Every enterprise AI team has the same scar. The system answered fluently, confidently and wrongly; someone acted on it; and now there is a slide in a steering committee deck that says "AI accuracy: TBD" next to a programme that used to have a budget.
The industry's first response was better prompting — "only answer from the provided context" — and its second was citations, and both fail the same way. They ask the model to police itself. A model that has produced an unsupported sentence is not well placed to notice that it has. The confidence is generated by the same machinery as the error.
Hallucination is not a character flaw in the model. It is a missing stage in the pipeline. Unsupported answers ship because nothing in the system's design makes them unshippable.
Refusal is a feature you build, not a tone you ask for
The honest baseline is this: when the evidence does not support an answer, the system says so. Not a softened paragraph, not a hedge with a citation attached — a refusal, recorded with a machine-readable cause.
This sounds easy and is commercially rare, because refusal rates are uncomfortable. A system that refuses fifteen per cent of questions in week one is telling you something true about your data, and the temptation is to tune the refusal away rather than fix what it pointed at. Resist it. The refusals accumulate into the most honest map of your knowledge gaps you will ever get.
The technical detail: five gates
A pipeline that prevents hallucination — rather than apologising for it — enforces five gates, and each one exists outside the model.
Gate one: ground. Answers come from governed records resolved at query time, not from the model's memory of the internet. If the question cannot be grounded in your material, that is discovered here, cheaply.
Gate two: retrieve. The exact rows and passages, with lineage attached. Not "documents similar to the question" — the specific records the answer will stand on.
Gate three: decompose. The draft answer is broken into atomic claims — single propositions that can be checked one at a time. A sentence with three figures is three claims. This step is tedious by hand, easy to automate, and usually skipped, which is part of why the problem persists.
Gate four: check. Each claim is verified against the passage that must support it — entailment, not topical similarity. A source about the right subject is not evidence for the sentence. Research on citation accuracy keeps finding the same gap: links resolve, topics match, and the claim still is not supported.
Gate five: decide. Ship with each claim one step from its source — or refuse, persist the cause, and count it. There is no third outcome in which an unchecked answer leaves the building wearing a confident tone.
What to ask a vendor
One question cuts through most of the marketing: show me a refusal.
Not a disclaimer in the footer — a question the system declined to answer, the recorded cause, and the count of how often that happens. A vendor who can show you their refusal log has built the pipeline. A vendor who tells you their accuracy number has not understood the question, because accuracy measured on answered questions, with refusals quietly excluded, is exactly the flattery the five gates exist to prevent.
Talk to us
