# Human oversight design and override procedure

- **Record type**: Control
- **Kind**: Process
- **Owner**: AI system owner
- **Frequency**: Once per AI system
- **Duties served**: 11

## What the control achieves

Ensures that competent people can understand, question, correct, stop or decline to use an AI system's output, and that the degree of human involvement is chosen deliberately for each decision point.

## How it is typically implemented

For every decision point the system influences, the owner records whether a person decides with the system's help, reviews after the fact, or is only alerted on exceptions, and why that level is proportionate to the harm at stake. The interface exposes confidence, limitations and the reasons for an output where feasible, and includes a documented way to override, pause or shut the system down. Overseers are named, trained against automation bias and given the time and authority to intervene. Override events are logged and reviewed so that the oversight design can be tightened if interventions are rare or ineffective.

## Evidence it produces

- Human oversight and override procedure (procedure): Named overseers, the involvement level per decision point, escalation and stop mechanisms.
- Human-involvement design rationale (approval_record): Signed record of the oversight level chosen for each decision point and the reasoning.
- Overseer training completion (training_record)

## Legal duties this control serves

- Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6) — Australian Voluntary AI Safety Standard, Australia (supports): https://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency
- Enable and assign effective human oversight — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-human-oversight
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-50-4-deepfake-and-public-interest-text-disclosure
- Determine the appropriate level of human involvement in AI decisions — Singapore Model AI Governance Framework, Singapore (satisfies): https://aipolicytracker.org/obligations/singapore-mgf-human-involvement
- Operators of high-impact AI must ensure human management and supervision — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-human-oversight
- Respect the right to object to automated decision-making without human intervention — UAE PDPL, United Arab Emirates (supports): https://aipolicytracker.org/obligations/uae-pdpl-automated-decision-objection
- Apply safeguards to solely automated decisions with significant effects — ICO AI guidance, United Kingdom (supports): https://aipolicytracker.org/obligations/uk-ico-automated-decision-safeguards
- Employers and employment agencies must let candidates request an alternative selection process or accommodation — NYC Local Law 144 (automated employment decision tools), New York (United States) (supports): https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-alternative-process-request
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States (supports): https://aipolicytracker.org/obligations/us-omb-m-25-21-high-impact-ai-practices

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.6.2.5, A.9.2, A.9.3
- NIST AI RMF 1.0: GOVERN 3.2; MAP 3.5; MANAGE 2.4
- OECD AI Principles: Principle 1.2 Human-centred values and fairness
- OWASP Top 10 for LLM Applications: LLM06 Excessive Agency

## MIT AI Risk Repository subdomains addressed

5.1, 5.2, 7.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/human-oversight-and-override
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
