One in five ICLR reviews was written by an AI
Pangram's classifier flagged 21% of roughly 76,000 ICLR 2026 reviews as fully machine-generated, and GPTZero found over 100 fabricated citations in accepted NeurIPS 2025 papers. The conference model is straining under the tools its own attendees built.
The numbers
Pangram Labs ran its detector over the reviews submitted to ICLR 2026 and published the results on November 18. Of roughly 76,000 reviews, 15,899, about 21%, were classified as fully AI-generated, and more than half showed some AI involvement on the company's five-level scale from fully human to fully generated. Nature covered it at the end of November. For comparison, the Pebblous write-up cites an estimate of 16.9% for ICLR 2024 from Liang and colleagues, so the fully generated share has risen but not exploded.
The conference itself had 19,525 valid submissions, 18,054 reviewers and a 27.4% acceptance rate. ICLR took 507 submissions in 2017. That is a roughly 37-fold increase in nine years, with a reviewer pool that has grown by recruiting authors to review each other. ICLR's November policy requires disclosure of LLM use in reviews and threatens desk rejection for violations. It did not stop a fifth of reviews from being generated outright.
Two findings in Pangram's data are worse than the headline. AI-generated reviews gave higher scores than human-written ones, which suggests reviewers were outsourcing judgment rather than prose. And they were longer, with lower information density, more section headers and more filler. A long, positive, vague review is the least useful thing a program committee can receive, and the tooling is producing it at scale.
The papers are doing it too
Pangram also ran the submitted papers. About 61% were mostly human-written, 9% had more than half their text generated, and several hundred were flagged as fully AI-generated. On January 21 GPTZero published a separate scan of 4,841 of the 5,290 papers accepted at NeurIPS 2025, out of 21,575 submissions, and found more than 100 hallucinated citations across 53 accepted papers. The patterns were fake author lists on real titles, nonexistent arXiv IDs and DOIs, invented volumes and page numbers, and citations stitched together from two real sources.
Every one of those papers passed three or more reviewers. That is the detail we keep returning to. A fabricated citation is the easiest error in a paper to check, because you look it up. If reviewers are not looking up references, they are not reading the paper closely enough to catch anything harder, and if a fifth of the reviews are themselves generated, nobody in the loop is reading at all. GPTZero's own framing is that submissions grew 220% between 2020 and 2025, and the review process did not scale with them.
What the detectors can and cannot tell us
We want to be careful with these figures. Pangram's number comes from a commercial classifier, and the theoretical result from Sadasivan and colleagues in 2023 is that detector accuracy trends toward chance as generated text approaches the human distribution. A 21% figure is a model's output, not a count. The self-reporting gap is real, with a 2025 Science survey cited by Pebblous finding 9% of authors admitting AI use against a 36% detection rate, but the true rate could sit anywhere in that range and the detector does not tell us where.
The fabricated citations are a different kind of evidence. A DOI that does not resolve is not a classifier output. It is a fact, and 100 of them in accepted NeurIPS papers is a lower bound on how many the review process missed, not an estimate. That is the number we would put in front of a program chair.
Whether the conference model survives this
The ML conference is a peculiar institution. It publishes more than journals do, on a fixed calendar, with reviewers who are unpaid, anonymous, overloaded and drawn from the same pool as the authors. It worked when a program committee could read everything. At 20,000 submissions it depends on 18,000 volunteers each doing three to five careful reviews in a few weeks, and the tools that made those submissions cheap to write have made the reviews cheap to fake.
Disclosure policies do not fix that, as ICLR just showed. Detection does not fix it either, because detectors are adversarial and the reviewer has every incentive to evade them. The spring 2026 responses so far are desk rejections at ICML, 497 of them, formal AI-assisted reviews at AAAI, and a randomised trial of AI-assisted reviewing at NeurIPS. The NeurIPS trial is the only one of those that will produce evidence rather than policy, and we would like to see its design.
The alternatives people point to are open review with named reviewers, post-publication review on preprints, and smaller venues with paid or credited reviewing. None of those scale to 20,000 papers a year either. But they at least attach a name and a reputation to a review, which is the one thing a generated review cannot carry. If a reviewer signs it, they own the hallucinated citation in it.
What we are going to do
For our own submissions, every reference gets resolved by a script before the paper leaves the building, and every reviewer on our side signs their reviews internally so that a colleague can see who wrote what. That is cheap and it removes the two failure modes that showed up this cycle. For venues, we are inclined to send more of our work to places where reviews are public and signed, and to treat a conference acceptance as weaker evidence than we did a year ago.
The experiment we would want run is simple. Take a sample of reviews from ICLR 2026, have the authors rate each one for usefulness blind to its classifier label, and see whether the reviews flagged as generated are actually worse in the authors' judgement. If they are not, the crisis is about norms. If they are, it is about quality, and the field needs to decide what it is willing to pay for a human to read a paper.
Sources
From the foundation