Human oversight design and override procedure
Ensures that competent people can understand, question, correct, stop or decline to use an AI system's output, and that the degree of human involvement is chosen deliberately for each decision point.
- Duties satisfied
- 3
- done properly, does the work
- Duties supported
- 8
- contributes; the duty needs more
- Jurisdictions
- 8
- Evidence items
- 3
How is it implemented?
For every decision point the system influences, the owner records whether a person decides with the system's help, reviews after the fact, or is only alerted on exceptions, and why that level is proportionate to the harm at stake. The interface exposes confidence, limitations and the reasons for an output where feasible, and includes a documented way to override, pause or shut the system down. Overseers are named, trained against automation bias and given the time and authority to intervene. Override events are logged and reviewed so that the oversight design can be tightened if interventions are rare or ineffective.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
European Union 4 duties
-
satisfies Legal requirement confidence highEnable and assign effective human oversight
EU AI Act · Article 14; Article 26(2) for deployers · applies from 2 Aug 2026
Oversight roles, interface measures, stop mechanism and override paths per deployment.
-
supports Legal requirement confidence highUse high-risk AI as instructed, monitor it and inform affected people
EU AI Act · Article 26 · applies from 2 Aug 2026
Assigning trained natural persons to oversee the system.
-
supports Legal requirementLaw-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
EU AI Act · Article 26(10) · applies from 2 Aug 2026
No adverse decision solely on the system's output.
-
supports Legal requirementDeployers must disclose deepfakes and AI-generated text published on matters of public interest
EU AI Act · Article 50(4) · applies from 2 Aug 2026
Editorial control that lifts the text-disclosure duty.
Singapore 1 duty
-
satisfies Voluntary confidence highDetermine the appropriate level of human involvement in AI decisions
Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making
Records the in-the-loop, over-the-loop or out-of-the-loop choice and rationale.
South Korea 1 duty
-
satisfies Legal requirement confidence highOperators of high-impact AI must ensure human management and supervision
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1) · applies from 22 Jan 2026
Named supervisors with monitoring and override capability.
Australia 1 duty
-
supports Voluntary confidence highTest and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
Australian Voluntary AI Safety Standard · Guardrails 4, 5 and 6
Guardrail 4: meaningful human control.
New York (United States) 1 duty
-
supports Legal requirementEmployers and employment agencies must let candidates request an alternative selection process or accommodation
NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1); 6 RCNY Section 5-303 · applies from 5 Jul 2023
Human-run alternative where one is offered.
United Arab Emirates 1 duty
-
supports Legal requirementRespect the right to object to automated decision-making without human intervention
UAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)
Design of the human intervention step.
United Kingdom 1 duty
-
supports Legal requirementApply safeguards to solely automated decisions with significant effects
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Meaningful human intervention design.
United States 1 duty
-
supports Legal requirementApply minimum risk-management practices to high-impact AI
OMB M-25-21 · Section 4
Human oversight and operator arrangements.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| Human oversight and override procedure | Procedure or standard operating process | Named overseers, the involvement level per decision point, escalation and stop mechanisms. |
| Human-involvement design rationale | Approval or sign-off record | Signed record of the oversight level chosen for each decision point and the reasoning. |
| Overseer training completion | Training record |
Owner: AI system owner. Frequency: once per ai system.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 5.1 Overreliance and unsafe use Human-Computer Interaction38 incidents · 60 risk entries
- 5.2 Loss of human agency and autonomy Human-Computer Interaction4 incidents · 47 risk entries
- 7.3 Lack of capability or robustness AI system safety, failures, & limitations305 incidents · 126 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Annex A.6.2.5, A.9.2, A.9.3 | medium | |
| NIST AI RMF | GOVERN 3.2; MAP 3.5; MANAGE 2.4 | high | |
| OECD AI Principles | Principle 1.2 Human-centred values and fairness | medium | |
| OWASP LLM Top 10 | LLM06 Excessive Agency | medium |
Cite this record
AIPolicyTracker (2026). “Human oversight design and override procedure”. https://aipolicytracker.org/controls/human-oversight-and-override (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Human oversight design and override procedure" satisfy?
- It is recorded as satisfying 3 and supporting 8 duties across European Union, Singapore, South Korea, Australia, New York (United States), United Arab Emirates, United Kingdom and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- Human oversight and override procedure, Human-involvement design rationale and Overseer training completion. Owner: AI system owner. Frequency: once per ai system.