Human oversight requirements for high-risk AI systems (Article 14)
In short
Human oversight is the primary safeguard the Act relies on for high-risk systems, the assumption underlying Articles 9-15 is that a competent, empowered person remains capable of catching what automated safeguards miss. Article 14 splits this obligation between design (a provider duty) and practice (a deployer duty).
What providers must design for
Article 14(4) requires the system to be designed so a human overseer can:
- Fully understand the system’s capacities and limitations, and monitor its operation, including for anomalies or malfunctions (4(a), 4(c)).
- Remain aware of automation bias, the tendency to over-rely on the system’s output even when it may be wrong (4(b)).
- Correctly interpret the system’s output (4(c)).
- Decide, in any particular situation, not to use the system, or to disregard, override, or reverse its output (4(d)).
- Intervene in the operation of the system or interrupt it through a stop mechanism or equivalent procedure (4(e)).
A stricter rule for biometric identification
Article 14(5) sets a specific “four-eyes” style rule for biometric identification systems: no action or decision may be taken based on a match without separate verification by at least two competent, trained individuals, unless a narrow law-enforcement exception applies. This is a design and process requirement together, not satisfied by a single reviewer no matter how qualified.
What deployers must do in practice
Assigning oversight to specific, named individuals with the competence, training, and authority to actually exercise it is a deployer responsibility, a role that exists on paper with nobody accountable does not satisfy Article 14. Deployers must also train overseers specifically on automation bias, which is a distinct training need from general system familiarity, and must give overseers real authority to disregard, override, or reverse the system’s output, and confirm, in practice rather than just in policy, that they actually do so when warranted.
The escalation path matters as much as the override
A stop mechanism or override capability is only useful if oversight personnel know when and how to escalate. Where an anomaly or risk is identified, the oversight process should connect to the organisation’s broader risk management (Article 9) and, where the threshold is met, its serious incident reporting process (Article 73), human oversight is not a standalone control, it is the first link in that chain.
The most common failure mode here is not a missing policy document, but a named overseer who has neither the practical authority nor the organisational backing to actually override the system when it matters, Article 14 is tested by what happens in a real disagreement, not by what the policy says should happen.
Frequently asked questions
- What must human oversight of a high-risk AI system allow a person to do?
- Under Article 14(4), the system must be designed so an overseer can understand its capacities and limitations, monitor for anomalies, stay aware of automation bias, correctly interpret its output, decide not to use the system, and intervene, override, or stop it.
- Is naming an overseer enough to comply with Article 14?
- No. Oversight must be assigned to named individuals with the competence, training (including specifically on automation bias), and real authority to disregard, override, or reverse the system's output, and they must actually do so when warranted. A role on paper with nobody empowered does not satisfy Article 14.
- Is there a special human-oversight rule for biometric identification?
- Yes. Article 14(5) sets a four-eyes rule: no action or decision may be taken on a biometric match without separate verification by at least two competent, trained individuals, unless a narrow law-enforcement exception applies.
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check