Berk Bayri

Human in the loop means the system is safe

A common misconception about AI governance, tested against the evidence.

The myth
Putting a human approval step in an AI workflow makes the system safe.
The reality
A human checkpoint is only a control if the person has the context, competence, time and authority to detect a problem and stop or reverse the action.

Explanation and evidence

The argument

“” describes where a person sits in a process. It does not tell you whether that person can actually control the process.

A reviewer may see too little evidence, receive the request too late, lack domain expertise, face hundreds of approvals, or have no practical way to undo what the system has done. In those conditions, the human can become a ceremonial checkpoint.

’s AI Risk Management Framework treats human oversight as something that must be defined, assessed and documented according to organizational policy. That wording matters. Oversight is not assumed to work merely because a human is present.

OpenAI’s 2026 work on Auto-review shows the opposite failure mode from another direction. Frequent manual approval can create so much friction that users grant broad permissions, write permissive rules or approve actions without fully understanding them. OpenAI explicitly cites reviewer fatigue as one reason manual approval can weaken security in practice.

A person in the workflow is not the same thing as human control.

Why people believe it

The phrase sounds reassuring. It converts an unfamiliar machine-risk problem into a familiar accountability story: the AI proposes, a person decides.

That can work. But only when the decision is genuinely reviewable.

What the evidence says

Good oversight is designed around the decision, not around the presence of a person. The reviewer needs enough context to judge the action, enough time to do so, a clear threshold for , and real authority to deny or reverse it.

Some low-risk actions can be governed more effectively by machine-enforced boundaries and evaluated automated review than by forcing a human to click “approve” repeatedly. Higher-risk decisions may need expert review, dual control or mandatory .

The better question

Instead of asking “Is there a human in the loop?”, ask:

What can this reviewer see, what are they expected to notice, what can they stop, and what happens if they miss it?

That turns human oversight from a reassuring label into a testable control.

Sources

AI RMF Core

NIST · 2026-10-06

Auto-review of agent actions without synchronous human oversight

OpenAI · 2026-04-30

Related reading