Editor’s Note: A disciplinary tribunal in London has removed a lawyer from the register of foreign lawyers over legal authorities that generative AI invented, and those authorities sat in his defense against the regulator prosecuting him. When the regulator’s counsel flagged the errors, he answered with an email he had also drafted using AI, and that email carried further false material. The Solicitors Disciplinary Tribunal says this is the first time a lawyer’s use of AI in legal proceedings has been litigated before it.

Professionals in cybersecurity, data privacy, regulatory compliance and eDiscovery should read the culpability findings rather than the headline. The tribunal weighed both how Kumar began using AI and what he did once the errors were identified, and it gave very substantial weight to the repetition. The same distinction runs through incident-response practice, where the handling of a defect is judged separately from the defect.

Watch the referral route. Courts on both sides of the Atlantic have referred AI citation failures to regulators, though no court referred Kumar; the SRA was already prosecuting him. The Solicitors Regulation Authority (SRA) said it received 42 reports of potential AI misuse in the year to July 2026, with investigations underway.


Content Assessment: A lawyer fed AI citations to his own regulator, and the tribunal struck him off

Information - 93%
Insight - 94%
Relevance - 94%
Objectivity - 93%
Authority - 92%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "A lawyer fed AI citations to his own regulator, and the tribunal struck him off."


News Analysis – Artificial Intelligence Beat

A lawyer fed AI citations to his own regulator, and the tribunal struck him off

ComplexDiscovery OÜ Staff

The Solicitors Disciplinary Tribunal for England and Wales has struck a lawyer from the register of foreign lawyers over AI-fabricated authorities, which he filed in his own defense against the regulator prosecuting him. When the regulator’s counsel flagged the errors, Abhishek Kumar answered by email. He had drafted that email with generative artificial intelligence as well, and it carried fresh false material.

The tribunal published its record of the case on Sept. 3, and it is the first of its kind in that forum. “This was the first time that a lawyer’s use of artificial intelligence or large language models in legal proceedings had been litigated before the Tribunal,” the tribunal said in its published case summary. The panel heard the matter on July 29 and dated its judgment Aug. 25.

For anyone running an eDiscovery workflow, an information governance program, or a security function that leans on machine output, the decision matters less for its novelty than for what the tribunal refused to accept as an excuse.



Two allegations, one sanction, no dishonesty alleged

That refusal came in two parts, because the tribunal had two allegations in front of it and only one of them involved a machine.

Kumar is 41 and was registered as a foreign lawyer in December 2018. The Solicitors Regulation Authority’s first allegation against him reaches back to 2020, long before any question of AI arose. On Aug. 19 that year, he knowingly employed an adult who was disqualified from working because of immigration status, conduct that produced a conviction on Jan. 29, 2024, under Section 21(1) and (2) of the Immigration, Asylum and Nationality Act 2006. He was sentenced to a 12-month community order and 150 hours of unpaid work. His original plea was not guilty, Kumar told the tribunal, and he changed it under the weight of severe physical and mental ill health, according to Legal Futures, which reported the judgment.

The second allegation arrived while he was defending the first, and it arrived because of how he chose to defend it. Kumar represented himself. The tribunal’s summary says he filed submissions and correspondence containing “incorrect, fabricated, misleading or unsupported authorities, quotations and legal propositions arising from the use of generative artificial intelligence (AI),” first in an answer dated March 12, 2026, then again in an email to the regulator on April 9.

Both allegations were proved, and the tribunal struck him from the register on each. It said the sanction would have been the same had either allegation come before it alone. One detail deserves attention from anyone reading this as a story about deception: dishonesty was not alleged on either count. He was struck off regardless, and the tribunal’s culpability reasoning rested on both the way he began using AI and what he did once the errors were pointed out.

Where the fabricated authorities appeared

Kumar did not put invented cases before a court on a client’s behalf. He put them in his answer to the regulator’s allegations against him, in proceedings where his own registration was the thing at stake.

Then he did it twice. When the SRA’s counsel identified the incorrect quotations and citations, Kumar replied by email admitting he had used generative AI on the answer. That reply was itself AI-drafted and carried further false material, a sequence the tribunal weighted heavily because he repeated the conduct after the problem had been explained to him.

His explanation is the part practitioners will recognize. He denied intending to mislead and said he “simply did not have the expertise to verify the AI output,” according to Legal Futures’ account of the judgment. He called himself an unqualified lawyer who was used to being supervised, and argued that Ayinde, the leading judgment on lawyers’ misuse of generative AI, did not reach him because he was a registered foreign lawyer rather than a solicitor.

The tribunal did not otherwise accept those submissions. Deceit and dishonesty were not in issue, so it made no finding on whether he meant to mislead, but on the rest it went against him. He was a person the SRA regulates, it held, and the standards of his profession bound him accordingly. It found breaches of Principles 1, 2 and 5 and paragraph 1.4 of the code, and found the paragraph 2.4 breach proved in part, in respect of two authorities he had cited for propositions they did not support.

What gives the exchange its weight is where it was offered. A claimed lack of expertise, tendered in mitigation to the body deciding whether you keep your regulated status, is an argument about competence. The tribunal did not treat it as an answer. It was careful, though, about which citation failures it was willing to call misconduct.

The line between a typo and a fabrication

The second allegation was proved “in respect of the citing of non-existent cases and incorrect legal propositions.” The tribunal then drew the boundary practitioners should carry away: “Typographical errors in case citations were not sufficiently serious to amount to misconduct.”

That is a workable standard rather than a slogan. A mistyped year in a real citation is an error. A case that does not exist, or a real case cited for a rule it never announced, is a submission the lawyer had no basis to make. The tribunal also observed that on a case-by-case basis, harm and culpability may differ between citing authorities that never existed and supplying incorrect citations to real ones, which leaves room for proportionality in the next case. American courts have been circling the same distinction, and reaching past their own sanction powers to do something about it.

Courts are routing these cases to regulators

The Illinois Appellate Court fined an attorney $1,500 for each false citation and quotation in July, a total of $15,000, in Scott v. Illinois Human Rights Commission. The court counted 10 of them: four false statutory quotations, one case that does not exist, and five real cases that do not say what they were cited for. It directed its clerk to send the opinion to the Illinois Attorney Registration and Disciplinary Commission. Fines will have to keep climbing before they deter, the court said, and it had considered ordering continuing legal education before concluding the governing rule may not authorize it, which is a court finding the edge of its own toolkit.

That breakdown is the same taxonomy the London tribunal used, and the lawyer’s explanation was close to Kumar’s. Mason Cole told the Illinois court he had cross-referenced his citations and overlooked the problems, and put his inability to verify them down to inexperience in appellate practice. His response to the court contained further errors of its own.

Maryland’s appellate court weighed the same question on Aug. 25 and went the other way. It declined to refer counsel to the Attorney Grievance Commission in Benjamin v. State, giving four reasons: the brief predated the state’s leading decision on AI in briefs, the inaccuracies were not excessive and included no fabricated cases, counsel tried to correct them before the state filed, and the state claimed no harm. That opinion is unreported and cannot be cited as precedent, though Maryland’s rules allow it to be cited for persuasive value, and its reasoning tracks the London tribunal’s own line on the same point.

The referral is one route, and Kumar’s case did not travel it. The Illinois opinion surveys what other courts have done and finds referrals recurring alongside fines, in earlier Illinois cases and in the Seventh Circuit. Ayinde told courts in England and Wales that a reference to the regulator is likely to be appropriate where false citations reach them, and the SRA’s warning notice cites that passage. No court referred Kumar. The SRA was already prosecuting him over his conviction when the AI allegation was added, which is a second and shorter path to the same regulator. His case shows what a disciplinary outcome can look like, not where every referral ends. Disciplinary outcomes are not unprecedented either, and the tribunal did not claim otherwise. Colorado’s presiding disciplinary judge suspended Zachariah Crabill in November 2023 for a year and a day, with 90 days to be served and the balance stayed on two years of probation, after Crabill cited ChatGPT-generated authorities and then blamed the errors on a legal intern. What distinguishes Kumar is the endpoint and the absence of any dishonesty allegation behind it, and that endpoint did not arrive unannounced.

Verification is a control, not a courtesy

British regulators had been under pressure to act for over a year. The High Court in Ayinde had asked the legal regulators to consider urgently what steps beyond guidance were needed, according to the tribunal’s summary. The SRA published a warning notice on the misuse of AI on Aug. 17, eight days before the tribunal dated this judgment. The notice reaches every firm and individual the SRA regulates, and its position is that reliance on AI output would not be a suitable defense.

Sequence matters here. Kumar’s conduct in March and April 2026 predates that notice, so it was not the standard he was measured against, and the judgment cites earlier SRA material instead, including compliance guidance issued in February 2026. Aileen Armstrong, SRA executive director for strategy and policy, said in the announcement that AI does not change the professional standards expected of solicitors and firms. Individuals stay responsible for the work they produce whether or not a tool was involved, she said.

The queue behind this case is the part worth watching. The regulator said it received 42 reports of potential AI misuse between July 2025 and July 2026, and that a number of investigations into AI misuse are ongoing. This is the first such matter to reach the tribunal, on the tribunal’s own account, and the SRA’s announcement did not say how many of those investigations might follow it there.

Why the repetition carried substantial weight

Read the culpability findings closely and the transferable lesson is not about citations. The tribunal relied on both how he began and how he responded. It found he had embarked on AI use without proper thought to the consequences and had not taken steps to check that his output was accurate, and it gave very substantial weight to the repetition after the errors were identified and explained, treating that as a persistent lack of insight.

Security and governance professionals will recognize the structure, because incident response is commonly assessed the same way: the defect draws a finding, and the handling of it shapes the severity. A team that ships a bad artifact and corrects it cleanly stands somewhere different from a team whose correction reproduces the defect. That framing is the analogy, not the tribunal’s test. What the tribunal did was weigh both limbs and put very substantial weight on the second.

The practical translation is unglamorous. Treat citation and source validation as a logged step with a named owner, not as something a competent person is assumed to have done. Keep the record of what was checked and when, because it is the difference between a controlled process and a confident one. And write any response to a flagged AI defect as though it will be read as evidence of whether the control works, because in this case it was.

Kumar argued that a suspension would be proportionate and that he had a right to be forgotten. The tribunal struck him off the register, and the SRA, accepting that he could not pay, did not seek costs. The sanction was removal from the register, and the findings behind it are published.

If a regulator asked your organization tomorrow to show its work on a single AI-assisted output, could you produce the verification record, or only the person who was supposed to keep it?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).