The claim linter: catching numbers your AI made up

The dangerous thing an AI copywriter produces is not the clumsy sentence — it is the confident one with a made-up number in it.

The worst thing an AI copywriter produces is not the clumsy sentence. It is the smooth, confident one with a number in it that nobody ever measured. Ask a model to write a product email and it will reach, unprompted, for specifics — cut your workload in half, join thousands of teams already doing this, the fastest way to ship. Specifics are what persuasive copy is made of, and the model has read a million examples of the shape. But none of those three claims came from your data. The model did not set out to deceive; it pattern-matched its way to the silhouette of a good sentence, and the silhouette of a good sentence includes a proof the model does not actually hold.

This is a different failure than the one everyone guards against. Every draft passes through a spell-checker and nobody thinks twice about it. Almost no draft passes through a claim-checker, and that is the gap where trouble lives. A typo embarrasses you. A fabricated statistic in a marketing email — a conversion lift you never measured, a customer count you cannot substantiate, a comparison to a competitor you never ran — is a different order of problem: it is a false statement of fact, sent at scale, with your name on it. Depending on what you claimed and to whom, it is a trust problem, a deliverability problem, or a regulatory one.

So between the model drafting a piece of copy and the system being allowed to schedule or publish it, we run a pass we call the claim linter. It does exactly one job: read the generated text and find the sentences that assert something the system cannot prove. It is not a grammar tool and not a style tool. It is a lie detector aimed at our own outputs, on the working assumption that a model writing marketing copy will, often enough to matter, promise things we have no standing to promise.

What counts as a claim worth catching falls into a few reliable buckets. Invented numbers are the first and worst: any percentage, multiplier, count, or dollar figure that did not come from a real, connected metric. Superlatives and absolutes are the second — best, only, number one, guaranteed, never — words that assert a provable-and-usually-false fact about the world. Then comparative claims that name or imply a competitor; fabricated social proof, the thousands of happy customers nobody counted; and regulated claims, the health or financial promises that carry legal weight no matter who writes them. A sentence tripping any of these does not get to publish on the model's confidence alone.

a spell-checker asks whether the words are right. a claim-checker asks whether the sentence has earned the right to be true.

The mechanism has two layers, because the buckets split into two kinds of problem. Some are shape problems a rule can catch: a superlative is a word on a list, a number is a digit the text should not contain unless we put it there, a competitor mention is a name in a set. Those are cheap and deterministic. The harder ones are grounding problems, and for those the linter needs to know what is actually true. So we hand it the facts — the real metrics the system already pulls from connected tools — and a second model pass grades each numeric or factual claim against them. We grew signups twenty percent is not flagged if the connected analytics say we grew signups twenty percent. The identical sentence is flagged when the data says nothing of the kind. Grounding is the difference between a linter that blocks all numbers, which is useless, and one that blocks only the numbers you made up.

The default when the linter is unsure is the entire design, and we made it deliberately strict: a claim it cannot verify is treated as a claim it must not ship. Unverifiable does not fall through to published; it falls through to blocked-and-surfaced. This is the same instinct that leads us to treat a missing secret as a locked door rather than an open one — when the safe reading and the convenient reading diverge, the convenient one has to be the deliberate choice, never the default. A claim the system cannot back is, for our purposes, a claim that is false until grounded, and it waits behind a gate instead of walking out the front.

What waits behind that gate is not a dead end. A flagged claim has two honest exits. The model can rewrite the copy to remove the unprovable assertion — cut your workload in half becomes spend less time on the busywork, a promise of a number downgraded to a promise of a direction, which is both truer and still persuasive. Or, when the claim might be real but the linter cannot confirm it, it surfaces to the operator as a plain flag: this sentence asserts a 20% lift we cannot verify — is it true? That is the same discipline that makes an honest operations room show connect this provider instead of a fabricated zero. A flag you can see and resolve beats a claim that shipped because nobody was watching.

The arithmetic is worth making concrete, even as pure hypothetical. Suppose the model drafts thirty pieces of copy in a month, and suppose one in five reaches for an ungrounded specific — a plausible rate for a tool built to sound confident. That is six false claims a month heading for real inboxes and real ad platforms. Without the linter, your defense is a human remembering to fact-check copy that reads as authoritative precisely because a language model wrote it — and authoritative-sounding text is the kind humans check least. Six unverified claims a month, shipped, is not a hypothetical reputation cost; it is a steady one. The linter turns those six into six flags a person resolves in seconds, or six rewrites the person never has to see.

Be honest about where the net has holes. A claim linter catches assertions, not implications — copy can mislead without stating a single checkable fact, through tone, omission, or a carefully suggestive framing, and no linter reads subtext. It produces false positives too: a true claim the system simply has no data to confirm gets flagged, and an operator who tires of clearing correct-but-unverifiable flags will start clearing them without reading, which is worse than no linter at all. The tuning that matters is not catching everything; it is keeping the flag rate low enough that every flag still gets a human's real attention. A linter that cries wolf trains you to ignore the wolf.

The frame we would offer anyone letting a model write words that go out under their name: your copy generator's job is to be persuasive, and persuasion and truth are not the same objective — a model optimizing for the first will cheerfully sacrifice the second, not from malice but from mimicry. You do not fix that by asking the model to be more honest. You fix it by putting a second, narrower thing between the draft and the world whose only job is to ask, of every confident sentence, one question: can we actually back this? Ship the ones that pass. Hold the ones that cannot. The most valuable copy your AI writes is sometimes the sentence it is not allowed to send.

These notes come from building SiteOps

Get started