Blog AI Governance October 7, 2025 4 min read

The Citation That Didn't Exist

Deloitte refunded part of a $440,000 government report after a fabricated court quote and nonexistent citations surfaced - not through internal review, but because an outside researcher checked the footnotes.

By the AuthorityGate Architect Team

In July 2025, Deloitte Australia delivered a 237-page report to the country's Department of Employment and Workplace Relations, commissioned to review how the department's welfare system applied automated penalties. The engagement was worth AU$440,000. It was meant to be an authoritative review of a government compliance system. Instead, it turned out to contain a fabricated quote attributed to a federal court judgment and citations to academic papers that don't exist.

A magnifying glass over a printed page at a research desk, revealing a faint warm-gold question mark glowing within a line of text
One careful reader, catching what many reviewers missed.

Caught by an outsider, not the review process

Nobody at Deloitte flagged this before publication. It surfaced because Chris Rudge, a University of Sydney researcher specializing in health and welfare law, went looking for the sources cited in the report to verify its claims - and found several weren't real. He went to the media. Only after the story broke did a revised version get published, this time disclosing that Azure OpenAI had been used to help produce the document. That disclosure wasn't in the original.

AU$440Kvalue of the original government engagement
237pages in the delivered report
AU$97Krefunded (about US$63K)
1outside researcher who caught what internal review missed

The financial resolution came on October 7, 2025: Deloitte agreed to refund roughly AU$97,000 to the department. That's a real number, but the more interesting failure sits upstream of it. Somewhere in Deloitte's production process, AI-generated content - including a fabricated legal citation - moved from a model's output into a paid government deliverable, without anyone in the review chain catching the fabrication or disclosing that AI had touched the document.

The correction here came from a researcher doing Deloitte's fact-checking in public. That's not a review process. That's luck.

Where the checkpoint should have been

This is the deliverable-integrity version of the same failure that keeps showing up across professional services: an AI system produced output, and nothing between "the model generated this" and "this ships under our name" verified the content was true, let alone flagged that a machine had written it. A citation-checking pass - even a basic one - would have caught a court quote that doesn't exist in any actual ruling.

The AuthorityGate take

As AI tooling becomes standard in professional services, "did a human verify this, and do we know AI touched it" stops being optional due diligence and starts being the actual product being sold. A framework that requires disclosure and validation of AI-generated content before delivery is the difference between an efficiency gain and a six-figure problem with your name on it.

Nothing about this required exotic tooling to catch - it required one gate asking "has this been verified" before the document shipped.

Share this post: LinkedIn

Go deeper

Every agent action, validated before it takes effect

AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.