This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If you know AI can produce confident mistakes but are unsure when that becomes your company's problem, that uncertainty is normal. Most small businesses are using tools that can draft credible text faster than their review processes have adapted. This guide explains where AI hallucinations can create business liability in the United States, what regulators and courts have actually said, and how to put a practical verification process around client-facing work without banning AI from the business.
The goal is not to predict every legal claim. It is to help you recognise when an error is low stakes, when it needs specialist review, and which controls reduce the chance of a wrong statement reaching a client or the public.
In short: An AI hallucination is not automatically illegal and does not create automatic liability. Risk usually arises when a business publishes, files, recommends or acts on false output in a way that harms someone, misleads a customer, breaches a contract or falls below a professional standard. Treat AI output as an unverified draft, then assign a person to check material facts, sources, calculations, quotes and decisions before external use.
The risk starts when the output leaves the draft
Your account manager asks ChatGPT to draft a quarterly performance report for a client. The draft includes a market-growth statistic, a plausible source name and a confident explanation of what the number means. No one checks the source, the report goes out, and the client later discovers that the study and statistic never existed.
Before a verification step, the agency has sent a false factual claim under its own name. The immediate damage may be a difficult client conversation, a fee dispute or lost trust. If the claim influenced a business decision, appeared in advertising or repeated a damaging allegation about another company, the consequences could become more serious.
After a verification step, the account manager highlights every statistic, quotation and external claim, opens the original source and confirms the wording and date. The fabricated figure is removed before the report leaves the building. The AI still saves drafting time, but it is not treated as the authority.
What an AI hallucination actually is
An AI hallucination is confidently presented information that is wrong, unsupported or invented. The US National Institute of Standards and Technology, or NIST, uses the term confabulation and describes it as erroneous or false content that may mislead users. NIST includes fabricated sources, contradictory answers and content that drifts away from the prompt within this risk category.
See the official NIST Generative AI Profile. The important business point is that fluent writing is not evidence of factual accuracy. A response can be well structured, specific and completely wrong at the same time.
Hallucinations are different from ordinary wording problems. A clumsy sentence is an editing issue. An invented statistic, nonexistent case, false product feature, incorrect customer promise or made-up quotation is an accuracy issue that can change what another person believes or does.
Can a business be liable for an AI hallucination?
Possibly, but liability does not come from the word hallucination by itself. It comes from the business conduct around the output, the type of harm, the promises made, the industry involved and the law that applies to the situation. A false internal brainstorming note is very different from a false claim in an advertisement, signed court filing, credit decision, medical instruction or client report.
There is no automatic rule that transfers responsibility to the software vendor whenever an employee used an AI tool. Customers, clients and regulators generally see the business that published the statement, delivered the advice or made the decision. Vendor terms may allocate some risk between the business and the provider, but those terms do not correct the external statement or undo harm already caused.
Potential exposure can include consumer-protection enforcement, breach of contract, professional negligence, defamation, employment claims or sector-specific rules. The exact position depends on state law, federal law, contract wording and the facts, so a qualified attorney should assess a live dispute or significant incident.
Important distinction: A July 2026 proposed FTC policy statement says ordinary incorrect AI output does not, by itself, necessarily raise an FTC enforcement issue. It also says a company may create a deception problem if it misrepresents the likelihood of hallucinations. This is a proposed statement, not a general ruling on every business use of AI. See the FTC proposal.
Where business exposure can arise
The practical risk increases when a false output crosses from drafting into representation, advice or decision-making. Common exposure points include:
- Advertising and sales claims. The Federal Trade Commission states that advertising claims should be truthful, not misleading and supported by evidence. An invented performance figure, customer result or product capability can create the same problem whether a copywriter or an AI tool produced it. See the FTC's advertising and marketing guidance.
- Client deliverables. A report, proposal or analysis may contain contractual promises about accuracy, methodology, confidentiality or professional care. A hallucinated fact can become a contract or negligence issue if the client relied on it and suffered loss.
- Statements about people or competitors. AI may invent misconduct, credentials, quotes or legal disputes. Publishing a false factual allegation can create defamation or unfair-competition risk under the law that applies in the relevant state.
- Professional filings and advice. Courts and professional bodies expect the person signing or issuing work to check it. AI use does not replace that responsibility.
- Automated decisions. Credit, hiring, insurance and eligibility decisions can trigger existing federal and state rules. The technology is not an excuse for an inaccurate reason, discriminatory outcome or unsupported decision.
What US regulators and courts have said
US authorities are applying existing rules to AI-assisted conduct rather than treating AI as a separate legal actor. The FTC has said AI can be used for fraud, deception, privacy infringements and other unfair practices that may violate existing laws. Its general advertising guidance also requires objective claims to have a reasonable basis, regardless of how the wording was generated.
Read the FTC's AI enforcement statement and advertising substantiation policy. These sources do not say that every AI mistake is an FTC violation. They show why a business should verify material claims before using them to sell, persuade or advise.
NIST's framework is voluntary, but it gives businesses a useful model for reducing risk. It recommends documented fact-checking, review of sources and citations, defined human oversight, ongoing monitoring and processes for recording errors and near misses. Those are practical controls a small business can scale down without creating an enterprise compliance department.
Courts have also made the responsibility point directly. In LNU v. Blanche, the Ninth Circuit imposed sanctions after briefs contained nonexistent cases and false quotations. The court explained that the problem was not merely using generative AI during drafting, but signing and filing material that had not been properly checked.
For financial decisions, the Consumer Financial Protection Bureau has said complex algorithms do not excuse creditors from giving accurate and specific reasons for adverse action. See the CFPB's official circular. The same operating lesson applies beyond lending: keep a human accountable for the decision and ensure the reason given matches the real evidence.
A practical control process for a small business
A useful process is risk-based. Low-stakes uses, such as brainstorming headlines, need a lighter check than work containing financial figures, legal statements, health guidance or claims about another organisation.
- Classify the use before drafting. Mark the task as internal, client-facing, public or decision-related. Anything client-facing, public or capable of affecting a person receives a factual review.
- Limit what the AI is allowed to invent. Provide source documents and instruct the tool to work only from them. Ask it to label uncertainty and leave a blank where a fact is not supported.
- Separate drafting from verification. The person who generated the output should not simply reread it for tone. Run a distinct facts pass covering names, dates, figures, quotations, product features, legal references and source links.
- Open the original source. A citation is not verified because the URL exists. Confirm that the source supports the exact claim, is current enough for the task and comes from an appropriate authority.
- Require specialist sign-off for high-stakes content. Legal, medical, tax, financial, safety and employment material should be reviewed by someone qualified for that subject before it affects a client or individual.
- Keep a short record. Save the source list, reviewer name, review date and material corrections for important work. This helps the business explain its process if a client questions a claim later.
- Record incidents and near misses. A caught hallucination is useful evidence about where the workflow is weak. Review repeated patterns, adjust prompts and templates, and decide whether a use case should be narrowed or stopped.
Simple agency rule: No statistic, quotation, legal statement, product comparison or competitor claim goes into client-facing work unless a named reviewer can point to the original source. This takes less time than repairing a report after the client finds the error.
What this looks like in higher-risk industries
Marketing and professional services
Agencies, consultants and accountants often use AI to make a draft sound authoritative. That creates a particular risk with market data, benchmarks, citations and summaries of regulations. The safest dividing line is to let AI organise supplied facts, but not treat it as the source of new facts.
Client contracts also matter. Review clauses dealing with accuracy, reliance, warranties, liability caps, confidentiality and subcontractors or software providers. NIST's Generative AI Profile suggests reviewing vendor contracts for how responsibility, incidents and model changes are allocated, which is a useful procurement question even though the framework is voluntary.
Legal services
Legal research is a clear example because a fabricated case can look convincing until someone checks the court record. The Ninth Circuit's 2026 order states that procedural and ethical rules apply regardless of whether the error came from AI or a person. A policy banning AI is not enough if staff can still use it and no one reads the authorities before filing.
Law firms need a verification step tied to the person signing the work, plus a clear response process when an error is discovered. Other professional services can apply the same principle to standards, tax rules, technical specifications and formal advice.
Healthcare, finance and employment
In healthcare, finance and employment, a wrong output can affect a person's treatment, money or opportunity. General-purpose AI should not become the final decision-maker simply because it produces a complete-looking answer. Qualified review, documented reasons and a way to challenge or correct the outcome become more important as the impact rises.
For employment tools, the Equal Employment Opportunity Commission states that federal anti-discrimination laws still apply when employers use AI in recruiting and workplace decisions. See the EEOC's AI and ADA resources. Hallucination is only one possible failure mode in these systems, alongside bias, inaccessible assessments and inaccurate candidate information.
What to do after a hallucination has gone out
Speed and honesty usually reduce the damage. Do not quietly edit the source document and assume the problem has disappeared if a client, customer or decision-maker may already have relied on it.
- Stop further use. Pause publication, distribution or decisions based on the output.
- Confirm the facts. Identify exactly what is wrong, where it appeared and who received it.
- Assess the impact. Consider whether anyone relied on the statement, whether personal data was involved and whether the issue touches a regulated service or formal filing.
- Correct the record. Give affected people a clear correction that identifies the error and supplies the verified information. Avoid blaming the AI as though that resolves the issue.
- Escalate when needed. Contact legal counsel, an insurer, a professional body or the relevant regulator when the harm, contract value or regulatory exposure is significant.
- Document the incident. Keep the prompt, output, source material, review history, correction and process changes.
A near miss should also be documented if it reveals a recurring weakness. The goal is not to punish the employee who found it, but to strengthen the system before a similar error reaches a higher-stakes document.
AI hallucination risk checklist
Use this checklist before AI-assisted work leaves the business:
- The intended use is classified as internal, client-facing, public or decision-related.
- A named person owns the final output.
- All figures, dates, names, quotations and links have been checked against original sources.
- Legal, medical, tax, financial, safety and employment claims have qualified review where appropriate.
- The content does not repeat unsupported allegations about a person or competitor.
- Customer promises and product claims match approved business information.
- The reviewer has checked whether the source is current and relevant to the United States and the applicable state.
- Important work has a saved source list and review record.
- Errors and near misses are recorded and used to improve the workflow.
- Vendor terms and insurance coverage have been reviewed for high-value or high-impact use cases.
Frequently asked questions
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Is an AI hallucination illegal?
Not by itself. Legal risk depends on what the business does with the output, whether someone is misled or harmed, and which contract, professional rule, federal law or state law applies. A false private draft is different from a false advertisement, filing or client recommendation.
Who is responsible when an employee publishes false AI-generated information?
The business may be the first party a customer, client or regulator looks to because the statement was published or delivered under the business's name. Responsibility between the employee, employer and AI vendor depends on the facts, contracts and applicable law. A vendor disclaimer does not automatically remove the business's external exposure.
Can an AI disclaimer protect a business from liability?
A disclaimer can set expectations, but it does not make a false factual claim accurate or remove every duty to check important work. It is more useful as one control alongside human review, clear source requirements and limits on high-risk uses. Specific wording should be reviewed by an attorney when the stakes are significant.
How can a small business reduce AI hallucinations?
Use approved source material, ask the tool to identify uncertainty, and require a separate facts pass before external use. Check the original source rather than trusting the citation text, and use qualified review for legal, health, financial, tax, safety or employment content. Record recurring errors so the workflow improves over time.
Should a business stop using generative AI for client work?
Usually not, provided the task is suitable and the review process matches the risk. AI can be useful for structure, summaries and first drafts, but it should not be the final authority for material facts or high-impact decisions. Narrow or stop a use case when reliable verification is not practical.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
A verification process works best when it sits inside a wider AI governance plan. Use our regional guide to document approved tools, review responsibilities and escalation points.
Read the AI Governance Guide