Paper deep dive
When Not to Automate: A Formal Protocol for Human Preservation in AI-Optimized Organizations
Jose Manuel de la Chica Rodriguez, Jairo Rodriguez Arias, Spyridon Chouliaras
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 92%
Last extracted: 7/20/2026, 4:01:04 AM
Summary
The paper introduces PHP-AIO (Protocol for Human Preservation in AI-Optimized Organizations), a five-gate sequential decision protocol designed to quantify unpriced systemic risks in automation decisions. It addresses four risk categories: Tacit Knowledge Erosion (TKE), Resilience Reduction (RR), Regulatory Exposure (RE), and Socio-Institutional Capital Degradation (SCD). The protocol produces auditable outcomes (automate, augment, hybrid, preserve) and includes a composite score check and an 'automation-debt' measure to prevent long-term organizational brittleness. Applied to financial services, it demonstrates robustness against standard cost-benefit analyses that would uniformly automate.
Entities (9)
Relation Signals (10)
PHP-AIO → addressesrisk → Resilience Reduction
confidence 95% · PHP-AIO... quantifies these unpriced systemic risks... Resilience Reduction (RR)
PHP-AIO → addressesrisk → Regulatory Exposure
confidence 95% · PHP-AIO... quantifies these unpriced systemic risks... Regulatory Exposure (RE)
PHP-AIO → addressesrisk → Socio-Institutional Capital Degradation
confidence 95% · PHP-AIO... quantifies these unpriced systemic risks... Socio-Institutional Capital Degradation (SCD)
PHP-AIO → addressesrisk → Tacit Knowledge Erosion
confidence 95% · PHP-AIO is a five-gate sequential decision protocol... quantifies these unpriced systemic risks... Tacit Knowledge Erosion (TKE)
Automation Debt → neutralizedby → human-in-the-loop anchor
confidence 92% · its warning is neutralised only by a regulator-mandated human-in-the-loop anchor
Santander AI Lab → developed → PHP-AIO
confidence 90% · Santander AI Lab (July 2026)... PHP-AIO... elicited through internal Santander AI Lab consensus
PHP-AIO → producesoutcome → hybrid
confidence 90% · PHP-AIO produces distinct outcomes -- automate, augment, hybrid, and preserve
PHP-AIO → producesoutcome → augment
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Standard automation ROI misses four categories of systemic risk -- tacit knowledge erosion, resilience reduction, regulatory exposure, and socio-institutional capital degradation -- that affect long-term organizational performance. PHP-AIO (Protocol for Human Preservation in AI-Optimized Organizations) is a five-gate sequential decision protocol with a final composite check that quantifies these unpriced systemic risks at the role level and produces auditable automation decisions. A closed-form automation-debt measure ($\rho(P)$) formalises how role-level decisions accumulate across multi-step processes; its warning is neutralised only by a regulator-mandated human-in-the-loop anchor. Applied to stylised profiles of representative internal roles, PHP-AIO produces distinct outcomes -- automate, augment, hybrid, and preserve -- for candidates that standard cost-benefit analysis would uniformly automate. Threshold sensitivity analysis confirms the gate decisions are robust to upward perturbations of at least 14% in three of four representative cases. Keywords: AI governance, automation decision, human oversight, tacit knowledge, organizational resilience, financial services
Tags
Links
- Source: https://arxiv.org/abs/2607.15944v1
- Canonical: https://arxiv.org/abs/2607.15944v1
Trouble viewing inline? Open PDF directly →
Full Text
67,596 characters extracted from source content.
Expand or collapse full text
When Not to Automate: A Formal Protocol for Human Preservation in AI-Optimized Organizations Jairo Rodríguez Arias1 Spyridon Chouliaras1 José Manuel de la Chica1 1Santander AI Lab (July 2026) Abstract Standard automation ROI misses four categories of systemic risk—tacit knowledge erosion, resilience reduction, regulatory exposure, and socio-institutional capital degradation—that affect long-term organizational performance. PHP-AIO (Protocol for Human Preservation in AI-Optimized Organizations) is a five-gate sequential decision protocol with a final composite check that quantifies these unpriced systemic risks at the role level and produces auditable automation decisions. A closed-form automation-debt measure (ρ(P)ρ(P)) formalises how role-level decisions accumulate across multi-step processes; its warning is neutralised only by a regulator-mandated human-in-the-loop anchor. Applied to stylised profiles of representative internal roles, PHP-AIO produces distinct outcomes—automate, augment, hybrid, and preserve—for candidates that standard cost-benefit analysis would uniformly automate. Threshold sensitivity analysis confirms the gate decisions are robust to upward perturbations of at least 14% in three of four representative cases. Keywords: AI governance, automation decision, human oversight, tacit knowledge, organizational resilience, financial services 1 The Problem: Automation’s Blind Spot PHP-AIO is a five-gate decision protocol that quantifies four categories of unpriced systemic risk in automation decisions and produces auditable outcomes—automate, preserve, augment, or hybrid—each with prescribed governance actions. The protocol addresses a structural blind spot in how organizations decide to automate. Standard ROI models optimize for cost per transaction, processing time, and error rates [4, 1]. They miss four long-term costs: the irreversible loss of tacit knowledge accumulated over decades, the reduction of organizational redundancy that buffers AI failures, the rising regulatory exposure as jurisdictions mandate human oversight, and the erosion of the public trust capital that financial institutions depend on [5]. We frame these four costs under a single organising principle: automation sovereignty—an organisation’s capacity to retain strategic autonomy over its consequential decisions as AI capabilities advance. We introduce the term automation sovereignty in this paper as an organising frame for the four risk dimensions; it does not appear under this label in prior work, but it consolidates concerns already present in Mittelstadt’s principles-to-practice gap [21] and Wagner’s analysis of accountability shifts under automated decision systems [39]. The automation-debt construct of Section 3.2 is its process-level operationalisation. Tacit-knowledge erosion (TKE) compromises sovereignty by removing the institutional memory required to recover from automation failure; resilience reduction (R), by creating correlated dependencies on the systems that automate decisions; regulatory exposure (RE), by transferring decision-making authority to actors outside the firm when oversight is mandated retroactively; and socio-institutional capital degradation (SCD), by depleting the trust that makes consequential decisions enforceable. PHP-AIO operationalises automation sovereignty as a continuous risk-and-debt accounting discipline, not a binary automate-or-not choice; automation debt (introduced in Section 3.2) is its process-level density signal across multi-step processes. We call these four categories systemic risks. Scholars have documented tacit-knowledge erosion [2, 7], automation-induced complacency and overreliance on algorithmic recommendations [27, 6, 8], organizational brittleness [28, 37], and the principles-to-practice gap in AI ethics [14, 21]. Recent surveys consolidate the human-in-the-loop design space [22]. The gap is not awareness, it is operational: no formal protocol incorporates these risks into the automation decision itself. Existing governance frameworks—the US NIST AI Risk Management Framework [24], the EU AI Act [13, 38], and human-in-the-loop (HITL) oversight taxonomies—engage after the deployment-commitment decision. None decide whether to automate. Sociotechnical scholarship moreover warns that procedural human oversight and technical compliance alone do not guarantee meaningful control when system design embeds the wrong abstractions [33, 39, 15, 35]. Where PHP-AIO sits. Table 1 contrasts PHP-AIO against the four closest governance frameworks. The NIST AI Risk Management Framework [24] is voluntary cross-sector guidance organised around four functions (govern, map, measure, manage); it does not prescribe thresholds or decisions. The EU AI Act conformity assessment [13, 38] mandates pre-market and post-market checks for high-risk systems—human-oversight requirements, Annex IV technical documentation, and post-market monitoring—but only once a system is classified as high-risk. FAccT-style algorithmic impact assessments [19, 23] produce structured analyses of fairness, discrimination, and sociotechnical context, ranging from qualitative narratives to participatory deliberation processes; outputs are typically used to inform deployment governance rather than as binary decision filters. AI Risk Profiles [34], the closest pre-decision competitor, provide pre-deployment risk-profile disclosure organised around a taxonomy of AI risks but use ordinal severity levels rather than formal scoring and do not produce a deployment decision. Three axes distinguish PHP-AIO from each comparator: (i) formal scoring—PHP-AIO produces explicit numerical gate scores rather than narrative or ordinal outputs; (i) an explicit decision output among four outcomes (automate / augment / hybrid / preserve); and (i) jurisdictional granularity through country-specific multipliers in the RE formula. Where PHP-AIO also differs in timing, it acts pre-decision—before the deployment-commitment choice is taken—whereas the other frameworks engage once a deployment candidate exists [30]. Table 1: PHP-AIO relative to the closest governance frameworks. Pin-cite mapping: NIST Timing & Multi-dim. → NIST AI RMF 1.0 §3.1 lifecycle framing and §3.2 trustworthy characteristics; EU AI Act Timing → Reg. 2024/1689 Art. 43 (pre-market conformity assessment) + Art. 72 (post-market monitoring); EU AI Act Multi-dim. → Annex I high-risk classes; AI Risk Profiles → [34] 4-part taxonomy. The four comparators address different points in the AI lifecycle; PHP-AIO acts upstream of the deployment-commitment decision itself. NIST AI RMF [24] EU AI Act [13, 38] FAccT IA [19, 23] AI Risk Profiles [34] PHP-AIO (this paper) Timing lifecycle (all phases) pre-market + post-market pre-deployment pre-deployment pre-decision Output type recommendations binary conformity narrative impact risk-profile disclosure score + decision Formal scoring × × × ordinal (taxonomy) ✓ (5 gates) Multi-dim. risk 7 trust characteristics Annex I high-risk areas varies taxonomy of AI risks 4 dim. + composite Jurisdiction-aware × implicit (EU) × × ✓ (10 countries) 2 Four Dimensions of Unpriced Risk Each of the four risk dimensions captures a distinct mechanism through which automation can damage organizational performance: TKE captures the irreversible loss of judgment that cannot be re-encoded once a role is removed; R captures the correlated fragility introduced when automated systems share failure modes; RE captures the option-value cost of reversing automation if regulation later mandates human oversight; and SCD captures the depletion of the trust capital that makes consequential decisions enforceable. Common scale convention. Every sub-dimension is first computed from its primary inputs (Likert scales, boolean dichotomies, monetary thresholds) and then affinely rescaled to [0,1][0,1] using its effective input range. If a sub-dimension s takes raw values in [smin,smax][s_ ,s_ ], its normalised score is (s−smin)/(smax−smin)(s-s_ )/(s_ -s_ ), clipped to [0,1][0,1]. The rescaling guarantees that a value of 0.5 means halfway through the risk range consistently across all twelve sub-dimensions, and that the four composite scores (TKE, R, RE, SCD) are directly comparable on the same axis. The bullets in each subsection report the raw construction for transparency. On weights. All four risk dimensions take the same form—a weighted sum of three normalised sub-dimensions, with the weights summing to one. The per-dimension weights reported alongside each formula below (0.4/0.3/0.3 for TKE; 0.35/0.35/0.30 for R and SCD; 0.4/0.4/0.2 for RE) are an expert configuration, not a derived constant. They encode a governance choice about the relative importance of each sub-dimension and are expected to vary by industry, use case, and risk appetite (in healthcare, for instance, RE typically over-weights its CQ sub-component). The values reported here are the financial-services baseline, elicited through internal Santander AI Lab consensus over Q1 2026 and informed by [8] on automation bias and [21] on algorithmic-governance practice. The four gates use a uniform threshold of 0.70, so the same risk score is treated identically across dimensions. 2.1 Tacit Knowledge Erosion (TKE) Tacit knowledge is the embodied, experience-derived judgment practitioners develop through years of domain-specific practice [25, 7]; explicit documentation cannot fully capture it [31, 11]. TKE combines three sub-dimensions—codifiability (κ), irreversibility (IR), and criticality (CM)—as a weighted sum: TKE(r)=0.4⋅(1−κ)+0.3⋅IR+0.3⋅CMTKE(r)=0.4·(1-κ)+0.3·IR+0.3·CM (1) The (1−κ)(1-κ) term flips codifiability: a fully codifiable role contributes 0 to that term. Example: a senior role with 5 years of experience, high expert judgment, and high error impact yields TKE≈0.56TKE≈ 0.56 (Appendix B; sub-dimension construction in Appendix C). 2.2 Resilience Reduction (R) AI systems fail in correlated ways under novel, adversarial, or high-ambiguity conditions [18]; human roles provide a non-correlated resilience layer whose removal makes organisations brittle in exactly those regimes [16, 40]. Pairing humans with AI does not automatically restore resilience: gains depend on careful role and explanation design [3]. R combines three sub-dimensions—Recovery (RC; manual fallback and downtime tolerance), Adversarial (AD; novel-threat detection and human-escalation rate), and Correlation (CR; count of dependent automated systems)—as a weighted sum: R(r)=0.35⋅RC+0.35⋅AD+0.30⋅CRR(r)=0.35·RC+0.35·AD+0.30·CR (2) Higher values mean greater resilience risk. Example: a loan-approval role with no manual fallback, 24h downtime tolerance, low novel-threat detection, and three dependent downstream systems yields R≈0.61R≈ 0.61 (full derivation in Appendix B, construction in Appendix C). 2.3 Regulatory Exposure (RE) Regulatory frameworks across jurisdictions are converging on mandatory human oversight for consequential automated decisions [36, 13]. Automation decisions made today carry regulatory option value—the cost of reversing automation if future regulation requires human review. RE combines three sub-dimensions—Consequentiality (CQ; customer impact, credit-decision involvement, sensitive-data handling), Jurisdictional (JU; audit-body count, HITL mandates, and precedent sanctions, multiplied by a country factor in 0.8,0.9,1.0,1.1,1.2\0.8,0.9,1.0,1.1,1.2\ across the ten countries with explicit multipliers), and Reversal (RV; cost to reintroduce human oversight, capped at €500K)—as a weighted sum: RE(r)=0.4⋅CQ+0.4⋅JU+0.2⋅RVRE(r)=0.4·CQ+0.4·JU+0.2·RV (3) Example: a UK loan-approval role (sensitive data, HITL mandatory, three audit bodies, €200K reversal cost) yields RE≈0.85→RE≈ 0.85→ hybrid (full derivation in Appendix B, construction in Appendix C). 2.4 Socio-Institutional Capital Degradation (SCD) Financial institutions operate on trust [41, 26]. Certain human roles serve as trust anchors: their presence signals care, accountability, and human agency [29]. Replacing them with automation triggers trust deficits that resist advance measurement but turn catastrophic when they materialize. SCD combines three sub-dimensions—Relational (RL; customer-interaction depth and explicit human expectation [10, 17]), Legitimacy (LG; brand-perception impact and public visibility), and Labor (LB; team-morale impact and headcount in the role)—as a weighted sum: SCD(r)=0.35⋅RL+0.35⋅LG+0.30⋅LBSCD(r)=0.35·RL+0.35·LG+0.30·LB (4) Example: a retail in-branch advisor (in-person interaction, customers expect a human, 30 employees, brand impact 5/5) yields SCD≈0.90→SCD≈ 0.90→ augment (full derivation in Appendix B, construction in Appendix C). 3 The Five-Gate Decision Protocol PHP-AIO evaluates automation candidates through five sequential gates. A role must clear each gate before reaching the next. Gate 1 is a net-benefit pre-filter: automation must deliver a minimum positive net benefit to justify risk assessment. The remaining four gates correspond to the risk dimensions defined in Section 2. The sequential structure assesses irreversible risks first. Table 2 specifies the gate questions, thresholds, and failure outcomes; Figure 1 renders the same protocol as a decision flow. Each gate’s failure routes the role to a specific outcome: G1, G2, or G3 → preserve (keep the human role, protecting against irreversible loss); G4 → hybrid (AI executes, human supervises, remediating regulatory exposure); G5 → augment (AI assists, human decides, protecting trust capital). A role that clears all five individual gates is then subjected to a final composite check: a weighted average of the four risk dimensions that must remain below a tighter threshold (≥0.60≥ 0.60 routes to hybrid; the per-gate threshold is 0.70). The composite catches roles whose four dimensions individually sit just below their thresholds but whose accumulated score signals systemic moderate risk—a failure mode that single-gate checks miss by construction. Roles that clear all five gates and the composite check yield automate; the formal definition, weights, and rationale for the asymmetric threshold are in Section 3.1. Why a cost threshold first. Gate 1 is a cheap necessary filter, not a sufficiency claim. It reserves the costly risk analysis of Gates 2–5 for candidates with at least a baseline economic case. Cost savings does not decide the outcome—the four qualitative gates do. Table 2: The five-gate protocol with its composite check. Gate Dimension Question Threshold If Failed G1 Net Benefit Does automation produce ≥15%≥ 15\% net benefit? Net benefit ≥15%≥ 15\% preserve G2 TKE Is tacit knowledge risk below threshold? TKE<0.70TKE<0.70 preserve G3 R Is resilience impact acceptable? R<0.70R<0.70 preserve G4 RE Is regulatory exposure manageable? RE<0.70RE<0.70 hybrid G5 SCD Is social capital impact acceptable? SCD<0.70SCD<0.70 augment Composite All four dims Is accumulated moderate risk acceptable? PHP-AIO<0.60PHP -AIO<0.60 hybrid G1 Net Benefit≥15%≥ 15\%G2 TKE<0.70<0.70G3 R<0.70<0.70G4 RE<0.70<0.70G5 SCD<0.70<0.70Composite<0.60<0.60automatepreservepreservepreservehybridaugmenthybridpasspasspasspasspasspassfailfailfailfailfailfail Figure 1: Five-gate protocol with its composite check. Solid arrows denote a passed gate; dashed arrows denote the failure outcome routed by each gate. Gates 2–3 protect against irreversible damage (failure → preserve); Gate 4 addresses regulatory risk through oversight (failure → hybrid); Gate 5 protects the customer relationship (failure → augment). Gate 1 measures direct cost savings by default; other monetised components (quality uplift, control strengthening, resilience, compliance, customer/employee experience) are admissible if each is named, sized and auditable. Threshold calibration, regulatory grounding, sensitivity analysis, and configurability per industry are discussed in Appendix D. 3.1 Composite Score If a role passes all five gates, a composite score detects accumulated moderate risks: PHP-AIO(r)=w1⋅TKE+w2⋅R+w3⋅RE+w4⋅SCDPHP -AIO(r)=w_1·TKE+w_2·R+w_3·RE+w_4·SCD (5) The financial-services configuration is w1=0.30w_1=0.30 (TKE), w2=0.25w_2=0.25 (R), w3=0.30w_3=0.30 (RE), w4=0.15w_4=0.15 (SCD); weights sum to one and are configurable per domain. These values are an AI Lab Santander research configuration, elicited through internal expert consensus over Q1 2026; they do not represent an official Santander Group automation policy. The pairing w1=w3=0.30w_1=w_3=0.30 encodes the design principle that regulatory exposure and tacit-knowledge erosion are functionally equivalent in severity (both effectively irreversible). R receives the middle weight w2=0.25w_2=0.25 because organisational redundancy and manual fallbacks are recoverable at high operational cost, and SCD the lowest w4=0.15w_4=0.15 because trust capital, although slow to rebuild, is the most recoverable of the four on a 3–5 year horizon and is partially absorbed by RE’s CQ sub-component. The ordering is an editorial choice; neither EU regulatory frameworks nor banking-supervisory guidance currently rank automation-related risk categories at this granularity, leaving the weight assignment to institutional governance. If the composite ≥0.60≥ 0.60, the role receives a hybrid recommendation. The composite threshold is deliberately tighter than the per-gate 0.70: a role whose four dimensions each score, say, 0.65 clears every individual gate but yields a weighted average of ≈0.65≥0.60≈ 0.65≥ 0.60, signalling the death-by-a-thousand-cuts failure mode in which no single risk is acute yet the joint profile is unacceptable. The 0.60 value is calibrated against the four worked examples in Section 5: it routes roles with one borderline-passing dimension (composite ≈0.45≈ 0.45–0.550.55) to automate, while flagging profiles with two or more borderline dimensions for human supervision. Single-gate decisions are robust to weight perturbations; composite-driven decisions are weight-sensitive by construction (Appendix D bounds the one composite-driven example of Section 5). 3.2 Cumulative Risk: Automation Debt Task-level decisions stack: a process composed of subtasks individually safe to automate may still erode end-to-end resilience as dependencies multiply, manual fallbacks atrophy, and reversibility costs compound—a pattern that mirrors the accumulation dynamics of technical debt in software [9] and in machine learning systems [32]. For a process P with leaf subtasks t1,…,tnt_1,…,t_n, decisions did_i, and time weights wi=avg_time_minutes(ti)w_i=avg\_time\_minutes(t_i), we define the time-weighted automation density ρ(P)=∑i=1nwi⋅[di=automate]∑i=1nwiρ(P)= _i=1^nw_i·1[d_i=automate] _i=1^nw_i (6) A process triggers an automation-debt warning when ρ(P)≥0.80ρ(P)≥ 0.80 and no leaf subtask carries a regulator-mandated human-in-the-loop anchor (hitl_required_by_regulation=truehitl\_required\_by\_regulation=true for at least one augment, hybrid, or preserve leaf). The HITL-anchor exception encodes the principle that a process whose oversight is grounded in a specific regulatory requirement at any point retains a defensible recovery point even at high automation density. Figure 2 contrasts the two scenarios; full mechanics (hierarchical rollup, link to automation sovereignty) are in Appendix E. LoanOriginationDoc digit.automateID verifyautomateCredit pullautomateUnderwr.automateOffer gen.automateScenario A: ρ(P)=5/5=1.00ρ(P)=5/5=1.00no HITL anchor ⇒ debt warningLoanOriginationDoc digit.automateID verifyautomateCredit pullautomateUnderwr.hybrid(HITL anchor)Offer gen.automateScenario B: ρ(P)=4/5=0.80ρ(P)=4/5=0.80HITL anchor at underwriting ⇒ no warning Figure 2: Automation-debt warning, two scenarios on the same five-leaf loan-origination process. Left (A): all five subtasks classified automate; density saturates (ρ=1.00ρ=1.00) and no leaf carries a regulator-mandated HITL anchor, so the warning fires. Right (B): underwriting is classified hybrid with an HITL anchor grounded in adverse-action explainability rules; the density drops to ρ=0.80ρ=0.80 but the anchor neutralises the warning. Full mechanics in Appendix E. Table 3: Four decision outcomes with prescribed governance actions. Decision Meaning Governance Action automate All gates cleared, composite <0.60<0.60 Proceed. Quarterly re-evaluation. preserve G1, G2, or G3 failed Keep human role. Document rationale. Annual review. augment G5 failed AI assists, human decides. Gradual knowledge capture. hybrid G4 or composite failed AI executes, human supervises. Role splitting. 3.3 Four Decision Outcomes Time-indexed evaluation. The risk profile of a decision is not static: regulation evolves, AI capabilities improve, knowledge can be partially documented over time, and reversibility costs grow as dependency deepens. The protocol projects each gate score sd(0)∈[0,1]s_d(0)∈[0,1] over a decision horizon H∈1,3,5H∈\1,3,5\ years using a first-order linear approximation, clipped to the score domain: sd(H)=clip(sd(0)+δd⋅H, 0, 1)s_d(H)=clip (s_d(0)+ _d· H,\ 0,\ 1 ) (7) where δd _d is an annual drift rate per dimension. The financial-services default drifts are δTKE=+0.03/yr _TKE=+0.03/yr (knowledge atrophies as AI handles routine cases), δR=−0.02/yr _R=-0.02/yr (AI reliability improves), δRE=+0.05/yr _RE=+0.05/yr (regulatory frameworks converge toward mandatory oversight), and δSCD=0/yr _SCD=0/yr (trust effects stable in the medium term). The decision-flip horizon H∗=minH:decision(sd(H))≠decision(sd(0))H^*= \H:decision(s_d(H)) (s_d(0))\ is the smallest projected horizon at which the outcome inverts; H∗=∞H^*=∞ if no horizon flips it. Illustrative example: a role currently passing G4 at RE(0)=0.62RE(0)=0.62 projects under δRE=+0.05 _RE=+0.05 to RE(3)=0.77>0.70RE(3)=0.77>0.70, so H∗=3H^*=3 years and the role receives conditional automate—approved today with mandatory re-evaluation at H∗H^*. The mirror case is deferred preserve: a role failing today on a dimension with δd<0 _d<0 whose projected score crosses below threshold within 5 years is preserved now, with automation re-evaluation triggered when the projection crosses. Full drift-rate derivation and v0.2.0 operationalisation status are in Appendix F. 4 Operationalization Operationalising the protocol imposes three constraints. First, scoring reduces to a 40-field structured input schema—this paper’s v1 reference (Appendix A)—that maps every score sub-component of Section 2 to an observable, falsifiable field. The schema has seven functional groups: 6 task-context fields, 2 Gate 1 (net-benefit) fields, 8 TKE fields, 5 R fields, 8 RE fields, 6 SCD fields, and 5 qualitative-context fields used for narrative justification but not for scoring. Second, scoring is deterministic over those inputs: large-language-model inference is restricted to assistive roles—decomposing a process description into discrete tasks, and producing post-scoring narrative justifications—and never enters the scoring path, preserving auditability under the EU AI Act traceability requirements (Art. 12 record-keeping for high-risk systems) [13] and NIST AI RMF traceability guidance (Measure function) [24]. Third, determinism plus explicit configuration of thresholds and weights yields a fully reproducible audit trail traceable to (a) the structured inputs, (b) the gate scores and composite, (c) the configuration version (thresholds, weights, schema), and (d) the protocol version. Two evaluators given the same inputs obtain the same decision; a regulator inspecting a past decision can reconstruct it from artefacts alone. The full discussion of each constraint, including the rationale for excluding LLMs from the scoring path, is in Appendix G. Schema authority and extensibility. The 40-field schema reported here is the AI Lab Santander v1 schema for financial services. It is part of the configuration layer, not the protocol layer: institutions deploying PHP-AIO in other industries (healthcare, public administration, retail) are expected to extend or restrict the schema to fit their observable role attributes, subject to two invariants. Invariant 1 (coverage): every formula sub-component of Section 2 must remain populated by at least one field—extensions never weaken the score, only enrich it. Invariant 2 (versioning): schema changes are versioned and approver-signed in the same audit trail as threshold and weight changes (Appendix G), so reproducibility holds within a schema version. The financial-services v1 schema is offered as a reference; deviations are governance choices, not protocol violations. 5 Practical Examples Table 4 reports four internal back-office processes yielding three distinct outcomes under PHP-AIO; Figure 5 renders the same evaluation as a per-cell heatmap that makes the deciding gate visually salient. None of the four involves external customers or regulator-mandated oversight; the protocol discriminates on tacit knowledge, resilience, and social-capital grounds alone. hybrid is a regulator-driven outcome (G4) and is therefore not represented in this set. The scores are illustrative of protocol behaviour on stylised role profiles; per-role detail (input rationale, gate-by-gate narrative) is in Appendix H. Table 4: Four roles, three distinct outcomes. ‘–’ indicates the gate is not evaluated because the protocol stops at the first failure (sequential structure of Section 3). All four examples pass G1. Gate Invoice Entry Incident Triage Mgr Coaching Architecture Review G1 Net Benefit 50% ✓ 50% ✓ 50% ✓ 50% ✓ G2 TKE 0.00 ✓ 0.08 ✓ 0.08 ✓ 0.80 × G3 R 0.23 ✓ 0.82 × 0.32 ✓ – G4 RE 0.07 ✓ – 0.07 ✓ – G5 SCD 0.13 ✓ – 0.83 × – Composite 0.10 ✓ – – – Outcome automate preserve augment preserve PHP-AIO does not produce a single recommendation for all roles. The same organisation can automate invoice entry, preserve incident triage on resilience grounds, augment people-manager coaching on social-capital grounds, and preserve senior architecture reviews on tacit-knowledge grounds—four assessments yielding three distinct outcomes, each grounded in the gate that decided it. Table 5: Gate-by-gate evaluation of the four practical examples. Green = pass, red = failing gate (decides outcome), grey ‘–’ = not evaluated (sequential stop). G1 G2 G3 G4 G5 Composite Outcome Net Ben. TKE R RE SCD Invoice Entry 50% 0.00 0.23 0.07 0.13 0.10 automate Incident Triage 50% 0.08 0.82 – – – preserve Mgr Coaching 50% 0.08 0.32 0.07 0.83 – augment Arch. Review 50% 0.80 – – – – preserve 6 Limitations The protocol presented here is a v1 conceptual framework. Five limitations should be made explicit. Expert-elicited parameters. All quantitative parameters—per-dimension weights, gate thresholds, country multipliers, and drift rates—were elicited by internal Santander AI Lab consensus drawing on the automation-bias and algorithmic-governance literature [8, 21], not optimised against ground-truth data. The sensitivity analysis in Appendix D shows single-gate decisions are robust to the implied uncertainty but composite-driven decisions are not. Refining multipliers against regulatory-fine datasets and drift rates against multi-year panels are tractable next steps. Validation is ongoing. The Section 5 examples are stylised role profiles; a retrospective validation study against historical automation decisions with observable outcomes (knowledge loss, regulatory action, trust failure) is currently underway, though no results are available yet. A multi-institution case panel spanning at least five years with matched outcome data remains the principal validation item and the precondition for moving PHP-AIO from candidate framework to evidenced framework. Input-level inter-rater reliability is unmeasured. The reproducibility guarantee of Section 4 is conditional: determinism holds from structured inputs to decision, not from role description to structured inputs. Several of the 40 schema fields are Likert judgments (requires_expert_judgment, brand_perception_impact, team_morale_impact) on which two independent analysts can plausibly diverge, and the protocol currently has no mechanism to detect such divergence. A two-rater study measuring agreement (Cohen’s κ) on the input fields and on the resulting decisions over a shared role set is part of the validation work plan. Single-industry calibration. The reported configuration is financial-services-specific. The architecture is industry-agnostic but its quantitative defaults are not transferable without recalibration: healthcare, public administration, and retail each have qualitatively different RE structures and SCD weights. Reference configurations for those sectors are future work. Dual-use risk and configuration audit. Configurability is also the surface that lets an institution ratify cost-driven outcomes under procedural cover. Three mitigations apply: the financial-services configuration is the minimum-compliance baseline111Here minimum-compliance baseline denotes the internal baseline against which approved configuration deltas are audited at the operating institution; it is not a claim that these values constitute a regulatory floor or an industry standard. against which reconfigurations are audited as approved deltas; every threshold and weight change is a versioned, timestamped, approver-signed artefact, so outcome-shopping cannot be disguised as parameter-tuning; and the retrospective validation mentioned above will yield empirical bounds within which protocol outcomes correlate with observed ones—deviations outside that band become out-of-distribution governance choices. 7 Conclusion PHP-AIO formalises a four-dimension risk profile—tacit-knowledge erosion, resilience reduction, regulatory exposure, and socio-institutional capital degradation—as a deterministic five-gate protocol that yields an auditable automate / preserve / augment / hybrid decision before an organisation commits to deployment. It is not a competitor to NIST AI RMF, EU AI Act conformity assessment, FAccT-style impact assessments, or pre-deployment risk-profile disclosure standards [34]—all of which act once a deployment candidate exists—but a complement upstream of them: a pre-decision filter whose output is a versioned configuration plus a gate-by-gate score, not a narrative. The separation between deterministic scoring and optional LLM assistance is what makes the protocol auditable under EU AI Act traceability requirements (Art. 12 record-keeping) [13] and NIST AI RMF traceability guidance (Measure function) [24]: identical inputs yield identical decisions regardless of model, prompt, or runtime, and every configuration change is a timestamped, approver-signed artefact. Per-domain configurability of weights, thresholds, and country multipliers lets each institution recalibrate to its own risk appetite, with the financial-services configuration in this paper offered as a v1 expert-elicited baseline rather than a universal default. A retrospective validation against documented automation decisions is currently underway; together with cross-industry calibration for healthcare and public administration and learning drift rates from accumulated assessments, these are the three lines of work that would move PHP-AIO from a v1 governance protocol toward an institution-specific, evidenced risk model. The automation decision is too consequential to leave to cost savings alone; PHP-AIO is offered as one way to ensure it is not. References [1] Daron Acemoglu and Pascual Restrepo. Automation and new tasks: How technology displaces and reinstates labor. Journal of Economic Perspectives, 33(2):3–30, 2019. [2] Lisanne Bainbridge. Ironies of automation. Automatica, 19(6):775–779, 1983. [3] Gagan Bansal, Tongshuang Wu, Joyce Zhou, Raymond Fok, Besmira Nushi, Ece Kamar, Marco Tulio Ribeiro, and Daniel Weld. Does the whole exceed its parts? the effect of ai explanations on complementary team performance. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems, CHI ’21. ACM, 2021. [4] Erik Brynjolfsson. The productivity paradox of information technology. Communications of the ACM, 36(12):66–77, 1993. [5] Erik Brynjolfsson. The turing trap: The promise & peril of human-like ai. Daedalus, 151(2):272–287, 2022. [6] Zana Buçinca, Maja Barbara Malaya, and Krzysztof Z. Gajos. To trust or to think: Cognitive forcing functions can reduce overreliance on ai in ai-assisted decision-making. Proceedings of the ACM on Human-Computer Interaction, 5(CSCW1):Article 188, 2021. [7] Harry Collins. Tacit and Explicit Knowledge. University of Chicago Press, 2010. [8] Mary L. Cummings. Automation bias in intelligent time critical decision support systems. In Collection of Technical Papers – AIAA 1st Intelligent Systems Technical Conference, volume 2, pages 557–562, 2004. [9] Ward Cunningham. The wycash portfolio management system. In Addendum to the Proceedings of OOPSLA ’92. ACM, 1992. [10] Berkeley J. Dietvorst, Joseph P. Simmons, and Cade Massey. Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1):114–126, 2015. [11] Mica R. Endsley. From here to autonomy: Lessons learned from human-automation research. Human Factors, 59(1):5–27, 2017. [12] European Banking Authority. Guidelines on internal governance under directive 2013/36/eu. Technical Report EBA/GL/2021/05, European Banking Authority, 2021. [13] European Parliament and Council of the European Union. Regulation (eu) 2024/1689 of the european parliament and of the council of 13 june 2024 laying down harmonised rules on artificial intelligence (artificial intelligence act). Official Journal of the European Union, L 2024/1689, 2024. [14] Luciano Floridi, Josh Cowls, Thomas C. King, and Mariarosaria Taddeo. How to design ai for social good: Seven essential factors. Science and Engineering Ethics, 26(3):1771–1796, 2020. [15] Ben Green. The flaws of policies requiring human oversight of government algorithms. Computer Law & Security Review, 45:105681, 2022. [16] Erik Hollnagel. The four cornerstones of resilience engineering. In Christopher P. Nemeth, Erik Hollnagel, and Sidney Dekker, editors, Resilience Engineering Perspectives, Volume 2: Preparation and Restoration, pages 117–134. Ashgate, 2011. [17] Jennifer M. Logg, Julia A. Minson, and Don A. Moore. Algorithm appreciation: People prefer algorithmic to human judgment. Organizational Behavior and Human Decision Processes, 151:90–103, 2019. [18] Sean McGregor. Preventing repeated real world ai failures by cataloging incidents: The ai incident database. Proceedings of the AAAI Conference on Artificial Intelligence, 35(17):15458–15463, 2021. [19] Jacob Metcalf, Emanuel Moss, Elizabeth Anne Watkins, Ranjit Singh, and Madeleine Clare Elish. Algorithmic impact assessments and accountability: The co-construction of impacts. In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, FAccT ’21, pages 735–746, 2021. [20] Margaret Mitchell, Simone Wu, Andrew Zaldivar, Parker Barnes, Lucy Vasserman, Ben Hutchinson, Elena Spitzer, Inioluwa Deborah Raji, and Timnit Gebru. Model cards for model reporting. In Proceedings of the 2019 Conference on Fairness, Accountability, and Transparency, FAT* ’19, pages 220–229. ACM, 2019. [21] Brent Mittelstadt. Principles alone cannot guarantee ethical ai. Nature Machine Intelligence, 1(11):501–507, 2019. [22] Eduardo Mosqueira-Rey, Elena Hernández-Pereira, David Alonso-Ríos, José Bobes-Bascarán, and Ángel Fernández-Leal. Human-in-the-loop machine learning: A state of the art. Artificial Intelligence Review, 56(4):3005–3054, 2023. [23] Emanuel Moss, Elizabeth Anne Watkins, Ranjit Singh, Madeleine Clare Elish, and Jacob Metcalf. Assembling accountability: Algorithmic impact assessment for the public interest. Technical report, Data & Society Research Institute, 2021. [24] National Institute of Standards and Technology. Artificial intelligence risk management framework (ai rmf 1.0). Technical Report NIST AI 100-1, NIST, 2023. [25] Ikujiro Nonaka and Hirotaka Takeuchi. The Knowledge-Creating Company: How Japanese Companies Create the Dynamics of Innovation. Oxford University Press, 1995. [26] Douglass C. North. Institutions, Institutional Change and Economic Performance. Cambridge University Press, 1990. [27] Raja Parasuraman and Dietrich H. Manzey. Complacency and bias in human use of automation: An attentional integration. Human Factors, 52(3):381–410, 2010. [28] Charles Perrow. Normal Accidents: Living with High-Risk Technologies. Basic Books, 1984. [29] Robert D. Putnam. Bowling Alone: The Collapse and Revival of American Community. Simon & Schuster, 2000. [30] Sebastian Raisch and Sebastian Krakowski. Artificial intelligence and management: The automation-augmentation paradox. Academy of Management Review, 46(1):192–210, 2021. [31] Tapani Rinta-Kahila, Esko Penttinen, Antti Salovaara, and Wael Soliman. Consequences of discontinuing knowledge work automation: Surfacing of deskilling effects and methods of recovery. In Proceedings of the 51st Hawaii International Conference on System Sciences, HICSS-51, 2018. [32] D. Sculley, Gary Holt, Daniel Golovin, Eugene Davydov, Todd Phillips, Dietmar Ebner, Vinay Chaudhary, Michael Young, Jean-François Crespo, and Dan Dennison. Hidden technical debt in machine learning systems. In Advances in Neural Information Processing Systems, volume 28, pages 2503–2511, 2015. [33] Andrew D. Selbst, Danah Boyd, Sorelle A. Friedler, Suresh Venkatasubramanian, and Janet Vertesi. Fairness and abstraction in sociotechnical systems. In Proceedings of the 2019 Conference on Fairness, Accountability, and Transparency, FAT* ’19, pages 59–68. ACM, 2019. [34] Eli Sherman and Ian Eisenberg. Ai risk profiles: A standards proposal for pre-deployment ai risk disclosures. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 38, pages 23047–23052, 2024. [35] Ben Shneiderman. Human-Centered AI. Oxford University Press, 2022. [36] Nathalie A. Smuha. From a ‘race to ai’ to a ‘race to ai regulation’: Regulatory competition for artificial intelligence. Law, Innovation and Technology, 13(1):57–84, 2021. [37] Nassim Nicholas Taleb. Antifragile: Things That Gain from Disorder. Random House, 2012. [38] Michael Veale and Frederik Zuiderveen Borgesius. Demystifying the draft eu artificial intelligence act – analysing the good, the bad, and the unclear elements of the proposed approach. Computer Law Review International, 22(4):97–112, 2021. [39] Ben Wagner. Liable, but not in control? ensuring meaningful human agency in automated decision-making systems. Policy & Internet, 11(1):104–122, 2019. [40] David D. Woods. The theory of graceful extensibility: Basic rules that govern adaptive systems. Environment Systems and Decisions, 38(4):433–457, 2018. [41] Lynne G. Zucker. Production of trust: Institutional sources of economic structure, 1840–1920. Research in Organizational Behavior, 8:53–111, 1986. Appendix A Input Schema The reference implementation operationalises the protocol with a 40-field input schema. Six fields capture task context (stored at the task level), 29 fields drive the five gates (stored at the assessment level), and 5 fields provide qualitative context used by the narrative layer but not by scoring. Field names match the implementation’s database schema. This is the financial-services v1 schema; extensions for other industries follow the schema-authority invariants stated in Section 4. A.1 Task Context (6 fields) Field Type Values / Range name string free text description text free text task_type enum decision, validation, data_entry, … frequency enum per_case, daily, weekly, monthly, ad-hoc avg_time_minutes int ≥0≥ 0 criticality enum blocking, important, optional A.2 Gate 1 — Net Benefit (2 fields) Gate 1 derives efficiency_gain=(current−ai)/currentefficiency\_gain=(current-ai)/current and tests it against the ≥15%≥ 15\% threshold. Field Type Range current_cost_per_case float ≥0≥ 0 estimated_ai_cost float ≥0≥ 0 A.3 Gate 2 — TKE (8 fields) Field Type Range / Values Drives requires_expert_judgment int 1–5 (Likert) κ exception_frequency float 0–100% κ documentation_level int 1–5 (Likert) κ min_experience_years int ≥0≥ 0 IR training_time_months int ≥0≥ 0 IR knowledge_concentration bool true / false IR downstream_dependencies list task ids CM error_impact enum low / medium / high / critical CM A.4 Gate 3 — R (5 fields) Field Type Range / Values Drives manual_backup_exists bool true / false RC max_tolerable_downtime_hours int ≥0≥ 0 RC detects_novel_threats bool true / false AD escalation_rate float 0–100% AD dependent_automated_systems list system identifiers CR A.5 Gate 4 — RE (8 fields) Field Type Range / Values Drives affects_customers_directly bool true / false CQ involves_credit_decisions bool true / false CQ handles_sensitive_data bool true / false CQ subject_to_audit list audit body codes JU hitl_required_by_regulation bool true / false JU regulation_reference string free text (e.g. EU AI Act Art. 14) JU precedent_sanctions bool true / false JU estimated_reversal_cost float EUR, ≥0≥ 0 RV A.6 Gate 5 — SCD (6 fields) Field Type Range / Values Drives customer_interaction_type enum none, email, phone, video, in_person RL customer_expects_human bool true / false RL brand_perception_impact int 1–5 (Likert) LG publicly_visible_role bool true / false LG team_morale_impact int 1–5 (Likert) LB employees_in_role int ≥0≥ 0 LB A.7 Qualitative Context (5 fields, non-scoring) These fields enrich the LLM-generated narrative justification and the audit trail; they do not enter any gate formula. Field Type additional_context free text known_risks free text previous_automation_attempts free text stakeholder_concerns free text notes free text Appendix B Detailed Worked Examples This appendix expands the one-line worked examples of Section 2 into full derivations and ties each dimension to the broader literature on sovereignty degradation. B.1 Tacit Knowledge Erosion (TKE) A role requiring 5 years of experience, high expert judgment, and high error impact yields normalised sub-scores κ=0.41κ=0.41, IR=0.44IR=0.44, CM=0.64CM=0.64 (raw values 0.49, 0.50, 0.69 rescaled from their effective ranges [0.14,1][0.14,1], [0.10,1][0.10,1], [0.15,1][0.15,1]), hence TKE=0.4⋅0.59+0.3⋅0.44+0.3⋅0.64≈0.56TKE=0.4· 0.59+0.3· 0.44+0.3· 0.64≈ 0.56—below the 0.70 Gate 2 threshold but flagged at the composite gate. TKE measures sovereignty degradation through the irreversible loss of judgment that cannot be re-encoded once the role is removed. B.2 Resilience Reduction (R) A loan-approval role with no manual fallback and 24-hour tolerance (RC raw 0.60, normalised 0.64), no novel-threat detection and 20% escalation (AD raw 0.56, normalised 0.58), and three dependent downstream systems (CR=0.60CR=0.60, already in [0,1][0,1]) yields R=0.64×0.35+0.58×0.35+0.60×0.30≈0.61R=0.64× 0.35+0.58× 0.35+0.60× 0.30≈ 0.61—below the 0.70 threshold, flagged at the composite gate. This dimension draws on antifragility theory [37] and on the broader literature on automation-induced complacency in safety-critical contexts [8]: diverse response mechanisms outperform purely automated systems under novel or adversarial conditions. R measures sovereignty degradation through the structural fragility introduced when correlated automated systems share failure modes. B.3 Regulatory Exposure (RE) A UK loan-approval role (affects customers directly, credit decision, sensitive data, three audit bodies, HITL mandatory, precedent sanctions, €200K reversal cost) yields raw values CQ=0.84CQ=0.84, JU=1.034JU=1.034, RV=0.40RV=0.40 which rescale to 1.000, 0.913 and 0.400 respectively, hence RE=1.000×0.4+0.913×0.4+0.400×0.2=0.4+0.3652+0.08=0.8452≈0.85RE=1.000× 0.4+0.913× 0.4+0.400× 0.2=0.4+0.3652+0.08=0.8452≈ 0.85—above the 0.70 threshold, so the protocol routes the role to hybrid. For multi-jurisdictional organisations operating across heterogeneous regulatory regimes, this dimension captures the country-level variation that single-jurisdiction analyses miss. RE measures sovereignty degradation through the regulatory option value lost when an automated decision is later mandated to be reversed. B.4 Socio-Institutional Capital Degradation (SCD) A retail in-branch advisor role (in-person interaction, customers expect a human, brand impact 5/5, publicly visible, 30 employees, morale impact 4/5) yields raw values RL=0.92RL=0.92, LG=0.92LG=0.92, LB=0.70LB=0.70 which rescale to 1.00, 1.00 and 0.67 respectively, hence SCD=1.00×0.35+1.00×0.35+0.67×0.30≈0.90SCD=1.00× 0.35+1.00× 0.35+0.67× 0.30≈ 0.90—above the 0.70 threshold, so the protocol routes the role to augment (AI assists the advisor, the human keeps the relationship). SCD measures sovereignty degradation through the trust capital depleted when consequential interactions lose their human anchor. Appendix C Sub-Dimension Construction This appendix gives the raw-input construction for each of the twelve sub-dimensions in Section 2. All sub-dimensions are subsequently affinely rescaled to [0,1][0,1] following the common-scale convention. C.1 TKE sub-dimensions • Codifiability (κ) ∈[0.14,1]∈[0.14,1]: what fraction of the role’s judgment can be formally represented. 40% from expert-judgment requirement on a 1–5 Likert scale (normalised as (6−ej)/5(6-ej)/5, so ej=1→1.0ej=1→ 1.0, ej=5→0.2ej=5→ 0.2), 30% from the complement of exception frequency (1−exc/1001-exc/100), 30% from documentation level on a 1–5 scale (doc/5doc/5). A fully documented role with no exceptions and no expert judgment saturates at κ=1κ=1; a role with ej=5ej=5, exc=100%exc=100\%, doc=1doc=1 hits the raw minimum 0.4⋅0.2+0.3⋅0+0.3⋅0.2=0.140.4· 0.2+0.3· 0+0.3· 0.2=0.14. The TKE formula uses (1−κ)(1-κ) so that lower codifiability raises risk. • Irreversibility (IR) ∈[0.10,1]∈[0.10,1]: 40% from minimum experience required (min(years,10)/10 (years,10)/10), 40% from training time (min(months,24)/24 (months,24)/24), 20% from knowledge concentration (1.0 if concentrated, 0.5 if not). Years are capped at 10 and training at 24 months. A role with 5 years’ experience, 6 months’ training, knowledge concentrated in a few people scores raw 0.4⋅0.5+0.4⋅0.25+0.2⋅1.0=0.500.4· 0.5+0.4· 0.25+0.2· 1.0=0.50; a junior role with no training and distributed knowledge hits raw 0.2⋅0.5=0.100.2· 0.5=0.10. • Criticality (CM) ∈[0.15,1]∈[0.15,1]: 60% from error-impact severity (low →0.25→ 0.25, medium →0.50→ 0.50, high →0.75→ 0.75, critical →1.0→ 1.0), 40% from downstream dependencies min(n/5,1) (n/5,1). A high-impact role with three dependent tasks scores raw 0.6⋅0.75+0.4⋅0.6=0.690.6· 0.75+0.4· 0.6=0.69; a low-impact role with no dependencies hits raw 0.6⋅0.25=0.150.6· 0.25=0.15. C.2 R sub-dimensions • Recovery (RC) ∈[0,1]∈[0,1]: 50% from whether a manual backup process exists (0.3 if yes, 0.7 if not) and 50% from downtime tolerance (1−min(hours/48,1)1- (hours/48,1)). A role with no manual backup and 1-hour tolerance scores ≈0.84≈ 0.84; a role with backup and 48-hour tolerance scores 0.15. • Adversarial (AD) ∈[0,1]∈[0,1]: 60% from whether the role detects novel threats today (0.2 if yes, 0.8 if not) and 40% from the human-escalation rate (0–100%, normalised to 0–1). A role that catches no novel threats and escalates 30% of cases scores 0.8×0.6+0.30×0.4=0.600.8× 0.6+0.30× 0.4=0.60. • Correlation (CR) ∈[0,1]∈[0,1]: number of dependent automated systems divided by 5, capped at 1. Five or more correlated systems saturate this term at 1.0. C.3 RE sub-dimensions • Consequentiality (CQ) ∈[0,1]∈[0,1]: 40% from whether the decision affects customers directly (0.8 if yes, 0.2 if not), 40% from whether it involves credit decisions (1.0 if yes, 0.0 if not), 20% from whether it handles sensitive personal data (0.6 if yes, 0.2 if not). A retail credit decision touching sensitive data reaches the raw maximum 0.84, which rescales to 1.0. • Jurisdictional (JU) ∈[0,1]∈[0,1]: an inner score (30% from audit bodies min(n/3,1) (n/3,1), 40% from whether HITL is required by regulation (1.0 if yes, 0.0 if not), 30% from precedent sanctions (0.8 if yes, 0.2 if not)) multiplied by a country factor: 1.2× for EU AI Act jurisdictions (Spain, Germany, Portugal, Poland), 1.1× for the UK (FCA/PRA), 1.0× for the US, 0.9× for Brazil and Mexico, 0.8× for Argentina and Chile. The asymmetric mapping for HITL (1.0/0.0, not 0.8/0.2) reflects the fact that a legally-binding HITL requirement is a hard regulatory constraint, not a soft signal. The raw product spans [0.048,1.128][0.048,1.128] and is then rescaled to [0,1][0,1], so the country multiplier preserves its directional effect even at the upper saturation. A UK role with three audit bodies, HITL required, and precedent sanctions has raw (0.3⋅1+0.4⋅1+0.3⋅0.8)×1.1=0.94×1.1=1.034(0.3· 1+0.4· 1+0.3· 0.8)× 1.1=0.94× 1.1=1.034, which rescales to ≈0.91≈ 0.91. • Reversal (RV) ∈[0,1]∈[0,1]: estimated cost to reintroduce human oversight, divided by €500K, capped at 1. A €200K reversal cost scores 0.4; €500K or more saturates at 1.0. C.4 SCD sub-dimensions • Relational (RL) ∈[0,1]∈[0,1]: 60% from interaction type (none 0.0, email 0.2, phone 0.5, video 0.7, in-person 1.0) and 40% from whether the customer expects a human (0.8 if yes, 0.2 if not). An in-person role with explicit customer expectation reaches the raw maximum 0.92 (rescaled to 1.0); a fully back-office role hits raw 0.08 (rescaled to 0). • Legitimacy (LG) ∈[0,1]∈[0,1]: 60% from brand-perception impact (1–5 scale, normalised by 5) and 40% from whether the role is publicly visible (0.8 if yes, 0.2 if not). A branch manager (impact 5, publicly visible) reaches the raw maximum 0.92 (rescaled to 1.0); a back-office data-entry role (impact 1, not visible) hits raw 0.20 (rescaled to 0). • Labor (LB) ∈[0,1]∈[0,1]: 50% from team-morale impact (1–5 scale, normalised by 5) and 50% from headcount in the role (min(n/50,1) (n/50,1)). A role held by 30 people with morale impact 4/5 has raw 0.8×0.5+0.6×0.5=0.700.8× 0.5+0.6× 0.5=0.70 (rescaled to ≈0.67≈ 0.67); 50+ people with maximum morale impact saturates at 1.0. Appendix D Threshold Calibration and Sensitivity The gate thresholds in Table 2 are derived from three converging sources: regulatory risk-tolerance standards in financial services, the asymmetric cost structure of irreversible decisions, and robustness analysis of the four practical examples in Section 5. Regulatory grounding. The EU AI Act [13] classifies credit scoring, insurance risk assessment, and employment decisions as high-risk AI applications requiring mandatory human oversight. EBA Guidelines on internal governance [12] require documented governance and accountability arrangements over institutions’ risk-taking decisions, including those that are supported or executed by automation. The RE threshold of 0.70 is calibrated to this ceiling: scores above 0.70 correspond to roles where automated operation would conflict with existing or imminent regulatory requirements in at least one of the five jurisdictions where the protocol is currently being piloted (a subset of the ten countries with explicit jurisdictional multipliers in the RE formula). Irreversibility asymmetry. Each of the four risk gates protects against an outcome whose recovery cost is asymmetric: tacit knowledge once eliminated cannot be reconstructed on demand (G2), organisational resilience once reduced cannot be restored instantly during a failure event (G3), regulatory non-compliance once incurred cannot be undone retroactively (G4), and trust capital once lost takes years to rebuild (G5). In all four cases preservation is reversible while the failure mode is not, which justifies conservative thresholds. The uniform value 0.70 is set at the point above which the underlying sub-dimension combinations produce damage exceeding what structured documentation, redundancy, regulatory remediation, or trust-restoration programmes have historically been able to recover [7, 25]. Sensitivity analysis. Table 6 reports the binding margin for each outcome in Section 5. All four examples tolerate upward threshold perturbations of at least +14%+14\% before the outcome inverts; downward perturbations are unbounded for the failing-gate cases, since they only reinforce the decision. The narrowest binding margin is +0.10+0.10 absolute (Architecture Review, TKE). Decisions driven by a single failed gate are therefore robust under the threshold uncertainty inherent to a v1 framework. Composite-driven outcomes are weight-sensitive by construction; the explicit margin to the composite threshold of 0.60 is reflected in the table’s first row. For Invoice Data Entry the margin admits a stronger statement: the composite is a convex combination of the four dimension scores 0.00,0.23,0.07,0.13\0.00,0.23,0.07,0.13\, so no weight vector summing to one can lift it above the maximum dimension score of 0.23, far below the 0.60 threshold. The automate outcome is therefore invariant to any reweighting as well as to threshold shifts; composite-driven outcomes closer to the threshold do not enjoy this bound. Configurability. The defaults reported in Table 2 are the financial-services configuration. Every threshold is configurable per domain, jurisdiction, and risk appetite; thresholds are part of the configuration that an institution must own and document. Table 6: Threshold sensitivity for the four examples of Section 5. Tolerable upward shift is the maximum proportional increase in the deciding-gate threshold that preserves the outcome. Role Deciding gate Score Threshold Margin Tolerable upward shift Invoice Data Entry Composite 0.10 0.60 −0.50-0.50 unbounded Incident Triage R 0.82 0.70 +0.12+0.12 +17.1%+17.1\% Manager Coaching SCD 0.83 0.70 +0.13+0.13 +18.6%+18.6\% Architecture Review TKE 0.80 0.70 +0.10+0.10 +14.3%+14.3\% Appendix E Automation Debt: Worked Example and Operationalisation Worked example. Consider a loan-origination process with five leaf subtasks—document digitisation, identity verification, credit-bureau pull, underwriting model scoring, and offer generation—with approximately equal average handling times so that wiw_i is uniform and ρ(P)ρ(P) reduces to the share of automate leaves. Scenario A (warning triggered). All five subtasks score automate individually. Then ρ(P)=5/5=1.00≥0.80ρ(P)=5/5=1.00≥ 0.80, and no leaf carries a regulator-mandated HITL anchor. The process triggers an automation-debt warning that individual gate analysis would have missed: five locally safe decisions compose into a fully automated end-to-end chain with no recovery point. Scenario B (saved by the HITL anchor). Same five subtasks, but underwriting model scoring is classified hybrid with hitl_required_by_regulation=truehitl\_required\_by\_regulation=true (e.g. adverse-action explainability under consumer-credit rules). Then ρ(P)=4/5=0.80ρ(P)=4/5=0.80, and the HITL-anchor condition is satisfied at the underwriting leaf. No warning fires: the regulator-grounded oversight point is treated as a structural recovery mechanism that defeats the density signal. This is the mechanic by which regulatory grounding does real work in the protocol. Hierarchical rollup mechanics. ρ is computed at every parent task in the process tree, not only at the root: each non-leaf node aggregates over the leaves of its own subtree using the same time-weighted formula, so warnings can surface at any level of the decomposition. A departmental sub-process whose leaves are all automated triggers locally even if the enclosing process as a whole stays under threshold. Relationship to automation sovereignty. Automation debt is the process-level measure of sovereignty degradation: ρ(P)ρ(P) quantifies how much of a process an organisation can no longer operate manually, and the HITL-anchor exception encodes the requirement that high density is tolerable only when at least one regulator-grounded human intervention point remains. The signal is intentionally density-only at this stage; richer risk-weighted formulations are a calibration question for the empirical-validation work plan. Appendix F Time-Indexed Protocol The protocol as defined in Sections 2–3 evaluates a role at a point in time. The risk profile of an automation decision is not static: regulatory requirements evolve (the EU AI Act phases into full application through 2026), AI capabilities improve, tacit knowledge can be partially documented over time, and the reversibility cost grows as the organisation’s dependency on the automated system deepens. PHP-AIO supports time-indexed evaluation by projecting each gate score over a decision horizon H∈1,3,5H∈\1,3,5\ years using a first-order linear approximation, clipped to the score domain: sd(H)=clip(sd(0)+δd⋅H, 0, 1)s_d(H)=clip (s_d(0)+ _d· H,\ 0,\ 1 ) (8) where sd(0)∈[0,1]s_d(0)∈[0,1] is the baseline score on dimension d∈TKE,R,RE,SCDd∈\TKE,R,RE,SCD\ and δd _d is an annual drift rate (positive: risk increasing; negative: risk decreasing). The clip operator guarantees sd(H)∈[0,1]s_d(H)∈[0,1] for any horizon and drift; non-linear refinements (logistic projection, saturating piecewise forms) are deferred to future work. Default drift rates. Table 7 reports indicative annual drifts for the financial-services configuration in the 2025–2027 regulatory phase-in window. These values are configurable per dimension and jurisdiction; empirical calibration of drift rates against multi-year observational data is part of the validation work plan. Table 7: Default annual drift rates for the financial-services configuration. Dimension Default δ Driver TKE +0.03+0.03/yr Knowledge atrophies as AI handles routine cases; exception judgment becomes rarer and harder to rebuild. R −0.02-0.02/yr AI system reliability improves; manual fallback procedures, when actively maintained, mitigate dependency risk. RE +0.05+0.05/yr Regulatory frameworks converge toward mandatory oversight; jurisdictional exposure increases. SCD 0.000.00/yr Trust effects stable in the medium term; institutional reputation changes slowly. Decision-flip horizon. The most actionable derived metric is the decision-flip horizon H∗=minH∈1,3,5:decision(sd(H))≠decision(sd(0))H^*= \H∈\1,3,5\:decision(s_d(H)) (s_d(0))\: the smallest projected horizon at which the gate outcome inverts (defining H∗=∞H^*=∞ when no horizon flips the decision). A role currently classified automate with H∗=3H^*=3 years is decision-fragile under expected drift, even though it passes today. Two derived decision types. The time-indexed protocol extends the four base decisions of Table 3 with two horizon-aware variants: • Conditional automate: gate-clear today with H∗<∞H^*<∞. Automation is approved today with a mandatory re-evaluation scheduled at H∗H^*. • Deferred preserve: gate-failed today on a dimension whose δd<0 _d<0, with sd(H)<τds_d(H)< _d projected for some H≤5H≤ 5. Preservation is maintained now, automation re-evaluation triggers when the projected score falls below threshold. Both extended outcomes are auditable: the decision record includes the projected score trajectory sd(0),sd(1),sd(3),sd(5)\s_d(0),s_d(1),s_d(3),s_d(5)\ and the re-evaluation trigger date. Operationalisation status. The time-indexed protocol is formalised here as part of the v1 protocol specification but is not yet operationalised in the reference implementation (v0.2.0). The implementation evaluates each role at a single point in time; horizon projection, the decision-flip horizon H∗H^*, and the two derived decision types are deferred to a future iteration. Empirical calibration of the drift rates against multi-year panel data, and the integration of the projection into the assessment pipeline, are jointly part of the validation work plan. Appendix G Operationalization Detail A protocol that exists only on paper does not change automation decisions. Translating the four-dimension formalism of Section 2 and the gate logic of Section 3 into a procedure that a non-research user can execute consistently imposes three design constraints. These constraints are illustrated by a reference implementation deployed for empirical validation; the implementation is one of several possible instantiations and is not part of the protocol’s specification. Input schema and observability. Each gate must reduce to a finite set of observable, falsifiable inputs. PHP-AIO formalises this requirement through a 40-field input schema (Appendix A) that maps every score sub-component of Section 2 to a structured field elicitable from process documentation, role specifications, and stakeholder interviews. The schema has seven functional groups: 6 task-context fields; 2 Gate 1 cost fields; 8 TKE fields; 5 R fields; 8 RE fields; 6 SCD fields; and 5 qualitative-context fields used for narrative justification but not for scoring. The schema is the contract between the protocol’s mathematics and operational reality: no score is computable without all relevant fields, and every scoring field maps to a specific sub-component of one of the four risk dimensions. Separation of concerns: deterministic scoring with stochastic assistance. A central design choice is to keep large-language-model (LLM) inference entirely outside the scoring path. The LLM, where used, has two assistive roles: (i) decomposing a process description (e.g., Corporate Client Onboarding) into discrete tasks for independent assessment, and (i) producing the narrative justification attached to each decision after scoring. Gate scores and the composite are computed deterministically from the structured inputs by the formulas of Section 2; identical inputs yield identical decisions, regardless of model, prompt, or runtime. This separation is deliberate: it keeps the protocol auditable under the EU AI Act traceability requirements (Art. 12 record-keeping for high-risk systems) [13] and NIST AI RMF traceability guidance (Measure function) [24], while still permitting LLM assistance where stochasticity is acceptable—decomposition is editable by the user before scoring, narratives are explanatory rather than decisive. Auditability and reproducibility. Determinism over the input schema, combined with explicit configuration of thresholds and weights, yields a fully reproducible audit trail. Every decision is traceable to (a) the structured inputs that produced it, (b) the gate scores and composite computed from those inputs, (c) the configuration version (thresholds, weights, schema) active at the time, and (d) the protocol version. Two evaluators given the same inputs obtain the same decision; the same evaluator on different days obtains the same decision; a regulator inspecting a past decision can reconstruct it from artefacts alone. This property is the operational counterpart of the deterministic-scoring constraint above and the ultimate justification for it: any framework operating under regulated AI oversight regimes must produce decisions that survive ex-post inspection [20]. Appendix H Per-Role Worked Examples This appendix expands each row of Table 4 into the gate-by-gate evaluation and the input rationale that produces the score. H.1 Invoice Data Entry → automate Gate Score Threshold Result G1 Net Benefit 50% ≥15%≥ 15\% PASS G2 TKE 0.00 <0.70<0.70 PASS G3 R 0.23 <0.70<0.70 PASS G4 RE 0.07 <0.70<0.70 PASS G5 SCD 0.13 <0.70<0.70 PASS Composite 0.10 <0.60<0.60 PASS Highly codifiable, fully documented, no expert judgment, manual fallback exists, no relational capital. Safe to automate end-to-end. H.2 Production Incident Triage → preserve Gate Score Threshold Result G1 Net Benefit 50% ≥15%≥ 15\% PASS G2 TKE 0.08 <0.70<0.70 PASS G3 R 0.82 <0.70<0.70 FAIL The triage role itself is moderately codifiable (G2 passes), but it is the organisation’s last line of defence when production breaks: no manual fallback, one-hour tolerance for downtime, five downstream automated systems depend on it. Automating it creates correlated failure modes precisely when the rest of the stack is also failing. H.3 People-Manager Coaching → augment Gate Score Threshold Result G1 Net Benefit 50% ≥15%≥ 15\% PASS G2 TKE 0.08 <0.70<0.70 PASS G3 R 0.32 <0.70<0.70 PASS G4 RE 0.07 <0.70<0.70 PASS G5 SCD 0.83 <0.70<0.70 FAIL Internal one-on-one coaching where managers expect a human counterpart, the role anchors the firm’s people-development brand, and 50 employees occupy similar positions. AI augments the coach (preparation, summaries, follow-up tracking) but the human owns the relationship. H.4 Senior Architecture Reviews → preserve Gate Score Threshold Result G1 Net Benefit 50% ≥15%≥ 15\% PASS G2 TKE 0.80 <0.70<0.70 FAIL Senior architects approving major design decisions: 80% of cases are exceptions, documentation lags reality, ten years of context required, knowledge concentrated in a handful of people, critical error impact. The judgment cannot be codified without losing the judgment itself. Declaration of Generative AI and AI-Assisted Technologies in the Writing Process During the preparation of this work the authors used Cascade (Windsurf’s AI coding assistant, powered by Claude, Anthropic) for editorial review of structure and prose, consistency checking of mathematical formulas and worked numerical examples, alignment between the paper text and the reference implementation, and bibliography curation. All AI-generated suggestions were reviewed and edited by the authors. The authors take full responsibility for the content of the publication, including the formal definitions, gate-threshold calibrations, and the empirical claims that follow once the validation work plan is executed.