The PwC AI Hallucination Lesson
When PwC Middle East published reports containing fabricated citations and a study that apparently never existed, the incident revealed a risk every AI-assisted business must take seriously.

On July 29, 2025, the Financial Times reported that four thought-leadership reports published by PwC Middle East contained problematic citations, broken links, misattributed claims, and at least one academic paper that appeared not to exist. The errors were first identified by AI-detection company GPTZero and subsequently reviewed by the FT. The story moved quickly because of who was involved. PwC is not a startup experimenting with new tools. It is one of the Big Four global professional-services firms — an organization that reported US$56.9 billion in gross revenue for the financial year ending June 30, 2025, and whose own governance statements describe quality and trust as fundamental to everything it does.
The lesson, however, is much larger than PwC. It belongs to every entrepreneur, consultant, marketer, content creator, and business owner who uses artificial intelligence to research, write, or publish. AI may help create the work, but it cannot accept responsibility for the work. That responsibility still belongs to us.
Why the PwC Context Makes This Especially Significant
PwC is regularly engaged by organizations navigating complicated decisions involving financial reporting, technology, risk management, governance, and — notably — the responsible use of artificial intelligence. Its clients include 82% of the Fortune Global 500. They hire firms like PwC not merely for data, but for professional judgment, assurance, and trust.
That context made the reported errors particularly damaging. The problem was not simply that mistakes appeared in several articles. The deeper reputational issue was that an organization advising clients on responsible AI apparently published AI-assisted material that had not been adequately verified before release.
What the Investigation Found
The four reports under scrutiny addressed corporate use of agentic AI, technology in government services, electric and autonomous vehicles, and transportation trends in the Middle East. These were not casual blog posts. They were professionally formatted thought-leadership documents intended to demonstrate expertise and attract consulting work. Researchers identified several categories of problems.
A Study That Apparently Did Not Exist
One report cited an academic paper concerning air quality in Riyadh. Investigators could not find the study in the named journal and could not verify that the identified authors had written it. The paper appeared to have been invented — a textbook example of what researchers and regulators call an AI hallucination, or what the National Institute of Standards and Technology more precisely terms a confabulation: a situation in which a generative-AI system confidently produces erroneous or false content.
An AI system can generate a realistic paper title, plausible author names, a journal name, and an apparently legitimate citation identifier. The reference may look entirely professional until someone attempts to locate the actual source.
Links That Worked but Did Not Support the Claims
Other footnotes directed readers to real webpages — but those pages did not contain the information attributed to them. One report referenced a PwC survey in which 70% of Middle Eastern chief executives reportedly said generative AI would significantly affect their businesses. The footnote led to a media article that did not mention the survey. A working link is not the same as a valid citation. The source must actually support the specific claim being made.
Inconsistent Citations for the Same Fact
One claim — that human error causes 90% of traffic accidents — appeared three times within two pages. It appeared once with one footnote, once without any footnote, and once with two different footnotes pointing to different sources. GPTZero researcher Paul Esau described this kind of inconsistent citation pattern as an indicator that generative AI may have been heavily involved in producing or researching the material.
A ChatGPT Tracking Parameter in a Citation URL
The FT also found that one citation URL contained a tracking parameter referencing chatgpt.com. That does not prove the entire report was written by ChatGPT. It does suggest that ChatGPT was involved in sourcing or generating at least part of the material — and that the citation was not fully reviewed before publication.
Understanding AI Hallucinations
NIST defines confabulation as generative AI producing output that is factually incorrect, internally inconsistent, or contradicts the material it was given. In practice, a generative-AI system may invent the title of a research paper, attribute a quotation to the wrong person, produce a realistic but nonexistent statistic, create a link to a page that does not exist, misrepresent what a source actually says, or combine several true details into an incorrect conclusion.
These errors are particularly dangerous because AI does not always signal uncertainty when it is wrong. False information may be presented in polished language, professional formatting, and an authoritative tone. A reader — or a busy editor working under deadline — may trust the output without realizing the supporting evidence was invented.
— NIST AI Risk Management FrameworkGenerative AI can produce content that is factually incorrect, yet internally consistent and confidently expressed — a risk that organizations must actively manage throughout the AI lifecycle.
The Real Failure Was Not Using AI
It would be easy to read this story and conclude that businesses should stop using artificial intelligence. That is the wrong lesson. AI is an extraordinarily capable tool. The danger does not come from using it. The danger comes from allowing it to operate without supervision, verification, and clearly defined accountability.
The real problem in the PwC case was not that AI helped produce reports. The real problem was that reports reached publication without anyone adequately confirming that the claims and citations inside them were reliable. Businesses already depend on spreadsheets, databases, accounting platforms, and automation software — every one of which can contribute to a poor outcome when its output goes unchecked. AI creates an additional layer of risk because it can generate an incorrect answer alongside a convincing explanation and apparently credible sources.
Seven Practices for Responsible AI Use
1. Treat AI Output as a First Draft, Not a Final Answer
AI is excellent at overcoming the blank page. It can organize scattered thoughts, develop article structures, simplify complicated subjects, and create readable language from rough notes. The draft it produces should be treated as the beginning of the work, not the finished product.
2. Separate Your Own Ideas From Verifiable Claims
Not every sentence requires an outside citation. Your personal observations, experiences, and opinions belong to you. But specific factual claims — statistics, research findings, direct quotations, financial figures, company descriptions, and legal requirements — must be verified against reliable sources before publication.
3. Open Every Source
Never assume a citation is legitimate because AI supplied it. Open the link and confirm that the page exists, that the author and title are correct, that the publication date is accurate, and — most importantly — that the source actually supports the specific claim you are making. A working link does not automatically validate a statement.
4. Apply Stronger Verification to High-Stakes Claims
The greater the potential harm, the more rigorous the verification process should be. A general marketing idea may need only an ordinary editorial review. A claim involving contracts, finance, health, safety, regulation, or another organization's reputation may require multiple independent sources or review by a qualified professional. NIST's AI Risk Management Framework recommends that verification standards reflect the actual risk level of each decision.
5. Keep a Human Voice and Point of View
AI tends to produce language that is polished but generic — predictable transitions, repeated sentence patterns, abstract business vocabulary. Your own observations, examples, and conclusions are what give content its genuine value. Use AI to help communicate what you believe, not to decide what you believe.
6. Build Controls Into the Workflow
Telling employees or contractors to "use AI responsibly" is not sufficient. Responsible AI use must be supported by specific, documented procedures. Before publishing any AI-assisted material, confirm that every name is spelled correctly, every statistic has a reliable source, every link works, every quotation is accurate, every citation supports the surrounding statement, and a human has read and approved the final version. NIST recommends defining clear human roles and responsibilities for AI governance rather than leaving accountability uncertain.
7. Assign Final Accountability to a Named Individual
Every published item should have a human owner — someone who reviews the final result, approves its publication, and accepts responsibility for its accuracy. When everyone assumes someone else checked the work, important errors go undiscovered. That assumption is exactly what appears to have happened in the PwC case.
A responsible-AI policy sitting in a folder is not enough. The safeguards must be embedded in the actual publishing workflow, with a named person accountable for every piece of content that carries your organization's name.
Why This Matters Especially in a Relationship-Based Business
A transaction-focused business may prioritize attracting the next sale. A relationship-based business depends on something harder to rebuild once it is lost: continued trust. People return to a business because they believe the owner is honest, useful, consistent, and dependable. One inaccurate article may not destroy a relationship. A continuing pattern of careless or misleading content eventually will.
This is why responsible AI use is inseparable from a hub-centric business model. A digital business hub is intended to become the trusted home for your audience — bringing content, resources, products, services, and relationships together in one connected environment. As that environment grows, so does your responsibility. You are not merely filling pages with content. You are building a body of knowledge that people may use to make real decisions.
Scale Works in Both Directions
One of AI's greatest advantages is the ability to produce more — articles, emails, social posts, presentations, and customer resources — faster than any individual could manage alone. But scale works in both directions. AI can multiply genuinely useful ideas. It can also multiply misinformation. An incorrect statement published on a website can be repeated through social media, quoted by other writers, summarized by search systems, and incorporated into future AI-generated answers.
That risk intensifies when the original source is a recognized authority. People are less likely to question information attributed to a respected organization. Other writers repeat the claim without opening the original source. One hallucination can become hundreds of second-hand errors. The PwC case follows similar scrutiny involving reports from EY and KPMG, which demonstrates that inadequate verification is not a single-company problem — it is an industry-wide risk.
The Competitive Advantage Is Not Simply Having AI
Soon, nearly every business will have access to powerful AI tools. The competitive advantage will not come from possessing the technology. It will come from using it responsibly and intelligently. The businesses that stand out will combine AI speed with human judgment, automation with accountability, content volume with content credibility, and technology capability with authentic relationships.
AI can help us produce more. Human judgment determines whether what we produce deserves to be trusted.
The PwC controversy is not a reason to fear artificial intelligence. It is a reason to respect its power and understand its limitations. Generative AI can confidently produce false information, inaccurate statements, and invented citations — and NIST identifies these confabulations as a risk that every organization must actively manage. We cannot delegate truth. We cannot automate accountability. We cannot allow speed to become more important than credibility. The future will belong to those who combine the capability of artificial intelligence with the wisdom, experience, and responsibility of real people. AI can accelerate the work. It cannot own the responsibility. That part still belongs to us.
Explore the Hub-Centric Business Model