The phrase was born in engineering. A human in the loop was a checkpoint — a person somewhere in the pipeline who could catch what the machine missed. The law has now borrowed the phrase, and in borrowing it, changed its weight.
In one paragraph: from 2 August 2026, Article 14 of the EU AI Act (Regulation (EU) 2024/1689) requires high-risk AI systems to be designed for effective human oversight, and Article 26 requires the organisations deploying them to staff that oversight with people who hold real authority, competence, time and support. A human in the loop is no longer a UX pattern — it is the point in an automated process where accountability attaches to a human decision.
From checkpoint to duty
Article 14 is short and its verbs are concrete. High-risk AI systems must be designed and developed so that natural persons can effectively oversee them while in use. The measures the article contemplates read like a job description: the overseer must be able to understand the system’s capacities and limitations, stay alert to the pull of automation bias — the documented tendency to trust a machine’s output because it is a machine’s output — correctly interpret what the system produces, decide not to use it, disregard or reverse its output, and intervene or halt the system altogether.
The duty is split along the supply chain. The provider must design the system so this oversight is possible — interface, documentation, the stop button that actually stops. The deployer must operate it: Article 26 requires oversight to be assigned to natural persons who have the necessary competence, training and authority, and the support to use them. Design without staffing fails; staffing without design fails. The loop is a joint construction.
The liability sponge
Here is the failure mode the legal literature has already named. An organisation installs a human before the output ships — a reviewer, an approver, a person with a checkbox. The diagram is satisfied. But the person cannot stop the system, was never trained on its limits, sees a volume of output no one could meaningfully review, and holds a record that proves only presence, not power. When the harm arrives, the organisation points to the human: someone approved this. Scholars of Article 14 call this person a liability sponge — positioned to absorb blame for failures that are systemic, not personal.
The sponge is not only unjust; it is bad law and worse strategy. Oversight that exists on paper does not discharge the deployer’s Article 26 duty, and it manufactures an internal defendant without removing the organisation’s own exposure. The regulation’s answer is to make effectiveness the test — and effectiveness has conditions.
What ‘effective’ requires
Read Article 14 and Article 26 together and the test resolves into four conditions. Authority: the person can disregard the output, reverse it, or stop the system, and everyone upstream knows it. Competence: training on what the system can and cannot do, including the bias toward trusting it. Time and information: a review cadence at which reading is possible, with access to what the system actually saw. Record: an account that would show, later and to a stranger, that oversight could be exercised and was. Remove any one and what remains is presence, not oversight.
When the loop meets product liability
Oversight has a second life in court. The new Product Liability Directive (2024/2853) treats software and AI systems as products, and its evidence rules turn documentation into destiny: once a claim is plausible, courts can order disclosure of how the system works, and a gap in that record can become a presumption of defect the operator must rebut (see The Product You Didn’t Know You Shipped). The oversight record Article 14 demands and the rebuttal evidence the directive rewards are, in practice, the same file. A loop whose human can show authority, competence, time and a record is not just compliant — it is the defence. A loop that cannot show them is an exhibit for the claimant.
A human who signs
There is a profession whose entire architecture already answers the four conditions: authority that is personal, competence that is licensed, time that is billed precisely so review is real, and a record — the signature — that binds the professional to the position taken. A lawyer standing at the seam of an automated legal flow is a human in the loop in the fullest legal sense: professionally liable, insured, bound by deontology, and unable to hide behind the machine. That is the function this practice productises — the Human in the Loop protocol maps where an automated flow stops carrying weight and installs judgment there, and the governance kernel writes the record as the work happens (method in full: how we use AI).
The move
Three questions, answered plainly
- Is a human in the loop required by the EU AI Act?
- For high-risk AI systems, in substance yes: Article 14 requires the system to be designed so natural persons can oversee it effectively, and Article 26 requires the deployer to assign that oversight to people with the competence, training, authority and support to exercise it. The obligations apply from 2 August 2026.
- Who is liable when a human approves a bad AI decision?
- Approval alone does not shift liability onto the person who clicked. Oversight designed without real authority or information produces a 'liability sponge' — someone blamed for a systemic failure. Formal liability follows the instruments: the AI Act binds providers and deployers, and the Product Liability Directive holds economic operators strictly liable for defects.
- What makes human oversight 'effective' under Article 14?
- Four conditions, read together: authority to disregard, override or stop the system; competence and training to understand its capacities, limits and automation bias; time and information to actually review the output; and a record showing oversight could be and was exercised. Providers must design for this; deployers must staff it.
General information on Article 14 of Regulation (EU) 2024/1689 (the AI Act) and Directive (EU) 2024/2853 (the Product Liability Directive), not legal advice, and no lawyer–client relationship is created. Article 14 applies to systems classified as high-risk under the AI Act, with obligations phasing in from 2 August 2026; classification and the precise scope of oversight duties depend on the system and sector. Any specific situation needs advice on its own facts.
Running AI inside a regulated flow? Map who your humans in the loop are — and whether their oversight would hold up as evidence.
Free brochure
The cross-border enforceability checklist
A one-page brief on this topic, sent straight to your inbox.
Facing this on a live document?
Book a 30-minute clinic
A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.
Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.