LinkedInInstagramXTikTok

Human oversight of high-risk AI: what Article 14 requires in practice

Why human oversight is the requirement businesses get wrong

Of all the obligations attached to high-risk AI systems, human oversight is the one that sounds easiest and turns out hardest. Most businesses believe they already have it: a person is in the loop, someone signs off, nothing goes out fully automated. That instinct is right in spirit and almost always wrong in substance, because the EU AI Act does not ask whether a human is present. It asks whether that human has been given the tools, the competence and the authority to actually change the outcome.

Article 14 is a design obligation owed by the provider. Article 26 is a staffing and operational obligation owed by the deployer. They interlock, and a business that reads only one will end up either building a system nobody can effectively oversee or buying one and assuming oversight came in the box. The Digital Omnibus on AI did not change the text of either article, so what follows is settled law waiting for its application date.

What Article 14 requires, and who owes it

Article 14(1) requires high-risk systems to be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use. Article 14(2) sets the aim: preventing or minimising the risks to health, safety or fundamental rights that may emerge when the system is used as intended or under conditions of reasonably foreseeable misuse, and in particular where such risks persist despite the other requirements in that section. That closing limb makes human oversight the backstop for residual risk — what risk management, data governance and accuracy could not catch. All of these are provider duties; the deployer’s come from Article 26.

Built in by the provider, or handed to the deployer

Article 14(3) requires oversight measures to be commensurate with the risks, level of autonomy and context of use, and ensured through either one or both of two types: measures built, when technically feasible, into the system by the provider before it is placed on the market; and measures identified by the provider which are appropriate for the deployer to implement. A supplier that ships a system with no oversight design and no instructions on how the customer should oversee it has not discharged Article 14 by pointing at the customer.

The five capabilities the overseer must have

Article 14(4) is the operative core. It requires the system to be provided to the deployer so that the natural persons to whom oversight is assigned are enabled, as appropriate and proportionate, to do five things: to properly understand the system’s capacities and limitations and duly monitor its operation, including detecting anomalies and unexpected performance; to remain aware of the possible tendency to automatically rely or over-rely on the output, in particular where the system provides information or recommendations for decisions to be taken by natural persons; to correctly interpret the output, taking into account the interpretation tools available; to decide, in any particular situation, not to use the system or to otherwise disregard, override or reverse its output; and to intervene in its operation or interrupt it through a stop button or a similar procedure that allows the system to come to a halt in a safe state. Article 14(5) adds a stricter rule for remote biometric identification: two competent people must separately verify an identification before the deployer acts on it.

Two qualifiers are easy to skim past. “As appropriate and proportionate” applies to all five and is no general escape clause: the more autonomous the system and the more serious the harm, the less room to argue a capability was not appropriate. And the fifth is not simply a stop button — the halt must reach a safe state, frequently a harder problem than the button.

Automation bias, named in the statute

The second capability is unusual enough to deserve attention. The Regulation names automation bias expressly and requires the overseer to remain aware of the tendency to over-rely on machine output, particularly where the system produces recommendations for a human to act on. That is a legal requirement to design against a documented psychological effect, and a line in a user manual does not satisfy it: it points towards interfaces that surface uncertainty, training that rehearses disagreement with the system, and monitoring of how often the human departs from the recommendation. An override rate of zero across thousands of decisions is not evidence of a good model but of nobody really overseeing anything.

The deployer’s side: Article 26

Article 26(1) requires deployers to take appropriate technical and organisational measures to use high-risk systems in accordance with the instructions for use. Article 26(2) is the sentence every business buying high-risk AI should have pinned somewhere: deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Four requirements, no proportionality hedge, no carve-out — though Article 26(3) leaves the deployer free to organise its own resources, so it chooses how to staff oversight, not whether to. “Necessary support” is a resourcing duty — a competent, trained, authorised person given no time and no help is not compliance.

Several other duties travel with oversight. Under Article 26(4) the deployer must ensure input data it controls is relevant and sufficiently representative for the intended purpose. Article 26(5) requires monitoring against the instructions for use, and where the deployer has reason to consider that use may result in the system presenting a risk within the meaning of Article 79(1), it must without undue delay inform the provider and the market surveillance authority — and suspend use. That suspension duty is mandatory, and triggered even where the system is used exactly as instructed. Article 26(6) requires automatically generated logs under the deployer’s control to be kept for a period appropriate to the intended purpose and of at least six months, so six months is a floor rather than the answer. Article 26(7) requires employers to inform workers’ representatives and affected workers before putting a high-risk system into service. And Article 26(11) requires deployers of Annex III systems that make or assist in making decisions about natural persons to inform those persons — “assist in making” meaning a human-in-the-loop design does not escape the duty.

Practical example

A Stockholm retail group introduces an AI system that generates staff schedules and flags employees whose productivity falls outside expected ranges. Employment and workers’ management is Annex III point 4, so the system is high-risk. In Sweden, market surveillance for point 4 falls to Post- och telestyrelsen under the interim designations made in June 2026 — which routinely surprises HR and legal teams who assume anything touching employees belongs to Integritetsskyddsmyndigheten.

As deployer, the group must assign oversight to named people with competence, training, authority and support. Store managers cannot simply inherit the task; someone must understand what the model does and does not measure, interpret its output, and override it. The group must inform workers’ representatives and affected employees before the system goes into service under Article 26(7). Separately, Swedish co-determination law may bite: MBL 11 § requires an employer bound by a collective agreement to negotiate on its own initiative with the union before deciding on an important change to its operations or to employees’ working conditions. Whether a particular AI deployment crosses that threshold is fact-specific and no authority holds that it always does — but a duty to negotiate before deciding is heavier than a duty to inform, and the AI Act expressly defers to national law on informing workers.

Common mistakes companies make

The first is confusing presence with oversight. A person who receives a recommendation, cannot interrogate it, has no realistic time to consider it and no authority to depart from it is not exercising oversight in the sense Article 14(4) means. The Court of Justice made an adjacent point in Case C-634/21, decided on 7 December 2023: the automated establishment by a credit information agency of a probability value about a person’s ability to meet future payment commitments is itself automated individual decision-making under GDPR Article 22(1) where a third party receiving it draws strongly on that value. The phrase “draws strongly on” is the warning — a formal human sign-off does not neutralise a decision the machine effectively made.

The second is treating oversight as a provider problem or a customer problem rather than both. Contracts silent on which measures the provider built in, and which it left to the customer, leave both parties exposed.

The third is under-resourcing the role. Article 26(2) requires competence, training, authority and support, and support is the one businesses reliably forget to fund.

The fourth is assuming the AI Act’s later application date means there is nothing to do now. GDPR Article 22 has applied since 2018, and in Case C-203/22, decided on 27 February 2025, the Court held that a data subject may require the controller, as meaningful information about the logic involved under Article 15(1)(h), to explain the procedure and principles actually applied to reach a specific result — and that a controller claiming trade secrecy must supply the protected information to the supervisory authority or court.

Recommended actions

Providers should treat Article 14 as a design brief, working through the five capabilities and asking, for each, what in the product actually delivers it. Where a capability is delivered by the customer’s process rather than the product, write that down and put it in the instructions for use, because Article 14(3) requires the provider to have identified those measures before the system goes to market.

Deployers should start from Article 26(2) and name the people: who holds oversight for each high-risk system, whether they have the competence and training the role needs, whether they have documented authority to override or suspend, and whether they have the time and support to use it. Then build the surrounding obligations into the same programme: input data under Article 26(4), the mandatory suspension trigger under Article 26(5), log retention under Article 26(6) justified by the intended purpose rather than defaulted to six months, worker information under Article 26(7) alongside any co-determination duty, and notification of affected individuals under Article 26(11). Finally, ask suppliers now what Article 14 measures are built in and what they expect you to implement — the answer belongs in the contract, not in a support ticket after go-live.

Frequently asked questions

Does having a person approve every decision mean we are outside GDPR Article 22?

Not automatically. Article 22(1) bites on decisions based solely on automated processing that produce legal effects or similarly significantly affect the person, and Case C-634/21 shows that where a downstream user draws strongly on an automated score, the scoring itself can be the regulated decision. The human involvement has to be real — someone with the authority and information to reach a different answer.

Who has to provide the human oversight, the vendor or us?

Both, in different ways. The provider must design the system so it can be effectively overseen and must identify which oversight measures the deployer needs to implement. The deployer must assign oversight to natural persons with the necessary competence, training, authority and support. Neither duty discharges the other, and the split should be documented in the contract.

When do Articles 14 and 26 start to apply?

The Digital Omnibus deferred the high-risk obligations for Annex III systems to 2 December 2027 and for Annex I systems under Article 6(1) to 2 August 2028, and those dates are no longer contingent on standards. No harmonised standard on human oversight has been cited in the Official Journal, so there is no presumption of conformity to rely on. GDPR Article 22 and the case law interpreting it apply now.

Conclusion

Human oversight is not a checkbox or a person sitting near a screen. It is a designed capability on the provider’s side and a resourced role on the deployer’s. Businesses have until December 2027 for Annex III systems, which sounds generous until you consider that the work spans product design, contract terms, job descriptions, training and, in Swedish workplaces, possibly a union negotiation before anything is decided. Those who treat the intervening period as preparation rather than delay will be the ones whose oversight actually works when someone asks to see it.

Lawgent helps businesses allocate human oversight duties between AI providers and deployers, draft the contract terms that make the split enforceable, and align AI Act obligations with GDPR and Swedish employment law.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop