AI Keeps Handing You Sources. Check Whether They're Real Before You Use Them.
A fake citation, a hallucinated URL, a paid-feeling product pick, and an invisible watermark all surfaced this year from the same root cause: nobody checked where the source actually came from. Here's the two-question habit that catches all four.
By Patin Team · Examples are illustrative composites
When an AI tool hands you something that looks sourced — a citation, a link, a "best pick," a stamp of provenance — the plausibility of the answer tells you nothing about where it came from. Four separate stories this year made that gap expensive, in four different ways. None of them were about the AI being wrong in an obvious sense. All four were about someone trusting a source that was never actually checked.
Four stories, one root cause
Perplexity extensively cites 215,128 "best software" pages that were themselves written by AI — content built specifically to get picked up as a citation, not to inform anyone. The same week, a study of two million product listings found Google's AI Mode steering shoppers toward options averaging 21.6% more expensive than the ranked list underneath it. Neither tool was hallucinating in the sense of making something up from nothing. Both were confidently sourcing from material engineered to be sourced.
Unit 42 found 2.1 million AI-generated URLs across 685,339 test prompts, and predicted one specific domain an AI model would reliably hallucinate. Twenty-three days later, an attacker registered that exact domain and started phishing whoever clicked. The URL looked like a normal link. It resolved to a real page. It was never a real source.
A hallucinated detail in an AI-drafted intelligence report nearly triggered a military strike before someone caught that the underlying claim didn't trace back to anything. And separately, Anthropic confirmed every Claude model since August 2 embeds an invisible watermark that survives copy-paste and moderate editing — which means the provenance question runs both directions now. It's not just "where did this AI's source come from," it's "can someone else tell this came from AI at all."
Search results, citations, links, and authorship all used to carry a rough, built-in signal of where they came from. A citation implied someone checked it. A link implied a real destination. AI output carries none of that by default — it just carries the shape of it.
What to do differently
The fix isn't "verify everything" — nobody has time to trace every claim in an AI-assisted draft back to its origin. It's narrower: before you pass along anything an AI presented as sourced — a citation, a recommended vendor, a linked reference, a "the data shows" — ask two questions. Would this page or claim exist if no AI were ever going to read it? And if I clicked through or called the source right now, would something real be on the other end?
Most AI output doesn't need this. A drafted email, a summarized meeting, a first-pass outline — none of it is claiming a source. The claims that need the check are the ones dressed up as already-verified: a citation, a stat with a study behind it, a link, a "top-rated" anything.
Renata: a vendor shortlist, not a courtroom filing
Renata runs procurement at a 90-person logistics company and uses AI to build first-pass vendor shortlists — pulling together candidate software companies, their pricing tiers, and reported customer reviews. It used to feel like research, not risk: a starting list, refined later in calls. After reading about Google's AI Mode steering shoppers toward pricier picks, she added one step. Before any vendor makes her shortlist, she opens the AI's cited review source directly and confirms the review exists and says what the summary claims. It costs her about five minutes per vendor. It's caught two cases where the "top-rated" pick was rated on a page that didn't actually exist under that name.
Marcus: an internal memo that got forwarded
Marcus does competitive analysis at a 25-person B2B startup and used AI to draft a memo citing a competitor's reported funding round, sourced from what looked like a news link. He treated it as low-stakes — internal, not going external. His co-founder forwarded it to an investor update without re-checking it. The link in the memo redirected to the outlet's homepage, not the article; the funding figure had no real source behind it. Marcus's rule now: any number or claim in a memo that includes a link gets the link clicked, once, before the memo leaves his drafts folder. If the link doesn't land on the specific claim, the claim doesn't ship.
The one thing
A citation, a link, a product pick, and a watermark all look like provenance. None of them are, until you've actually checked where they lead. The habit that would have caught all four of this year's stories is the same one: before a sourced-looking claim leaves your hands, click the source.
Put this into practice
Reading is a start — but skill comes from doing. Try these drills now.
Reading about it only gets you so far
Patin turns this into five-minute drills that score what you write and tell you why. It's in closed beta — join the waitlist and we'll email you when your cohort opens.
Just want the writing? .
Keep reading on this
Why 'It Looks Right' Isn't a Verification Check
Fabricated citations, a second AI fact-checker, merged code, and OpenAI's own safety warning all failed the same test this year: does this look right. Here's the specific check that replaces it for each type of output.
5 min readReviewing AI Output: What to Actually Check
Reading it and approving it isn't a review — it's the exact filter AI output is best at passing. Interrogating is a different activity, it takes about ninety seconds, and it's most of what separates the people getting value from AI.
5 min readHow to Check a Number an AI Gave You
Figures are the highest-risk thing AI produces and the thing people check least, because a number looks like a fact. Four checks that take under a minute each, and the one that catches the most.
5 min read