A hallucination arrives in exactly the same shape as a correct answer. That is the whole problem — and why fluency is not evidence.

The dangerous property of a fabricated answer is not that it is wrong. Plenty of things are wrong. It is that it is indistinguishable: same confident register, same clean prose, same absence of hedging. Human error usually leaks — people hesitate, qualify, contradict themselves. Generated error does not leak, because fluency is produced independently of accuracy.
This breaks the intuition most people bring to reading. We are trained on a correlation between confidence and reliability that simply does not hold here, and no amount of experience with the tool retrains it, because there is no signal to learn. Which is why "I'll just check the ones that look wrong" fails as a strategy: the ones that look wrong are not the population you need to worry about.
It also explains why hallucination and bias need separating rather than lumping under "AI gets things wrong". A hallucination is a fabrication with no basis — a fact that never existed. Bias is a systematic lean in outputs that are grounded, produced by patterns in the data or the context. Different causes, different detection, different fixes. Prompt injection is a third thing again: not error but hijack, an instruction smuggled in through content the model was asked to read.
So the only durable defences are structural, not perceptual. Ground answers in retrievable sources and demand citations. Constrain output to a schema a validator can check. Route low-confidence cases to a human instead of smoothing them. Make the system say "I don't know" a permitted answer with a defined trigger. None of these make the model humbler — they make its claims checkable by something other than your instinct about the prose.