Authorized to Draft Is Not Authorized to File
The Supreme Court of New Mexico held an attorney in direct contempt after he signed and filed an appellate brief containing testimony from fabricated witnesses and misrepresented legal authority. He had used ChatGPT to prepare it, and he admitted he never checked whether any of it was true before it went to the court.
Event analysed: . This analysis was published on 12 September 2026.
No, and the Supreme Court of New Mexico said so through a direct contempt finding rather than a guideline. In a Dispositional Order of Direct Contempt decided September 9, 2026 in State v. Sandoval, S-1-SC-40845, the court found that attorney Stephen Aarons used ChatGPT to prepare an appellate brief containing, in the order's own words, false testimony from wholly fabricated witnesses, along with misrepresented legal authority. Aarons acknowledged using the tool and admitted that he did not verify the factual claims and legal authority it produced before he signed the brief and filed it with the court. Nothing about being permitted, or even well advised, to use an AI tool to prepare a first draft extended to being excused from the separate step of checking that draft before it became a filed representation to a court under his own signature. The court struck all briefing filed in the matter, replaced Aarons as counsel, referred him for professional discipline, barred him from appearing before the court while that process runs, and imposed a five thousand dollar sanction.
The order is short on ambiguity. Stephen Aarons, counsel of record in a criminal appeal before the Supreme Court of New Mexico, used ChatGPT to help prepare an appellate brief. The brief that reached the court contained, as the court's own Dispositional Order of Direct Contempt states, false testimony from wholly fabricated witnesses and misrepresented legal authority. Aarons acknowledged as much, and he went further: he admitted he did not verify the factual claims and legal authority the tool produced before he signed the brief and filed it.
The court's response was not a warning. It held Aarons in direct contempt, struck all briefing filed in the matter, replaced him as counsel, referred him for professional discipline, barred him from appearing before the court pending that process, and imposed a five thousand dollar sanction.
Capability to prepare, not authority to file
Nothing in the order suggests that using an AI tool to help draft a brief was itself the violation. What the order treats as the failure is narrower and more precise: Aarons signed and filed the brief without independently checking whether what it said was true. Preparing a document and being entitled to submit it as an accurate, verified representation to a court are two different authorities, and this order is direct evidence that a professional obligation to verify sits between them regardless of which tool, or which person, produced the first draft. An attorney's authority to use a drafting aid does not, on its own, ever extend into authority to skip the check that turns a draft into a filing.
That distinction matters beyond this one case because the same shape recurs whenever a system, human or automated, is authorized to prepare a consequential output and nothing separate confirms that output before it takes effect. Here the separation was never automated away: it was a professional's own duty, and the order's own account is that the duty was not performed, not that no mechanism existed to perform it.
What the record establishes, and what it does not
This record is built from three excerpts of the court's own order, mirrored in full text by Justia, since a court hosted written-order URL was not the route through which the order text was captured. The Supreme Court of New Mexico's own recordings-of-oral-arguments listing independently confirms the case number and its show cause hearing, and Reuters reported the same five thousand dollar sanction and the same ChatGPT attribution independently. Between them, an official docket confirmation and independent journalism corroborate the order's own account.
What this record does not establish is also worth stating plainly. It does not identify which specific witnesses were fabricated or which specific authority was misrepresented beyond the order's own quoted language. It does not establish how the fabrications were first discovered, or by whom. It does not state the eventual outcome of the discipline referral against Aarons, which the order refers onward rather than resolving itself. Those facts are recorded here as unknown, not inferred from what a similar case might suggest.
Where this sits against what Moona Intelligence has already written
The gap between authority to prepare a change and authority to enact it recurs across this desk's own reporting, most often as an agent delegated both halves of a workflow that was designed to keep them separate. This record extends that same authority gap to a different shape: not an agent holding both roles, but a human professional who occupied the separate, supposedly independent role and did not perform the check that role existed to provide. The gap is the same. The actor who failed to keep it closed is not.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
Protocol evidence
This record does not assess these architectures. The connection runs through the Risk Registry requirement each one bears on, and these published authority architectures are what the evidence says about that requirement.
Protocol evidence related through AEW-003 Execution authority collapsed into capability to prepare
- Supports requirement
Agent Infrastructure Control Protocol (AICP)
Tihan-Nico Paxton, Apollo Deploy (individual submission to the IETF)
Requirement Capability discovery is explicitly separated from an authorization grant
This weakness names the collapse of capability to prepare into authority to enact. AICP's own Section 6.3 states the corrective directly for the discovery stage specifically: a capability listing indicates discoverability, not a durable authorization grant, and policy is evaluated again when planning and immediately before execution. Section 4.2 restates the same boundary as a provider obligation, that authority must be derived from authenticated server side context rather than granted because a request body claims it. Recorded as design evidence for the requirement this weakness already states, not as a claim that any provider has implemented this draft's text.
- Reveals bypass
Slack Code, code channels and expert sign off for high stakes actions
Slack, a Salesforce company
Requirement Slack itself is the point at which the production decision is enforced
Slack Code carries a change to the edge of production and describes an expert sign off, but Slack is not the point at which the deployment is enforced, and no artifact binds the sign off to a refusal on the far side. The weakness names exactly that gap.
