GovCompass

Oversight log: how to document human oversight under the EU AI Act

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

An oversight log is the contemporaneous record that proves human oversight of a high-risk AI system under Art. 26.2 of the EU AI Act. It must capture, per oversight event, who reviewed the AI output, what they decided and why, and it must be retained for at least six months under Art. 26.6.

Updated: June 2026

Introduction: why oversight documentation matters

Art. 26.2 requires human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → of high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →. But oversight without documentation is invisible to supervisory authorities. When the supervisory authority investigates a complaint or conducts a compliance audit, the question will not be "do you have oversight?" but "can you demonstrate oversight?" A well-maintained oversight log is your primary evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry →.

This guide explains what an oversight log must contain, how to structure it, and how to maintain it efficiently in practice.

What is an oversight log?

An oversight log is a contemporaneous record of human oversight activities for high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry →. It documents that a qualified person reviewed AI outputs before or shortly after they influenced significant decisions, and records the outcome of that review.

The log serves three functions:

  1. Compliance evidence: Demonstrates to the supervisory authority and to affected individuals that meaningful oversight occurred
  2. Performance monitoring: The log data reveals patterns, rising override ratesoverride rateThe share of proposals from an AI system that a human reviewer changes or rejects, used as an indicator of whether human oversight is functioning. A structural zero is a reason to investigate rather than a reassurance, because it can mean the system performs well or that the reviewer has stopped examining. It is a signal, not a standalone quality measure. See human oversight, automation bias.Open full entry → signal model degradation
  3. Learning and improvement: Override reasons documented over time build institutional knowledge about AI system strengths and weaknesses

What must an oversight log contain?

Minimum required elements for each oversight event:

FieldDescription
Date and timeWhen was the oversight conducted?
AI systemWhich AI system generated the output being reviewed?
Overseer identityWho conducted the oversight (name/role)?
AI output summaryWhat did the AI system recommend or decide?
Oversight decisionAccept / override / escalate
Override rationaleIf overridden: why? (required for audit trail quality)
Final decisionWhat decision was ultimately made?

Oversight frequency

Oversight frequency depends on the AI system's decision volume and risk level:

  • High-volume, high-stakes systems (credit scoring, CV screening): Oversight on every individual decision, or at minimum a structured sample of decisions with defined statistical coverage
  • Lower-volume systems (performance appraisal AI): Oversight on every decision
  • Monitoring-only systems (anomaly detection AI that generates alerts): Oversight review of all alerts before action is taken

Oversight log implementation options

  • Integrated in the AI platform: Ideal, many enterprise AI platforms have built-in human review workflows. Configure the platform to capture oversight decisions as part of the workflow.
  • Ticketing system (Jira, ServiceNow): Create oversight tickets linked to AI outputs. The ticket trail serves as the log.
  • Structured spreadsheet: Acceptable for low-volume systems. Use a shared spreadsheet with protected formatting to maintain integrity.
  • Document management system: Monthly oversight review reports filed in a versioned document system.

Retention

Oversight logs are AI system logs within the meaning of Art. 26.6. You must retain them for at least 6 months, or longer if sector-specific law requires.

Compliance checklist

  1. Is there an oversight log for every high-risk AI system?
  2. Does each log entry contain all required elements?
  3. Are override rationales documented for all overrides?
  4. Is the oversight frequency appropriate for the decision volume and risk level?
  5. Are logs retained for the required period?
  6. Is override rate data regularly analyzed for performance monitoring purposes?
Legal referencesArt. 26.2Art. 26.6
Continue withHuman oversight
Share Share on LinkedIn

More on Human oversight

Agentic AI: what changes when the system acts, not just decides

Analysis

Agentic AI is AI that carries out a chain of actions on its own rather than producing a single output for a human to review. That shift does not add a new responsible-AI principle; it changes how every existing principle has to be governed. The human checkpoint moves from inside each decision to around the whole system: setting the bounds the agent operates within, monitoring the chain as it runs, and holding the ability to intervene.

From Copilot to autopilot: governance in the age of AI agents

Analysis

AI agents do not just answer, they take actions in your systems, amplifying both the value and every failure mode. Governing them means governing the actions, not only the decisions: action allowlists, approval gates for high-consequence steps, full logging, and a kill switch.

Human oversight: keeping people in control of AI

Analysis

Human oversight means AI serves people rather than replacing their judgment. It keeps a competent person meaningfully in control of an AI system, with the authority and the information to intervene, and it keeps that control in proportion to what is at stake. The deeper idea behind it is human-centricity: AI should support human judgment, respect autonomy and dignity, and remain accountable to the people it affects, not only the people who use it. The practical core is choosing the right oversight pattern for the stakes, because oversight that is too light fails to catch harm and oversight that is too heavy fails to scale.

Progressive autonomy: a maturity model for agent deployment

Analysis

The safest way to deploy an agent is to grant it the least autonomy that lets it do its job, then widen that autonomy only as evidence of reliable behavior accumulates. Progressive autonomy is to agentic governance what the three control layers are to the seven pillars of responsible AI: the operating discipline that turns a pillar into a practice. This article sets out a maturity model for agent deployment along three dimensions, decision authority, process autonomy, and accountability, and the controls that should be in place at each level.

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.