In brief
- Human control needs a specific purpose and must not be reduced to a generic confirmation button.
- Review effort should reflect the risk, frequency and detectability of possible errors.
- People need understandable evidence, alternatives, uncertainty and the consequences of approval.
- The human part of the process must also be tested, measured and assigned organisational ownership.
What role can a person play in the process?
Human-in-the-loop is not one technical method. People may confirm data before processing, answer questions during the flow, review an output or approve a consequential action. The role should be selected deliberately for the relevant type of error.
A sample review may be sufficient for low-risk drafts. Financial, legal, safety-related or hard-to-reverse decisions usually require review before execution. Some tasks should remain entirely outside automated decision paths.
| Risk level | Suitable review | Timing | Escalation |
|---|---|---|---|
| Low: easily corrected internal draft | Sample review and feedback by domain staff | After use or in a weekly batch | Repeated error goes to the product owner |
| Medium: customer communication or relevant domain data | Complete domain review with supporting evidence | Before sending or writing to a business system | Ambiguous cases go to a senior domain reviewer |
| High: financial, legal or hard-to-reverse consequence | Explicit approval using original data and highlighted deviations | Immediately before the action | Named decision authority; no automatic continuation |
| Unacceptable: review cannot prevent harm in time | No automated decision or execution | Keep the task outside the autonomous path | Redesign the process and accountability first |
When is human control genuinely effective?
Review is effective only if the person is suitably qualified, sufficiently independent and not overloaded by unrealistic case volumes. They need to understand which parts came from AI, what evidence supports the output and which limitations are known.
The interface should not encourage automatic acceptance. Sources, deviations, uncertain fields and the concrete effect of approval must be visible. The reviewer needs a real ability to reject, correct or escalate.
- Explicit review criteria instead of a general instruction to check
- Adequate time and appropriate subject-matter competence
- Access to original data and supporting evidence
- No penalty for stopping or escalating a case
How should approval points be designed?
Approvals belong where a person can still intervene effectively. Rather than confirming every minor intermediate step, the process should define relevant risk thresholds, such as amount limits, external recipients, sensitive data, low confidence or conflicting sources.
- Step 1
Identify failure impact
Determine which wrong outputs or actions are possible and how difficult they would be to detect or reverse.
- Step 2
Choose the intervention point
Place review where all necessary information is available before a consequential effect occurs.
- Step 3
Present the basis
Show original data, sources, proposed changes and consequences side by side.
- Step 4
Define escalation
Decide who takes over when there is uncertainty, conflict or a repeated failure.
How do you evaluate the human-AI combination?
A technically capable model can still create a poor overall process if people accept suggestions uncritically or become numb to excessive warnings. Tests must therefore reflect actual working conditions rather than evaluating the model output in isolation.
- Measure critical errors detected and missed by reviewers
- Analyse corrections, rejections and escalations by case type
- Include time pressure, interruptions and high volumes in pilots
- Update review rules and training as new failure patterns appear
Example: reviewing contract deviations
AI compares incoming supplier contracts with approved standard clauses. Harmless formatting differences are flagged but do not each require approval. For liability, termination or data sharing, the application displays the original clause, standard text and reasoned deviation side by side. A legally accountable person decides and can reject or escalate the case. The approval and its basis are logged.
What to remember
Do not define only that a human is involved. Define which decision that person makes, with what information and authority. That is what turns human-in-the-loop into a dependable control.
Sources and further reading
These primary sources provide further detail on definitions, technical foundations or responsible use.
Content reviewed