All insights AI regulation · Liability

The Human in the Loop Is a Legal Role

Engineering calls it a checkpoint. From 2 August 2026, EU law treats it as a duty — Article 14 of the AI Act asks for a human whose oversight is effective, and what that word demands decides whether the person in the loop carries authority or merely absorbs blame.

Răzvan Alexandru Olaru20 July 20269 min read

The phrase was born in engineering. A human in the loop was a checkpoint — a person somewhere in the pipeline who could catch what the machine missed. The law has now borrowed the phrase, and in borrowing it, changed its weight.

In one paragraph: from 2 August 2026, Article 14 of the EU AI Act (Regulation (EU) 2024/1689) requires high-risk AI systems to be designed for effective human oversight, and Article 26 requires the organisations deploying them to staff that oversight with people who hold real authority, competence, time and support. A human in the loop is no longer a UX pattern — it is the point in an automated process where accountability attaches to a human decision.

From checkpoint to duty

Article 14 is short and its verbs are concrete. High-risk AI systems must be designed and developed so that natural persons can effectively oversee them while in use. The measures the article contemplates read like a job description: the overseer must be able to understand the system’s capacities and limitations, stay alert to the pull of automation bias — the documented tendency to trust a machine’s output because it is a machine’s output — correctly interpret what the system produces, decide not to use it, disregard or reverse its output, and intervene or halt the system altogether.

The duty is split along the supply chain. The provider must design the system so this oversight is possible — interface, documentation, the stop button that actually stops. The deployer must operate it: Article 26 requires oversight to be assigned to natural persons who have the necessary competence, training and authority, and the support to use them. Design without staffing fails; staffing without design fails. The loop is a joint construction.

THE AUTOMATED FLOWInputModel outputdraft · score · decisionHumanoversight · Art. 14Legal effectsigned position · decision with consequencesaccountability attaches here
The law does not regulate the loop; it regulates the human node — oversight is where accountability attaches.

The liability sponge

Here is the failure mode the legal literature has already named. An organisation installs a human before the output ships — a reviewer, an approver, a person with a checkbox. The diagram is satisfied. But the person cannot stop the system, was never trained on its limits, sees a volume of output no one could meaningfully review, and holds a record that proves only presence, not power. When the harm arrives, the organisation points to the human: someone approved this. Scholars of Article 14 call this person a liability sponge — positioned to absorb blame for failures that are systemic, not personal.

The sponge is not only unjust; it is bad law and worse strategy. Oversight that exists on paper does not discharge the deployer’s Article 26 duty, and it manufactures an internal defendant without removing the organisation’s own exposure. The regulation’s answer is to make effectiveness the test — and effectiveness has conditions.

THE LIABILITY SPONGECannot stop or override the systemVolume makes review a rubber stampUntrained on capacities and limitsRecord proves presence, not powerblame without powerTHE LOAD-BEARING HUMANCan disregard, override, interruptTime and information to actually reviewTrained on limits and automation biasRecord proves intervention was possibleauthority with accountability
Same seat, two legal meanings — oversight without authority absorbs blame; oversight with authority carries it.

What ‘effective’ requires

Read Article 14 and Article 26 together and the test resolves into four conditions. Authority: the person can disregard the output, reverse it, or stop the system, and everyone upstream knows it. Competence: training on what the system can and cannot do, including the bias toward trusting it. Time and information: a review cadence at which reading is possible, with access to what the system actually saw. Record: an account that would show, later and to a stranger, that oversight could be exercised and was. Remove any one and what remains is presence, not oversight.

ALL FOUR, TOGETHERAuthority — override, disregard, stopCompetence — limits, automation biasTime & information — real reviewRecord — intervention provableOversight that carries legal weighteffective within the meaning of Art. 14Provider designs for it (Art. 14) · Deployer staffs it (Art. 26)
Article 14 in one test — remove any one condition and what remains is presence, not oversight.

When the loop meets product liability

Oversight has a second life in court. The new Product Liability Directive (2024/2853) treats software and AI systems as products, and its evidence rules turn documentation into destiny: once a claim is plausible, courts can order disclosure of how the system works, and a gap in that record can become a presumption of defect the operator must rebut (see The Product You Didn’t Know You Shipped). The oversight record Article 14 demands and the rebuttal evidence the directive rewards are, in practice, the same file. A loop whose human can show authority, competence, time and a record is not just compliant — it is the defence. A loop that cannot show them is an exhibit for the claimant.

A human who signs

There is a profession whose entire architecture already answers the four conditions: authority that is personal, competence that is licensed, time that is billed precisely so review is real, and a record — the signature — that binds the professional to the position taken. A lawyer standing at the seam of an automated legal flow is a human in the loop in the fullest legal sense: professionally liable, insured, bound by deontology, and unable to hide behind the machine. That is the function this practice productises — the Human in the Loop protocol maps where an automated flow stops carrying weight and installs judgment there, and the governance kernel writes the record as the work happens (method in full: how we use AI).

The move

Before 2 August 2026, inventory your loops. For every automated decision that touches legal effect — a contract clause, a credit score, a content takedown, a filing — name the human, and test the four conditions: could they stop it; do they understand it; do they have time to read it; what would the record prove. A loop whose human fails the test is not oversight. It is a diagram — and, after a claim, an admission.

Three questions, answered plainly

Is a human in the loop required by the EU AI Act?
For high-risk AI systems, in substance yes: Article 14 requires the system to be designed so natural persons can oversee it effectively, and Article 26 requires the deployer to assign that oversight to people with the competence, training, authority and support to exercise it. The obligations apply from 2 August 2026.
Who is liable when a human approves a bad AI decision?
Approval alone does not shift liability onto the person who clicked. Oversight designed without real authority or information produces a 'liability sponge' — someone blamed for a systemic failure. Formal liability follows the instruments: the AI Act binds providers and deployers, and the Product Liability Directive holds economic operators strictly liable for defects.
What makes human oversight 'effective' under Article 14?
Four conditions, read together: authority to disregard, override or stop the system; competence and training to understand its capacities, limits and automation bias; time and information to actually review the output; and a record showing oversight could be and was exercised. Providers must design for this; deployers must staff it.

General information on Article 14 of Regulation (EU) 2024/1689 (the AI Act) and Directive (EU) 2024/2853 (the Product Liability Directive), not legal advice, and no lawyer–client relationship is created. Article 14 applies to systems classified as high-risk under the AI Act, with obligations phasing in from 2 August 2026; classification and the precise scope of oversight duties depend on the system and sector. Any specific situation needs advice on its own facts.

Running AI inside a regulated flow? Map who your humans in the loop are — and whether their oversight would hold up as evidence.

Free brochure

The cross-border enforceability checklist

A one-page brief on this topic, sent straight to your inbox.

Facing this on a live document?

Book a 30-minute clinic

A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.

Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.