Writing

A second model is a critic, not a verifier

Asking one model to review another can improve a draft. It cannot tell you the draft is true.

A common pattern in AI workflows goes like this. One model writes a draft. A second model reviews it. If the reviewer raises no concerns, the output is marked as checked.

The first half of that pattern is useful. The second half is a mistake. A second model is a good critic and a poor verifier. Knowing the difference decides whether your checks mean anything.

What a critic is good for

Critique and revision can improve drafts. Give a reviewing model the draft, the brief and explicit criteria, and ask it to list problems. It can find real ones: a claim with no citation, a missing caveat, two sections that contradict each other, an ignored instruction, a conclusion that goes further than the evidence. Feed those points back and revise. The next draft may well be clearer. Whether it is better on your task is something to measure, not assume.

This is the work of an editor. Editors make writing better. Nobody treats an editor’s approval as proof that the facts are right.

Critique works best when it is specific. “Review this” invites vague praise. “List every sentence that makes a factual claim without a citation” produces something you can act on, and something you can check.

Why agreement is not verification

When a second model agrees with the first, it is tempting to read that as independent confirmation. It rarely is.

Models share blind spots. They are trained on overlapping data with similar methods, and they can make the same mistakes on the same inputs. If both have learned the same wrong fact, they will agree about it. If a claim is fluent and plausible, a reviewing model will tend to find it plausible too. The errors that matter most are the ones that look right. Those are the errors a similar model is least likely to catch.

The review set-up adds its own bias. A reviewer that reads the draft first starts from the draft’s framing. It is judging someone else’s answer, not working the problem from the sources. Agreement under those conditions tells you the draft is persuasive. It does not tell you it is correct.

The OWASP Top 10 for LLM Applications treats misinformation as a risk in its own right. The 2025 edition (LLM09:2025) recommends cross-checking output against trusted external sources, with human oversight for critical or sensitive information. The current 2026 edition (LLM07:2026) asks for claims to be grounded in authoritative, current sources before anyone acts on them. Both point to sources. Another model’s opinion is not a source.

If you want a second opinion, make it independent

There is a better way to use a second model. Ask it the original question, with the same sources, without showing it the first draft. Then compare the two answers.

Now disagreement is informative. Where two independent answers differ, there is something to look at: an ambiguous source, a hard judgement, or an error in one of them. That tells a reviewer where to spend their time.

Agreement between independent answers is still not proof. Shared blind spots do not disappear because the prompts are separate. A different model family and a different prompt may reduce them. They do not remove the need to check.

The same logic applies to people. A reviewer handed a polished draft and asked “is this OK?” is being asked to agree. A reviewer asked “what do the sources say about this question?” is being asked to think. The second request takes longer, and it is more likely to catch errors.

Verify against the sources

Verification means tracing each claim to evidence. In a summary of evidence, every material claim should point to a specific passage. Checking then has a clear shape: does the passage exist, and does it say what the claim says?

Some of this is mechanical, and plain code does it more reliably than a model. Quotations can be matched exactly against the source text. Citations can be resolved. Numbers can be compared. These checks are cheap, repeatable and not fooled by fluent writing.

Other parts need judgement, such as whether a paraphrase is fair or whether an omission matters. A model can help here as a triage tool, pointing a person towards the claims most likely to be wrong. If you use a model as a grader, first measure how often it agrees with people on your own material. The comparison that counts is still against the source, not against a second model’s view.

A person decides

Someone has to own the output. The AI Playbook for the UK Government sets out ten principles. One of them is that you have “meaningful human control at the right stages”. For AI-assisted analysis, one of those stages is before anyone relies on the result.

For that control to mean something, the person needs to see what was checked and what was not. A green tick that means “a second model said it was fine” hides exactly what they need to know. Show instead which claims were matched to sources, which were flagged, where independent answers disagreed, and what remains unverified.

A practical pattern

  1. Draft with citations to specific source passages.
  2. Critique against explicit criteria, then revise.
  3. Run deterministic checks on quotations, citations and numbers.
  4. For higher-stakes questions, get an independent answer and compare.
  5. A person reviews the flagged claims and a sample of the unflagged ones.
  6. Record what was verified, what was not, and who decided.

Use the second model for what it is good at. Let it make the draft better. Do not let it tell you the draft is true.

Sources

  1. OWASP GenAI Security Project, LLM09:2025 Misinformation, OWASP Top 10 for LLM Applications 2025 (source text on GitHub). See “Cross-Verification and Human Oversight” under prevention and mitigation.
  2. OWASP GenAI Security Project, LLM07:2026 Misinformation, OWASP Top 10 for LLM Applications 2026 (source text on GitHub). See “Ground Claims Before Action” under prevention and mitigation.
  3. AI Playbook for the UK Government, GOV.UK. See principle 4, “You have meaningful human control at the right stages”.

Views are my own. Where I refer to public guidance, this is my reading of it: unofficial; not government guidance.