KPMG published a report in October 2025 titled "Total Experience: Redefining Excellence in the Age of Agentic AI." It was meant to show clients how companies around the world are using AI to improve customer experience. It was also meant to be read, cited, and trusted.
GPTZero, a firm that builds tools to detect AI-generated content, ran a forensic check on the report's citations. Of 45 citations, only 5 pointed to real, accurate sources. The rest ranged from heavily altered titles grafted onto real sources, to references that were entirely invented. Around half of the factual claims in the paper were false or misattributed.
The case studies were the most embarrassing part. The report described UBS, the Swiss bank, as having integrated AI agents across its investment advisory, risk management, and compliance systems. UBS told the Financial Times that was "factually incorrect." Swiss Federal Railways was described as using AI agents to help passengers plan and book trips in real time. A spokesperson said that was "not accurate." Emirates' Sara assistant was described as an AI-powered chatbot that could change passenger bookings. It was a basic mobile assistant launched in 2023 with no such capabilities.
GPTZero's investigators concluded that "no human at KPMG double-checked the citations, the claims, or the sources before" the report was published. The most plausible explanation is that an AI research tool was asked to find real-world examples of AI being used in business, and it simply invented them rather than admit it could not find enough.
GPTZero has named this pattern "vibe citing": AI tools generating references that look real, with plausible titles and authors, pointing to sources that do not exist or do not say what the citation claims.
The damage does not stop with KPMG. Reports from these firms rank highly in search engines and are treated as authoritative sources by journalists, analysts, and other researchers. By the time GPTZero caught the errors, the KPMG report had already been referenced by multiple industry publications and at least one major newspaper. False claims about what UBS or Emirates are doing with AI were circulating as established facts.
This is not an isolated incident. EY retracted a cybersecurity study in May 2026 after 16 of 27 citations were found fabricated. Deloitte partially refunded an Australian government contract after AI-hallucinated references appeared in a welfare compliance review. Sullivan and Cromwell, a major law firm, apologized to a New York court over an AI-hallucinated filing. Three of the Big Four consulting firms have now had public failures tied to the same basic problem: AI output that was not verified before publication.
For anyone in business who relies on industry research, including reports from big-name firms, this is the practical takeaway. A credible logo on the cover is not evidence that the content is accurate. When a report cites a statistic or claims a company has deployed a specific technology, that claim now needs to be checked, not assumed. You can often verify directly: call the company, check their press releases, or search for independent coverage of the thing being claimed.
The firms selling AI governance advice have demonstrated, in their own published work, what happens when AI output skips the verification step. That is worth remembering the next time a report from a trusted name lands in your inbox with a confident headline about what AI can do.