Your AI system recommends a decision.

A person clicks approve.

Does that mean you have human oversight?

Not necessarily.

For high-risk AI, the EU AI Act expects something more meaningful than placing a person at the end of an automated process.

The person overseeing the system needs to understand what it can and cannot do, recognise when something looks wrong and have the authority to challenge or override its output.

01

What does human oversight actually mean?

Article 14 of the AI Act requires high-risk AI systems to be designed so they can be effectively overseen by people.

Depending on the system and its risks, those people should be able to:

  • understand relevant capabilities and limitations
  • monitor for anomalies, unexpected behaviour or poor performance
  • interpret the system's output correctly
  • recognise the risk of over-relying on AI recommendations
  • disregard, override or reverse an AI output where appropriate
  • intervene in or stop the system safely where necessary

That last point matters.

Human oversight is not simply about observing what an AI system does.

It is about having the ability to act.

02

The person needs real authority

Article 26 places additional responsibilities on organisations deploying high-risk AI.

Human oversight must be assigned to people with the necessary:

  • competence
  • training
  • authority
  • support

Consider a recruitment system that ranks candidates.

If the recruiter can see the AI score but cannot understand what influenced it, is expected to follow it automatically and needs senior approval to override it, the organisation may have a person involved but very limited meaningful oversight.

The same issue can arise in credit decisions, employee management, insurance, education or other significant decisions involving people.

Explore AI in recruitment

03

Watch for automation bias

The AI Act specifically identifies the risk of automation bias.

People can become overly confident in a computer-generated answer simply because it appears objective, consistent or data-driven.

Human review becomes weak if the reviewer routinely accepts the recommendation.

A practical oversight process should therefore ask:

Why did the AI reach this result?

Does the result make sense in this case?

Is relevant information missing?

Would I make the same decision without the AI recommendation?

The objective is not to second-guess every output.

It is to ensure that human judgement remains genuine where human oversight is required.

04

When do these rules apply?

This timing distinction is important.

Articles 14 and 26 form part of the EU AI Act's high-risk AI framework.

Following the revised implementation timetable, the high-risk rules for Annex III use cases are scheduled to apply from 2 December 2027.

These include certain AI uses in areas such as employment, education, essential services, biometrics and access to important opportunities.

Rules for high-risk AI integrated into regulated products are scheduled to apply from 2 August 2028.

So businesses do not need to pretend these future high-risk obligations are already generally enforceable today.

But organisations selecting systems now may still be using them when those dates arrive.

05

Four things businesses can do now

1. Identify important AI decisions

Find systems whose outputs influence decisions about employees, candidates, customers or other individuals.

2. Define who can challenge the AI

Assign responsibility before deployment.

The reviewer should know when they can reject, override or escalate an AI recommendation.

3. Ask vendors about oversight controls

Check whether users can understand outputs, monitor performance, override recommendations and stop the system where necessary.

Do not wait until implementation to discover that the software does not support meaningful human review.

4. Train for judgement, not just operation

Knowing which button to press is not enough.

People overseeing important AI systems need to understand limitations, foreseeable errors and the risk of automatically trusting the machine.

Read the AI literacy guide

06

Blanche perspective

"Human in the loop" sounds reassuring.

But a human who cannot understand, challenge or override the system may simply become part of the automation.

Meaningful oversight requires three things:

Knowledge.

Authority.

A practical way to intervene.

For businesses preparing for high-risk AI obligations, those questions should be addressed when the system is selected, not after it has already become part of everyday decision-making.

S

Sources

Primary and authoritative sources used for this Insight.

  1. EUR-Lex: Regulation (EU) 2024/1689, consolidated 27 July 2026, Articles 14 and 26 (binding EU law)
  2. European Commission: The enforcement framework of the AI Act (official implementation information)
  3. European Commission: AI Act regulatory framework (official explanatory material)
  4. AI Office of Ireland: EU Artificial Intelligence (AI) Act (Irish implementation information)
  5. Data Protection Commission: Automated decision making, including profiling (guidance on separate GDPR law)
Share this Insight