The human oversight duty
Regulators now require a person who can understand, intervene, and halt.
Regulation (EU) 2024/1689, the EU AI Act, Article 14 and Annex III
adopted 2024; high-risk obligations phased and subject to deferral
ISO/IEC 42001:2023, AI management systems
published December 2023
NIST AI Risk Management Framework 1.0
January 2023
Several regimes converge on the same requirement. The EU AI Act obliges high-risk systems to be designed so they can be effectively overseen by natural persons, able to understand the system, intervene, and stop it, and it explicitly targets automation bias, meaning the operator who rubber-stamps whatever the machine proposes. Employment uses including recruitment, promotion decisions, and task allocation are classed high-risk.
ISO/IEC 42001 provides a certifiable AI management system. The NIST AI Risk Management Framework organizes practice around govern, map, measure, and manage. CMMC governs the US defense base. The word doing the work across all of them is effective: oversight that is nominal, retrospective only, or impossible because the system runs too fast does not satisfy it.
Timelines have moved. High-risk obligations under the EU AI Act have been subject to deferral under the Digital Omnibus, so confirm current dates with counsel before building compliance claims on them.
What would you show an auditor, and can the system produce it without being asked?
Which decisions may an agent make alone, and who is able to stop it?
Who is qualified to overrule the machine, and how would you prove it?
