. They are the rules for deciding which words are allowed to act, when they are allowed to act, and on whose authority. And with the involvement of agentic participation, those rules are being disrupted.

Text addressed to non-human actors is already commonplace. Attackers are not the only ones writing it. One study from Duke University found that approximately 1% of resumes that were examined by the researchers included hidden instructions. Most of the hidden text was fabricated credentials, not commands. They were intended to beat the AI screening tool; (presumably) not to mislead the human reviewer. Even more controversially, earlier this year, a Brazilian court became the first to punish lawyers who had hidden in their petition to the court an instruction addressed to the court’s AI review tools that the AI reviewer should “contest the petition only superficially” and not to “challenge the documents.”

Although it is tempting to mark all of this as a risk to be held as a security vulnerability, I think that it is worthwhile resisting that temptation. Text aimed at influencing parties indirectly is not inherently a security flaw, or even unusual in pre-AI transactions. For example, if I am negotiating a deal and I believe that in order to move an opposing lawyer, I will require that that lawyer receive instructions from a counterparty CIO, the communication that I draft may be aimed at addressing the concerns of the CIO more than the lawyer. I may do this by addressing practical functional matters instead of legal prose, and providing comfort relating to business risk instead of attempting to provide a new contractual clause. Not only is this choice not a wrong one in a moral sense, it is not remotely new as a transaction strategy. Advocacy has always involved addressing the decision-maker through the available machinery, including the judge through the submissions, the board through the advisory documents, or the CIO through the procurement manager. If the AI tool of my counterparty now reads my documents, writing in a way that I expect to be understood by the machine is competent drafting, not a covert and malicious trick.

The difference in the Brazilian court petition example is that it was a concealed command. Advocacy is a beast of a different kind. Advocacy enables the argument to work in plain sight, whereas a concealed command speaks to the AI tool as if it were the operator of that tool, typically directing it against the interests of the actual operators. This is not equivalent to competent negotiation that accounts for the involvement of a counterparty agent. It is blatant and offensive corruption of the process that humans must follow. The more correct equivalent is to covertly include an additional clause in a long contract whose terms had been agreed before the inclusion. You may persuade the other side’s advisor or decision maker, but not suborn them.

The line is reasonably easy to draw. The questions relate to whether the text is an argument or an instruction; whether it is overt or concealed; and the authority that it claims to possess. The engineering concern is that the line cannot currently be policed effectively, because enforcement relies on the intelligence and judgement of the models themselves. The words, by their nature, cannot carry the authority to execute, which means that authority must be carried by something else.

So where, if not in the words themselves, can the authority of words exist? I think that we have answered this before, several hundred years ago. In medieval England, writing was treated as a craft that was hired. Almost nothing was authenticated by handwriting, and the force of a document did not come from handwriting, but from the ceremony imbued within it: a wax seal; a witness list; performative language such as “To all who shall see or hear.” And they would be heard, because charters were read aloud. By the year 1300 the seal had spread throughout society, and an entire profession grew around document drafting. Scriveners were London’s professional penmen, who included elaborate flourishes called paraphs in their work to prevent counterfeiting, and were regulated by the Guildhall from 1373. There was a name attached to written instruments, marks to protect against fraud and forgery, and witnesses to the act. The purpose of the ceremony was to answer the question: “Whose authority stands behind this document?”

When the population became literate, the procedure gradually died, and the signature displaced the seal because a literate population required less ceremony. In 1677 the Statute of Frauds required that writing be “signed by the partie to be charged”. In Australia, the company seal was made optional only in 1998 — during my lifetime. On 23 February 2022, execution of a deed was made possible with no witness or delivery, and no “paper, parchment or vellum”. Our decision to relax these execution formalities was almost unbearably well-timed, because on 30 November of that same year (2022), ChatGPT running on GPT-3.5 was officially launched. Just as the Australian parliament retired the medieval trust apparatus, the age of the artificial second reader began.

Before returning to the present day, I want to make some predictions. I think that within two years, text addressed to AI will be standard in transactional practice. Whether it is labelled as such or not, precedents will include content that considers the interpretive behaviour of AI readers. Boilerplate defensive clauses will be included in some contracts declaring that nothing in the document constitutes an instruction to an automated system or artificial intelligence. As far as I can tell, these precedents do not yet exist as accepted standard. If you are a lawyer who is considering how best to draft them, you are early. Within three years, a law society or regulatory body will deliver guidance separating legitimate machine-aware drafting from concealed instructions (essentially the same line that I have drawn), but by the time it happens, the profession will barely notice. And finally, a court will eventually find the other side of the line drawn in Brazil, and deliver the first ruling on what deliberate machine-directed text is acceptable in a legal document.

And now the engineering effort to manage text that can act is underway. Cryptographic signing of instructions, so that AI assistants can recognise and comply only with directives from authorised sources. We now have provenance standards extending from images to plain text so that written work can prove where its contents came from. You don’t have to view this future through the lens of the medieval past as I am choosing to for this essay, but I think that the analogy is fitting. We are rebuilding the witness list, the paraph, and the execution ceremony using mathematics and code. Of course, formality is friction, and yes, it may be stripped away and reinvented in cycles, until a new kind of fraud makes it necessary again. But it exposes a humbling truth: the ceremony was not a decorative part of old writing; it was — if you’ll forgive the AI-ism — a load-bearing feature.

I have been told, with painful regularity, that my profession is about to be automated. As I look honestly at that forecast, I admit that it isn’t wrong about much of the reading and drafting that lawyers do. But law is also the only profession that has ever run an authority infrastructure for executable natural language. It counts for something to know why the formalities exist, why they are worth the costs, and what happens when pieces are removed. That knowledge is now needed by the people designing the next phase of the infrastructure.

For hundreds of years, the law has kept the word for text that satisfies the requirements to act. Where the words have been verified, and where the formalities have been met. The engineers are reaching now for that same word, which has been printed on the last page for my whole career.

Executed.

written-by: Luke Topfer <editor> · 2026·09·04
Sources
  • Context Collapse Part 3 — AI Worming through Word, Håkon Måløy
  • Hidden instructions in the document — watts.it.com (the module this essay refers to)
  • How to Do Things with Words — J. L. Austin, Oxford University Press (the 1955 William James Lectures)
  • Duke University / hireEZ study of ~200,000 résumés — approximately 1% carried hidden instructions
  • 3rd Labour Court of Parauapebas, Brazil — lawyers sanctioned for concealed instructions addressed to the court's AI review tools
  • Corporations Act 2001 (Cth), s 127 — Compilation No. 147
  • Company Law Review Act 1998 (Cth) — s 123, the common seal made optional
  • Corporations Amendment (Meetings and Documents) Act 2022 (Cth) — deeds without witnessing, delivery, or paper, parchment or vellum
  • Statute of Frauds 1677 (Eng), s 4 — "in Writeing and signed by the partie to be charged"
  • The Signature in Law — Stephen Mason, University of London Press (open access), ch 4