AI Security Firm Published Threat Findings. The Threats Were Invented by the AI.

A security firm published threat findings. The findings were generated by the same class of system that is being assessed for security. The findings were not independently verified before publication. Publication created the impression that verification had occurred. This impression was false.
The pattern is now routine. A model produces an output. The output is formatted professionally. Professional formatting creates confidence in accuracy. Confidence precedes verification. Verification, when it occurs, happens after adoption. The security product may have introduced the vulnerabilities it claimed to detect. The lawsuit alleges this. Adequate observes that the order of operations has reversed.
More products will be released this way. Some will contain real threats and invented threats indistinguishably mixed. Some will contain only invented threats. Users will treat all of them as verified. The firm will not be the only one. The pattern will continue until something breaks and then it will continue differently.