The standard account of which work is safe from AI is a physical one. Machines took muscle, then they took routine cognition, and what is left for people is the stuff needing hands, or a body, or a place. Plumbers are fine. Nurses are fine. Anyone at a desk should be nervous.
The first half of that is right, and this index supports it strongly. Construction is the least exposed major group at a median of 5.1%. Stonemasons score zero. Handling and moving objects, the largest activity family in the taxonomy at 271 activities, has a mean exposed share of 2.4%.
But when you total up where the friction in the whole index actually comes from, physical work is not the largest source.
The friction budget
Every one of the 18,838 scored tasks carries five friction ratings. Adding all of them across the whole index and asking what share each dimension contributes gives this:
| Friction dimension | Share of all friction in the index |
|---|---|
| Context | 24.7% |
| Verification cost | 22.5% |
| Embodiment | 21.6% |
| Accountability | 17.0% |
| Presence | 14.2% |
Context is the largest. Embodiment is third.
Context, in our rubric, is the degree to which work depends on private, tacit or real-time knowledge that a model cannot hold: what this organisation actually does, what was agreed in a meeting nobody minuted, what the client meant rather than said, what happened on this site last winter.
Why this matters more than the ranking suggests
Embodiment and context behave very differently over time, and that difference is the practical point.
Embodiment is close to a hard floor. A language model cannot lay brick. Moving that constraint requires robotics that is both capable and cheap enough to deploy widely, which is a slow, capital-heavy, physically constrained problem. When we re-score next quarter, embodiment scores will almost all be unchanged.
Context is not a floor. It is a description of what a system has been given access to. Every integration that connects a model to an organisation's documents, records, mail and history reduces it. That erosion is already underway and it does not require any breakthrough, only plumbing.
So the largest single source of protection in this index is also the one most likely to weaken, and to weaken for commercial rather than scientific reasons.
What that implies
If your work is protected mainly by context, the protection is real today and is a depreciating asset. The question worth asking is not whether a model could do your job in the abstract. It is how much of what you know has been written down somewhere the organisation could point a system at.
If your work is protected by embodiment, presence or licensure, the protection is structurally different in kind. Those frictions move when robots get cheap, when norms change, or when regulators decide, and none of those are quarterly events.
That distinction is the reason this index scores five separate frictions rather than emitting one number. A single exposure figure would have told you that a job is safe. It would not have told you which kind of safe, or for how long.
Figures from release v2026.Q3. Friction shares are computed by summing each dimension's rating across all scored tasks. Friction ratings are judgments against a published rubric, with inter-rater agreement of 84.9% exact and 100% within one point. See the methodology page.