Practical skills · Beginner
How to Fact-Check AI Output (A Workflow That Takes Two Minutes)
A triage system for deciding what to verify, plus the specific methods for checking citations, statistics, quotes, code, and legal or medical claims.
"Always verify AI output" is advice nobody follows, because verifying everything would take longer than doing the work yourself. The useful question is not whether to verify but what to verify and how fast.
This guide gives a triage rule, then specific methods per claim type.
The triage rule
Before checking anything, sort each claim into one of three buckets.
| Bucket | What it covers | Action |
|---|---|---|
| Verify always | Named sources, statistics, dates, prices, legal/medical/financial claims, anything you will publish or send externally, anything with an authoritative source | Check before use, every time |
| Verify by consequence | Technical explanations, historical summaries, how-something-works claims | Check if being wrong would cost you real time, money, or credibility |
| No verification needed | Rewrites of text you supplied, brainstormed options, structural suggestions, style edits, code you will run and test | Your own judgment is the check |
The pattern behind the buckets: verification effort should track how much the model had to invent. If you supplied the material, there is little to invent. If it produced a specific fact from memory, that is exactly where fabrication lives.
The most common expensive mistake is treating bucket 1 as bucket 3 — forwarding a confident-sounding statistic because the surrounding prose was well written.
Method 1: citations and sources
This is the highest-risk category, because fabricated references look more legitimate than real ones — they are generated from the average of thousands of real citations, so the formatting is flawless.
The check, in order:
- Search the exact title in quotation marks. Not the topic — the title. If a paper exists, an exact-phrase search finds it.
- If nothing returns, stop. It does not exist. Do not ask the model for a link; it will generate a plausible URL with the same mechanism.
- If something returns, confirm author and year match. A real title with the wrong authors attached is extremely common.
- Open it and find the claim. A real source that does not support the claim is the subtlest failure of all.
Worked example
Ask any assistant for research on a narrow topic and you might get:
Kaminski, R. & Oyelaran, T. (2021). Longitudinal Effects of Asynchronous Instruction on Undergraduate Retention. Journal of Educational Technology Research, 48(3), 211–229.
Everything here is right except its existence. The journal name is plausible, volume/issue formatting is correct, the page range is sensible, the title uses genuine field vocabulary. Searching "Longitudinal Effects of Asynchronous Instruction on Undergraduate Retention" in quotes returns nothing — which is the whole test. Thirty seconds.
Red flags — not proof, but reasons to check first:
- Suspiciously well-matched titles. Real research is rarely this on-the-nose for your specific question.
- Round page numbers, or a run of citations with unusually consistent formatting.
- Multiple sources that all support the same convenient conclusion.
- DOIs that do not resolve. A DOI is checkable in one click; always click it.
Method 2: statistics and numbers
Numbers are dangerous because they feel like evidence and get quoted onward.
Ask three questions:
- Who measured this? A statistic without an origin is not a statistic. Ask the model directly: "Who produced this figure, in what year, using what method?" Vagueness here is diagnostic.
- Does the primary source say it? Go to the organisation, not a secondary article about it.
- Is it plausible at all? Sanity-check the magnitude. A market "growing 340% annually" for five years implies a size that usually collapses on contact with arithmetic.
A specific trap: blended or drifted figures. A model may state "73% of businesses report improved productivity" where the real study said 73% of surveyed respondents at companies over 500 employees reported some improvement in at least one measured area. The number survived; every qualifier that made it meaningful did not. This is not detectable from the output — only by opening the source.
Method 3: quotations
Assume every quote is wrong until checked. Models reconstruct quotes from paraphrases in training data, producing a version that is close, more quotable, and not what was said.
The check: search the exact wording in quotes. If results only show aggregator quote sites and no primary source — no transcript, book page, interview, or recording — treat it as unverified. Misattribution to famous figures is especially common: crisp aphorisms accumulate around Einstein, Twain, and Churchill regardless of origin.
Method 4: code
Code has the best verification story of any category, because you can execute it.
What to check:
- Do the APIs exist? Confirm every function, method, and parameter against official docs. Plausible-but-nonexistent methods are routine — they follow the library's naming conventions perfectly.
- Does the package exist? Check the registry before installing. Fabricated package names are a real supply-chain risk: attackers have registered names that models commonly hallucinate.
- Run it, including edge cases. Empty input, nulls, very large values, concurrent access.
- Read the security-sensitive parts line by line. Generated code frequently omits input validation, uses string interpolation in queries, or logs secrets — because insecure examples are abundant in training data.
Do not rely on "I tested this" claims in the output. No test was run. See AI for programming for a review workflow.
Method 5: recent events
A model's knowledge ends at its training cutoff, and it usually does not know where that boundary is.
The rule: for anything time-sensitive — prices, versions, who currently holds a role, whether a company still exists, current law — either use a tool that actually searched, or verify externally. "Current" and "latest" in AI output mean "as of some unstated point in the past."
When search was used, still check the source. Retrieval improves accuracy but adds no verification step. The model can misread a page, merge two sources, or confidently summarise a bad one. Click the citation and confirm it says what the summary claims. If a claim has no citation in a search-grounded answer, treat it as unsourced.
Method 6: high-stakes domains
For medical, legal, financial, tax, safety, and immigration questions, one additional rule applies:
Use AI to understand the shape of the problem, never as the authority.
It is genuinely useful for learning vocabulary, understanding what a document is doing, and working out what to ask a professional. It is not a substitute for one — these domains are jurisdiction-specific, date-sensitive, and fact-specific in ways that generated text cannot reliably capture. Lawyers have been sanctioned for filing AI-fabricated case citations. The failure mode is not hypothetical.
The two-minute routine
For a typical answer you are about to rely on:
- Scan for specifics — numbers, names, dates, citations, API calls. These are the verification surface. Prose between them is usually low-risk.
- Check the load-bearing one first. Usually a single claim carries the conclusion. If it fails, you can stop.
- Exact-phrase search citations and quotes. Fastest, highest-yield check available.
- Open one primary source for the key statistic.
- Ask the model to mark its own inferences: "Which statements here are from the sources you retrieved, and which are your own inference? List them separately." This is imperfect — it is still generated text — but it reliably surfaces the softest claims for a first pass.
Most answers need one or two checks, not a full audit. Triage is the skill.
What does not work
| Non-method | Why it fails |
|---|---|
| "Are you sure?" | Tests agreeableness. Models abandon correct answers under mild pressure. |
| Asking twice | A second sample from the same distribution, not a second opinion. |
| Asking for a confidence score | Generated text, not a calibrated measurement. |
| Asking for a link | The URL is produced by the same mechanism as the fake citation. |
| Cross-checking with another AI | Shared training data means shared errors. Two models can agree on the same fabrication. |
Every item on that list is a way of asking the model about itself. The only real verification is external.
Doing this in PhantomAI
The workflow above is the reason PhantomAI leans on document context and web search rather than raw recall. When you attach a file or paste a URL, answers are grounded in that text, and asking for supporting quotes makes errors immediately visible — if the quote is not in your document, you have caught it.
When PhantomAI searches, it surfaces what it found so you can open it. We would rather you click through and confirm than trust the summary. Nothing in the product removes the need for the checks on this page; see our limitations page for what we know it gets wrong.
Continue
- Limitations of AI assistants — the failure modes behind these checks
- How AI assistants generate answers — why fabrication happens at all
- AI for research — a research workflow with verification built in
Simanta Pratim Das
Founder & Developer
Simanta is an independent AI engineer based in Guwahati, India, building PhantomAI as a solo project — designing the product, the interface, and the AI pipeline end to end.
Related guides
Try these techniques in PhantomAI
PhantomAI is free to use, and the workflows in this guide work best when you paste in your own material rather than relying on the model's memory. Before you start, it's worth reading what it can't do.