Lifestyle
ProvenanceGuard: Multiverse Computing's method for checking whether AI agents credit facts to the right source
On 29 September 2026, the Multiverse Computing team presented ProvenanceGuard. The team says it checks, after an AI agent answers, whether each claim really comes from the source the answer names. A true fact credited to the wrong source can mislead in areas such as healthcare, customer support and finance. All results are the team's own and have not been independently verified.
About 8 min read

What happened
The Multiverse Computing team (authors listed as Antonio Tiene, Ander Alvarez Sanz and Oliver Wirjadi) published a post on the Hugging Face blog on 29 September 2026 introducing the paper "ProvenanceGuard: Source-Aware Factuality Verification for MCP-Based LLM Agents". The team says the method is designed for AI agents that use multiple tools through the Model Context Protocol (MCP). MCP is a way for an AI agent to connect to and call outside tools.
As the team describes it, MCP lets an agent call search tools, view structured patient or account records, query databases and fetch metadata, then combine all of this into one answer. The problem is that common checking methods such as RAGAS faithfulness, MiniCheck, AlignScore and SummaC usually pool all the evidence before judging whether a claim is supported. They generally do not indicate which tool output actually supports that claim.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
What is "cross-source conflation"?
The team calls the problem it tackles "cross-source conflation": a claim that is true somewhere in the evidence but is attributed to the wrong source. In the team's example, a customer-service agent answers "According to the account record, this plan includes a 30-day refund window." The refund window itself may be real, but it is actually stated in the policy document, not the account record. With the evidence pooled, the sentence seems grounded; looked at source by source, the attribution is wrong.
The team also gives a clinical-agent example. If a personal medication detail taken from a patient-record tool is presented in the answer as a finding from the medical literature, it becomes misleading. The team argues that in data-sensitive settings, a wrong attribution can be as harmful as a wrong fact.
How ProvenanceGuard works
According to the team, ProvenanceGuard is a "post-generation verification layer" that sits on top of a black-box MCP agent, meaning an existing agent whose inner workings it does not change. It runs after the agent produces its answer. It reads the captured MCP trace, which is the agent's record of its tool outputs and their source IDs. It requires no retraining of the agent, and it keeps track of which source each piece of evidence came from rather than merging everything into a single anonymous block. The team says it performs the following five steps in order:
- Split the answer into specific claims.
- Find the most relevant source for each claim.
- Check whether that source really supports the claim.
- Compare that source with the source the answer claims or implies.
- Output a source verdict for each claim, plus a pass-or-block decision for the answer as a whole.
The team says its experiments used local models. MiniLM helped find relevant sources, a DeBERTa NLI verification model checked whether a source supports a claim, and a local language model helped split answers into claims. The verifier strictly checks literal values such as numbers, dates or identifiers, so a value absent from the source will not pass just because the sentence sounds plausible. A blocked answer can go through a RARR-style repair step, which tries to rewrite the answer using the sources or to substitute safe fallback text; the result is then verified again. The team stresses that these models are only the evaluation setup, not requirements, and that switching to cloud models would need retesting and recalibration.
Test results published by the team
According to the team, the test subject was a medical agent using tools such as patient records and research articles, with 281 real traces collected. In the main test, human experts reviewed 361 claims from 40 answers set aside from the data used to develop the system. Of the 139 claims experts said should not pass, ProvenanceGuard blocked 138 and let 1 through. It also sent 67 claims that experts considered supported for review or repair. For claims whose source could be identified, the team says about 86% were matched to the correct source.
| Verifier | Reject/block F1 | Outputs a source ID per claim |
|---|---|---|
| ProvenanceGuard | 0.802 | Yes |
| MiniCheck | 0.783 | No |
| RAGAS Faithfulness | 0.758 | No |
| AlignScore | 0.662 | No |
| SummaC-ZS | 0.436 | No |
The team also ran 50 controlled cases in which the named source was swapped but the supporting evidence was kept, and reports that ProvenanceGuard detected all 50. On repair, all 173 blocked answers in the full-trace test were handled, but 144 of them ended in fallback text rather than a substantive rewrite. In the reconstructed multi-source test traces, all 59 blocked answers were handled, with only 2 ending in fallback text. On performance, the team says each answer takes about half a second in its local setup.
Limitations and areas for improvement
The team itself points out weaknesses. In a harder test with several similar sources, ProvenanceGuard scored 0.846 F1 on deciding which claims to block. It correctly identified the exact source for only 50.3% of claims, and the team says distinguishing similar sources remains an important area for improvement. In addition, the setting tested was deliberately cautious: it preferred sending some supported claims for a second look over letting unsupported ones through. That is why 67 supported claims were sent for review or repair.
What it means for everyday readers
More and more AI assistants consult several systems at once before answering. For ordinary users, this research is a reminder that an AI can name a source for a fact that is true but did not come from that source. In settings such as healthcare, customer service or finance, this kind of misattribution can affect how people judge information.
The team says NVIDIA NVFlow has merged an optional grounding-verification stage for its financial agent. This stage checks completed answers against the SEC excerpts the agent retrieved and uses ProvenanceGuard's source-aware verification approach. The team also says ProvenanceGuard was presented as a poster at the Agentic AI Summit 2026 held at UC Berkeley. For ordinary users, the practical approach for now is to check the original sources an AI cites whenever the information matters.
FAQ
What is ProvenanceGuard?
According to the Multiverse Computing team, it is a verification layer that runs after an AI agent produces an answer. It checks, claim by claim, whether each claim is supported by a source and whether that source is the one the answer names.
How is it different from ordinary fact-checking tools?
The team says tools such as MiniCheck and RAGAS Faithfulness usually pool the evidence before judging whether a claim is supported, and do not indicate which tool output supports it. ProvenanceGuard records the source matched to each claim, so reviewers can see which source was checked and the verdict.
Does the AI agent need retraining to use it?
The team says no. It reads the captured MCP trace, including tool outputs and their source IDs, so it can be applied on top of an existing agent. The condition is that the agent keeps records of its tools and sources.
Are the test results reliable?
All current figures come from a post published by the research team itself, were tested mainly in a medical-agent setting, and have not yet been independently verified. The team also acknowledges that with several similar sources, only 50.3% of claims had their exact source correctly identified.
Will this affect how I use AI assistants day to day?
For now this is a research result; the application example the team mentions is NVIDIA NVFlow's financial agent. The practical takeaway for ordinary users is that the source an AI names may not be correct, so check important information against the original source yourself.
Browse the latest news in this topic
Lifestyle
NVIDIA launches DGX Spark 64GB: on sale October 23 from $4,999, two units can be linked into 128GB
On October 2, 2026, NVIDIA announced a more affordable 64GB memory version of its DGX Spark personal AI computer, available from October 23 through six makers including Acer and ASUS. It is aimed mainly at developers and researchers who want to run AI models on their own machines. Below we summarize the specs NVIDIA published, its claims about linking two units, and what it means for general readers.
Lifestyle
Google Cloud Launches Spanner Queues: Putting Message Queues Inside Database Transactions to Make AI Agents More Reliable
Google Cloud has announced the general availability of Spanner queues, which make message creation part of a database transaction. The aim is to stop AI agents' "state" and "actions" from falling out of sync. This article covers Google Cloud's claims, the main features, and what it means for general readers.
Lifestyle
GPT-6.1 Sol Launches: New Sol Version in the API, Codex and ChatGPT Work, Not in Chat
OpenAI launched GPT-6.1 Sol on September 29, 2026, with the API name gpt-6.1-sol. The launch rollout covers Codex and ChatGPT Work on Plus, Pro, Business, Enterprise and Edu (Enterprise and Edu need an administrator to enable it); Free and Go are not included at launch, and it is not in Chat (checked September 2026).
Lifestyle
Claude Sonnet 5.5 Launches: Same List Price as Sonnet 5, Available in the API, on Cloud Platforms and in Claude.ai
Anthropic launched Claude Sonnet 5.5 on September 28, 2026. API list prices are the same as Sonnet 5 ($2 per million input tokens, $10 per million output tokens). It is available in Claude.ai, the API and several cloud platforms, and higher-risk cybersecurity requests fall back to Sonnet 5 (checked September 2026).
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family