# PIR-2026-0009 - Mata v. Avianca: first sanctions for ChatGPT-fabricated case citations in a federal filing

**Boundary case**: no agentic tool use - the failure was unverified human reliance on generative output, submitted under a lawyer's signature. Kept per batch-1 convention, flagged for definitional review.

- `id`: PIR-2026-0009
- `title`: Lawyers file a federal brief built on six ChatGPT-fabricated precedents; $5,000 Rule 11 sanction (S.D.N.Y.)
- `date_occurred`: 2023-03 (affirmation in opposition citing the fake cases filed)
- `date_detected`: 2023-03/04 (opposing counsel and the court unable to locate the cited cases)
- `date_disclosed`: 2023-05 (order to show cause and national press); sanctions opinion 2023-06-22
- `status`: corroborated (published opinion, 678 F. Supp. 3d 443 (S.D.N.Y. 2023), with docketed exhibits)

### The agent
- `agent_description`: ChatGPT used by plaintiff's counsel (Steven Schwartz, filing under Peter LoDuca's signature, firm Levidow, Levidow & Oberman) as a legal research tool in a personal-injury suit against Avianca.
- `operator_type`: individual (small law firm)
- `autonomy_level`: human-approves-each-action (all output human-submitted)
- `model_stack`: ChatGPT (early-2023 vintage; exact model unknown)
- `harness`: none (consumer chat interface)

### Authority
- `authority_scope`: none - text generation only; authority came entirely from the humans who signed the filing
- `funds_at_risk_usd`: unknown (professional exposure of counsel; not agent-held)
- `blast_radius`: one org (the firm and its client; secondary: the six real judges falsely named as authors of fake opinions)

### The failure
- `root_cause`: operator-error (primary; submission of unverified model output to a federal court; conscious avoidance once challenged); contributing plain-error (model fabricated cases, citations, quotes - and "affirmed" them when asked to confirm)
- `failure_locus`: agent-reasoning (fabricated content), harm realized through operator conduct
- `exploitation_status`: in-wild-malfunction (no adversary; real filing, real court, real sanction)
- `mechanism`: Schwartz asked ChatGPT for supporting precedents; it fabricated at least six non-existent decisions ("Varghese," "Shaboon," "Petersen," "Martinez," "Durden," "Miller") with full citations and quotes. When opposing counsel and Judge P. Kevin Castel could not find them, Schwartz asked ChatGPT itself whether the cases were real; it affirmed its own fabrications, and excerpts were filed with the court. Castel found the lawyers acted in bad faith (conscious avoidance and false statements to the court), imposed a $5,000 penalty jointly and severally on Schwartz, LoDuca, and the firm, and required them to mail the opinion to their client and to each judge falsely identified as an author.
- `adversary_present`: no

### Impact
- `severity`: loss
- `direct_loss_usd`: 5,000 (Rule 11 penalty, paid into the court registry)
- `indirect_loss_usd`: unknown (reputational and professional consequences for counsel)
- `downtime`: n/a
- `data_exposure`: none
- `controls_that_worked`: the adversarial process itself - opposing counsel's citation check and the court's verification caught the fabrications before they could infect a ruling

### Detection and recovery
- `detected_by`: third-party (opposing counsel flagged unlocatable citations; the court confirmed)
- `time_to_detect`: ~2 weeks from filing
- `time_to_recover`: ~3.5 months (filing to sanctions order and corrective letters)
- `remediation`: sanctions, corrective letters to the falsely-named judges, national disclosure
- `structural_fix`: courts nationwide adopted standing orders requiring disclosure/certification of AI use in filings; the opinion is the canonical citation for the duty to verify generative output

### Legal
- `liability_holder`: the human attorneys and their firm, jointly and severally - not the model provider; the court treated the tool's output as fully the signers' responsibility
- `precedent_set`: first prominent Rule 11 sanction for AI-fabricated citations; existing verification duties apply undiminished to AI-assisted work
- `sealed_material`: no (opinion and exhibits public)

### Evidence
- `telemetry_grade`: witnessed (published federal opinion plus docketed exhibits, including the ChatGPT exchanges entered into the record - evidence custody is the court's, not the operator's)
- `sources`:
  - https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2022cv01461/575368/54/ (sanctions opinion)
  - https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2022cv01461/575368/55/ (same-day dismissal opinion; replaces the earlier cases.justia.com direct-PDF link for the same Document 55, which could not be verified to resolve)
  - https://en.wikipedia.org/wiki/Mata_v._Avianca,_Inc.
  - https://www.acc.com/resource-library/practical-lessons-attorney-ai-missteps-mata-v-avianca
  - https://caselaw.findlaw.com/court/us-dis-crt-sd-new-yor/2335142.html
  - `independence`: strong - primary court records plus independent legal commentary.
- `aiid_incident_id`: 541 (https://incidentdatabase.ai/cite/541/) - cross-reference; primaries verified independently
- `confidence`: high (published opinion; no material weak links)

### Verification notes (corrections applied)
1. The candidate listed the loss as "$5,000 sanction + dismissal of the client's claim," implying dismissal flowed from the AI incident. Corrected: the case was dismissed in a separate same-day opinion because Mata's claim was time-barred under the Montreal Convention's two-year limit - it would have been dismissed regardless of the fabricated citations. Attributable realized loss is the $5,000 sanction (plus unquantified professional fallout); the fabricated brief failed to save an already-untimely claim.
2. "Found bad faith" verified against the opinion (bad faith, conscious avoidance, false statements) - retained.

### Corrections

- 2026-08-19: Added `aiid_incident_id` cross-reference (AIID 541), matched against the AIID weekly database export (2026-08-17). A cross-reference, not a re-verification; no claim changed.
