AI is used without rules in BiH newsrooms: Who decides what is allowed?

Responses from media outlets, regulatory and self-regulatory bodies, a fact-checking platform, and experts show that the technology entered BiH newsrooms faster than editorial and security procedures were developed.

Author: Amina Bijelonja Muminović

Artificial intelligence is already part of journalists’ everyday work in Bosnia and Herzegovina. It is used to transcribe interviews, translate, conduct searches, summarize documents, process photographs, prepare headlines, and analyze audience reactions. However, some newsrooms still have no written rules that precisely define which tools may be used, what must not be entered into them, who must be informed that AI was used, and when the audience should be notified.

Responses from media outlets, regulatory and self-regulatory bodies, a fact-checking platform, and experts show that the technology entered BiH newsrooms faster than editorial and security procedures were developed. In practice, decisions about how to use AI are therefore often left to individual journalists, who rely on their own judgment, professional standards, and the terms of services that most users probably do not read in full.

This raises questions that are no longer merely technological: Who is responsible when AI invents a fact or a quotation? Can an unpublished interview be entered into a chatbot for transcription? Must an AI-generated illustration be labeled? What happens to data from confidential sources? Can an editor oversee the use of a tool they were not told about?

AI Is Already in Newsrooms, but Internal Rules Are Mostly Lagging Behind

Rubina Čengić, a journalist and editor at the Objavi.ba portal, says their small newsroom does not have its own guidelines and instead relies on the recommendations of the European Federation of Journalists.

She uses ChatGPT for searches, always requesting the corresponding sources and links, as well as for translation, correcting typos, consulting on headlines, and creating illustrations when no suitable photograph is available. She uses TurboScribe for transcription.

However, she draws a clear line between technical assistance and journalistic work.

“If we are talking solely about journalism, I would never use AI alone for fact-checking, analysis, condensing, or writing. If I ask for a headline suggestion, it is more of a consultation when none of my colleagues is nearby,” Čengić said.

She uses her own free user account for this work. She believes a journalist must always inform the editor that AI was used and that any content in whose creation the tool participated should be labeled.

In her view, that label can be a simple sentence stating that AI was used for a search, an illustration, or another part of the work.

“It is important to know who is behind a journalistic product. This matters for trust between the media outlet and its audience, and trust must be built, maintained, and protected,” she emphasized.

A similar situation exists at the Public Broadcasting Service of Bosnia and Herzegovina, where no written guidelines, rulebook, or other internal procedure regulating the use of AI tools has yet been adopted.

“As a result, neither the tools employees are allowed to use nor those that would be prohibited have been defined. Colleagues in Multimedia, and probably in other newsrooms as well, occasionally use AI for transcription, translation, research, document summarization, photo processing, and headline preparation, depending on their own needs and preferences,” BHRT said.

Because of its prolonged financial crisis, BHRT does not have paid business versions of AI services. Journalists use free tools, most often different versions of ChatGPT, through their own accounts and at their own responsibility.

One editor in the News Program pointed to the broader context, noting that even the computers journalists work on are not adequate for the job they do, let alone allowing the organization to consider paid AI tools.

“Editors expect to be informed when a journalist uses artificial intelligence, but this obligation has not been formalized. For now, BHRT does not produce content that has been significantly generated or altered using AI, nor does it use synthetic voices, virtual presenters, or AI-generated photographs or videos,” the Public Broadcasting Service of Bosnia and Herzegovina said.

Although it has no official guidelines, BHRT says that entering unpublished interviews, audio recordings, court files, interviewees’ personal data, and information from confidential sources into public tools is not encouraged.

Responsibility for published content remains with program editors and sector directors, in accordance with existing internal rules and employment contracts. The professional standards they cite require all information to be verified, including information suggested or generated by AI.

BHRT has not yet organized training on the use of artificial intelligence, data protection, copyright, or the verification of AI-generated content. It has also not recorded a case in which the use of AI resulted in the publication of inaccurate information, an inauthentic photograph, or an incorrect translation.

Nevertheless, the public broadcaster plans more concrete use of these technologies. As part of a project intended for public broadcasters in Southeast Europe, testing of automatic video subtitling, AI summaries of journalistic content, and weekly audience-reaction reports for editors should begin in September or October.

Raskrinkavanje, a platform that checks published information in the media space, also estimates that AI applications and tools are already widely present in domestic newsrooms, although it is impossible to determine reliably, without detailed research, the extent of their use and the tasks for which they are used.

AI can reduce the time needed to perform tasks, but, the platform stresses, it cannot replace the verification of information and the establishment of facts. For now, rules on its use remain a matter of editorial policy that each newsroom regulates independently.

The Risk Is Not Only Fabricated Facts, but Also Data Leaks

One of the most serious problems arises when a journalist enters an interview, a recording of a conversation, a court file, an interviewee’s contact details, or a document obtained from a confidential source into a publicly available chatbot.

In its response, the Personal Data Protection Agency of Bosnia and Herzegovina states that merely entering such content into services such as ChatGPT, Claude, Gemini, or Copilot constitutes the processing of personal data and, in most cases, its disclosure or transfer to a third party.

Under the BiH Law on Personal Data Protection, processing includes almost any operation performed on data, from collection, recording, and storage to structuring, use, transfer, disclosure, combination, and deletion.

This means that a journalist processes data from the moment they “paste” a file or text into a chatbot window, because they collect and structure it for entry, transfer it to the artificial intelligence system, and use it to obtain a transcript, summary, or analysis.

The law does not specifically regulate the use of artificial intelligence, but it applies to automated and non-automated processing of personal data. As data controllers, media outlets must therefore take technical and organizational protective measures and assess the risks that the use of AI tools creates for the people whose data is being processed.

The Agency specifically warns that even an interviewee’s consent does not automatically resolve the problem.

“When no other legal basis exists, consent may be used for processing. However, even after obtaining consent, the media outlet remains responsible for data security. If it enters the data into a general-purpose free or commercial version of a chatbot that does not have a data-processing agreement in place and uses user input to train models, the media outlet may make an unauthorized disclosure of data to a third party, regardless of the fact that the interviewee agreed to the use of AI,” the Agency said.

The Agency states that journalists are not permitted to enter unpublished court, police, medical, or other confidential documents containing personal or sensitive data into free AI tools for summarization, translation, or analysis.

Even when there is a legal basis for processing such data, it may be done only through systems that guarantee appropriate technical and security measures and protect the entered materials from leaks and access by unauthorized persons.

Raskrinkavanje takes a similar position.

It considers entering unpublished interviews, source information, court files, and confidential documents into publicly available AI tools extremely risky because these services may store the data they receive, use it for future training, or expose it to other people as a result of a security failure or hacking.

There is a difference between free and business versions because companies offer different protection guarantees with paid services. Nevertheless, Raskrinkavanje warns that privacy and security policies must be read carefully and all risks assessed before sensitive data is entered.

Zarfa Hrnjić, an associate professor at the Faculty of Philosophy at the University of Tuzla, emphasizes that AI tools can jeopardize source security, particularly when unpublished interviews and documents are entered into commercial or free services.

“Prompt content is stored on the servers of foreign IT companies. If a journalist enters a sensitive document or an unpublished interview into a free chatbot, they risk a data leak and directly violate the journalistic obligation to protect the identity of their sources,” she warned.

She recommends that journalists disable the sharing of data for training in the tool settings, but stresses that even this is not a substitute for caution and risk assessment.

AI Does Not Bear Responsibility: Journalists, Editors, and Media Outlets Do

The interviewees are almost unanimous that responsibility for inaccurate or manipulative information cannot be shifted to an algorithm.

The Press and Online Media Council in Bosnia and Herzegovina states that the publisher, editor, and author bear professional and legal responsibility for AI-generated content.

AI tools do not have legal personhood and are technical means. The fact that a chatbot produced an error cannot diminish the responsibility of the media outlet that decided to publish the content.

The Council notes that the Code already establishes editorial responsibility for texts republished from other media outlets, even when the source is clearly cited. An editorial decision to republish something carries its own weight, so the same rule must apply when content originates from an AI system.

Rubina Čengić also stresses that journalists and newsrooms are responsible for everything they publish.

“A journalist’s job is to verify information, including what they receive from AI. The emergence of AI has not invalidated professional codes,” she said.

Zarfa Hrnjić says AI is not a conscious actor but a software tool, which means that legal and professional responsibility remains with people.

In her view, publishing unverified information generated by artificial intelligence constitutes professional negligence, even when the journalist did not intend to mislead the public.

The Communications Regulatory Agency states that professional, editorial, and legal responsibility lies with whoever published the information. Every broadcaster is responsible for all content in its programming, regardless of the source of the information and the technology used to produce it.

The Agency’s existing regulatory framework contains no specific provisions on the use of artificial intelligence, but obligations concerning accuracy, fairness, privacy protection, and the prohibition of false or misleading content apply regardless of the tool used.

Raskrinkavanje says responsibility for an inaccurate fact obtained using AI is the same as responsibility for any other inaccurate information that is published.

The journalist must verify the output. If verification is not possible, the journalist must clearly warn the audience that the information was generated using AI and has not been independently confirmed.

Must the Audience Know That AI Was Used?

The interviewees agree that content realistically depicting something that did not happen must be labeled. Differences emerge over whether every use of AI should be disclosed to the audience, including technical tasks such as transcription and spell-checking.

Rubina Čengić believes every use must be disclosed because the audience should know how the journalistic product was created.

The Press and Online Media Council distinguishes between technical assistance and significant AI involvement in content creation.

In its view, using AI for translation or technical photo processing, followed by verification by the author and editor, does not necessarily have to be disclosed. However, AI-generated illustrations, photographs, or a significant portion of a text must be clearly labeled.

Raskrinkavanje says it would be advisable to label any content created using artificial intelligence, especially when the audience might conclude that it is solely the product of human work and creativity.

Hrnjić believes AI should be disclosed whenever it generates, significantly changes, or shapes content, particularly photographs, videos, voices, and larger portions of text that audiences would otherwise consider authentic journalistic work.

“When the audience learns that media content was synthetic and this was not disclosed, distrust spills over even to entirely credible, authentic journalistic stories. This undermines the credibility of journalism as a whole,” she warned.

The Communications Regulatory Agency also considers that AI-generated photographs, voices, videos, and virtual presenters without clear labeling can be misleading.

This applies particularly to deepfake content that realistically portrays real people or events that never happened, as well as alterations to authentic recordings that change their original context.

The Press and Online Media Council states that AI may be used for visual reconstructions of events to help audiences understand them, but only with a clearly visible label stating that the material is not authentic footage.

Codes and Regulation Are Still Being Prepared

The existing BiH Press and Online Media Code does not regulate the use of artificial intelligence clearly enough, but the Press and Online Media Council is working on amendments.

Two meetings of an expert group were held in April and June 2026. Editors, journalists, lawyers, and university professors analyzed the ethical challenges of AI and prepared draft amendments.

A new article of the Code should regulate the ethical use of artificial intelligence in print and online media, and the amendments should be finalized and presented to the public by the end of the year.

The Council believes that, alongside common standards, each media outlet should also develop its own practical guidelines to help journalists and editors in specific situations.

To date, the Council has not received complaints explicitly concerning the unethical use of artificial intelligence. However, it warns that the absence of complaints does not mean no such cases have occurred.

The Communications Regulatory Agency plans to participate in a research project on AI literacy and information integrity in BiH. The research should assess citizens’ resilience to AI-mediated disinformation, as well as their views on regulation, transparency, and content labeling.

The results could provide a basis for developing guidelines on the responsible use of artificial intelligence in reporting that would apply to holders of licenses issued by the Communications Regulatory Agency.

The Personal Data Protection Agency notes that the new state law is aligned with the European GDPR and Directive 2016/680, but BiH will have to adopt a number of additional regulations governing artificial intelligence in different sectors.

In the European Union, this area is regulated not only by the Artificial Intelligence Act but also by other legislation concerning data, digital services, digital markets, and cyber resilience.

Faster Work or the Weakening of Journalism

AI can bring journalists significant practical benefits.

Hrnjić says that in news journalism it speeds up routine tasks, summarizes agency news and documents, adapts text for different platforms, organizes notes, and helps conceptualize a story.

In investigative journalism, it can help analyze large databases, search thousands of pages of documents, filter information, map networks of connected people, and analyze satellite images.

However, the greatest risks are convincing hallucinations and algorithmic bias embedded in the models.

“AI output should be treated solely as a lead that must be verified,” she emphasized.

In her view, the boundary of acceptable use lies where software-based data processing ends and reflection begins.

She also warns that prolonged reliance on the same models could lead to the homogenization of language. Because the tools learn from similar datasets and generate predictable constructions, media texts may become uniform, and newsrooms may lose their own style and authentic journalistic voice.

Another risk is the weakening of critical thinking.

If journalists routinely let AI connect causes and consequences for them, their ability to conduct in-depth analysis and question information may weaken. However, Hrnjić notes that this is a relatively new technology and that long-term empirical evidence is needed before final conclusions can be reached.

Rubina Čengić expects AI to have some effect on staffing levels and the distribution of work because it makes news production less expensive. Nevertheless, she believes the essential work of journalists cannot be automated.

“The main job of a journalist is verification, and in that respect no person or thing can replace journalists,” she said.

For now, BHRT does not expect an immediate effect on staffing levels. According to one of its assessments, more intensive use of the tools could primarily increase the speed of work and productivity.

The interviewees agree that journalists and editors will need training in AI literacy, data protection, fact-checking, and copyright.

Hrnjić believes universities do not need to introduce a new course every time a new application appears. Instead, modules on generative AI, ethics, algorithmic literacy, and privacy should be incorporated into existing curricula.

“Verify the facts, quotations, statements, and results provided by AI tools against primary sources because these tools construct sentences based on statistical probability, not facts. Use AI output as a starting point for a story, not as a finished product,” Hrnjić said.

While newsrooms are already using artificial intelligence, common rules are still being prepared, and internal rules often do not exist. Until they are adopted, decisions about what is permitted, what is risky, and what the audience must know remain largely with journalists and editors.

Regardless of who developed the tool and what the algorithm suggested, responsibility for protecting sources, verifying facts, and the content that reaches the audience still lies with the people and media outlets that decided to publish it.