A Safety Framework for the AI Era

Human, AI, & Organizational Performance

Adopting AI is the move everyone is making.

Knowing what you need, what to choose, and whether your work system stays safe,

that is the hard part.

HAOP is the framework for the hard part: anticipate and identify the hazards AI introduces, and know how to maintain control.

White Paper · Rev 4.1 Workbook · In development Tools · In development Pilot requests open
The Three-Performer Model

How humans, AI, and organizations perform together is the new frontier of occupational safety.

Examine AI deployment through three performers: the organization authors and governs the work system, the human and the AI perform inside it, and work as done emerges from all three performing together.

ORGANIZATIONAL PERFORMER authors and governs the work system allocates functions · establishes conditions: governance · incentives · metrics · resources · authority · procedures · procurement performer envelope HUMAN PERFORMER interprets conditions exercises judgment adapts as work unfolds catches weak signals performer envelope AI PERFORMER generates · ranks · routes predicts · recommends executes configured workflows optimizes within constraints transition points interfaces · handoffs WORK AS DONE emerges from all three performing together
Fig. 01 · The three-performer architecture · from White Paper Rev 4.1
Five Hazard Domains

What hazards does AI introduce into the work system?

HAOP examines AI deployment across five connected domains. Open a card to see the question each domain brings into view.

Domain 1

Physical interaction and machine agency

When AI can move, initiate, authorize, or control physical activity.

Robotics, automated equipment, process control, machine initiation, unsafe operating envelopes, and actions that reach the physical environment.

What can the system cause to happen in the world?

In the white paper →
Domain 2

Psychosocial conditions

How AI changes the conditions under which people work.

Surveillance, scoring, pacing, work intensification, alert burden, reduced autonomy, and continuous algorithmic evaluation.

What does this system make work feel like and require from people?

In the white paper →
Domain 3

Human performance and verification

Whether people can still understand, check, and correct the work.

Automation bias, skill degradation, symbolic approval, alarm fatigue, and verification demand that exceeds the conditions provided.

Can the human still perform the role the system assigns them?

The signature hazard: Verification Overrun →
Domain 4

Information and knowledge integrity

Whether the system's representation stays connected to operational reality.

Closed informational loops, representation–reality mismatch: missing context, stale data, false coherence, weak anchors, and outputs that appear more complete than the evidence supports.

What keeps the representation correctable by reality?

In the white paper →
Domain 5

Work-system design and control allocation

Who decides, controls, verifies, and carries the consequences.

Poor function allocation, procurement before purpose, unclear authority, fragmented vendor control, accountability gaps, and decisions made without the ability to intervene.

Who controls the consequential conditions of the work?

In the white paper →
Hazard identification, not blame assignment.
Human Oversight

A human in the loop is not necessarily a human in the design.

A person may appear in an AI-enabled workflow and still be unable to provide meaningful verification. The difference begins before the system is deployed.

HITL / An operating position

Human in the Loop

A person is placed at a point in the operating workflow to review, approve, correct, pause, or intervene.

The human is visible in the process. That alone does not establish that they can understand, verify, or control what the AI is doing.

Where does the human appear?
HITD / A design-time decision

Human in the Design

At design time, the organization decides that a human must perform a consequential verification function, and builds the workflow around that requirement.

The work must give the verifier what the verification needs: domain knowledge, evidence and context, time, authority, and a safe path when the check cannot be completed.

Was the verification designed to work?
A human can be added to the loop. A verifier must be designed into the work.

When the requirement to check exceeds the capacity to check, HAOP names that hazard Verification Overrun →

Apply HAOP

Run the method against a real workflow.

HAOP is a proposed framework. Pilot work examines usability, consistency, and whether the method identifies consequential conditions that existing assessments miss. That is exactly why participation matters now.

Request a Pilot
In development

The HAOP Workbook. Operationalize HAOP with a work-design sequence and tools.

Step 01

Map the workflow

Step 02

Allocate functions

Step 03

Place verification gates

Step 04

Assign control

The work-design sequence the HAOP Workbook will operationalize.

The Foundation

HAOP: A Safety Framework for the AI Era

White Paper · Rev 4.1 · Deposited July 19, 2026 · DOI 10.5281/zenodo.21445835

The three-performer model, five hazard domains for AI-enabled work, eight operating principles, and Accountability by Control: responsibility mapped to whoever holds control over a function, its design, and its operating conditions, before failure rather than after.

HUMAN adapts to conditions ORGANIZATION designs the container AI acts on representation HANDOFF who controls what? BOUNDARY where must work pause? VERIFICATION GATE representation checked against reality ANCHORS where reality corrects the representation human expertise physical measurement hard limits (math, physics) ground-truth outcomes OPERATIONAL REALITY grounding is a control
Fig. 02 · The three-performer system
Pilot It. Challenge It.
[email protected]

One address, read by the author. Run the method against a real workflow, bring field evidence, or challenge the framework. Disagreement is a contribution.

The Record
White Paper Rev 4.1 · deposited July 19, 2026doi.org/10.5281/zenodo.21445835
Verification Overrun · working paper, v2.1doi.org/10.5281/zenodo.20874288
The Collapse of Correction · preprintdoi.org/10.5281/zenodo.20856121
ORCID · Jaina Ko0009-0007-2559-4035