This website uses cookies

Read our Privacy policy and Terms of use for more information.

In early September, the District of Columbia Court of Appeals struck an entire appellate brief filed on behalf of a Deutsche Bank subsidiary. The brief, in an ongoing mortgage foreclosure case, cited four cases that do not exist, fabricated by a Google AI tool. The attorney who filed it, Loishirl Hall of McCabe, Weisberg & Conway, admitted the citations were hallucinated and should never have appeared in a filing before the court. The three-judge panel rejected the firm's request to simply redact the four fake citations and let the rest of the brief stand, calling that no sanction at all. Every attorney who signed the brief, the court found, bears some responsibility.

The detail that makes this case worth a UK board's attention has nothing to do with AI capability and everything to do with governance. The firm told the court its internal policy explicitly forbids using AI to draft legal filings. The court struck the brief anyway, faulting the firm for failing to supervise its own attorney against a policy the firm says it had. In a separate concurrence, Senior Judge Stephen Glickman went further: the firm never actually produced its policy for the court, and never explained how, or whether, it had been communicated to the lawyer who violated it.

Read that sequence again, because it is the whole argument this newsletter has made for two months, arriving unprompted from a US appellate court. A policy existed. Nobody could show it had been applied, communicated, or checked. To the court, an unproven policy and no policy were functionally the same thing.

Why this is not a US story

It would be easy for a UK financial services board to read this as an interesting American legal curiosity and move on. That would be a mistake, and not because the AI Act or GDPR happen to apply. Two live UK mechanisms make the same failure personally, individually costly for a named senior manager, right now.

First, the Financial Conduct Authority and the Prudential Regulation Authority have already confirmed, following consultation, that AI does not get its own prescribed responsibility under the Senior Managers and Certification Regime. The senior manager already accountable for a business area is automatically accountable for the AI used inside it. Had McCabe, Weisberg & Conway been a UK regulated firm and Hall's supervising partner an SM&CR senior manager, the question would not stop at whether a firm policy existed. It would extend to whether that individual, by name, could show they had taken reasonable steps to ensure the policy was followed, and could be personally investigated if they could not.

Second, Section 80 of the Data (Use and Access) Act 2025, in force since February, gives individuals a statutory right to contest automated decisions made about them. A mortgage foreclosure decision informed by AI-assisted legal work sits precisely inside the kind of automated or AI-assisted process that provision was written for. The right to contest is only meaningful if there is a record to contest against, and a policy nobody can prove was applied is not a record.

The test this case actually sets

Strip away the jurisdiction and the case becomes a clean test, applicable to any board in any sector. A written policy answers what the organisation says should happen. It does not answer whether a named individual verified that it did, on a specific occasion, before something went out under the organisation's name. The D.C. Court of Appeals drew that line without needing to invoke a single UK or EU regulation. It drew it because that is what governance failure actually looks like when a court examines it closely: not the absence of a rule, but the absence of anyone who can show the rule was checked.

A UK senior manager reading this case should ask three questions, adapted from the same gap an independent adviser flagged, from a different angle, in reviewing UK boards' AI governance this year. Is there a named individual who could say, without checking, who is accountable if an AI-assisted output in their area turns out to be wrong? Is there a record showing that person, specifically, reviewed the relevant output before it left the building, not a policy asserting they generally would? And would that record exist if a regulator, a court, or a claimant's counsel asked for it tomorrow, or would it need to be assembled once they did?

McCabe, Weisberg & Conway had an answer to the first question and, on the court's own reading, no answer to the second or third. That gap struck an entire brief for a client described in the proceedings as one of the largest financial institutions in the world. For a UK senior manager under SM&CR, the equivalent gap does not require a court to find it. The regulator already has the power to.

Regulatory references: Douglas v. Deutsche Bank Nat'l Trust Co., No. 24-CV-1099 (D.C. Ct. App., decided September 2026); FCA/PRA joint consultation outcome on senior manager accountability for AI (April 2026); SM&CR (SYSC, FCA Handbook); Data (Use and

The Roche-Review is the weekly publication of Dr Ivan Roche FRSS FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.