How much human oversight does an AI decision actually need?
Oversight is not a single setting. It is a ladder, and the rung is chosen by the harm at stake.
Andy Wake, Founder and Managing Director6 min read
Organisations tend to answer this question twice, both times wrongly: either a human reviews everything, which collapses within a fortnight, or nobody reviews anything, which holds until the first complaint.
Four levels of oversight
- Level 1 — assistive. Drafting, summarising, formatting. A person reads the output before use; spot-check quality monthly.
- Level 2 — advisory. The assistant proposes an answer that shapes a person's work. A named human accepts or rejects each one, and the reasoning is visible.
- Level 3 — consequential. The output affects someone's education, employment, money, health, safety or legal rights. A named decision-maker records the decision and the basis, and can override with a reason.
- Level 4 — prohibited. Decisions we do not automate at all, including safeguarding conclusions and anything where a wrong answer cannot be undone.
Where UK GDPR draws its line
UK GDPR places extra restrictions on solely automated decisions producing legal or similarly significant effects: people have the right to be informed, to obtain human intervention, to express their view and to contest the decision. The word 'solely' does a lot of work — nominal human involvement does not remove the obligation.
Designing oversight that survives contact with reality
- Set the level per decision type, not per tool. One assistant may operate at three levels across different tasks.
- Show the reviewer the reasoning and the uncertainty, not just the answer.
- Make overriding easy and record why — the reasons are your best improvement data.
- Cap volume. If review throughput exceeds what a person can genuinely consider, the level is wrong or the process is.
- Review the levels quarterly. Tasks drift upward in consequence without anyone deciding that they should.
Frequently asked questions
- What counts as meaningful human oversight?
- A named person who sees the reasoning behind a recommendation, has the competence and authority to reach a different conclusion, has enough time to do so, and whose override is recorded. Confirmation clicks at high volume do not meet the standard.
- Can AI make decisions about people on its own?
- Under UK GDPR, solely automated decisions with legal or similarly significant effects are restricted and carry rights to human intervention, explanation and challenge. In practice, most organisations should keep such decisions at advisory or consequential level with a named human decision-maker.
Sources and further reading
- Rights related to automated decision making including profiling
Information Commissioner's Office
Where to go next
More articles on the insights index.