A listed company blocked AI from its website and published its results with no titles and no authors. Somebody else published their own version of those results, written so that AI could read it. When investors asked, that was the version AI returned, with a citation. The citation was accurate, the answer came from a source, and that is the only thing the systems check.
The company had not published anything false. It had published its results in a form a machine could not read, and someone else filled the space. That is AI poisoning: material placed where AI will read it, shaping the account AI returns of a company, and in this case the figures investors acted on.
01What the checks test.
Much of what boards have been told about AI controls in the last 2 years is reassuring. The copilot answers only from approved documents, the assistant cites its sources, and the grounding behind each answer is checked. Each of those statements is true, and each describes the same test: that the words in the answer can be found in the words of a source.
AI checks that its answer came from your document. It does not check whether your document was right.
We spent Jun. and Jul. 2026 establishing how far that goes, across 10 of the systems organisations use. They are the models from OpenAI, Anthropic, Google, Mistral and xAI, Perplexity, Microsoft 365 Copilot, the enterprise stacks from Amazon and Azure, and the open retrieval frameworks. Each documents a safeguard, and each safeguard is a comparison between 2 pieces of text. None asks whether the source was the current version, whether the figure in it was ever true, or whether its argument reaches a conclusion the premises support.
02The 3 properties a source must hold.
A source has to hold 3 properties before an answer built on it can be relied on.
- The right document has to reach the system in a form it can read: the current version, from the right place, with its tables and headings intact.
- The claims in it have to be accurate and independently supported.
- Its reasoning has to hold, too, so that the conclusion rests on something other than itself.
A document can pass 2 of those and fail the third, and the systems' checks will not say which.
03Circular reasoning in the board’s own documents.
The third is the one to pause on, because it is where the board's own documents come in. A policy states that a risk classification is correct because the committee approved it. The assurance report, 3 sections later, records that the committee approved it because the classification was correct.
The internal copilot retrieves both, cites both pages, and summarises the control as independently validated. The grounding check passes, because nothing in the answer departs from the source. Nothing in the chain established independent evidence, and nothing in the chain was built to look for it.
The problem has been studied: circular reasoning has been a named, scored category in machine fallacy detection since 2022. What we found is that none of the 10 systems documents detection of it as a feature it ships. Asking a model to check its own reasoning is unreliable for this defect in particular. The only method with measured evidence of catching it is a research architecture, not a product feature.
The research record, with its sources, is in the white paper that accompanies this piece.
04When the exposure is deliberate.
The exposure is not only accidental. The mechanism that lets a company's own superseded document stand in for its current position lets a third party's document do the same, which is what happened in the case we opened with.
79% of misinformation or misrepresentation has the organisation's own online position as its root cause. Across more than 21,000 brands analysed by AirOps, 85% of brand mentions in AI search come from third-party content. And risk profiling across more than 119 million websites found 41% of websites unknown to the organisation's own digital teams. Anyone who wants to shape that account has more to work with than the organisation is watching.
05What directors will be asked.
For a director, the question that follows an incident is what leadership knew and what it did. A Delaware court allowed a claim against directors to proceed over an alleged failure to put board monitoring of a central risk in place. On that reading, the protection is a monitoring system that existed before the event. For a London-listed board, the information the company has published, and AI now reads, sits in our view among the material controls Provision 29 asks it to declare effective.
An industry survey of insurers, brokers and insured companies, reported in Aug. 2026, found 94% agreeing that poor AI governance increases the chance of claims against directors and officers. None of this makes an AI answer the company's statement. What it asks for is the record of what the company knew, and what it did.
06Questions to ask this week.
Three questions put that record within reach, and they can be asked of your own teams this week.
- Which of the 3 properties does our AI assurance test: that the right document was read, that its claims were true, that its reasoning held?
- Do we know which of our documents AI is reading, including the ones we have forgotten are online?
- Who is watching what AI says in our name, so that someone else's version is seen while it is still 1 document rather than a settled position?
07The record, or memory.
The answers come from a record or from memory. We believe a board is better placed with the record. The paper sets out what holding it requires: a map of what is online, named owners, the authoritative version made the easiest to read, tests on the systems in use, and a watch on what is being said. None of it is a model setting, and it sits with the organisation.
Source and link register.
External sources
- The D&O Diary, Industry survey results: AI’s impact on D&O liability and insurance.Aug. 2026. 94% of insurers, brokers and insured companies agree poor AI governance increases the chance of claims against directors and officers.https://www.dandodiary.com/2026/08/articles/artificial-intelligence/industry-survey-results-ais-impact-on-do-liability-and-insurance/dandodiary.comWe do not enable external links - please copy and paste, you are then certain as to the link being opened
- AirOps, Introducing AirOps Offsite.2026. 85% of brand mentions in AI search come from third-party content.https://www.airops.com/blog/introducing-offsiteairops.comWe do not enable external links - please copy and paste, you are then certain as to the link being opened
- Delaware Supreme Court, Marchand v Barnhill.2019. Board monitoring of a central compliance risk.https://courts.delaware.gov/Opinions/Download.aspx?id=291200courts.delaware.govWe do not enable external links - please copy and paste, you are then certain as to the link being opened
- Financial Reporting Council, Corporate Governance Code guidance.Provision 29 on material controls.https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/corporate-governance-code-guidance/frc.org.ukWe do not enable external links - please copy and paste, you are then certain as to the link being opened
- Jin, Z. et al., Logical fallacy detection. Findings of EMNLP 2022.2022. Circular reasoning as a scored category since 2022.https://aclanthology.org/2022.findings-emnlp.532/aclanthology.orgWe do not enable external links - please copy and paste, you are then certain as to the link being opened
AAAnow research and material
- AAAnow, Source-Document Integrity and Circular Reasoning in AI-Grounded Information.2026. The white paper this piece draws on.https://briefing.aaanow.ai/briefing.aaanow.aiWe do not enable external links - please copy and paste, you are then certain as to the link being opened
- AAAnow, The use cases: what happened, and the impact.2026. Reference UC/2026/R4.aaanow.ai/use-cases/
- P&C / Sitemorse risk profiling, 2017 to 2023, covering more than 119 million websites.41% of websites unknown to the organisation's own digital teams.
- AAAnow Research, Dec. 2023 to Jan. 2026; P&C (human misinformation) 2014 to 2023.79% of misinformation or misrepresentation has the organisation's own online position as its root cause.