The shape of the problem

The database is the closest thing the profession has to a census, and its curve tells the story. Roughly 1,490 decisions by May 2026; 1,598 by early June; 2,041 by mid-September. The growth is not evidence that models are getting worse — by most measures they are getting better. It is evidence that adoption has outrun verification, and that courts have started looking.

The jurisdictional spread matters more than the total. The United States dominates because it has the most lawyers, the most litigation and the most aggressive sanctions practice, but the per-capita figures for Canada, Australia and Israel are striking, and the 69 British cases have produced some of the sharpest judicial language anywhere. These are all common-law systems with heavy citation cultures, where a brief lives or dies on authority. That is precisely the environment in which a fabricated citation does maximum damage — and it describes Turkish civil practice more closely than many Turkish lawyers would like to admit.

Three kinds of fabrication, in ascending order of danger

Treating "hallucination" as one phenomenon obscures the fact that three quite different failures are being lumped together, and they carry different risks.

  • The invented case. A citation to a decision that does not exist, with a plausible name, court and year. This is the original failure mode, and it is the easiest to catch: a single database search returns nothing.
  • The invented proposition. A real case, correctly cited, described as holding something it does not hold. Harder to catch, because the citation checks out; only someone who reads the judgment discovers the problem. This is the variant most likely to survive into a judgment.
  • The corrupted identifier. A real decision, with real reasoning, carrying a fabricated docket or file number. This is the Turkish case, and it is the most insidious of the three: the substance is genuine, so the lawyer reads it, recognises it as correct law, and signs. The error is in exactly the field that no one reads for meaning and everyone relies on for verification.

The third type explains why "just check the output" is weaker advice than it sounds. A lawyer verifying substance will pass a corrupted identifier. Only a lawyer verifying the identifier itself — in the court's own database — will catch it.

Why the machine invents a docket number

Understanding the mechanism is not an academic exercise; it determines which mitigations work and which are theatre.

A language model generates text by predicting what should come next given everything before it. A citation is, from the model's point of view, a highly regular pattern: a chamber, a pair of numbers separated by a slash, a date, a formulation like "in the same direction". Producing something that matches that pattern is trivially easy. Producing something that matches a record in a database is a completely different task, and nothing in the basic architecture performs it. The model is not looking anything up; it is completing a shape. A fabricated citation is therefore not a malfunction. It is the system doing exactly what it does, in a context where pattern-matching and truth happen to diverge.

This explains three things practitioners keep getting wrong:

  • Better models do not remove the risk. They reduce its frequency, which paradoxically makes it more dangerous: a tool that invents a citation once in fifty uses trains its user to stop checking.
  • Retrieval helps, but only over the corpus it actually has. Tools that search a real database before answering are substantially safer, and they are the right choice for legal work. But retrieval failure modes are subtler: the system finds a real decision, then summarises it loosely, or blends two decisions into one proposition. The Ankara pattern — real substance, wrong identifier — is exactly what a partially grounded system produces.
  • Asking the model to verify itself is worthless. "Are you sure these citations are real?" invites another generated answer, produced by the same process that generated the citations. Confidence is not a signal of accuracy.

The only reliable verification is external: the identifier, checked against the authoritative record. Everything else is a probability adjustment.

The Turkish case: Ankara, June 2026

The facts, as reported in the Turkish legal press, are worth setting out precisely, because they are more instructive than the American ones.

In a civil matter heard in Kızılcahamam, Ankara, a lawyer used a generative AI tool to strengthen a pleading with supporting authority. The tool produced what appeared to be three separate Court of Cassation decisions. The substance was not invented; the decisions were real. What the tool had done was attach incorrect file and decision numbers — and, on closer inspection, the three "different" authorities turned out to be variant citations of the same underlying decision.

The problem surfaced in open court. Opposing counsel raised the citations, a check against UYAP confirmed that the numbers as cited did not correspond to existing decisions, and the matter escalated immediately in two directions: a complaint to the Ankara Public Prosecutor's Office and a disciplinary file at the Ankara Bar Association.

The lawyer's defence has been consistent: the content of the decisions was authentic, only the identifiers were wrong; there was no intent to deceive; this was negligent reliance on a defective tool rather than deliberate falsification. He has also said publicly that he was not told which offence he was alleged to have committed. Sections of the profession have argued that opening a criminal file at all is disproportionate and cuts against the independence of defence counsel.

Both positions have force, and the case is being used — fairly — as the reference point for a debate the Turkish profession had not yet had.

What duty is actually breached?

It is worth being precise, because the public conversation keeps sliding into "lawyers should not use AI", which is neither the rule nor a workable one.

The duty breached by a fabricated citation is not a duty about technology. It is the duty that has always attached to signature: a lawyer who submits a pleading asserts that its contents have been checked. That obligation flows from the Attorneys' Act and the profession's rules on diligence and dignity, and from the general duty of the parties to conduct proceedings honestly. Nothing about it is new. What is new is a tool that manufactures material which looks exactly like the product of research and is produced in seconds, at a volume that makes cursory checking feel sufficient.

The criminal question is harder and, in my view, has been reached too quickly. Turkish criminal law contains offences addressed to the use of false documents and to false statements made in the course of official processes. Whether a pleading carrying an incorrect citation number fits any of them is genuinely doubtful: there is a real question about whether a pleading is a document of the relevant kind, and a much larger question about intent. An offence built on deception requires deception. A lawyer who reproduces the correct legal content and is himself deceived by the tool about the identifier is, on any ordinary reading, closer to a victim of the tool than to its accomplice — although a lawyer who continues to rely on a source he knows to be unreliable is somewhere else on that spectrum.

The disciplinary question is the one that actually matters, and it is more straightforward. Diligence is the standard. A lawyer who files unverified authority has fallen below it, whatever produced the error. That is where this case belongs.

What courts elsewhere are actually doing

The sanctions practice has matured into a recognisable ladder, and knowing where a given failure sits on it is now part of professional risk management.

  • Correction and warning. Still the most common outcome, particularly on a first occurrence with prompt disclosure. It leaves no financial trace and often no public record — which is why the true incidence is far higher than any database shows.
  • Costs and modest fines. The routine tier. Recent examples from the database include roughly $8,000 in Booker v. Kroger in late August 2026, $5,000 in a New Mexico criminal appeal, and $3,000 in Beus Gilbert PLLC v. BYU on 9 September 2026. In California on 15 September 2026, a lawyer acting for State Farm was reported to have been fined $999.99 after seven fabricated citations appeared in filings — a sum that reads as deliberately symbolic.
  • Substantial sanctions. Sixth Circuit practitioners paid $30,000 in March 2026. The largest US figure recorded to date is $110,204.38 in Couvrette v. Wisnovsky, spread across orders in December 2025 and March 2026.
  • Suspension. The first attorney licence suspension arrived in the first quarter of 2026. In Withers v. City of Aberdeen in June 2026, a federal judge in Mississippi suspended two lead attorneys from practice in the district for two years — after both sides had filed hallucinated citations — and cancelled the trial.
  • Annulment of the decision itself. The most severe consequence is not a sanction on the lawyer at all. Where fabricated material has entered a judgment, the judgment is exposed. Reported Indian practice this year has treated the presence of AI-invented authority in a ruling as a ground for setting it aside regardless of how material the fabrication was to the outcome.

Two features of this ladder deserve emphasis. The monetary tiers are not really about money — $999.99 does not deter a firm acting for an insurer. They are about the published order, which is searchable, permanent and attached to a named lawyer. And the trajectory is unmistakably upward: the profession's grace period, during which courts treated this as an unfamiliar technology problem, is over.

Türkiye's soft-law answer: the TBB guide

On 28 August 2026 the Union of Turkish Bar Associations published a recommendation guide on the use of artificial intelligence by lawyers. It is advisory rather than binding, but it is the first structured statement of professional expectations in Turkish, and disciplinary boards will reach for it.

Its architecture is a four-tier risk model:

  • Unrestricted use — general legal research and anonymised planning work.
  • Limited or controlled use — drafting, anonymised summaries.
  • Restricted use — sensitive files, requiring closed systems and KVKK-compliant configuration.
  • Prohibited — transferring client data to unsecured systems, and making legal decisions without human oversight.

Around that model sit the principles that matter in practice. Before adopting a tool, a lawyer is expected to establish where data is stored, whether it leaves the country, which sub-processors are involved and how long material is retained — the same due-diligence questions we set out in our guide to KVKK and AI governance. Generated content, and case law in particular, must be validated before it goes to a court. Certain uses require the client's informed consent. Final judgment cannot be delegated. And — a point that will surprise some firms — efficiency gained from AI cannot be billed as attorney time, and general technology costs should not be passed to clients without agreement.

The guide has been criticised, in my view correctly, on three grounds. It blends recommendation and obligation, using the language of prohibition without identifying the legal source of the prohibition. It is largely silent on agentic systems that execute multi-step tasks autonomously, which are already in use. And it says nothing useful about prompt-injection risk or about verifying deepfaked evidence — problems that arrived before the guide did.

The other direction: when the court uses the tool

The discussion is almost entirely about lawyers, which is a blind spot. Judges and court staff face the same pressure, with none of the adversarial checking that catches a lawyer's error.

Turkish practice has already produced an early example on the responsible end of the spectrum: an Istanbul commercial court that used AI tools as a calculation and document-verification aid while keeping the decision itself firmly human. That is the right model — the tool touches arithmetic and cross-checking, not reasoning, and its output is verifiable by inspection.

The failure mode on the other end is more serious than any lawyer's misstep. A fabricated citation in a pleading is caught by the opponent. A fabricated citation in a judgment is caught by nobody until appeal, and it carries the authority of the court. This is why the annulment remedy has emerged: it is the only response proportionate to the damage. Turkish courts have no standing rule on judicial use of these tools, and the gap should be filled before an incident rather than after one. We examined the wider question of how administrative and judicial decision-making absorbs algorithmic error in our report on the intersection of administrative law and AI.

The people who are not lawyers

A significant share of the recorded cases does not involve lawyers at all. It involves litigants representing themselves, who asked a chatbot what the law was and filed the answer.

This deserves more attention than it gets, because the professional framing — diligence, signature, discipline — has no purchase on it. A self-represented litigant owes no professional duty, carries no insurance, and faces no bar. What they face instead is a struck-out claim, a costs order, and the loss of a case that may have been meritorious before the fabricated authority discredited it.

There is an uncomfortable access-to-justice observation underneath. These are, overwhelmingly, people who could not afford representation and reached for the only advisor available to them at three in the morning. The tool gave them a document that looked exactly like what a lawyer produces. The result is that a technology marketed as democratising legal knowledge is, in this particular channel, producing a new way for unrepresented people to lose.

The mitigations here are not professional rules but design and institutional ones: consumer-facing assistants that refuse to produce citations for court use, or attach a visible warning; court self-help services that tell litigants explicitly that AI-generated authority must be verified; and clerks empowered to flag rather than file. None of this is in place anywhere, and it will matter more, not less, as the tools improve.

The economics that produce the error

It is tempting to read two thousand cases as two thousand instances of carelessness. That is too easy, and it will not fix anything.

The work that produces fabricated citations is almost always the same kind of work: a filing under time pressure, on a matter whose fee does not support hours of research, done by whoever is available. The tool arrives precisely into that gap. It converts an hour of database work into ninety seconds of drafting, and — this is the part that matters — it produces output whose quality signals are indistinguishable from good work. A hurried lawyer cannot tell by looking that the authority is invented. That is a different situation from every previous shortcut available to the profession.

Which means the remedy is structural rather than moral. Firms that respond to this by telling people to be careful will keep having the problem. Firms that respond by making verification a named step, allocating time to it, and refusing to let citations enter documents from a chat window will not. The same logic applies to fee structures: work priced so that research is unaffordable is work that will be done by a tool, and the pricing decision is therefore a risk decision.

Why detection is unevenly distributed

A fabricated citation is caught in one of three ways: an alert opponent, a diligent clerk or judge, or a database check. Each depends on resources, and the distribution of those resources is not neutral.

A well-resourced firm on the other side will check every authority. A litigant in person will not. A commercial court with a heavy docket may not. The result is a quiet inequality: fabricated authority is most likely to survive precisely where the opposing party is weakest — in small-value civil disputes, in enforcement proceedings, in matters where one side is unrepresented. The published sanctions cases are disproportionately drawn from large commercial litigation not because that is where the problem is worst, but because that is where it is found.

For Türkiye there is a structural mitigation worth naming: UYAP makes verification genuinely fast. A citation check that takes a British solicitor a subscription database and several minutes takes a Turkish lawyer a query. The Ankara case was resolved in open court in minutes for exactly this reason. That is an advantage, and it raises rather than lowers the standard of diligence that can fairly be expected here.

Who pays: liability and insurance

Beyond sanctions, three exposures follow a fabricated citation, and firms have thought about almost none of them.

  • The client's claim. If a case is lost, a filing struck out, or costs awarded because authority was fabricated, the client has a straightforward professional-negligence claim. The defence that "the tool did it" is not available: the duty is the lawyer's.
  • Professional indemnity cover. Policies written before 2024 do not contemplate this scenario. Whether a sanction is covered at all depends on whether it is characterised as a penalty (usually excluded) or as loss; and insurers are beginning to ask about AI use at renewal. Firms should expect underwriting questions and, in time, conditions.
  • The vendor. The obvious target — the provider whose tool invented the citation — is the hardest. Terms of service disclaim accuracy warranties comprehensively and almost always require professional verification. A claim against a provider would have to be built on specific representations made in marketing to the legal profession, which is a narrow and untested path but not an empty one, particularly where a product is sold as a legal-research tool rather than a general assistant.

A verification protocol that actually works

Advice at the level of "check the output" has demonstrably failed, because it does not tell anyone what to check or who is accountable. A protocol that survives contact with practice looks like this.

  • Separate the tasks the tool may do from the tasks it may not. Structuring an argument, summarising a document you supply, improving language: low risk. Producing authority: high risk. The rule should be that no citation enters a document from a generative tool — citations come from the database, always, and the tool's role is limited to suggesting what to look for.
  • Verify the identifier, not the substance. Open the decision in UYAP or the subscription database and confirm the chamber, the file number, the decision number and the date. Reading a summary that sounds right is not verification; it is the failure mode of the Turkish case.
  • Read the passage you are relying on. The second failure mode — a real case described as holding something it does not — is caught only here.
  • Mark AI-assisted passages during drafting. An internal convention that flags generated text until it has been checked, and a rule that the flag must be gone before filing.
  • Name a reviewer. In any matter handled by more than one person, verification of authority should be an allocated task with a name attached, not a diffuse expectation.
  • Keep the prompt and the output. If something goes wrong, the ability to show the court exactly what happened is the difference between negligence and suspected deception. The Ankara lawyer's position would be considerably stronger with a preserved record.
  • Configure the tool. Disable retention where the provider allows it, use enterprise rather than consumer accounts for client material, and do not paste identifying case details into a general assistant at all — the KVKK analysis here is the same one that applies to any other transfer, as we set out in training data: the KVKK and GDPR questions to settle first.
  • Write it down. A firm-level AI use policy converts all of the above from good intentions into an auditable rule; our guide to a corporate AI use policy provides a starting framework.

Three years in: how the profession got here

The starting point is now well known. In 2023, in a New York personal-injury case, a lawyer filed a brief containing several decisions that did not exist, having asked a chatbot for supporting authority and then asked the same chatbot whether the cases were real. The court's response — sanctions, and a published opinion written in the register of disbelief — made the incident famous, and for about a year the profession treated it as a cautionary tale about one person's foolishness.

That framing was comforting and wrong, and the database curve proves it. If the phenomenon were about individual foolishness, publicity would have suppressed it. Instead the numbers accelerated as adoption spread, which is the signature of a systemic failure rather than an anecdotal one.

The judicial response has passed through three phases. First, astonishment: early orders spent paragraphs explaining what a language model is. Then, exasperation: courts began noting that the profession had been warned, and sanctions moved from symbolic to substantial. Now, routine: the recent orders are short, the technology is no longer explained, and the question has narrowed to whether the failure was negligent or dishonest — and whether it was disclosed before it was discovered.

Türkiye entered this sequence at the second phase rather than the first, which is an advantage. The Ankara case arrived into a profession that already knew the risk existed. That is precisely why the disciplinary framing is available and the criminal one is not necessary.

What clients should be asking

General counsel and individual clients are the missing actor in this discussion. They pay for the work, they carry the consequence of a lost case, and almost none of them ask about it.

  • Do you use generative AI on my matter, and for what? The answer "no" should now be met with mild scepticism; the useful answer describes which tasks.
  • Where does my confidential information go? Consumer accounts, retention settings and cross-border transfer are the substance of this question, not the branding of the tool.
  • Who verifies authority before filing, and how? A firm that cannot name the step does not have one.
  • Does your professional indemnity cover AI-related errors? Worth asking before the engagement rather than after the order.
  • Is efficiency being passed on? If a task that took three hours now takes twenty minutes, the billing arrangement should say what happens to the difference — a point the TBB guide makes explicitly.

For corporate clients there is a neat symmetry here: these are the same questions their own procurement teams ask AI vendors. Applying them to outside counsel is not adversarial; it is consistency.

What courts and regulators should do

The profession cannot solve this alone, and three interventions would do most of the work.

A certification requirement. Several American courts now require a signed statement that any AI-assisted filing has had its authority verified by a human. This is cheap, it changes nothing for the careful, and it converts a vague duty into a specific representation with consequences. A rule of court of this kind, or a uniform practice direction, would be the single most effective step available in Türkiye.

A published escalation policy. The Ankara case became a crisis partly because nobody could say what the consequence of a fabricated citation was supposed to be. A bar association that states in advance how first, repeated and dishonest incidents will be treated gives its members a standard and its boards a framework.

Guidance for judicial use. Rules for lawyers without rules for courts leave the more dangerous half of the problem unaddressed. Judicial guidance should distinguish permitted uses — summarisation of a file, arithmetic, translation, document comparison — from the drafting of reasoning and the sourcing of authority.

The broader legislative agenda is moving in this direction anyway, through the AI Action Plan's governance architecture and the draft bills before parliament that we analysed in our study of the draft Turkish AI Act. But none of the three steps above requires legislation, and waiting for a statute is the wrong instinct where a practice direction would do.

What to watch next

Four things. Whether the Ankara prosecutor's file results in a charge, which would set the tone for how Turkish criminal law treats this class of error. Whether the TBB guide is upgraded from recommendation to a binding professional rule, or is cited by a disciplinary board as if it already were. Whether the sanctions curve abroad keeps climbing or flattens as verification practices settle. And whether the first Turkish judgment containing a fabricated citation surfaces — because on current trajectories it is a question of when, and the appellate response to it will matter far more than any sanction against a lawyer.

Frequently asked questions

Is it professional misconduct to use AI in legal work?

No. Neither the TBB guide nor any Turkish rule prohibits it. What is sanctionable is filing material that has not been verified — a duty that predates the technology entirely.

What exactly went wrong in the Ankara case?

The tool reproduced genuine Court of Cassation decisions but attached incorrect file and decision numbers, and presented what were in substance variants of a single decision as three separate authorities. Opposing counsel raised it in the hearing and a UYAP check confirmed the numbers did not exist as cited.

Can a lawyer be prosecuted criminally for this in Türkiye?

A file was opened in the Ankara case, but whether any offence fits is genuinely doubtful, above all because offences of this kind require intent to deceive. Negligent reliance on a defective tool is, in my view, a disciplinary matter rather than a criminal one.

Is the TBB guide binding?

It is advisory. But advisory professional guidance is routinely treated by disciplinary boards as evidence of the applicable standard of care, so its practical weight exceeds its formal status.

What is the largest sanction imposed so far?

The highest recorded US figure is $110,204.38 in Couvrette v. Wisnovsky, across orders in December 2025 and March 2026. Suspensions, such as the two-year district suspensions in Withers v. City of Aberdeen, are the more serious professional consequence.

What happens if a judgment itself contains a fabricated citation?

It becomes vulnerable on appeal. Reported practice in India this year has treated the presence of AI-invented authority in a ruling as a ground for setting it aside, irrespective of how central the fabricated material was.

Does professional indemnity insurance cover this?

It depends on the policy and on whether the amount is characterised as a penalty or as loss. Firms should raise it with brokers at renewal rather than discovering the answer after an order.

Which tools are safe to use for case law?

The question is framed wrongly. No general-purpose assistant should be the source of a citation. Databases are the source; the assistant's legitimate role is to help you decide what to search for and to explain what you have found.

Burhan Doğuş Ayparlar's View

This section sets out my personal assessment as the founder of this site and an AI ethics & compliance counsel.

My first reaction to the Ankara case was that the criminal file is a mistake. Not because lawyers deserve special protection, but because the conduct does not match the offence. Criminal provisions addressed to falsity require someone to intend the falsity. What happened here is that a machine produced a correct legal proposition attached to an incorrect number, and a professional failed to check the number. That is negligence, and negligence has a forum: the bar. Reaching for the prosecutor in a case like this teaches the profession the wrong lesson — it encourages concealment rather than disclosure, and the single most valuable behaviour in this entire problem is a lawyer who notices the error and tells the court before the opponent does.

My second reaction is that the profession has been treating this as a technology story when it is a discipline story. Two thousand cases in three years is not a story about models. Models produce plausible text; that is their function, and no amount of improvement will make an unverified citation safe to sign. The story is about a signature culture in which checking authority became optional because everything looked authoritative. The lawyers being sanctioned in Ohio and Ankara and Tel Aviv did not fail at using AI. They failed at the oldest obligation in the job.

What worries me most is not the pleading; it is the judgment. The asymmetry is stark: a fabricated citation in a brief meets an adversary, while a fabricated citation in a ruling meets nobody. We have no rule in Türkiye on how courts may use these tools, and we will not have one until something goes publicly wrong. I would rather we wrote it now, and I would keep it simple: permitted for arithmetic, translation, summarisation and comparison; not permitted for reasoning or for sourcing authority.

On the TBB guide, I think its publication was the right call and its content is a reasonable first draft, but it has the weakness of most soft law — it speaks in the language of obligation while being unable to impose any. My preference would be a short, binding rule about verification and a certification line in the pleading, plus a published escalation policy so that members know what a first incident costs. That combination is enforceable, proportionate and, unlike a prosecution, aimed at the behaviour we actually want.

And one practical note for colleagues, because it is the habit that would have prevented every case discussed here: never let a citation enter a document from a chat window. Let the tool tell you what to look for. Get the citation from the database, open the decision, read the paragraph you are relying on, and then sign. It takes two minutes, and those two minutes are the whole of the professional duty at stake.

This article is for information only and does not constitute legal advice. Case counts and sanction figures are drawn from the publicly maintained AI Hallucination Cases database (Damien Charlotin) as at 14 September 2026 and from press reporting; individual figures may be superseded. The Ankara matter is described on the basis of Turkish legal-press reporting of June 2026; investigations were reported as open and no finding of wrongdoing is implied. Statements about Turkish criminal, professional and civil law are general in nature and specific cases require individual assessment. The analysis and assessments are the author's own.