The audit: never trust an AI citation
In legal work, a fabricated citation doesn't cost a like: it costs the case and your bar license. This is the RESPOND moat lesson applied to law: AI proposes, the lawyer verifies, and a person always signs.
A lawyer asked AI for three precedents to support a statute-of-limitations argument. In seconds an impeccable text came back: case number, judge, date of the ruling, a tidy summary. He copied it straight into the brief and already had his finger on the file button when an intern, out of habit, went to check the first number on the court's website. The case didn't exist. Neither did the second. The third mixed the name of a real judge with a made-up summary. The document looked perfect and was entirely fabricated, and only the habit of checking before filing prevented the disaster.
An analyst asked AI for an opinion grounding a tax classification and received the citation of a tax authority rule "in effect since 2021." The writing was convincing, the number looked official. Except the cited regulation had been revoked two years earlier, and the transcribed passage never existed in any version of it. Checking the official source, done before attaching it to the opinion, was what kept the wrong classification from going out.
An assistant asked AI for case law for a labor case and received four rulings with panel, division, and judge listed. While auditing before filing, she found two were invented from scratch and a third was real, but said exactly the opposite of what AI claimed it said. There was an hour left before the deadline.
A team asked AI for the legal grounding of a campaign claim ("proven by a study") and received the citation of a study with author, year, and journal. The piece was almost published. In the audit, the study didn't exist, and the unsupported claim exposed the company to a false-advertising lawsuit. Checking the source before approving the piece was what kept the claim from going out.
A recruiter asked AI for a summary of a candidate's background from the resume and got back a tidy text: company, title, three years of experience with a specific system, all in the tone of someone who read everything carefully. She almost sent the assessment to the hiring manager recommending an offer. On review, she cross-checked it against the real resume: that system never appeared in it, and the "three years" was a number AI made up to fill the gap. The text looked evaluated and was fabricated, and only comparing it against the real resume kept her from recommending based on made-up data.
A PM asked AI for market data to justify a roadmap priority and got three beautiful numbers: segment size, adoption rate, a source with a consultancy name and year. He was about to paste it into the PRD to defend the feature at the committee. Before that, he went after the primary source: the cited report didn't exist, and one of the real numbers said the opposite of what his thesis claimed. The entire priority was resting on made-up ground, and checking the source before the committee was what kept the roadmap from being based on a fabricated number.
A salesperson asked AI for an account summary to build the proposal and got the client's history back: revenue, past contracts, the decision-maker's name, all in the format of something pulled straight from the CRM. He almost sent the proposal with that data. He went to check the real CRM: the cited decision-maker had left months earlier and the previous contract never existed. A proposal with a made-up fact about the client's own account burns the relationship instantly, and only checking the real CRM before sending kept that from happening.
A coordinator asked AI for a vendor's procedure to close the logistics plan and got a detailed SLA back: delivery deadline, pickup window, penalty clause, contract number. He was about to distribute it to the team as official policy. In the audit, he opened the real contract: the cited deadline was different and the penalty clause didn't exist in any version. The document looked operational and was entirely made up, and only opening the real contract before distributing it kept the wrong rule from spreading.
An analyst asked AI for the data-privacy article backing an internal control and received the citation of a "current" provision, with a number and convincing wording. She was about to attach it to the risk opinion. Before signing, she checked the official text: the cited article had been amended and the transcribed passage never existed in the law. A control resting on a phantom regulatory basis is exactly the kind of failure the next audit finds, and checking the official text before signing was what kept that from happening.
A developer asked AI for documentation of a library function to finish the deploy and got an impeccable snippet back: method name, parameters, usage example, a link to the official docs. He almost shipped the code with that. He went to check the source: the method didn't exist in that version and the link led to a page that never covered it. The code looked ready and was about to break in production, and checking the source before the deploy was what kept that from happening.
A designer asked AI for research data to justify a flow decision and got a usability statistic back with source, year, and exact percentage. She was about to put it in the report to close out the prototype with the stakeholder. On review, the cited study didn't exist, and the real heuristic pointed the opposite direction from the proposed flow. The entire journey decision was about to be built on a number nobody ever measured, and only checking the source before closing out the prototype kept that from happening.
A strategy analyst asked AI for the operating margin benchmark of the three main competitors to support the board deck's thesis and got back tidy numbers, with a source from a well-known consultancy and a publication year. He was about to upload the slide for the meeting. Before presenting, he went after the original report: the cited study didn't exist under that name, and the consultancy had never published that data. The entire investment thesis was resting on a fabricated benchmark, and only checking the primary source, before uploading the slide, kept him from presenting a number that didn't exist.
Look, let me be honest with you. The most dangerous part of AI in legal work isn't when it gets it wrong in an obvious way. It's when it nails the form and gets the fact wrong. It hands you a ruling with a case number, judge, and summary, all in the right tone, and your guard drops because it looks like the work of a competent colleague. That relaxation is the hole. In legal work, a fabricated citation doesn't cost a bad comment online: it costs the case, costs the client, and can cost your bar license.
The core idea of this lesson. AI doesn't "consult" the law: it predicts the most likely next piece of text. That's why it invents rulings, case numbers, statutes, and legal scholarship with absolute confidence, and its confidence is exactly what fools you. The rule is simple and non-negotiable: never trust a citation from AI. You audit it. And a person always signs the document, because "the AI that wrote it" doesn't exist before a judge.
01Why AI lies with the straightest face in the world
Let's clear up a misunderstanding that costs dearly. AI doesn't have a database of laws in its head that it "opens" to answer you. It works by predicting the most likely next word, given everything that came before. When you ask for a ruling, it doesn't search: it composes something that has the shape of a ruling. Number, judge, summary, all in the perfect format, because it has seen thousands of real rulings and learned the mold. The mold is correct. The content can be pure fiction.
This even has a technical name: hallucination. But the name hides what matters. The problem isn't that it gets things wrong; it's that it gets things wrong with the same confidence it gets things right. There's no warning, no "maybe," no hesitation. Out comes secure, polished text, the way an experienced practitioner would write it. And it has already happened for real: lawyers have been sanctioned for filing briefs with AI-invented case law, citing cases that never existed. The judge went to check, found nothing, and the bill came with the lawyer's name on it, not the tool's.
Notice the cruel inversion here. In the analog world, the signal that something is trustworthy is that it looks well made. With AI, looking well made says nothing about being true, because producing something well made is exactly what it does best. Form stopped being proof. Only the fact is proof. And a fact, in legal work, gets checked at the source.
02The speed paradox: you feel faster while getting it wrong
There's a study that needs to sink into your head before you trust your own sense of things. In 2025, METR measured experienced developers working with and without AI assistance. The result went against everyone's expectations: with AI, they got slower. About nineteen percent slower. But here's the detail that matters for legal work: they thought they were faster. The sense of acceleration was real; the gain wasn't.
Why does this happen? Because AI gives you an instant draft, and your brain registers that fast delivery as progress. Except the real work, checking, correcting, undoing what came out wrong, stays hidden and disappears from your perception. You feel the fast start and don't feel the time you spend cleaning up the mess. The sense of being right is deceptive: it's strongest exactly when you should be most suspicious.
In development, this paradox costs hours. In legal work, it costs the case and your bar license. Because the feeling of "it's already done, just file it" is the same, but the bill is incomparable. That's why the audit can't depend on how you feel about the document. The feeling is exactly the miscalibrated instrument. You need an external, cold process, one that doesn't ask if you're confident. It asks if the citation exists.
03The legal audit checklist: five questions before signing
Here's the heart of the lesson. Auditing an AI-assisted document isn't intuition, it's a routine. Five questions, always the same, always at the source. If any one fails, the document doesn't go out. It's not about how much you trust it: it's about passing through all five gates.
- Does every citation exist and say what AI claimed? Open the court, the official gazette, the primary source. Check the case number, the judge, the date. And read the summary for real, because a real precedent can say the opposite of what AI guaranteed it said.
- Is the law in effect? A cited statute might be repealed, amended, or not yet in force. AI doesn't know today's date and doesn't track repeals. Confirm the current status in the official, updated text.
- Does the precedent apply to this case? Existing and being in effect isn't enough. The ruling needs to match your matter, jurisdiction, and context. A precedent out of context is ammunition that blows up in your hand.
- Is any fact about the client made up? AI fills gaps with what sounds plausible: dates, amounts, names, sequence of events. Cross-check every fact stated in the document against what the client actually told you and against the documents. A made-up fact about the client's own case is the error that destroys the relationship.
- Can whoever signs actually stand behind it? If the judge asks where that argument came from, in a hearing, on the spot, with no AI around, can you back it up? If the answer is no, the document still isn't yours. It's a draft you don't understand.
04The RESPOND principle: the one who signs is a person, always
Back in the map The 3 Moves, RESPOND is the moat: the part of AI-assisted work you don't outsource, because that's where responsibility lives. In legal work, RESPOND has an exact and unforgiving translation: the document goes out with a human name under it, and that name answers for every word in it.
Think about what happens in a hearing. If there's a problem in the document, the judge doesn't call AI. There's no "the AI that wrote it" before the court, before the client, before the bar. There's the lawyer who filed it. The machine executes, the machine proposes, the machine drafts fast. But the signature is the boundary where responsibility stops being able to get pushed further along. It hits a person and stays there. That's the RESPOND principle applied to law, and it connects directly to the governance you saw in lesson 4.4: the human controls the system, and the human name answers for the output.
And here's the frame that changes your relationship with the audit. Checking every citation isn't distrusting the tool, isn't old-fashioned, isn't a waste of time. Auditing protects three things at once: the client, who entrusted you with the case; the case, which is lost with a single fabricated precedent; and your license, which is your right to practice. AI gave you speed in the draft. The audit is what turns that speed into something you can sign without losing sleep. Whoever skips the audit isn't being faster. They're outsourcing their own risk and pretending not to see it.
Do it now
Take a real case from your day-to-day (your real task works well) where you'd use AI to draft a document with legal grounding. Before thinking about filing anything, build YOUR OWN five-item legal audit checklist, adapted to your area of practice:
- CITATION EXISTS AND CHECKS OUT: write the exact question and which primary source you'll use to check every ruling, statute, or scholarship reference (which court, which database, which official record).
- IN EFFECT: how do you confirm every cited law, rule, or regulation is currently in force, and not repealed or not yet effective?
- APPLICABILITY: what criterion do you use to decide whether the precedent really serves THIS case (matter, jurisdiction, context)?
- CLIENT FACTS: how do you cross-check every fact stated in the document against what the client told you and the documents, to catch anything AI made up?
- STANDING BEHIND IT: the question you ask yourself to know whether you could defend each argument in a hearing, with no AI around.
Write the five out on one page and stick it next to your screen. If you file without going through all five, it wasn't AI that signed: it was you.
Practice
1. Why should a citation produced by AI never be filed without checking the source, even when it comes with a full case number, judge, and summary?
2. The 2025 METR study showed experienced professionals were slower with AI, but thought they were faster. What is the direct lesson for the legal audit?
3. Applied to law, what does the RESPOND principle (AI proposes, the lawyer verifies, the person signs) determine about responsibility for the document?
Fair? This lesson's message is the shortest in the module and the most expensive to ignore: never trust a citation from AI. It's a fast writer and a terrible witness to itself. Use its speed in the draft, but run everything through the five gates before putting your name underneath. Auditing isn't distrusting the tool; it's protecting the client, the case, and your license. AI proposes, you verify, and a person signs. Always.
For the board
On letting your guard downa docket number, a judge and a headnote in the right tone make your mind relax. That relaxation is the hole.
On formperfect form is not proof of truth. It is precisely what the AI does best.
On the costin law an invented citation does not cost you a bad review. It costs you the case.
Thanks for the feedback. It helps sharpen the next lesson.