alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533
Become a Member
alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533

How does human oversight of AI work?

How does human oversight of AI work?

Human oversight of AI works only when a named person has the time, the information and the authority to reject what the system suggests. If the reviewer cannot realistically say no, the human in the loop is decoration, not control.

Hypothetical example: a recruitment agency uses an AI tool to rank job applicants, and a recruiter approves each shortlist before it goes to the client. In practice, the recruiter handles hundreds of applications a day, sees only the ranking, not the reasons, and is measured on speed. Almost every ranking goes through unchanged. Nobody has checked whether the tool pushes certain candidates down, and rejected applicants have no one to ask.

Why clicking “OK” is not oversight

People tend to trust automated output, especially when busy and the system is usually right. This is called automation bias. The EU AI Act names it directly: people overseeing a high-risk system must be able to remain aware of the tendency to over-rely on its output (AI Act, Art. 14(4)(b)). An approval step that never rejects anything is a warning sign.

What a reviewer needs

  • Time. Set a realistic volume per reviewer. If a real check is impossible, reduce the volume or narrow what the AI decides.
  • Information. The reviewer sees the input, the output and, where the tool provides them, the main factors behind the output. They also know its weak spots.
  • Authority. The reviewer can reject or change the output without first justifying it to a manager, and can pause the tool.

Write down who holds this authority for each use case, and log every override. Overrides show where the tool goes wrong, which is exactly what monitoring AI after launch relies on.

What the law says about human oversight of AI

Legal requirement (GDPR, Art. 22). This applies now. People have the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects on them, such as rejecting a job application or a loan. These are allowed only in limited cases. Where they rely on a contract or explicit consent, the company must at least let the person obtain human intervention, express their point of view and contest the decision (GDPR, Art. 22). EU data protection guidance adds that token human involvement does not take a decision outside Art. 22: the reviewer must have the authority and competence to change it (Guidelines on automated decision-making and profiling). For such decisions the person is also entitled to meaningful information about the logic involved (Art. 13–15): an intelligible explanation of the procedure and principles actually applied, not the source code (CJEU, C-203/22).

Legal requirement (EU AI Act, Art. 14 and 26). This applies to high-risk systems: from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I Section A products, as amended by Regulation (EU) 2026/1744; Section B products follow the sector route in Art. 2(2). The full timeline is in what the EU AI Act requires. The provider must design the system so that people can oversee it, including deciding not to use it, overriding or reversing its output, and stopping it (Art. 14(4)). The deployer must assign oversight to people with the necessary competence, training and authority, and give them the support they need (Art. 26(2)). AI used to recruit or select candidates is listed as high-risk in Annex III. Which obligations fall on you depends on whether you are a provider or a deployer.

A way to challenge the decision

Recommendation. Give people affected by an AI-assisted decision a simple way to ask for a review: where to write, who reviews the case and when they will get an answer. The reviewer should not have been involved in the original decision.

Legal requirement (EU AI Act, Art. 86). For certain decisions based on high-risk systems listed in Annex III, the AI Act adds a right to an explanation from the deployer (Art. 86). Unlike Art. 14 and 26, it is not expressly postponed, but it only concerns high-risk systems, so when it applies to a given system needs a legal assessment. See what AI transparency requires.

Next step: for every AI-assisted decision in your AI inventory, write down who can overturn it and how an affected person can ask for a review.

Sources and further reading

This article is for general information and is not legal advice.

Event

AI Horizon Conference

The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.

November 11, 2026
Lisbon, Portugal
Register Now
AI Horizon
alt alt

Join Us in Shaping the Future of Ethical AI!

Join us as a member and play a vital role in shaping a future where AI is created responsibly, with integrity, transparency, and fairness at its core.

Apply Now