AI Hallucinates. Does the Board Notice?
Why hallucinations are the underestimated governance risk of the AI era
The problem: statistical plausibility instead of causality
Large language models possess no intelligence in the human sense. They possess statistical pattern recognition. What they generate is based on probabilities, not on an understanding of truth. Floridi and Chiriatti showed as early as 2020 that these models produce answers “without any understanding”, meaning without any grasp of content.
The result is content that can be linguistically flawless, structurally convincing, and factually wrong in its entirety. AI research calls this phenomenon hallucination: the generation of content that is linguistically and structurally indistinguishable from correct statements, yet entirely invented.
The answers depend heavily on the training data. What an artificial intelligence produces is based on statistical correlations, not on factual causality. Particularly problematic: when a correct answer cannot be found in the training data, the model falls back on associations that reflect no causal relationship at all. boyd and Crawford described this as early as 2012 as apophenia: perceiving patterns that do not actually exist, simply because vast quantities of data can offer connections radiating in every direction.
Two types of hallucination
Research distinguishes between two types with different risk profiles for the board:
- Intrinsic hallucinations directly contradict the source information. The model receives correct data and still generates false statements. For the board, this means that even when the underlying documents are correct, the AI-generated summary can still contain factual errors.
- Extrinsic hallucinations are claims that can neither be confirmed nor refuted, because they are simply invented. For the board, this type is particularly dangerous, because it escapes straightforward fact-checking.
Causes of hallucination
The causes are varied and partly systemic. The following overview shows the main drivers:
- Statistical approximation: The model maximises the probability that the generated text sounds right. Not that it is right.
- Flawed training data: Missing, biased, outdated, or synthetic data lead to systematic misinterpretation.
- Context loss: Models can become inconsistent over long dialogues (“context drift”).
- Overconfidence: The model signals high certainty even when it has no evidence. This disables human scrutiny.
- Prompt induction: Biased or ambiguous inputs can activate false patterns.
- Knowledge cutoff: Language models have a knowledge cutoff date and still generate answers about events after that date.
- Retrieval errors (RAG): Flawed or irrelevant documents in the retrieval phase lead to hallucination even when a knowledge base is connected.
- Temperature parameter: Higher temperature settings increase the creativity of the output, but also raise the probability of hallucination.
AI generates statistically plausible fiction with absolute conviction.
This is not a bug. This is the architecture.
Risk amplifiers: agentic AI and compound risk
The hallucination risk is significantly sharpened by two current developments:
Agentic AI: When AI systems act autonomously and use their own outputs as inputs for further steps, a hallucination at the start of the chain propagates through the entire process. The model does not check its own intermediate results for correctness.
Compound risk: When AI-generated output A forms the basis for AI-generated output B, the error risk multiplies. For board decisions that rest on several AI-supported inputs, this cumulative risk is critical.
Both developments make one thing clear: the hallucination risk is not a static, isolated problem. It scales with the degree of automation and the chaining of AI systems.
Operational approaches to reduction
Various approaches to reducing hallucination have become established at the technical and operational level. None of them eliminates the problem entirely. The board does not need to understand these approaches in detail, but it must know that they exist, what they achieve, and where their limits lie:
Retrieval-Augmented Generation (RAG) adds an upstream search over a defined knowledge base to the language model, so that answers rest on verifiable documents. However, the model must be able to recognise noise and irrelevant information during retrieval, and integrating heterogeneous or contradictory sources remains a challenge.
Reinforcement Learning from Human Feedback (RLHF) reduces hallucination through targeted training with human feedback. However, RLHF can produce a so-called “alignment tax”, in which the model loses previously learned capabilities.
Post-hoc methods check and correct generated content after the fact, for instance using external tools such as search engines or fact-checking systems.
What all these approaches share: they reduce hallucination, but they do not remove it. Human review therefore remains indispensable. And this is exactly where the board’s responsibility begins.
Regulatory context
For high-risk AI systems, the EU AI Act requires that training, validation, and testing data sets be relevant, sufficiently representative, and, to the best possible extent, free of errors and complete (Art. 10). This requirement is already regulatory reality. For the board, this means: should the company fall within the scope of the EU AI Act because of its market exposure, the quality of the training data is not a technical detail. It is a compliance duty that belongs on the board’s agenda.
Strategic governance: what the board must actually do
Technology can be delegated. Judgement cannot.
The operational measures for reducing risk (RAG, RLHF, post-hoc methods) are necessary, but they sit within the responsibility of operational management. The board carries a different responsibility: it must create the framework within which AI is used responsibly. That requires six concrete strategic measures.
- Mandatory labelling of AI-supported decision papers: The board must always know which decision papers rest wholly or partly on AI-generated content. Without this transparency, it cannot assess the hallucination risk. In practice: every paper submitted to the board that contains AI-generated content must be labelled as such. The label must state which model was used, which data sources were drawn on, and whether human validation took place. This duty belongs in an AI policy and must be checked periodically for compliance.
- Human-in-the-loop as a binding governance policy: No AI-generated content may feed into a strategic or regulatorily relevant decision without qualified human review. This is not a recommendation; it must be anchored as binding policy. In practice: for every AI application that feeds decision papers to the board, it must be defined which specialist carries out validation, against which criteria review happens, and how approval is documented. The board must satisfy itself that this process exists, is actually followed, and is auditable.
- AI literacy at board level: The board does not need to know how to code. But it must be able to ask the right questions. Anyone who does not understand what hallucinations are and how they arise cannot assess the risk, and will end up relying on papers they cannot judge. In practice: AI literacy must be defined as a competency requirement for board members. This covers a basic understanding of hallucination, the dependence on training data, the limits of current mitigation approaches, and the risks of agentic AI and compound risk. Regular training and briefings by independent specialists should be introduced.
- Supplier due diligence for AI vendors: When the company uses AI systems from third-party providers, the board must ensure that a sound due diligence process takes place, one that goes beyond functional requirements. In practice: due diligence must cover hallucination rates and how they are measured, the origin, quality, and currency of the training data, the risk-reduction measures in use (RAG, RLHF, post-hoc), configurable parameters such as temperature settings, transparency about model limits and knowledge cutoffs, and the contractual allocation of liability for flawed outputs. These criteria must be built into procurement and presented to the board for material AI investments.
- Clarify liability and escalation before the incident, not after: When an AI-supported decision basis turns out to have been hallucinated and a wrong decision was made on that basis, the chain of responsibility must already be clear. This question must not be settled only once damage has occurred. In practice: the board must have it defined who is responsible for validating AI outputs, what the escalation path looks like once a hallucination is detected, which decisions must be unwound if their basis turns out to be flawed, and how liability is contractually regulated when third-party AI was involved. These arrangements belong in the internal control system and must be reviewed by the audit committee.
- AI governance as a standing agenda item on the risk or audit committee: AI governance must not be a one-off project or reactive crisis management. The technology moves fast, the risks keep changing, and the board must stay informed. In practice: AI governance is anchored as a recurring agenda item on the risk or audit committee. Reporting must cover the current state of AI use in the company, hallucination incidents that have occurred and their impact, the effectiveness of mitigation measures, regulatory developments requiring action, and the assessment of new risks, particularly agentic AI and compound risk. The board ensures that this reporting comes from a qualified, independent source.
References: