Call · 15 min
GlossaryMattia Esposito26 September 20266-minute read

Human in the loop. The point where a person can stop the machine.

Human in the loop (HITL) describes an automated system in which a person can step into every decision cycle: they read the proposal and approve it, correct it or stop it before the action takes effect. It's the tightest form of human oversight of artificial intelligence.

In brief

The European Commission's 2019 ethics guidelines distinguish three levels: human in the loop, with intervention on every decision; human on the loop, with monitoring during operation; human in command, with oversight of the system's use as a whole.

The AI Act makes it a requirement for high-risk systems, through Article 14 on human oversight, which applies to Annex III systems from 2 December 2027.

In an SME, the practical question is where to put the person: on every message that commits the business, or once, in advance, on the content the system will use.

This entry is part of the AI and automation glossary, where the term appears as human oversight. Here the definition goes further: where it comes from, the three levels of oversight, what the AI Act and the GDPR require, and how to decide where to put the person.

What human in the loop means

The Ethics Guidelines for Trustworthy AI, published on 8 April 2019 by the European Commission's expert group, define it like this: “HITL refers to the capability for human intervention in every decision cycle of the system”. The same sentence adds that in many cases such intervention is neither possible nor desirable.

A decision cycle is the full round of an automated decision: the system receives data, proposes an action, and the action has an effect. Human in the loop means that between the proposal and the effect there's a person with the power to say yes, no, or change it. A person who watches without that power stays outside the loop.

The three levels: in the loop, on the loop, in command

The guidelines, in paragraph 65, describe three levels of human oversight, from the tightest to the broadest. Between them, two things change: when the person steps in, and on what. The choice depends on risk: the more a mistake costs, the closer the person needs to be to the individual decision.

LevelWhat the person doesAn example in an SME
Human in the loopHITL, in the loop

Approves or corrects every single decision before it takes effect.

The quote prepared by the system goes out only after the owner has read it.

Human on the loopHOTL, over the loop

Steps in at the design stage and monitors operation, without approving every action.

Replies about opening hours and availability go out on their own; a person reads the log and steps in on exceptions.

Human in commandHIC, in command

Decides whether, when and how to use the system, and can override one of its decisions.

The owner switches off automatic replies in the week the prices change.

What the law requires

Article 14 of the AI Act, Regulation (EU) 2024/1689, requires high-risk systems to be designed so that they “can be effectively overseen by natural persons” while in use. The people overseeing them must be able to understand their capabilities and limits, decide not to use them, disregard or reverse their output, and stop them with a stop button or a similar procedure.

The measures must be “commensurate with the risks, level of autonomy and context of use”, says paragraph 3: the law doesn't require approval of every single decision. Following Regulation (EU) 2026/1744, these obligations apply from 2 December 2027 to the high-risk systems in Annex III, such as recruitment. The full timeline is on the page about AI Act deadlines.

The GDPR, in Article 22, contains an older rule: the data subject has the right not to be subject to a decision “based solely on automated processing” which produces legal effects concerning them or similarly significantly affects them. So wherever an automated decision affects a person, human oversight has to be designed in before use.

The risk the law names: automation bias

Article 14 names a specific risk, “automation bias”: the tendency to rely automatically, or too much, on what the system proposes. A person who approves a hundred drafts a day ends up approving them without reading them. At that point they're in the loop only on paper, and human oversight hollows out without anyone having decided it.

The risk has been measured. Stanford University's RegLab group evaluated three legal research tools marketed as hallucination-free, and found that they get it wrong between 17% and 33% of the time. Anyone approving without reading, in that case, signs off the mistakes too.

That's why the approval point belongs where the person has time to look: on messages that commit the business, on prices, on money, on anything that can't be taken back. For the rest, monitoring works better, meaning human on the loop: spot checks and an event log you can read in a few minutes.

How to decide where to put the person

The decision is made in two stages. First, you list the actions the system can take, one by one. Then, for each, you decide who approves and when: every time, or once, on the content, before the system uses it. A quote with a price belongs in the first group, opening hours in the second.

The simplest test is what a mistake costs. If a mistake can be fixed with an apologetic email, monitoring is enough. If it costs a customer, a fine or money leaving the account, a person is needed before sending. It's also the easiest rule to explain to the people in the business who'll be doing the approving.

The question concerns more and more businesses. According to Istat, in 2025 16.4% of Italian businesses with at least 10 employees used at least one artificial intelligence technology, against 8.2% in 2024 and 5.0% in 2023. Among large businesses the share is 53.1%.

How Itria applies it

It's the third of the six principles set out in Ethics: “The machine prepares, a person always decides”. There's always approval; what changes is when it comes. A reply built on information the owner has already approved can go out on its own; anything that commits the business or involves money waits for a person, message by message.

Replies that go out on their own say they come from a system, as Article 50 of the AI Act requires from 2 August 2026. The list of systems we use, with the level of human oversight for each, is available on request, as stated on the AI transparency page.

Related terms

AI hallucinations

A false statement produced with confidence by a model. It's the most concrete reason to keep a person before sending.

Workflow

The flow of work with its rules. The human approval point is a step in the workflow, and it's designed along with the others.

AI Act

The European regulation on artificial intelligence, which classifies uses by level of risk.

Audit trail

The record of who did what and when. Without a trail, human oversight can't be demonstrated.

Questions and answers

What does human in the loop mean?

Human in the loop, HITL for short, describes an automated system in which a person can step into every decision cycle: they read the system's proposal and approve it, correct it or stop it before it takes effect.

The European Commission's 2019 ethics guidelines define it as the capability for human intervention in every decision cycle of the system.

What are the three levels of human oversight of artificial intelligence?

The European Commission's ethics guidelines, in paragraph 65, describe three. Human in the loop: human intervention in every decision cycle. Human on the loop: intervention during design and monitoring of operation, without approving every single action.

Human in command: oversight of the system's use as a whole, with the ability to decide when to use it, when not to, and when to override one of its decisions.

What's the difference between human in the loop and human on the loop?

In the first, the person approves every single decision before it takes effect: the quote goes out only after someone has read it. In the second, the system acts on its own within rules set in advance, and the person monitors how it runs and steps in on exceptions.

The first makes sense where a mistake is costly, the second where there are many actions and a single mistake is easy to fix.

Does the AI Act require a person in the loop?

For high-risk systems, Article 14 of Regulation (EU) 2024/1689 requires that they can be effectively overseen by natural persons, with measures commensurate with the risk, the level of autonomy and the context.

Following Regulation (EU) 2026/1744, the obligation applies from 2 December 2027 for Annex III systems. Most of an SME's systems aren't high-risk.

Does human in the loop slow work down?

Yes, where the person approves every single action, which is why it belongs only where a mistake is costly: quotes, prices, money, communications that commit the business.

For replies built on information already approved, such as opening hours and availability, approval can be given once, on the content, and the system replies straight away, saying it's a system.

Notes on sources

  1. The definition and the three levels come from paragraph 65 of the Ethics Guidelines for Trustworthy AI, by the High-Level Expert Group on Artificial Intelligence set up by the European Commission, 8 April 2019, read on 26 September 2026; the link leads to the Italian version, the quotation is from the English original. They're guidelines, not law.
  2. The quotations on human oversight and automation bias come from Article 14 of Regulation (EU) 2024/1689, quoted from the official English text. The date of 2 December 2027 comes from Article 113 as amended by Regulation (EU) 2026/1744, which leaves the text of Article 14 unchanged.
  3. The quotation on automated decisions comes from Article 22 of Regulation (EU) 2016/679, the GDPR. Paragraph 2 of the same article provides for exceptions: under a contract, by law or with explicit consent.
  4. The 17% and 33% come from the pre-registered evaluation by Stanford's RegLab group, Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, 2024: three US legal tools on questions of law, a harder task than an SME's. We cite it for the shape of the risk, not as a prediction for your case.
  5. The shares of businesses using artificial intelligence come from Istat, Imprese e ICT, 2025 (in Italian), covering businesses with at least 10 employees, read on 26 September 2026.
  6. This page is an overview, not legal advice: whether one of your systems counts as high-risk depends on how it's used, and that's for the people advising your business to determine.
·The next step

First, decide where the person sits. Then build the system around them.

The first step with Itria is a fifteen-minute video call: we look at which steps in your work can be automated, and at which ones a person needs to stay in place before sending. Drop us a line about what's slowing you down. We'll make the first move: we'll look at what a customer sees when they search for you, and tell you what we found. Even if we never end up working together.