45% of the time, the AI gets the news wrong. Your name's still on it.
An assistant rewrote a grieving family's words, credited the BBC, and nobody at the BBC knew.
When Liam Payne died in October 2024, his family put out a statement. The BBC published it. "We are heartbroken. Liam will forever live in our hearts and we'll remember him for his kind, funny and brave soul."
That December, BBC journalists asked Perplexity about his death. What came back was this: "We are heartbroken. Liam will live forever in our hearts, and we'll always remember him for his kind, loving, and brave soul."
Read those twice. A family chose the word "funny" to describe their dead son. The machine gave them "loving." Nothing here is a scandal. That's the problem. The sentence is warm, plausible, and sourced to the BBC. It just isn't what anybody said.
The reader who read that closed the tab and moved on. They never reached the BBC's site, never saw the paragraph the family wrote, and had no reason to doubt any of it, because the masthead under the answer was one of the most trusted in the world.
Nobody at the BBC knew. There's no log, no notification, no correction queue. The error was entirely generated by Perplexity's LLM. The damage was the BBC's, and it was invisible to them until they went looking.
The extent of the impact
The BBC went looking because that Payne quote turned up in a study they were running on themselves. A hundred news questions, four AI assistants, and forty-five BBC journalists grading the answers in their own subject areas. Half the responses came back with something significant wrong in them, and thirteen percent of the quotes attributed to BBC articles had been altered or weren't in the cited piece at all.
Then the European Broadcasting Union ran the study again at scale. Twenty-two public-service media organizations across eighteen countries and fourteen languages, and more than three thousand AI assistant responses. Each was evaluated by working journalists against accuracy, sourcing, context, and whether opinion was distinguished from fact.
Forty-five percent of the answers had at least one significant problem. Thirty-one percent had sourcing failures: attributions that were missing, misleading, or simply wrong. Twenty percent contained major accuracy problems, including invented detail. Google Gemini was worst by a wide margin, with significant issues in 76% of its responses, most of that a sourcing failure.
?? A wrong fact is a wrong fact. A wrong attribution puts your name on it.
Six in ten American adults now say they read AI search summaries. When Pew watched what people actually did across nearly 69 thousand Google searches, users who saw an AI summary clicked through to a real result 8% of the time, against 15% when no summary appeared. Clicks on the links inside the summary happened in only 1% of visits.
So the AI summary has become the destination. The citation under it is mere decoration. And roughly half the time, the facts the reader is trusting are wrong and, even worse, they're attributed to you.
The risk is beyond your reach
For two years the newsroom conversation about AI has been internal tooling and workflow. About who used the tool and whether it was disclosed. Whether the byline is honest. Whether the guild contract covers it. That work matters and I'm not arguing against any of it.
But, the risk has expanded beyond your immediate reach. You can run the cleanest internal AI policy in the industry, disclose everything, keep a human on every draft, and still have your brand absorb an error rate near fifty percent in a layer you don't own, can't audit, and can't reach.
The break happens downstream of everything an editor touches.
Every content pipeline I've worked on broke at a handoff, in the gap where one team's job ended and nobody's began. The name at the end of the chain paid for it, and the name at the end of the chain was never the one that dropped the ball. This is that, at national scale, running continuously, with no phone number to call.
Audiences already expect the defect. Reuters Institute asked what AI does to the news and got back cheaper, more current, less accurate, and less trustworthy by a net eighteen points. They're right, and they've priced in a flaw they will attribute to you.
Their skepticism doesn't save you, though. The BBC says its own audience research shows that when an AI assistant cites a trusted brand, people are more likely to believe the answer, including when the answer is wrong. That research has never been published, so nobody outside the BBC can check it, and I'd want to see it before building a strategy on it. Though, if it's right, your credibility is what carries the error past the reader's guard.
The fix we try doesn't work yet
The instinct is right and I had it too: sign the work. Publish machine-readable provenance so that when a model represents your reporting, there's a canonical, cryptographically attested original to check it against. Content Credentials, C2PA, the whole architecture the industry has been working toward since 2021.
It doesn't hold up yet. In April a team at UMBC's Cyber Defense Lab, working with Neal Krawetz and an engineer from the National Security Agency, published the first independent security analysis of that architecture. They found the specifications and conforming implementations "fail to achieve both claimed and essential security goals," and named the use case on their way past it: C2PA "should not yet be relied upon for high-stakes uses such as financial disclosures, journalism, or legal evidence."
The obvious objection is that standards move and audits don't. The same authors checked the two releases that have shipped since, and wrote that the current one "does not resolve any of our concerns." I took that apart at length in a separate piece, so I'll leave it at the short version: a camera signed a photograph it had never taken, and the industry's own verification tool called it genuine.
None of which matters much here anyway, because the credentials don't survive the trip. Tim Bray put it plainly: "all the networks strip all the photo metadata." Anthropic, one of the largest implementers, documents that its own marks are removed by "format conversion, re-saving, screenshots, or other means," and that finding a mark proves only that the model touched the file.
There's no cryptographic remedy available to your newsroom this quarter. I'd like to tell you otherwise.
What is still yours
The BBC named the asymmetry in that first study, and it's the cleanest statement of the problem I've read. AI assistants carry a disclaimer about the risk of inaccuracy, and "there is no mechanism for AI applications to correct errors, unlike professional news outlets that acknowledge and correct occasional errors." The distributor gets a disclaimer. You keep the duty to correct, and lose the ability to reach the person who needs correcting.
So you're accountable for a representation of your work that you can't see, can't audit, can't correct, and can't yet prove wrong by signature. Naming that accurately is worth more than a provenance roadmap that won't hold when someone leans on it.
What remains in your control is smaller than anyone wants and more useful than it sounds.
You control whether the thing you published is durable and dated. Whether the URL still resolves in four years. Whether the timestamp is real, the revision history is visible, and the version a reader lands on can be compared against the version a model paraphrased. That's ordinary publishing hygiene, and every bit of it is available to you right now.
You control your correction record. Publicly, permanently, on your own domain, with the original error still readable next to it. That's the one artifact no assistant can manufacture and no platform can strip, and it's the only ground truth you'll have when a summary misquotes you and someone asks which version is real.
All of that decides what's waiting when a reader goes looking for the original, which is the only moment in this whole chain you still get to influence.
The record you keep is the one part of this you own outright. Keep it like evidence, because the morning somebody checks, that's exactly what it is.
More on Trust as Infrastructure
Ten of the Fifteen Books Didn't Exist.
Two newspapers printed a summer reading list that nobody in the chain had actually read.
Testimonials Are Dead. You Just Haven't Noticed Yet.
Social proof broke when the proof got cheap to fake.
The Rebrand is the Tell
Every rebrand quietly admits the last version wasn't real.