Of the four families on the safeguards page, this risk belongs to verification of outputs. In practice: a named human owns anything AI-drafted that leaves the building, and owning means reading. Citations and quotes get opened, not skimmed. The test from the court cases: does the source exist, and does it say what the output claims? Numbers get traced to a system of record. Customer-facing tools answer from approved content or hand off to a human, and their answers are treated as commitments, because legally they are.
One safeguard that does not work: asking the AI to check itself. The lawyers tried exactly that, and the tool that fabricated the cases confirmed them. Verification happens against the real source or it has not happened.
On the risk register, run hallucination as a driver on the entries it feeds, customer misinformation, professional negligence, misleading reporting, and score each surface where AI output can ship unchecked. What AI should and should not own outright is mapped on the AI in risk management page.