Grammarly Put Real Journalists' Names on AI Writing Advice They Never Gave
What happened
Grammarly built a feature called Expert Review that offered users editing suggestions attributed to named journalists, authors, and academics. The advice appeared under those individuals' names as if they had personally reviewed the user's writing. None of them had. A federal class action filed by journalist Julia Angwin in early 2026 alleged that Grammarly was using a large language model to generate the suggestions and then attaching real people's identities to the output without their consent or any compensation.
The product design was straightforward in its mechanics and pointed in its effect. A user submitting text for review would receive feedback presented as coming from a specific named expert, someone whose published work and public reputation lent weight to the suggestion. That framing was the commercial value of the feature. Grammarly was not just selling AI-generated editing advice; it was selling advice with a real name attached to it, a name the named person had not authorized for that purpose.
Angwin's lawsuit, filed as a federal class action, argued that Grammarly had misappropriated identities for commercial gain and attributed professional advice that the named individuals never actually gave. The class framing suggested the problem was not isolated to one or two careless choices about whose name to use. It implied a systematic practice of pulling real credentials into a product to make machine output appear more credible and authoritative than it could stand on its own.
The consent gap here is not incidental. Grammarly's business model for the feature depended on the credibility those names carried, which is exactly the credibility those individuals had built through years of their own professional work. Using that credibility without their knowledge, and without offering them any control over what advice was being attributed to them, converted their reputations into a product feature they had no stake in and no power to correct or withdraw.
A case like this points directly at a record-keeping gap that sits beneath many AI product decisions. There is no required log of which real names were used in which product context, what output was attributed to them, and whether any of those individuals were ever notified. Without a provable record of what a system did and under whose name it did it, the people whose identities were borrowed have no way to assess the scope of the use, and regulators have no baseline to evaluate what redress looks like.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.