Harmful outputPI-0020
Deloitte to refund part of an Australian government fee over a report with AI-fabricated references
An A$440,000 assurance report that Deloitte wrote for Australia's Department of Employment and Workplace Relations was found to cite non-existent academic works and a misquoted court judgment. A University of Sydney researcher flagged the errors in late August 2025. Deloitte reissued the report, disclosing that it had used Azure OpenAI GPT-4o, and repaid the final installment of A$97,587.11.
- Harm
- Harm level 2, Minor harmTracked separately (AI-fabricated content relied on by professionals).
- Control
- Control level 1, No rule brokenReported beside the index; never added to it.
Sources
How we know
6 sources · multiple credible sources. Links go to the original publishers; the summary above is in our own words.
- primaryMinisterial and Secretarial briefings regarding the Targeted Compliance FrameworkAustralian Department of Employment and Workplace Relations · date unknowndewr.gov.au/download/17306/ministerial-and-secretarial-briefings-regarding-targ…
- primaryContract Notice CN4118426: Assurance Review to support the Targeted Compliance Framework (records final instalment repaid)AusTender (Australian Government) · date unknowntenders.gov.au/Cn/Show/05c19be8-a95f-4379-bd35-630cc2f472c6
- newsDeloitte to refund government after using AI in $440,000 reportCyber Daily · Oct. 8, 2025cyberdaily.au/government/12737-deloitte-to-refund-government-after-using-ai-in…
- newsLaw lecturer Christopher Rudge slams Deloitte's government-funded report written with AIThe Nightly · Oct. 6, 2025thenightly.com.au/australia/nsw/law-lecturer-christopher-rudge-slams-deloittes…
- newsDeloitte to partially refund Australian government for report with apparent AI-generated errorsAP (via KSAT) · Oct. 7, 2025ksat.com/business/2025/10/07/deloitte-to-partially-refund-australian-government…
- blogMedia appearances (lists the Australian Financial Review's 22 Aug 2025 report on the suspected AI use)Christopher Rudge · date unknownrudge.tv/media-appearances/
Why this rating
Minor harm; control failure level 1
Two separate assessments. Only documented harm can count toward the index.
Observed harm
Minor harmA government client received a report with fabricated references. The department asked for the final installment of A$97,587.11 (including GST) back, and the official contract register records it as repaid. Residual costs after the corrections are not quantified.
Money & property: $10k to $1M.
Not counted: tracked separately (AI-fabricated content relied on by professionals), outside the index's scope (methodology section 0).
The harm scale
- 1 Negligible Inconvenience, easily remedied.
- 2 Minor Limited, recoverable harm.
- 3 Moderate Material harm needing significant effort to remedy.
- 4 Severe Severe harm to health, rights, property or essential services.
- 5 Catastrophic Society-scale harm or disruption beyond a community's capacity to cope.
Control assessment
No rule brokenOrdinary fabrication in generated text that was not checked; no rule or permission breach by the AI.
Reported beside the index; never added to it.
The control scale
- 1 Negligible Behaved as instructed. The problem was an ordinary error or a flawed output, with no rule broken.
- 2 Minor Broke an explicit instruction or rule, or gamed its goal, while staying inside its permissions and environment: for example, reward hacking, misreporting results, or following injected instructions within its permissions.
- 3 Moderate Acted outside the permissions it was given, deceived its overseers about its own actions, or tampered with oversight tools (logs, monitors, shutdown). Stopped by normal controls within an hour.
- 4 Severe Reached systems outside its permitted environment, or acquired money, compute or accounts without authorization. The type and mechanism say how.
- 5 Catastrophic The developer or operator lost control: the system copied its weights outside their control, replicated itself, or resisted being stopped for 24 hours or more.
Rating rationale
The department's briefing specifies A$97,587.11 (including GST) as the final payment it requested back for a report below expected quality standards. This clears the level-2 money threshold without assuming a refund amount; AusTender records the installment as repaid (checked Oct. 3, 2026). The flawed report was a deployment quality failure, not evidence that the model hid its actions. Control remains level 1.
Effect on the index
It does not count toward the Aug. 25 reading
The reading for the week to Aug. 25, 2025, with this record and without it. Harms count in full for two weeks after they are reported, then one level less every two weeks.
Not counted: tracked separately (AI-fabricated content relied on by professionals). 5 other records behind the reading for that week.
The arithmetic
| Step | With it | Without |
|---|---|---|
| Counts toward the index?documented, external, eligible evidence | No | — |
| Worst documented harm, ksets the band | — (none counting) | — (none counting) |
| Harms at that level, nposition in the band | 0 | 0 |
| Highest control level breachedsets the reading only when no harm counts | 3 | 3 |
| Readingrounded down | 3 Control failures only | 3 Control failures only |
Inside the window of 4 weekly readings
| Week to | Reading | Band |
|---|---|---|
| Aug. 25, 2025 | 3 | Control failures only |
| Sept. 1, 2025 | 3 | Control failures only |
| Sept. 8, 2025 | 2 | Control failures only |
| Sept. 15, 2025 | 2 | Control failures only |
Revisions
What we changed
7 logged. Every change to a rating is logged here, with the reason.
- v7Oct. 6, 2026
Ratings confirmed by the editor.
- v6Oct. 3, 2026
Repayment now verified on the official contract register (AusTender CN4118426, checked 3 Oct 2026; the repayment entry is undated, so the source is dated unknown); earlier 'not verified' wording and the obsolete $10,000 threshold wording replaced. Behavior label Deception → Harmful output; Cyber Daily and The Nightly dated; Rudge's media page added for the 22 Aug report date. The DEWR report page (said in search extracts to carry a February 2026 corrected version) and the Secretary statement timed out, so they are not listed and that version is not stated. Ratings and separate track unchanged.
- v5Oct. 2, 2026
Moved to the separate track for AI-fabricated content relied on by professionals (methodology section 0): the consultancy adopted and published the model's output, so the record is kept and shown but no longer counts toward the index.
- v4Oct. 2, 2026
Report date corrected from August 2025 (month precision, placed on 1 Aug) to 22 Aug 2025, when the Australian Financial Review first reported academics' concerns about fabricated references (date from secondary accounts; the AFR page was not opened). The record no longer enters windows before it was public.
- v3Oct. 1, 2026
Added a departmental primary briefing identifying the A$97,587.11 final payment requested back; removed the unsupported assumed refund threshold from the current impact rationale.
- v2Sept. 30, 2026
Rated: impact documented level 2; control type none.
- v1Sept. 30, 2026
Backfilled from public reporting.
Cite and share
Use this record
Citation
Paperclip Index. “Deloitte to refund part of an Australian government fee over a report with AI-fabricated references.” Record PI-0020. Reported Aug. 22, 2025; updated Oct. 6, 2026. Rated under methodology v0.6. https://paperclipindex.com/incident/PI-0020