EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 14Human oversight

Article 14 requires high-risk AI to be designed for effective human oversight. A person must be able to understand the system's output, override or stop it, and the whole design must guard against automation bias.

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • High-risk AI must be overseen by natural persons during use, proportionately to the risk.
  • Oversight must guard against automation bias — people rubber-stamping machine outputs.
  • Oversight measures can be built into the system (human-in-the-loop, -on-the-loop, -in-command).
  • Deployers must assign competent overseers with training, authority, and access to information.
  • For 'no full automation' use cases like HR rejection, the oversight design is what keeps the system lawful.

Scope

Who this applies to

Providers must design oversight in; deployers must staff and run it. Both share the duty to make oversight real, not nominal.

Obligations

What you must actually do

Design for meaningful oversight

The system must let humans interpret output, understand limits, and intervene or stop the system when needed. Include override controls that are actually reachable in the workflow.

Defeat automation bias

Design workflows so the human has the information and confidence to disagree — for example, showing confidence scores, alternatives, or the reasons behind a recommendation.

Assign and train overseers

Deployers must name competent individuals, train them on the system's limits, give them the authority to override, and ensure they have the system data they need.

Action plan

Practical first steps

  1. 1

    Map where each decision is made and where a human can intercept it — find the points where automation bias is likeliest.

  2. 2

    Build override into the product flow, then test it with real users, not just the vendor.

  3. 3

    Train operators with explicit 'when to override' scenarios from your risk register.

  4. 4

    Log overrides and their outcomes — they are your evidence that oversight was real.

Penalty exposure

Human-oversight failures sit in the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 14

Does Article 14 mean a human must approve every decision?

Not necessarily. The Act allows human-in-the-loop (approving), human-on-the-loop (monitoring and intervening), and human-in-command (setting limits). The right model depends on the risk and must be genuinely effective, not decorative.

Who is liable if oversight fails — provider or deployer?

Both, for their own failures: providers for not building oversight in, deployers for not operating it. Contracts should assign these duties clearly, but liability is not fully contractual.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.