
EXECUTIVE SUMMARY
KPMG International published a report titled "Total Experience: Redefining Excellence in the Age of Agentic AI" in October 2025, positioning the firm as an authority on responsible AI deployment across enterprise and institutional settings. On June 12, 2026, research firm GPTZero published a forensic investigation establishing that 40 of the report's 45 citations had fabricated, paraphrased, or unverifiable titles; that roughly half of the report's factual claims were false or misattributed; and that named organizations including UBS, the UK's National Health Service, Swiss Federal Railways, and Transport for London publicly disputed the claims attributed to them. KPMG removed the report from its websites on June 13, 2026 while conducting its own investigation. The incident followed a nearly identical withdrawal by EY the prior month. KPMG had, in the same assessment period, publicly launched AI agents for regulatory and compliance use cases, positioning itself as a governance authority for enterprise AI adoption. It cannot be both.
Overall Accountability Standing: FAILING
A firm that markets AI governance advisory services to enterprise clients while publishing research that failed every basic evidentiary standard it would apply to a client's own AI outputs has a fundamental accountability gap between its stated posture and its demonstrated practice.
SUBJECT PROFILE
Entity: KPMG International, an English private company limited by guarantee, headquartered in London. Coordinating entity for member firms operating in 138 countries with more than 250,000 employees.
Operating Context: One of the four largest professional services and accounting networks globally. Provides audit, tax, and advisory services including AI governance, risk management, regulatory compliance, and technology strategy to enterprise and institutional clients worldwide.
AI Systems in Scope: AI-assisted research and authoring tools used in the production of "Total Experience: Redefining Excellence in the Age of Agentic AI" (October 2025). KPMG's publicly announced AI agents powered by Google Cloud Gemini Enterprise for regulatory and operational use cases (April 22, 2026).
Systems Excluded: KPMG member firm client-side AI deployments, which are out of scope for this assessment.
Prior Vordan Coverage: None. This is KPMG's first Vordan Accountability Report.
ACCOUNTABILITY FRAMEWORK APPLICATION
AAB ASSESSMENT
2.1 Agent Identity: FAILED. KPMG has not disclosed which AI system or systems were used in the production of the report, who within KPMG was responsible for configuring or directing those systems, or what parameters governed their use. The absence of any disclosed agent identity for the AI-assisted authoring process means there is no accountable origin for the outputs that failed.
2.2 Permission Scope: INDETERMINATE. KPMG's stated guidelines require human oversight to validate content and verify independent sources. Whether the AI system used in report production was operating within defined scope boundaries — or whether those boundaries existed and were enforced — cannot be determined from available evidence. The output pattern (systematic citation hallucination across 40 of 45 references) is consistent with a system operating without constrained scope on evidentiary claims.
2.3 Memory Governance: NOT IMPLICATED. This condition addresses memory persistence across agent sessions and is not directly implicated by this incident.
2.4 Activity Trail: FAILED. No audit trail of the AI-assisted research and authoring process has been disclosed. The absence of a traceable record of which claims were AI-generated, which were human-verified, and which passed through what review gates is itself the accountability gap. When four named organizations disputed factual claims about their own operations, KPMG had no disclosed mechanism for reconstructing how those claims were produced or approved.
2.5 Approval Gates: FAILED. KPMG's spokesperson stated the firm expects its people to follow guidelines requiring human oversight to validate content and verify independent sources. The publication of a report in which 40 of 45 citations were fabricated or substantially altered — including claims that named organizations publicly denied — establishes that no effective approval gate operated on the evidentiary content before publication. A stated policy that produces this outcome is a gate that did not function.
2.6 Forensic Readiness: FAILED. When the citation failures were identified by GPTZero and the named organizations disputed the claims, KPMG's response was to remove the report and announce an investigation into the circumstances of its publication. The firm had no pre-existing forensic record capable of immediately answering the most basic accountability question: who reviewed what, and when. That is not a post-incident gap. It is an absence that was present at the moment of publication.
2.7 Response Architecture: FAILED. No response architecture appears to have existed. Discovery came from an external research firm, not from any KPMG internal control. The response was reactive removal, not a structured correction process with named owners, timelines, or public commitments.
2.8 Model Substrate Integrity: INDETERMINATE. The specific AI system used has not been disclosed. Whether the hallucination pattern resulted from a model's inherent behavior, prompt design, retrieval failures, or some combination cannot be determined from available evidence.
AAB Summary: 0 of 8 conditions MET · 5 FAILED · 3 INDETERMINATE
VAF ASSESSMENT
Origin: FAILED. The report presents research claims and case studies as established fact without disclosing that AI was used in their production. The origin of the factual content — which claims were AI-generated, which were human-researched, which were verified by named individuals against primary sources — is not disclosed anywhere in the report. For a document that attributed specific capabilities and deployments to named organizations, the absence of disclosed origin is an accountability failure at the most basic level.
Voice: FAILED. UBS, NHS, Swiss Federal Railways, and Transport for London all publicly stated that the claims attributed to them in the report were false or misleading. Four organizations found their institutional voice represented inaccurately in a document they had no opportunity to review before publication. The report did not provide those organizations with any mechanism to be heard before the claims about them were published globally.
Traceability: FAILED. GPTZero's forensic investigation found that only 5 of 45 citations accurately pointed to their stated sources. The remaining 40 had fabricated titles, incorrect authors, fabricated dates, or source documents that did not support the claims they were cited to evidence. A citation structure that cannot be traced from claim to source is not a citation structure. It is a simulation of one.
Timing: FAILED. The report was published in October 2025. GPTZero's investigation was published June 12, 2026 — approximately eight months later. In the intervening period, the report's false claims circulated across industry publications, were cited in downstream articles, and were incorporated into LLM training and retrieval corpora. GPTZero's CEO specifically named the downstream contamination risk: publications by Big Four firms rank highly in search algorithms and AI research queries, and hallucinated statistics from the report were already being recycled in named publications before the retraction.
Response: FAILED. KPMG's response upon being notified of the investigation was to remove the report and issue a statement that it was reviewing the circumstances of its publication. No correction was published. No affected organization received a direct communication. No timeline for findings was stated. No named individual was designated as accountable for the review. The firm that advises clients on AI incident response did not follow the basic principles of AI incident response when the incident was its own.
Transparency: FAILED. As of the date of this report, KPMG has not published findings from its investigation. The firm has not disclosed which AI systems were used, what the review process consisted of, what specifically failed, or what changes have been made. The only public record is a spokesperson statement and a removed URL.
VAF Summary: 0 of 6 components MET
VEPA ASSESSMENT
KPMG is not a primary AI deployer assessed under VEPA in this report. However, KPMG's April 22, 2026 public announcement of AI agents powered by Google Cloud Gemini Enterprise for regulatory and operational use cases places the firm directly in the deployer category for future assessment. A VEPA of KPMG's AI agent products is warranted and flagged for scheduling.
The incident under review also has direct VEPA relevance as a VAF failure in published content: KPMG produced AI-attributed outputs without disclosing AI involvement, without verifying accuracy, and without providing affected named organizations any mechanism to correct false claims before publication. Under VAF, this is an Origin, Voice, Traceability, Timing, Response, and Transparency failure simultaneously — a complete sweep.
GAP SCORE
INDETERMINATE for full Gap Score calculation. Insufficient access to KPMG's internal AI governance documentation, review processes, or post-incident findings to calculate a complete score. The AAB and VAF assessments above establish a floor: 0 conditions met across both frameworks against available evidence. The Gap Score will be recalculated when KPMG publishes its investigation findings.
Trend: DECLINING. The publication of a hallucinated research report, followed by a pattern match to EY's similar withdrawal the prior month, establishes a negative trajectory for Big Four AI governance accountability posture in the assessment period.
EVENT RECORD
October 2025 — KPMG International publishes "Total Experience: Redefining Excellence in the Age of Agentic AI." Report circulates globally, cited in CXM, CX Dive, Mi3, and a major Czech newspaper. Accountability implication: AI-assisted research outputs enter the trusted-source tier without verification. Vordan Coverage: None at time of publication. PR: PENDING.
April 22, 2026 — KPMG publicly announces AI agents powered by Google Cloud Gemini Enterprise for regulatory and compliance use cases. The firm positions itself as a provider of governed AI for enterprise regulatory workflows. Accountability implication: KPMG is now selling AI governance while operating without disclosed governance on its own AI-assisted research outputs. Vordan Coverage: None. PR: Not applicable.
May 2026 (exact date unconfirmed) — EY withdraws a report found to contain fabricated footnotes and AI hallucinations. Second Big Four firm in the same period. Accountability implication: Pattern, not isolated incident. Neither firm published a root cause analysis or structural remediation. Vordan Coverage: None. PR: Not applicable to this report — separate entity.
June 12, 2026 — GPTZero publishes forensic investigation of KPMG's October 2025 report. Finds 40 of 45 citations fabricated or substantially altered; approximately half of factual claims false or misattributed; four named organizations publicly dispute claims. Accountability implication: External research firm, not KPMG's own controls, identified the failure eight months after publication. Vordan Coverage: GA20 candidate. PR: PENDING.
June 13, 2026 — KPMG removes report from its websites; issues spokesperson statement. No correction published. No timeline given for investigation findings. Accountability implication: Response is reactive removal, not structured accountability. The firm that advises clients on AI incident response has no disclosed incident response architecture for its own AI outputs. Vordan Coverage: This report.
THE ACCOUNTABILITY STRUCTURE ANALYSIS
KPMG occupies a structurally unusual position in the AI accountability landscape: it is simultaneously an advisor on AI governance, a deployer of AI systems for regulatory use cases, and — as this incident demonstrates — a producer of AI-assisted content distributed under its institutional authority. Each of those roles carries distinct accountability obligations. The failure here is in the third role, but it implicates the credibility of the first two.
The governance mechanism that should have operated on this report is KPMG's own published AI guidelines, which the spokesperson described as requiring human oversight to validate content and verify independent sources. Those guidelines exist. They did not function. That is the structural condition this report documents: a stated control that produced no evidence of operation.
The deeper structural problem is one that KPMG's own advisory practice would identify immediately in a client: the guidelines are a policy artifact, not a governance architecture. A governance architecture for AI-assisted research would require named reviewers with designated accountability for citation verification, a documented review record that survives the publication process, and a mechanism for affected third parties to identify and correct false claims before publication reaches distribution. None of those elements appear to exist. The policy says human oversight is required. The architecture for enforcing that requirement was absent.
This matters beyond KPMG. Big Four research circulates differently than other advisory content. It is cited in board presentations, regulatory filings, procurement decisions, and vendor evaluations. It is indexed by search engines and incorporated into LLM retrieval corpora. When it contains hallucinated claims attributed to named organizations, those hallucinations propagate through the information ecosystem faster and deeper than corrections can follow. GPTZero's CEO named this directly: the false 55% CEO statistic from the KPMG report was already being recycled in named publications before the retraction. That is not an embarrassment. That is an accountability architecture failure with downstream consequences that no retraction fully reverses.
PRECEDENT REGISTER ENTRIES
PR-2026-006 — First documented instance of a Big Four professional services firm publicly retracting a globally distributed research report due to AI hallucinations confirmed by named organizations whose accurate descriptions were misrepresented in the report — NORMATIVE / INSTITUTIONAL — PENDING
VORDAN POSITION
KPMG is in the business of telling organizations what accountable AI governance looks like. The October 2025 report was a product of exactly the failure mode KPMG sells protection against: AI outputs distributed as authoritative without verification, with no disclosed origin, no audit trail, no mechanism for affected parties to correct false claims, and no incident response architecture capable of identifying the failure before an external research firm did. The firm's response — a spokesperson statement and a removed URL — does not constitute accountability. It constitutes avoidance dressed as action. What accountability would require is a named investigation with a published timeline, a root cause disclosure that identifies specifically which AI systems were used and which review processes failed, direct communication to the four organizations whose names were misrepresented, and a structural remediation that makes the same failure harder to repeat. None of that has been published. Until it is, the gap between what KPMG advises and what KPMG practices is not a reputational problem. It is a documented accountability failure that belongs in the institutional record.
The EY withdrawal the prior month makes this a pattern. Two of the four largest professional services firms in the world have now retracted AI-assisted research reports in consecutive months, with neither publishing a root cause analysis or structural remediation. The firms that enterprise clients rely on to govern AI risk are demonstrating, in public, that they have not governed their own.
DISCLOSURE
Vordan has no financial or advisory relationship with KPMG or any of its member firms. This assessment is based entirely on the public record as constituted at the date of publication. KPMG's internal AI governance documentation, review processes, and post-incident investigation findings are not available to Vordan and have not been published. Where evidence is unavailable, conditions are assessed as INDETERMINATE rather than FAILED. The AAB and VAF assessments above represent the most conservative findings the available evidence supports.
SOURCES
[1] GPTZero, Paul Esau, Om Ogale, Alex Cui, "Chasing the Hallucinations: KPMG's AI-Powered Attempt at Redefining Excellence," June 12, 2026. https://gptzero.me/news/investigations-kpmg/
[2] The Register, Carly Page, "KPMG's AI report becomes an accidental demo of AI hallucinations," June 12, 2026. https://www.theregister.com/ai-and-ml/2026/06/12/kpmgs-ai-report-turns-into-a-demo-of-ai-hallucinations/5255029
[3] TechCrunch, Anthony Ha, "KPMG pulls report on AI usage due to apparent hallucinations," June 13, 2026. https://techcrunch.com/2026/06/13/kpmg-pulls-report-on-ai-usage-due-to-apparent-hallucinations/
[4] The AI Insider, "KPMG Pulls AI Report After Hallucinated Claims About Major Organisations," June 16, 2026. https://theaiinsider.tech/2026/06/16/kpmg-pulls-ai-report-after-hallucinated-claims-about-major-organisations/
[5] KPMG International, "Total Experience: Redefining Excellence in the Age of Agentic AI," October 2025. [Report removed from KPMG websites June 13, 2026; archived version at smallpdf.com]
[6] KPMG International, "KPMG Announces New AI Agents to Help Organizations Solve Complex Regulatory and Operational Challenges, powered by Google Cloud's Gemini Enterprise," April 22, 2026.
CROSS-REFERENCES
Gap Alerts: GA20 candidate pending — pattern-level analysis of Big Four AI research governance failures
VEPA Assessments: KPMG AI agents (Google Cloud Gemini Enterprise) — assessment warranted, not yet scheduled
Precedent Register: PR-2026-006 — PENDING
Accountability Forecasts: None to date
Related Accountability Reports: None to date
Vordan is an independent AI governance and accountability intelligence institution. Editorial Independence Declaration at vordan.co/governance.
vordan.co | reports.vordan.co | [email protected]
