AI Hallucinations in a Disclosure Context
The most dangerous sentence an AI will ever hand a disclosure team does not look dangerous. It reads: "The emission factor for purchased steel is 2.31 kgCO2e per kilogram (DEFRA 2024)." It is specific. It cites a source. It is exactly the format a real factor takes. And it is invented, factor and citation both, sitting in your inventory now, multiplying tens of thousands of tonnes of steel, waiting for an assurer to look up DEFRA 2024 and find that this line does not exist.
What a Hallucination Is, in Disclosure Terms
In AI, a hallucination is output that is fluent, confident, and false: the model produces something that reads as fact but corresponds to nothing real. In most settings a hallucination is an annoyance you catch and laugh off. In disclosure, a hallucination is a misstatement with a fuse on it, because the false output does not stay on your screen. It flows into a calculation, into a total, into a public filing, into an assurance engagement, into the historical record. The same trait that makes generative AI useful, its ability to produce plausible, well-formed text on demand, is the exact trait that makes it hand you a perfectly formatted lie.
The reason this matters more in sustainability reporting than in most fields is the combination of two things. First, your outputs are numbers that get multiplied, summed, and published under external assurance (independent checking of your data). Second, the people reading those numbers, the assurer and the regulator, are specifically looking for the gap between what you claimed and what you can support. A hallucination is precisely that gap, manufactured at speed. So the rest of this lesson catalogs the specific hallucinations that end up in disclosures, why each one is so easy to miss, and how each becomes an assurance finding.
It helps to understand why these models hallucinate at all, in plain terms, because the mechanism explains the danger. A generative model is, at heart, a system for predicting plausible continuations of text. Asked for an emission factor, it produces the most plausible-looking factor, not the correct one, because plausibility is what it was built to generate and correctness is not something it can check. Most of the time the plausible answer and the correct answer coincide, which is exactly what lulls you, because the tool is right often enough to earn your trust and then wrong precisely when you have stopped checking. The model is not lying, because lying requires knowing the truth. It is doing the only thing it does, generating something that reads right, and in disclosure something that reads right but is not right has a name, and it is misstatement.
The Invented Emission Factor
An emission factor is a published conversion rate that turns activity data into emissions: so many kilograms of CO2 equivalent per litre, per kilogram, per kilometre. Factors come from authoritative, named, dated databases, and the right factor is a matter of record, not opinion. This is why the invented factor is the textbook disclosure hallucination.
Ask a model for "the emission factor for X" and it will almost always give you one, beautifully formatted, often with a citation. The trouble is that the model is not looking the factor up in a database; it is predicting what a plausible factor and citation would look like. Sometimes it reproduces a real one. Sometimes it produces a number that is close but wrong. Sometimes it invents both the number and the source. From the analyst's chair, all three look identical, because all three arrive in the correct format with the confident tone.
The damage is silent and large. A factor is a multiplier, so an invented factor does not corrupt one figure, it corrupts every tonne of activity data it touches. And it does so without any visible error: the inventory still balances, the total still looks reasonable. The corruption only surfaces when someone checks the factor against the cited source, which is exactly what an assurer does.
The cited source is the cruelest part. An analyst who sees "(DEFRA 2024)" attached to a factor often relaxes, because the citation looks like the verification has already been done. It has not. The model can invent the citation with the same ease it invents the number, and a fabricated citation that names a real database is more dangerous than no citation at all, because it actively discourages the check that would catch it. The rule that follows is uncomfortable but absolute: a citation you have not personally confirmed is not evidence, it is decoration. The only thing that makes a factor real is opening the named source and finding the line. Until you have done that, "(DEFRA 2024)" tells you nothing except what the model guessed a real reference would look like.
Fabricated Scope 3 Activity Data
Scope 3 is your value-chain emissions, around 75% of a typical footprint, and the hardest data to collect, with 79% of reporters citing supplier-data availability as a top barrier (a number to verify against its source). That difficulty creates a vacuum, and a generative model abhors a vacuum. Ask it to "complete the Category 4 upstream transport figures" when half the data is missing, and it will helpfully produce numbers for the missing rows. They will be plausible. They will fit the pattern of the rows that do exist. They will be fabricated.
This is the most tempting hallucination because it arrives disguised as help, exactly when you are most under pressure, on the data you can least verify. The model is not flagging "I made these up." It is presenting fabricated activity data in the same format, with the same confidence, as the real rows beside it. If you accept it, you have not filled a gap. You have laundered an absence into what looks like measured data, and you have done it in the largest, least-verifiable part of your footprint, the part an assurer scrutinizes hardest precisely because everyone knows it is hard.
The tell, when there is one, is that the fabricated rows are often too good. Real supplier data is messy: it has gaps, odd units, outliers, and inconsistencies, because the world is messy. Fabricated rows tend to be smooth and pattern-conforming, because the model generated them to fit. So a Category 4 table where every row is plausible, consistent, and complete should raise suspicion rather than relief, especially when you know the underlying collection was anything but complete. The honest version of that table has holes in it. A version with no holes, produced from data you know had holes, did not get more complete; it got fabricated. Learning to distrust suspiciously clean data is one of the most valuable instincts a disclosure professional can develop in the AI era.
The Target the Company Never Set
Not every disclosure hallucination is a number. Ask a model to draft your climate narrative from a few bullet points and it may write: "The company is committed to achieving net zero across all scopes by 2040." It reads beautifully. It is the kind of sentence sustainability reports are full of. And if your company never actually approved a 2040 all-scopes net-zero target, that sentence is a fabricated commitment in a public, regulated document.
This one is uniquely dangerous because it hides in prose, where numerical instincts do not fire. An analyst who would scrutinize a factor will often read a narrative sentence for tone rather than truth. But a target in a disclosure is a commitment with governance behind it: it was set, or it was not. A model inventing or inflating one, even subtly, even by shifting a date or widening a scope, has put a claim in your report that your governance never made. When an assurer or a stakeholder asks "where was this target approved," there is no minute, no board paper, nothing. The narrative said something the company did not.
The Softened Negative Impact
The quietest hallucination of all is not addition but distortion. Impact materiality requires you to disclose how your company affects people and the environment, including the negative effects, plainly. Ask a model to "draft the impact narrative" and its instinct, shaped by mountains of corporate prose, is to soften. A genuine adverse human-rights impact in the supply chain becomes "an area of ongoing engagement." A real pollution incident becomes "an opportunity for continuous improvement." Nothing is technically invented, yet the disclosure now misrepresents the severity of a real impact.
A hallucination in disclosure is not always a number that is wrong. Sometimes it is a true thing made to sound less true.
This is hallucination by omission and tone, and it is the most likely to slip through because it feels like good writing. But a softened negative impact is a misstatement in the other direction: it understates what the company must disclose. Under double materiality, failing to fairly present a material negative impact is exactly the kind of gap an assurer tests and a regulator penalizes. The fluent, reassuring sentence is doing harm precisely by being reassuring.
What makes this one especially insidious is that the softening aligns with what everyone in the room secretly wants. Nobody enjoys disclosing a bad impact. So when the model produces a gentler version, the path of least resistance is to accept it, because it reads well and it is more comfortable, and the comfort masquerades as good editing. This is the hallucination that requires the most professional courage to catch, because catching it means insisting the report say something less flattering than the draft offered. The check is mechanical, compare the narrative to the underlying evidence, but the discipline to act on it is not. Impact materiality exists precisely to stop companies from telling only the comfortable half of the story, and an AI that softens by default is a quiet pressure in exactly the wrong direction.
Why Fluent Confidence Is the Danger
Across all four, the common thread is not error, it is confidence. A model that hedged, that said "I am not certain, you should check this factor against DEFRA," would be far safer, because doubt prompts verification. Instead the model delivers everything, the real and the invented, the accurate and the softened, in the same even, authoritative voice. There is no tonal tell. The invented factor sounds exactly like the correct one. The fabricated row sounds exactly like the measured one. The fake target reads exactly like the real one.
This is why you cannot verify by reading. Reading rewards plausibility, and plausibility is the one thing every hallucination has in abundance. The only defense is structural: every factor checked against its named source, every activity figure traced to a document, every target matched to a governance record, every impact compared to what the evidence actually shows. The model's confidence must be treated not as reassurance but as the absence of information about whether the output is true.
Reframe what the model's confidence actually means and the danger becomes manageable. When a person speaks confidently, the confidence carries information: it usually means they have checked, or they have expertise, or they are willing to stake their reputation. We are trained from childhood to read confidence as a signal of reliability. A model breaks that link entirely. It is equally confident when it is right and when it is inventing, because confidence is a property of its writing style, not of its knowledge. So the skill you must build is to stop reading AI confidence as a human signal and start reading it as noise. The output's tone tells you nothing. Only the structural check, holding the claim against its source, tells you anything. Professionals who internalize this stop feeling reassured by a polished answer and start feeling reassured only by a confirmed one.
Why Each Hallucination Becomes a Specific Finding
It is worth being precise about the back end of this, because it sharpens why the front-end check matters. Each of the four hallucinations does not just create a vague risk; it creates a specific, predictable assurance finding the moment the assurer does their normal work. The invented factor becomes a finding the instant the assurer looks it up and cannot confirm it, recorded as an unverifiable conversion rate. The fabricated Scope 3 data becomes a finding the instant the assurer asks for the source of a row and none exists, recorded as unsupported activity data. The fake target becomes a finding the instant the assurer asks for the governance record that approved it, recorded as an unapproved or unsupported commitment. The softened impact becomes a finding the instant the assurer compares the narrative to the evidence and sees the severity understated, recorded as a material impact not fairly presented.
Seeing the findings in advance is what makes the verification feel worthwhile rather than paranoid. You are not checking factors because checking is virtuous. You are checking because you can see, with complete clarity, the exact question the assurer will ask and the exact finding that follows if you have no answer. Every structural check is simply you asking the assurer's question before the assurer does, while it is still cheap to fix. The hallucination caught at your desk is a non-event. The same hallucination caught at the engagement is a finding, and a finding caught after publication is a restatement. The work does not change. The cost of skipping it does, enormously, at each stage.
Worked Example: One AI Draft, Four Findings
An analyst asks AI to draft a steel-importer's emissions and narrative section. The output is clean and arrives in minutes. Read as prose, it is excellent. Read as a disclosure, it contains all four hallucinations.
The factor: "purchased steel, 2.31 kgCO2e per kg (DEFRA 2024)." The narrative: "committed to net zero by 2040." The Scope 3 table: complete, including six supplier rows for which no data was ever received. The impact note: a supply-chain labour finding described as "an area of active stakeholder dialogue." Four sentences, four hallucinations, zero of them flagged by the model.
Now watch the informed professional. They look up DEFRA: there is no 2.31 line for this steel grade; the factor is rejected and replaced with a verified one, changing the total. They check governance: no 2040 all-scopes target was ever approved; the sentence is deleted. They reconcile the Scope 3 table to received responses: six rows have no source; they are pulled and re-flagged as gaps pending labelled estimates. They pull the labour finding's underlying report: it describes a substantiated adverse impact; the narrative is rewritten to present it plainly. Same draft, four interventions, and the difference between a disclosure that fails assurance on sight and one that survives it. The AI wrote fast. The professional made it true.
Key Takeaways
- A hallucination is fluent, confident, false output. In disclosure it is a misstatement with a fuse, because it flows from your screen into a calculation, a filing, and an assurance engagement.
- The invented emission factor is the textbook case: a model predicts what a plausible factor and citation look like rather than looking one up, and because a factor is a multiplier, it silently corrupts every figure it touches.
- Fabricated Scope 3 activity data is the most tempting hallucination, because it arrives disguised as help, under deadline, in the largest and least-verifiable part of the footprint.
- A target the company never set is a fabricated commitment hiding in prose, where numerical instincts do not fire; a target is a governance fact, set or not set, never to be invented or inflated.
- A softened negative impact is hallucination by tone and omission: a true adverse impact made to sound less severe, which understates what double materiality requires you to disclose.
- Fluent confidence is the danger, not error. The model delivers the invented and the real in the same authoritative voice, so there is no tonal tell and you cannot verify by reading.
- The only reliable defense is structural: check every factor against its named source, trace every figure to a document, match every target to a governance record, and compare every impact to the evidence.
- Each hallucination becomes a specific assurance finding the moment the assurer pulls the thread, which is why catching it before it ships is the entire skill.
Skill.re