A federal magistrate in Miami spent most of an order last week explaining why four lawyers should answer to a grievance committee for citing police training bulletins that do not exist. The sanctions motion against them lost anyway. It lost in an email server.

THE LEAD PLAY

The Safe Harbor Your Email Server Closed

Thomas Raynard James sued a Miami-Dade detective and others in the Southern District of Florida. His Fifth Amended Complaint relied on five International Association of Chiefs of Police "Training Keys" on photographic identification procedure, numbered 135, 159, 202, 225 and 302. Nobody could find them, because they were not there. The court's phrase is "the Keys were AI hallucinations."

The defendant moved for Rule 11 sanctions. On August 27, Magistrate Judge Marty Fulgueira Elfenbein recommended denying the motion.

Rule 11 has a safe harbor and it works the way a warning shot works. You serve the motion on the other side, you wait 21 days, and if they withdraw the offending filing in that window, the matter ends there. If they do not, you file. The rule exists so that lawyers get one chance to fix their own mistake before a judge has to.

Defense counsel certified that she served the motion by email on March 27, more than 21 days before filing. The emails never reached plaintiff's counsel. Rule 5 says electronic service "is complete upon filing or sending, but is not effective if the filer or sender learns that it did not reach the person to be served." She learned. According to the order, defense counsel "was notified five separate times through bounce-back emails that her message was not delivered to Plaintiff's counsel."

Five times.

So the safe-harbor clock never started, the motion was premature, and the recommendation is denial. Here is the part worth sitting with. Once plaintiff's counsel actually got the filed copy of the motion, they moved to amend and withdraw the fictitious Keys within 13 days. That is inside the safe harbor. The rule would have done exactly what it was written to do. It never got the chance, because five bounce-backs landed in somebody's inbox and nothing happened next.

The lawyers who filed the fake citations are not walking away clean. The court separately recommended that the four attorneys who signed the Fifth Amended Complaint, Aaron Michael Cohn, David S. Rudolf, Sonya Pfeiffer and Natalie G. Figgers, be referred to the district's Ad Hoc Committee on Attorney Admissions, Peer Review, and Attorney Grievance. The order calls their "repeated reliance on unverified AI-generated research" irresponsible, quotes the competence rule on "the benefits and risks associated with the use of technology, including generative artificial intelligence," and instructs counsel that they "must ensure that they carefully evaluate, elucidate, and advocate," before landing on the word the whole opinion was built toward: "not hallucinate."

But the monetary sanction is gone. The consequence that would have cost somebody real money evaporated in a mail configuration.

Now the part that is your problem rather than theirs. The running tracker of AI hallucination cases stood at 1,996 documented matters as of this morning. You are going to run into fabricated citations in filings you did not write, and when you do, the Rule 11 motion is the only thing that makes it cost the other side anything. That motion is now worth exactly as much as your proof of delivery. Most firms treat safe-harbor service as clerical work: attach the PDF, hit send, calendar 21 days, move on. James v. Conley is what that looks like when the message bounces and the calendar entry runs anyway.

The Play this week: Find out how your firm serves a Rule 11 safe-harbor motion, then put a delivery-confirmation step in front of the 21-day calendar entry.

Three changes, all of them boring. First, the motion goes out from an account a human monitors, and somebody checks for a bounce-back that day rather than on day 21. Second, the 21-day calendar entry does not get created until delivery is confirmed, so a rejected message cannot quietly burn the clock. Third, when the attachment is large or the recipient is outside your usual circle, serve by a second method and document both.

Then run the check in the other direction, because in this case it was the receiving server's rejection that saved the party with the fake citations. Ask your IT group what your own mail system has been silently refusing, and from whom.

SECOND CHAIR

A Reprimand Does Not Expire

On August 24, Judge Dominic W. Lanza of the District of Arizona entered an order in Ruiz v. Magellan Financial & Insurance Services, No. CV-23-02090-PHX-DWL. Plaintiff's counsel Elizabeth Tate had filed briefs containing fake AI-generated quotations inside case parentheticals, attributed to Ninth Circuit decisions, along with an inaccurate AI-generated case summary. The order states that "Ms. Tate utilized ChatGPT to prepare the draft brief" and that she "also utilized ChatGPT to assist with the Brief on Impeachment."

The court did not fine her. It wrote: "IT IS ORDERED that this order constitutes a formal public reprimand." Then it added the line that outlasts any dollar figure: "Ms. Tate must report this discipline in any context in which she is required to report past instances of attorney discipline."

The read: Firms have been pricing this risk like a fine, which is to say as an expense with a number on it and an end date. A public reprimand is neither. It is a disclosure obligation attached to a named lawyer, and it surfaces on professional liability renewals, pro hac vice applications, bar admissions in other states, and a fair number of client RFPs. If you are the person who signs your firm's malpractice application, that is your question to answer, about somebody else's prompt.

California's Lawyer AI Bill Is Sitting on the File, and Today Is the Last Day

SB 574 would tell every California attorney what they may and may not hand to a generative model. As of this morning it has not passed. The Assembly read it a third time and amended it on August 21, then ordered it back to third reading, and the record shows nothing since. Today is the last day for each house to pass bills before the legislature adjourns sine die.

The arithmetic is tight. Because the Assembly amended the bill, an Assembly floor vote today still has to be followed by Senate concurrence, both before business closes. Three other AI bills cleared that gauntlet last week and went to the Governor: AB 2025 on real estate AI disclosure, AB 2656 on generative AI notice to employees, and AB 2392 on education technology. The lawyer bill sat.

The operative sentence, if it gets there, is thirteen words: "An attorney shall not delegate the practice of law to generative artificial intelligence." Every other duty in the bill is a supervision duty, meaning you may use the tool so long as you verify what comes out. That one is a flat prohibition, and the bill does not define "the practice of law."

The read: Read your California workflows against that sentence this week whatever happens by tonight. If it dies on the file, a version of it returns next session, because the sentence is a reaction to a caselaw pile that keeps growing. The question worth answering now is which of your current workflows a regulator would call delegation rather than assistance, and whether you could explain the difference out loud without reaching for a vendor's slide.

The Fake Law Is Arriving From the Other Side of the V.

Four federal courts handled fabricated citations from unrepresented litigants in three days last week. On August 25, the District of New Jersey admonished a plaintiff in Kurelko v. Ballard whose motion "contains several inaccurate or nonexistent case citations and quotations." On August 26, Judge Matthew F. Leitman of the Eastern District of Michigan found that the pro se plaintiffs in Potterf v. Wessels "used artificial intelligence to prepare their objections" and that those objections were "replete with false and/or materially inaccurate citations of cited cases." He found an apparent Rule 11(b)(2) violation, restricted their future filings, and warned of sanctions "up to and including dismissal of this action with prejudice." The same day, Judge Julie R. Rubin of the District of Maryland worked through a citation in Johnson v. Nationstar Mortgage and wrote, "Based on the court's review, this case does not exist." Also on August 26, the District of New Hampshire recounted a bankruptcy court striking a pro se objection that contained "false, hallucinated case citations."

The public tracker of these matters stood at 1,996 as of this morning. Pro se litigants account for 1,149 of them. Lawyers account for 794.

The read: Firm AI policies govern what your people produce. Almost none of them assign anyone the job of checking what arrives. If you have volume practices with meaningful pro se opposition, then the fabricated citations you encounter this year are more likely to come from an opponent than from your own file, and the first person to see one is usually an associate who assumed it was real because it showed up in a court filing.

STILL WATCHING

  • Thomson Reuters v. ROSS Intelligence, No. 25-2153, argued in the Third Circuit on June 11. Eighty-one days, no opinion. The fair use question underneath every legal AI training claim is still sitting with three judges.

  • The California rules amendments to RPC 1.1, 1.4, 1.6, 3.3, 5.1, and 5.3. One hundred nineteen days since public comment closed on May 4, still no Board of Trustees vote. Note what that means alongside SB 574: the profession's own regulator has been slower than the legislature.

  • The Copilot for Word prompt injection. One hundred seventy-eight days since Hakon Maloy reported it to Microsoft, thirty-four since he published it. No CVE, no patch. The next Patch Tuesday is September 8.

  • Gemini Enterprise for Legal. Six days old, still in preview, still no published price.

QUICK HITS

  • Thomson Reuters launched its own model. Thomson 1.0, trained on Westlaw, Practical Law, Checkpoint and Reuters content, announced August 24. Roughly $40 million over two years, and a final training run that cost $450,000. TR benchmarked it against GPT 5.4 and Claude Sonnet 5 and says it holds its own on web-only research and pulls ahead once its own content is in play. It has seen under 10% of TR's available content so far. First deployment is Tabular Analysis in CoCounsel Legal.

  • LexisNexis rebuilt Protege. The new Legal Intelligence Engine adds what the company calls a "harness" layer over models, agents and content that picks an approach from the task instead of running a predefined workflow. CTO Jeff Reihl says it "can bring in additional tools, it can bring in additional information, and it can check its work and then loop back and redo it." Several hundred prebuilt skills. Proprietary models previewing later this year. No price.

  • Clio passed $500 million in annual recurring revenue and opened a US headquarters in New York. It also stood up a business unit for courts and the judiciary, run by Pablo Arredondo, the Casetext cofounder who built CoCounsel. He started today.

  • Harvey shipped Memory. Saved user preferences and standards that carry across the web app, Outlook and the Word add-in. Memories get cited the way sources get cited, admins control whether the feature exists in a workspace at all, and Harvey says individual memories "are never used to train AI models." Early access now, general availability in a couple of weeks.

  • ILTACON was the largest one yet. 5,700 registrations against 4,600 last year, 241 exhibit booths at $10,000 per ten-by-ten space, and all 2,803 rooms at the Gaylord Opryland sold out. Harvey bought 24 spaces and booked Lady A. Legora bought 22 and booked Sheryl Crow.

Defense counsel in Miami got five bounce-backs and filed anyway. I have hit send on something that mattered and never confirmed it landed. Not five times, and not on a sanctions motion, but I have done the smaller version of that. Go look at your outbound.

See you in the next one.