Failure mode · FM-07
Hallucinated facts, real actions
The model invents something (a policy, a price, a legal citation) and then acts on it or communicates it with the authority of the firm behind it.
Answered by
Grounding, and human sign-off before consequential action.
OWASP cross-reference
LLM09:2025 Misinformation · ASI09 Human-Agent Trust Exploitation (partial)
No dedicated OWASP agentic category for hallucination-driven action. ASI09 is adjacent (agents fabricating plausible rationales that get approved regardless of root cause). The site states this openly rather than forcing a 1:1 identifier.
Sources: OWASP Top 10 for Agentic Applications 2026↗
In the record
- Air Canada held liable for its chatbot's invented fare policy
Air Canada's website chatbot told a customer he could apply for a bereavement fare after travel. The BC Civil Resolution Tribunal rejected the argument that the chatbot was a separate entity and held the airline liable for negligent…
- Courts worldwide document AI-fabricated legal citations
A growing, actively maintained database tracks court and tribunal decisions in which a party was found to have relied on AI-fabricated case citations. The count has risen steadily as more matters reach judgment.