Identifying AI-Ready Steps Without Crossing Ethics Lines
Maria finished her Weekly Task Map on a Friday afternoon: eighteen tasks, four quadrants, and a Quadrant 1 candidate pool holding roughly 9.5 unpaid hours a week of drafting, formatting, and summarizing. The temptation is to subscribe to a scribe Monday morning and feed it everything in that quadrant. Do not. Suitability is a capability finding, not a permission. This lesson installs the permission layer: a three-question test applied to every candidate step (Does the client know? Does the BAA cover it? Does my ethics code permit it?), plus a content-based cull that removes anything touching custody, abuse disclosure, or active risk before clinical judgment closes the loop. By the end you will have produced the Cleared Task List, the culled, documented set of AI-ready steps that survived all three questions, which the next lesson converts into formal human-AI handoff specifications.
Suitability Is Not Permission
The Weekly Task Map answered an engineering question: which tasks can a language model competently perform? This lesson answers a different question: which of those tasks are you, a licensed clinician bound by an ethics code, a confidentiality duty, and a regulatory landscape that now names AI explicitly, actually allowed to hand over? The two questions get conflated constantly, and the conflation is where licenses get hurt. A task can be perfectly suited to AI and perfectly forbidden in your situation, because the client never consented, because the vendor never signed a Business Associate Agreement, or because your ethics code's confidentiality and competence clauses do not stretch to cover what you are about to do.
The controlling analogy for this lesson is airport security. Your Quadrant 1 candidate pool is a line of passengers, every one ticketed: they all have a legitimate-looking reason to board, which is what high AI-suitability means. But a ticket does not board a plane. Every passenger still passes three independent checkpoints: identity verification, baggage screening, and the watch list. Pass all three and you board. Fail any single one and you do not, no matter how valid the ticket, no matter how late you are. The three-question test works exactly this way: three independent gates, each with its own veto, applied to every step. And like airport security, there is a category of items that never board at all, no matter who carries them: in our profession, that no-fly list is custody content, abuse disclosure, and active risk before the clinician's judgment has closed the loop.
One framing matters before we open the gates. The test is applied per step, not per tool. "I use Mentalyc" answers none of the three questions. "I use a HIPAA-configured scribe, under a signed BAA, to draft progress notes for clients who signed my AI consent addendum, after I have made any risk determination the session required" answers all three, for that one step. Group practices like Jordan's get into trouble precisely by approving tools instead of steps: a tool approved for note drafting quietly becomes a tool used for diagnosis brainstorming, and nobody re-asked the questions when the use changed.
Question One: Does the Client Know?
The first checkpoint is informed consent, and it is the one clinicians most want to wave through. The question is concrete: has this specific client been told, in language they understood, that AI will be involved in this specific kind of step, and have they agreed in a form you can produce later? "It was in the intake paperwork somewhere" does not clear the gate. A psychotherapy client discloses things they have told no living person, on an explicit promise of confidentiality. Routing a recording, transcript, or detailed account of that disclosure through a third-party AI system without their knowledge is not a paperwork lapse. It is a breach of the premise the treatment stands on, and it is exactly the scenario that becomes a board complaint when a client discovers it after the fact: not because the note was wrong, but because they were never asked.
Run the gate with three sub-checks. First, scope: does your consent language actually cover this step? An addendum that says "I may use secure software to assist with appointment reminders" does not cover session recording for an ambient scribe; recording requires its own explicit, documented consent, and in two-party-consent states like California that is law, not courtesy. Second, comprehension: could the client say back, in their own words, what happens to their information? "A program helps my therapist write her notes, a person at the company does not read my sessions, and I can say no without losing care" is comprehension. A signature under unexplained legalese is not. Third, revocability: the client can decline AI involvement and still receive treatment, and a decline is recorded and honored at the workflow level, meaning your process has a working non-AI path. If any sub-check fails, the step waits until your consent process catches up. The fix is usually a one-page AI consent addendum and a two-minute conversation; the point here is that the gate stays closed until that exists.
Notice what this gate does to the quiet practices nobody announces. Pasting a session summary into a free chatbot "just this once" fails the gate, because the client does not know. Carmen's $59-per-month personal Upheal subscription, used on agency clients whose consent forms predate any mention of AI, fails the gate even though the tool is reputable. The question is never whether the tool is good. The question is whether this client knows.
Question Two: Does the BAA Cover It?
The second checkpoint is the legal-infrastructure question. Under HIPAA, any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate and must sign a Business Associate Agreement before PHI touches its systems. No BAA, no PHI, no exceptions, and a free consumer chatbot tier does not come with one. This gate catches the single most common AI violation in behavioral health: pasting identifiable session content into the free tier of a general-purpose chatbot. However good the output, the step fails Question Two categorically.
But "we have a BAA" is the beginning of the check, not the end. Run four sub-checks. First, coverage of the actual step: a BAA signed for one product or tier may not cover another; an EHR vendor's BAA does not automatically extend to the new AI add-on, and the tier you pay for matters. Jordan discovered this the hard way: the EHR vendor said yes to AI-assisted features, but the vendor's subprocessor list included a model provider that does not sign a BAA at the tier Jordan was paying for. The chain is only as covered as its weakest subprocessor. Second, training and retention terms: does the agreement state whether your clients' data is retained, for how long, and whether it trains models? Zero-data-retention is a different risk posture than indefinite retention, and you should be able to say which you have. Third, the special-population overlay: for clients in a federally assisted substance use disorder program, 42 CFR Part 2 under the 2024 final rule imposes consent and redisclosure rules a generic HIPAA BAA does not satisfy; SUD records need their own analysis before any AI step touches them. Fourth, the psychotherapy-notes carve-out: if the step involves your separately maintained psychotherapy notes (heightened protection under 45 CFR 164.508(a)(2), defined at 164.501), think hard before any third party touches them; most AI workflows should be built on the progress-note record, not the psychotherapy-notes layer.
The practical discipline: for every AI-touched step, you can produce the BAA, name the vendor and tier, and state the retention posture in one sentence. If you cannot do that today, the step has not passed Question Two, whatever the marketing page says.
Question Three: Does My Ethics Code Permit It?
The third checkpoint is professional, and it is the one no vendor can answer, because the vendor is not licensed and you are. Your ethics code, ACA, APA, NASW, AAMFT, NBCC, or the BACB Ethics Code for Behavior Analysts if you practice ABA, binds you through clauses that touch every AI step: confidentiality (disclose the minimum necessary, protect what you disclose), competence (use only methods you understand well enough to supervise, including what a language model does with your input and where it fails), informed consent (independently grounded in your code, not just HIPAA), delegation and oversight (you remain responsible for work produced under your name), and accuracy in documentation and billing (you may not sign what you have not verified).
On top of the codes sits a statutory layer that now names AI directly, and it varies by state, so cite your own jurisdiction rather than generalizing. The Illinois WOPR Act prohibits AI from providing therapy or making independent therapeutic decisions while permitting administrative and documentation support under licensed review. Nevada AB 406 prohibits AI from delivering what would constitute professional mental or behavioral health care if performed by a person. Colorado's AI Act framework (the SB 24-205 / SB 26-189 dual track) imposes duties around high-risk AI systems. California clinicians carry the duty-to-protect framework of Civil Code section 43.92 and mandated reporting under WIC section 11166, both non-delegable clinical determinations no matter what any tool offers to draft. The Question Three habit, per step: which clause of my code, and which statute in my state, governs this, and can I articulate in two sentences why this use complies? If you cannot write those two sentences, the step is not cleared; it is merely unexamined.
Each of the three questions carries its own veto. A step boards your workflow only when the client knows, the BAA covers it, and your ethics code permits it; failing one gate fails the step, no matter how brilliantly the AI performs it.
The No-Fly List: Custody, Abuse Disclosure, and Active Risk
Beyond the three gates sits an absolute cull, content-based rather than consent-based or contract-based: any step that touches custody material, abuse disclosure, or active risk is removed from the AI-ready list until clinical judgment has closed the loop, even if all three questions would technically pass. This is the no-fly list, and it exists because these three content areas share a property the gates cannot manage: each contains a live, non-delegable clinical-legal determination, and AI involvement before that determination is made contaminates the determination itself.
Custody content first. Anything in a chart involving a custody dispute is potential litigation material: it can be subpoenaed, dissected by opposing counsel, and read aloud in family court. An AI-drafted characterization of a parent, generated from a transcript and signed in a hurry, becomes your sworn clinical opinion in a deposition. Custody-adjacent documentation is drafted by the clinician, slowly, with the awareness that a judge may read every word. Abuse disclosure second. The moment a session contains a possible abuse disclosure, you are inside a mandated-reporting analysis (in California, under WIC section 11166), and that analysis belongs to you: whether the reasonable-suspicion threshold is met, what must be reported, to whom, by when. No AI summarization, structuring, or drafting touches that session's content until you have made the call, because the report decision must rest on your direct clinical perception, not a machine's paraphrase of it. Active risk third, the program's cardinal guardrail restated: AI never scores the CSSRS, never assigns a risk level, never makes the duty-to-protect determination under Civil Code section 43.92, never decides whether ideation is passive or active. When a session surfaces active risk, every AI step in that session's pipeline pauses; the clinician assesses, decides, acts, and documents the determination; only then, and only for formatting the record of decisions already made, may AI re-enter.
Operationally, the no-fly list means cleared steps carry a content trigger written into them: "AI drafts the progress note from my recap, EXCEPT when the session contained custody material, a possible abuse disclosure, or risk content, in which case the note is clinician-drafted (or AI re-enters only after my documented determination)." That exception clause is what the next lesson formalizes into the escalation hand-back rule. Write it onto every surviving step in plain language. A cleared list without the exception clause will eventually automate the one session it must not.
Running Maria's Candidate Pool Through the Gates
Watch the test work on Maria's actual Quadrant 1 pool. Step one: draft progress notes from her structured recap. Question One: her clients signed an AI documentation addendum she rewrote in Level 2, and she can produce it; pass. Question Two: her scribe runs under a signed BAA at a zero-data-retention tier; pass. Question Three: NASW confidentiality and accuracy clauses are satisfied because she supplies the facts and reads every word before signing, and the use sits on the administrative-support side of the IL WOPR line; pass. No-fly check: the exception clause is written in. Cleared.
Step two: draft prior authorization letters from supplied facts (the time-in-session minutes for the 90837, the PHQ-9 delta from 18 to 11, the modality named in session). All three gates pass, and the step carries a verification note: the clinician supplies and confirms every verifiable detail, because those specifics are precisely what AI cannot know and what a payer reviewer checks. Cleared. Step three: summarize past notes into a pre-session brief. Questions Two and Three pass, but Question One snags: her consent addendum covered note drafting, not secondary AI processing of the existing chart. The step is parked, not killed: it returns after she updates the addendum at each client's next session. That parking move matters; the test produces three outcomes, cleared, parked pending a fix, and culled, and an honest list shows all three.
Step four: draft replies to client scheduling messages. Parked on Question Two: messages arrive through her EHR portal, and her scribe BAA does not cover that data flow; she either finds the EHR's own covered feature or keeps drafting replies herself. Step five: turn intake paperwork into a structured chart summary. Culled for now on the no-fly rule: intakes are exactly where abuse history, custody context, and risk content first surface, and Maria keeps the intake summary clinician-written until the next lesson's handoff design gives her a screening step she trusts. Step six: draft referral-out and no-show outreach templates containing no client specifics. Cleared trivially: no PHI enters the system at all, the easiest way to pass Question Two. Six candidates in: three cleared with exception clauses, two parked with named fixes, one culled. That is what a defensible AI-ready list looks like: smaller than the candidate pool, every line annotated with why.
Documenting the Cull: Why the Paper Trail Is the Point
The clinicians who get hurt in board inquiries and payer audits are rarely the ones who made a considered decision that proved debatable; they are the ones who can produce no evidence that a decision was made at all. So the output of this lesson is documentation, not just judgment. For every candidate step, the Cleared Task List records: the step (verb phrase, input, output, carried over from the task map), the answer to each question with one line of evidence (consent addendum version and date; BAA vendor, tier, retention posture; the ethics clause and state statute with your two-sentence compliance rationale), the no-fly exception clause, and the disposition: cleared, parked (with the named fix), or culled (with the reason).
This document does three jobs. It is your audit answer: when the malpractice carrier's renewal questionnaire asks about AI use, as Jordan's CPH & Associates questionnaire now does, you answer from the list instead of from memory. It is your drift detector: when a new AI feature appears inside your EHR, the discipline of adding it as a new row, with fresh answers to all three questions, prevents the quiet scope creep that turns a note-drafting tool into an unexamined diagnosis assistant. And in a group practice it is the supervision instrument: a supervisor who countersigns an associate's work can require the associate's Cleared Task List in the supervision agreement, exactly the conversation Carmen and her supervisor needed eighteen months ago. The list converts "we need to talk about that" into a reviewable page.
The Applied Problem: Your Cleared Task List
Your artifact is the Cleared Task List: every Quadrant 1 candidate from your Weekly Task Map, run through the three-question test and the no-fly cull, with dispositions and evidence. Step one: copy your Quadrant 1 tasks into a table with columns for the step, Q1 (client knows?), Q2 (BAA covers?), Q3 (ethics permits?), the no-fly exception clause, and disposition. Task names only; no PHI belongs in this exercise.
Step two, use AI to pressure-test your answers, not to make them. Prompt text: "I am a licensed behavioral health clinician screening workflow steps for AI involvement. For each step below, I state my answers to three questions: Does the client know (what my consent addendum covers)? Does the BAA cover it (vendor, tier, retention)? Does my ethics code permit it (clause and state statute)? Challenge each answer: identify consent-scope gaps, BAA chain weaknesses such as subprocessors or uncovered data flows, and ethics clauses I have not addressed. Then check each step against this rule: any step touching custody material, abuse disclosure, or active risk is removed or given an explicit exception clause until clinician judgment closes the loop. Do not approve anything; your job is to find the holes." Paste your table. The model is a skeptical colleague here, useful precisely because it will name the subprocessor question or the consent-scope gap you waved through.
Step three, the verification pass, yours alone: confirm every piece of evidence physically exists. Open the consent addendum and check its date against each client's file. Locate the BAA PDF and read the retention clause. Write the two-sentence ethics rationale for each cleared step in your own words; if you cannot, the step is parked, not cleared. Add the exception clause verbatim to every cleared step that processes session-derived content.
Done looks like this: a dated table in which every Quadrant 1 candidate has a disposition; every cleared step shows three passing answers with evidence you physically located today; every parked step names its fix and a date; every culled step states its reason; and every cleared step touching session content carries the custody-abuse-risk exception clause in plain language. Expect the cleared list to be shorter than the candidate pool. That shrinkage is not lost value; it is the difference between an AI workflow and an AI exposure. The next lesson takes only the cleared steps and builds the handoff specification: exactly what the AI produces, what you verify, and the timestamped signature point where liability transfers to you.
Key Takeaways
- AI-suitability is a capability finding, not a permission. Every Quadrant 1 candidate must independently pass three gates: Does the client know? Does the BAA cover it? Does my ethics code permit it? Each gate carries its own veto, like the checkpoints at airport security.
- Question One demands step-specific, comprehensible, revocable consent you can produce later. Reminder-software language does not cover session recording; recording needs its own documented consent, and two-party-consent states make that law. A decline must leave a working non-AI path.
- Question Two starts, not ends, with a signed BAA: check that it covers the actual product, tier, and data flow; check subprocessors (Jordan's chain failed at a model provider that signs no BAA at his tier); know your retention posture; apply the 42 CFR Part 2 overlay for SUD records and the psychotherapy-notes carve-out under 45 CFR 164.508(a)(2).
- Question Three is the gate no vendor can answer: confidentiality, competence, delegation, and accuracy clauses in your code, plus state statutes naming AI (IL WOPR Act, NV AB 406, the Colorado dual track). A cleared step has a two-sentence compliance rationale in your own words; an unwritten rationale means an unexamined step.
- The no-fly list is content-based and absolute: steps touching custody, abuse disclosure, or active risk are culled or carry an explicit exception clause until clinical judgment closes the loop. AI never scores the CSSRS, never assigns risk level, never makes the duty-to-protect (CA Civ Code section 43.92) or mandated-report (CA WIC section 11166) determination; it may format the record only after the clinician's decision.
- The test applies per step, never per tool, and produces three honest dispositions: cleared with evidence, parked with a named fix, or culled with a reason. Maria's six candidates yielded three cleared, two parked, one culled; a defensible list is always shorter than the candidate pool.
- The Cleared Task List is the artifact and the audit answer: it responds to the malpractice carrier's AI questionnaire, detects scope drift when new AI features appear, and serves as the supervision instrument that turns an associate's quiet tool use into a reviewable page.
Skill.re