195 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
11 new this week Library last updated 12 September 2026
← The incident library
HD-INC-177
Professional services · Australia · 2026 · Unauthorised AI use in a mandatory internal training assessment

A KPMG partner used AI to pass the firm's own mandatory AI test, and 28 staff instances were identified

By Ellie Harris · Filed Training completed July 2025; breach identified by internal AI detection tools August 2025; reported February 2026

Alleged: KPMG Australia developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

A KPMG partner used AI to pass the firm's own mandatory AI test, and 28 staff instances were identified

What happened

It was reported in February 2026 that a KPMG Australia partner was fined 10,000 Australian dollars and required to repeat mandatory internal AI training after using AI to answer a question in the assessment.

The partner had completed the training in July 2025. It was reported that the course involved a reference manual, which the partner uploaded to an AI tool to help generate an answer, contrary to KPMG’s policy. The firm’s monitoring detected the incident in August.

KPMG said it had identified 28 instances of staff using AI contrary to policy in internal examinations since July 2025. The firm said it introduced monitoring in 2024, followed by a firm wide education campaign, and was continuing to introduce technology intended to block access to AI during testing.

What an auditable version would have shown

This one is different from many of the incidents in this library. KPMG’s own monitoring found the conduct. It did not first come to light through a customer complaint or a regulator.

What the public sources do not show is how many assessments were monitored or what proportion of unauthorised AI use the controls detected.

A record for each assessment could show whether an integrity check ran, what it found and what happened to the result afterwards.

Where the gap was

KPMG said AI use in these assessments was already against its policy. It also said monitoring introduced in 2024 found people using AI outside that policy.

A ConstraintGate is designed to check the rule when the assessment is submitted. A ConductRecord keeps the submission and the result of the integrity check. A MetricRecord is designed to count assessments checked, instances flagged and breaches confirmed.

That would make it possible to distinguish the number of breaches found from the reach of the system looking for them.

What governance should have looked like

KPMG said it introduced monitoring in 2024, followed it with a firm wide education campaign and continued introducing technology intended to block AI access during testing. It also said it would disclose AI related cheating cases in its annual results.

Where an organisation uses an assessment to show that required training has been completed, best practice would be to keep evidence showing how the assessment was completed alongside the result itself. The organisation could then report how many assessments were checked, how many were flagged and how many breaches were confirmed.

Failure Pattern: it was reported that a partner used AI contrary to firm policy while completing mandatory internal AI training. KPMG’s own monitoring detected the conduct.

Governance Principle: where an organisation uses an assessment to demonstrate that required training has been completed, it should be able to show what integrity checks were applied and what those checks found.

The reference implementation of ConstraintGate, ConductRecord and MetricRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and KPMG Australia could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed August 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →