← All articlesPRACTICAL KNOWLEDGE

Human in the loop: control is more than a click

Human in the loop means a qualified person reviews, decides or approves at defined points. A confirmation button without time, information and authority is not an effective control. The article provides a controlled method, a realistic CTPM practice example and a concrete transfer artefact.

Realistic enterprise scene illustrating Human in the loop: control is more than a click
Short answer

Human in the loop means a qualified person reviews, decides or approves at defined points. A confirmation button without time, information and authority is not an effective control.

What the concept actually means

Effective human oversight requires competence, intelligible evidence, realistic review time and authority to reject outputs or stop the process.

Why it matters in the enterprise

Control depth depends on impact and reversibility. An internal draft may be sampled; decisions affecting people, safety or material value require stronger rules.

A controlled method

The CTPM practice framework for controllable AI applications uses seven stages: understand the task, clarify context and data, apply AI deliberately, review professionally, handle deviations, approve accountably and document transfer. It is a transparent working framework, not a certification.

  • Define task and impact
  • Clarify data, context and permissions
  • Review against domain criteria
  • Control deviations, approval and evidence

CTPM practice example

CTPM practice example: AI proposes categories for support tickets. Staff see the suggestion, rationale and original text, can correct it and only then release critical cases to the next process.

Quality and test criteria

The following criteria make quality observable for this use case:

  • Reviewers have domain knowledge and authority.
  • The interface presents relevant evidence.
  • Overrides and reasons are recorded.
  • Escalation and shutdown are practically possible.

Risks and common misconceptions

Nominal oversight arises from automation bias, time pressure, unclear ownership or interfaces that make rejection unnecessarily difficult.

Example transfer artefact

Transfer artefact: a role and approval model with review points, decision authority, escalation and evidence.

Sources and references

  1. NIST: Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023)
  2. NIST: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024)
  3. European Commission: Regulatory framework for Artificial Intelligence (AI Act) (2024)