Two Thousand Fake Cases
Co-Founder & CEO of CLRT
If your firm files documents, somebody in it believes this problem has been solved. The reasoning runs like this: the fake-citation cases were a 2023 story about a chatbot, the firm now uses a professional research product, and a policy went round. That belief decides whether anyone reads the authorities in the next brief before it leaves the building. The evidence says the belief is wrong on every count. The number of court decisions that record fabricated or misrepresented authority has already outrun the whole of 2025 by a third with a quarter of the year to go, lawyers rather than litigants in person account for two in five of them, the tools named in the orders include the professional products, and in a single month the consequences ran from a fine to a contempt finding to a career. What follows is the count, the acceleration, and the ladder.
Start with the count. Damien Charlotin, an academic, keeps a public database of court decisions in which a party or a judge relied on material that generative AI made up. Read on 14 September 2026, it holds 2,041 decisions. Four numbers tell the story: 16 in 2023, 61 in 2024, 852 in 2025 and 1,112 in 2026 so far. Read monthly from the database's own file, January 2025 produced 16 decisions, December 2025 154, March 2026 a peak of 179, and every full month of 2026 has landed between 107 and 179. The curve has not bent down. Two cautions belong beside it. The database is curated by one person and depends on decisions being indexed, so recent months will rise. And it holds only the cases a court wrote about: a floor, not a census.
The comfortable reading is that this is a litigant-in-person phenomenon. The database's own labels say otherwise. About 1,170 of the decisions involve a self-represented party and about 810 involve a lawyer, and on our reading of the file the lawyer count for 2026 to date is 431 against 353 for the whole of 2025. The share has held near two in five; the volume is up by more than a fifth, with three and a half months of 2026 still to be indexed. Nor is it only an American story. The United States accounts for 1,396 decisions, but Canada has 217, Australia 110, the United Kingdom 69, India 15, and the Gulf has arrived: two decisions in the United Arab Emirates and one in Qatar, where the QFC court found contempt in November 2025 over a cited case that did not exist and warned that the next lawyer would be named, from courts that publish in English and apply the duty the English Divisional Court set out in 2025.
Then the tool defence. In the 225 decisions that identify the product, ChatGPT appears 135 times, but Claude 18, Gemini 16, Westlaw or CoCounsel 16 and LexisNexis 11. On 9 September 2026 a federal judge in Utah sanctioned counsel whose brief had been drafted with four tools, ClearBrief, Claude, ChatGPT and Gemini, and cited a case that does not exist; the order says Rule 11 requires attorneys to read the authorities they cite. Four tools did not catch what one reading would have, and the failure rates explain why. Stanford's 2024 audit found the paid research tools from LexisNexis and Thomson Reuters hallucinated between 17 and 33 percent of the time. An August 2026 audit of eight retrieval-grounded legal systems found the best still failed in under a tenth of answers, the worst in nearly half. And when three frontier models were asked for 300 clinical references in a peer-reviewed test, 28.3 percent were wholly fabricated; the authors noted that fabricated references can appear complete and credible.
Now the ladder, and the month that finished it. On 4 August a New York court imposed the $10,000 statutory maximum on a lawyer who had cited 23 fictitious decisions and misrepresented 83 real ones across nineteen submissions, referred him for discipline, and recorded that when opposing counsel objected he asked the same AI platform, which assured him they were valid. On 21 August the Supreme Court of New Mexico heard a criminal appellate lawyer whose brief carried testimony from four witnesses who do not exist; it found him in direct contempt, struck all briefing, barred him pending discipline and ordered $5,000 paid. On 25 August the Solicitors Disciplinary Tribunal struck a registered foreign lawyer off in its first AI case: a lawyer is always responsible for the accuracy of his or her output. On 2 September the Supreme Court of India vacated a customs penalty of Rs 425.28 crore because the officer's order rested on non-existent case law. The Gulf had priced it the previous December: AED 282,508 in wasted costs against a law firm in the ADGM courts, 18 December 2025.
The second-order point is where the duty landed. The English Divisional Court, in June 2025, wrote that practical and effective measures must now be taken by those with leadership responsibilities, naming heads of chambers and managing partners, and that the court will inquire whether they were fulfilled. The Tribunal's strike-off in August flowed from that judgment. And the courts have been precise about what they want. A law firm's tracker of American standing orders and local rules, captured in July 2026, listed 793 entries: 161 require disclosure or verification and 5 prohibit AI. The bench chose certification over prohibition by roughly thirty to one. That ratio is the design brief: the court assumes the tool will be used and holds the firm to proof that a human checked. A memo cannot produce that proof. A verification system can, and deciding what it checks, for which documents, against which sources, is the judgment the memo skipped.
The courts did not ban the tool. They priced the failure to check it, and addressed the bill to the managing partner.
A deeper dive
The mechanism deserves to be understood precisely, because it is the reason reading harder does not work. A fabricated authority is not a typo. It is a well-formed citation, in the right reporter, with a plausible year, a party name that sounds like a real dispute and a holding that says exactly what the brief needs it to say. That is not a defect of the model; it is the behaviour being optimised for, fluent completion of a legal pattern. Nothing on the page distinguishes the real case from the invented one, so the reviewer's eye, which is trained to catch things that look wrong, passes over the thing that looks right. Retrieval-grounded tools narrow the failure without removing it: the 2026 audit found the best systems failing on up to one in ten answers, with false-premise questions producing the highest rates, so a confidently wrong instruction from the lawyer yields a confidently wrong authority from the tool. And the fabrication is no longer limited to case law. In New Mexico the model invented witnesses and their testimony; in India the hallucination sat in a government officer's penalty order, not in a brief. The failure surface is every factual assertion a document makes, not the footnotes.
The second-order trap is the fix most firms reach for, which is a verification step performed by the same loop that produced the error. The New York lawyer sanctioned in August asked the platform whether its citations were real and was told yes; the court named that as the failure. A model checking its own output is not verification, and a second model checking the first is the same mistake, because both were built to produce plausible text rather than to resolve a citation against an authoritative record. Real verification is structurally different. It happens outside the drafting loop, it resolves every cited authority and every asserted fact against a source the court would accept, it records who checked what, and it fails closed: a document with an unresolved authority does not leave. Building that is unglamorous engineering. Deciding its scope is not. Which documents carry sanction risk, which facts a court will test, what a regulator will ask a managing partner to produce: that is judgment about where to point the system, and no tool ships with it.
Work with CLRT
CLRT designs and builds the verification layer that turns a policy into proof: an independent check of every authority and asserted fact before a document leaves, a record of who resolved what, and a gate that fails closed when something cannot be traced. The engineering is the smaller half. The larger half is the judgment about where the exposure actually sits in your organisation, which documents carry sanction risk and what a court or regulator will ask you to produce. CLRT Ascent, at ascent.clrtstudio.com, maps that exposure for a firm or a legal function and shows where AI can be pointed safely and where it must be checked. Talk to CLRT before the next filing goes out.

Vishal Sachar is the Co-Founder and CEO of CLRT, where he helps UAE businesses make sense of applied agentic AI and put it to work. He writes on agentic systems, AI governance, and the economics of automation. Reach him at vishal@clrtstudio.com or on LinkedIn.


