Analysis

60% of Experts Agree: No One Knows What They Are Talking About

Let’s start with a number that nobody mentions in those 299-euro “AI literacy” courses.

The OECD, through its PISA and PIAAC assessments, estimates that 60–70% of adults in developed countries do not reach the level of literacy required to independently read a scientific study and evaluate its methodological soundness.

This is not an insult. It is a structural fact about an educational system that was never designed to produce critical readers of primary literature on a mass scale.

This number existed before AI. Before ChatGPT, before transformers, before prompt templates were sold as professional skills. And it exists regardless of whether you have a green badge on LinkedIn that says “AI Fluent.”

Now consider what we are doing: we are deploying AI systems in legal, healthcare, cybersecurity, and public administration sectors, while simultaneously organizing webinars, certifications, and onstage keynotes to teach the exact same population how to “use AI responsibly.”

The math doesn’t add up. And the courts are starting to take notice.

We’ve Seen This Movie Before

COVID-19 was the first modern stress test of institutional credibility on a mass scale.

The failures were real and documented: contradictory messaging on masks, predictive models presented as certainties rather than probabilistic ranges, suppression of scientifically legitimate hypotheses before they were falsified, and undisclosed conflicts of interest at regulatory tables. These were not conspiracy theories — they were governance failures, some later documented in peer-reviewed literature.

The population’s response was not calibrated skepticism. It was authority substitution: people stopped believing one institution and found another, equally uncritical narrative to believe in. The result: cell towers set on fire, 5G controlling pigeons, and Flat Earth trending again.

The point is not that people are stupid. The point is that without the tools to distinguish one lie from another, people end up replacing one certainty with another. Critical thinking cannot be improvised, and it cannot be installed with a three-hour course.

AI is following the exact same trajectory. With one compounding factor: this time, the cycle is inverted — institutions communicate before the event has even occurred, the masses react to narratives, and the epistemic damage is pre-loaded before any real experience exists to reason upon.

The Problem Is Not Those Who Don’t Know. It’s Those Who Sell What They Don’t Know.

Dunning-Kruger does not strike the ignorant. It strikes those who know just enough to look credible but not enough to recognize their own limits — and who build a business out of that exact position.

The distinction that matters is not between technical and non-technical people. A legal scholar analyzing the accountability of AI systems does not need to know how to train a model — they analyze effects, liabilities, and systemic impacts. It is a legitimate contribution. A sociologist studying how the spread of LLMs modifies labor markets does not need to know the mathematics behind transformers — they study the social phenomenon, not the architecture.

The problem is different, and more specific: it is those who state with absolute certainty what an LLM “can” or “cannot do” technically without the foundation to say so. Those who sell prompt engineering courses as if it were a professional specialization. Those who implement “AI-powered security” buying into pitch decks without asking a single technical question about the underlying model. Those who write opinion pieces on algorithmic bias without ever having looked at a training data distribution.

Not stupidity — snake oil with a badge of credibility, which occupies the space of serious discourse, contaminates it, and makes it impossible to distinguish those with real competence from those who are just acting.

The operational result: those without the tools to evaluate learn that “experts always contradict each other.” A wrong conclusion, drawn from a partially true premise.

Courts Do Not Hallucinate

Let’s move from concepts to public documents.

Researcher Damien Charlotin maintains a global legal database tracking cases where a court has explicitly commented on AI hallucinations in legal filings. As of today: over 1,300 documented cases. The number is growing faster than any remediation framework.

Data from the recent docket:

In the first two weeks of August 2025, three separate US federal courts sanctioned lawyers for AI hallucinations. Not in the same month — in the first two weeks. The courts have begun to formally distinguish between “intentional deception” and “involuntary reliance on AI.” Both are sanctionable.

In July 2025, Johnson v. Dunn (N.D. Alabama): a federal judge formalized the operational principle — even when the use of AI is involuntary, the attorney bears full professional responsibility for the accuracy of what they file. “I trusted the tool” is not a defense.

In May 2026, a judge in Oregon issued the highest sanction in American history for AI hallucinations: 110,000 dollars. Two lawyers had filed 23 fabricated citations and eight invented case quotes. The case was subsequently dismissed. During the same period, in Manhattan, a defendant who used an AI chatbot to prepare his own defense discovered that the government could subpoena his chat history and use it against him. He had typed his defense strategy into a commercial interface.

In California, September 2025 (Noland v. Land of the Free): the state’s first published opinion on AI hallucinations in legal proceedings. Sanction: 10,000 dollars. In the same month, the Court of Appeal of Alberta issued its first decision regarding case law citations fabricated by AI.

The pattern is always the same: a professional with insufficient technical understanding of the system delegates epistemic responsibility to a tool that cannot sustain it. The tool produces output with a confident tone. The professional, lacking the capacity to detect the error, files generative fiction as verified fact.

This is not a failure of technology. It is the 60–70% problem manifesting in environments with formal accountability mechanisms.

Cybersecurity: Where It Becomes Operational

In the legal field, hallucinations produce sanctions and embarrassment. In cybersecurity, they produce an attack surface.

On the offensive side, the 2025 IBM data is instructive in its complexity: the global average cost of a data breach dropped for the first time in five years, from 4.88 million dollars in 2024 to 4.44 million in 2025, thanks to faster detection driven by AI defenses. In the United States, however, the average cost spiked to 10.22 million dollars — a historic record — driven by stricter regulatory penalties and slower detection times. The exact same technology that lowers global costs drives them up where governance is absent. The 2025 data also reports that 63% of organizations have no AI governance policies in place and that 97% of AI-related breaches occurred in environments lacking adequate access controls.

The Slack AI incident of August 2024 remains a precise textbook case — and nearly two years later, most organizations have still not implemented structural countermeasures: researchers demonstrated how indirect prompt injection in private channels could cause the corporate AI to summarize sensitive conversations and exfiltrate the summary to an external address. The agent believed it was executing a legitimate summarization task. It was operating as an insider threat.

The vectors that AI-naive security teams systematically fail to cover:

  • Prompt injection via analyzed data: An attacker who knows you are using an LLM for SIEM triage can embed adversarial instructions within logs, emails, or file metadata. The model processes content controlled by the attacker and acts on embedded instructions — treating them as legitimate commands rather than data to be analyzed. This isn’t theory: Palo Alto Networks’ Unit 42 has documented such scenarios on real agentic frameworks like CrewAI and AutoGen.
  • Agentic exfiltration: An AI agent with tool-calling capabilities and data access permissions becomes a potential exfiltration point. This vector does not require classic technical vulnerabilities — it simply requires the agent to receive a request phrased as a legitimate operational task. The semantic layer has no firewall.
  • Shadow AI as an attack surface: The 2025 IBM report documents that breaches involving shadow AI — unauthorized AI tools used internally — cost an average of 670,000 dollars more than standard breaches. 20% of 2025 breaches involved un-governed AI tools. Not sophisticated attackers: employees using ChatGPT to process corporate data simply because it is convenient.
  • Regulatory exposure: Deploying AI systems that process personal data without adequate oversight mechanisms is not just a security risk — it is a concrete compliance liability that NIS2, the AI Act, and GDPR are starting to enforce. The most exposed organizations are often those with the least technical capacity to self-assess.

The Anatomy of the Problem, Unfiltered

It is not a single thing. It is a stack.

The structural literacy deficit is the baseline condition. It won’t change with three-hour courses, it won’t change with LinkedIn badges, and it won’t change with the good intentions of HR managers. It is a metric of the educational system that takes generations to correct, not quarters.

The post-COVID collapse of institutional credibility has negatively indexed the prior toward institutional expertise. AI safety communications, regulatory guidance, and vendor claims are all discounted across the board — including the legitimate ones, which become indistinguishable from the compromised.

Snake oil with a badge of credibility occupies the space of serious discourse. Signal and noise become operationally indistinguishable for anyone who lacks the tools to separate them. This is precisely the environment where both organized disinformation and aggressive marketing thrive.

Economic incentives are misaligned with the accurate transfer of information. AI vendors have strong incentives to obscure the line between real capability and marketing. Security vendors have strong incentives to sell “AI-powered” products to buyers who cannot evaluate the claim. Consultants have strong incentives to offer AI training to populations that actually require a completely different intervention.

What Remains

The literacy deficit is not closing. The damage to institutional credibility is not recovering. The economic incentives driving both the hype and the doom narratives are not aligned with accurate communication.

What is changing is the legal and operational record — which produces falsifiable ground truth at scale, faster than any narrative can suppress it. Courts do not hallucinate. Sanctions are real. Breaches have costs documented down to the penny.

The population that can effectively read and utilize that record remains, by structural measurement, a minority.

That minority bears a disproportionate responsibility.

Not out of goodwill. Because of arithmetic.

Sources: OECD PIAAC/PISA literacy assessments; Damien Charlotin AI Hallucination Cases Database (damiencharlotin.com); Jones Walker LLP, August 2025; ABA Journal; Fortune, May 2026; IBM Cost of a Data Breach Report 2025; Palo Alto Networks Unit 42 Agentic AI Attack Framework; Northdoor/CyberScoop IBM 2025 analysis.