Back to News & Insights
Professional Firms August 13, 2026 5 min read

The Mark Meets the Sanctions Docket

Courts sanctioned attorneys in six appellate decisions this spring over fabricated citations. Now the drafting tools have started signing their work.

Two things happened to the legal profession this year that have not yet been read together.

The first is that courts stopped treating AI-fabricated citations as a novel embarrassment and started treating them as sanctionable misconduct. The second is that the drafting tools began embedding provenance signals into their output.

Neither is a crisis on its own. Together they change what a firm should have in place.

What the courts actually did

Norton Rose Fulbright's review of generative AI sanctions in 2026 collects six appellate decisions from a single February-to-April stretch, and the range of outcomes is the instructive part.

In *Fletcher v. Experian Information Solutions*, the Fifth Circuit imposed a $2,500 sanction over 16 fabricated quotations, noting that greater candor would have reduced the penalty. In *Whiting v. City of Athens, Tennessee*, the Sixth Circuit went considerably further on a brief containing more than 24 fake citations: attorneys' fees, double costs, $15,000 in punitive sanctions against each attorney, and a disciplinary referral. In *United States v. Farris*, an attorney with a clean forty-year record who responded candidly was still removed from the case, denied Criminal Justice Act compensation, and referred for discipline.

And in *Gamez v. County of Fresno*, an attorney who gave the court a candid explanation of what happened drew no sanctions at all.

The Fifth Circuit's framing does the analytical work: modern generative AI may be new technology, but the same sanctions rules apply, and courts are well equipped to handle these cases. There is no special AI doctrine coming. Rule 11 and the duty of candor were always sufficient.

Read across the six, the pattern is not really about AI. Candor mitigates. Evasiveness aggravates, sharply. The severity tracks the response after discovery far more than the original error. The attorneys who fared worst were the ones who characterized fabricated citations as typographical errors before conceding what had happened.

The tracked case count referenced in that review exceeded 1,148 documented instances of attorney hallucinations across U.S. courts. This is no longer a handful of cautionary tales.

What changed on the tooling side

Anthropic began embedding an imperceptible watermark in text generated by Claude and signed C2PA provenance metadata in supported files, by its own documentation, with no documented opt-out and coverage across its API and applications. Other major vendors are moving the same direction under transparency requirements that took effect in the EU.

The limits matter as much as the capability. A detected mark signals that content "was processed by Claude, but is not fully conclusive." Absence of a mark proves nothing either. The signal degrades under heavy editing and paraphrasing. And the detection tools that would let a court, an opposing party, or a client read these marks are not publicly available.

So no one is running provenance analysis on your filings today. The question is what a firm wants its position to be in two years, when someone can.

The exposure is not what most firms assume

The instinctive worry is that a court will detect AI use in a brief and sanction the firm for it. That is the wrong thing to worry about. Using AI to draft is not sanctionable. Filing citations no one verified is sanctionable, and it always was.

The real exposure sits in three quieter places.

Client representations. Outside counsel guidelines and engagement letters increasingly contain AI provisions, and many were signed without much attention. A firm that certified it does not use generative AI on a matter, while associates use it routinely, has a problem that predates any watermark and is merely made more discoverable by one.

Confidentiality. This one is underrated. If a marked document originated in a consumer-tier tool rather than an enterprise deployment, the mark is downstream evidence of where client material was processed. The confidentiality question was already the more serious one. Provenance makes it harder to leave unexamined.

The unlicensed drafter. Several of the reported cases involved work produced by someone other than the signing attorney. The signature is the point. Whoever signs owns every citation in the document, regardless of who or what generated it.

What a workable policy contains

Firms that handle this well tend to have four things written down, and they fit on a page.

A verification rule with no exceptions. No citation appears in a filing unless the responsible attorney has personally read the cited authority and confirmed it says what the brief claims. This single rule resolves the entire sanctions risk, and it predates AI by decades.

An approved tool list. Which deployments are cleared for client material and which are not. Consumer accounts using client confidential information should be named as prohibited, in writing, because "everyone knew that" is not a defense.

A candor protocol. Decide now what happens when someone discovers a fabricated citation in a filed brief, including who tells the court and how fast. The case law is unambiguous that the response drives the outcome. Firms that have thought this through in advance respond well under pressure. Firms that have not tend to minimize first, which is precisely the path that turned a $2,500 sanction into a $15,000 one plus a referral.

A record of review. Who checked the authorities, and when. Not bureaucracy. The thing that lets you answer the question quickly if it is ever asked.

The honest read

The profession's anxiety about detection is somewhat misdirected. Provenance marking mostly protects careful practitioners, because it establishes a record, and a record favors people whose process would survive inspection.

What the sanctions docket shows is that courts are not punishing the technology. They are punishing unverified filings and, considerably more harshly, the instinct to obscure what happened. Both of those were career risks long before any model embedded a watermark.

A firm with a real verification rule and a real candor protocol has very little to fear from any of this. A firm relying on the fact that nobody can check is now watching that assumption develop an expiration date.

If your firm is working out where these tools fit and what the policy should say, that is the kind of question we work through with people.

Join the conversation

Straight talk welcome. Comments are moderated, no pitches, no spam.

Comments load once the Hyvor Talk Website ID is set in article.html.