Article 1 ended with a question: how and where exactly could AI help us in our expert disciplines?
The answer might assume a binary. Tasks AI can do. Tasks AI cannot do. Draw the line, and you have your strategy.
Still the practice breaks that idea.
Because the most interesting tasks were not on either side. They are in the middle. Tasks where the AI produced something genuinely useful — not garbage, not hallucination, not sycophantic validation — but a real, structured, substantive draft. And yet that draft is not the deliverable. It can not be. It needs practitioner hands on it. Restructuring. Political calibration. Removal of confident-sounding recommendations that would die on contact with organizational reality. Addition of context that no training dataset contains.
Take a continuity plan. Real engagement. The AI writes a complete draft. Solid structure, correct clauses, reasonable recovery strategies — actually useful as a starting point.
But.
The plan does not account for the fact that the backup site has a capacity problem everyone knows about but nobody has documented.
It does not reflect the informal agreement between the IT director and the COO about who really owns the activation decision.
It does not carry the memory of the last exercise that failed because the communication tree assumed people would answer their phones at 4 AM.
You take that draft and turn it into a real plan. Not by starting over. By working ON the AI output. Modifying it. Enriching it. Taking responsibility for it.
That is not automation. That is not human-only work. That is something else entirely.
The pattern held across every engagement, every model, every document type.
Some tasks where the AI output IS the deliverable. You do not touch it. A compliance checklist generated against ISO 22301 clauses. A maturity assessment matrix populated from structured data. An impact cascade computation. The rules are explicit, the output is verifiable, and modification adds nothing. The AI handles it. Done.
Some tasks where the AI output is the STARTING POINT of the deliverable. You work on it, reshape it, inject expertise, and sign it. The continuity plan. The audit report. The risk treatment recommendation. The BIA narrative. The AI produces. You decide.
Some tasks where no AI output enters the deliverable at all. You alone. Arbitrating unrealistic RTOs in front of the executive committee. Conducting an interview where the real objective is not the documented output but the political alignment happening in the side conversation. Deciding at two in the morning whether the situation warrants full activation or a wait-and-see. The AI can provide background data, but the deliverable — the decision, the arbitration, the facilitation — is entirely yours.
Three zones. Three fundamentally different relationships between the AI output and the final deliverable.
The observation itself is not revolutionary. Any practitioner who has spent time with these tools recognizes the three modes intuitively.
So I went looking for the protocol. There has to be one already, somewhere in the literature.
There is not.
The academic work is rich. Vaccaro and colleagues at MIT analyzed 106 experimental studies on human-AI teams and found that the team underperforms AI alone in decision tasks, but outperforms both in creation tasks. A crucial insight. No operational method.
Haupt and Brynjolfsson argued that humans and AI should be evaluated jointly, not separately. Important position. No upstream protocol for building the partition.
Tong synthesized sixty years of human-AI collaboration research and identified the same performance paradox. Pareschi proposed a centaurian design architecture. Loaiza and Rigobon identified five irreducibly human capabilities — empathy, presence, opinion, creativity, hope.
Every contribution advances the field. None of them answers the question a working practitioner actually has:
Take my thirty-one BCM activities. Decompose them into elementary tasks. Tell me which ones go where — in a way that is reproducible, auditable, and independent of whatever AI model happens to be dominant this quarter.
The frameworks exist. The protocol does not.
So we built it.
Not from theory projected onto practice. From practice formalized into theory. The starting point was not “what does the AI literature say about task allocation?” The starting point was: what does a BCM practitioner actually do every day, and what happens when AI enters each of those activities?
The method had to satisfy three constraints that no existing framework addressed.
Discipline-agnostic. Applicable to BCM today. To risk management or information security tomorrow. To any expert discipline governed by a formal standard.
Technology-agnostic. The classification cannot depend on whether the AI is ChatGPT, Claude, Gemini, or something that does not exist yet. Next quarter's model release should not invalidate this quarter's classification.
Observable. Based on deliverables, not on cognitive states or subjective assessments of “AI capability.”
The criterion landed on something simple. The relationship between the AI output and the final deliverable.
Three sequential questions. Can the AI do it? If yes, is the deliverable identical to the AI output, with no modification? If yes: the AI handles it alone. If no: does AI-produced content appear in the final deliverable? If yes: collaboration. If no: practitioner alone.
Three questions. Any task. Any discipline. Observable, replicable, auditable.
The three categories received names. Deterministic — the AI output is the deliverable. Mixed — the AI produces, you modify and decide. Strategic — you alone, no AI content in the deliverable.
D, M, S.
What this changes
The shift from “AI can or cannot do this” to “what is the relationship between the AI output and the final deliverable” may sound like semantics.
It is not.
The traditional question — can AI do this task? — forces a capability assessment of the AI itself. That assessment changes every six months as models improve. It depends on the specific tool, the specific prompt, the specific configuration. It is unstable by nature.
The D/M/S question — what happens to the AI output? — assesses the task, not the tool. A continuity plan is M not because today's AI is not good enough to write it alone, but because the plan structurally requires practitioner judgment, political context, and responsibility assumption that no AI can provide.
That classification is stable. It survives the next model release.
The method also forces a confrontation with an uncomfortable truth. We spend a lot of time on tasks that do not require our judgment. Not because we are lazy. Because the profession was designed before AI existed. Every compliance matrix, every template population, every deterministic computation was built assuming a human would do it — because there was no alternative.
Now there is.
The reverse is equally true. Some tasks that look simple are irreducibly complex. Conducting an interview looks like “ask questions, write answers.” But the real skill is reading the interviewee, adjusting the line of questioning in real time, catching the thing they almost said but did not, and knowing which silence to fill and which to let breathe.
No model does that.
D/M/S does not judge the practitioner. It maps the work as it actually is, and reveals where the AI adds value, where it needs supervision, and where it has no business being.
But knowing the three zones exist is not the same as knowing where each of your tasks falls. That requires applying the method. To something real. To something complete. To a full discipline — every activity, every task — and seeing what comes out.
That is what happened with BCM.
Next: Article 3 — When you actually do the work. 104 tasks. 31 activities. And a number that reframes the profession: 53%.