AI Governance
AI-Generated Evidence and Lawyer Liability: What the New Mexico Case Means for European Law Firms
A New Mexico court sanctioned a lawyer after an AI-assisted filing contained fabricated testimony. The case signals a broader challenge for European law firms: keeping AI-assisted legal work verifiable, confidential and under professional control.

Complex law. Clear action.
Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.
Generative AI is rapidly becoming part of everyday legal work. But a recent case before the New Mexico Supreme Court demonstrates where the boundary between technological assistance and professional responsibility remains remarkably clear.
On 9 September 2026, the New Mexico Supreme Court held attorney Stephen Aarons in direct contempt and imposed a $5,000 sanction after an appellate brief in a murder case contained testimony attributed to witnesses who did not exist.
This was not the now-familiar problem of AI-generated citations to fictitious cases.
The AI had invented parts of the evidentiary record itself.
The case provides an important warning for lawyers, law firms and other regulated professional organisations using generative AI: AI can assist professional work, but responsibility for the resulting work product remains human.
From AI assistance to fabricated evidence
Aarons represented Oscar Renee Sandoval in an appeal against a murder conviction and life sentence.
While preparing the appeal, the lawyer provided ChatGPT with a computer-generated transcript of the trial and other case materials. According to the court record, he expected the system to produce what he described as a “bulletproof summary.”
Instead, the resulting appellate brief contained serious factual inventions.
The filing included testimony attributed to four wholly fabricated witnesses, as well as fabricated testimony attributed to real witnesses and inaccurate representations of legal authorities.
The critical failure, however, occurred after the AI produced the material.
The lawyer filed the brief without independently verifying the AI-generated factual and legal claims against the underlying record.
The New Mexico Supreme Court responded with significant sanctions. It held Aarons in direct contempt, imposed a $5,000 sanction, referred the matter to the state Disciplinary Board, barred him from appearing before the Supreme Court pending that process, struck the existing briefs and appointed the public defender to take over the appeal.
The order itself is nonprecedential.
Its significance nevertheless extends well beyond this individual case.
The problem is no longer hypothetical
For several years, courts have encountered lawyers submitting AI-generated material containing fictitious judicial decisions, incorrect quotations and nonexistent authorities.
The scale of the problem is now becoming clearer.
On 17 September 2026, Reuters reported that a researcher tracking AI-related court errors had identified them in at least 1,395 U.S. state and federal cases.
A day later, another development pointed towards a possible institutional response.
The U.S. Court of Appeals for the Tenth Circuit proposed a rule requiring lawyers and self-represented litigants using generative AI to certify that the resulting filing had been reviewed by a human for accuracy and truthfulness.
The proposal remains subject to the rulemaking process.
Together, these developments indicate an important shift.
The legal discussion is moving beyond the question of whether lawyers may use generative AI.
The emerging question is how professional organisations must control, verify and document its use.
Professional responsibility does not transfer to the AI system
The underlying principle is straightforward.
Using an AI system does not transfer the lawyer's professional obligations to the technology provider or to the model itself.
The American Bar Association's Standing Committee on Ethics and Professional Responsibility addressed this directly in Formal Opinion 512, examining lawyers' use of generative AI through existing professional obligations including competence, confidentiality, communication, supervision and candour toward tribunals.
The technology may change.
The professional responsibility does not.
This distinction becomes particularly important where AI is used to analyse evidence, summarise testimony, prepare pleadings or generate legal authorities.
A plausible AI output is not necessarily a verified output.
For high-consequence legal work, therefore, the relevant control is not simply whether a human has read the generated text.
The question is whether the material has been verified against authoritative source material.
The European dimension
The Sandoval case arises under U.S. law, but the governance problem is directly relevant to European legal practice.
The Council of Bars and Law Societies of Europe (CCBE) identifies professional competence and confidentiality as central considerations when lawyers use generative AI.
Its guidance recommends verification of GenAI output where required by the relevant use case and warns that using AI-generated content without appropriate verification may expose lawyers to professional sanctions, contempt proceedings, malpractice claims and harm to their clients' interests.
European law adds another regulatory layer.
AI literacy under the EU AI Act
Article 4 of Regulation (EU) 2024/1689 — the EU AI Act — requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf.
Those measures should take account of technical knowledge, experience, education and training, as well as the context in which the AI systems are used.
The current text also clarifies that the obligation does not require providers or deployers to guarantee any specific level of AI literacy of an individual.
Article 4 should not be interpreted as establishing a specific obligation to manually verify every AI-generated legal document.
But it changes the organisational context in which professional AI use must be considered.
A law firm allowing personnel to use generative AI for client work without appropriate understanding of hallucination risks, confidentiality implications, verification requirements or the limitations of particular AI systems may therefore face a broader governance question:
Were appropriate organisational measures in place to support competent and responsible use of AI?
The second risk: client data
There is another aspect of the New Mexico case that deserves particular attention.
The lawyer provided ChatGPT with a computer-generated trial transcript and other case materials.
For a European law firm, an equivalent workflow could immediately trigger additional questions.
What information is being uploaded?
Does it contain personal data?
Does it include special-category data or data relating to criminal convictions and offences?
Is the information protected by professional secrecy or contractual confidentiality?
For what purposes may the AI provider process it?
Can the provider retain the information?
Can it be used for model improvement?
Where is the information processed?
Has the organisation approved that particular AI environment for the relevant category of client information?
These questions arise before the accuracy of the AI-generated output is even considered.
The CCBE therefore treats confidentiality as a core concern and identifies safeguards that may include contractual confidentiality protections, appropriate data-processing arrangements, zero-data-retention configurations and controlled or local AI environments.
For European professional organisations, AI governance consequently has at least two distinct dimensions:
Input governance — what information may enter an AI system and under what conditions.
Output governance — how AI-generated material is verified before it influences professional advice, decisions or filings.
Both matter.
“Human in the loop” is not enough
Simply stating that a human remains “in the loop” does not resolve the problem.
A lawyer can read an AI-generated document and still fail to detect fabricated facts.
The relevant control therefore needs to be more structured.
For high-consequence legal work, a defensible workflow can be expressed as:
Source → AI processing → source verification → professional review → approval → filing
Each stage performs a different function.
The source establishes the authoritative factual or legal basis.
AI processing assists with analysis, summarisation or drafting.
Source verification checks generated claims against the underlying material.
Professional review assesses their legal relevance, accuracy and implications.
Approval establishes responsibility for the final work product.
Only then should the material be communicated externally or filed.
The same principle can extend beyond litigation to regulatory submissions, due diligence, investigations, contract analysis and compliance assessments.
What law firms should do now
The appropriate response is not necessarily to prohibit generative AI.
Used appropriately, AI can significantly improve legal research, document analysis and drafting efficiency.
The stronger approach is to establish controls proportionate to the consequences of an error.
Professional organisations using generative AI should consider:
defining which AI systems are approved for client work;
classifying what client and confidential information may be uploaded;
establishing source-verification requirements for factual and legal claims;
introducing enhanced controls for litigation, regulatory submissions and other high-consequence work;
documenting responsibility for final review and approval;
training personnel on hallucination risks, confidentiality and appropriate AI use; and
periodically reviewing whether actual AI use corresponds with internal policies, professional duties and contractual obligations.
The objective is not simply AI compliance.
It is maintaining evidentiary integrity, confidentiality and professional accountability while obtaining the productivity benefits of the technology.
CORVUS Legal Signal
The New Mexico case illustrates a broader transition.
The first phase of professional GenAI adoption focused on whether lawyers could use the technology.
The next phase is about control.
Courts, professional bodies and regulators are increasingly concerned not merely with whether AI was involved, but with whether organisations can demonstrate that its use remains subject to appropriate professional and organisational safeguards.
The emerging principle is simple:
AI output is not evidence.
AI output is not legal authority.
AI output is not professional judgment.
AI can accelerate legal work.
It cannot replace professional responsibility.
For law firms, the strategic question is therefore no longer simply:
Can our lawyers use generative AI?
It is:
Can we demonstrate that AI-assisted legal work remains verifiable, confidential and under effective professional control?
That distinction will increasingly define defensible professional use of AI.
Disclaimer
This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.
It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.
The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.
To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.
AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.
For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.
Sources
New Mexico Supreme Court, State v. Sandoval / In re Stephen D. Aarons, No. S-1-SC-40845, Order of 9 September 2026.
American Bar Association Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, Generative Artificial Intelligence Tools, 29 July 2024.
Council of Bars and Law Societies of Europe (CCBE), Guide on the Use of Generative AI for Lawyers.
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Article 4, current consolidated text.
Reuters, AI error-ridden court filings surge despite three years of court sanctions, 17 September 2026.
U.S. Court of Appeals for the Tenth Circuit, proposed 2027 Circuit Rules concerning generative AI-assisted court filings, September 2026.
CORVUS AI
complex law. Clear action.
