← All articles

Practical guide

AI Hallucinations: What They Cost a Small Business in Practice

Why AI tools state wrong things confidently, the five ways it shows up in small business work, and the checks that catch it before it reaches a customer.

Key takeaways

  • A hallucination is not a malfunction — the tool is predicting plausible text, and a fabricated figure is produced by the same process as a correct one.
  • The output carries no confidence signal. Invented numbers and real ones are formatted identically, which is precisely why they get through.
  • The five common business cases: invented figures, fabricated sources, wrong details about your own business, confidently wrong technical instructions, and outdated information stated as current.
  • Highest-risk material is anything with a number, a citation, a legal or medical claim, or specifics about your own products and pricing.
  • The mitigation is not a better prompt. It is verifying anything checkable against a real source before it leaves the business.

Ask an AI tool for a market statistic and it will give you one: a specific percentage, a named source, a year. Formatted exactly the way a real statistic is formatted.

Sometimes the statistic exists. Sometimes it does not, and nothing in the output distinguishes the two cases.

This is the practical risk that matters most for a small business using AI daily — more than data leakage, because it happens more often and is harder to notice.

Why it happens

AI language tools generate text by predicting what plausibly comes next. They are not looking anything up, and they have no internal model of "I know this" versus "I am constructing something that fits the pattern."

Two consequences follow, and both matter:

First, fluency is not evidence. Well-formed, confident prose is what the tool produces in all cases. Coherence tells you nothing about accuracy.

Second, gaps get filled rather than flagged. Asked for something it has no basis for, the tool generally produces a plausible answer instead of declining. A citation with a real-looking author, journal, and year is a very easy pattern to complete.

This is not a defect to be fixed with better instructions. It is how the technology works, which is why the response has to be a process rather than a prompt.

The five ways it shows up

1. Invented figures

The most expensive one. Percentages, market sizes, growth rates, industry benchmarks, pricing comparisons — produced on request, formatted authoritatively.

Where it hurts: a proposal citing an invented statistic, a quote built on a wrong figure, a business decision made on a number nobody sourced.

2. Fabricated sources

Studies, standards, regulations, and articles that do not exist, or that exist but say something different. The formatting is correct, which is the whole problem.

Where it hurts: published content citing a study that is not real. This is checkable in thirty seconds and routinely is not checked.

3. Wrong details about your own business

Ask for a product description and the tool will fill in specifics it has no way of knowing — features you do not offer, turnaround times you never promised, a guarantee you do not provide.

Where it hurts: marketing copy or a customer email committing you to something you cannot deliver. The customer read a promise; you have to honor it or walk it back.

4. Confidently wrong technical instructions

Configuration steps, spreadsheet formulas, code, settings paths — plausible, specific, and wrong. Often referencing options that do not exist in the version you are using.

Where it hurts: someone follows the steps and changes something they should not have.

5. Outdated information stated as current

Models have a training cutoff. Details that were true at some point — a vendor's pricing, a product's feature set, a regulatory position — get presented in the present tense with no indication they may have changed.

Where it hurts: relying on a vendor's data-handling practices as described by an AI tool rather than by the vendor. This is exactly why reading the vendor's own terms is not optional.

What is actually at stake

For a small business, the realistic costs are ordinary rather than dramatic:

  • Credibility. A customer who catches a fabricated statistic in your proposal now doubts the rest of it. Trust is the asset that took longest to build.
  • Commitments you did not intend. A promise in a customer email is difficult to retract, whether or not you meant to make it.
  • Rework. Published content with fabricated citations has to be corrected publicly.
  • Decisions on false premises. The quietest cost, because nobody traces the bad decision back to the invented number.

The checks that catch it

There is no way to make a tool stop hallucinating. There is a reliable way to stop hallucinations reaching anyone.

Verify every number against something you can open. Your own records, or a source you clicked. If a figure came from the model, it does not go out.

Open every citation. Confirm it exists and says what the draft claims.

Supply your own facts rather than requesting them. Paste your real product details, your real pricing, your real turnaround times, and ask the tool to write with them. This eliminates category 3 almost entirely — it is the single most effective habit on this list.

Treat technical instructions as a hypothesis. Check them against official documentation before acting, especially anything that changes a setting or deletes something.

Assume anything time-sensitive is stale. Pricing, features, and terms get verified at the source.

The structured version of this — what to check, who checks it, and when — is how to review AI-generated content before it goes out.

Where this sits in the wider picture

Output accuracy is one of the five risk dimensions in AI risk management for small businesses, and the one that determines how firm your human-review checkpoint needs to be. The expectation belongs in writing — how to write an AI usage policy covers the document, and ChatGPT rules for employees covers the version you hand to staff.

If wrong output has already reached a customer, AI incident response for small businesses treats that as a Type 2 incident and covers the first hour.

Assess the exposure for a specific use

The AI Risk Checklist scores a planned AI use across five dimensions — including how the output is used and whether a human reviews it — and returns a Low / Medium / High rating with the safeguards that fit. Free, no account, entirely in your browser.

For an output review checklist, a policy that sets the review expectation, and employee guidance covering what to verify, see the Starter Pack.

This article provides practical operational guidance for AI usage management. It is not legal advice and does not guarantee regulatory compliance. Review it with qualified professionals where appropriate before adopting it.

Put it into practice

Turn the guidance into a working rule.

The free tools on this site generate a tailored AI policy, risk assessment, or prompt safety check in under two minutes — no account required.