An AI fraud screen has stopped a supplier payment. The accounts-payable analyst reviewing the case can see a high-risk flag, but she cannot see which evidence produced it. She does not know whether the system misunderstood the invoice or whether other suppliers have been affected.
The analyst can add a note. She cannot release the payment. Only a manager can do that, and the manager is unavailable until tomorrow. If the payment remains blocked today, a truck carrying essential parts will stay in the depot.
The governance report will still say that a human reviewed the decision.
That report leaves out the most important fact. The analyst could see the result, but she did not have enough information or authority to protect the business. This is why the phrase “human-in-the-loop” is not enough. It confirms that a person appeared somewhere in the workflow. It does not show what that person could do.
For a consequential AI-supported decision, leaders need to ask a more practical question: where is the human authority line in AI-supported decisions?
What the reviewer can actually do
When I review a workflow, I ask the employee to show me what they can do when they believe the AI is wrong. The answer is often different from the policy.
The policy may say that a reviewer can challenge a recommendation. The system may allow only a comment. The employee may need management approval for an override, while accepting the recommendation takes one click. Escalation may take longer than the time available to prevent harm.
The human authority line is a simple way to examine that gap. It follows one decision from the AI output to the person who can inspect it, pause it, change it and provide a remedy if the decision causes harm. It also records how quickly each step must happen.
This is more specific than a RACI chart. A RACI chart assigns general responsibilities. An authority line tests whether the people named in those responsibilities can act in a live case.
Figure 1. Human review becomes meaningful when evidence, intervention rights and a remedy route operate before harm becomes difficult to reverse.
Four questions reveal the gap
The authority line can be understood through four questions.
-
What can the reviewer see?
The reviewer needs the reason for the recommendation, the relevant evidence and any important information the system does not contain. A risk score without its basis is rarely enough for a consequential decision.
-
What can the reviewer do immediately?
The person may need permission to place a temporary hold, request more evidence or stop an irreversible action. A right to disagree is weak if the system does not provide a usable action.
-
Who can make the final decision, and how quickly can they be reached?
The named decision-maker needs a deputy and a response time. If harm becomes difficult to reverse in two hours, an escalation service level of one business day does not work.
-
Who repairs the consequence?
Someone must own the practical remedy. That may involve releasing a payment, restoring a service or compensating an affected customer. Recording a complaint is not the same as resolving it.
A completed supplier example
The supplier-payment case can be mapped without buying new software. A document, spreadsheet or existing service-management form is enough.
| Question | Supplier-payment example |
| What decision is AI influencing? | Whether to stop the supplier payment |
| What happens if it is wrong? | Essential parts remain at the depot |
| When does harm become difficult to reverse? | Before today’s dispatch closes |
| What evidence can the reviewer see? | Risk flag, invoice and supplier history |
| What can the reviewer do immediately? | Place a two-hour hold and request review |
| Who can change the decision? | Accounts-payable manager or named deputy |
| How quickly must escalation respond? | Within 30 minutes |
| What triggers escalation? | Missing evidence, dispatch at risk or a repeated pattern of similar blocks |
| How is review capacity protected? | A named deputy takes overflow before the 30-minute response limit is breached |
| Who can suspend the process? | The AI service owner can suspend the fraud rule and activate the manual fallback |
| What decision evidence is retained? | Evidence reviewed, action, decision-maker, reason, time and related-case check |
| Who owns the remedy? | Accounts-payable manager with Procurement |
| When was the route last tested? | Record the date, case and result |
The example makes the gaps visible. If the analyst cannot see the evidence, the review is incomplete. If no deputy can act before the dispatch deadline, the escalation route is too slow. If the business corrects one payment but does not check similar cases, the underlying problem remains.
Controls must match the speed of the decision
Different decisions need different controls.
A cybersecurity system may need to block suspicious activity within seconds. Prior human approval may be impossible. Protection then depends more heavily on technical limits, monitoring and a tested rollback. The authority line begins with who can investigate the block and restore access quickly.
A supplier payment usually provides more time. A reviewer may be able to place a temporary hold while a second person checks the evidence. A high-consequence decision may require two authorised people.
Some harm will be discovered only after the decision. The organisation then needs a route to stop the continuing effect, correct the case and identify other people or transactions exposed to the same defect.
Choose the control according to the decision and the time available. Some cases need prior approval; others need monitoring, rapid investigation and tested recovery.
Will authority survive normal workload?
Authority that works for one demonstration case may fail during normal operations. Reviewers need enough time to examine the evidence before the queue moves on or the consequence becomes difficult to reverse.
Test the workflow using its normal and peak case volumes. Record how much review time is available per case, when the backlog becomes unsafe and who provides cover during an incident or staff absence. If the available review time is shorter than the work required, adding another approval box will not repair the control. The organisation must reduce the number of cases requiring review, provide more capacity or limit what the AI-supported process may do.
The workflow also needs two kinds of stop authority. The first applies to an individual case: hold this payment, reopen this complaint or restore this account. The second applies to the process itself: suspend the model, rule or integration when several cases suggest a common defect. The triggers for both actions should be defined before an incident.
For each consequential decision, record the evidence considered, the action taken, the decision-maker, the reason and whether related cases need review. A log showing that somebody clicked approve does not establish that meaningful review occurred.
Work can discourage challenge
Permission in a policy does not guarantee that employees will use it.
Consider a recruiter reviewing an AI-generated shortlist. Accepting the ranking takes one click. An override requires a written explanation and management approval. The recruiter is measured on time-to-hire. A low override rate in this workflow may reflect confidence in the system, but it may also reflect the cost of disagreeing with it.
Ask the reviewer how long a challenge takes. Check whether repeated disagreement affects performance measures or relationships with managers. Review whether the interface presents evidence clearly or encourages quick acceptance.
Human judgement also needs scrutiny. Reviewers can be inconsistent or mistaken. They may need training, bounded authority and a second person for unusual or high-consequence cases. The quality of overrides should be sampled rather than assumed.
Some systems should not be deployed. A human approval step cannot make an unlawful or unsuitable system safe.
The affected person also needs a route
Internal review is only part of the control. A customer, worker or citizen affected by a decision needs a practical way to supply missing information and reach someone who can change the outcome.
A customer-service employee may be able to reopen an AI-closed complaint but still lack permission to restore service or approve compensation. The customer has reached a person, but not yet a remedy. The workflow should identify who can act and how long the customer should expect to wait.
Australia’s Robodebt Royal Commission shows why review and remedy matter in automated decision-making. The Commission documented an unlawful debt-assessment and recovery scheme involving income averaging and serious institutional failures. Its recommendations included clearer review paths, plain-language disclosure and independent scrutiny of automated decision processes.
Private AI workflows are not equivalent to Robodebt. The practical lesson is that decisions made at scale need a route for challenge, correction and investigation.
What current guidance requires in practice
The frameworks impose different obligations, but each expects organisations to give responsible people enough information, authority and support to intervene.
NIST’s voluntary AI Risk Management Framework calls for clear human roles and responsibility. Australia’s 2025 Guidance for AI Adoption asks organisations to assign accountable roles and provide the competence, authority and resources needed for oversight. For high-risk systems, the EU AI Act also addresses the competence and authority of people assigned to oversight.
Organisations still need advice for their own legal and regulatory circumstances. The operational test remains useful: can the assigned person understand the decision, intervene in time and obtain a remedy?
Evidence that intervention helped
Do not measure oversight only by counting how many cases a person reviewed.
Sample whether overrides were correct and consistent. Track how often appeals change an outcome and how long it takes to deliver a remedy. When one defect is found, check whether similar decisions were examined. Compare false positives and false negatives across affected groups where appropriate.
Review queue length, time available per case and the proportion of cases completed before the escalation deadline. These measures show whether the authority line still operates when demand rises.
An unusually low disagreement rate should be investigated. It may mean the system performs well. It may also indicate that reviewers lack information, time or confidence to challenge it.
NIST’s voluntary AI RMF Playbook suggests recording oversight activity, overrides, complaints and escalation decisions. These records are useful, but they do not prove that the control worked. Review actual cases to see whether a person identified a problem, acted before harm became difficult to reverse and triggered correction of the wider defect.
A worksheet for next week’s review
Choose one AI-supported decision with a consequence that matters. Follow one real case with the employee who reviews it and the manager who owns the business outcome.
| Field | Record the actual arrangement |
| Decision being reviewed | |
| Possible consequence if wrong | |
| Time before harm is hard to reverse | |
| Evidence visible to reviewer | |
| Immediate action reviewer can take | |
| Final authority and named deputy | |
| Required escalation response time | |
| Escalation trigger or risk threshold | |
| Normal and peak case volume | |
| Review time per case and unsafe backlog point | |
| Individual-case stop authority | |
| Process suspension authority and trigger | |
| Decision rationale and evidence record | |
| Remedy owner | |
| Route for affected person | |
| Last test date and result | |
| Gap owner and correction date |
Complete the worksheet using actual permissions, response times and system evidence. Do not rely only on the policy or process map. Ask the reviewer to demonstrate the hold, escalation and correction route where it is safe to do so.
Record every gap, assign an owner and agree on a date for correction. Repeat the test after the changes have been made.
Editorial note: The supplier-payment, recruitment, cybersecurity and customer-service examples are composites. They explain recurring operating conditions and do not describe a named organisation or measured incident.
Selected sources for editorial review
- European Union, Regulation (EU) 2024/1689, Articles 14 and 26, human oversight and deployer obligations. Open source
- European Union, Regulation (EU) 2026/1744, Article 1(40), amended application dates for high-risk AI obligations. Open source
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023, including Govern 3.2 and Appendix C. Open source
- National Institute of Standards and Technology, AI RMF Playbook: Measure. Open source
- Australian Government Department of Industry, Science and Resources, Guidance for AI Adoption, 2025. Open source
- Australian Government Department of Industry, Science and Resources, Voluntary AI Safety Standard: The 10 Guardrails, 2024. Open source
- Information Commissioner’s Office and Alan Turing Institute, Explaining Decisions Made with AI. Open source
- Bainbridge, L., “Ironies of Automation,” Automatica, 1983, 19(6), 775-779. Open source
- Parasuraman, R., Sheridan, T. B., and Wickens, C. D., “A Model for Types and Levels of Human Interaction with Automation,” IEEE Transactions on Systems, Man, and Cybernetics – Part A, 2000, 30(3), 286-297. Open source
- Elish, M. C., “Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction,” Engaging Science, Technology, and Society, 2019, 5, 40-60. Open source
- Royal Commission into the Robodebt Scheme, Report, 2023, Chapter 17 and Recommendations 17.1-17.2. Open source
Explore more articles by Mani Padisetti:
Why Clean CRM Data is the Key to Unlocking AI’s Potential
Blockchain and AI: A Partnership to Mitigate Risk and Build Trust
AI Adoption Fails After Launch. The Operating Model CIOs Forget

My journey as the COO, vCIO, and Co-Founder of Digital Armor Corporation; Co-Founder and CEO of Emerging Tech Armory; and Curator, Almost Magic Tech Lab reflects my extensive experience and unwavering dedication to helping medium-sized businesses leverage technology for growth and success. With over two decades of founding and running my own company, I have established myself as a trusted expert in empowering SMBs to enhance productivity, scale effectively, and gain a competitive advantage in their respective industries.
I often refer to myself as the “Growth Catalyst for Mid-Sized Businesses” because I understand the unique challenges these enterprises face, such as limited budgets. I deliver tailored solutions that address their specific goals and constraints.
My secret ingredient to effective leadership is finding joy in being a catalyst for others’ success. I firmly believe in acting in the best interest of my clients, genuinely caring for their businesses as if they were my own. This client-centric approach forms the foundation of my leadership philosophy, driving me to go above and beyond to ensure my clients’ satisfaction and prosperity.





