Skip to main content

The EU AI Act requires human oversight — but not that anyone actively watches

Ilustrační obrázek
One person. One screen. A system quietly deciding who gets a mortgage, a shift or a job interview — and paperwork that can still declare "human oversight: yes". That is not a loophole slipped in at the last minute. It is what the European AI Act actually says.

The phrase that isn't in the text

The Dutch technology publication Silicon Canals has highlighted a wording gap that has sat inside Europe's flagship AI law since the day it was agreed: the phrase "human in the loop" does not appear anywhere in the AI Act. Not once. Not even in Article 14, the article whose entire job is to govern human oversight of high-risk systems.

What Article 14 does say is that high-risk AI systems must be designed so they can be "effectively overseen by natural persons during the period in which the AI system is in use". It then lists what that oversight has to make possible: the person assigned to it should understand the system's abilities and its limits, remain aware of automation bias — the very human tendency to trust a machine's output too readily — be able to interpret the output correctly, and be able to disregard, override or reverse a decision, or press a stop button.

What it does not say is how often anybody has to do any of that. There is no minimum number of human beings per automated decision, no required reaction time, no rule that the human, rather than the software, must act first. A single operator watching a dashboard while the system runs sits inside the letter of the text — and that is precisely the arrangement the phrase "human in the loop" was invented to warn about.

Where the words came from: killer robots, 2012

The vocabulary is not European in origin, and it is older than most people assume. The taxonomy of "human in the loop", "human on the loop" and "human out of the loop" was codified in November 2012 in Losing Humanity: The Case Against Killer Robots, a report by Human Rights Watch and the International Human Rights Clinic at Harvard Law School.

The report argued for a ban on fully autonomous weapons, and one of its central warnings was that merely nominal human supervision — a person technically present but not genuinely deciding — produces machines that are autonomous in practice. Fourteen years later, that defence-sector vocabulary has been transplanted into commercial AI procurement, vendor slide decks and compliance checklists, where it now reads as a reassuring feature rather than the caution it was written as.

What Europe changed this year — and what it postponed

The timing matters. On 2 August 2026, the AI Act's transparency obligations took effect. Chatbots must tell users they are talking to a machine; deepfakes and certain synthetic content must be labelled; AI-generated material should carry machine-readable marking. In practice, that is the part of the law an ordinary European is most likely to notice in daily life — a disclosure line under a chat window, a label on a video.

The heavier obligations — including Article 14 oversight for high-risk uses such as biometric identification, recruitment and hiring systems, and migration controls — were deferred to December 2027. So the visible half of the Act is live, while the part meant to keep a human genuinely in charge of consequential decisions is, for now, mostly a design exercise that companies are preparing for rather than complying with.

That gap is not harmless. Procurement documents, internal risk assessments and vendor contracts are being drafted right now, and they are drafted in the law's language. If "effective oversight" quietly comes to mean "someone could look at it if they wanted to", that reading becomes the benchmark for years — long after the December 2027 deadline passes.

The rule that still bites: GDPR Article 22

Here is the part that is easy to miss. The AI Act is not the only European law in the room, and the older one is already enforceable. GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them — with narrow exceptions such as explicit consent, a contract, or a specific legal basis in law.

In December 2023 the Court of Justice of the European Union went further in the SCHUFA case, holding that the automated production of a probability value by a credit reference agency can itself amount to a "decision" under Article 22 where a third party leans strongly on that value. If you are refused credit, filtered out of a recruitment process or flagged by an automated check, you can ask for meaningful information about the logic involved, and you can contest the outcome — regardless of whether the AI Act's oversight deadline has arrived. Complaints go to your national data protection authority; in Czechia that is the ÚOOÚ.

What to ask before you sign

If you run a small business, a clinic or a school in Europe and you are buying an AI system now, the useful question is not "is there a human in the loop?" Almost every vendor will say yes. Ask instead:

  • Who, by name or role, is that person — and how many systems are they overseeing at the same time?
  • What exactly can they reverse, and how quickly?
  • Is that person measured on how fast the queue moves, or on how often they intervene? The first metric turns oversight into a rubber stamp.
  • What gets logged? If nobody records the overrides, oversight cannot be audited — by you or by a regulator.
  • And what happens when the person is on holiday?

The stakes are not abstract. Penalties under the Act reach €35 million or 7% of global annual turnover for the most serious breaches, and up to €15 million or 3% for most other obligations, including failures of Article 14 oversight. Those numbers are what make the wording of Article 14 worth reading closely rather than trusting a summary.

Is "human in the loop" a legal requirement anywhere in EU law?

The term itself is not a legal standard in the AI Act, which speaks instead of "human oversight". The idea of meaningful human involvement does appear elsewhere — GDPR Article 22 restricts decisions based solely on automated processing — but no European rule uses "human in the loop" as its wording.

Our AI system is not classified as high-risk. Do we still need human oversight?

Article 14's oversight duties apply to high-risk systems. But the transparency rules for chatbots and synthetic content have applied since 2 August 2026, and GDPR applies to any processing of personal data regardless of the AI Act's risk category — so a low-risk label does not switch off your other obligations.

When do the high-risk rules actually start applying?

Transparency duties have been in force since 2 August 2026. The high-risk obligations covering areas such as biometrics, hiring and migration were deferred to December 2027, so companies are currently preparing for them rather than being fully bound by them.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.