GovCompass

Pillar 07 of seven

Human oversight

Human oversight means a competent person can understand, intervene in, override, or stop the system, and has the information, authority, and time to do so. The EU AI Act requires oversight measures commensurate with the risks, level of autonomy, and context of use of the system (Art. 14(3)).

What it means

Human oversight is the property that a person with the competence, authority, and information to intervene remains meaningfully in control of a high-risk AI system. It is the EU AI Act's primary safeguard for human agency in automated decision-making, expressed in Art. 14 as a design obligation on providers and in Art. 26.2 as an operational obligation on deployers. Oversight is what prevents an AI system from becoming an unaccountable decision-maker, and it is the pillar most often present on paper and absent in practice.

Meaningful oversight has three requirements that the EU AI Act makes explicit. The overseer must have the competence to understand the system and evaluate its outputs, which connects oversight to the Art. 4 literacy obligation. They must have the authority to override the system, which is an organisational property, not a technical one. And they must not be subject to automation bias, the well-documented tendency to defer to a machine's output without genuine scrutiny. An oversight arrangement that fails any of these three is oversight in name only.

Why it matters

Human oversight is where many programs are weakest, because it is the easiest to fake and the hardest to do well. An organization can appoint an overseer, document the role, and satisfy a checklist, while in practice that overseer approves hundreds of decisions a day without the time, the information, or the authority to review any of them. This is the failure mode that a supervisory authority probes by asking not whether oversight exists but whether it is real: the override rate, how long the overseer spends per decision, what training they received, and whether they can stop the system.

Governing human oversight

The controls have to defend against the quiet collapse of oversight into rubber-stamping, which is why they focus as much on the conditions of oversight as on its existence.

Control layerControl
PreventiveAppoint named oversight personnel for each high-risk system, with documented competence (Art. 4) and documented authority to override. Design the oversight interface to present uncertainty, surface low-confidence outputs, and make the override action available and easy (Art. 14). Set the workload so that meaningful review per decision is possible, rather than a volume that forces rubber-stamping. Provide a kill switch the overseer can invoke.
DetectiveMonitor the override rate: a rate at or near zero is a warning sign that oversight is not genuine, not evidence that the model is perfect. Track time-per-decision against the level needed for real review. Audit a sample of overridden and non-overridden decisions for the quality of the human judgment applied.
CorrectiveWhere monitoring indicates automation bias, intervene on the conditions: reduce workload, improve the interface, or re-train the overseers. Where an oversight failure contributed to a harmful decision, review the decision, remediate the individual harm, and feed the failure into the risk management system. Treat a systemic oversight failure as a reason to suspend the system, not merely to coach the individual.
From principle to evidence
  • PrincipleMeaningful human control
  • HarmAutomation bias, over-reliance on the system
  • RiskLikelihood of over-reliance, combined with its impact
  • ControlOversight design, competence, and a stop function
  • EvidenceOverride log and oversight records
Legal anchors*
Art. 14Art. 26.2

* Article references are verified against the consolidated text of Regulation (EU) 2024/1689 and, where cited, Regulation (EU) 2016/679. The pillar itself is a general responsible-AI principle; these articles are where it anchors in EU law.

In practice
How this principle is governed and executed

Oversight is controlled by designing genuine intervention points and equipping competent people to use them, and proven through override and oversight records.

Governance design

Define who oversees the system, their competence, and their real authority to intervene or stop it.

Execution

Provide working intervention and stop functions, and record overrides so oversight can be evidenced.

With agentic AI
What changes when the system acts, not just decides

An agent acts in steps, often faster than a person can follow. Oversight shifts from reviewing one decision to interrupting a chain of actions, and from "human in the loop" to "human on the loop" with hard limits.

Governance design

Decide which agent actions need prior approval and which may run unattended, with authority to halt that is real, not nominal.

Execution

Provide real-time interruption, approval thresholds for high-impact actions, and rate limits, and guard against automation bias.

Across all seven pillarsAgentic AI is not an eighth principle. When human oversight has to hold while the system acts on its own, not just decides, every control runs over a chain of autonomous steps. See Agentic AI, the condition that runs across all seven.
Go deeper

See how the pillars connect