Versatile AI Risk Assessment

AI threat catalogueReliability and Responsible UseProduction

Factual Inconsistencies (Hallucinations)

AI language models sometimes produce content that sounds convincing but is simply made up (hallucinations), including citations, figures, sources, or events. These outputs appear just as confident as correct answers.

As of: July 2026 · Catalogue version 2026.07.17.3 · 6 mitigations · 10 verified sources

Description

Language models compute, word by word, the statistically most likely continuation of a text. They do not check whether a statement is true and have no concept of the difference between knowing and inventing. Where the model lacks information, it fills the gap with plausible-sounding but fabricated content, including invented scientific references, court rulings, statistics, or software libraries. This threat needs no attacker: it is a property of the technology and can occur in any deployment, especially for questions at the edge of its trained knowledge. It becomes risky wherever outputs flow unchecked into advice, legal matters, medicine, or journalistic content.

Possible impact

When employees or customers act on fabricated content, the result is poor decisions, rework, and liability exposure; in a publicly documented legal dispute, a company has already been held to its chatbot's incorrect statement. Invented statements about individuals also touch the GDPR principle of accuracy. Publicly known incidents damage trust in the company and its AI services.

Example

An airline's customer chatbot explained a refund policy to a traveller that had never existed. The company lost the ensuing legal dispute and had to honour the invented commitment; the case is publicly documented.

Recommended mitigations (6)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM09:2025NIST AI RMF Section 2.2 · Section 2.8EU AI Act Article 13(1), 13(3)(b)(ii), (iv), (v) · Article 9(1), 9(2)(a), 9(2)(d)BSI R15 · R4BIML BIML-LLM inference:3 · BIML-LLM LLMtop10:9 · BIML-LLM raw:10

Verified references (10)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Reliability and Responsible Use.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Factual Inconsistencies (Hallucinations)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/hallucinations/

← Back to the full catalogue