Skip to content
Founderz: Responsible Use of AI home

in collaboration with Microsoft

The ten principles

Principle 07 · Before you share · Accuracy

Verification proportionate to the stakes

The depth of checking matches the cost of being wrong, and every source relied on is opened and confirmed.

Key question

What would it cost if this were wrong?

Benefit

Work that others can rely on, and a reputation for it.

Context

AI writes just as fluently when it’s wrong. It can invent a reference, misquote a source, drop a condition or turn “expected Friday” into “guaranteed.” NIST calls the invented part confabulation: false content stated with confidence, sometimes with made-up citations that make it look justified. Long reports make these errors harder to spot, and they have reached clients and courts.

You can’t check everything, so match the depth of the check to the cost of being wrong.

Levels of verification

LevelForWhat you do
A glanceInternal drafts, ideas, notes to yourselfRead it through. Does it answer the question you asked?
Spot checksAnything you share with colleaguesCheck the names, dates, figures and claims that matter most.
Full verificationAnything published, signed, sent to a client or used to decideOpen every source, recalculate, confirm quotes and dates, and ask a second person when the stakes are high.

Source verification

A citation proves nothing until you open it. Check that the source exists, that it says what the AI says it says, and that it’s current and relevant to your country and market. A second AI can share the first one’s blind spots, so its agreement doesn’t replace opening the source.

Specialist tools reduce errors without removing them. A Stanford study published in 2025 found that leading AI legal research tools still hallucinated on 17% to 33% of test queries. By September 2026 a public database had logged more than 2,000 court and tribunal decisions involving AI-invented content, most of them fake citations.

Verifying requests and identities

AI also makes fakes cheap. A voice, a face or a writing style can be imitated well enough to fool colleagues. In early 2024 an employee in Hong Kong transferred about HK$200 million after a video call in which the other participants, including the finance chief, were fakes. Read the case study.

Treat any unusual request for money, credentials or confidential data as unverified until you confirm it through a channel you start yourself: call back on a number you already have, or walk to the person’s desk. The FBI and Spain’s national cybersecurity institute both advise this.

Practices

  1. 01Match the level of verification to the stakes: a glance, spot checks or full verification.
  2. 02Open the source. Confirm it exists and says what the AI says it says.
  3. 03Recalculate the numbers that matter.
  4. 04Check the date and the place: is this current, and right for your country and market?
  5. 05Verify unusual requests for money, credentials or data through a channel you start yourself.

Prompt examples

A prompt before and after improvement, and the part a person does outside the prompt.

Research

Writing with statistics

Before

“Write a paragraph on the growth of the European AI market, with statistics.”

After

“Using only the three reports I’ve attached, write a paragraph on the European AI market. After each number, give the report and page. List any claim you couldn’t support.”

Your part

Check every number against its page. Numbers you can’t find come out.

Why it works: Limiting the sources and asking for pages turns an unverifiable paragraph into one you can check in minutes.

Contracts and policies

Summarizing a regulation

Before

“Summarize the new EU rules on AI chatbots.”

After

“Summarize Article 50 of the EU AI Act from the official text I’ve attached, in plain English. Quote the sentence behind each point, and flag anything that depends on dates or exceptions.”

Your part

Check each quoted sentence in the official text, and ask your legal team before you act on it.

Why it works: Quotes tie every point to the text, and the flags show where the detail matters.

Data and numbers

Comparing quotes

Before

“What’s the total cost of the three quotes?”

After

“Extract the price, quantity and any extra charges from each of the three attached quotes into a table, with the page for each figure. Then total them and show the calculation.”

Your part

Check every figure against its page and redo the total yourself. Look for charges hidden in the terms.

Why it works: A table with page references makes a wrong number easy to spot, and your own total catches the rest.

Evidence

  • NIST defines confabulation as false content stated with confidence, sometimes with invented reasoning or citations that make it look justified. [NIST AI 600-1]
  • Leading AI legal research tools hallucinated on 17% to 33% of 202 test queries in a peer-reviewed Stanford study. [Magesh et al., Stanford]
  • By September 23, 2026, a public database listed 2,077 decisions in which courts or tribunals found, or implied, that a party relied on AI-invented content. [Charlotin database]
  • Microsoft’s own documentation says generative AI responses aren’t guaranteed to be 100% factual, and that users should use their judgment when reviewing output before sending it to others. [Microsoft Learn]
  • The FBI advises hanging up and calling back on a number you look up yourself. Spain’s INCIBE advises never authorizing payments by phone and requiring more than one approver for large payments. [FBI] [INCIBE]

Case studies and scenarios

Team practice

Agree which outputs get a glance, which get spot checks and which get full verification, so everyone checks in proportion.

Team toolVerification levels

Sources

What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.

  1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) US National Institute of Standards and Technology · July 26, 2024 · Voluntary framework Lists twelve risks of generative AI, including confabulation (confidently stated false content, sometimes with invented citations) and human-AI configuration, which covers automation bias and over-reliance. Limits: Voluntary. It was issued under an executive order that has since been revoked, and the wider framework is under revision.
  2. Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools Journal of Empirical Legal Studies (Stanford RegLab and HAI researchers) · April 23, 2025 · Peer-reviewed research On 202 legal questions, leading AI legal research tools hallucinated on 17% to 33% of queries, and a general-purpose model on 43%. Limits: A snapshot of tools tested in 2024. The tools have changed since.
  3. AI Hallucination Cases database Damien Charlotin · Updated continuously (2,077 cases on September 23, 2026) · Research database Lists decisions in which a court or tribunal found, or implied, that a party relied on AI-invented content, mostly fake citations: 2,077 by September 23, 2026, 1,428 of them in the United States. Limits: Maintained by one person. It leaves out cases where reliance was only alleged.
  4. Data, privacy, and security for Microsoft Copilot Microsoft · Updated August 18, 2026 · Product documentation States that Copilot only surfaces organizational data the user has at least view permission for; that prompts, responses and data accessed through Microsoft Graph aren’t used to train foundation models; and that generated responses aren’t guaranteed to be 100% factual, so users should use their judgment before sending output to others. Limits: Applies to that product and its commercial terms only.
  5. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (I-120324-PSA) FBI Internet Crime Complaint Center · December 3, 2024 · Public service announcement Warns that criminals use AI-generated voice, images and video to impersonate people, and advises hanging up and calling back on a number you look up yourself. Limits: Aimed at US consumers.
  6. Suplantación del CEO utilizando la técnica de inteligencia artificial deepvoice INCIBE, Spain’s national cybersecurity institute · January 9, 2024 · Official case note (in Spanish) Describes a company that paid a fraudster after an AI-cloned voice of its chief executive called; advises confirming through a channel where you know who you’re talking to, never authorizing payments by phone and requiring more than one approver for large payments. Limits: An anonymized helpline case.

Cite this page

Founderz (2026). Principle 7: Verification proportionate to the stakes. The RUAI Standard, 2026 edition. Developed by Founderz in collaboration with Microsoft. https://responsibleai.founderz.com/toolkit/principles/proportionate-verification

Licensed under CC BY 4.0: share and adapt with attribution.