At oral argument in the Ninth Circuit, counsel for an asylum applicant was asked whether generative AI had written the briefs. He said no. Asked again, no. Asked a third time, he allowed that it was “possible”. The briefs cited Eduardo v. Garland and Lay v. Holder, neither of which exists. On 3 June 2026 the court fined both lawyers, suspended them from practising before it for six months, referred them to the State Bar of California and ordered two years of sworn AI disclosures on every filing from their firm.

So AI for immigration lawyers cannot be a list of time-saving tips, real as those are. That order is among the harshest appellate sanctions of the AI era, and it is no accident that it fell on an immigration practice: immigration is where high volume, thin margins and outsourced drafting meet a technology that produces confident, plausible, wrong text on demand.

Why AI for immigration lawyers is uniquely exposed to failure

The sanctions data are clear about who gets caught. Riana Pfefferkorn’s Stanford analysis of 114 US cases in which lawyers filed AI-tainted material found that solos accounted for 50.4% of the firms involved and firms of two to twenty-five lawyers for another 39.5%: roughly 90% small practices.

The second pattern is outsourcing. Both defining US immigration cases involved briefs written by someone other than the signing lawyer: in Lnu v. Blanche by unlicensed law graduates with no attorney citation review, and in Dehghani v. Castro (D.N.M., 2 April 2025) by a freelance attorney who apparently used generative AI, unchecked by the lawyer who bought the brief and paid with a fine, mandatory CLE and self-reporting to the state bars.

The third is volume from the other side: of the 2,039 decisions in Charlotin’s hallucination database on 12 September 2026, 1,173 involve self-represented litigants, and the Upper Tribunal noted “a considerable increase in the latter half of 2025 in the citation of fictitious authorities.”

Lnu v. Blanche: three denials at oral argument and a six-month suspension

The Ninth Circuit’s order in Lnu v. Blanche, No. 24-4790, is the document to read in full, because its standard is now the standard. The fakes were Eduardo v. Garland, 28 F.4th 742, and Lay v. Holder, 729 F.3d 962, alongside two real cases misquoted. The court did not sanction AI use; it sanctioned what came after:

“But a competent and diligent attorney must do more than prompt generative AI, check that the citations provided by the AI are real and the subject matter roughly on point, and call it a day. … A competent and diligent attorney must also read and reason.” — Ninth Circuit (Paez, Bea, Forrest JJ.), Lnu v. Blanche, 3 June 2026

And: “the rules are not violated at the point of research and drafting, but at the point of signing and filing.” The discipline was calibrated to the cover-up as much as the citations, and the two-year order requires every filing from the firm to carry an under-penalty-of-perjury statement disclosing whether generative AI was used, naming the tools and certifying that the signing attorney personally reviewed every citation.

The UK Upper Tribunal and the statement of truth for every citation

The English equivalent arrived first. In [2026] UKUT 81 (IAC), promulgated 17 November 2025, a solicitor at TMF Immigration Lawyers had cited “Horleston v SSHD [2007] EWCA Civ 654”: a real neutral citation belonging to an unrelated equal-pay case. He had “inadvertently used the ‘AI Mode’ of a Google search”, and the tribunal reproduced the hallucination live, getting different Court of Appeal benches for the non-existent case by rephrasing the query. He had also pasted client emails about Home Office decisions into ChatGPT to “improve” them:

“To put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege.” — Upper Tribunal (Immigration and Asylum Chamber), [2026] UKUT 81 (IAC) at [21]

The judicial review claim form now requires a statement of truth that every cited authority “(a) exists; (b) may be located using the citation provided; and © supports the proposition of law for which it is cited”, and headnote 2 tells supervisors they “must ensure that fee-earners under their supervision are aware of the dangers of using non-specialist Artificial Intelligence (AI) for legal research and drafting”. Both solicitors, the second from City Law Practice, are under SRA investigation. The SRA’s warning notice of 17 August 2026, issued after 42 reports of potential misuse in a year, adds: “Reliance on an output of AI would not be a suitable defence.”

Lnu v. Blanche (9th Cir.) [2026] UKUT 81 (IAC)
Matter Asylum, withholding, CAT Immigration judicial review
Who drafted Unlicensed law graduates Solicitor using Google AI Mode; a part-time trainee at the second firm
The fake Two non-existent cases, two misquoted Real citation, wrong case, invented bench
Confidentiality finding None Client letters in ChatGPT are “in the public domain”
Outcome $2,500 each, six-month suspension, bar referral, two years of sworn disclosures SRA and ICO referrals; statement of truth on the JR form; supervisors on notice

Other European decisions are collected in AI hallucination cases in the UK, Germany and Europe.

Intake and triage: the workflows that pay for themselves

None of that makes the tools useless. Greg Siskind of Siskind Susser publishes prompting tips that are refreshingly specific: assign a perspective (“Act as an immigration lawyer advising a client on a J-1 waiver issue”), be concrete (“Summarize this client’s I-601A waiver consultation and list potential red flags”), and iterate: “Think of it like working with a junior associate or paralegal: give feedback, ask for revisions, and experiment with different approaches to improve the output.”

Intake is where the hours are. An anonymised consultation note becomes a triage sheet in a minute:

Consultation note to triage sheet
From the anonymised consultation notes below for a prospective [family-based / employment-based / asylum] client, produce: (1) the likely form of relief and the two most plausible alternatives; (2) every eligibility criterion for each, as a checklist marked MET / NOT MET / UNKNOWN from the notes only; (3) red flags (prior removal, unlawful presence, criminal history, misrepresentation, missed deadlines) with the fact that triggers each; (4) documents to request, in priority order; (5) the questions I must ask at the next meeting.
Cite no statute, regulation or case; write [VERIFY] where a legal rule matters. Do not invent any fact not in the notes.

Notes:
[paste]

The lawyer then does the part that is law. Kevin J. Andrews, an immigration lawyer who asked ChatGPT “How do I open a terminal?” in April 2025, had a solo practice and a software platform running by February 2026 without writing a line of code, on “a radical sense of intellectual humility”.

Evidence chronologies and declarations without inventing facts

The model’s legitimate job with evidence is to organise what you give it and show where the gaps are.

Evidence checklist mapped to the criteria
For a [category] petition for a beneficiary who is [anonymised profile], using only the regulatory criteria in <criteria> (current as at [date]) and the document inventory in <inventory>: map each criterion to the documents that support it and to the gaps, giving date, author, one-line content and exhibit number per document; then outline a cover letter arguing the criteria in order of strength, citing exhibit numbers, with every legal assertion marked [VERIFY].
Do not invent exhibits, dates or achievements. Where a criterion has no supporting document, write NO EVIDENCE YET.

The declaration is different. It is the client’s testimony, and the Supreme Court of New South Wales has said what most immigration judges assume: generative AI “must not be used in generating the content of affidavits, witness statements, character references or other material that is intended to reflect the deponent or witness’ evidence” (Practice Note SC Gen 23, para 10). The reason is on the record: a Santa Fe lawyer who asked ChatGPT for “a bulletproof summary” of a transcript filed “false testimony from wholly fabricated witnesses” and was fined $5,000 in September 2026. Use the model to structure the interview and check the account against the documents; the words on the page are the applicant’s.

Country-conditions research: sources or nothing

A general model will produce fluent paragraphs about conditions in any country, in any year, sourced or not. Harvey’s benchmark team put the failure mode in one line: agents’ “bias is to search efficiently, not completely. Diligence requires reversing this intuition.” The fix is a source fence.

Country-conditions brief with a source fence
Produce a country-conditions briefing on [treatment of [group] in [country]] as at [date] for an asylum application. Use only sources you can cite with a working link: government human-rights reports, UN and treaty-body documents, established NGO reports and named news organisations. For every claim give source, date and page or section. Where you cannot find a citable source, write NOTHING FOUND rather than describing conditions from general knowledge. Flag any report older than [18 months] and list the sources you searched without result.

Then click every link. A research agent with browsing suits this task better than a chat window; a legal research platform suits the case law, and the six-layer verification protocol is the minimum before anything is filed.

Translation and interpretation: where AI helps and where it must not

Immigration files are multilingual, and machine translation is the AI most immigration lawyers used before ChatGPT; in a 2024 survey of Bavarian lawyers, DeepL was the single most-used AI tool at 70.7%. Two limits apply. The certified translation in the filing is a personal attestation of accuracy, and a model’s output is not a translator’s certificate. And the CCBE’s 2025 guide warns that generative AI is now embedded in “translation tools, PDF readers, text editors”, so “the same care should be taken” with confidential material. The legal translation guide covers the back-translation check.

Confidentiality for vulnerable clients and the local-model option

Immigration clients are the people least able to absorb a leak. The Law Society’s rule for a free online AI service is “do not put any confidential data into the tool”, and Morgan v. V2X (D. Colo., 30 March 2026) set the same standard contractually: no confidential material into an AI platform unless the provider is prohibited from training on inputs and disclosing them to third parties.

The most sensitive facts can stay inside the building. A tech blog reports an immigration attorney running Llama 3.1 on a MacBook Pro to brainstorm case framing with real client facts, “something her firm’s cloud policy explicitly forbids”; the anecdote is unverified, the set-up is not. A practitioner’s guide puts Ollama with Llama 3.1 8B on a 16 GB laptop in about fifteen minutes (see the local LLM guide), with the caveat that matters: “Three of the five cases it gave me either didn’t exist or had holdings that said the opposite.” Local solves confidentiality, not accuracy.

A supervision protocol for outsourced and junior drafting

Every authority points the same way. ABA Formal Opinion 512: “supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools.” North Carolina’s 2024 FEO 1: Rule 5.3 applies “to nonlawyer assistants within a law firm as well as those outside of a law firm … such as third-party software companies.”

A protocol a three-lawyer immigration firm can run:

  1. Written disclosure from every drafter. Freelancers, contract attorneys and law graduates state per document whether generative AI was used and which tool. Silence is treated as yes.
  2. Approved tools only, named. A one-page policy lists the no-training tiers the firm pays for; consumer tools are not used for client material.
  3. Anonymise before any general model. Names, A-numbers, addresses and dates of birth become placeholders; the key stays on the firm’s drive.
  4. Every authority opened by the signer. Not confirmed by the model: opened in a real database, read at the pinpoint, run through a citator. The Lnu standard is “read and reason”.
  5. A verification log per filing. Who checked what, where, when. Insurers ask at renewal; courts ask afterwards.
  6. The client’s words stay the client’s. Declarations are taken down from the applicant and translated by a person who certifies.
  7. Self-report on the day you find a fake. Courts escalate for the denial, not the citation.

Where to go next: the practice-area hub covers the neighbouring fields, the 30-day plan for solo and small firms turns the protocol above into a rollout, and the prompt library has more.

Frequently asked questions

Can immigration lawyers use ChatGPT for asylum declarations?

Not to generate the content. A declaration is the applicant's own evidence, and the Supreme Court of New South Wales has banned generative AI from generating the content of affidavits and witness statements, a rule worth adopting anywhere. AI can help you structure the interview, spot gaps against the regulatory criteria and produce a chronology from documents you supply. The words, the facts and the signature remain the client's, taken down in a no-training tool.

What happened in Lnu v. Blanche?

On 3 June 2026 the Ninth Circuit sanctioned two immigration attorneys whose asylum briefs cited two non-existent cases and misquoted real ones. The briefs had been drafted by unlicensed law graduates without citation review, and counsel denied AI use three times at argument before conceding it was 'possible'. Each was fined $2,500, suspended from Ninth Circuit practice for six months and referred to the State Bar, and the firm must file sworn AI disclosures for two years.

Is AI translation reliable for immigration evidence?

Reliable enough for triage, not for the certificate. Machine translation lets you read a hundred pages of foreign-language evidence in an afternoon and decide which twenty matter. The certified translation that goes in the filing is a personal attestation of accuracy by a competent translator, and the CCBE warns that generative AI is now embedded in translation tools, so the same confidentiality care applies. Use a no-training tier and have a human check anything that will be relied on.

How can a small immigration firm supervise AI-assisted drafting?

Treat every drafter, human or machine, as a nonlawyer assistant under Rule 5.3. North Carolina's 2024 FEO 1 says the rule reaches assistants outside the firm, including third-party software companies. Practically: no filing goes out without the signing lawyer having opened every cited authority in a real database, a named person records who verified what and when, and outsourced drafters disclose in writing whether and how they used AI.

Which AI tools are safe for immigration client data?

Only tools whose terms prohibit training on your inputs and disclosure to third parties: ChatGPT Business or Enterprise, Claude Team or Enterprise, Copilot with enterprise data protection, or a legal platform. Consumer tiers are out: the UK Upper Tribunal held that pasting client letters into ChatGPT places them in the public domain, and a New York court held consumer chats unprivileged. For the most sensitive facts, a local model on the firm's own machine keeps everything inside the building.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.