What human oversight of an AI system really means (and the real levels that exist)
Equipo Tecnea
Tecnea
"Human oversight" is one of the most repeated phrases in any AI proposal for a business, and one of the least explained. Sometimes it means a person reviews every output before it's used. Sometimes it means someone is generally "aware" of the system, with no written process behind it. These are very different things, and the difference matters: the EU AI Act doesn't require "having someone behind it" — it requires a concrete design.
Here's what it actually means, the levels that exist in practice, and how you decide which one applies to each process.
Why it's a legal obligation, not just good practice
Regulation (EU) 2024/1689 (the EU AI Act) devotes its Article 14 to human oversight of high-risk systems: it requires them to be designed so that a natural person can effectively oversee them while in use, including the ability to decide not to use the system, to correctly interpret its output, and to interrupt or stop it. This isn't a best-practice recommendation — it's a design requirement, enforceable before the system goes into production.
Outside high-risk systems, GDPR adds another, older and well-established obligation: its Article 22 gives any individual the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them. In practice, this means that if an AI decides something with real consequences for a person — granting or denying something, scoring a risk, filtering an application — there has to be meaningful human involvement in that decision, not an "approve" button nobody actually looks at.
Both rules agree on the substance: oversight isn't a box to tick, it's a real capacity to understand, correct, and stop.
The real levels of human oversight
In a system's design, "human oversight" isn't one single thing. It's at least four distinct decisions, and a single project usually combines several:
1. Pre-execution approval. Nothing executes — no email is sent, no accounting entry is posted, no document is filed — without a person confirming it first. This is the level that applies to any action with an economic, legal, or client-facing effect. In an invoice-reading system, for example, the AI proposes the accounting entry, but a person gives the final confirmation before it's posted.
2. Sample-based supervision. The system acts within a bounded scope without requesting approval case by case, but a person reviews a representative sample — or the full history, depending on volume — with the real ability to correct the system's criteria if something fails. This fits low individual-risk, high-volume processes, such as a first pass at classifying incoming email.
3. Stop capability. There has to be a real mechanism to interrupt the system or stop using it, and someone with the responsibility and knowledge to activate it. This isn't purely technical: if nobody knows when to stop it, or nobody has permission to, the stop capability doesn't exist in practice, even if the button does.
4. Traceability as a precondition. None of the levels above work without this. If the system doesn't say which document, data point, or source each statement comes from, the person "supervising" has nothing to compare against — they're reviewing blind. That's why any well-designed system cites the source of every piece of data it uses, not just the final result.
What human oversight is not
Three patterns that get sold as human oversight and aren't:
- A person "available" with no written process. Someone on the team being able to glance at the system if something looks off isn't oversight — it's luck. Real oversight defines what gets reviewed, how often, and what happens if an error is found.
- Reviewing an output with no source. If the system delivers a conclusion without saying where it comes from, reviewing it just means re-reading the same hallucination with extra steps. Oversight requires the ability to verify, not just the ability to read.
- Symbolic approval. An "approve" button that most users click without looking, because the volume is too high to genuinely review, doesn't satisfy Article 14: the rule requires effective oversight capacity, not a formality.
How you decide which level applies to each process
The criterion isn't the technology, it's the effect of the decision:
| What the system decides | Oversight level | |---|---| | Legal, economic, or external-person effect (a payment, a filing, a reply to a client) | Pre-execution approval, always | | Internal, reversible, low individual-impact effect (classifying email, tagging documents) | Sample-based supervision, with traceability | | Any high-risk system under the EU AI Act | Pre-execution approval or intensive sample-based supervision, plus documented stop capability |
How we apply this at Tecnea
In every project, this decision is made process by process, in writing, before deployment: which oversight level applies to each action the system can take, who exercises it, and what traceability backs it up. It's part of the compliance documentation we deliver with every application, not an appendix written at the end.
Frequently asked questions
Does a system with no human oversight always break the law? Not always — it depends on the risk and the effect of the decision. A minimal-risk system with reversible decisions and no significant effect on a person can operate with sample-based supervision. Article 14 demands its strictest level for high-risk systems; GDPR's Article 22 comes into play for any automated decision with legal or significant effects, whether or not the system is high-risk.
Does human oversight slow the process down? Pre-execution approval adds a step, yes, but over an already-completed draft: the person reviews and confirms, they don't start from scratch. In low-risk processes with sample-based supervision, the system acts without waiting for case-by-case approval, so speed doesn't change.
Who should exercise oversight — can it be anyone on the team? It has to be someone with enough knowledge to interpret the output and spot an error, and with real authority to stop or correct it. Delegating it to someone with neither the knowledge nor the authority is exactly the symbolic approval described above.
Sources
- Regulation (EU) 2024/1689 (EU AI Act), Article 14 (human oversight): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689
- Regulation (EU) 2016/679 (GDPR), Article 22 (automated individual decision-making): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
This article is informational. Tecnea designs this level of oversight into every project it builds, so it has a commercial interest in companies taking it seriously — whether they do it with us or with any other provider.
¿Te ha resultado útil este artículo?
Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.
Did you like this article?
Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.