An actual citation and a string that happens to be formatted to look like a citation are very different. I wish we were at the point that most LLMs could do the former.
I've seen the former happen for some GitHub docs and when enabling plugins.
I agree there's cause for concern, and I hope it's a gradual rollout that's introspected in between each propagation of such, but I definitely think it's viable to be used no more less safely than other tooling in the government today (for better or worse).