Why Legal Work Is Unusually Exposed
Fluency Is the Product, Not Accuracy
A language model generates text by repeatedly predicting a plausible next token. It has no separate store of verified facts and no internal mechanism that distinguishes recalling something from constructing something that fits. When the training data contains a real case, the model may reproduce it. When it does not, the model produces text with the same surface properties: correct citation format, plausible court, coherent holding. Nothing in the output signals which happened. In most domains a fabricated detail is caught because it reads oddly. Legal writing is unusually formulaic — that formulaic quality is exactly what a next-token predictor reproduces perfectly, so the fabrications inherit full surface credibility from the genre itself.
- The model has no internal boundary between remembering and inventing — both are the same operation
- Legal citation format is highly regular, so fabricated citations are indistinguishable on their face
- Confidence in tone reflects the training distribution, not the model's certainty about the fact
- Fluency is what these systems optimise; accuracy is something you have to add from outside
The Domain Amplifies the Failure
Several features of legal work compound the base risk. Authority is the currency: an argument rests on cited sources in a way that few other professional outputs do, so a fabrication lands directly in the load-bearing part of the document. Verification is costly and unevenly distributed, which creates pressure to skip it under deadline. The adversarial structure means an opponent is actively motivated to find your errors. And the audience is a tribunal with sanctioning power. Compare a fabricated statistic in an internal marketing memo — embarrassing, recoverable. The same error class in a filing engages duties of candour, invites sanctions, and becomes part of a public record that follows the practitioner.
- Citations are load-bearing in legal argument — a fabrication lands in the structural part of the document
- The adversarial process guarantees someone is looking for exactly this class of error
- The audience holds sanctioning power and the record is usually public and permanent
- Deadline pressure attacks the verification step specifically, which is the only control that works
- In US federal court, Rule 11 certifies that legal contentions are warranted by existing law and provides for sanctions
Automation Bias Does the Rest
The technical failure only becomes a professional failure because of how people relate to confident machine output. Automation bias is the well-documented tendency to defer to a system's answer, and it strengthens when the output is fluent, when the reviewer is tired or rushed, and when the system has been right many times before. That last condition is the trap: a tool that is reliable on ninety-five per cent of tasks trains its user into exactly the deference that makes the remaining five per cent dangerous. Reliability and complacency grow together. This is why verification has to be a procedural requirement enforced by process rather than a judgement call made in the moment by someone who has stopped expecting errors.
- Deference to confident output is a documented human pattern, not a personal failing to be willed away
- A mostly-reliable tool is more dangerous than an obviously unreliable one — it earns unearned trust
- Fatigue and deadline pressure are when the deference peaks and the checking stops
- Make verification a process step with an artefact, not a state of mind you rely on maintaining
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.