A judge in Esquel, Argentina, had a criminal conviction annulled after it was discovered he used ChatGPT to draft portions of the ruling. The judge accidentally included the AI's prompt response in the final document, revealing a lack of human oversight and potential data privacy violations. The case has been reassigned, and an ethics investigation into the judge's conduct is underway.
The Penal Chamber of Esquel, Argentina, reportedly annulled a June 2025 robbery conviction after determining that Judge Carlos Rogelio Richeri had allegedly used ChatGPT to draft part of the ruling without disclosure or human oversight. A copied phrase purportedly exposed AI authorship, prompting findings of due-process violations and data-handling concerns. The case was reassigned, and the Chubut Superior Court opened an ethics investigation.
Risk classification
- Primary risk domain: 5 Human-Computer Interaction
- Primary risk subdomain: 5.1 Overreliance and unsafe use
The judge over-relied on ChatGPT to draft a critical criminal sentencing ruling, failing to exercise mandatory human supervision and control over the output.
Additional risk subdomains
- 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information: The judge uploaded sensitive personal data of parties, witnesses, and experts to an external AI platform, violating judicial confidentiality rules.
Causal factors
- Entity: Human
- Intent: Unintentional
- Timing: Post-deployment
The incident was caused by the judge's human decision to use ChatGPT to draft a judicial sentence without proper oversight, and the resulting risk of annulment was an unexpected outcome of this action.
EU AI Act risk tier
High Risk: The report describes the use of AI in the administration of justice to draft a criminal sentence, which has significant implications for fundamental rights and public interests, specifically violating due process.
AI system and alleged parties
- AI system: ChatGPT (OpenAI)
- AI purpose: Writing Assistant; Judicial Decision Support
- Behaviour type: Assistant
- Alleged developer: OpenAI
- Alleged deployer: Carlos Rogelio Richeri
- Alleged harmed parties: Raúl Amelio Payalef, Juzgado Penal de Esquel, Justice system of Argentina, Judicial integrity, Epistemic integrity
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Privacy
Reported: The report explicitly describes potential privacy and confidentiality violations caused directly by the incident.
Directly caused: The judge uploaded the names of the parties, witnesses, and experts to an online AI assistant, exposing sensitive personal data to an external platform in violation of judicial confidentiality rules.
Indirectly caused: N/A
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 10
Potential causes
Management
- Lack of Institutional Control: Absence of monitoring or validation systems for AI use in court rulings.
- Unclear Ethical Boundaries: Insufficient guidance on acceptable limits of AI assistance for judges.
Technology
- Online Assistant Use: Using external web-based AI tools for processing sensitive legal texts.
- Conversational Meta-text: AI output included conversational phrases that were copied into the text.
Data Inputs
- Confidential Data Leakage: Inputting names of parties, witnesses, and experts into external AI.
Human Factors
- Lack of Human Supervision: The judge signed the sentence without checking the AI-generated content.
- Overreliance on AI: Directly copying and pasting AI text for central parts of the ruling.
- Careless Copy-Pasting: Failing to remove conversational AI text before finalizing the document.
Process and Methods
- Delegation of Decision-Making: Delegating core judicial reasoning and resolutions to an automated system.
- Lack of Reasoning Traceability: Failing to document prompts or the extent of AI assistance in the ruling.
- No Disclosure of AI Use: Omitting the required record of AI collaboration in the final sentence.
Regulatory Environment
- Breach of Confidentiality Rules: Violating Agreement N 5435 regarding digital data processing safety.
- Violation of Natural Judge Principle: Delegating the constitutional duty of judging to an automated system.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide clear, consistent, and detailed accounts of the incident, including the specific phrase that exposed the AI use, the legal consequences (annulment of the sentence), and the ethical/privacy concerns raised by the court. There is no conflicting information among the sources.
An Argentine judge had a criminal conviction annulled after using ChatGPT to draft key portions of the ruling without proper oversight, exposing sensitive personal data of parties and witnesses. This incident highlights growing risks of AI overreliance in judicial decision-making and government functions, though its national security impact remains minor and localized.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: Argentina
- Alleged perpetrator: Individual
Threat characteristics
- Imminence: Long-term. Represents an ongoing strategic concern regarding the integration of AI in judicial systems rather than an immediate crisis.
- Autonomy: Human-controlled. The AI assisted in drafting, but the judge retained final decision-making authority and manually copied the text into the ruling.
- Novelty: Evolved capability. Building on known issues of lawyers using generative AI, this represents an evolved threat where a judge integrated AI output directly into an official ruling.
Impact by dimension
- Physical security: Negligible. There is no indication of physical harm, kinetic threats, or critical infrastructure disruption in this incident.
- Information security: Minor. The judge uploaded names of parties, witnesses, and experts to ChatGPT, violating judicial confidentiality rules and exposing sensitive data to an external platform.
- Sovereignty: Minor. The delegation of judicial reasoning to an AI compromised local government decision-making processes, leading to the annulment of a criminal sentence.
- Economic security: Negligible. The incident does not present any threats to economic stability, strategic industries, or technological competitive advantage.
- Societal stability: Minor. The incident violated the defendant's constitutional rights to due process and a natural judge, but impact was limited to a single case.