Human oversight

Human in the loop AI: where to put approvals and how to design them

How to choose between human in the loop, on the loop and out of the loop, where approval gates belong, and how to design approvals that people can actually decide on.

Human in the loop means a person approves or decides before an AI system acts. Put the gate where an action is irreversible, leaves your organisation, costs real money or touches sensitive data, and nowhere else, so approvers see few requests and read each one. An approval is only worth having if the approver sees the exact action, can say no and is not pressed to say yes. For some systems the EU AI Act sets human oversight duties, and whether yours is one of them depends on its use.

Last verified 2026-10-07. Sources are listed at the end of the page.

What is the difference between human in the loop, on the loop and out of the loop?

These terms vary between authors. The definitions below are the ones this page uses.

PatternWho decidesFitsWeakness
In the loopA person approves each action before it happens.Irreversible, external, costly or sensitive actions.Slow, and approvers tire and start clicking through.
On the loopThe system acts within limits. A person monitors and can intervene or stop it.Reversible, frequent actions where a delay is tolerable.Needs a working stop control, alerts and a person who is actually watching.
Out of the loopThe system acts and nobody reviews in time. Review, if any, happens after the fact from logs.Low-risk, easily undone work with strong tests.Errors spread before anyone sees them.

Where do approval gates belong?

Anthropic’s guidance on agents says to pause for human feedback at checkpoints or when the agent hits blockers. LangGraph’s documentation names the common case: pause before critical actions such as API calls, database changes and financial transactions. OWASP lists human approval for sensitive operations as a defence against injected instructions. Four tests decide most cases:

  • Irreversible. Deleting records, sending money, deploying to production, closing a case. If it cannot be undone, ask first.
  • External. Anything that leaves your organisation: an email to a customer, a post, a message to a supplier, a call to a third-party system.
  • Costly. Spend above a threshold that the process owner sets, or any action that starts large jobs.
  • Sensitive data. Reading or moving personal, confidential or regulated data beyond what the task needs.

How do you design approvals that people can actually decide on?

  1. Show the exact action

    The approver sees what will run: the tool, the arguments, the target and the effect, not a summary written by the model. An approval should apply to that call only. If the arguments change, ask again.

  2. Show the evidence

    Give the sources the agent used and anything that makes the request unusual. A request with no evidence is a request to trust.

  3. Keep the queue short

    If everything needs approval, nothing is read. Gate the four cases above and let low-risk steps run, with logs.

  4. Set a timeout and a default

    Decide what happens when nobody answers. For risky actions the safe default is deny. Escalate to a named backup before the request expires.

  5. Record who decided and why

    Take the decider’s identity from the authenticated session, not from a field the agent fills in. Keep the decision and the reason with the action.

  6. Make resuming safe

    LangGraph’s documentation warns that side effects before an interrupt must be idempotent, because the node re-runs on resume. Do the same in any design that pauses and resumes.

  7. Sample and review decisions

    Check a sample of approvals for approvals given too fast or too often. A rubber stamp is a control that has failed.

What does EU AI Act Article 14 say about human oversight?

Article 14, read on the European Commission’s AI Act Service Desk on 2026-10-07, concerns high-risk AI systems. It says they shall be designed so that natural persons can effectively oversee them while in use, with the aim of preventing or minimising risks to health, safety or fundamental rights. Oversight measures must be proportionate to the system’s risks and level of autonomy.

Paragraph 4 lists what the people given oversight must be enabled to do: understand the system’s capacities and limitations and monitor it; remain aware of the tendency to rely too much on its output, called automation bias; interpret its output correctly; decide not to use the system or to disregard, override or reverse its output; and intervene or interrupt it through a stop button or similar procedure. Article 26 adds that deployers assign oversight to people with the necessary competence, training and authority, and keep the logs under their control for at least six months, unless other law says otherwise.

Whether Article 14 applies to your system depends on whether it is high-risk, which turns on its purpose and your role, and on which dates apply to you. This page does not say. Use the AI Act high-risk checklist and take legal advice. The five oversight abilities are still a useful design test for any approval interface, regulated or not. Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.

What should an approval record contain?

An approval you cannot reconstruct later is hard to defend to an auditor or a customer. Keep these fields for every decision:

  • The request: the action, its exact arguments and the agent and run that asked.
  • The decider: an identity taken from the authenticated session, with the time of the decision.
  • The outcome: approved, rejected, expired or escalated, and the reason in the decider’s words.
  • What the approver was shown, by version, so you can tell later whether the evidence was adequate.
  • What happened next: the result of the action, or the fact that it did not run.

Where Swfte fits: what is built and what is not

The platform has five separate approval mechanisms and no single shared approval model. Do not assume one inbox covers them all.

MechanismStatusWhat it does
Nexus approvals for coding agentsBuiltThe first decision wins. The decider is stamped from the authenticated principal. A request that is not decided in time expires.
Cortex in-app tool approvalsBuiltApprovals are bound to the exact call. In a Claude Code session, anything beyond reading and searching prompts, and an unanswered prompt times out and denies. A high-risk gate covers send, pay, delete, push and shell.
Workflow human-input stepBuiltPauses a run for an assignee, with approve and reject branches and a default timeout.
Relay gates, governance ASK and mission approvalsBuiltSeparate queues with their own timeouts and escalation. Missions are not deployed to production for customers.
Four-eyes and segregation of dutiesNot builtNo check stops a person approving their own request. Approver roles are not enforced. Do not rely on Swfte for this today.
Autonomy levels L1 to L5 as an enforced settingRoadmapThe levels are described on controlled autonomy. L4 and L5 are designed for. They are not an enforced field.

For the step-by-step build see how to set up human approval for AI agents. If your agents are few and every action is reversible, a spreadsheet of decisions and a manual check may be enough, and you do not need Swfte for approvals.

Sources and last verified

Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.

Frequently asked questions

What does human in the loop mean in AI?

It means a person reviews or approves before an AI system acts or before its output is used. The person can accept, change or reject it. It is the strictest of the three common patterns, and the right one for irreversible, external, costly or sensitive actions.

What is the difference between human in the loop and human on the loop?

In the loop, a person approves each action first. On the loop, the system acts within set limits while a person monitors and can step in or stop it. On the loop suits frequent, reversible work. It only works if the stop control is real and someone is watching.

Which AI actions should always need human approval?

Actions that are irreversible, leave the organisation, cost money above a set threshold or move sensitive data. Sending, paying, deleting and deploying are typical. The threshold belongs to the process owner. Everything else can usually run with logging and a stop control, so approvers are not buried.

How do you stop approvers rubber-stamping?

Keep the queue short, show the exact action and its evidence, and let the approver say no without penalty. Sample decisions for approvals given too quickly. Article 14 of the EU AI Act names the tendency to over-rely on system output, automation bias, as something oversight people should stay aware of.

Does the EU AI Act require human in the loop?

Article 14 requires high-risk AI systems to be designed for effective human oversight. It does not use the label human in the loop, and it asks for oversight measures proportionate to risk and autonomy. Whether your system is high-risk depends on its use, so this page does not say. Check the AI Act Service Desk text and take advice.

Does Swfte enforce four-eyes approval?

No. Four-eyes and segregation of duties are not built. Nothing in the current approval mechanisms stops a person approving a request they started, and approver roles are not enforced. Swfte has several separate approval mechanisms and no single shared model, so check the one you use.

Tell us which actions your agents take and we will help place the gates.

See what your agents are actually doing

Nexus gives you governance, observability and spend control across every agent you run.