GovCompass

Art. 26.2 EU AI Act: human oversight of high-risk AI

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 26.2 requires deployers to ensure that the people assigned to oversee a high-risk AI system have the competence, training, and authority to do so effectively. Valid oversight is substantive, not formal: the overseer must understand the system, be trained on its limitations, and hold genuine authority to override its outputs.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: the meaning of human oversight

Art. 26.2 requires deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → to "ensure that the natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry → to whom human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → of high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → is assigned have the necessary competence, training, and authority to perform that oversight." Art. 26(2) is sometimes loosely called a "four-eyes principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry →", but that is imprecise: the genuine two-person rule is Art. 14(5), which applies only to biometric identification (Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → 1(a)). Art. 26(2) requires competent, trained and authorized oversight in AI governance, not that two people sign off.

Human oversight is not a bureaucratic formality. It is the mechanism through which the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → maintains human agency in high-stakes automated decision-makingautomated decision-makingDecisions based solely on automated processing with legal or similarly significant effects. GDPR Article 22 restricts them to three exception grounds, with human-intervention safeguards.Open full entry →. An oversight process that is nominally in place but substantively ineffective, because the overseer lacks the competence to evaluate AI output, does not satisfy Art. 26.2.

Three requirements for valid oversight

1. competence

The overseer must understand the AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → sufficiently to critically evaluate its outputs. This is a substantive requirement, not a formal one. A manager who rubber-stamps AI credit decisions without understanding the scoring model's methodology does not provide qualified oversight.

Competence is assessed relative to the riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → level: a higher-risk system (e.g. AI used in criminal justice) requires deeper technical understanding than a lower-risk high-risk system. The supervisory authority will evaluate whether the competence of the oversight function matched the complexitycomplexityThe governance-challenging characteristic where risk lives in the interactions of many components, suppliers and environments that no one can reason about whole. The answer is system-level assessment and end-to-end testing.Open full entry → and risk level of the system.

2. training

Oversight requires formal training covering: the AI system's functioning and limitations, the types of errors the system is known to make, the interpretation of AI outputs and confidence scores, the process for overriding AI outputs, and the procedure for escalating concerns and reporting incidents.

Training must be documented (connecting to Art. 4 literacy obligations) and must be refreshed when the AI system is updated or when performance data reveals new failure modes.

3. authority

The overseer must have genuine decision-making authority. If an organization's process requires AI output to be approved by a junior analyst whose recommendations can be overridden by a system automatically, there is no effective human oversight. The person with oversight responsibility must have the organizational authority to accept, reject, or modify AI-generated outputs.

Practical implementation

Human oversight in HR selection

For CV screening AI (Annex III, point 4), a compliant oversight process might look like: AI generates a ranked shortlist → HR officer (trained, documented) reviews each shortlisted and excluded candidate → HR officer approves final shortlist with written confirmation → manager independently reviews before interview invitation.

Non-compliant process: AI generates shortlist → system automatically sends interview invitations to top 5 candidates without human review.

Oversight logging

Art. 26.2 compliance requires documentation of oversight decisions. For each significant AI-assisted decision, log: the AI output, the overseer's assessment, whether the overseer agreed or overrode the output, and the rationale for override if applicable. This log is subject to the Art. 26.6 retention requirements.

Compliance checklist

  1. Is there a named oversight function for every high-risk AI system?
  2. Does the oversight function have documented competence in the AI system?
  3. Has the oversight function received and documented training on the system?
  4. Does the oversight function have organizational authority to override AI outputs?
  5. Is there a log of oversight decisions with rationale for overrides?
  6. Is oversight training refreshed when the AI system is updated?
Legal referencesArt. 26Art. 14Art. 4
Share Share on LinkedIn

More on Human oversight

Agentic AI: what changes when the system acts, not just decides

Analysis

Agentic AI is AI that carries out a chain of actions on its own rather than producing a single output for a human to review. That shift does not add a new responsible-AI principle; it changes how every existing principle has to be governed. The human checkpoint moves from inside each decision to around the whole system: setting the bounds the agent operates within, monitoring the chain as it runs, and holding the ability to intervene.

From Copilot to autopilot: governance in the age of AI agents

Analysis

AI agents do not just answer, they take actions in your systems, amplifying both the value and every failure mode. Governing them means governing the actions, not only the decisions: action allowlists, approval gates for high-consequence steps, full logging, and a kill switch.

Human oversight: keeping people in control of AI

Analysis

Human oversight means AI serves people rather than replacing their judgment. It keeps a competent person meaningfully in control of an AI system, with the authority and the information to intervene, and it keeps that control in proportion to what is at stake. The deeper idea behind it is human-centricity: AI should support human judgment, respect autonomy and dignity, and remain accountable to the people it affects, not only the people who use it. The practical core is choosing the right oversight pattern for the stakes, because oversight that is too light fails to catch harm and oversight that is too heavy fails to scale.

Progressive autonomy: a maturity model for agent deployment

Analysis

The safest way to deploy an agent is to grant it the least autonomy that lets it do its job, then widen that autonomy only as evidence of reliable behavior accumulates. Progressive autonomy is to agentic governance what the three control layers are to the seven pillars of responsible AI: the operating discipline that turns a pillar into a practice. This article sets out a maturity model for agent deployment along three dimensions, decision authority, process autonomy, and accountability, and the controls that should be in place at each level.