Why
Correct and incorrect look exactly the same.
Everybody has settled on a word for this. The model hallucinated. It made something up, said it with total composure, and you found out later. The word is useful, and it points at the wrong half of the problem.
Making things up is not the difficulty. People guess too, and every profession has machinery for that. The difficulty is that when a model is wrong, the wrongness has no tell. Confidently wrong is the phrase people reach for, and the word doing the work is confidently.
So the machinery of second looks stops working. Not because your reviewers got worse, but because what they were good at — the sentence that feels thin, the number that looks off, the paragraph where somebody was clearly guessing — has nothing to grip on text where the guessing reads exactly like the knowing.
What a model hands you
The inlet separator is designed for 1 950 kPag at 65 °C. The minimum ambient design temperature is −40 °C. A turndown ratio of 3:1 applies to the train.
Three statements. One of them is standing on something.
What Chirality hands you
The inlet separator is designed for 1 950 kPag at 65 °CFact · P-DB-004 §3.2. The minimum ambient design temperature is −40 °CAssumption · site data pending. Turndown ratio: not in the admitted sourcesTBD · open item OI-07.
The same three. Now your reviewer knows where to look, and the 3:1 had nowhere to go.
Why that is fatal in a duty-of-care profession
Authenticating a work product means accepting personal, non-delegable responsibility for it. The regulator permits that on one of two conditions: you supervised the work, or you reviewed it thoroughly. Both assume you can tell what is known from what is assumed, and where evidence stops and interpolation starts.
A raw model output does not let you. It reads as authoritative and offers no provenance and no labels, so the thorough review the regulation requires becomes a complete independent re-derivation.
Which eliminates the entire benefit of having used the model. You bought a faster draft and paid for it with a slower review, and the person paying is the one whose seal goes on the drawing.
That is the trap most organisations are sitting in. No amount of policy or prompting discipline gets you out of it, because it is structural.
Stop trying to fix the model
The obvious response is to make the model wrong less often: better models, retrieval, grounding, citations. That work is real and we use it, and on its own it cannot finish the job, because all of it is population-level. It moves the rate at which a system is wrong, and a rate is a fact about a thousand outputs. Professional reliance is a question about this claim, in this document, today. A ninety-nine per cent grounded report is not ninety-nine per cent signable.
So the architecture takes the other route. It does not try to stop the model being wrong. It makes the standing of every claim visible, through four rules that every published workflow is written to, that the review scans look for, and that a reviewer checks first:
- It shows its work. A substantive claim carries the file and section it came from, or an explicit marker saying it has none.
- It does not fill the gap. Where a value is missing, the agent records that it is missing and raises it as an open item. The scans look for values with no source, so an invented one has somewhere to be caught.
- It does not settle an argument between your sources. When two documents disagree, both are recorded and the disagreement goes to a person. A silently reconciled contradiction is how a wrong number survives three reviews.
- Every claim says what kind of claim it is. Fact, assumption, proposal awaiting a decision, or unknown. The tell that was missing is put back deliberately, by the method and not by the model’s tone.
The reviewer opens the document at the assumptions and the unknowns and spends their judgement there. Missing information has become a finding.
Why it has to be files
All project state lives in version-controlled plain files. No database behind the scenes, no vendor system holding the real copy. Traceability, immutable snapshots, an approval bound to the exact content it was given for, an audit trail a stranger can read — all of it depends on the record being ordinary files that outlive the session. Six months after a job closes, the question is where a number came from, what was assumed, and who decided that was acceptable.
There is a commercial consequence too. A method kept as files is an asset you hold. The same capability kept as configuration inside somebody’s platform is one you rent.
The regulator already wrote the rule
APEGA’s practice standard on Relying on the Work of Others and Outsourcing governs what a professional must do when relying on work somebody else produced. Its obligations are written in terms of the professional’s conduct — supervise, review, authenticate — and not in terms of what the worker is. Junior engineer, intern, subcontractor or agent, the duties do not change.
A firm adopting this is applying machinery it already runs to a new kind of worker. Our architecture is mapped clause by clause against that standard. The interpretation is ours, and it is jurisdiction-dependent.
Where the name comes from
A chiral object cannot be superimposed on its mirror image. Your two hands are the same object in every measurable respect, and no rotation will make one become the other.
Information and accountable knowing stand in that relation. You can write something down completely, transmit it perfectly and index it forever, and it still will not have become anybody’s accountable knowledge.
Authentication does not create knowledge and does not establish truth. It records one attributable, scoped, content-bound act: this person, having reviewed this exact content, accepts responsibility for relying on it.
That permanent gap is the chirality the company is named for, and it is why no amount of engineering will let a machine authenticate work. It is not a limitation of current technology. It is the shape of the thing.
It is also a more useful way to see hallucination. Hallucination describes a defect in the model and points you at fixing the model. Seen the other way, nothing has gone wrong: the model produced information, and information never carried its own warrant. A citation does not know it is true. Humans used to carry the accountability along with the information, invisibly, in the same transaction. The machine breaks that bundle apart. You cannot close the gap, but you can stop pretending it is closed, mark where it falls, and put a person at the crossing.
Where the loop stops
The usual phrase is human in the loop, and it gives the game away. A loop is something you can be taken out of — by a setting, by a deadline, by somebody who has watched it work forty times. Every system built that way eventually runs without you.
So the human is not in the loop here. The human is the point at which the loop stops. In every published workflow, machine output waits: a finding for a disposition, a section at its gate, a lifecycle state for a signature. The provenance, the labels, the boundaries and the record all exist to make that decision better informed. None of them exist to make it unnecessary.
We should be plain about what enforces this. The application enforces which folder an agent may touch and whether it may read, ask, or write. The rest is not enforced by software, and we will not pretend it is. It is a discipline, written into the files the agents work from, so that keeping it is the easy path and dropping it is a visible act.
What this does not solve
The controls make specified gaps and nonconformance detectable within their declared coverage. They do not guarantee that every claim is captured or every failure caught. A labelled assumption is still an assumption; the label tells you to look, not that somebody has. A citation proves a claim came from a source, not that the source was right. None of this makes anybody competent, and none of it makes anybody disciplined: a gate can be waved through and a finding can be dismissed unread. It makes a competent person’s review efficient, and it makes a lapse in discipline visible in the record.
What it does is give the wrongness a tell again. The reviewer who could once spot the thin paragraph gets their instincts back, because the document now says which sentences are standing on something.
If any of that landed
You do not have to agree with any of this. The software is free either way.
Take the application, point it at a job you already understand, and see whether a document that tells you where it is standing on something is worth having.