top of page

Human Authority in the Age of AI · Canonical Paper · Section 2

Why a Human in the Loop Is Not Enough

The conditions of meaningful human oversight

Written by Karina Carlos, Founder of Self-Conquest
Canonical source: karinacarlos.com
Methodology body and gateway: Self-Conquest
Author-approved and source-verified · Version 0.3 · 30 August 2026

Human oversight is not a role assignment. It becomes meaningful only when people with relevant competence can access the governing context, form a reasoned position that is not predetermined by system output or hierarchical pressure, communicate it through protected and traceable channels, exercise role-appropriate intervention rights with the organizational support necessary to make those rights real, and remain answerable within a clear accountability structure.

The previous section established that human beings are not reliable by default. That fact makes a common governance shortcut untenable: placing a person somewhere in a workflow and treating their presence as proof that the decision remains under human control.

A human may appear in the loop while doing little more than confirming a recommendation already framed by the system, the interface, the deadline, or the authority structure around the decision. The person may lack the information required to challenge it, the competence to interpret its limitations, the time to investigate, the mandate to resist, or a protected route for escalation. Under those conditions, review is ceremonial. Responsibility remains visible; authority does not.

The presence fallacy

The phrase human in the loop describes a position in a process. It does not establish the quality of the judgment exercised there. A checkpoint may be technically human and still fail to provide meaningful oversight if the reviewer cannot understand the system, evaluate the situation beyond the system's framing, or alter what happens next.

This distinction is already visible in governance standards. For high-risk systems, Article 14 of the EU AI Act does not stop at requiring a person to be present. It requires oversight measures proportionate to risk, autonomy, and context, and it specifies that assigned people must be enabled to understand capabilities and limitations, remain alert to automation bias, interpret outputs, disregard or override them, and interrupt the system. [1] NIST similarly calls for clear roles, trained and empowered people, differentiated human-AI responsibilities, executive accountability, and a critical-thinking culture. [2]

Articles 14 and 26 allocate different parts of the oversight problem. Article 14 establishes system-level oversight capability; Article 26 creates a deployer-side duty to assign that oversight to natural persons with the necessary competence, training, authority, and support. Recital 91 connects competence, in particular, to an adequate level of AI literacy. Article 26(3) preserves other obligations independently imposed on the deployer under Union or national law while leaving the deployer free to organize its resources and activities. Organizational form remains flexible; substantive oversight capacity does not. [1]

These sources apply in different jurisdictions and carry different legal weight. They should not be collapsed into a universal legal definition. Their shared direction is nonetheless consequential: oversight is a functional condition, not a headcount variable.

Why nominal oversight fails

 

AI-supported decisions create a particular risk because a fluent or pre-structured recommendation can reduce the felt need to construct an independent view. The reviewer may inspect the answer without reconstructing the problem. The presence of an explanation can increase confidence without producing deeper evaluation.

 

In an experiment with 199 participants, Buçinca, Malaya, and Gajos found that simple explanations did not reliably reduce overreliance on incorrect AI suggestions. Cognitive-forcing designs reduced overreliance more effectively, but the designs that worked best were rated least favorably. [3] The trade-off matters: mechanisms that require more active thought can feel less convenient than interfaces that make agreement easy.

 

Expertise does not eliminate the problem. In a study involving 18 clinicians, automated label recommendations could support work, but fully pre-populated suggestions led participants to show less agency: they accepted improper mentions and took less initiative in adding missing annotations. [4] This does not show that automation is inherently harmful. It shows that the form in which assistance is presented can change the quality of human participation.

 

The practical implication is precise. A reviewer should not be evaluated only by whether a final action passed through human hands. The organization must examine whether the person formed a reasoned position that was not predetermined by the recommendation or the surrounding authority structure, noticed what the recommendation omitted, and retained the ability to change the course of action.

 

Context must be actively governed

 

My earliest work with AI made one operational limit visible: the quality of the result depended heavily on the quality and completeness of the context I supplied. As memory improved, the need to restate every fact diminished. Yet accumulated context did not guarantee that the system would keep the right priorities in the right order as the work evolved.

 

A workflow could retain prior information and still become side-tracked. An earlier objective, a locally compelling branch, or the momentum of continued generation could begin to dominate the task even after the governing priority had changed. The corrective act was not simply to provide more information. It was to re-establish the hierarchy: restate the decision, re-rank the constraints, identify what no longer mattered, and close the branch that no longer served the outcome.

 

This is not a claim that an AI system has motives of its own, nor that memory is without value. It is a practice-based observation about contextual drift. Information can be present without being governed well. The same is true in human teams: shared history does not remove the need to realign people when scope, stakes, or priorities change.

 

Practice distinction. Context is not merely the amount of information available. It is the current hierarchy of stakes, constraints, responsibilities, and consequences that should govern the decision.

 

Competence before control

 

Meaningful oversight begins with competence, but competence here is not a generic claim of intelligence or seniority. It is the role-specific ability to understand the decision context, interpret what the system can and cannot establish, and evaluate the recommendation rather than merely process it.

 

The difference is observable. A genuine evaluator asks why the recommendation makes sense, what the team was not seeing before, what has changed, which assumptions carry the conclusion, and what evidence would disconfirm it. The evaluator asks how success will be measured, on what timeline, at what scale, and with what consequences for adjacent stakeholders. A nominal approver is more likely to focus on the immediate task, the speed of completion, or whether the output appears usable now.

 

Evaluation threshold. The question is not whether a person read the recommendation. It is whether that person could reconstruct the decision, identify what the recommendation leaves unresolved, and form a defensible position of their own.

 

Competence is therefore inseparable from calibrated trust. The person must know when the system is operating within a validated scope, when additional evidence is required, and when a contextual change makes prior confidence no longer transferable. Explanation can assist this work; it cannot substitute for it.

 

Authority must be exercisable

 

Competence without the right to act produces an informed spectator. To exercise Human Authority, the reviewer must have more than permission to observe. The operating model must make the following actions available and legitimate in proportion to the stakes:

 

Right of intervention: Question
What it makes possible: Challenge the objective, assumptions, framing, relevance, or proposed course.

 

Right of intervention: Request evidence
What it makes possible: Obtain the basis, limitations, uncertainty, provenance, tests, or corroboration required to evaluate the output.

 

Right of intervention: Disregard
What it makes possible: Decline to use a recommendation without being penalized for failing to defer to the system.

 

Right of intervention: Modify
What it makes possible: Adapt the recommendation when context, stakeholder needs, or governing constraints require a different course.

 

Right of intervention: Stop
What it makes possible: Pause the system or its use when conditions move outside the approved scope or risk tolerance.

 

Right of intervention: Escalate
What it makes possible: Transfer the decision when authority, evidence, or expertise is insufficient at the current level.

 

Right of intervention: Document
What it makes possible: Record the reasoning, intervention, residual uncertainty, and accountability path.

 

Not every reviewer needs to exercise every right in every decision. The point is that the rights must be real, understood, technically possible, and organizationally protected. A stop control that cannot be used without retaliation is not a meaningful control. An escalation path that exists only on paper is not a governance mechanism.

 

The organization remains in the loop

 

Oversight can fail even when the individual has sufficient knowledge. In practice, ambiguity of mandate is a recurring inhibitor. High-performing people may recognize a problem but remain silent when a superior controls access, credit, or the communication of results. The informal rule is familiar: do not threaten the person who owns the room. Under time pressure, that political calculation can become stronger than the formal duty to challenge.

 

This is why Human Authority cannot be reduced to personal courage. NIST states that effective AI risk management requires organizational accountability mechanisms, roles, culture, and incentive structures, and that a framework alone cannot create them. Its human-AI appendix specifically identifies the need to study whether people are empowered and incentivized to challenge system output. [2]

 

The Regulation does not exhaustively define “necessary support.” [1] In this paper, the term identifies the organizational conditions that make oversight exercisable rather than ceremonial. Depending on context and material risk, these may include sufficient time and attention, access to relevant system and governing information, manageable workload, technical or domain assistance, protected communication and escalation channels, documentation infrastructure, and institutional backing for legitimate intervention. This is an operational specification within Human Authority, not an exhaustive statutory definition.

 

Operational guidance from the UK Information Commissioner's Office adds practical conditions: reviewers need appropriate qualifications, training, manageable caseloads, independence, and the ability to influence senior decision-making; overrides and their reasons should be logged. [5] The guidance is currently under review following changes in UK law, so it is used here as an operational reference rather than a universal legal rule.

 

AI does not automatically remove organizational politics or produce integrity. It may create an opportunity to make reasoning more explicit, criteria more consistent, and interventions more traceable. Those same systems can also encode existing power, narrow what counts as evidence, or make a predetermined decision appear objective. The direction depends on design, incentives, decision rights, and the ability of people to contest the process.

 

The defensible institutional proposition is therefore conditional: transparent criteria, preserved records, independent challenge rights, and auditable escalation can reduce the space in which unexamined influence determines outcomes. Technology can support that shift. It cannot substitute for the governance choices required to produce it.

 

Accountability without scapegoating

 

A final danger arises when a person is formally designated as the human safeguard but has limited control over the system, the deployment, or the surrounding incentives. Madeleine Clare Elish calls this a moral crumple zone: responsibility is absorbed by the nearest human operator when agency and control were actually distributed across a complex sociotechnical system. [6]

 

Human Authority requires answerability, but answerability must follow role, knowledge, and control. It should not become a device for transferring upstream failures onto the person closest to the final action. Responsibility in AI-assisted work must remain distributed and explicit.

 

Role: Operator
Irreducible duty: Exercise care, diligence, and excellence; stay within scope; question, document, and escalate when conditions change.
Accountability boundary: Own the quality of operation and the interventions available to the role - not hidden design choices or sponsor decisions the operator could not control.

 

Role: Executive sponsor
Irreducible duty: Define intended use, risk tolerance, decision rights, resources, success measures, and escalation; treat implementation as provisional and monitor continuing fitness.
Accountability boundary: Own the organizational decision to authorize, continue, modify, or stop the deployment and the consequences of inadequate governance.

 

Role: Provider / designer
Irreducible duty: Communicate capabilities, limitations, intended use, known risks, and performance evidence; support incident response and continual improvement.
Accountability boundary: Answer for design, disclosure, testing, and performance obligations within the provider's control; deployment context does not erase provider responsibility, and procurement does not erase deployer responsibility.

 

This allocation is consistent with the broader direction of the OECD AI Principles, which ties accountability to role and context, calls for traceability across the system lifecycle, and supports mechanisms to override, repair, or decommission systems when needed. [7] NIST likewise emphasizes that all relevant actors must manage the risks connected to what they design, deploy, or use. [2]

 

The Human Authority threshold

 

Meaningful Human Authority exists when people with relevant competence and governing context can form a reasoned position not predetermined by an AI recommendation or hierarchical pressure, communicate it through protected and traceable channels, and exercise jurisdiction-appropriate intervention rights with the organizational support necessary to make those rights real. Every participant assigned a consequential role must be able to question, document, and escalate without retaliation; rights to disregard, modify, authorize, or stop depend on competence, jurisdiction, and material risk. Governing bodies must review material operational evidence, provide a reasoned response, document the governing criteria and final decision, and allocate accountability according to knowledge and control.

 

Governing principle. The irreducible human act is to govern the legitimacy of action: to determine and revise its purpose and criteria, judge tradeoffs and exceptions, authorize or interrupt execution, and remain answerable for its consequences within a transparent structure of accountability.

 

This threshold does not require manual review of every automated action. Execution must first survive structured contestation, real-world testing, exception discovery, and clear allocation of decision rights to be considered sufficiently mature, bounded, measurable, and governable to scale through automation. The threshold becomes material when decisions allocate meaningful risk, rights, resources, responsibility, or strategic direction; when context changes; or when a person is expected to bear consequences on behalf of the system.

 

The claim is also not that human intervention will improve every outcome. Human beings can introduce bias, inconsistency, fear, status protection, and error. The purpose of Human Authority is not to presume human superiority. It is to ensure that consequential use remains governable: contestable by a competent person, alterable when conditions change, and answerable through an explicit structure of responsibility.

 

Normative boundary. Applicable law is a minimum floor, not the full boundary of legitimate action. Where regulation lags, a duty to prevent foreseeable harm may remain. The common good permits collective benefit without violating fundamental rights, imposing disproportionate harm on less powerful groups, or externalizing material consequences onto people excluded from the decision.

 

The next task is to define the category itself. If authority is neither guaranteed by human presence nor conferred by title, what capacities allow a person to remain discerning, agentic, legible, and accountable when stakes rise? The following section sets out the dimensions of Human Authority and the ethical boundaries that distinguish it from dominance, certainty, or control for its own sake.

 

Continue to Section 3: Defining Human Authority →

 

Scope and boundaries

 

This section does not claim that every AI-assisted decision requires manual human review.

 

It does not claim that a human reviewer is inherently more accurate, ethical, or reliable than an AI system.

 

It does not treat the EU AI Act's high-risk requirements or UK data-protection guidance as a universal legal definition of meaningful oversight.

 

It does not present the operational examples of “necessary support” in this section as an exhaustive statutory definition; they are a Human Authority specification whose application depends on context and material risk.

 

It does not claim that explanations alone create understanding, or that expertise alone prevents automation bias.

 

It does not claim that AI will eliminate organizational politics, create meritocracy, or produce integrity without appropriate governance.

 

It does not place sole responsibility on the operator or sole responsibility on the provider; accountability follows role, knowledge, control, and the applicable legal and contractual environment.

 

It does not present the Self-Conquest methodology as scientifically validated or as a substitute for technical, legal, risk, compliance, or domain-specific oversight.

 

It does not define the common good as simple majority preference; collective benefit does not legitimize violations of fundamental rights or disproportionate harm imposed on less powerful groups.

 

Sources

 

These sources support specific legal, governance, and empirical propositions in this essay. They apply within their own scope and jurisdiction. They are not offered as a universal legal definition of meaningful oversight or as scientific validation of the complete Human Authority or Self-Conquest methodology.

 

  1. European Union (2024; consolidated version current 27 July 2026). Regulation (EU) 2024/1689 (Artificial Intelligence Act), especially Article 3(56), Articles 4, 14, and 26, Recital 91, and Article 113 as amended. The substantive wording of Articles 14 and 26 remains unchanged; application timing was amended by Regulation (EU) 2026/1744. Access source

  2. National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). Access source

  3. Buçinca, Malaya, and Gajos (2021). To Trust or to Think: Cognitive Forcing Functions Can Reduce Overreliance on AI in AI-Assisted Decision-Making. Access source

  4. Levy, Agrawal, Satyanarayan, and Sontag (2021). Assessing the Impact of Automated Suggestions on Decision Making: Domain Experts Mediate Model Errors but Take Less Initiative. Access source

  5. UK Information Commissioner's Office (current guidance). Human Review - AI Audit Toolkit. Access source The ICO states that this guidance is under review following the Data (Use and Access) Act.

  6. Madeleine Clare Elish (2019). Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction. Access source

  7. Organisation for Economic Co-operation and Development (updated 2024). OECD AI Principles. Access source

About the author

 

Karina Carlos founded Self-Conquest, a developing methodology for Human Authority in the age of AI. Her work in executive communication and discernment under pressure examines how competence becomes accessible, legible, and usable in consequential conditions.

 

Authorship, version and citation

 

Written by Karina Carlos, Founder of Self-Conquest.
Published by Self-Conquest as the methodology body.
Based on the author-approved, source-verified Human Authority canonical paper.

 

Canonical source: karinacarlos.com
Methodology gateway: self-conquest.com
Source record: Human Authority in the Age of AI, Section 2, Source-Verified Claim Lock V0.3, 30 August 2026.
Web edition: 0.1

Suggested citation: Carlos, Karina. "Why a Human in the Loop Is Not Enough." Human Authority in the Age of AI, Section 2. Self-Conquest, 2026. https://www.karinacarlos.com/human-authority/why-human-in-the-loop-is-not-enough.

Continue the work

This essay is part of the canonical Human Authority in the Age of AI series on karinacarlos.com.

Return to the Human Authority overview →
Read Section 1: The Category Shift →
Read Section 3: Defining Human Authority →
Read Section 4: The Access Problem →
About Karina Carlos →
Read the Spanish executive synthesis →

For the methodology pathway and its applications, continue through Self-Conquest.

Enter the Self-Conquest methodology gateway →

bottom of page