Human in the loop: AI does the work, people keep the authority
Approving everything sounds prudent. It is in fact the surest way to lose control. The real question is not how many approvals, but which ones — and where to place them.
A business leader's first reaction to an AI agent that can act on its own is a healthy one: "I want to approve." Approve what, exactly? That is where most projects pick the wrong answer.
Approving everything looks prudent. It is in fact the most reliable way to lose control.
Three ways to keep authority, and they do not cost the same
The vocabulary has been around since 2019, in the guidelines of the European Commission's high-level expert group.
Human in the loop: a person steps in at every decision cycle. The document itself notes that this is "neither possible nor desirable" in many cases.
Human on the loop: a person intervenes in the design of the system and monitors how it runs, without validating every action.
Human in command: a person oversees the activity as a whole and keeps the right to decide not to use the system in a given situation.
Most companies say they want the first and actually need the second, with the third as a backstop. Confusing the three produces either paralysis or empty approval.
Why approving everything does not protect you
There is one measurement that should give pause to anyone who believes the human eye catches what the machine misses.
A study published in Radiology in May 2023 put 27 radiologists in front of 50 mammograms, with an artificial intelligence suggestion displayed on screen. When that suggestion was wrong, accuracy among the least experienced radiologists fell from roughly 80% to under 20%. Among the most experienced — more than fifteen years of practice — it went from 82% to 45.5%.
These are not distracted people: they are specialists, on their own ground, with a single image to judge. The phenomenon has a name, automation bias, and it is established enough to be named in the text of the European AI regulation, at article 14, which requires the human overseer to "remain aware" of that tendency.
One detail makes it worse. A Harvard Business School study published in March 2025, covering more than two thousand job applications that were assessed, found that the explanations supplied by the AI increase the human's agreement with its recommendation while degrading the quality of the decision. A good justification makes it easier not to think.
Multiplying approval points therefore does not increase control. Past a certain volume, it dilutes it. Approve everything, and you approve nothing.
What the law requires, and what it does not
In Quebec, the rule is precise and few executives know it in detail.
Section 12.1 of the Act respecting the protection of personal information in the private sector, in force since September 22, 2023, covers decisions based exclusively on automated processing. The company must inform the person no later than the moment of the decision. On request, it must disclose the information used, "the reasons and the principal factors and parameters" that led to the decision, and give the person the chance to submit observations to a member of staff who is in a position to review the decision.
That last phrase is the heart of the obligation. It is not an acknowledgement of receipt. It is a person with the power to overturn the outcome.
The European regulation points the same way at its article 14 — a text adopted in July 2026 pushed part of the obligations covering high-risk systems back to December 2027, without touching the article on human oversight.
What the law nowhere requires: approving every action a system takes. It requires that certain decisions be reviewable by a competent human being.
Where to place the checkpoint
The right question is not "how many approvals," it is "which approvals."
One criterion works better than all the others: irreversibility. Preparing a document, matching an invoice, writing a draft, filing a record — all of that can be undone. Sending to a customer, debiting an account, confirming a commitment, deleting data — that cannot be undone, or only badly.
The control belongs on what cannot be undone, and on deviation: the price outside the usual band, the supplier never seen before, the amount above the threshold, the file that breaks the pattern. Checking 100% of invoices produces the mechanical approval measured above. Checking the 5% that deviate concentrates human judgment where the person holds information the agent does not have.
A technical argument reinforces the choice. Work published in February 2026 on agent reliability shows a persistent gap between succeeding at a task once and succeeding at it every time, and shows that recent gains in capability have produced only small gains in reliability. An agent that succeeds nine times out of ten is excellent at preparing work and unacceptable for committing the company on its own.
A point of honesty: there is no reliable company data putting a number on what is gained by checking only the exceptions, and the academic literature is in fact contradictory on this point. The reasoning above is sound; the figure that would prove it does not yet exist publicly.
The Belarel perspective
A company does not delegate actions. It delegates mandates, with limits.
It is what any manager does with a new employee: you can order up to this amount, you call me above it, and anything going out to a customer comes through me the first week. Nobody calls that surveillance. We call it a framework.
A human belongs where their judgment adds value — not where they merely confirm what the machine has already decided. A well-placed checkpoint is fast, rare, and genuinely read. A badly placed checkpoint is frequent, slow, and turns into a click.
Three questions to start with
What, in my company, is irreversible? Make the list. It is shorter than people think, and it is the list that decides your approvals.
Do my approvers have the power to say no? If the person approving cannot overturn the decision, it is not a review. Quebec law, for its part, requires that power.
How many approvals does one person sign in a day? If the number goes past what a human can actually read, you already have the problem measured in those radiologists.
Authority is not measured by how often you say yes. It is measured by the ability to say no, at the right moment, knowing why.