The language of “the loop” describes where human judgement sits in an AI-supported workflow. Parasuraman, Sheridan and Wickens (2000) argued that automation can support information acquisition, analysis, decision selection and action implementation at different levels. This is important because an AI tool may only draft a response, or it may recommend a decision, prioritise work, approve an action or execute a task automatically. The stronger the automation, the more carefully organisations need to define who remains accountable, what evidence is reviewed and when intervention is required.
Human in the loop means the system cannot complete the relevant action until a person has reviewed, approved or changed the output. This is usually appropriate where the decision affects people, rights, safety, compliance, money, reputation or access to important services. For example, an AI tool may summarise customer complaints or flag high-risk cases, but a trained person should check context, uncertainty, policy and fairness before action is taken. The human role must be meaningful. A rushed click on “approve” is not oversight if the person lacks time, competence, information or authority to challenge the system. The ICO (2023) stresses that AI processing must still meet data protection principles such as fairness, transparency, accuracy and accountability.
Human on the loop means the AI system can operate without a person approving every individual action, but people monitor performance and intervene when needed. This can work where volume is high, risk is moderate and there are reliable controls, alerts, thresholds and audit trails. For example, a chatbot may answer routine internal questions while a team monitors unresolved queries, complaint patterns, hallucinations, bias risks and escalation rates. On-the-loop oversight depends on dashboard quality, clear stop rules and named owners. It is weaker than it appears if nobody checks the signals, if alerts are too noisy, or if staff cannot pause, override or investigate the system.
Human out of the loop means the system acts with little or no real-time human involvement. This may be acceptable for low-risk, reversible and tightly bounded tasks, such as formatting data, routing non-sensitive tickets or generating draft labels that do not affect decisions. It is much more problematic where outcomes are significant, hard to reverse or difficult to explain. Article 22 of the UK GDPR restricts solely automated decisions that have legal or similarly significant effects unless specific conditions and safeguards apply (ICO, nd). The EU AI Act also requires high-risk AI systems to be designed so they can be effectively overseen by natural persons (European Union, 2024).
Automation can also change human capability. Bainbridge (1983) warned that automation can leave people responsible for rare abnormal situations while giving them less practice, poorer feedback and more passive monitoring work. Endsley and Kiris (1995) called this the out-of-the-loop performance problem: operators may lose situation awareness and struggle to take over when automation fails. In AI-enabled workplaces, the same risk appears when people accept recommendations without understanding the data, model limits or confidence level.
Good oversight is therefore a design choice, not a slogan. Organisations should start with purpose and risk: what decision is being supported, who is affected, what could go wrong, and how reversible is the outcome? They should then set human gates, monitoring rules, override routes, evidence standards and review cycles. DSIT (2023) frames UK AI regulation around principles including safety, transparency, fairness, accountability and contestability, while ISO/IEC 42001:2023 supports organisational management systems for responsible AI use (ISO, 2026). The practical test is simple: if the AI output is wrong, biased or harmful, can a competent person notice, intervene, explain the decision and learn from it? If not, the loop has not been designed responsibly.
Action Point
Choose one AI-supported workflow, even if it is informal use of a generative AI tool. Map where the human currently sits: in the loop, on the loop or out of the loop. Then identify the decision risk, who is affected, what evidence the human sees, whether they can override the output and how errors are reviewed.