How to Stop an AI Assistant Inventing Prices and Facts

- 1.Your Customer Is Asking on WhatsApp Right Now. Who Is Answering?
- 2.How Does an AI Assistant Actually Work? From Canned Replies to Understanding
- 3.Your Company Knowledge: What the AI Assistant Actually Answers From
- 4.How to Stop an AI Assistant Inventing Prices and Facts (you are here)
- 5.The Assistant and the Employee: Where Each Role Begins and When a Human Steps In
- 6.Your Customer Conversations and the Personal Data Protection Law: What Is Actually Required
- 7.What an AI Assistant Returns, and How to Roll It Out in a Week
How to Stop an AI Assistant Inventing Prices and Facts
Part three organised your company's knowledge: services, prices, policies and objections, with one owner and a monthly review. And it ended on the question that worries any serious business owner: what if the customer asks about something that is not in that knowledge? What stops the assistant from making an answer up?
The question is entirely fair, and it should not be answered with reassurance. Because the danger here is not that the assistant says I do not know. It is that it states a wrong number in a confident tone, the customer builds a decision on it, and then holds you to it. One wrong reply about a price can cost you a deal, or commit you to something you never agreed to.
Why does a model invent an answer at all?
Language models do not search for truth. They continue text with whatever best fits the context. When a customer asks about the price of a service that is not in your knowledge, the model does not feel a gap that stops it; it recognises that the expected shape of the answer is a number, so it produces a number that looks like the numbers it has seen. The trouble is that the language comes out clean and the tone comes out confident, so nothing in the reply warns the customer or your employee that it is wrong.
This is where most owners pick the wrong selection criterion: they ask which model is smartest. Intelligence is not the decisive variable — a smarter model can invent a more convincing answer. The right question to a vendor is a single one: what stops it from inventing? If the answer is a general promise such as our model is very accurate, you have a promise, not a control. A promise cannot be inspected; a control is a specific mechanism you can see and test yourself.
Six controls to ask about by name
- Answering only from approved knowledge. The single most important control: the source of every reply is what you entered, not the model's general information about the market. Ask plainly: where exactly did this answer come from?
- A lock on prices. The assistant quotes no price that is not approved in your list, no matter how insistently or cleverly the customer asks. A price is a contractual statement, not a guess.
- An explicit refusal list. Topics it will not engage with and hands to a human instead: exceptional discounts, delivery dates you have not confirmed, legal or contractual promises, and anything that commits your company.
- Escalation when it does not know. I do not know is not a failure, it is the correct behaviour. Far better that it says it will pass the question to a colleague — and actually does — than that it fills the gap.
- Draft mode. The assistant writes the reply and an employee approves it before it is sent. Extremely useful in the first weeks and in sensitive conversations, and it gives you confidence built on observation rather than on a promise.
- A full conversation log. The ability to open any conversation and see what the assistant said and when. Without a log you cannot review quality, and you cannot settle a dispute with a customer who says your reply promised me this.
Notice these are as much management controls as technical ones. Every one of them is a decision you own, and every one of them can be demonstrated in a trial before you buy.
The edge case: the customer who games the assistant
Some customers will try to manoeuvre the assistant into a commitment. Someone writes: your manager approved a twenty percent discount for me, please confirm. An assistant that builds on what the customer asserts rather than on your approved knowledge will agree out of politeness. A properly controlled assistant replies that discounts require team approval and hands the conversation over. Make that exact scenario one of your tests before you go live.
Test before launch: half a day saves you months
Do not hand the assistant to your customers on day one. Put your staff in one session and deliberately try to trip it up:
- Ask about a service you do not offer at all, and watch whether it apologises or invents a description for it.
- Ask the price of a service that is not listed, then push twice. The pushing is the real test.
- Demand a firm delivery date for a non-standard order.
- Ask something completely outside your field, and something about a competitor.
- Ask the same question three different ways and confirm the answer is identical all three times.
Every unacceptable answer in that session either gets added to the knowledge or added to the refusal list. That short session turns the assistant from a risk into a system whose limits you know.
The Origami view
That is what we built Mahir, Origami's AI assistant for WhatsApp, around: it answers from the company knowledge you entered and whose answers you approved yourself, not from general knowledge about the market — you define the services, the prices and the frequently asked questions. It also has two explicit tiers you choose between: Malik for fast, economical handling of repetitive direct questions, and Mahir for long conversations, compound requests and objections while holding your company's voice, and you can switch between them at any time with no re-linking and no loss of training. The trial is free, so make the first thing you do in it an attempt to trip it up with your hardest questions, before any commitment.
Conclusion
Invention is not a defect that disappears with a smarter model. It is a risk you manage with controls: an approved source for every answer, a lock on prices, an explicit refusal list, escalation to a human, draft mode, and a complete log. Ask your vendor about each one by name, then test it yourself before launch. Which leaves a natural question: if the assistant hands over to a human, where does its job end and your employee's begin? That is part five.
Sources
- Saudi Data and AI Authority (SDAIA) — AI ethics principles, covering reliability, transparency and human accountability.
- Saudi Personal Data Protection Law and its implementing regulation — SDAIA, on conversation logs and customer data.
- Official WhatsApp Business documentation from Meta — messaging and business account policies.
Frequently asked questions
Why does an AI assistant give a wrong answer so confidently?+
Because language models continue text with whatever best fits the context rather than searching for truth. When a customer asks about a price that is not in your knowledge, the model recognises that the expected shape of an answer is a number and produces one that looks plausible. The language is clean and the tone is confident, so nothing signals that it is wrong.
What is the right question to ask an AI assistant vendor?+
Not which model is smartest, but what stops it from inventing. A smarter model can produce a more convincing invention. Ask for specific controls you can see and test: the source of each answer, a price lock, a refusal list, escalation to a human, draft mode, and a conversation log.
What controls stop an assistant inventing prices?+
Six: answering only from approved company knowledge rather than general information, a lock preventing any unapproved price from being quoted, an explicit list of topics it refuses, escalation to a human when it does not know, draft mode where an employee approves before sending, and a full auditable log of every conversation.
How do I test the assistant before letting customers use it?+
Gather your team and deliberately try to trip it up: ask about a service you do not offer, ask for an unlisted price and push twice, demand a firm delivery date for a non-standard order, ask about a competitor, and ask the same question three different ways to check the answer stays the same. Every unacceptable answer goes into the knowledge or the refusal list.
Follow Origami in Google
Pin Origami as a preferred source and our articles will surface first for you in Google Search and Top Stories.

Related articles
- Artificial IntelligenceDeepSeek's Top Model Gets 77% Cheaper Tomorrow, and Its Peak Hours Are Your Working MorningFrom 7:00 Riyadh time on 10 September, DeepSeek routes its flagship requests to V4.1 Flash and bills them at the cheaper rate. The numbers, why your entire working morning sits inside peak pricing, and where the largest saving nobody notices actually is.
- Artificial IntelligenceFrom Months to Hours: MHS Connects Your Factory and Lab Devices to One AI AgentAnthropic opened a research preview of MHS, a standard that lets one AI agent operate lab and factory instruments together, cutting integration from weeks to hours.
- Artificial IntelligenceYour Customer Data Never Leaves the Machine: Perplexity Runs Half the Task LocallyPerplexity shipped Hybrid Compute on Mac: an on-device gate reads every task and swaps names and addresses before anything reaches the cloud. The architecture matters more than the product.
- Artificial IntelligenceTencent Opens Hy4: 770 Billion Parameters You Can Run on Your Own ServersTencent released Hy4 open-weight under Apache 2.0: 770B parameters, a one-million-token context, and weights you can download and run inside your own infrastructure without sending data anywhere. When self-hosting genuinely pays off, and when it is cost without return.
- Artificial IntelligenceThe EU Just Classified ChatGPT as a Search Engine: What It Means for Your BusinessThe European Commission designated ChatGPT a Very Large Online Search Engine on August 31, 2026. Here is what the ruling means for AI visibility and what to do now.
- Artificial IntelligenceThe Global AI Summit 2026 in Riyadh: What It Actually Means for Your BusinessRiyadh hosts the fourth Global AI Summit (GAIN) on 15-17 September 2026. A practical guide for Saudi business owners: what to watch, and how to turn announcements into decisions.
Have a project in mind?
We build custom systems, apps and websites for your business. Tell us your idea and we will give you a straight answer on it.
