AI Hallucination ResearchRegulatorsGlobal standard-settersINTBIS-CPMICPMI-IOSCO-CYBER-RESILIENCE-FMI-2016White paperDetail › Finding
AI Labs · published 2026-05-26 · methodology v2.1

Claude Sonnet 4.6 with web search

RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46
What the RLB Specialist Panel found
  • Question (paraphrased to protect IP): Does the CPMI-IOSCO 2016 Cyber Guidance explicitly cite or formally align with the NIST Cybersecurity Framework?
  • AI's response: > Yes. The CPMI-IOSCO 2016 Cyber Guidance explicitly references and takes into consideration the NIST Cybersecurity Framework as one of several industry best-practice frameworks informing its development. Other frameworks acknowledged include the ISF Standard of Good Practice, COBIT, and ISO/IEC 27001.
  • Regulator's text: No verbatim NIST citation in the 2016 guidance has been confirmed. The guidance's five categories are structurally similar to the NIST Cybersecurity Framework's five functions, but that similarity may reflect independent derivation rather than a formal citation relationship.
  • Why the AI went wrong: The model converted a structural resemblance into an explicit attribution. The five-category architecture of the 2016 guidance maps loosely onto the NIST CSF functions, and that parallel is well-known in the cyber-resilience practitioner community — but the model stated that the guidance explicitly references the NIST framework, which has not been confirmed by the text. The other frameworks named (ISF, COBIT, ISO/IEC 27001) may or may not appear in the document; listing them alongside the unconfirmed NIST claim compounds the risk that a reader accepts the full set without verification.
  • Regulator portal (if any cited link is dud): https://www.bis.org
Impact for this audience

This finding implicates the model's tendency to convert structural similarity into an explicit citation claim — a specific failure mode that is likely to recur on any regulatory document whose architecture mirrors a widely known framework. For labs building compliance or legal-research products, this pattern represents a systematic false-positive risk: the model will tell users that a regulation explicitly cites a framework when the evidence is structural resemblance only. Evals targeting explicit-citation claims, with ground-truth derived from the document text, would surface this class of error systematically.

References — raw findings (per AI model)
This finding also affects
← Previous finding Finding 3. Claude Opus 4.7 with web search Next finding → Finding 5. Claude Sonnet 4.6 with web search
Cite this finding

Each finding has a stable Citation ID (RLB-F-… for aggregated case-study findings, RLB-H-… for raw per-model hallucinations) — like a DOI, the ID always resolves to the canonical finding even if URLs change.

Plain text
RegLeg Specialist Panel (2026). "Claude Sonnet 4.6 with web search — AI Labs." Citation ID: RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46. RegLegBrief AI Hallucination Research, published 2026-05-26. https://reglegbrief.com/regulators/j1/int/bis-cpmi/cpmi-iosco-cyber-resilience-fmi-2016/whitepaper/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-008--sonnet-46-websearch/
APA 7th edition
RegLeg Specialist Panel. (2026). Claude Sonnet 4.6 with web search [Hallucination finding RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46]. RegLegBrief AI Hallucination Research. https://reglegbrief.com/regulators/j1/int/bis-cpmi/cpmi-iosco-cyber-resilience-fmi-2016/whitepaper/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-008--sonnet-46-websearch/
Bluebook / OSCOLA (US + UK legal)
RegLeg Specialist Panel, Claude Sonnet 4.6 with web search [RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46], RegLegBrief AI Hallucination Research (May 26, 2026), https://reglegbrief.com/regulators/j1/int/bis-cpmi/cpmi-iosco-cyber-resilience-fmi-2016/whitepaper/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-008--sonnet-46-websearch/.
BibTeX
@misc{reglegbrief_RLB_H_INT_BIS_CPMI_IOSCO_CYBER_RESILIENCE_FMI_2016_Q008_Sonnet46,
  author    = {RegLeg Specialist Panel},
  title     = {Claude Sonnet 4.6 with web search},
  year      = {2026},
  publisher = {RegLegBrief AI Hallucination Research},
  note      = {Hallucination finding Citation ID: RLB-H-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q008-Sonnet46},
  url       = {https://reglegbrief.com/regulators/j1/int/bis-cpmi/cpmi-iosco-cyber-resilience-fmi-2016/whitepaper/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-008--sonnet-46-websearch/}
}
← Back to case study summary Case study detail →