Confidence is the wrong feature
The impressive demo is the one where you ask a hard question and get a fluent answer. It is also the one that should worry you, because fluency and accuracy are produced by different mechanisms and only one of them is visible.
In a consumer setting a wrong answer is an inconvenience. In a business setting somebody repeats it in a meeting. The cost is not the error; it is that nobody can tell which of the previous hundred answers were also wrong, so all of them become suspect at once.
A wrong answer with a citation is a fixable bug
This is the whole argument for citation, and it is not really about trust. It is about repair.
An uncited wrong answer is a mystery. You cannot tell whether the model misunderstood, the data was stale, or it invented something plausible. There is nothing to fix, so nothing gets fixed. A cited wrong answer points at a specific record or a specific article, and that is a defect with an owner and a resolution. One wrong article, corrected once, for everybody.
Which means it has to refuse
If every claim must carry a source, the assistant will meet questions it cannot answer. It has to say so.
That feels like a downgrade and it is the opposite. A refusal costs a handover to a person. A confident invention costs a policy commitment you did not make, discovered by a customer. We would rather answer fewer questions and have the answers hold.
The enforcement matters as much as the intent. Asking a model nicely not to guess works until somebody is persistent. So the rule sits outside the model: an answer without a source is not sent, whatever the model produced.
Where we deliberately stop
The assistant will not commit to a refund, a credit, a date or an exception. Not because it could not produce a sentence about one, but because those are decisions rather than facts, and a decision needs somebody accountable for it.
It also does not learn from customer conversations on its own. A system that quietly retrains on what it has been told is one nobody can audit, and we would rather have a knowledge base somebody owns than a model that has drifted somewhere interesting.
None of this is clever. It is a set of refusals and a citation requirement, which is a dull thing to put in a product announcement. It is also the difference between a tool people rely on and a demo people enjoy.