Generative errors and professional liability: the Deloitte-Australia case and the new frontier of AI governance

Articles19 October 2025
The firm acknowledged the use of AI in the process and refunded part of the fees, estimated at 440,000 Australian dollars.

In October 2025, the Australian government confirmed that Deloitte had used generative artificial intelligence – specifically GPT-4 – to produce a report on technological innovation commissioned by the federal government. The document, which was intended to serve as a strategic input for the country’s digital planning, contained numerous factual errors, non-existent quotations and fabricated references. The firm acknowledged the use of AI in the process and refunded part of the fees, estimated at 440,000 Australian dollars[1].

The incident marks a turning point in the relationship between automation, professional accountability and institutional trust. What went wrong in Australia is something that anyone who has used ChatGPT, Gemini or Copilot is well aware of. Large language models invent information with disconcerting confidence. The technical phenomenon is called ‘hallucination’ and works like this: the system generates content that sounds plausible but is completely false, citing studies that do not exist, attributing statements to people who never said them, and fabricating credible statistics. And it does so without warning, without hesitation, with the same certainty with which it answers other questions correctly.

OpenAI, Anthropic, Google and Meta warn about this feature in their terms of use. Academic research has documented it extensively. Any professional using these tools should be aware of this. This is the crux of the Deloitte case. Someone handed over an AI-generated product to the Australian government without verifying its content. In legal terms, that constitutes professional negligence.

Professional liability in consultancy services has deep roots. Long before artificial intelligence, the law established that anyone offering specialist knowledge must act with care and competence. In Mexico, Articles 2615 and 2616 of the Federal Civil Code stipulate that the provider of professional services is liable for negligence, incompetence or wilful misconduct. Consultants, lawyers and auditors provide, in addition to their service, the assurance that their work has been reviewed, cross-checked and verified[2]. This obligation is heightened when the client is the State.

The Law on Public Sector Procurement, Leasing and Services provides for administrative sanctions and the termination of contracts where the supplier fails to meet the agreed quality standards or specifications[3]. If a strategic report contains false information because nobody verified the output of an automated tool, this constitutes a clear breach of contract. If, furthermore, that report influences public policy decisions based on fabricated data, the potential damage is enormous.

Comparative law offers clues as to how the courts will resolve such cases. In the United States, several states are facing lawsuits against lawyers who submitted pleadings containing false case law generated by ChatGPT[4]. The courts have been unequivocal. In one of the most widely discussed cases, a federal judge in New York sanctioned two lawyers who cited non-existent cases in a motion, arguing that they had a positive duty to ensure the accuracy of everything they submitted to the court, regardless of the tools used.

The UK’s Solicitors Regulation Authority issued clear guidelines in 2024. Lawyers may use AI but retain personal and professional responsibility for all work they sign off on[5]. The English Law Society published a guide to good practice[6] which includes advising clients when AI is used, documenting which tools were employed, and establishing human review protocols to detect errors.

Europe regulates the matter more systematically. The AI Act classifies certain uses of AI as high-risk when they are employed in decisions affecting fundamental rights, access to essential services or legal compliance. Providers of these systems must ensure data traceability, human oversight and error-correction mechanisms. Responsibility lies both with those who develop the AI and those who use it professionally, and companies contracting services where high-risk AI has been used may require audits and documentation of the process[7].

Technical standards are advancing rapidly, such as the ISO/IEC 42001 standard, which sets out the requirements for the responsible management of artificial intelligence, ranging from risk assessment to quality controls and system governance[8]. Although the NIST AI Risk Management Framework is voluntary, it already serves as a benchmark for companies seeking to demonstrate due diligence and transparency[9]. Both frameworks share the essential principle that trust in technology depends on robust processes for detecting errors, correcting them and learning from them.

Mexico is likely to have its own ‘Deloitte case’ soon. Consultancy firms, law firms, audit firms and professional services companies are already using generative AI to produce reports, analyses, presentations and legal documents. Some do so with rigorous controls. Others are probably merely experimenting without clear protocols. When the first case comes to light involving a strategic report, a legal opinion or an audit produced using AI that contains serious errors, legal questions will arise immediately. Who is liable when something goes wrong? The company that delivered the document? The professional who signed it without checking it? Both? Can a supplier claim that the client assumed the risk if they were never warned that AI had been used? Is there a legal obligation to disclose the tools used?

In the world of private contracts, these issues could be resolved through well-drafted clauses that allocate responsibilities and set out clear expectations. In public procurement, where tender documents are usually standardised and quality obligations are implicit in the very nature of the service, there is less room for manoeuvre. And it is precisely there, at the intersection between technology and public obligations, that the next Mexican case is likely to erupt.

The sensible approach would be to plan ahead. Firms offering professional services should establish clear policies on how and when to use artificial intelligence. AI can be used for initial drafts, to organise ideas, to summarise lengthy documents or to explore preliminary approaches. When a report includes factual data, case law citations, technical references or strategic conclusions generated by AI, someone with the necessary expertise must review it line by line before it leaves the firm. Human verification must be mandatory and documented.

Documenting the process internally is a basic requirement for traceability. Knowing which tools were used on each project, at what stage of the work, and who was responsible for the final review makes it possible to demonstrate due diligence if something goes wrong. Staff training is equally critical. A junior analyst who is unaware that GPT-4 can fabricate entire academic studies with fictitious authors and journals poses a significant risk.

Transparency with the client deserves special attention. Some firms already include warnings in their contracts regarding the use of automated tools, explaining their limitations and the extent of the human review carried out[10]. Managing expectations and protecting both parties is more prudent than facing a dispute later due to a lack of information. The same applies to technology providers. If a firm outsources the development of AI systems, contracts must include shared liability clauses, quality assurance provisions and audit mechanisms. When an algorithm integrated into a professional service fails, liability remains even if a third party wrote the code.

On the government side, the conversation must also change. When a public body puts consultancy, audit or technical analysis services out to tender, the tender documents could begin to include questions that until recently would have sounded strange. Will artificial intelligence be used at any stage of this work? Which specific models? Using which verification protocols? Transparency should be the norm. A supplier who conceals the fact that half a report was generated using AI and then submits false data faces the same consequences as if they had deliberately lied: termination of the contract, repayment of payments and temporary or permanent disqualification from contracting with the State.

The Deloitte-Australia case serves as a wake-up call for the entire professional services industry. Artificial intelligence can boost productivity, streamline processes and improve analysis. It can also lead to costly errors if used without adequate controls. AI errors become the errors of the professional who failed to detect them. Negligence lies in blindly trusting the technology without applying the critical judgement that any provision of specialised services demands.

And whilst the legal risk becomes apparent, the technology industry is attempting to respond. Platforms designed specifically for the legal sector have begun to emerge. Tools such as Harvey AI, used by firms of the calibre of Allen & Overy[11] or PwC[12], or Casetext CoCounsel, now part of Thomson Reuters[13], are trained on massive legal corpora and connected to verified case law databases. Rather than speculating on what a law says or inventing a precedent, these platforms search actual repositories. vLex Vincent does something similar for Latin American markets. The promise is tempting: legal accuracy without sacrificing speed.

Nor are these tools infallible. Harvey AI includes explicit warnings urging lawyers to review everything before using it. Thomson Reuters maintains layers of human verification in Practical Law because they know that the margin for error, whilst smaller, still exists. The value of these technologies lies in shifting where time is invested: less on mechanical searches, more on critical analysis; less on copying and pasting case law, more on interpreting and applying it correctly. It represents a shift in the role of the profession.

This difference is likely to divide the market. Some firms will continue to use ChatGPT or Copilot without serious safeguards because it is accessible and quick, taking risks they may not fully understand. Others will invest in specialised platforms, rigorous verification protocols and ongoing training for their staff, building a reputation for reliability that will ultimately prove to be their most valuable asset. For clients – particularly governments and large companies that contract high-value services – this difference will matter more and more when deciding who to work with.

Technological specialisation offers a parallel path to regulation. Whilst legislators strive to catch up with regulatory frameworks that are still in draft form, developers of specialised legal tools are building technical barriers against hallucinations. Connecting models to verified databases, training them on real case law, and incorporating mechanisms for automatic citation and source validation represent a pragmatic step forward. The solution to the problem of AI in law may come from both the law and better technology. Both approaches are necessary and complementary.

In the age of artificial intelligence, professional trust remains profoundly human. Machines can assist, but verification, expert judgement and accountability remain in human hands. Anyone who signs an AI-generated document without reviewing it assumes all the risks. Those risks, as Deloitte has just discovered in Australia, can be very costly.

The lesson for Mexico comes at just the right time. Regulation is on the horizon, whether or not there are specific cases to warrant it. Firms that establish robust AI governance protocols will avoid future liabilities whilst building a competitive advantage based on something no technology can replicate: credibility. When a client engages professional services, they are buying trust. In the world of artificial intelligence, that trust is earned by demonstrating that there is a responsible human being behind every word that is delivered. And, more profoundly, by demonstrating that there is a professional ethos which understands that technology amplifies both our capabilities and our ethical responsibilities.




[3] The LAASSP provides that government departments and agencies may administratively terminate contracts in the event of a supplier’s failure to fulfil their obligations, and may initiate administrative sanction proceedings in respect of goods or services that do not meet the agreed specifications.” (See Article 53, LAASSP; ‘Sanctions against tenderers, suppliers and contractors’, Government of Mexico.) - https://www.diputados.gob.mx/LeyesBiblio/pdf/LAASSP.pdf


[4] A Utah lawyer was punished for filing a brief containing ‘fake precedent’ generated by artificial intelligence - https://www.sltrib.com/news/politics/2025/05/29/lawyer-punished-filing-brief-with/

Judge sanctions lawyers defending Alabama’s prison system for using fake ChatGPT cases in filings - https://www.wvtm13.com/article/alabama-prison-lawyers-chatgpt-sanction/65513261

New York lawyers sanctioned for using fake ChatGPT cases in a legal brief – https://www.reuters.com/legal/new-york-lawyers-sanctioned-using-fake-chatgpt-cases-legal-brief-2023-06-22/

Lawyers using AI keep citing fake cases in court. Judges aren’t happy. –https://www.washingtonpost.com/nation/2025/06/03/attorneys-court-ai-hallucinations-judges/

[5] Risk Outlook report: The use of artificial intelligence in the legal market - https://www.sra.org.uk/sra/research-publications/artificial-intelligence-legal-market/

[7] Article 12 of the AI Act (“Record-Keeping”): stipulates that AI systems deemed to be high-risk must automatically log events throughout their lifecycle, to ensure “a level of traceability of the system’s operation”. - https://artificialintelligenceact.eu/article/12/

Article 14 of the AI Act (“Human Oversight”): states that such systems must be designed so that they can be effectively and proportionately supervised by natural persons, who are able to interpret, intervene in or halt their operation where necessary. - https://artificialintelligenceact.eu/article/14/

The European Commission’s official portal on the AI Act: explains that the regulation adopts a risk-based approach, and that high-risk systems are subject to enhanced obligations. - https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

[8] AI management systems: What businesses need to know - https://www.iso.org/artificial-intelligence/ai-management-systems

[9] “The AI RMF is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.” - https://www.nist.gov/itl/ai-risk-management-framework


[12] PwC announces strategic alliance with Harvey, positioning PwC’s Legal Business Solutions at the forefront of legal generative AI - https://www.pwc.com/gx/en/news-room/press-releases/2023/pwc-announces-strategic-alliance-with-harvey-positioning-pwcs-legal-business-solutions-at-the-forefront-of-legal-generative-ai.html

Una imagen abstracta que muestra una serie de líneas curvas y onduladas en tonos suaves.
  • Artificial Intelligence

Related professionals

LATEST FROM #ECIJA