Skip to content
Founderz: Responsible Use of AI home

in collaboration with Microsoft

The ten principles

Principle 01 · Before you start · Human in the loop

Human oversight of AI

People decide what AI may do on its own, where a person reviews the work and which decisions remain human.

Key question

If this goes wrong, can it be undone, and who would it affect?

Benefit

Clear limits make it possible to delegate more, because everyone knows where a person steps in.

Context

For most people, AI began as a chat window: it answered, and you decided what to do with the answer. Today AI also acts. Assistants send emails, book meetings, update records and hand work to other agents. The question has moved from “is this answer right?” to “what is this allowed to do without me?”

Decide that in advance and you can delegate more. With a clear limit in place, an agent can work through two hundred routine requests while you handle the three that need you.

Four levels of human oversight

LevelWhat AI doesWhat you doGood for
1. AI draftsProduces materialDecide what to use, change or discardWriting, analysis, research, ideas
2. AI proposesPrepares a specific actionApprove that exact action before it happensClient emails, payments, changes to records
3. AI acts within limitsActs alone inside limits set in its permissionsWatch, handle exceptions and stop it when neededRoutine work that’s easy to undo, such as sorting, tagging or booking internal rooms
4. You do itNothing on its ownDecide yourselfDecisions about people, and costly actions you can’t reverse

To choose a level, ask three questions. Can it be undone? Who else is affected? What does it cost if it’s wrong? Anything irreversible, external or about a person starts at level 2 or 4.

The levels build on three kinds of human oversight that the EU’s High-Level Expert Group on AI described in 2019: in the loop, on the loop and in command. Level 2 is the everyday form of being in the loop, and level 3 of being on it. Choosing the level for each task puts you in command. The glossary has the full definitions.

Effective checkpoints

At an effective checkpoint you see what will actually happen: the recipient, the amount, the wording, the record. You have the time and the knowledge to judge it. Saying no stops it, and silence never counts as yes. If the action changes after you approve it, it comes back to you. A second AI can review the work as well, and its agreement still doesn’t count as your approval.

The easiest way to fall out of the loop is to approve by habit. If you click “approve” on everything, you’re present, but you’re no longer deciding. Researchers call this automation bias, and the EU AI Act asks for human oversight that guards against it. Singapore’s framework for agentic AI adds a practical warning sign: when reviewers almost never override the system, or approve very fast, check whether anyone is really reviewing.

Decisions about people

Some decisions stay with people, whatever the tool can do: hiring, promotion, pay, performance ratings and dismissals, and anything that changes someone’s access to money, health care or public services. AI can help with the administration, such as drafting a job advert or scheduling interviews. The decision is yours, made on criteria you can explain, and it follows your organization’s HR and legal process.

In many places this is also the law. The EU AI Act treats AI used to recruit, promote, dismiss or evaluate workers as high-risk, and the GDPR gives people rights when a decision with significant effects on them is made solely by automated means. Where the law fits has the detail.

Practices

  1. 01Name the level before you start: AI drafts, AI proposes, AI acts within limits, or you do it.
  2. 02Read before you approve. If you can’t judge it, ask someone who can.
  3. 03Keep a way to stop the work and undo what it did.
  4. 04Keep decisions about people with people, on criteria you can explain.
  5. 05When the task, the data or the tool changes, choose the level again.

Prompt examples

A prompt before and after improvement, and the part a person does outside the prompt.

Customers

Refunds in the support queue

Before

“Answer the complaints in the support queue and refund anyone who qualifies.”

After

“For each complaint in the support queue, draft a reply and recommend one action: refund, replacement or escalation. Cite the policy clause you used. Put everything in a review list for me.”

Your part

Approve each reply and each refund yourself. Check that the agent’s permissions make every refund wait for you, because the prompt alone can’t hold one back.

Why it works: The agent does the preparation at speed. The decision that costs money stays with a person, who sees the policy behind each one.

Operations and projects

Moving a meeting

Before

“Move tomorrow’s project review to Friday and let everyone know.”

After

“Find three slots on Friday when all six attendees are free. Draft a short message explaining the move. Don’t change the calendar or send anything yet.”

Your part

Pick the slot, check the message and send it, and make sure the agent can’t change calendars without your approval. Once you’ve seen it get this right a few times, you might let it act alone for internal meetings. That’s level 3, and it’s your call.

Why it works: Starting at level 2 shows you how the agent behaves before you give it more freedom.

People and hiring

Preparing interviews

Before

“Rank these 40 résumés and tell me who to interview.”

After

“Using the attached job description, draft eight interview questions that test the four must-have skills, with what a strong answer would include.”

Your part

Screen and choose candidates yourself, through your HR process. AI helps you prepare, and the decision about people stays with people.

Why it works: AI saves time on the preparation, while the decisions that affect someone’s chances stay explainable and lawful.

Evidence

  • The EU AI Act requires high-risk AI systems to be built so the people overseeing them stay aware of automation bias, the tendency to over-rely on the output. [EU AI Act]
  • Singapore’s framework for agentic AI keeps organizations and their human supervisors accountable for what agents do, and asks for human approval at significant checkpoints such as deleting data, sending messages and making payments. [IMDA]
  • The same framework treats a very low override rate, or very fast reviews, as a possible sign of rubber-stamping, and prefers approvals enforced by the system over approvals requested in a prompt. [IMDA]
  • The OECD AI Principles, adopted by governments in 2019 and revised in 2024, call for safeguards such as capacity for human agency and oversight. [OECD]
  • A systematic review found that automation bias leads people both to follow wrong advice and to miss problems the system didn’t flag. [Goddard et al., JAMIA]
  • When the UK government used AI to sort 87,738 consultation responses, 125 people checked the tool’s work and policy teams signed off the themes. [i.AI]

Case studies and scenarios

Team practice

List the AI tasks your team repeats and give each one a level. It fits on one page, and it answers the question every new colleague asks: can I let it do this?

Team toolHuman checkpoint map

Sources

What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act) European Union, Official Journal · June 13, 2024 · Law The binding text of the EU AI Act, including the definitions of AI literacy and deep fake (Article 3), banned practices such as emotion recognition at work (Article 5), human oversight that guards against automation bias (Article 14) and transparency duties (Article 50). Limits: Applies in stages and was amended in July 2026 (see the AI Omnibus). Which duties apply depends on the organization’s role and the system. The summaries on this site aren’t legal advice.
  2. Model AI Governance Framework for Agentic AI Infocomm Media Development Authority, Singapore · Version 1.5, May 20, 2026 (first published January 22, 2026) · Voluntary framework Keeps organizations and their human supervisors accountable for agents’ actions; asks for human approval at significant checkpoints such as deleting data, sending messages and payments; treats very low override rates and very fast reviews as possible signs of rubber-stamping; prefers approvals enforced by system controls over prompts. Limits: Voluntary guidance, not law. Its case studies were supplied by the companies themselves.
  3. Recommendation of the Council on Artificial Intelligence (OECD AI Principles) OECD · Adopted May 22, 2019; revised May 3, 2024 · Intergovernmental principles Calls for safeguards such as capacity for human agency and oversight (principle 1.2), accountability with traceability of datasets, processes and decisions (1.5), and systems that can be overridden, repaired or shut down safely (1.4). Limits: Not legally binding.
  4. Automation bias: a systematic review of frequency, effect mediators, and mitigators Journal of the American Medical Informatics Association · 2012 (online June 2011) · Peer-reviewed review Defines automation bias as the tendency to over-rely on automation, leading to errors of commission (following wrong advice) and omission (missing problems not flagged), and finds that training, accountability and how advice is presented can reduce it. Limits: Reviews clinical decision support from before generative AI.
  5. Consult Evaluation: DWP’s Pathways to Work consultation UK Incubator for AI (i.AI) · Dated August 27, 2025; published October 30, 2025 · Government evaluation Policy teams edited and signed off the AI’s themes; 125 reviewers checked the tool’s sorting of 87,738 responses and left 73% unchanged; the tool agreed with reviewers (F1 0.816) more than reviewers agreed with each other (0.710); the median check took 19 seconds. Limits: One consultation. It timed the checking, not the whole analysis.

Cite this page

Founderz (2026). Principle 1: Human oversight of AI. The RUAI Standard, 2026 edition. Developed by Founderz in collaboration with Microsoft. https://responsibleai.founderz.com/toolkit/principles/human-oversight

Licensed under CC BY 4.0: share and adapt with attribution.