When AI makes the claim, who checks it before you act?
What this means
Expert disagreement about long-term AI risk does not remove your immediate duty: know who verifies AI-generated claims before consequential action.
Your immediate problem is not whether artificial intelligence will eventually become powerful enough to escape human control.
It is whether an AI-generated claim can enter a consequential decision today without its sources, uncertainty and ownership surviving the journey.
That boundary matters whenever an output can influence customers, money, reputation, security or operations. A person may still approve the final action. That does not make the process controlled if the person cannot see where the claim came from, how it changed or what remains unknown.
Section 01
A reported incident, not a settled official finding
On 18 September 2026, CNN reported that an intelligence report produced with help from AI had led the US military to prepare to intercept a Chinese vessel in the Middle East.
CNN based its account on four unnamed sources familiar with the episode. According to that reporting, a chatbot used by an analyst had inaccurately identified the vessel's cargo. Officials examined the underlying sourcing shortly before the planned operation and stopped it. One source described the report to CNN as entirely false.
That is a serious reported near miss. It is not an independently confirmed US government finding. The sources have not been named publicly, and the full report, system, prompts, model, evidence chain and review process are not available for independent examination.
Those limits belong in the story. They do not make the control question disappear. They make it more precise: how could an AI-assisted claim reportedly travel far enough through a consequential workflow for operational preparations to begin before its provenance was properly challenged?
Section 02
What this does and does not prove
The incident does not prove that your AI system is unsafe. It does not establish that every AI-generated error will survive human review. It does not show that the use of AI itself caused every reported failure in the wider decision process.
It does illustrate a failure pattern worth testing in any organisation:
- a system produces or strengthens a claim
- the claim acquires authority as it moves through a formal workflow
- the people downstream see a finished answer rather than the weaknesses underneath it
- action begins before the evidence is reconstructed
The danger is not simply a model producing a wrong sentence. Organisations have always handled bad information. The change is speed, scale and apparent fluency. A plausible output can pass through familiar documents, dashboards and approval routes before anyone notices that the supporting evidence is weaker than the presentation.
Section 03
You do not need agreement about the distant future
Experts disagree sharply about the probability and timing of long-term loss of control. The International AI Safety Report 2026 says that expert opinion varies greatly and that the likelihood, nature and timing remain unusually ambiguous. It also says current systems show early signs of some relevant capabilities, but not at levels that would enable the loss-of-control scenarios it examines.
That disagreement matters for policy and long-range investment. It is a poor excuse for leaving today's operating boundary vague.
You do not need to settle the existential-risk debate before deciding:
- which information an AI system may read
- which sources it may retrieve from outside your organisation
- which outputs require verification
- what it may create, change, publish or send
- which decisions require named human authority
- how an action can be stopped and reversed
These are ordinary leadership decisions made more urgent by a technology that can compress research, interpretation and execution into one apparently smooth sequence.
Section 04
Start where AI enters the workflow
Do not begin with the product name or the label attached to it. Assistant, copilot and agent are used too inconsistently to tell you what the system actually does.
Start with one real workflow and trace the first point at which AI touches it.
Ask what triggers the system. Is it responding to a person, monitoring an inbox, reading a document, querying a database or acting when another system changes state?
Then separate four levels of authority:
- Answer: it produces text or analysis for a person to consider.
- Access: it can retrieve files, records, messages, websites or connected-system data.
- Recommend: it interprets evidence and proposes a decision or next action.
- Act: it can create, change, publish, send, buy, move or delete something.
The commercial and operational exposure changes at each level. Read-only access can still disclose sensitive information or shape a poor decision. A recommendation can carry more authority than its evidence deserves. An action can reach a customer, supplier, employee or financial system before a person understands what happened.
Section 05
Follow the evidence, not the finished answer
For a consequential decision, you should be able to reconstruct the claim from the output back to its inputs.
That means seeing:
- which internal records were used
- which external sources were retrieved
- when those sources were published or updated
- what the model inferred rather than found
- where conflicting evidence was excluded or compressed
- what confidence or uncertainty was communicated
- which person reviewed the evidence rather than only the summary
This is also where prompt injection becomes an operating issue rather than a technical curiosity. OWASP explains that indirect prompt injection can occur when a model accepts content from external sources such as websites or files and treats material within them as instructions. Retrieval can therefore import both information and an attempt to influence what the system does with it.
A source link alone is not enough. The reviewer needs to know whether the source supported the claim, whether the system transformed it accurately and whether another instruction altered the result.
Section 06
Human approval is useful, but it is not a magic shield
“A human was in the loop” tells you almost nothing about the quality of the control.
The useful questions are:
- Which human?
- What were they authorised to decide?
- What evidence could they see?
- Did they have time and expertise to challenge it?
- Could they stop the workflow without being penalised for delay?
- Was their approval recorded against the exact version they reviewed?
A person asked to approve a polished recommendation without its evidence is not exercising meaningful oversight. They are absorbing accountability after the system has already framed the decision.
The NCSC's May 2026 guidance recommends starting with tightly bounded, low-risk tasks, applying least privilege and making clear who owns access, monitoring, incidents and the ability to stop a system. Its August 2026 guidance adds practical emphasis on defined red lines, sandboxing, guaranteed approval gates and not relying on prompting alone.
These controls do not require every organisation to build a new governance department. They require the existing owners of technology, data, operations and commercial outcomes to agree where authority begins and ends.
Section 07
Make the decision reconstructable, stoppable and reversible
Good control does not mean preventing every mistake. That promise would be dishonest. It means reducing the chance that one weak output becomes an irreversible consequence.
For each material workflow, establish:
- Reconstruction: can you reproduce which inputs, instructions, tools and model version contributed to the result?
- Interruption: can an authorised person pause the workflow before the consequence reaches the outside world?
- Reversal: if an action is taken, can it be undone safely and within a useful time?
- Escalation: does the system recognise when evidence is missing, contradictory or outside its permitted scope?
- Ownership: is one named person accountable for the workflow rather than only for the software contract?
The NIST AI Risk Management Framework provides a useful operating sequence: govern, map, measure and manage. Its value is not the vocabulary. It is the insistence that roles, context, evidence, risk response and ongoing review remain connected.
Section 08
Controls should match consequence
The answer is not to wrap every harmless use of AI in a committee.
A tool drafting an internal meeting summary does not need the same controls as a system that changes a price, sends a customer message, approves a supplier, ranks a candidate or moves money. Treating them as equivalent wastes attention and turns governance into theatre.
Match the control to three things:
- reach: who or what can be affected
- reversibility: how easily the outcome can be undone
- evidence burden: how much confidence the decision requires
Low-consequence uses may need simple disclosure and spot checks. Higher-consequence uses may need constrained access, independent source verification, versioned decision records, explicit approval and a tested rollback route.
The point is not to slow every workflow. It is to stop speed from hiding the moment when a suggestion becomes authority.
Section 09
Five questions for your next leadership meeting
Choose one AI-enabled workflow that already affects a real decision. Ask:
- Where exactly does AI enter, and what outcome is it meant to improve?
- What internal data, external material and connected systems can it use?
- What can it create, change, recommend or send without another check?
- Who sees the underlying evidence and holds authority to stop the action?
- Can the decision be reconstructed and the consequence reversed?
If the answers are vague, do not begin with a policy document covering every possible use. Tighten the boundary around that workflow first.
You may find that the system is working well and the right decision is to leave it alone. You may find that it needs better evidence, narrower access or one additional approval. You may find that the problem sits outside AI altogether.
The test is whether the evidence helps you make a better decision, including a decision to take no further action.
If you need a practical way to examine one consequential workflow, use our five-question AI authority check. It explains the boundary between answering, accessing, recommending and acting, and what a bounded review can establish without asking you to expose confidential data.
Section 10
Sources and evidence boundaries
- CNN, “US military had close call after using AI for false intelligence report, sources say”, 18 September 2026. The account relies on unnamed sources and is treated here as reported evidence, not an official finding.
- International AI Safety Report 2026. Used for the state of evidence and expert disagreement about long-term loss-of-control risk.
- UK National Cyber Security Centre, “Thinking carefully before adopting agentic AI”, 15 May 2026.
- UK National Cyber Security Centre, “Managing the cyber risk of agentic AI”, 20 August 2026.
- NIST AI Risk Management Framework.
- OWASP, LLM01:2025 Prompt Injection.
Next useful step
Test the question before committing to an action.
See what a Marketing MRI examination includes. If you first want to clarify one specific question, you can send it without committing to a booking.
Chris Wheeler
This article comes from one of the senior operators who also carries out the examination and stands behind the recommendation at letsrocc. If we work together, you deal directly with the people testing the evidence and owning the recommendation.
Continue the thinking
Watch Marketing MRI on YouTube
Chris Wheeler explains how commercial problems can present as marketing underperformance, and the questions leadership should test first.
Visit the YouTube channelWeekly digest
Get the next insight by email
Fridays. No hot takes. Just patterns, evidence and causes.
Related reading
Follow the wider pattern
3 min read
How to Choose a Digital Marketing Consultant: Better Questions
Most selection criteria for digital marketing consultants optimise for comfort. Here is what to ask if you want structural change.
Read insight4 min read
SEO consulting: what companies should look for
How to distinguish serious SEO consulting from activity theatre, and what questions to ask before signing.
Read insight4 min read
Seven Signs You Need a Marketing Consultant, Not Another Agency
Agencies execute. Consultants assess. If you keep changing agencies without changing outcomes, the problem is probably not the agencies.
Read insight