PwC Credited Four Governments With Using A Product That Nobody Can Find
By Gabriel Tan | August 2026
PwC Middle East published a report saying the governments of Denmark, Saudi Arabia, the United States and Australia were all using a service called Citizen Pulse.
GPTZero, a company that builds artificial intelligence (AI) detection software, went looking and could find no public evidence that the product existed or that any of those four governments had bought anything. Its investigators scored the page carrying those case studies as entirely machine-written.
The Financial Times checked the work independently and reported it on 29 July 2026. I verified it across the original investigation and a dozen other outlets, because I was not going to build advice on a story that turned out to be wrong.
Here is the part your team needs.
Why a citation being present is not evidence that anyone checked it
Those fabricated case studies carried citations. The citations were live links to real government portals. Click one and it opens, on a genuine page of a genuine government website.
The page just does not say what the report claimed it said.
A citation sitting under a claim looks like the work was done. It was not. Placing a citation is going through the motions, and a machine can go through those motions perfectly. It will produce a source-shaped object, pointing at a real and working address, with nothing behind it that supports the sentence it is attached to.
That is why every automated check passes. A link checker sees a live URL. A junior confirming that every footnote resolves sees a live URL. Anyone scanning the reference list for something that looks broken sees nothing broken.
The only check that catches it is a person opening the page and reading it against the claim.
The same failure at all four of the largest accounting firms
Firm What happened
Deloitte Issued a partial refund to the Australian federal government after a report contained errors traced to AI use
EY Withdrew a study on loyalty rewards programmes after a probe found apparent hallucinations and fake footnotes
KPMG Pulled a report making false claims about AI use at UBS, the National Health Service and Transport for London
PwC Credited four governments as users of a product nobody can find
PwC Middle East's response was that it takes the accuracy of its published research seriously, and that it has quality control processes for research and content development that it expects all its people to follow.
I believe them, and that is exactly why this should worry you. The controls existed. They just did not include the step where a person reads the source.
If firms that sell rigour for a living cannot catch this with the review layers they have, your agency will not catch it by being careful.
The two review blocks that sit after the machine step
We put two review blocks after the machine does its work, not one. They catch different things, and how you run the first decides whether it catches anything.
Block one is a machine reviewing the output, and it cannot be the same machine, in the same conversation, that produced it. An assistant carrying the context that created an error will defend the error, because it already decided the claim was reasonable.
So move the draft before you review it. Paste it into a fresh chat with no history, or better, into a different model, then ask for every factual claim and the source behind each one, in a table. A reviewer with no memory of writing it reads the draft the way a stranger would.
That gives you a list, including the claims the machine cannot source.
Block two is a person checking every claim on it. Not the machine. A human being opens every source and finds the statement in the words of the page. Not the same topic. The same statement.
Block one narrows the work down to a list. Block two is the block that would have stopped PwC, and there is no version of this where software does it for you. The failure in that report was invisible to software by design.
Why you check every claim rather than a sample
There is no acceptable failure rate here, so do not calculate one.
Sampling works when defects spread evenly and a rate tells you something useful. A fabricated citation is not that kind of defect. It sits in one sentence and is invisible everywhere else, and the number needed to put four governments into a PwC report was small.
So check every claim and every citation in the document. The whole report, not a portion of it. A report you have sampled is a report you have not checked, and anything you cannot confirm in the words of its source comes out or gets re-sourced before it publishes.
What to put in place before your next AI-assisted piece
Take the last client-facing piece your team produced with AI help. A report, a release, a set of talking points. Two minutes to choose it.
Run block one in a clean context. Paste the draft into a fresh chat with no history, or into a different model, then ask for every claim and its source, in a table. Fifteen minutes.
Run block two yourself, or give it to a named person. Open every source and find the claim in the words of the page. Forty-five minutes for a typical report, and this is the block PwC did not run.
Pull or re-source anything you could not confirm. Twenty minutes.
Name the person who signs before publication. One conversation, ten minutes. A role does not read footnotes. A person does, and their name goes on the document.
One limit worth naming. This tells you whether your claims are supported. It says nothing about whether your recommendation is any good, or whether a well-sourced claim is the wrong one for this client. That is the senior read, and it stays human for the same reason block two does.
Somebody at PwC wrote four governments into a report as customers, somebody laid it out, somebody approved it, and it was published under the firm's name. I doubt any of them were careless. There was simply no point in the process where opening a link and reading it was a named person's job.
Gabriel Tan is the founder of Mekong Bridge Advisory, the lean consultancy for PR and IR agencies.