The same speed that makes AI useful to consultants is where the danger sits. Large language models hallucinate: they produce plausible citations, quotes and facts that do not exist, and they do so with complete confidence. When a tool returns a polished answer in seconds, the temptation to trust it is strong. In most industries that is a quality problem. In consulting, where the product is credibility, it is a business problem, and between 2025 and 2026 it stopped being hypothetical.
Key takeaways
- Deloitte, EY, KPMG and PwC Middle East each published reports in 2025 and 2026 containing fabricated citations, quotes or claims. In three of the four cases the errors were surfaced by the research group GPTZero.
- The pattern is identical: a trusted firm publishes claims that were never true, and its authority is what makes others cite them, so a private mistake becomes a public one.
- The fix is procedural, not technological: no AI-generated claim reaches a client or the public until a human has traced it to a real document.
- Article 4 of the EU AI Act now requires organisations deploying AI to ensure adequate AI literacy among staff, a rule aimed at exactly this kind of over-reliance.
Why hallucinations are a consulting problem specifically
A consultancy sells two things: an answer and the confidence to act on it. The second is worth more than the first, and it rests entirely on the client's belief that the firm checked its work. Regulators noticed early. In June 2025 the UK's Financial Reporting Council warned the audit teams of the Big Four that they lacked performance indicators for AI, pressing the firms to define metrics for how the tools affect audit quality.[1] The warning was about audit, but the underlying concern, that firms were deploying tools faster than they were measuring their effect on quality, applies across the industry.
Four documented incidents, 2025 to 2026
The cases below are drawn from Spaik's 2026 report and are limited to incidents that are publicly documented. We have deliberately not embellished them; the facts are strong enough on their own.
| Firm | When | What was published | What was wrong | What happened next |
|---|---|---|---|---|
| Deloitte[2] | 2025 | A report for Australia's Department of Employment and Workplace Relations, published on the department's website | Cited academic research papers that did not exist and quoted a Federal Court judgment that was never made | Deloitte disclosed it had used Azure OpenAI to help produce the report and, in October, agreed to refund the final instalment of a roughly $290,000 contract |
| EY[3] | May 2026 | A study on loyalty rewards programmes, used by EY consultants to market the firm's cyber-security work in Canada | GPTZero found more than half a dozen hallucinated footnotes pointing to pages that did not exist or did not contain the cited information, including a reference to a McKinsey report that does not exist | EY withdrew the study |
| KPMG[4] | Published Oct 2025, removed June 2026 | “Redefining excellence in the age of agentic AI” | Claimed UBS, NHS Greater Manchester, Swiss Federal Railways and Transport for London were running AI agents in ways those organisations said they were not | GPTZero identified the inaccuracies; KPMG removed the report from its website |
| PwC Middle East[5] | 2026 review of 2025 reports | Four reports, including “Transforming Governance” (2025) | Claimed Denmark, Saudi Arabia, the US and Australia used a PwC framework called “Citizen Pulse”; no source supported it and the framework appeared nowhere else. Another report cited a URL still carrying a ChatGPT tag | Documented by GPTZero |
Deloitte confirmed the use of Azure OpenAI in producing the Australian report. EY's and KPMG's errors and the PwC Middle East findings were identified and published by GPTZero, a research group specialising in detecting AI-generated content. Spaik did not independently re-verify each footnote; the facts above are as reported by those sources.
The pattern: authority turns a private error into a public one
Strip away the names and the four cases are one case. A firm whose authority makes people trust its work published claims that were never true. Nobody checked, because the firm's name was itself the check. That is the uncomfortable mechanism: the more credible the publisher, the less likely a reader is to verify, and the further a fabricated fact travels before anyone does.
“Publishing a report online is essentially a form of data injection into the pool of knowledge that is the internet. When the report includes fake information (either vibed citations or false claims) it can ‘poison the well’ by misleading future researchers, especially if the report is published by a well-known consulting firm and hosted on a high-traffic website.”[3]
How errors propagate once published
The GPTZero authors' phrase, “poison the well”, describes a second-order effect that consulting firms have not had to think about before. A report from a Big Four firm is not read once; it is cited in client decks, quoted in tenders, summarised by journalists, and, increasingly, ingested by the very AI systems that will answer the next analyst's question. A fabricated McKinsey report cited in an EY footnote does not stay in the footnote. It becomes a fact that exists because a trusted firm said so.
This is why the reputational cost is asymmetric. The productivity gain from skipping verification is measured in minutes per report. The cost of one public correction is measured in the discount every future client applies to the firm's claims. Consulting firms have always priced their credibility; they are now discovering that an unverified footnote is a way to spend it.
Building verification into the delivery process
The remedy is not to stop using AI, and it is not primarily a tooling question. It is a process rule: no AI-generated claim reaches a client or the public until a human has traced it back to a real document. In practice, the firms Spaik works with tend to implement that rule in four places.
Where verification belongs
| Stage | What to check | Who owns it |
|---|---|---|
| Research | Every source an AI tool surfaces is opened and read, not just listed. Sources that cannot be located are removed, not paraphrased. | The consultant who ran the query |
| Drafting | Quotes, figures and named examples are tagged as verified or unverified in the draft itself, so nothing unverified can be mistaken for fact at review. | The drafter |
| Review | A reviewer samples citations against the underlying documents, with a mandatory full check for anything that will be published externally. | Engagement manager or partner |
| Publication | A final pass specifically for fabricated references, framework names and URLs, the three failure modes in the 2025 to 2026 incidents. | A named owner, recorded |
Two design choices matter more than the rest. First, make verification a named step with a named owner, not a general expectation; every incident above happened at a firm with excellent general standards. Second, treat the external publication threshold as absolute. Internal notes can carry an unverified claim with a flag; a report on a government website cannot.
AI literacy, and what the EU now requires
The regulatory direction points the same way. Article 4 of the EU AI Act requires organisations deploying AI to ensure their staff have adequate AI literacy[6], a rule aimed at preventing exactly the failure these cases share: people trusting AI output they had no basis to trust. Literacy in this sense is not knowing how a transformer works. It is knowing that the model will invent a citation rather than admit it has none, and building the habit of checking. That is a training outcome, and it is one of the reasons Spaik puts verification exercises, not just prompting techniques, at the centre of every programme.
This analysis expands chapter 5[7] of The State of AI in Consulting 2026. For the regulatory detail, see the EU AI Act for consulting firms.
Notes and sources
- UK Financial Reporting Council, communication to Big Four audit teams on AI performance indicators, June 2025
- Australian Department of Employment and Workplace Relations, Deloitte report, disclosure of Azure OpenAI use and partial refund, 2025
- GPTZero (Om Ogale, Paul Esau, Alex Cui), analysis of EY loyalty-rewards study, May 2026
- GPTZero, analysis of KPMG “Redefining excellence in the age of agentic AI” (October 2025), report removed June 2026
- GPTZero, review of four PwC Middle East reports including “Transforming Governance” (2025), 2026
- Regulation (EU) 2024/1689 (EU AI Act), Article 4 on AI literacy
- Spaik, The State of AI in Consulting 2026, chapter 5
Figures attributed to third parties are their own reported data; Spaik did not produce those statistics. Where the text offers an interpretation, it is Spaik's own.
Continue reading
Working with Spaik
Verification is a skill. It can be trained.
Every Spaik programme builds source verification and critical thinking into the exercises, on the tools your teams actually use. Consultants leave knowing where the model is reliable, where it is not, and what must be traced to a real document before it reaches a client.