If Your AI Can't Cite It, Treat It as Unproven.

An AI answer either shows where it came from or asks you to take it on faith. In GRC, where an answer may support evidence, treat it as unproven until the source is shown.

Sorena AI TeamAI and Platform4 min read

In GRC, the citation is the product

In compliance, the source is part of the answer. A response to 'does this control satisfy the obligation' is useful only if you can point to the obligation, the control, and the line that connects them.

'The AI said so' gives an auditor, regulator, or customer nothing to verify. A traceable claim gives them a document and passage to inspect.

Uncited means unverifiable means unusable

An AI answer with no source is a dead end. Confirming it requires redoing the work, and a third party has nothing to inspect. The model's tone gives no evidence that the claim is right.

A fluent paragraph can look researched when it is not. NIST AI 600-1 calls confidently stated false content 'confabulation' and notes that false logic or citations can appear to justify an answer. Treat an uncited answer as unverified until the source is shown.

The hallucination numbers are not small

Stanford researchers benchmarked three AI legal research tools built to retrieve and ground their answers. Lexis+ AI and Ask Practical Law AI produced incorrect information more than 17% of the time, while Westlaw's AI-Assisted Research did so more than 34% of the time.

Stanford summarized the result as one hallucination in every six benchmarking queries or more. The same article cites earlier work that found general-purpose chatbots hallucinated between 58% and 82% of the time on legal queries. Specialized retrieval-backed systems still need source checks.

A good citation has to prove the claim

A citation should support the claim. It should point to the exact paragraph or clause, show the source name and version, preserve the date or publication context, and explain why the passage is relevant. Merely mentioning the topic is not enough.

A reviewer should be able to click the citation and verify the sentence without redoing the research task. NIST's Generative AI Profile recommends reviewing and verifying sources and citations in GAI outputs during pre-deployment risk measurement and ongoing monitoring. Source, passage, relevance, currency, and permission all matter.

Grounding helps, but only if it is enforced

Retrieval and grounding give the model real documents to use, but they do not guarantee a supported answer. A system can retrieve the wrong passage, combine unrelated sources, or cite text that does not support the claim.

Require the answer to attach the passage it relied on, then check that the passage supports the claim. If either condition fails, do not ship the answer.

How Sorena enforces the rule

The Sorena AI Assistant answers from curated, permissioned documents and links each claim to its source passage for review.

Those answers are grounded in Sorena SSOT, our Single Source of Truth. The citation records the material used to produce the answer. When the system cannot attach a supporting source, it should withhold the claim.

What a citation does and does not promise

A citation lets you inspect the source offered for an answer. It does not prove that the source supports the claim or that it is correct, current, and right for your situation. A cited answer can still be wrong when the citation is irrelevant, fabricated, outdated, or misapplied.

The citation makes human verification faster by giving the reviewer a passage to judge.

Demand the source or discard the answer

Treat an AI answer as unproven until it shows you a source. This makes verification part of the workflow instead of an optional check.

If your AI can cite the claim, verify it and move fast. If it cannot, do not rely on it.

Frequently asked questions

If an answer is cited, does that mean it is correct?+

No. A citation gives the reviewer a source to inspect; it does not prove that the source supports the claim or that it is accurate, current, and right for the situation. The citation may itself be fabricated or irrelevant. Its value is that a human can check it instead of taking the answer on faith.

Doesn't retrieval-augmented generation already solve hallucination?+

It reduces the problem but does not solve it. Stanford found that purpose-built legal AI tools produced incorrect information more than 17% of the time, with one tool above 34%. A system can retrieve the wrong passage or cite something that does not support the claim. The answer must attach the passage it relied on, and that passage must support the claim.

Is a source-backed AI answer legal advice?+

No. Nothing produced by an AI system, cited or not, is legal advice or a substitute for qualified counsel. Provenance makes an answer verifiable and defensible, which supports a human decision. It does not replace professional judgment or the accountability of the person who signs off.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.