KPMG Withdrew Its AI Report After 40 of 45 Citations Failed Verification. Here's the Check Your Team Is Skipping.
KPMG withdrew a flagship AI report in June after The Register found that 40 of its 45 citations failed verification, and four named organisations told the Financial Times their AI use had been misrepresented. Here's the verification step that failure points to for any team publishing AI-drafted work.

KPMG International published a report on agentic AI in October 2025, titled "Redefining excellence in the age of agentic AI." In June 2026 the firm withdrew it, after an outside check of its sourcing found the report didn't hold up.
According to The Register, the AI-detection firm GPTZero checked the report's 45 citations and found five accurate. The other 40 ranged from mangled and misleading to partially fabricated or too vague to verify. TechCrunch didn't report those figures, but it independently reported the detail that turned this into more than an internal correction: several of the organisations the report named as AI adopters told the Financial Times it had misrepresented what they were actually doing.
The organisations named
TechCrunch reported that UBS, the UK's National Health Service, Swiss Federal Railways and Transport for London all told the Financial Times that the report's claims about their AI use were untrue or misleading. The report also stated that Emirates had deployed a chatbot named "Sara," capable of rebooking passengers onto new flights. According to The Register, Sara is a robot assistant Emirates introduced in 2023, not a chatbot, and it can't rebook flights.
The report's own numbers didn't agree with KPMG's separate research either. It claimed 55% of CEOs rank AI as their top investment priority. KPMG's real 2025 CEO Outlook survey puts that figure at 71%, a gap The Register pointed out directly.
KPMG's response
The Register quoted KPMG's statement in full: "KPMG International takes the accuracy and integrity of its published content seriously. The report has been removed and we are reviewing the circumstances surrounding its publication. We expect all our people to follow our guidelines on the responsible use of AI, including human oversight to validate content and verify independent sources." Neither outlet reports what produced the errors: whether that was a drafting tool used without a check, a research process that took AI-generated citations at face value, or something else. I'm not going to guess at KPMG's internal process from the outside, and neither source supports doing so. What's on the record is enough on its own: a report bearing the name of one of the world's largest professional services firms went out with 89% of its citations failing basic verification, and four organisations had to correct the public record about their own AI use as a result.
The check any team could be skipping
KPMG has more resources than almost any business that will read this, a governance and risk practice that advises its own clients on exactly this kind of control, and a direct reputational interest in not shipping an AI report that doesn't check out. None of that caught the 40 citations that later failed verification. If a firm with KPMG's incentives and resources missed it, a mid-size business using AI to draft market reports, competitor analysis, board papers or client-facing research should assume its current review process has the same gap, unless it can point to something specific that closes it.
What verification built in looks like
I wrote earlier this year about how Thomson Reuters rebuilt its legal AI products around citation checking, treating verification as the design goal rather than a step added at the end. When "Mostly Right" Isn't Good Enough covers how that works in practice: the system checks its own citations before presenting a finding, and the professional confirms rather than hunts for errors. KPMG's report is what the same failure mode looks like without that discipline in place: a fluent, confident document that nobody checked against its sources before it carried the firm's name.
What I'd take from this
If your team uses AI to draft anything that leaves the building, whether that's a report, a market analysis, a board paper or client-facing research, three controls follow directly from this case.
- Classify AI-drafted content headed for external publication as its own risk tier, with a named owner who signs off before release. Section 08: Risk and Governance, Tool 08a (AI Risk Classification Matrix), sets out how to do that proportionately rather than gating every use of AI equally.
- Verify every checkable claim against a live source before publication: specifically citations, statistics, and any statement about what a named third party is doing. That's the exact category that failed at KPMG, claims that were verifiable and simply weren't verified.
- Write the check into your AI use policy so it doesn't depend on one person remembering to do it. Section 09: Ethics and Responsible AI, Tool 09e (AI Use Policy Template), gives a working structure for what that policy should cover.
None of this needs KPMG's budget. It needs a decision, made before the next AI-drafted document goes out, about who checks the sources and what happens if the answer turns out to be nobody.
Sources
- KPMG pulls report on AI usage due to apparent hallucinations (TechCrunch, June 2026)
- KPMG's AI report turns into a demo of AI hallucinations (The Register, June 2026)