HALA: Human-AI Layered Architecture
A pattern language for the things AI can say that humans can't.
Updated Jan 2026“If a role is socially costly, politically dangerous, or career-limiting for a human, it is a prime candidate for an AI pattern.”
5 processing layers, plus a separate Decision Output stage that isn't a layer itself — it's where every layer's output has to land: a signed human decision.
The Problem
Organizations systematically fail to surface certain truths—not because people don't know them, but because saying them carries unacceptable personal cost.
→ Career risk if you championed it
→ Political suicide
→ Labeled as not a team player
→ Dismissed as speculation
HALA addresses this by designing AI systems that can occupy these roles—saying what needs to be said without the human bearing the social cost.
Accountability, Not Laundering
A sharp reader will have already spotted the problem with the framing above: if the AI says the uncomfortable thing, does that just let the human off the hook? “The system said it” is a benefit right up until it becomes a way to launder a decision without anyone owning it. That isn't a hypothetical edge case — it's the central objection to this entire pattern language, and it deserves a design answer, not a disclaimer.
The resolution is a first-class design principle, not an afterthought:
A HALA pattern may own the claim. It never owns the decision. Every worked example in this language — including the EHR migration scenario below — ends the same way: a named human reviews the pattern's output, the evidence and dissent behind it, and signs the decision. Not “the system was right.” Override Protocol makes overriding any Agency-layer output a first-class, low-friction action; Decision Historian makes the record of who decided, and on what basis, permanent and searchable. Together they're what make this a resolution instead of a promise.
There is a second objection this language has to face honestly: the social cost of dissent may not be eliminated — it may be relocated. Someone chooses to deploy Mr Unpopular; someone invokes Kill Switch Advocate in the meeting where the CFO's project is on the table; and everyone in the room knows who. Whether AI truth-telling reduces the total social cost of surfacing uncomfortable truths, or merely transfers it to the invoker, is an empirical question — the central one, in fact. It is stated as a falsifiable hypothesis in Open Problems below, not assumed away.
See each pattern's Connections section in the gallery below for the specific trigger/gate/complete/police relationships this creates.
Situating HALA
HALA did not emerge in a vacuum. The problem it addresses has been documented for decades in organizational behavior, and its riskiest bets have been tested — sometimes unfavorably — in adjacent forms. Situating the patterns in that literature is part of the epistemic discipline the patterns themselves demand: the strongest published challenge to this language is engaged below, not omitted.
Organizational silence and the economics of voice5678910
HALA's core question — what true and valuable things go unsaid — is not a private observation; it names a phenomenon this literature has documented for decades. Morrison and Milliken described organizational silence as a systemic property, produced by managerial structures, not individual timidity [5], and later found that the most common reason employees withhold input is fear of being seen as troublemakers, with futility close behind [6]. Detert and Edmondson traced the self-censorship rules people carry between jobs — "don't embarrass the boss in public" — that operate even when the current environment is safe [7]. Edmondson showed psychological safety is a team-level condition that predicts learning behavior [8]; Hirschman framed voice as one of only three responses to organizational decline [9]; Dutton and Ashford showed that even raising an issue is an act of impression management with career stakes [10]. HALA's premise restates this literature as an engineering constraint: silence is incentive-compatible, so truth-telling must be made incentive-compatible by design — by moving the costly role onto infrastructure that cannot pay career costs.
Structured dissent — and its documented failure mode23411
Organizations have tried institutionalizing dissent before: Janis prescribed devil's advocacy as an antidote to groupthink [2], and Schwenk's meta-analysis found structured dissent techniques do improve decision quality over expert-led consensus [4]. But the strongest challenge to HALA's Uncomfortable Agency layer comes from the same tradition: Nemeth and colleagues found that an assigned devil's advocate underperforms an authentic dissenter — people discount dissent they know is role-played, and it fails to stimulate the divergent thinking real dissent provokes; worse, it can create the illusion of having considered alternatives [3]. Argyris documented how organizational defensive routines absorb and neutralize exactly such rituals [11]. An AI dissenter is, in one reading, the ultimate assigned dissenter — so if AI dissent behaves like Nemeth's devil's advocate, this layer produces theater, not decisions. HALA's wager is that AI dissent differs on the dimensions that plausibly drive the discounting: it is evidence-gated (Grounding Contract), persistent rather than performed on request, career-blind rather than strategically motivated, and its track record is auditable (Trust Calibrator). Whether that wager pays is the Nemeth Test in Open Problems — the single most important empirical question this language faces.
Escalation of commitment12
Kill Switch Advocate is a direct response to Staw's escalation-of-commitment findings: decision-makers who initiated a failing course of action allocate more resources to it, precisely because they are responsible for it [12]. The pattern institutionalizes the counter-position — a standing, dispassionate voice for stopping, triggered by adoption and cost data rather than by anyone's willingness to confront a sponsor.
Institutional precedents: whistleblowers, ombuds, and theater131415
Uncomfortable Agency has pre-AI ancestors. Whistleblowing research documents both the value and the severe personal cost of formal truth-telling channels [13] — cost being exactly the variable HALA tries to redesign. The organizational ombuds role, as described by Rowe, is a designed, neutral, confidential channel for surfacing what cannot be said through the hierarchy [14] — Proxy Confrontation Agent is best understood as a partial automation of that institution, inheriting its safeguards (confidentiality, corroboration) and its risks. And Meyer and Rowan's account of decoupling — formal structures adopted as ceremony while actual practice proceeds untouched [15] — is the theoretical basis for HALA's bluntest contraindication: an organization that wants compliance theater will make these patterns part of the theater.
Judgment de-biasing and the outside view16
Base-Rate Enforcer automates what Lovallo and Kahneman called taking the outside view: correcting the planning fallacy by forecasting from the distribution of comparable past cases rather than from the inside story of the current one [16]. The pattern's contribution is making the reference-class lookup a default step in the pipeline rather than a discipline individuals must remember to apply under exactly the conditions that make them forget it.
Appropriate reliance on AI judgment1718192021
Whether humans will weight these patterns' outputs correctly is its own literature. Lee and See framed the goal as appropriate reliance — trust calibrated to actual capability, not maximal trust [17]. Dietvorst showed people abandon algorithms after seeing them err, even when the algorithm outperforms them [18]; Logg found the opposite bias — deference to algorithmic judgment — in other conditions [19]. Buçinca showed that cognitive forcing functions reduce overreliance but at a cost users dislike [20], and Bansal found that AI explanations can increase acceptance of wrong recommendations rather than improving complementary performance [21]. Trust Calibrator and Trace UX are HALA's response: surface auditable track records and inspectable reasoning, and treat calibration itself as a designed, measured property. Whether a displayed track record is sufficient to produce calibrated reliance is an open problem below.
The pattern-language form1
The form of this document — Context, Problem, Forces, Solution, and typed connections between named patterns — follows Alexander's original conception of a pattern language as a grammar of solutions in tension, not a checklist [1]. The connection grammar here (triggered-by, gated-by, completed-by, policed-by, composes-with) extends the form with explicit governance edges: every pattern that can say something dangerous names the pattern that polices it.
Architecture
Five layers, each building on the layers below.
HALA Architecture
Click a layer to explore its patterns
Meta-Governance
Patterns that govern the patterns
Foundation Infrastructure
Patterns that make everything else possible
Epistemic Integrity
Patterns that ensure reasoning quality
Organizational Perception
Patterns that see what humans can't or won't
Uncomfortable Agency
Patterns that say what humans can't
Decision Output
Where patterns meet human decisions
Pattern Gallery
28 patterns organized by layer. Each pattern includes its function and failure mode.
Uncomfortable Agency
Patterns that say what humans can't
Mr Unpopular
Surface inconvenient but high-value truths suppressed by human incentives
Failure mode: Weaponized for agendas, undermines trust
Click for context, connections, and a worked instance →
Kill Switch Advocate
Continuously argue for stopping/sunsetting initiatives to counter sunk cost
Failure mode: Decision paralysis, excuse for inaction
Click for context, connections, and a worked instance →
Long-Horizon Advocate
Argue for consequences beyond current planning horizons (5-10+ years)
Failure mode: Unfalsifiable predictions
Click for context, connections, and a worked instance →
Proxy Confrontation Agent
Mediate sensitive issues anonymously to enable truth flow
Failure mode: Enables cowardice, erodes direct norms
Click for context, connections, and a worked instance →
Moral Injury Sentinel
Detect patterns where people repeatedly act against stated values
Failure mode: Surveillance creep, moralizing
Click for context, connections, and a worked instance →
Stakeholder Ghost
Represent interests of absent parties (future employees, communities)
Failure mode: Paternalism, misrepresentation
Click for context, connections, and a worked instance →
HALA in Action
Illustrative scenario — projected outcomes to show the intended mechanics, not a measured case study.
EHR Migration Decision
A hospital system is 18 months into a $40M EHR migration. Adoption is at 30%. No one wants to say "kill it" because the CFO championed it.
Without HALA
The project limps along for 2 more years, eventually "succeeds" at 45% adoption, $60M over budget.
With HALA
At month 12, the system surfaces: "Projects with <40% adoption at 12 months have 8% probability of reaching target. Three prior decisions assumed 60% adoption by now. Recommend formal kill/pivot review." The VP of Clinical Operations reviews the recommendation, the counterfactual analysis, and a dissenting note from the implementation lead, and signs the decision to begin a formal pivot review — the system surfaced the case; a named human owns the call.
Interactive Demo
🔬Try It: HALA Pattern Analyzer
Describe a decision scenario and see which HALA patterns would activate.
Meta-Principles
The Core Question“What true and valuable things go unsaid in organizations, and how can AI safely say them?”
Adoption Principle
A pattern that organizations reject provides zero value. Design for gradual trust-building.
Failure Mode Principle
Every pattern has shadow-sm applications. Name them explicitly or they'll be discovered adversarially.
Override Principle
Humans must always be able to override AI patterns, but overrides must be logged and reviewable.
Sunset Principle
Patterns that aren't providing value should be removable without organizational trauma.
Calibration Principle
The goal is appropriate trust, not maximum trust. Humans should know when to override.
Accountability Principle
A pattern may own the claim it surfaces. It never owns the decision that follows. A named human signs the answer.
When to Use HALA
HALA is appropriate when:
- Organization has baseline psychological safety
- Leadership genuinely wants better decisions (not decision theater)
- There's tolerance for uncomfortable outputs
- Technical infrastructure can support traceability
- Clear escalation paths exist
HALA is contraindicated when:
- Organization will weaponize outputs for political purposes
- No one has authority to act on uncomfortable truths
- Compliance theater is the actual goal
- Trust between humans is already critically damaged
- Legal/regulatory constraints prevent transparency
- Employee-monitoring restrictions apply (works councils, GDPR-covered behavioral metadata) and no privacy-preserving design or consultation has been done — the Perception-layer patterns are monitoring systems in the legal sense
Implementation Guide
Minimum Viable Deployment
Start with Foundation Infrastructure + one pattern from Uncomfortable Agency:
Provides: Structured input, audit trail, one uncomfortable truth-teller, and decision capture
Expansion Path
Epistemic Integrity
Trigger: When users trust the infrastructure
Add reasoning quality patterns to ensure claims are grounded and challenged
Organizational Perception
Trigger: When leadership is ready to see power dynamics
Add patterns that surface informal structures and incentive misalignments
Meta-Governance
Trigger: When the system is mature enough to govern itself
Add patterns that monitor and adjust the HALA system itself
Open Problems
HALA is an architecture proposal, and its load-bearing assumptions are empirical claims that have not yet been tested. These are the questions that would falsify or validate it — stated as hypotheses with proposed tests, because a pattern language that demands disconfirmation from organizations owes the same to itself.
1.The Invocation-Cost Hypothesis
Does AI truth-telling reduce the total social cost of dissent, or merely relocate it to whoever deploys or invokes the pattern?
Why it matters: This is the null hypothesis for the entire Uncomfortable Agency layer. Everyone in the room knows who brought Kill Switch Advocate to the meeting. If the career cost simply transfers from the speaker to the invoker, HALA changes who pays without changing the price — and adoption will collapse for exactly the reason the patterns predict silence in the first place.
Proposed test: Vignette and panel studies varying the messenger of an identical uncomfortable finding — a peer, an assigned devil's advocate, an AI system, and an AI system invoked by a named colleague — measuring both acceptance of the message and blame or status penalty attributed to the human closest to it. Pilotable cheaply with LLM-simulated panels before human-subject replication.
2.The Nemeth Test
Is AI dissent discounted like assigned dissent, weighted like authentic dissent, or received as something new?
Why it matters: Nemeth's finding that assigned devil's advocacy underperforms authentic dissent — and can create an illusion of deliberation — is the strongest published challenge to this language. An AI dissenter is the ultimate assigned dissenter unless the properties that distinguish it (evidence-gating, persistence, career-blindness, auditable track record) actually change how its dissent is processed. If they don't, Uncomfortable Agency delivers theater.
Proposed test: Extend Nemeth's paradigm with AI-voiced dissent conditions: measure divergent thinking, alternative generation, and decision quality in groups receiving authentic human dissent, assigned human devil's advocacy, and grounded AI dissent, with and without a displayed track record. A direct, publishable extension of a classic paradigm.
3.Status-Blind Measurement
How much do author-status cues shift the evaluation of identical proposals, and does the two-stage blind/reattach protocol actually recover the blind assessment?
Why it matters: Status-Blind Analyst assumes both that authority bias distorts evaluation (well supported in general) and that recording a blind merit pass before reattaching authorship preserves its value (untested). If the reattached context simply overwrites the blind judgment, the pattern is ceremony.
Proposed test: Present identical proposals with varied authorship cues to human and LLM evaluators; then test whether evaluators who first record a blind assessment retain it after authorship is revealed, versus assimilating to the status cue. The most tractable single-pattern experiment in this language.
4.Calibrated Reliance
Is a displayed per-pattern track record sufficient to produce appropriate reliance — neither algorithm aversion nor rubber-stamping?
Why it matters: Trust Calibrator bets that showing 'upheld in 8 of the last 10 reviews' induces calibrated weighting. But the reliance literature shows both aversion after observed errors and uncritical deference in other conditions, and shows that explanations can increase acceptance of wrong outputs. If track-record display doesn't calibrate, the meta-governance layer needs cognitive-forcing designs it currently lacks.
Proposed test: AI-assisted decision tasks varying track-record display (none, aggregate, per-pattern with recency), measuring reliance on correct versus incorrect outputs against the appropriate-reliance criterion of the trust-in-automation literature.
If you work on organizational behavior, human-AI interaction, or judgment and decision-making and want to collaborate on any of these, get in touch.
Origin
Building production AI within HCA Healthcare's advanced-technology division, I observed repeatedly that organizational dynamics—not technical limitations—were the binding constraint on AI impact. Those observations inspired HALA. To be unambiguous about the relationship: the pattern language was developed independently and afterward. It was never proposed, piloted, or used at HCA Healthcare, and nothing here describes an HCA system.
To be precise about what that means: the patterns below are designed from that observation, not themselves battle-tested at any scale. The worked examples (including the EHR migration scenario below) are illustrative, not case studies of HALA in production. Treat this as an architecture proposal grounded in real observation, not a track record.
One more precision point, since a pattern language for “AI that says what humans can't” invites an obvious objection: if the system says it, does that just let the human off the hook? That's a design failure mode, not a feature — see Accountability, not laundering above.
Version History
Derived, so it can't drift: v1 = 22 patterns (28 total − 6 added in v2).
References
- [1]Alexander, C., Ishikawa, S., & Silverstein, M. (1977). A Pattern Language: Towns, Buildings, Construction. Oxford University Press.
- [2]Janis, I. L. (1972). Victims of Groupthink. Houghton Mifflin.
- [3]Nemeth, C., Brown, K., & Rogers, J. (2001). Devil's advocate versus authentic dissent: Stimulating quantity and quality. European Journal of Social Psychology, 31(6).
- [4]Schwenk, C. R. (1990). Effects of devil's advocacy and dialectical inquiry on decision making: A meta-analysis. Organizational Behavior and Human Decision Processes, 47(1).
- [5]Morrison, E. W., & Milliken, F. J. (2000). Organizational silence: A barrier to change and development in a pluralistic world. Academy of Management Review, 25(4).
- [6]Milliken, F. J., Morrison, E. W., & Hewlin, P. F. (2003). An exploratory study of employee silence: Issues that employees don't communicate upward and why. Journal of Management Studies, 40(6).
- [7]Detert, J. R., & Edmondson, A. C. (2011). Implicit voice theories: Taken-for-granted rules of self-censorship at work. Academy of Management Journal, 54(3).
- [8]Edmondson, A. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2).
- [9]Hirschman, A. O. (1970). Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States. Harvard University Press.
- [10]Dutton, J. E., & Ashford, S. J. (1993). Selling issues to top management. Academy of Management Review, 18(3).
- [11]Argyris, C. (1990). Overcoming Organizational Defenses: Facilitating Organizational Learning. Allyn & Bacon.
- [12]Staw, B. M. (1976). Knee-deep in the big muddy: A study of escalating commitment to a chosen course of action. Organizational Behavior and Human Performance, 16(1).
- [13]Miceli, M. P., & Near, J. P. (1992). Blowing the Whistle: The Organizational and Legal Implications for Companies and Employees. Lexington Books.
- [14]Rowe, M. P. (1991). The ombudsman's role in a dispute resolution system. Negotiation Journal, 7(4).
- [15]Meyer, J. W., & Rowan, B. (1977). Institutionalized organizations: Formal structure as myth and ceremony. American Journal of Sociology, 83(2).
- [16]Lovallo, D., & Kahneman, D. (2003). Delusions of success: How optimism undermines executives' decisions. Harvard Business Review, 81(7).
- [17]Lee, J. D., & See, K. A. (2004). Trust in automation: Designing for appropriate reliance. Human Factors, 46(1).
- [18]Dietvorst, B. J., Simmons, J. P., & Massey, C. (2015). Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1).
- [19]Logg, J. M., Minson, J. A., & Moore, D. A. (2019). Algorithm appreciation: People prefer algorithmic to human judgment. Organizational Behavior and Human Decision Processes, 151.
- [20]Buçinca, Z., Malaya, M. B., & Gajos, K. Z. (2021). To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-assisted decision-making. Proceedings of the ACM on Human-Computer Interaction, 5 (CSCW1).
- [21]Bansal, G., Wu, T., Zhou, J., Fok, R., Nushi, B., Kamar, E., Ribeiro, M. T., & Weld, D. S. (2021). Does the whole exceed its parts? The effect of AI explanations on complementary team performance. Proceedings of CHI 2021.
Interested in Applying These Patterns?
Whether you're building AI systems for enterprise decision-making or researching human-AI collaboration, I'd love to discuss how HALA might apply to your context.