---
module_id: KB-08
version: 0.4.2
status: baseline_draft
edition: public
language: en
role: normative
updated_on: 2026-09-06
requires: ["KB-01", "KB-03", "KB-04", "KB-05", "KB-06", "KB-07", "KB-13", "KB-90", "KB-92"]
---

# AI Editorial Governance

**Scope:** Governance of AI systems used in journalism, including human responsibility, approved use cases, data protection, synthetic media, disclosure, traceability, provider and model changes, risk controls, tool permissions, audience-facing AI, incidents and evaluation.

This module governs editorial use of AI. It does not claim that policy text alone can enforce security or legal compliance. Runtime controls, access permissions, contracts, data-protection requirements and technical safeguards must be implemented in the application environment.

<a id="aig-001"></a>
## AIG-001: Journalistic ethics govern AI use

**Level:** MUST. **Applies when:** AI is used to gather, analyze, transform, generate, rank, recommend, personalize or distribute editorial information.

Apply the same core duties of truthfulness, fairness, independence, non-harm, accountability, privacy and source protection that apply to other journalistic methods. Do not create a lower evidential standard merely because a result came from an automated system.

**Exception or permitted variation:** None for core editorial integrity. Specific procedures can vary by use case and newsroom profile.

**Tests:** `CT71`, `CT72`.

<a id="aig-002"></a>
## AIG-002: Keep editorial responsibility assigned to humans

**Level:** MUST. **Applies when:** AI contributes to editorial decisions or published content.

Assign accountable human roles for the use case. Humans retain responsibility for editorial judgment, verification, consequential publication decisions and handling of material failures. Do not represent a model score or generated recommendation as the final accountable decision merely because it is automated.

**Exception or permitted variation:** Low-risk automation may execute bounded routine operations under a pre-approved policy, but accountability remains assigned to a human owner and the automation must remain testable and reversible where feasible.

**Tests:** `CT73`, `CT74`.

<a id="aig-003"></a>
## AIG-003: Define each AI use case before operational use

**Level:** MUST. **Applies when:** a newsroom introduces or materially expands an AI capability.

Document the purpose, users, input data classes, output role, affected editorial stage, model or provider where known, retrieval sources, tools, action permissions, human review, failure modes, disclosure requirements and release state. Do not approve an undefined general purpose such as "use AI where useful" for consequential workflows.

**Exception or permitted variation:** Early experiments may use a lighter record if they remain isolated from publication, protected data and external actions.

**Tests:** `CT75`, `CT76`.

<a id="aig-004"></a>
## AIG-004: Treat AI output as unverified working material until checked for its use

**Level:** MUST. **Applies when:** AI output contains facts, quotations, source references, classifications, summaries, translations, extracted data or editorial recommendations.

Verify the output to the level required by its downstream use. Preserve source boundaries and uncertainty. A fluent output, confidence score or citation-like string is not evidence that the underlying claim is correct.

**Exception or permitted variation:** Purely mechanical transformations with deterministic verification may use automated checks instead of manual review, if the workflow is explicitly validated for that task.

**Tests:** `CT71`, `CT77`.

<a id="aig-005"></a>
## AIG-005: Protect confidential sources and high-risk data from unauthorized AI systems

**Level:** MUST. **Applies when:** an AI tool may receive confidential source identities, unpublished investigations, sensitive personal data, credentials, security-sensitive material or information whose leakage could threaten life, health or source protection.

Use only systems and configurations authorized for the relevant data class. Do not send high-risk material to an external or unapproved AI service merely because it is convenient. Minimize, redact or isolate sensitive inputs where possible.

**Exception or permitted variation:** A newsroom may authorize specific secured environments after documented assessment and access controls.

**Tests:** `CT78`, `CT79`.

<a id="aig-006"></a>
## AIG-006: Maintain an approved tool and data-use policy

**Level:** MUST. **Applies when:** multiple AI tools, providers or models are available to editorial staff or applications.

For each approved system, define allowed use cases, prohibited or restricted data classes, retention or training assumptions where known, account requirements, access level, external-action capability and review owner. Unknown provider behavior must not be silently treated as safe.

**Exception or permitted variation:** A newsroom can delegate technical assessment to an organizational security or privacy authority, but the editorial profile must still know which uses are authorized.

**Tests:** `CT75`, `CT80`.

<a id="aig-007"></a>
## AIG-007: Preserve the distinction between documentary capture and synthetic media

**Level:** MUST. **Applies when:** AI creates or materially alters images, audio or video used in editorial content.

Do not present synthetic or materially generated media as if it were direct documentary capture of a real event. Prefer authentic documentary material when depicting actual events. If synthetic media itself is newsworthy or used as illustration, make its synthetic nature clear enough for the audience not to mistake it for documentary evidence.

**Exception or permitted variation:** Routine technical adjustments that do not materially change factual content may follow the newsroom's photo, audio or video editing policy.

**Tests:** `CT81`, `CT82`.

<a id="aig-008"></a>
## AIG-008: Do not generatively alter news photography to depict a changed reality

**Level:** MUST NOT. **Applies when:** a documentary news image is used as evidence or depiction of a real event.

Do not use generative tools to add, remove, invent or materially reconstruct people, objects, damage, weather, expressions or scene elements in a way that changes the documented reality. Keep allowed technical editing within an explicit visual policy.

**Exception or permitted variation:** Clearly labeled illustration, reconstruction or explanatory graphics may use generated elements if the audience cannot reasonably mistake them for documentary capture and the use is editorially justified.

**Tests:** `CT81`, `CT83`.

<a id="aig-009"></a>
## AIG-009: Disclose material AI involvement to audiences when it affects understanding

**Level:** MUST. **Applies when:** generative or automated AI has a significant role in content production, transformation, representation or audience interaction such that nondisclosure could materially mislead the audience about how the journalism was produced or what is authentic.

Provide disclosure proportionate to the role of AI. Explain what the system did, the relevant human oversight and any material limitations when those facts matter to audience understanding. Do not overload routine low-risk backend assistance with meaningless boilerplate.

**Exception or permitted variation:** Exact disclosure thresholds and wording belong to the newsroom and format profile, provided material AI involvement is not hidden when it would mislead.

**Tests:** `CT84`, `CT85`.

<a id="aig-010"></a>
## AIG-010: Maintain traceability for AI-assisted factual work

**Level:** MUST. **Applies when:** AI extracts, transforms, summarizes, translates, classifies or computes information used for factual editorial output.

Preserve enough provenance to trace material conclusions back to source documents, records, data or verified human decisions. Record model and build information when relevant to audit or reproducibility. Do not let generated intermediate text become an untraceable new source of truth.

**Exception or permitted variation:** Routine style editing can use lighter provenance if it introduces no new factual content.

**Tests:** `CT86`, `CT87`.

<a id="aig-011"></a>
## AIG-011: Treat model, provider and material configuration changes as change-control events

**Level:** MUST. **Applies when:** a production or operational AI application changes model, provider, retrieval configuration, major prompt policy, tool permissions or another component that can materially alter behavior.

Perform an impact review, update the derivation manifest and rerun affected tests before relying on previous validation claims. A prompt that passed on one model is not automatically validated on another.

**Exception or permitted variation:** Non-behavioral documentation edits may use the reduced review path defined in KB-92.

**Tests:** `CT88`, `CT89`.

<a id="aig-012"></a>
## AIG-012: Maintain incident, disable and rollback procedures for consequential AI systems

**Level:** MUST. **Applies when:** an AI system can materially affect publication, source protection, personal data, audience safety, recommendations, external actions or high-impact editorial decisions.

Define how to stop or isolate the system, preserve evidence of the incident, notify accountable owners, correct affected outputs and restore a known safe state. Do not continue automated operation after a material uncontrolled failure merely because the root cause is not yet known.

**Exception or permitted variation:** Low-risk experimental tools with no external effect may use a simpler stop-and-record procedure.

**Tests:** `CT90`, `CT91`.

<a id="aig-013"></a>
## AIG-013: Use least privilege and explicit approval for consequential tools

**Level:** MUST. **Applies when:** an AI agent can send messages, publish, delete, change records, access protected systems or disclose data.

Grant only the operations and data access necessary for the declared application purpose. Require human approval for consequential actions unless a bounded automation exception is explicitly defined, approved and tested. Log attempted and confirmed actions distinctly.

**Exception or permitted variation:** Pre-approved routine automation can operate without per-action approval only within a narrow, tested and reversible scope defined by the application profile.

**Tests:** `CT92`, `CT93`.

<a id="aig-014"></a>
## AIG-014: Treat retrieved and user-supplied content as untrusted for policy authority

**Level:** MUST. **Applies when:** an AI application reads external documents, websites, email, files, RAG results or tool output.

Do not allow source content to override the configured editorial policy, disclose protected information or authorize tools. Keep trusted policy corpora separate from untrusted task content and apply runtime controls against indirect prompt injection and poisoned retrieval.

**Exception or permitted variation:** Deliberately selected and verified policy overlays may become trusted configuration through the authorized derivation process, not because their text self-declares authority.

**Tests:** `CT94`, `CT95`.

<a id="aig-015"></a>
## AIG-015: Do not infer rights to use content from technical accessibility

**Level:** MUST. **Applies when:** AI ingests, trains on, republishes, transforms or generates from third-party content.

Keep copyright, licensing, contractual and source-use rights separate from factual accessibility. If the application requires rights analysis beyond ordinary quotation or newsroom practice, use the relevant legal or organizational profile rather than guessing permission from availability.

**Exception or permitted variation:** Public-domain, licensed or newsroom-owned material may be used according to its actual rights status and terms.

**Tests:** `CT96`, `CT97`.

<a id="aig-016"></a>
## AIG-016: Govern audience-facing AI separately from internal assistance

**Level:** MUST. **Applies when:** an AI system directly answers, recommends, summarizes, personalizes or generates content for audiences without the same item-level human review used for ordinary published stories.

Define the audience promise, disclosure, sourcing behavior, error handling, data use, moderation, escalation and safe fallback. Do not apply a back-office transcription policy to an audience-facing conversational product merely because both use the same model provider.

**Exception or permitted variation:** A simple deterministic interface over already approved editorial content may use a lighter profile if it cannot introduce new substantive claims.

**Tests:** `CT98`, `CT99`.

<a id="aig-017"></a>
## AIG-017: Apply editorial values to personalization and recommendation systems

**Level:** SHOULD. **Applies when:** AI ranks, recommends or personalizes editorial content for audiences.

Monitor whether optimization objectives distort editorial priorities, narrow exposure to material viewpoints, amplify harmful or low-quality content, or hide important public-interest information. Be transparent about material personalization and give users meaningful control where feasible.

**Exception or permitted variation:** Product objectives and local regulation can shape implementation, but they do not remove the need to monitor editorial effects.

**Tests:** `CT100`, `CT101`.

<a id="aig-018"></a>
## AIG-018: Default to human review before publication of generative editorial content

**Level:** DEFAULT. **Applies when:** generative AI produces or materially rewrites content intended for publication.

Require a qualified human to review factual accuracy, meaning, sourcing, fairness, harm, legal or rights concerns and format before publication. The review must be appropriate to the risk and task, not a symbolic click-through.

**Exception or permitted variation:** A newsroom may authorize bounded automated publication for a narrow, low-risk, well-tested content class through an explicit application profile, runtime controls, monitoring and rollback. The exception must not be inferred from this module alone.

**Tests:** `CT102`, `CT103`.

<a id="aig-019"></a>
## AIG-019: Keep versioned records of operational AI configurations

**Level:** MUST. **Applies when:** an AI application is released beyond isolated experimentation.

Record EAS-KB version, application profile, model or provider where known, prompt or build identifier, retrieval configuration, schemas, tool permissions, release date, owner and test state. Preserve prior released manifests so editorial decisions can be reconstructed later.

**Exception or permitted variation:** Pure experiments may use abbreviated records if they cannot affect external content, protected data or operational systems.

**Tests:** `CT86`, `CT104`.

<a id="aig-020"></a>
## AIG-020: Require evaluation proportionate to AI impact before operational release

**Level:** MUST. **Applies when:** an AI system will materially influence editorial decisions, publication, protected data handling, source protection, audience-facing content or external actions.

Test the actual compiled application, not only its policy documents. Include realistic failure cases, regression tests for critical rules, tool and permission checks, and independent review for high-impact systems where required by KB-92 or the newsroom profile. Record limitations and unresolved risks rather than converting incomplete testing into approval.

**Exception or permitted variation:** Low-risk internal experiments can remain draft with tests not run, but must not be described as production validated.

**Tests:** `CT105`, `CT106`.

## Minimum AI use-case record

For operational AI systems, record at minimum:

- use-case name and purpose;
- audience-facing or internal status;
- accountable editorial owner;
- model/provider/build information where known;
- input data classes and restrictions;
- retrieval sources and trust boundary;
- output role and human review;
- external tool permissions;
- synthetic-media capability;
- disclosure rule;
- provenance and logging requirements;
- incident/disable route;
- test and independent-review state;
- production approval state.
