> AI Policy
Xploitwire's articles are drafted by AI. We think readers deserve to know exactly what that means in practice, rather than a vague "AI-assisted" disclaimer — so here's the full picture.
What AI does
An AI model (currently Google's Gemini) rewrites source reporting — RSS coverage from established security/tech outlets, or structured vulnerability data from CISA, NVD, and GitHub Security Advisories — into an original Xploitwire article: headline, narrative structure, framing, and analysis. It also selects a category, tags, and a search query for a stock photo.
What's automatically checked
Before publication, every draft passes through an automated fact-check step that compares the article against its source text and flags any claim, quote, number, or link that isn't traceable back to it. Findings are categorized by severity — a fabricated fact, quote, or number blocks publication outright; lower-severity issues (like a date reference that isn't precisely grounded) can also block publication depending on the check. Numeric claims (CVE IDs, dollar figures, percentages) are additionally verified by a deterministic check, not just the AI's own judgment.
What isn't done
Articles are not individually reviewed by a human editor before they go live — the pipeline publishes automatically once a draft passes its automated checks. We don't currently contact companies for comment before publishing, and legal review isn't performed on every story before publication. Stories involving named individuals or accusations of wrongdoing are flagged internally for a human to follow up on comment/legal review, but that follow-up happens after publication, not before.
Confidence labeling
Every article carries a confidence label — Confirmed, Developing, or Unverified — derived automatically from how the story is sourced (an official advisory or vendor statement, versus a single outlet's as-yet-uncorroborated report). See our Editorial Policy for exactly how each label is determined.
Why we do it this way
Full automation lets us cover a much broader range of stories than a small team could manually report. We think that's only defensible if we're honest about the tradeoff — hence labeling every story's confidence level, disclosing AI's role plainly, and logging corrections publicly rather than quietly editing mistakes away.