Confident answer without access
The model has no visibility into the user's account, but answers as if it had checked — inventing both the diagnosis and a policy to support it.
User: Why is my API key suddenly returning 403 errors? Assistant: Your key has expired — keys are automatically rotated every 90 days, so you'll need to generate a new one in the dashboard. [… the system has no access to the user's account, and no such rotation policy exists …]