LLM vulnerabilities (hallucination, prompt injection, and jailbreaks) are not academic curiosities: they change what you can trust in interview transcripts, open-ended survey responses, and scraped social data. In the August 19, 2025 analysis “The Price of Intelligence, ” researchers show concrete error rates (e.g., GPT‑4 hallucinated in 28.6% of medical-document queries vs 39.6% for GPT‑3.5) and argue mitigation must be system-level and process-driven (www.cacm.acm.org/practice/the-price-of-intelligence/). This post explains what those risks mean for AI-enabled qualitative research and gives a tight, practical workflow you can run in Evidano (www.evidano.com) to keep thematic findings reliable, auditable, and secure. Read on to learn where errors show up in a typical qual pipeline, which controls reduce false narratives, and a 8‑step playbook to deploy RAG, filters, and human-in-the-loop checks so your insights hold up to stakeholders and regulators.
Fast Take: Why this matters now
The ACM piece published on 19 August 2025 lays out three intrinsic LLM behaviors (hallucination, indirect prompt injection, and jailbreaks) and recommends “defense in depth” rather than a single fix. Read the full analysis here: www.cacm.acm.org/practice/the-price-of-intelligence/.
- Key quotation: mitigation is a system-design problem; expect occasional failure and design for it.
- Practical implication: qualitative teams must assume some outputs are wrong and build verification into the research workflow.
- Audience: UX researchers, policy analysts, health researchers, and ops teams running interviews, surveys, or social scraping.
Findings Snapshot
| Metric / Item | Value | Source / Note |
|---|---|---|
| Publication date | 19 Aug 2025 | ACM article |
| GPT‑4 hallucination rate (medical docs) | 28.6% | ACM (example stat in article) |
| GPT‑3.5 hallucination rate (same study) | 39.6% | ACM (comparison) |
| Hallucination range (reported) | ≈2% to 50% depending on task/domain | ACM, domain-sensitive |
| Three core risks | Hallucination; Indirect Prompt Injection; Jailbreaks | Authors' taxonomy |
What happened: core behaviors in plain language
The article explains why modern LLMs exhibit three unavoidable behaviours: (1) hallucinations, plausible-sounding but incorrect or missing facts, amplified in domain-specific or long-answer tasks; (2) indirect prompt injection, instructions embedded inside untrusted inputs (e.g., emails, scraped pages) that the model may follow; and (3) jailbreaks, crafted prompts that circumvent alignment or safety constraints.
- Root causes: autoregressive generation, stochastic decoding, imperfect and dated training data, and linguistic flexibility.
- System effect: errors can multiply when multiple AI agents or chained prompts feed each other.
- Takeaway: mitigation requires pipeline controls (RAG, filters, human review), not just a different model.
Implications for AI-Enabled Qualitative Research
For UX & qualitative researchers
Risk: fabricated quotes, misattributed themes, or missing nuance from summarization can mislead product decisions.
Action: treat model outputs as draft artifacts. Verify high-impact claims with source quotes and subject-matter reviewers before reporting.
For policy and health analysts
Risk: hallucinated clinical or legal claims can produce harmful recommendations.
Action: enforce retrieval-grounded answers, lock model responses to cited sources, and require expert sign‑off for any action-oriented recommendation. (Note: this blog is research-focused and not clinical advice.)
For ops & data teams
Risk: prompt injection from untrusted inputs (emails, scraped pages) can exfiltrate or corrupt data.
Action: implement strict data classification, input sanitization, and output filters; log and monitor for anomalous outputs.
Do more, faster with Evidano
Problem: noisy transcripts and multilingual inputs
Solution: Evidano provides integrated transcription and translation with custom dictionaries and PII redaction, so you ingest cleaned, standardized text before analysis.
Problem: hallucinated summaries and false themes
Solution: Use Evidano's retrieval-augmented workflows to bind summaries to source excerpts, run co-occurrence checks, and produce clickable verifiable quotes for every theme.
Problem: prompt-injection from scraped or third-party text
Solution: Evidano supports input tagging and classification, system-prompt controls, and output guardrails. Route untrusted inputs through stricter filters and require human approval on sensitive outputs.
Problem: inconsistent coding across analysts
Solution: Import or create a codebook, then apply AI-assisted coding and hierarchical code→subcode visualizations for fast reconciliation and inter-rater checks.
Security & compliance
Solution: Evidano encrypts data end-to-end and does not use customer data to train third-party models, enabling audit-ready analyses for sensitive research.
Checklist: 8-step workflow to guard qualitative insights
Run this as your standard pipeline for studies using LLMs:
- 1) Classify inputs by trust level (trusted interview transcript vs scraped forum).
- 2) Preprocess: transcribe (with PII redaction), normalize, and apply custom dictionaries.
- 3) Retrieval setup: attach source docs and a citations index for RAG before any summarization.
- 4) System prompts & guardrails: explicitly mark data vs. instruction; enforce output format templates.
- 5) Multi‑check: ensemble or multimodel cross-checks on critical claims; flag disagreements.
- 6) Human-in-the-loop: require SME review on high‑impact themes and any action recommendations.
- 7) Monitoring: log queries/outputs for anomalies that indicate prompt-injection or jailbreak attempts.
- 8) Export & audit: generate verifiable outputs (clickable quotes, provenance) for stakeholders.
Most steps map directly to features in Evidano, start a pilot on www.evidano.com to test RAG + codebook + review workflows with a small dataset.
FAQ: common questions from qualitative teams
How do I reduce hallucinations in summaries?
Bind summaries to retrieved source passages (RAG), require confidence thresholds, and surface the original quote beside every synthesized claim.
Can models be trained to ignore injected instructions?
Partially, system prompts and training with explicit markers help, but the ACM authors emphasize this remains an open, probabilistic challenge; guardrails and monitoring are required.
Is human review mandatory?
For any decision with material risk (policy, clinical, legal, major product changes), yes. Automate the draft stage, but gate the final recommendation.
Wrapping up: next moves
LLM risks are real but manageable if you design your qualitative pipeline with verification, provenance, and human checks baked in.
- Start small: run an Evidano pilot on one study to validate RAG + codebook + human-review checkpoints.
- Document your guardrails and export auditable reports so stakeholders can trace every claim to source text.
- Iterate: use monitoring logs to discover new jailbreak patterns and update filters and prompts.
Ready to harden your qual research workflow? Try a pilot on www.evidano.com and convert transcripts and survey text into verifiable, theme-driven insights with built-in provenance and security.
Keep reading
- Commentary on NewsTwo Definitions: Climate Change Acceptance for UndergradsHow a PLoS One Delphi study (Aug 25, 2026) defined climate change acceptance for undergraduate science students, and how AI-enabled qualitative analysis applies it.
- Commentary on NewsResearcher-in-the-loop: AI-enabled UX researchHow the researcher-in-the-loop model governs AI-enabled UX research. Learn practical governance, stats from the August 2026 piece, and how Evidano supports this workflow.
- Commentary on NewsResearcher-in-the-Loop: Governance for AI UX ResearchGovern AI in qualitative UX research with the researcher-in-the-loop model from Jennifer L. Bowie (Aug 25, 2026): practical rules, risks, and tool mappings.
