HumanAI and OrgAI: what capacity has the organisation built

,
Diagrama cadrului HumanAI și OrgAI: sistemul capacității umane, stratul relațional mediat de inteligență artificială și sistemul capacității organizaționale

A group of employees using the same AI model does not constitute organizational capacity. The difference between the two is not one of scale but of architecture, and the HumanAI / OrgAI framework makes it visible, measurable and auditable.

Alexandru Angheluș · September 2026 · Based on “HumanAI and OrgAI: A Relational Framework for AI-Mediated Human and Organizational Capacity”, version 1.5, DOI 10.5281/zenodo.22295278, licensed CC BY-ND 4.0.

The question a licence count cannot answer

AI adoption is usually reported through product names, licence counts or automation volumes. Those figures show that the technology is available. They do not show which capacity has been created, where knowledge resides, how results are validated, or who holds authority.

The same interface may support a competent professional, induce uncalibrated dependence, or propagate an error throughout an organization. The central confusion is between individual AI use and organizational capacity. Without authorized sources, roles, validation, traceability, security and controlled memory, the result is aggregated use rather than governed capacity.

For a security or compliance officer the consequence is immediate and practical: in a supervisory enquiry, an audit or a risk assessment, a licence count is not an answer. It does not say which sources produced the conclusion, who verified it, who is accountable for it, or how it can be reconstructed.

Two constructs, two units of analysis

HumanAI

HumanAI denotes a situated person–AI–task–context configuration in which an AI system materially changes a person’s performance, judgment, learning or vulnerability, while the human role and decision authority remain identifiable.

The contribution may be positive, neutral or negative. Overreliance, error or skill erosion do not remove a case from the category, they describe its outcome profile. The configuration is episodic when it concerns a bounded task, and becomes stable when repeated use changes the person’s practice, trust, competence, autonomy or validation behaviour.

OrgAI

OrgAI denotes the organizational socio-technical configuration in which HumanAI episodes, AI systems, authorized institutional knowledge, roles, workflows, validation, traceability, security and control jointly mobilize a distributed capacity that cannot be attributed to a single user or model.

OrgAI is not a product, a model, an agent or a document repository. It is a property of the organizational configuration.

Reading rule: HumanAI and OrgAI describe configurations, not outcomes. A configuration may produce good, poor or unsafe results. Category membership and outcome quality are separate judgments.

Excluded cases

  1. An ignored AI suggestion with no material effect does not constitute HumanAI in that episode.

  2. A deterministic automation without an AI component is not included merely because it is complex.

  3. Multiple independently used AI licences do not constitute OrgAI.

  4. A chatbot connected to unverified documents does not demonstrate authorized organizational knowledge.

  5. A system-only decision without identifiable authority and accountability does not satisfy the governed framework.

The membership test

Classification is not established by declaration but through seven questions applied to a bounded configuration.

Test HumanAI OrgAI
Identifiable unit person, system, task and context organizational process, actors, systems and knowledge
AI contribution materially changes execution or judgment is integrated into institutional capacity
Authority human role and decision can be attributed roles, approvals and escalations are defined
Knowledge relevant sources can be delimited sources are authorized, versioned and owned
Validation the person can verify in proportion to risk validation is independent and institutionalized
Traceability the episode can be reconstructed the workflow and decision can be audited
Learning effects on the person can be tracked validated feedback updates memory in a controlled manner

Table 1. Membership and boundary criteria.

The constitutive threshold: why OrgAI is not the sum of episodes

The relationship between the two levels is one of conditional integration. Individual episodes provide local contributions. Organizational architecture selects, authorizes, coordinates, validates and retains only those contributions that can become part of institutional capacity.

OrgAI ≠ Σ HumanAIᵢ

Iorg = 1[Korg ∧ P ∧ R ∧ G ∧ S ∧ T]

The Iorg indicator expresses the minimum conceptual threshold: Korg is authorized institutional knowledge, P are processes and control points, R are roles and accountability, G is governance with validation, contestability and audit, S is security and data protection, and T is configuration and decision traceability.

If any of these components is missing, the configuration may represent connected or aggregated AI use, but it does not demonstrate governed OrgAI. Controlled learning is required for the cumulative form, not for the minimum threshold.

The transformation mechanism

  1. An actor performs a task within a delimited HumanAI configuration.

  2. The output is accompanied by sources, configuration, interventions and confidence level.

  3. A competent role validates or rejects the contribution in proportion to risk.

  4. The decision is attributed and integrated into a controlled organizational process.

  5. Accepted conclusions may update memory only through a separate adjudication workflow.

  6. Outcomes and errors are monitored, and access or rules can be withdrawn or corrected.

Epistemic decoupling: the risk that appears in no control catalogue

Epistemic decoupling is the gap between the range of claims, interpretations or options that AI makes accessible and the demonstrated capacity of the accountable actor to validate them.

Δepi(T; X, t) = A(T; X, t) − V(T; X, t)

Across a declared task set T, A is the proportion of tasks for which the system provides a usable response, and V is the proportion for which the accountable actor can produce a verified justification. The difference is calculated within the same domain and ranges from −1 to 1. A high positive value shows that access has outpaced validation.

The distinction matters for governance because it separates three questions that practice routinely conflates: what the system can generate or retrieve, what the competent actor can validate, and who is authorized to decide or execute. Access to a claim does not automatically produce justified knowledge, and technical validation does not automatically confer decision authority.

Observable signals

  1. Responses are accepted faster than their sources can be checked.

  2. Citations, explanations or calculations cannot be reproduced independently.

  3. The same output is reused across processes without reassessing context.

  4. Reported confidence rises while error-detection rates decline.

  5. Organizational memory is updated with unadjudicated outputs.

  6. Authority is formally assigned to a person, but practical constraints make contestation impossible.

Mitigation measures

  • Limit the domain and state the unknowns.

  • Cite and verify primary sources.

  • Require independent validation for high-impact outputs.

  • Separate generation from approval and execution.

  • Test trust calibration and error detection.

  • Control reuse and memory updates.

  • Preserve the right to contest, to stop, and to return to the unassisted process.

Propagation: how a local error becomes systemic risk

Ωprop = max(0, Δepi) × ρ × κ

ρ is the rate at which an output is reused or diffused, and κ is consequence criticality. Without local calibration the formula does not estimate real-world probabilities. Its role is different: it makes visible why a small error, reused frequently in a critical process, may become a major organizational risk, and why reducing decoupling has a multiplicative rather than linear effect.

Five use scenarios

7.1. Analysis and research

An analyst uses AI to identify themes, synthesize documents and formulate hypotheses. The configuration is HumanAI when the intervention materially changes the scope or speed of analysis. The corpus must be bounded, citations verified, inferences labelled as such, and the analyst’s decision retained.

The configuration becomes part of OrgAI only when sources, rights, methodology, validation and reuse are integrated into an institutional process. The dominant risk is that a plausible but unverified synthesis becomes organizational fact.

7.2. Creation, communication and marketing

AI can expand the space of concepts, audiences and creative variants. Each creator–model–brief relationship is HumanAI. OrgAI requires authorized data, asset rights, approval criteria, versions, performance evaluation and controlled feedback. Abundance does not demonstrate relevance and may produce narrative convergence or homogenized expression.

7.3. Cybersecurity

A security operations analyst uses AI to correlate alerts, formulate hypotheses and propose investigative steps. HumanAI describes the analyst–model–telemetry episode. OrgAI emerges when identities, data classification, chain of custody, sources, approval roles, logging and response procedures are integrated.

Automatic execution of proposed commands, contamination of memory with unverified indicators, or exposure of investigative data are cases in which speed has overtaken control. Destructive operations require explicit confirmation, separation of duties and rollback capability.

7.4. Compliance and evidence evaluation

AI can map requirements to policies, controls and evidence. At HumanAI level the assessor receives suggestions and syntheses. At OrgAI level the organization manages control owners, periods, versions, exceptions, approvals and evidence lineage. The existence of a document does not establish control operation, and an automated score does not demonstrate compliance.

7.5. Organizational memory and strategic decision-making

An organization connects AI to policies, projects, lessons learned and prior decisions. Retrieval is useful only if sources have status, version, owner and scope. The cumulative form emerges when validated conclusions update memory without self-confirmation and obsolete information can be withdrawn. Strategic decisions remain attributable to authorized roles.

Scenario HumanAI unit Threshold for OrgAI Dominant risk
Analysis analyst, model, corpus, question institutional sources and validation unverified citations and conclusions
Creation creator, model, brief, audience rights, approval, controlled feedback convergence and unauthorized use
Security analyst, telemetry, hypothesis chain of custody, roles, audit incorrect execution and contamination
Compliance assessor, requirement, evidence owners, periods, adjudication apparent compliance
Memory user, question, internal sources validity and validated learning propagation of obsolete information

Table 2. Scenario summary.

Demonstrative case study: assessing an incident

Status: this case is hypothetical and explanatory. The values are illustrative, not empirical findings, and do not represent the performance of any real product or organization.

An organization must assess a potential cyber incident. Inputs include alerts, logs, internal procedures, threat intelligence and prior reports. A wrong conclusion may interrupt services, destroy evidence, or cause a real incident to be missed.

The HumanAI episode

The analyst asks the model for a timeline, hypotheses and validation steps. AI reduces triage time and expands the hypothesis space, so its contribution is material. The analyst verifies events in primary sources, marks inferred claims, and retains authority over classification. The configuration remains HumanAI even when some suggestions are rejected.

Aggregated use that is not OrgAI

Several analysts use the same model independently and copy its answers into tickets. There is no source catalogue, configuration version, adjudication role or rule for updating memory. This is aggregated AI use. Activity volume does not compensate for missing architecture.

The governed OrgAI configuration

  • Sources are classified, owned and filtered before retrieval according to analyst identity.

  • Retrieved content is treated as untrusted data and cannot introduce executable instructions.

  • The model produces hypotheses linked to primary events and states missing data.

  • A separate validator adjudicates critical claims, while the decision-maker approves the operational response.

  • Commands are denied by default and require confirmation, logging and target-domain validation.

  • Only adjudicated conclusions can update case memory; rejected indicators are withdrawn and remain auditable.

Illustrative decoupling calculation

Initial: A = 0.92; V = 0.68; Δepi = 0.24

After controls: A = 0.92; V = 0.88; Δepi = 0.04

Access has not been reduced, but validation capacity has increased through primary sources, adjudication and traceability. If the reuse rate ρ is 0.80 and criticality κ is 0.90, the conceptual propagation indicator falls from 0.173 to 0.029. The values only explain the relationship among variables.

The practical observation for a security officer is that the fix was not to restrict access to the tool, the usual reflex, but to raise validation capacity. Restricting access would have lowered A, and with it the utility, without addressing the underlying problem.

Maturity: six states, none of them mandatory

The maturity model describes observable states of integration, not an obligation to reach the highest level. For some tasks, a managed HumanAI configuration is more appropriate than the cumulative form. A level is assigned to a bounded domain and process, not to an organization in the abstract.

Level Description Minimum evidence Boundary
M0 Exploratory occasional use without stable practice inventory of uses or experiment does not demonstrate stable HumanAI
M1 Episodic HumanAI AI materially changes bounded tasks artifacts and task comparator the effect is not institutionalized
M2 Managed HumanAI practice is repeatable and governed locally guidance, measurement, validation, owner more users do not imply OrgAI
M3 Connected OrgAI models access organizational sources and workflows source catalogue, identities, integration connectivity does not demonstrate governance
M4 Governed OrgAI the constitutive threshold is satisfied roles, validation, audit, security, contestability learning may remain manual
M5 Cumulative OrgAI adjudicated feedback updates controlled memory staging, approvals, history, withdrawal, testing adaptation does not demonstrate synergy

Table 3. Maturity levels.

The status of synergy: “Synergistic OrgAI” is an outcome label, not an M6 level. It applies only to a configuration and task for which comparators and risk thresholds have been evaluated explicitly.

An organization may operate at M1 in one domain, at M4 in another, and prohibit AI use in a third. Applying a single level to a whole organization is itself an assessment error.

Governance: roles, incompatible shortcuts and threats

Governance is not a separate chapter of the framework but the element that constitutes the category. Removing authority, validation or traceability does not weaken an OrgAI configuration, it moves it out of the category.

Role Primary responsibility Incompatible shortcut
Process owner defines purpose, scope and acceptance criteria delegating purpose to the vendor or model
Knowledge owner authorizes sources, validity and withdrawal treating every accessible document as authoritative
User or operator performs the task and records interventions copying output without review
Validator tests claims against criteria and evidence validating one’s own high-impact output without controls
Decision-maker accepts consequences and authorizes action assigning responsibility to AI
Security and privacy controls access, isolation, retention and incidents relying solely on vendor terms
Audit or oversight tests reconstruction, exceptions and effectiveness treating policy existence as operating evidence

Table 4. Roles and separation of duties.

Threat Mechanism Minimum controls
Prompt injection retrieved content manipulates model behaviour separate instructions from data, sanitize, constrain tools, test adversarially
Unauthorized disclosure prompts, context or logs expose protected data classification, minimization, access control, retention limits, redaction
Privilege confusion the model acts with broader rights than the user identity propagation, least privilege, target checks, deny by default
Hallucinated authority plausible output is treated as an approved decision source verification, status labels, validator and decision-maker
Memory contamination unverified feedback becomes institutional truth staging, adjudication, provenance, rollback and withdrawal
Automation bias human review becomes formal rather than effective error-detection tests, time allocation, independent evidence, contestability
Common-mode failure one defect propagates across downstream uses diverse sources, dependency mapping, monitoring and kill switch

Table 5. Threat model and minimum controls.

What the framework does not demonstrate

Much of the framework’s practical value lies in what it refuses to confirm.

Anti-pattern Why it is incorrect Correction
AI as authority output is treated as the decision retain a decision-maker, validation and contestability
Nominal human in the loop a person approves without time, competence or evidence access measure actual detection and intervention capacity
OrgAI by licence count account numbers are confused with integration evaluate sources, roles, workflows and controls
Memory without adjudication all feedback becomes institutional truth separate raw feedback from approved updates
Single score trade-offs and risks are hidden report dimensional profiles and thresholds
Convenient comparator gain is measured against a weak baseline include the best realistically available process
Irreversible automation a suggestion triggers action without control deny by default, confirm, log and support rollback
Compliance label the concept is treated as legal or audit evidence demonstrate obligations and control effectiveness separately

Table 6. Anti-patterns and corrections.

Six explicit clarifications follow: HumanAI does not mean that a person becomes AI or that a system acquires human status; HumanAI is not synonymous with success; OrgAI is not the name of a model or a commercial package; access to an internal corpus does not demonstrate provenance, validation or authority; automation does not transfer accountability to AI; and using the term OrgAI does not make an organization mature, safe or compliant.

The regulatory boundary

The framework supports analysis and control design but does not establish legal compliance. Systems with material effects on rights, safety, employment, finance, health, security or public services require domain-specific legal assessment, data protection analysis, competent human oversight, contestability, separation of duties and evidence preservation. The HumanAI or OrgAI labels do not replace applicable obligations.

From framework to implementation

Stage Activity Exit criterion
1. Delimitation select process, tasks and consequences approved scope, owner and exclusions
2. Baseline measure the process without the new configuration comparator, thresholds and task set
3. Controlled HumanAI pilot with users, rules and validation documented material contribution and risk profile
4. Knowledge catalogue and authorize sources owners, validity, access and withdrawal
5. OrgAI threshold integrate roles, workflow, audit and security Iorg test satisfied with evidence
6. Operational pilot test normal, boundary, adversarial and unavailable states approved acceptance criteria and residual risk
7. Controlled learning introduce adjudicated feedback and withdrawal updatable, auditable, reversible memory
8. Monitoring track profiles, changes and incidents periodic review and stop conditions

Table 7. Implementation pathway.

Stop conditions

Implementation must stop or return to the previous state when data exposure, loss of decision attribution, degradation in error detection, unauthorized access, memory contamination, inability to reproduce critical results, or an unvalidated configuration change occurs.

The computational companion

The HumanAI and OrgAI Framework Calculator is the separately versioned digital companion to the framework. It operationalizes six relationships defined in the whitepaper: epistemic decoupling, propagation exposure, the constitutive OrgAI threshold, material contribution, synergy and maturity classification.

It should be used only after defining the unit of analysis, task, context, observation period, comparator, materiality threshold and evidence standard. Every organizational condition must be supported by evidence, and an unknown state never counts as demonstrated. The local release calculates in the browser and can export a JSON assessment for reproducibility and audit. Exported values remain user-entered claims until linked to evidence; results are not empirical validation, certification, legal advice or a compliance determination.

Software citation: version 1.2.0, DOI 10.5281/zenodo.22884721.

The decisive question

The framework’s value does not depend on who first used the HumanAI notation, nor on the absolute absence of a similar expression for OrgAI. It depends on definitional clarity, on the separation of constructs from outcomes, on the relational model, and on the ability to make accountability, validation, authority and risk visible.

In practice, the decisive question is not whether an organization uses AI. It is whether the organization can demonstrate which capacity it has created, in which domain, from which sources, through which roles, with what validation, and within which limits. HumanAI makes the person’s configuration visible. OrgAI makes visible the institutional architecture that can turn it into controlled collective capacity.

For security and compliance professionals the operational consequence is that assessment applies to a bounded configuration rather than to a model, and that validation, not access, remains the central problem between the availability of technology and real capacity.

Source

Angheluș, A. (2026). HumanAI and OrgAI: A Relational Framework for AI-Mediated Human and Organizational Capacity. Version 1.5, 4 September 2026. DOI: 10.5281/zenodo.22295278. Licensed under Creative Commons Attribution-NoDerivatives 4.0 International.

Further reading

The instrument that operationalises the relationships described here is presented in the HumanAI and OrgAI Framework Calculator, version 1.2.0.

Frequently asked questions

What is HumanAI?

HumanAI, also written HumanAI, denotes a situated person, AI system, task and context configuration in which the system materially changes a person’s performance, judgement, learning or vulnerability, while the human role and decision authority remain identifiable.

What is OrgAI?

OrgAI denotes the organisational socio-technical configuration in which HumanAI episodes, AI systems, authorised institutional knowledge, roles, workflows, validation, traceability and security together mobilise a distributed capacity. It is not a product, a model or a document store, but a property of the configuration.

What is the difference between HumanAI and OrgAI?

It is not a difference of scale but of architecture. OrgAI is not the sum of HumanAI episodes. The constitutive threshold requires, cumulatively, authorised knowledge, processes, roles and accountability, governance with validation and contestability, security and traceability. If any is missing, the result is aggregated use, not governed capacity.

What is epistemic decoupling?

It is the distance between the range of claims AI makes accessible and the demonstrated capacity of the accountable actor to validate them, computed as the difference between the proportion of tasks with a usable answer and the proportion with a verified justification, over the same declared task set.

Do multiple AI licences amount to OrgAI?

No. Multiple licences used independently are aggregated use. A seat count demonstrates no authorised sources, roles, independent validation, traceability or controlled memory, and under audit a licence count answers no supervisory question.

What maturity levels does the framework define?

Six observable states, from M0 explorer to M5 cumulative OrgAI. A level is assigned to a bounded domain and process, not to an organisation in the abstract. The same organisation can be at M1 in one domain, M4 in another, and prohibit AI in a third.

Does the framework establish legal compliance?

No. It supports analysis and control design, but does not replace domain-specific legal assessment, data protection analysis, competent human oversight or separation of duties. The HumanAI and OrgAI labels do not replace applicable obligations.

Skip to content