ai governance

Human in the loop: keeping people accountable for AI

Human control needs to be proportionate to the risk and consequence of each process step.

At a glance

The essentials

  1. oversight is more than an approval button
  2. accountable owners must be named
  3. critical decisions remain human
Contents

Human in the loop is an operating model

People define objectives and boundaries, review sensitive outcomes, handle exceptions and can correct or stop a workflow. The control point needs to sit where it makes business sense.

Greater consequence requires stronger control

Strategic, employment, medical, legal, financial or safety-critical contexts need particularly careful oversight. Specific legal assessment belongs with qualified counsel.

  • named accountability
  • understandable escalation
  • sufficient decision context
  • documented approval

Effective oversight needs competence, context and authority

A person in the workflow provides meaningful control only when they can understand the outcome, recognise doubt and actually intervene. They need suitable expertise, time, information and clear decision authority.

The interface and workflow should expose uncertainty, sources, relevant input and prior approvals so review does not become a rushed confirmation exercise.

  • named and trained role
  • understandable decision basis
  • ability to reject and correct
  • stop and fallback procedure
  • protection against uncritical automation bias

Control points belong where effects can occur

Approval is particularly relevant before data is changed, messages are sent, payments are initiated, people are assessed or safety-related steps are triggered. A later sample review may be proportionate where effects are lower.

The appropriate control follows the purpose, people affected, possible harm, reversibility and detectability of an error.

Oversight does not end with the pilot

NIST describes risk management as an ongoing cycle. Normal and difficult cases, escalations, wrong decisions and changes to the system therefore need repeated review.

Where people cannot reliably detect errors or intervene in time, the task, authority or level of automation needs adjustment.

The legal meaning depends on the actual use

Article 14 of the EU AI Act sets specific human-oversight requirements for high-risk AI systems. Whether a system falls within that category and which further duties apply depends on factors including role, purpose and context of use.

This general explanation is not a risk classification and does not replace data-protection, employment or other legal advice.

Source note

General business guidance based on the NIST AI RMF, the EU AI Act and current European Commission guidance. Legal sources reviewed on 11 August 2026; this is not legal advice.

Primary sources

Official sources, editorially checked on 11 August 2026.

Which process should work better in your organisation?

We begin with the work, the people and the current process — then assess which form of AI genuinely makes sense.

Discuss your process