Summary. In 2023 a New York lawyer filed a brief containing six cases that did not exist, produced by a chatbot he had asked to find supporting authority and then asked whether the cases were real. The resulting sanctions opinion became the most widely read order in American legal practice that year, and it did not stop the problem. Courts across the country have since sanctioned lawyers, referred them to disciplinary authorities, struck filings, and denied relief because the supporting authority was fabricated. This article explains what happened in the leading cases, why large language models produce citations that look correct and are not, and what the governing rules require: Rule 11 and its safe harbor, § 1927, inherent authority, and the ethics rules on competence, candor, confidentiality, supervision, and fees. It then turns to practice: the standing orders courts have adopted, what a defensible verification workflow looks like, how retrieval-based tools differ from open-ended chatbots, what to do if a fabricated citation has already been filed, and how to supervise the people using these tools. It closes with a firm policy outline, a worked example, an FAQ, and related reading.


The most quoted sentence in this area comes from Judge P. Kevin Castel's opinion in the case everyone knows about: "Many harms flow from the submission of fake opinions."

He then listed them, and the list is worth reading because it explains why courts have reacted the way they have. The opposing party wastes time and money exposing the deception. The court's time is consumed. The client may be harmed by a wasted opportunity to make real arguments. The judicial system suffers reputational harm when a fake opinion is attributed to a real judge. And future litigants may cite the fake opinion, propagating the error.

That opinion issued in June 2023. In the years since, the number of documented incidents has grown into the hundreds, across federal and state courts, involving solo practitioners, large firms, government lawyers, expert witnesses, and pro se litigants. It has stopped being a novelty and started being a category of malpractice.

It is also entirely preventable, by a step every lawyer was already supposed to be taking.

The short answer

  • Nothing in the rules changed. Fed. R. Civ. P. 11(b) has always required that legal contentions be "warranted by existing law or by a nonfrivolous argument" for changing it, and has always imposed a duty of reasonable inquiry. Citing a case you did not read violates that duty whether the case came from a chatbot, a form file, or a memory.
  • The tool is not the violation. Filing without verification is.
  • Sanctions available: Rule 11 (monetary and nonmonetary), 28 U.S.C. § 1927 (excess costs against counsel who multiply proceedings unreasonably and vexatiously), the court's inherent authority (Chambers v. NASCO, Inc., 501 U.S. 32 (1991)), striking the filing, denying the motion, disciplinary referral, and fee awards.
  • Ethics rules implicated: competence (Model Rule 1.1 and comment 8 on technological competence), candor to the tribunal (3.3), communication (1.4), fees (1.5), confidentiality (1.6), and supervision of lawyers and nonlawyers (5.1 and 5.3). ABA Formal Opinion 512 (2024) addresses generative AI directly.
  • Many courts have standing orders requiring disclosure of AI use, certification of human verification, or both. Check the judge's standing order before every filing, in every court.
  • The fix is a verification step, not a prohibition on the technology.

Part I: What actually happened in the leading cases

The origin case

In Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y. June 22, 2023), counsel opposing a motion to dismiss submitted a brief citing six nonexistent decisions. When opposing counsel and the court could not locate them, counsel submitted excerpts of the fabricated opinions, also generated by the chatbot.

The details that produced sanctions were not the use of the tool. They were:

  • No verification. Counsel did not attempt to locate the cases in any database.
  • The confirmation question. Counsel asked the chatbot whether the cases were real, and it said yes. The court treated reliance on that as unreasonable.
  • The continued defense. After being alerted, counsel did not immediately investigate and withdraw; the fabricated excerpts were submitted after questions had been raised.

The court imposed a $5,000 penalty jointly on the two lawyers and their firm, and required them to notify their client and each judge falsely identified as the author of a fabricated opinion. Judge Castel was explicit that "there is nothing inherently improper about using a reliable artificial intelligence tool for assistance."

The Second Circuit weighs in

In Park v. Kim, 91 F.4th 610 (2d Cir. 2024), counsel's reply brief cited a nonexistent decision. When the court ordered production of the case, counsel admitted using a chatbot to conduct the research and not verifying the result. The Second Circuit referred the attorney to its Grievance Panel, holding that the conduct "falls well below the basic obligations of counsel" and noting that Rule 11 requires an attorney to "read and thereby confirm the existence and validity of the legal authorities on which she relies."

The significance of Park is that a court of appeals treated the failure as a matter for discipline rather than merely a monetary sanction.

The pattern since

Documented incidents now span a wide range of contexts, and several patterns recur:

  • Escalating sanctions for concealment. Courts have been considerably harsher where counsel denied using AI, blamed staff without investigating, or failed to withdraw promptly after the problem surfaced. The sanction is usually proportionate to the response, not to the original error.
  • Fabricated quotations from real cases, which are harder to catch than fabricated case names because the citation resolves.
  • Fabricated authority in expert declarations, which raises Rule 702 and Rule 26 problems in addition to Rule 11. See Expert Witnesses After the 2023 Amendment to Rule 702.
  • Sanctions against large firms, not just solo practitioners, typically where a junior lawyer's draft was incorporated without verification.
  • Consequences beyond sanctions: motions denied, briefs struck, fee awards to the opposing party, referrals to state bars, and clients terminating representations.
  • Pro se litigants, where courts have generally been more forgiving on sanctions but have still denied relief and, in some cases, awarded damages for frivolous appeals.

Part II: Why this keeps happening

It helps to understand the mechanism, because the failure mode is not random.

A large language model generates text by predicting likely continuations. A legal citation has an extremely regular form: a case name in a recognizable pattern, a volume number, a reporter abbreviation, a page number, a court, and a year. That structure is exactly what a next-token predictor reproduces well. Producing a plausible citation is easy; producing a true one requires the model to have the specific case in its parameters and to retrieve it accurately, which is a different capability.

Three consequences follow:

  1. Fabricated citations look right. They use real reporters, plausible volume numbers, real court abbreviations, and often real judge names. They are designed, in effect, to pass a glance.
  2. The model will confirm them. Asking a generative model whether its own output is accurate is not a verification step. The model has no external ground truth to check against, and it will generally produce a confident affirmative.
  3. Partial hallucination is the harder problem. A real case, cited correctly, with a quotation that does not appear in it, or with a holding characterized as the opposite of what it held, is far more likely to survive a citation check than a fake case is.

This is why the fix is a retrieval step, not a prompting technique. Every proposition must be traced to a document in a real database, opened and read.

Tools differ enormously

  • General-purpose chatbots answering from parameters alone are the highest risk.
  • Retrieval-augmented systems that search an actual legal database and generate answers grounded in retrieved documents are substantially better, because the citations correspond to documents the system actually found. They are not immune: they can mischaracterize what a retrieved case holds, cite a retrieved case for a proposition it does not support, or blend sources.
  • Purpose-built legal research platforms with linked citations and citator integration are better still, and independent evaluations have nonetheless found meaningful error rates.

No tool eliminates the verification duty. The duty is on the signer of the filing.

Part III: The governing rules

Rule 11

Fed. R. Civ. P. 11(b) provides that by presenting a paper to the court, an attorney "certifies that to the best of the person's knowledge, information, and belief, formed after an inquiry reasonable under the circumstances":

  • it is not being presented for an improper purpose;
  • the legal contentions are warranted by existing law or by a nonfrivolous argument for extending, modifying, or reversing existing law or for establishing new law;
  • the factual contentions have evidentiary support; and
  • the denials of factual contentions are warranted on the evidence.

The standard is objective. Good faith is not a defense to an unreasonable inquiry.

Rule 11(c) procedure:

  • A motion for sanctions must be served but not filed, giving the offending party 21 days to withdraw or correct the paper. Rule 11(c)(2). This safe harbor is a genuine opportunity, and a party that withdraws a filing with fabricated citations within it usually avoids Rule 11 sanctions, though not necessarily inherent-authority or § 1927 exposure.
  • A court may act on its own by order to show cause, Rule 11(c)(3), and the safe harbor does not apply to court-initiated sanctions.
  • Sanctions are "limited to what suffices to deter repetition," Rule 11(c)(4), and may be nonmonetary: striking the filing, requiring CLE, requiring notice to the client, or requiring a written explanation.
  • Rule 11 does not apply to discovery filings, which are governed by Rules 26(g) and 37. Note that Rule 26(g) contains its own certification with mandatory sanctions.

Section 1927 and inherent authority

28 U.S.C. § 1927 allows a court to require an attorney who "so multiplies the proceedings in any case unreasonably and vexatiously" to satisfy personally the excess costs, expenses, and attorney's fees reasonably incurred. Most circuits require bad faith or recklessness.

Inherent authority permits sanctions for bad-faith conduct not reached by rule or statute. Chambers v. NASCO, Inc., 501 U.S. 32 (1991). But a compensatory sanction under inherent authority must be limited to fees the innocent party incurred because of the misconduct. Goodyear Tire & Rubber Co. v. Haeger, 581 U.S. 101 (2017). Anything beyond that is punitive and requires criminal-type protections.

That but-for limit matters in these cases: the recoverable amount is the cost of chasing the fake citations, not the cost of the litigation.

The ethics rules

Rule 1.1 (Competence) and comment 8: a lawyer should keep abreast of "the benefits and risks associated with relevant technology." That comment has been adopted in the large majority of states. Competence now includes understanding that a generative tool can fabricate.

Rule 3.3 (Candor Toward the Tribunal): a lawyer shall not knowingly make a false statement of fact or law to a tribunal, or fail to correct a false statement previously made. Critically, the duty continues: on learning that a filing contains fabricated authority, the lawyer must take reasonable remedial measures, which means prompt disclosure to the court.

Rule 1.4 (Communication): clients may need to be informed about the use of AI, particularly where it affects confidentiality or the basis of fees.

Rule 1.5 (Fees): billing a client for hours not spent because a tool did the work, or billing for time spent fixing the tool's errors, raises reasonableness questions.

Rule 1.6 (Confidentiality): entering client information into a tool that retains it, uses it for training, or exposes it to the provider's personnel can be an unauthorized disclosure. Enterprise terms with no-training and no-retention commitments materially change this analysis.

Rules 5.1 and 5.3 (Supervision): partners and supervising lawyers must make reasonable efforts to ensure firm compliance, and must supervise nonlawyer assistance, which the ABA has interpreted to include technology used by the firm. "The associate used a chatbot" is not a defense for the signing partner.

ABA Formal Opinion 512 (2024) addresses generative AI directly, concluding that lawyers must have a reasonable understanding of the tools they use, must protect confidentiality (including by evaluating whether inputs will be used for training), must exercise independent professional judgment rather than deferring to outputs, may need to obtain informed client consent for certain uses, and must bill reasonably for time actually expended.

State bars have issued their own guidance along similar lines, with variations on client consent and disclosure.

Part IV: Court orders and disclosure requirements

Beginning in 2023, individual judges began issuing standing orders. They fall into three families:

1. Certification orders. Require counsel to certify either that no generative AI was used to draft the filing or that any language drafted with AI was checked for accuracy by a human using a print reporter or a traditional database. The best-known early example is Judge Brantley Starr's order in the Northern District of Texas.

2. Disclosure orders. Require identification of the tool used and the portions of the filing it produced.

3. Prohibition orders. A smaller number bar the use of generative AI for drafting filings entirely, or bar it without prior leave.

Some districts have adopted local rules or general orders, and some state courts have issued statewide guidance. Judicial conferences and advisory committees have studied whether a national rule is needed, and proposals to amend the Federal Rules of Evidence to address AI-generated evidence have been under consideration.

The practical instruction is unglamorous: read the standing order of the judge you are appearing before, every time, and add a standing-order check to the filing checklist. The orders are not uniform, and a certification requirement in one courtroom is a prohibition in another.

Courts have also begun addressing their own use of AI, with several judges disclosing use in opinion preparation and at least one withdrawing an opinion after errors were traced to an AI-assisted draft. The judiciary is working through the same verification problem everyone else is.

Part V: A verification workflow that actually works

This is the operational core of the article. The workflow below costs a few minutes per brief and eliminates the failure mode entirely.

For every citation in every filing

  1. Open the case. Not the citation, the case. In a real database, in a real document. If you cannot open it, it does not go in the brief.
  2. Confirm the citation elements: party names, volume, reporter, first page, court, and year, and that the pincite page contains what you say it does.
  3. Read the passage you rely on, in context. A quotation lifted from a summary of the losing party's argument is a different kind of error with the same consequences.
  4. Confirm the proposition. Does the case actually hold what you say? Was the statement dicta? Was it in a dissent?
  5. Run the citator. Is it good law? Overruled, abrogated, superseded, or distinguished into irrelevance?
  6. Check the quotation character by character if it is a direct quote. Paraphrase and drop the quotation marks if you cannot verify it exactly.
  7. Verify statutes and rules against the current official text, including effective dates and recent amendments.

For the filing as a whole

  • A second reader checks every citation against the source, ideally someone who did not draft.
  • A standing-order check for the specific judge, plus local rules.
  • A certification if required, signed by someone who actually performed or supervised the verification.
  • A record of the verification, which is what you will produce if a question arises.

Where AI can be used safely

Generative tools are genuinely useful in legal work, and a blanket prohibition is neither realistic nor wise. Lower-risk uses:

  • Summarizing documents you provide, where the source is in front of you and you can check the summary.
  • First-draft structure and outlines, which you then research and write.
  • Rewriting for clarity and length, where the substance is already verified.
  • Brainstorming counterarguments to test your own position.
  • Deposition and document review support, with human review of the results.
  • Translating technical material into plain language for a client letter, verified by someone who understands the technology.

Higher-risk uses that require the full verification workflow:

  • Finding authority.
  • Stating what a case holds.
  • Producing quotations.
  • Summarizing the law of a jurisdiction.
  • Anything that will be filed.

What to do if it has already happened

Move immediately, and in this order:

  1. Verify the scope. Which citations are fabricated, which are real but mischaracterized, and what else did the same person file?
  2. Notify the court promptly, in writing, before you are asked. Rule 3.3's remedial duty is triggered by knowledge, and every sanctions opinion in this area distinguishes between lawyers who came forward and lawyers who were caught.
  3. Withdraw or correct the filing. If a Rule 11 motion has been served, the 21-day safe harbor is running.
  4. Do not blame staff without investigating, and do not deny AI use if you are not certain. Courts have treated inaccurate explanations far more seriously than the original error.
  5. Notify the client, per Rule 1.4, and consider whether the malpractice carrier requires notice.
  6. Notify the carrier. Most policies require prompt notice of circumstances that could give rise to a claim.
  7. Fix the process and be prepared to describe the fix to the court. Courts respond well to a concrete remediation plan.
  8. Consider whether a disciplinary self-report is required in your jurisdiction.

Part VI: A firm policy

The policy does not need to be long. It needs to be specific and enforced.

Scope. Applies to all lawyers, paralegals, contractors, and staff, and to all generative tools, whether firm-provided or personal.

Approved tools. A list, with a process for adding to it. Personal accounts are prohibited for client work.

Confidentiality. No client confidential information, personally identifiable information, or privileged material into any tool without enterprise terms that prohibit training on inputs and specify retention. Maintain a record of which tools have been vetted and on what terms.

Verification. Every citation opened and read. Every quotation checked. Every proposition confirmed. No exceptions, no matter the deadline.

Attribution and disclosure. Follow the standing order of the court. Maintain a checklist item confirming the standing order was checked.

Supervision. The signing lawyer is responsible. Supervising lawyers must confirm that those they supervise understand and follow the policy.

Billing. Bill for time actually expended. Do not bill for time spent correcting tool errors.

Training. Annual training covering the failure modes, the verification workflow, and the confidentiality rules.

Incident reporting. An internal obligation to report a suspected fabricated citation immediately, without fear of blame, because the response window is short.

Record retention. Prompts and outputs used in client work may be discoverable and may be needed to explain what happened. Address retention explicitly. See Litigation Holds, Spoliation, and Rule 37(e).

For the broader governance framework, see AI Governance and Compliance.

Part VII: Beyond citations, the adjacent problems

Fabricated authority is the visible edge of a larger set of issues that the same verification discipline addresses.

Fabricated evidence and deepfakes. Courts are beginning to confront audio, video, and documents that are synthetically generated. Existing authentication doctrine under Fed. R. Evid. 901 requires evidence "sufficient to support a finding that the item is what the proponent claims it is," and the Advisory Committee on Evidence Rules has studied whether a new rule is needed for AI-generated or AI-altered evidence, including proposals addressing the burden a party must meet when challenging authenticity. Litigators should expect authentication fights to become more evidentiary and more expert-driven, and should preserve original files with metadata rather than working from exports. See Authenticating Website Evidence and Name, Image, Likeness, and Digital Replicas.

Confidentiality leakage. The more common and less visible failure. A lawyer pastes a draft settlement agreement, a client's financial data, or a witness statement into a consumer chatbot. Depending on the terms, that content may be retained, reviewed by the provider's personnel, or used to improve the model. Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure, and comment 18 directs consideration of the sensitivity of the information and the cost of safeguards. Enterprise agreements with no-training and no-retention terms, and a prohibition on personal accounts for client work, are the practical answer.

Privilege and discoverability of prompts. Prompts and outputs created in the course of representation may be work product, but the analysis is not automatic, and the question of whether prompts are discoverable has begun to appear in motion practice. Treat them as documents: they can be preserved, logged, and produced. See Attorney-Client Privilege and Work Product for Businesses.

Unauthorized practice and access to justice. Consumer-facing legal AI products have drawn both regulatory attention over unauthorized practice and genuine interest as a partial answer to the enormous unmet demand for legal services. Both are true at once. Courts seeing a rise in pro se filings with fabricated authority are seeing a symptom of a system in which most people cannot afford a lawyer, and the long-run answer is unlikely to be sanctions.

Billing and value. If a tool reduces a four-hour drafting task to one hour, the client is entitled to be billed for one hour. Formal Opinion 512 says so. Firms that resolve this honestly, by moving toward value-based pricing where appropriate, will handle the transition better than firms that quietly keep the hours.

Part VII-A: What the research says about error rates

It is worth knowing what the empirical picture looks like, because the marketing claims and the measured performance diverge sharply, and clients ask.

General-purpose chatbots answering legal questions without retrieval produce fabricated or substantively incorrect citations at rates that multiple studies have placed well into the double digits, and higher for jurisdiction-specific and lower-court questions where the training data is thinner. The pattern is consistent: performance is best on famous Supreme Court cases and degrades sharply as the question narrows.

Purpose-built legal research tools using retrieval do substantially better and are still not error-free. Independent academic evaluation of leading commercial legal AI research products has found meaningfully non-zero rates of hallucinated or unsupported statements, including citations to real cases for propositions they do not support, which is precisely the failure mode a citation check does not catch.

Three practical lessons follow:

  1. Retrieval helps a great deal and does not eliminate the duty. The improvement is real; the residual risk is concentrated in mischaracterization rather than fabrication, which makes it harder to detect, not easier.
  2. Vendor benchmark claims deserve scrutiny. Ask what the benchmark measured, whether it was independently validated, and what counts as an error. "Hallucination-free" is a marketing claim, not a measurement.
  3. The failure rate is high enough that a firm doing volume work will encounter it. A tool with a two percent error rate, used across a thousand research questions a year, produces twenty problems. The verification step is what converts those from filings into caught drafts.

A note on judicial use. Several federal and state judges have disclosed using generative tools in chambers, and at least one opinion has been withdrawn and reissued after errors were traced to an AI-assisted draft. Judicial conferences have begun issuing guidance for chambers use. Practitioners should read that development sympathetically rather than gleefully: the verification problem is identical on both sides of the bench, and the profession is working it out together.

A worked example

Thorne & Waverly LLP (fictional) is a fourteen-lawyer litigation boutique. A second-year associate drafts an opposition to a motion for summary judgment under a two-day turnaround while the supervising partner is in trial.

The associate uses a general-purpose chatbot to find authority on a narrow question about the admissibility of business records created by a third party. It returns four cases. Three are real. One, cited as a decision of the relevant circuit, does not exist, and the chatbot supplies a plausible quotation from it.

The associate checks two of the four in the firm's research database, finds them, and, under time pressure, does not check the other two. The partner signs the brief from the courthouse hallway without reading the citations.

What happens next. Opposing counsel cannot find the case, emails, and then serves a Rule 11 motion.

The right response, in the first hour:

  • Pull every citation in the brief and verify all of them, including the ones already checked.
  • Determine that one is fabricated and that another real case is cited for a proposition it does not support.
  • File a letter with the court within 24 hours, before the safe harbor expires, disclosing the error, withdrawing the affected argument, and attaching a corrected brief.
  • Do not argue that the associate is solely responsible; the partner signed it.
  • Describe the process change: mandatory second-reader citation verification, a filing checklist item, and a firm policy.
  • Notify the client and the carrier.

Likely outcome. With prompt disclosure and correction inside the safe harbor, no Rule 11 sanction, possible fee-shifting for the time opposing counsel spent, and a court that is satisfied. The alternative path, defending the citation or blaming the associate, produces a published opinion with the firm's name in it.

The cost of prevention. Roughly fifteen minutes of associate time to open four cases. That is the entire story.

Frequently asked questions

Is it unethical to use AI in legal practice? No. ABA Formal Opinion 512 and state bar guidance treat generative AI as a tool lawyers may use, subject to competence, confidentiality, supervision, candor, and reasonable fees. The obligation is to understand the tool and verify the output.

Do I have to disclose that I used AI? It depends on the court. Many judges have standing orders requiring disclosure or certification, some districts have local rules, and most courts have no requirement. Check before every filing. As to clients, disclosure may be required under Rule 1.4 where it affects confidentiality or fees.

Are AI legal research tools safe? Safer than general chatbots, because they retrieve from real databases, but not error-free. Independent evaluations have found meaningful rates of unsupported statements even in purpose-built legal tools. The verification duty does not change.

What if the citation is real but the quotation is wrong? That is the more dangerous failure, because it survives a citation check. It is also a Rule 11 problem and, if the misquotation is material and you know of it, a Rule 3.3 problem. Verify quotations character by character.

Can I be sanctioned if my expert used AI? The expert's declaration is your submission. Fabricated authority in an expert report raises Rule 11 and Rule 26 issues and gives the other side an exclusion motion under Rule 702. Ask experts, in writing, what tools they used and how they verified.

What about pro se litigants? Courts have generally imposed lighter sanctions on pro se parties but have still struck filings, denied relief, and in some cases awarded damages for frivolous appeals. Pro se status is not a license to file fabricated authority.

Should my firm ban these tools? Most firms should not. A ban drives usage underground onto personal accounts, which is worse for confidentiality and worse for supervision. An approved-tools list with enterprise terms, mandatory verification, and training addresses the risk while capturing the benefit.

Is there malpractice exposure? Yes. A filing with fabricated authority that leads to a denied motion or an adverse ruling is a classic malpractice fact pattern, and the underlying error is easy for a jury to understand. Notify your carrier promptly when an incident occurs.

Will the rules change? Rule and evidence amendments addressing AI have been under study, particularly for AI-generated evidence and deepfakes. Nothing needs to change for the citation problem: Rule 11 already requires reasonable inquiry, and it always did.

How do I explain this to a client who wants us to "use AI to cut costs"? Honestly. These tools do reduce time on drafting, summarization, and review. They do not reduce the time required to verify authority, and the attempt to skip that step is what produces the incidents in the news. The savings are real and they come from somewhere other than the citation check.

Closing thought

The striking thing about every one of these cases is that the underlying failure predates the technology. Citing a case you have not read has never been acceptable. Quoting language you have not confirmed has never been acceptable. Signing a brief without checking it has never been acceptable.

What generative AI changed is the volume and plausibility of the material available to a lawyer who skips that step. Before, an unverified citation was usually a real case remembered imprecisely. Now it can be a complete fabrication with a court, a year, a page number, and a quotation, produced in two seconds and formatted perfectly.

The professional response is not to be afraid of the tools. It is to reinstate a discipline that was always required and had grown quietly optional in a hurry. Open the case. Read the page. Then sign the brief.


Related articles

This article is provided for general informational purposes and does not constitute legal advice. Court standing orders and bar guidance on generative AI vary and change frequently; check the requirements applicable to your court and jurisdiction before every filing.