A Spanish Lawyer Submitted 48 AI-Generated Citations. None of Them Were Real.
What happened
In January 2026, a lawyer practicing in Santa Cruz de Tenerife filed an appeal before Spain's Canary Islands Supreme Court. The appeal contained 48 legal citations, complete with case numbers, dates, and identifiers, all produced by a general-purpose AI chatbot. Not one corresponded to an actual ruling.
The fabrications came to light during judicial review. Checking each citation against CENDOJ, Spain's official public legal database, took little effort: every reference came back empty. The appeal, intended to strengthen the lawyer's client's position, had instead introduced 48 invented precedents into formal proceedings. Had the fabrications gone undetected, the case outcome could have been shaped by sources that simply did not exist.
The root cause was uncritical reliance on a tool not designed for legal research. The lawyer had submitted the chatbot's output directly, without verifying a single case number, date, or identifier against any authoritative source. CENDOJ would have surfaced the problem immediately. The court found no evidence that any such comparison was made before the filing was submitted. The citations went in as though they had been checked, because nothing in the workflow required that they actually be.
The Canary Islands Supreme Court fined the lawyer EUR 420 and framed the breach in terms of professional conduct, not technical misfortune. The ruling cited violations of the duty of truthfulness and good faith, improper use of public judicial services, and a failure to meet the diligence standard required by the Spanish Code of Ethics for legal professionals. The court described the fine as carrying an exemplary character, signaling that treating AI output as verified fact in a high-stakes filing would be treated as an ethical breach rather than an honest mistake.
What the incident makes visible goes beyond one courtroom. A general-purpose AI tool that produces confident-sounding legal citations carries nothing that would interrupt the path from generated output to formal submission. There is no record of what the tool produced, no built-in check against authoritative sources, and no audit trail showing whether any verification step occurred before the output was staked on a client's case. A provable record of what a system did, and what a professional did to confirm it before acting on it, would have changed the accountability question entirely. Without that record, the only available check remains a database lookup after the fact, and the only visible consequence is a fine.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.