Call · 15 min
GlossaryMattia Esposito26 September 20266 min read

Human in the loop. The point where a person can stop the machine.

Human in the loop (HITL) describes an automated system in which a person can intervene in every decision cycle: they read the proposal, approve it, correct it or stop it before the action takes effect. It is the tightest form of human oversight of artificial intelligence.

In short

The European Commission's 2019 ethics guidelines distinguish three levels: human in the loop, with intervention on every decision; human on the loop, with monitoring during operation; human in command, with oversight of the use of the system as a whole.

The AI Act makes it a requirement for high-risk systems, with Article 14 on human oversight, applicable from 2 December 2027 to the systems in Annex III.

In an SME the practical question is where to put the person: on every message that commits the company, or once, beforehand, on the content the system will use.

This entry is part of the glossary of AI and automation, where the term appears as human oversight. Here the definition widens: where it comes from, the three levels of oversight, what the AI Act and the GDPR require, and how to decide where to put the person.

What human in the loop means

The Ethics Guidelines for Trustworthy AI, published on 8 April 2019 by the European Commission's expert group, define it like this: «HITL refers to the capability for human intervention in every decision cycle of the system». The same sentence adds that in many cases that intervention is neither possible nor desirable.

The decision cycle is the full round of an automated decision: the system receives data, proposes an action, the action produces an effect. Human in the loop means that between the proposal and the effect there is a person with the power to say yes, no, or to change it. A person who watches without that power stays outside the loop.

The three levels: in the loop, on the loop, in command

The guidelines, in paragraph 65, describe three levels of human oversight, from the tightest to the broadest. Two things change from one to the next: when the person steps in, and on what. The choice depends on risk: the more an error costs, the closer the person should be to the single decision.

LevelWhat the person doesAn example in an SME
Human in the loopHITL, in the loop

Approves or corrects every single decision before it takes effect.

The quote prepared by the system goes out only after the owner has read it.

Human on the loopHOTL, above the loop

Steps in on the design and monitors operation, without approving every action.

Replies about opening hours and availability go out by themselves; a person reads the log and steps in on exceptions.

Human in commandHIC, in command

Decides whether, when and how to use the system, and can override one of its decisions.

The owner switches off automatic replies in the week prices change.

What the law requires

Article 14 of the AI Act, Regulation (EU) 2024/1689, requires that high-risk systems can be «effectively overseen by natural persons» while in use. Whoever oversees them must be able to understand their capabilities and limits, decide not to use them, disregard or reverse their output, and interrupt them with a stop button or a similar procedure.

The measures are «commensurate with the risks, level of autonomy and context of use», says paragraph 3: the law does not impose approval of every single decision. After Regulation (EU) 2026/1744 these obligations apply from 2 December 2027 to the high-risk systems in Annex III, such as staff recruitment. The full calendar is on the page about the AI Act deadlines.

The GDPR, in Article 22, contains an older rule: the data subject has the right not to be subject to a decision «based solely on automated processing» which produces legal effects or similarly significantly affects them. Where an automated decision touches a person, then, human oversight has to be designed before use.

The risk the law names: automation bias

Article 14 names a precise risk, «automation bias»: the tendency to rely automatically, or too much, on what the system proposes. A person who approves a hundred drafts a day ends up approving them without reading them. At that point they are in the loop only on paper, and human oversight empties out without anyone having decided it.

The risk has a measure. Stanford University's RegLab group evaluated three legal research tools sold as free of hallucinations, and found that they are wrong between 17% and 33% of the time. Whoever approves without reading, in that case, signs the errors too.

That is why the approval point should be placed where the person has time to look: on messages that commit the company, on prices, on money, on what cannot be taken back. For the rest, monitoring works better, that is human on the loop: a sample check and an event log that can be read in a few minutes.

How to decide where to put the person

The decision is made in two steps. First you write the list of actions the system can take, one by one. Then, for each, you decide who approves and when: every time, or once on the content, before the system uses it. A quote with a price belongs to the first group, opening hours to the second.

The simplest criterion is the cost of the error. If an error can be fixed with an apology email, monitoring is enough. If it costs a customer, a fine or money leaving the account, a person is needed before sending. It is also the easiest rule to explain to whoever in the company will have to approve.

The question concerns more and more businesses. According to Istat, in 2025 16.4% of Italian enterprises with at least 10 employees use at least one artificial intelligence technology, against 8.2% in 2024 and 5.0% in 2023. Among large enterprises the share is 53.1%.

How Itria applies it

It is the third of the six principles written in Ethics: «The machine prepares, but a person always decides». Approval is always there, and what changes is when it arrives. A reply built on information the owner has already approved can go out by itself; everything that commits the company or touches money waits for a person, message by message.

Replies that go out by themselves state that they come from a system, as Article 50 of the AI Act requires from 2 August 2026. The list of the systems we use, with the level of human oversight of each, is available on request, as written on the AI transparency page.

Related terms

AI hallucinations

A false statement produced with confidence by a model. It is the most concrete reason to keep a person before sending.

Workflow

The flow of work with its rules. The human approval point is a step of the workflow, and it is designed together with the others.

AI Act

The European regulation on artificial intelligence, which classifies uses by level of risk.

Audit trail

The record of who did what and when. Without a trail, human oversight cannot be demonstrated.

Questions and answers

What does human in the loop mean?

Human in the loop, abbreviated HITL, describes an automated system in which a person can intervene in every decision cycle: they read the system's proposal and approve it, correct it or stop it before it takes effect.

The European Commission's 2019 ethics guidelines define it as the capability for human intervention in every decision cycle of the system.

What are the three levels of human oversight of artificial intelligence?

The European Commission's ethics guidelines, in paragraph 65, describe three. Human in the loop: human intervention in every decision cycle. Human on the loop: intervention during the design cycle and monitoring of the system's operation, without approving every single action.

Human in command: oversight of the overall use of the system, with the ability to decide when to use it, not to use it or to override one of its decisions.

What is the difference between human in the loop and human on the loop?

In the first case the person approves every single decision before it takes effect: the quote goes out only after someone has read it. In the second the system acts by itself within rules decided beforehand, and the person monitors its operation and steps in on exceptions.

The first suits cases where errors are costly, the second cases with many actions where a single error is easy to fix.

Does the AI Act require a person in the loop?

For high-risk systems, Article 14 of Regulation (EU) 2024/1689 requires that they can be effectively overseen by natural persons, with measures commensurate with the risk, the level of autonomy and the context.

After Regulation (EU) 2026/1744 the obligation applies from 2 December 2027 to the systems in Annex III. Most systems used by an SME are not high-risk.

Does human in the loop slow work down?

Yes, where the person approves every single action, which is why it should be placed only where errors are costly: quotes, prices, money, communications that commit the company.

For replies built on information already approved, such as opening hours and availability, approval can be given once on the content, and the system replies straight away, stating that it is a system.

Notes on sources

  1. The definition and the three levels come from paragraph 65 of the Ethics Guidelines for Trustworthy AI, by the High-Level Expert Group on Artificial Intelligence set up by the European Commission, 8 April 2019, Italian version read on 26 September 2026. They are guidelines, not a law.
  2. The quotations on human oversight and automation bias come from Article 14 of Regulation (EU) 2024/1689, read in the official text. The date of 2 December 2027 comes from Article 113 as amended by Regulation (EU) 2026/1744, which does not touch the text of Article 14.
  3. The quotation on automated decisions comes from Article 22 of Regulation (EU) 2016/679, the GDPR. Paragraph 2 of the same article provides for exceptions, by contract, by law or with explicit consent.
  4. The 17% and 33% come from the pre-registered evaluation by Stanford's RegLab group, Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, 2024: three US legal tools on questions of law, a harder task than those of an SME. We cite it for the shape of the risk, not as a forecast for your case.
  5. The shares of enterprises using artificial intelligence come from Istat, Imprese e ICT, 2025, on enterprises with at least 10 employees, read on 26 September 2026.
  6. This page is a review, not legal advice: whether one of your systems falls under high risk depends on its use, and it is for whoever advises the company to establish it.
·The next step

First you decide where the person stands. Then you build the system around them.

The first step with Itria is a fifteen-minute video call: we look at which steps of your work can be automated and in which ones a person must stay before sending. Write us a line about what weighs on you. We take the first step: what a customer sees when they look for you, and what we found there. Even if we don't end up working together.