
How Much of a Job Can AI Automate? What Remains valuable is not the leftover task
In my last post I argued that governing AI is a more durable bet than racing to build with it. The obvious follow-up question is the harder one, and it’s the question I now get asked in almost every client conversation, usually by someone who has just watched an agent do in four minutes what used to take their team a week:
How much of a job can actually be converted into an AI-executable workflow — and what is still worth paying for once that conversion happens?
Most of the public debate answers this at the level of job titles. That’s the wrong unit of analysis. Jobs don’t get automated; tasks do. And once you look at tasks, the answer gets both more measurable and considerably more uncomfortable.
The conversion rate is already higher than most leaders think
We finally have task-level evidence instead of survey vibes. Anthropic’s Economic Index tracks what people actually delegate to a model, mapped against the U.S. Department of Labor’s O*NET task taxonomy.
Three findings matter for this question:
- Roughly 49% of jobs in the sample have seen at least a quarter of their constituent tasks performed with AI — up from about 36% a year earlier. Around 4% of occupations see it across three-quarters of their tasks.
- Of observed usage, 68% sits on tasks rated fully feasible for a model working alone. Only about 3% of usage sits on tasks rated not feasible. Delegation is concentrating on the genuinely convertible.
- API traffic runs roughly three-quarters automated, versus a near-even split on the consumer product. That’s the tell. When a task migrates from a chat window into a pipeline, the human turn count drops toward zero — and it stops being a productivity aid and becomes an executable workflow.
So the honest answer to “how much” is: for a large share of knowledge roles, somewhere between a quarter and half of the task inventory is already convertible today, and the frontier is moving through the remainder in the direction of more autonomy, not less.
But that’s the easy half of the question.
The uncomfortable part: the residual is not automatically the valuable part
There’s a comforting story we tell ourselves — AI takes the drudgery, humans keep the interesting work. The task-level data does not support it.
When Anthropic ran the thought experiment of removing AI-covered tasks from job descriptions, the first-order effect was to deskill the average job, because the tasks currently covered skew toward the ones requiring more education. Technical writers, travel agents, teachers: what’s left after you subtract the model’s coverage is often the coordination, the chasing, the formatting, the sitting-in-the-meeting.
Pair that with Anthropic’s labor-market analysis, which found no clear unemployment signal in high-exposure occupations as of early 2026, but did find hiring of 22-to-25-year-olds into the most exposed roles slowing by roughly 14% against a counterfactual. The pipeline compresses before the headcount does. Entry-level work is precisely the “do the convertible tasks under supervision until you develop judgment” apprenticeship that the conversion eats first.
So the strategic question isn’t “will my job be automated.” It’s “when the convertible tasks leave, is the residual a promotion or a demotion?”
That depends almost entirely on whether you own the part of the workflow that cannot be delegated. And that part has a name in every AI governance framework written to date: accountability.
A practical conversion audit for your own role
Before deciding what to defend, decompose. Here is the audit I run with clients, borrowed structurally from the MAP function of the NIST AI Risk Management Framework (AI RMF 1.0) — MP-1 context of intended use, MP-3 stakeholder impact, MP-4 risk prioritisation.
List every recurring task in the role. Score each on four axes:
| Axis | Question | Why it matters |
|---|---|---|
| Specifiability | Can success be defined in writing, in advance, without you in the room? | Unspecifiable work can’t be converted — but it also can’t be scaled or defended. |
| Feasibility | Could a competent model do this alone, given the right context and tools? | This is the raw conversion ceiling. |
| Reversibility | If it’s done wrong, can the decision be unwound? | A mis-sorted ticket is cheap. A denied credit application, a mis-scoped data room permission, a wrongly redacted disclosure document is not. |
| Attributability | When it goes wrong, whose name is on it? | This is the axis that survives everything. |
The pattern is consistent across the roles I’ve audited:
- High specifiability, high feasibility, high reversibility — retrieval, summarisation, first-draft generation, format conversion, control-language mapping, reconciliation against a defined rubric. Convert these now. Defending them is a losing position and, frankly, keeping them is a waste of a professional.
- High feasibility, low reversibility — eligibility determinations, access provisioning, disclosure decisions, anything touching a regulated outcome. Convertible in execution, not in authority. The model drafts; a named human owns.
- Low specifiability — judgment under conflicting stakeholder interests, negotiating a finding with an auditor, telling a CEO their flagship AI feature isn’t defensible. Not convertible, and the reason is not model capability. It’s that nobody can write down the success criteria in advance, which means nobody can hand over the consequences either.
What remains valuable: five capabilities that survive conversion
1. Specification — turning tacit process into a testable spec
The bottleneck on agentic deployment turns out not to be model capability. Deloitte’s 2026 survey of 3,235 leaders found roughly three-quarters of enterprises expecting to use agentic AI at least moderately within two years, while only about 21% had a mature governance model for autonomous agents. Every credible study lands in the same place: integration, data quality, and decision rights are what stall, not intelligence.
Which means the person who can take an undocumented process living in three people’s heads and render it as an explicit, bounded, testable specification — inputs, tools, permitted actions, escalation thresholds, definition of done — is doing the work that makes conversion possible at all. That skill maps directly to ISO/IEC 42001 Annex A.6 (AI system lifecycle) and A.9.2 (processes for responsible use). It is also the least automatable thing in the building, because it requires knowing which undocumented exceptions actually matter.
2. Oversight design — and the difference between oversight and theatre
Grant Thornton’s 2026 AI Impact Survey found only 5% of organisations allow agents to execute high-stakes decisions without human review. Encouraging, until you check whether the review can actually intervene.
Kiteworks’ 2026 annual survey scored AI governance maturity at 35 out of 100 across 459 organisations — roughly 7 of 19 measured capabilities deployed. Only about 26% restrict AI agents to authorised tasks and data scopes. Only about 21% can automatically terminate a misbehaving agent’s access, and among organisations running AI in production, 23% have never tested their termination process end to end. Gravitee’s 2026 survey of 900+ practitioners found more than half of deployed agents running with no security oversight or logging at all, and 88% of organisations reporting confirmed or suspected agent security incidents in the year.
A human in the loop who cannot actually override, disregard, or halt the system is not a control. It is an accountability sink — a place to put blame with no capacity to prevent harm. EU AI Act Article 14 is explicit on this point: human oversight for high-risk systems means the demonstrated capability to intervene, interrupt, and disregard output. Designing oversight that meets that bar — thresholds, kill switches that have been tested, escalation paths with named owners — is durable, senior, and currently very scarce work.
3. Evidence — proving the workflow behaved
An automated workflow that cannot be reconstructed after the fact is a liability with good throughput. Four questions have to be answerable from your logs: Who authorised this? What context did the system have? What did it decide? Was that consistent with policy?
This is not aspirational. EU AI Act Article 26 obliges deployers of high-risk systems to ensure staff competence, monitor operation, notify incidents, retain logs for at least six months, and inform affected workers. ISO 42001 Clause 9.2 wants internal audit evidence, not intentions. When I led VDR through ISO 42001 Stage 2 certification, the difference between passing on the first attempt and a nonconformity was almost never whether a control existed. It was whether we could produce the artifact that proved it operated.
Evidence production is where AI-executable workflows create more human work, not less — and it’s higher-status work than what it replaced.
4. Boundary judgment — the jagged frontier
The Dell’Acqua field experiment with management consultants remains the cleanest finding in this literature: AI improved performance inside its capability frontier and degraded performance outside it, because people accepted plausible-but-wrong output. Anthropic’s own data shows the largest productivity gains on complex work — where reliability is simultaneously lowest.
That combination defines the residual professional job: knowing where the frontier runs for your domain, and catching the confident failure. It cannot be delegated to the system whose blind spot you are compensating for. It also can’t be learned from a framework — it comes from having done the task manually enough times to feel when an answer is wrong before you can articulate why. Which is exactly what the compression of entry-level work threatens, and why serious firms should be deliberately preserving some manual reps for junior staff even where automation is available.
5. Accountability — the thing that structurally cannot convert
ISO 42001 Clause 5.3 requires assigned roles and responsibilities for the AI management system. NIST AI RMF GOVERN 1.1 and GV-3 require accountability structures and defined roles. EU AI Act Article 4 has required AI literacy across staff since February 2025. Every one of these instruments makes the same structural assumption: a named human being carries the consequence.
You can automate the analysis, the drafting, the monitoring, the reconciliation, and the reporting. You cannot automate the signature. Someone has to be answerable to a regulator, a board, an auditor, a customer whose data was in scope. SAP and Oxford Economics surveyed 2,600 leaders across 13 countries and found 69% either unsure or believing they deploy agents faster than they can govern them. That is not a tooling gap. It’s an unfilled seat.
The self-application test
It would be dishonest to run this analysis on everyone else’s job and not my own. So: consulting is roughly 60% convertible, and I’ve converted most of it.
Drafting gap-assessment language against Annex A controls, mapping ISO 27001 controls to NIST CSF 2.0 subcategories, generating first-pass policy text, building assessment logic, summarising a 200-page vendor security package — all of that runs as workflow now, and my throughput is several times what it was. What did not convert: deciding whether a control is effective rather than present; sitting across from a certification body and defending a scoping decision; telling a client the AI feature they’ve already announced needs an impact assessment before launch; carrying the professional judgment that an audit opinion rests on.
The convertible 60% got faster. The remaining 40% got more valuable, because there is now far more AI in production needing someone to sign for it. That asymmetry is the whole thesis. It holds for me because I owned the accountable end of the workflow before the conversion started. For people who owned only the execution end, the same conversion runs the other direction.
What to do about it this quarter
- Run the conversion audit on your own role. Four columns: specifiability, feasibility, reversibility, attributability. Be ruthless about which of your tasks are just well-paid formatting.
- Convert your own high-reversibility tasks before someone converts them for you. Owning the automation of your work is a fundamentally different position from being its subject.
- Move up the accountability axis deliberately. Get named on something. Own an inventory, an oversight threshold, an internal audit, a supplier assessment under ISO 42001 A.10.3.
- Learn to produce evidence, not just outcomes. Logs, artifacts, defensible decision records. This is the skill that converts a technologist into a governance practitioner.
- Protect the apprenticeship. If you manage people, do not let AI eat every rep that builds boundary judgment. You are buying throughput today with capability you’ll need in three years.
The uncomfortable summary: a large and growing share of any knowledge job converts into an AI-executable workflow. What remains valuable is not the leftover tasks — it’s the specification, the oversight, the evidence, the boundary judgment, and the signature. Those five things are exactly what AI governance is made of, which is why the governance seat keeps getting more valuable while the execution seat gets cheaper.
AI-executable workflow, AI automation tasks vs jobs, human oversight AI, ISO 42001, NIST AI RMF, EU AI Act Article 14, AI governance career
Work with DISC InfoSec
DISC InfoSec helps B2B SaaS and financial services organisations convert AI adoption into something defensible — AI system inventories, ISO/IEC 42001 AIMS implementation, NIST AI RMF profiles, EU AI Act readiness, human oversight design, and the evidence packages that survive an external audit. I led ShareVault through ISO 42001 Stage 2 certification on the first attempt as an internal practitioner, not a spectator.
If you’re standing up AI-executable workflows and you don’t yet have a clear answer to who is accountable when this acts on its own, that’s the conversation to have now rather than after the incident.
Disc — Principal Consultant, DISC InfoSec CISSP, CISM | ISO 42001 & ISO 27001 Lead Implementer | PECB Authorized Training Partner
📅 Book an appointment: 📧 info@deurainfosec.com 📞 (707) 998-5164 🌐 deurainfosec.com
Sources referenced
- Anthropic Economic Index reports (Jan 2026, Mar 2026) and Labor market impacts of AI: A new measure and early evidence
- Deloitte, State of Generative AI in the Enterprise 2026 (3,235 leaders, 24 countries)
- Grant Thornton, 2026 AI Impact Survey
- Kiteworks, 2026 Data Security and Compliance Risk Annual Survey (459 organisations)
- Gravitee, State of AI Agent Security 2026 (900+ respondents)
- SAP / Oxford Economics, Value of AI Report 2026 (2,600 leaders, 13 countries)
- Dell’Acqua et al. (2023), field experiment on AI and consultant performance
- ISO/IEC 42001:2023; NIST AI RMF 1.0 (NIST AI 100-1); Regulation (EU) 2024/1689 (EU AI Act), Arts. 4, 14, 26
Download the AI Governance & Cybersecurity pdf file
MachineLearning & Artificial Intelligence
AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do
Your Shadow AI Problem Has a Name-And Now It Has a Score
Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit
DISC InfoSec blog | DISC InfoSec Site
- How Much of Your Job Can Become an AI-Executable Workflow — and What’s Left Standing When It Does
- The AIMS/ISMS readiness ladder: seven steps from curious to certified
- AI Governance Careers: The Skills Gap Nobody Is Filling (2026)
- AI Governance & Cybersecurity That Holds Up Under Scrutiny
- “Sorry, Typo”: Why a Markdown File Is Not a Security Control




















