Midwest Frontier AI Consulting Year One: Big Wins, Things I Missed, IOUs, and the Year to Come
This First Year: 18 August 2025 → 18 August 2026.
This First Year: 18 August 2025 → 18 August 2026.
Last year, on August 18, 2025, I started my company with the goal of improving GenAI risk training, especially in law and small and medium businesses. Since founding Midwest Frontier AI Consulting, the number of hallucinated case citations in the United States has more than quadrupled.[^1] [1] To paraphrase the under-appreciated show Better Off Ted: “what’s your problem Midwest Frontier AI consulting?”
Top Stuff
- My own CLE accredited in 7 states; co-presented a half-day workshop with Joe Bambara for ACI; presented for NBI.
- Admitted to bug bounty program for a frontier lab.
- Retained expert witness in LTL LED, LLC v. Google (Minnesota). [^2] [2] I have permission to say this publicly. The case was removed to D. Minnesota in mid-2025 but remanded back to the state in January; I have seen several trackers of major AI cases continue to carry the “D. Minnesota” label, but that’s outdated.
- Several major topics from my CLE and writing have been validated by events in law this year, e.g.:
- Doppelgänger Hallucinations: LLM confirming a hallucination.
- Subtle changes with “writing help” causing material errors.
- Indirect prompt injection with white font on a white background.
- Watch out for your expert witness’s misuse of LLMs too
- LLM transcription is not an adequate substitute for court reporters and is a major, under-appreciated privacy risk.
- Helping clients write AI Use Policies and develop workflows.
- Instructor for Govology: forthcoming webinar in one week!
Predictions (Big Wins)
- In October 2025, I wrote publicly about Doppelgänger Hallucinations, a phenomenon that means an LLM will sometimes confirm the hallucination of a second LLM and even add details, which means that “double-checking” can actually fool you and also calls into question the industry-standard use of LLM-as-judge for benchmarks; I later warned about Doppelgänger Hallucinations in my live CLE (December 2025) and on-demand CLE (recorded early 2026, based on the December curriculum). Since then judicial opinions, including:
- Zhang v. NPR (D.D.C., Howell, Dec. 18, 2025): counsel relied on Google summaries, did not know they were AI, trusted the source because of the links.
Plaintiff’s counsel explained that, while using Google and other search tools to find authority for the opposition brief, he relied upon “summaries” generated by Google that he was “not even aware . . . were being generated by artificial intelligence.” Pl.’s OTSC Resp. at 2. These summaries “linked to purportedly legitimate case databases,” such as “VLex,” and plaintiff’s counsel therefore apparently relied upon them as accurate. Id.
- Doiban v. OLCC (Or. Ct. App., Mar. 18, 2026): quote from attorney about Google AI Overview affirming fabricated cases were real
Counsel has tried but has been unable to locate the direct source again after over a year has passed from originally incorporating the case citations into the brief. Counsel reports that “if one asks Google’s search engine whether many of the fabricated cases are real, it will generate a response using its artificial intelligence search engine, affirming that the fabricated case are in fact real.” [sic]
- Zhang v. NPR (D.D.C., Howell, Dec. 18, 2025): counsel relied on Google summaries, did not know they were AI, trusted the source because of the links.
- Prompt injection via hidden text, including the specific example of white text on a white background: first publicized globally in Brazil May 12, 2026; recently a topic of discussion because of Elliott v. NY Bariatric (Conn., Aug. 6, 2026); however, as I noted in "AI Gone Wrong in the Midwest" CLE, the
- Specialist tools hallucinate: while this was already established in the academic literature, the case U.S. v. Farris (6th Cir., CoCounsel) still drew gasps of "COCOUNSEL can hallucinate?!?!" (dear reader: any LLM-enabled tool can hallucinate). I also drew attention to the inconsistency of rules purporting to "ban AI" with the express purpose of avoiding hallucinations yet explicitly allowing or failing to address many LLM-enabled features like Copilot in Word, AI Overviews in Google; Brooks v. Patel (vLex Fastcase, predecessor to Clio Vincent, $5,000 fine in Minnesota)
- Can't just check whether the case exists: there have been more and more cases with fake quotations, mischaracterization of real cases, misattribution of quotes to the wrong speakers, and other failure modes that fit my taxonomy of AI hallucinations.
- I warned about risks of excessive agency and about overly sycophantic agents getting files by any means necessary: OpenAI–Hugging Face, July 2026.
- The cover-up is worse: Nebraska Supreme Court case attorney did not admit AI misuse initially, suspended until further notice.
- AI Policy without AI training on specific LLM failure modes and your policy should be []”human first in, last out”](/blog/stop-saying-ai-junior-associate#better-metaphors-japanese-point-and-call-and-the-glass-donut-machine) for editing: e.g., Sullivan & Cromwell incident in SDNY bankruptcy case.
- AI misuse would be a big topic. As of today, August 18, 2026, there are a lucky 1313 U.S. hallucination cases in Damien Charlotin’s database and if we count from Q4 2025, there were 1003. In other words, there were over 1000 cases from when I started my company, and there had only been about 300 before that. Does that sound like “the models are getting better?” There have been cases in every single U.S. state (once you properly clean the data, which I did).
Every AI hallucination case or other major AI case I have written about, along with a small citation graph. Can be filtered for state or federal only, and federal cases show district borders. See the dedicated page at Risks of Legal AI.
Mixed Predictions
- AI coding agents’ usefulness. I would say that I was very right about their potential for destruction and their risks to the user. I was also right that the models “getting better” (which I reframe as “more capable”) does not eliminate this risk—users who got access to ChatGPT Sol, the most advanced Codex model, for example, reportedly had SSDs degraded due to rapid rewrites and some apparently sophisticated users self-reported on X that they had Codex take destructive agentic actions. On the other hand, I had said earlier in the fall that coding agents were mostly not useful for small businesses or worth the risk tradeoff; the capabilities grew rapidly with the consensus, myself included, noting a marked change in late 2025/early 2026 to the point that they are very much useful even to highly experienced programmers. So, they are worth learning, but you must still exercise caution and not delegate too much, which is actually very difficult.
- Legal fight between companies over AI agents. I predicted that different companies have different incentives around use of an AI agent. and I even thought Amazon might be a battleground for it—I have notes of a quote from Sam Altman talking to Tyler Cowen about it—but I didn’t write the article in time and it ended up being about Perplexity rather than ChatGPT. Current status is Amazon v. Perplexity (9th Cir.) vacated injunction Aug. 4, 2026; user-directed access defeats CFAA. I am also surprised that thus far there have not been any legal cases related to “loss of control” incidents.
Missing Predictions (Not Predicted)
- OK I expected case numbers to keep growing dramatically, but not THAT dramatically. I have the crazy idea that if I wrote about a few cases a day, I would eventually catch up. This was silly. I have written about a lot of hallucination cases in detail MAP HERE, and looking at the details has mattered a lot. But the daily flood of new hallucination cases, not to mention the existing backlog, is too much to do just to in detail (unless I want to slop together reports, and I don’t.)
- Did not expect coding agents to take off the way they did in late 2025-early 2026, nor to become so personally useful to me. Nevertheless, the risks still apply.
- Did not expect Pangram to emerge as such a strong and credible tool for detecting AI-generated text, and a welcome addition to X and Substack; however, there are still problems with the tool (often not the ones noted by uninformed critiques who make generic attacks on AI detection in general).
- The privilege and work-product issue: Heppner (S.D.N.Y.) vs. Warner v. Gilbarco (E.D. Mich.). My focus was more on privacy and information security from the perspective of attorneys' use than the legal rulings around clients' use. Over the past year, I have significantly increased the coverage of clients' AI use and misuse in my GenAI Policy Consultation with clients: from the "WebMD for law problem" to potential for deepfake evidence to communication challenges with AI email summaries and responses to clients providing "helpful" caselaw research (hallucinated).
Third Parties
- Opposing counsel: Nuvola v. Wright (Minnesota)
- Taking over for previous counsel: Payne v. State (Georgia)
- Pro hac/local counsel, even if did not use the AI but are supervising or on the signature line: Lexos v. Overstock (D. Kansas), Withers v. City of Aberdeen (N.D. Mississippi)
- Trial judge: Payne, Torres Campos, H.C. v. Contreras
- Unofficial AI Transcript is unreliable: U.S. v. Smith (E.D. Mich.) hinged on the difference between the AI-generated transcript rendering a statement when the audio recording showed it was question; there is a case before Texas Supreme Court now debating court reporters v. AI transcripts
- Court reporter "cleaning up" transcript mixing up parties (this is about rewrites, not speech-to-text) or "searching" transcripts: Williams v. State (Ind., July 23, 2026), State v. Coleman (Ohio)
- Non-attorney staff: Coleman, Doiban
- Problems with third-party meeting recording (note: I talked about this from a social norms and personal privacy and security posture perspective, not a legal opinion; recorded May 28, 2026 and live July 28, 2026 — https://podcasts.apple.com/us/podcast/ai-or-not/id1746993808?i=1000778675121) compared to lawsuit against OtterAI, In re Otter.AI Privacy Litigation in N.D. California but also alleging violations of Illinois privacy laws, among others — https://news.bloomberglaw.com/litigation/otter-ai-stuck-with-privacy-lawsuit-over-meeting-transcriptions
Details: AI & Law
- Retained as expert in LTL LED, LLC (Wolf River Electric) v. Google LLC, which had been removed to D. Minnesota in mid-2025, covered in major outlets like the New York Times, and then remanded to Minnesota state court Jan. 2026
- CLE Accreditation: Seven states accredited: IA, IL, MN, NE, KS, VA, NC — https://midwestfrontier.ai/cle/intro
- One course an hour of general credit plus NC Technology Credit
- One course an hour of ethics/professional responsibility/other equivalent in the seven jurisdictions
- Thanks for the shout out from David Timm on Beyond the FAR podcast about the CLE - https://podcasts.apple.com/us/podcast/beyond-the-far/id1784733007?i=1000764179356
- Co-presented with Joe Bambara for a half-day ACI conference CLE workshop titled "Explaining Your AI Tool to the Regulator: Everything FS Lawyers Need to Navigate AI Audits and Reviews," which included using synthetic data for tabletop exercises. I have since adapted the synthetic data process to an immersive training demo for law enforcement and AML professionals: if you are interested, email me at [email protected].
- Presented (as a substitute speaker) for a CLE on e-Discovery for NBI. I mentioned the risks of hidden prompt injection in large document dumps. Of course, prompt injection is now the topic du jour on LinkedIn because of a case in Connecticut (see).
- Contributed cases to the Damien Charlotin hallucination database and helped with some corrections and updates to existing entries. I wrote about the high quality of Charlotin’s database and how this can nevertheless result in slop reports for those who churn out unreviewed LLM-authored reports on the basis of that data without reviewing it here: https://midwestfrontier.ai/blog/not-just-gigo-do-not-dunk-on-the-dakotas
IOUs
Here are several articles that I promised or alluded to writing over the year in my blog posts or have in my drafts folder, which I still owe readers (as a methodology aside, this was a good place to use LLMs for a first pass, because Claude could look at everything in context and call me out on what I had missed, although it hallucinated at times and all of these have been manually rewritten):
- Privacy-settings guides for ChatGPT and Claude, promised alongside the Google Gemini privacy guide, which are available in my CLE but not public-facing posts; updates are also needed for 2026
- A write-up on modernizing Taprats (Islamic geometric tile pattern tool) with Claude Code, teased in the GIS with Claude Code post (Jan. 6, 2026)
- Full write-ups for several other 2025 side projects only summarized in Odd Projects of 2025 (Dec. 29, 2025)
- Continuing the AI detection series on SynthID and AI-content detection, kicked off on April 1 and promised in a footnote of the UMN AI/Human Legal Reasoning Study post (Apr. 13, 2026)
- I already have drafts on Adams v. Anderson (Kentucky) (from June 2026) and Matter of M.S. (New York)
- I intend to write about Pangram: the good effects, the errors and failure modes, the narrative around AI detection use, the flaws, whether detection resembles an arms race, and other challenges to public uses of detection.
- Fivehouse v. DoD (E.D. North Carolina): career DOJ AUSA lost job after hallucinated citations identified by pro se litigant (former Air Force judge advocate)
- Lowery Wilkinson Lowery, LLC, et al. v. State of Illinois, et al. (E.D. Oklahoma): I touched on this in the article on slop reports but it deserves its own article given that I went to college in Oklahoma and it involves Illinois, so it’s got the Midwest angle, plus a hallucination trying to creatively extend McGirt while misattributing it to the judge in the case, rather than to Justice Gorsuch
- I had said on LinkedIn that I should do a writeup of all the state Supreme Court cases that have had generative AI misuse in the past year. I need to review the list and make sure I get all the details correct before writing the final version, but thus far I believe we’re at:
- Prososki v. Nebraska (Nebraska Supreme Court): family law attorney suspended over hallucinated citations in divorce case
- S26A0459 Payne v. The State (Georgia Supreme Court)
- Vermont Supreme Court case, a New Hampshire attorney introduced the fake case after receiving them from a client
- Matter of MS was in New York’s highest court, which is not the “Supreme Court”
- Kosel Equity v. McGregor (Connecticut Supreme Court)
- There were also disciplinary matters relating to attorneys in Oklahoma and Iowa under the state Supreme Courts but not the same as what I was referring to, which is misuse in an existing case in a case before the Supreme Court.
- State v. Coleman (Ohio Supreme Court): this involved using AI to search for quotes in a court transcript, getting ungrounded hallucinations that misattributed and fabricated inflammatory quotes to various individuals, which the Court described as “defamatory allegations.”
- Volker v. Nygaard (North Dakota Supreme Court), involves a Minnesota pro se litigant; I have not read anything about this case yet
- Texas Supreme Court case involving AI transcription
- Any others I may have missed
Year to Come
Here are some of my predictions for AI and my research plans.
Big Picture Security and AI Safety
I am exploring options to work more on frontier model safety and policies around securing AI models and preventing large-scale misuse. Obviously, I think misuse in law will continue to be a major area of societal concern, but cybersecurity risks continue to grow with model capabilities and with it the risk of attacks on critical infrastructure.
Research Areas: Judges and Law Schools
Within the legal domain, I am going to focus on documenting standing orders, rules around judicial use of AI, AI software rollouts targeting judges, polls and research on judicial use of AI, and other related information.
I will also be documenting universities’ policies around AI and other technology and device policies that are motivated by the desire to adapt to AI in the classroom. As I am able, I also want to identify which AI tools are being taught to or provided to law students based on publicly available information.
Helping More AI Use Policies
I think more law firms are realizing the need for AI use policies as they hire new graduates leaving law school never having a time when they did not have access to an AI tool like ChatGPT. From now on, there will never again be a crop of law students for whom AI wasn’t available during law school (policies notwithstanding as noted above).
If you want to get a sample of what my policy consultations are like, try the free 3-minute assessment.
On Software
In my initial blog post I said:
We are not selling any particular software, device, or tool. Instead, we want to equip our clients with the knowledge to be effective users of whichever generative AI tools they choose to use. This may mean realizing that all they need is a free tool or getting the most value they can out of an expensive subscription. It may also mean making an informed decision not to use GenAI tools. With GenAI features being added to familiar software like Microsoft Word or Google Search, opting out of GenAI is an intentional decision rather than a default. We can help clients with this option as well, understanding how to limit GenAI exposure as much as possible.
I still stand by the principle behind this, that not everyone needs to use generative AI and I support clients who want help crafting policies and training that limit or ban generative AI use for work purposes.
However, what I’ve learned is that not everyone wants to use LLMs themselves. They just want the solution. So, moving forward, I will also be open to helping clients build custom software solutions for their specific problems if they prefer that option over learning how to do it themselves.
Games and Learning
I am making more educational games and a learning track that I will be beta testing.
Legal Misuse of AI Should Be Treated Like a Public Health Issue
I think the discussion around legal misuse of AI remains pretty naive. For example, the breathless discussion of the “first” prompt injection attack on a court because of the Connecticut case a week ago should actually be far more troubling to lawyers and judges.
We already saw the legal prompt injection attempt example from Brazil in May 2026. Is it really the case that no one in a nation of nearly 350 million people with one of the highest LLM adoption rates in the world didn’t have a single such attempt in the past three months? Think about it seriously.
If you find an ant in your kitchen, you should not conclude you had exactly one ant in your kitchen.
If your city had found 1 case of Covid in 2020 the first time they administered a test to anyone, you definitely should not have concluded that you lucked your way into detecting the one and only person who had Covid. If that person were only detected at random and not through strict contact tracing and screening, you would probably conclude you have community spread.
We do not have, as far as I am aware, Courts doing systematic searches for indirect prompt injection attempts beyond the protections built in to the frontier models’ APIs (which, to be clear, protect from quite a lot of unsophisticated prompt injection attempts now and are used in most of the mainstream legal AI tools). But prompt injection has been around since at least late 2022 when Riley Goodside and Simon Willison were writing about them. I have been teaching people about these risks since at least early 2023.
We need to get to a point where as a matter of course attorneys and judges are systematically checking for hallucinations, prompt injections, and other AI risks, checking the work of those they supervise, checking clients, and checking adversarially for opposing counsel and the other party. I’ll lay out a more detailed blog post dedicated to this “public health” approach in the near future (another IOU on the pile).
Writing on AI and Parenting
My personal Substack is where I write about parenting, board games, and books (especially children's books). Of course, I've been thinking a lot about generative AI, so if you're interested in my thoughts on how parenting and AI relate, here are a few posts. I actually feel reinvigorated to write more thanks to the Pangram integration in Substack, which is not something I had expected:
- “This Book Can Help You Talk to Your Kids About AI. “Creepy Crayon!" Review”; I write about the character’s temptation to use the Creepy Crayon to cheat on all homework is an individual choice, but we have a society-wide problem
- “I Want More Funny and Weird Poetry”: Review, Book Advent Calendars, and an Aside About Emdashes”; I write about the absurdity of people using certain shibboleths to try to tell if something is AI-written, but this does not apply to Pangram; I also mock the absurd trend in “my typos prove it is human written” as the pre-ripped jeans fad of our day, because LLMs can easily mimic intentional typos, no capitalization or punctuation, and other formatting tricks. By the way, typing an emdash in real life is dash dash space “-- “.
- “Enjoying the Northern Lights and Thinking About Books and Technology”; I write about when technology can be helpful in connecting people and I have an aside about how ChatGPT’s search capabilities have helped me dig up specific half-remembered stuff from when I was a kid.
- “On Table Saws and Toys: How I Think About “AI For Kids””; I write about using Claude Code to make stuff for my kids, how that doesn’t mean I want my kids interacting with LLM chatbots, and other problems with throwing frontier APIs into everything. Through the lens of Small Soldiers.