Cognatum

AI governance

AI grounding stops where governance starts

Every grounding guide tells you to make sure the model answers from verified source material. Almost none of them say what makes a source verified, who approved it, or what happens when two grounded documents disagree.

Cognatum Team · Sep 16, 2026 · 5 min read

Ask an enterprise AI team whether their assistant is grounded and the answer is almost always yes. It reads from company documents instead of inventing from the model's memory. That counts as progress, and for most teams it is also where the work stops.

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

Grounding tells you an answer came from a document. It does not tell you the document was the right one.

What grounding actually means

Google Cloud's documentation defines grounding as the ability to connect model output to verifiable sources of information, reducing invented detail by pulling from retrieval, search or tools at query time. Read the overview.

Salesforce puts it more plainly. Grounding is what happens when you add your own data to a prompt to get better results from generative AI. Read the tutorial.

Both are accurate. Both are also describing a retrieval problem rather than a trust problem. The load bearing word in nearly every definition on the first page of results is verifiable, and not one of them says who does the verifying.

Retrieval is not verification

A retrieval layer can only rank what it can reach. It holds no opinion about whether the policy it surfaced was superseded in March, whether the person who wrote it had the authority to, or whether a second file in the same folder says the opposite. It returns the closest match, and the model writes fluently from it.

Grounded systems still get answers wrong

The clearest public evidence comes from law. A preregistered evaluation of the leading AI legal research tools, by researchers at Stanford and Yale, found that the retrieval based systems sold by LexisNexis and Thomson Reuters each produced false information between 17 and 33 percent of the time, against vendor language about eliminating it. Read the study.

Those tools are grounded in caselaw, which is curated, professionally edited, version controlled and about as clean as source material gets. Most enterprise document estates are none of those things. One folder holds the 2023 policy, the 2026 revision and a deck somebody built from the 2024 draft, and grounding will answer from any of them without comment.

Three questions grounding does not answer

  • Who approved this source, by name, for this use?
  • Which version of it was in force at the moment the answer was given?
  • If two sources disagreed, what happened to the one that lost?

The first is usually answerable with effort, by tracing a document back to an owner. The second and third are the ones that stall a review, because they can only be answered if something recorded them at the time. A retrieval log does not do this. It lists which documents were consulted, not which version was live or what was set aside.

When two sources disagree

Research has a name for this. A survey of knowledge conflicts in large language models separates context memory conflict, inter context conflict and intra memory conflict, and examines how each affects trustworthiness in deployments where noise and stale material are normal. Read the survey.

Inter context conflict is the enterprise case. Two retrieved documents contradict each other, and the system settles it quietly by preferring the passage that reads more confidently. That is an adjudication nobody asked for and nobody recorded. The better behavior is to present both, say where the disagreement sits, and route it to a person who can decide.

What the instruments already assume

The EU AI Act treats the inputs as governable in their own right. Article 10 requires the data sets behind high risk systems to be subject to data governance and management practices appropriate to their purpose. Read Article 10.

Article 14 requires high risk systems to be designed so that natural persons can effectively oversee them, which presumes there is something specific for a person to oversee. Read Article 14.

NIST's Generative AI Profile lists information integrity as a risk category in its own right, separate from security and privacy. See the profile.

ISO/IEC 42001 applies management system discipline to artificial intelligence itself, including the evidence an organization is expected to keep. See the standard.

What software can and cannot claim

These instruments set out what an organization has to be able to demonstrate. Software can align with them and produce the evidence a demonstration rests on. No tool confers compliance or certification on the company running it, and a vendor who says otherwise is describing a marketing claim rather than a control.

A test you can run on your own stack

Pick a question your assistant is asked most weeks, one where being wrong would matter. Ask it. Then put four prompts to the reply rather than to the model.

  • Name the human who approved this wording for this purpose.
  • Name the source, and the version of it, this answer used.
  • Show me what else was read and not used.
  • Tell me what happens to this answer when the source changes next month.

Most stacks handle the first prompt reasonably and come apart on the second. The fourth is the one worth sitting with, because it is a question about time, and grounding has no concept of time. It resolves at query time and then forgets.

Notification, not silent correction

When a source moves, the right response is to tell somebody. Every entry that depends on the changed source is flagged and routed to a named person, who decides what the change means and can rework the wording before approving it again. A system that quietly rewrites an approved answer has removed the approver, which was the point of the approval. No knowledge base should be sold as always current.

Change detection has to reach structured sources too. If a table, a query or a data mart shifts, whatever depends on it needs flagging, not only the documents.

Ground on something governed

Grounding answers where an answer came from. Governance answers whether anyone stands behind it. The Cognatum Knowledge Loop is built around that handoff, with a named human at the approval gate rather than a model deciding what is true. Your company's knowledge isn't missing. It's unusable. Cognatum changes that.

Common questions

Questions this raises.

What is grounding in AI?

Grounding is the practice of connecting a model's output to external source material, usually company documents or a live search index, so the answer draws on retrievable material rather than on the model's training alone. It is a retrieval technique. It says nothing about the quality, currency or approval status of what gets retrieved.

Is grounding the same thing as RAG?

Not quite. Retrieval augmented generation is the most common way to ground a model, but grounding also covers live web search and tool or database calls. RAG is one implementation of the idea. Both share the same blind spot, which is that neither has a view on whether the retrieved material is the version anyone would stand behind.

Does grounding stop AI from making things up?

It reduces it rather than stopping it. A preregistered study by researchers at Stanford and Yale found that retrieval based legal research tools still produced false information between 17 and 33 percent of the time, and those tools draw on unusually clean, professionally edited caselaw. Grounding narrows where the model can go. It does not make the destination correct.

What makes a source verified in a grounded AI system?

In most stacks, nothing does. Verified usually means the document was reachable by the retriever. A source is verified in any useful sense when a named person approved it for a stated purpose on a recorded date, and when the answer drawn from it carries that approver, that date and that version forward.

How should a grounded system handle sources that contradict each other?

By surfacing the conflict rather than resolving it. The system should show both passages, state where they disagree, and send the item to a person who can decide which one governs. Picking the more confident sounding passage is an adjudication, and one made without a decision maker or a record of the decision.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.