Listen to this article
In July 2025, Deloitte Australia delivered a 237-page report to the country's Department of Employment and Workplace Relations, commissioned to review how the department's welfare system applied automated penalties. The engagement was worth AU$440,000. It was meant to be an authoritative review of a government compliance system. Instead, it turned out to contain a fabricated quote attributed to a federal court judgment and citations to academic papers that don't exist.
Caught by an outsider, not the review process
Nobody at Deloitte flagged this before publication. It surfaced because Chris Rudge, a University of Sydney researcher specializing in health and welfare law, went looking for the sources cited in the report to verify its claims - and found several weren't real. He went to the media. Only after the story broke did a revised version get published, this time disclosing that Azure OpenAI had been used to help produce the document. That disclosure wasn't in the original.
The financial resolution came on October 7, 2025: Deloitte agreed to refund roughly AU$97,000 to the department. That's a real number, but the more interesting failure sits upstream of it. Somewhere in Deloitte's production process, AI-generated content - including a fabricated legal citation - moved from a model's output into a paid government deliverable, without anyone in the review chain catching the fabrication or disclosing that AI had touched the document.
The correction here came from a researcher doing Deloitte's fact-checking in public. That's not a review process. That's luck.
Where the checkpoint should have been
This is the deliverable-integrity version of the same failure that keeps showing up across professional services: an AI system produced output, and nothing between "the model generated this" and "this ships under our name" verified the content was true, let alone flagged that a machine had written it. A citation-checking pass - even a basic one - would have caught a court quote that doesn't exist in any actual ruling.
The AuthorityGate take
As AI tooling becomes standard in professional services, "did a human verify this, and do we know AI touched it" stops being optional due diligence and starts being the actual product being sold. A framework that requires disclosure and validation of AI-generated content before delivery is the difference between an efficiency gain and a six-figure problem with your name on it.
Nothing about this required exotic tooling to catch - it required one gate asking "has this been verified" before the document shipped.
Sources
Go deeper
Every agent action, validated before it takes effect
AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.