For Heads-of · Practitioner
Human-in-the-loop review
Mandatory human approval gate for high-consequence or irreversible AI-generated actions before they take effect.
- preventive
- oversight
- approval-gate
What it does
Routes high-consequence or irreversible AI-generated actions through a mandatory human approval step before they take effect.
Where it fits
Sits structurally between generation and execution — a checkpoint in the pipeline, not a policy document describing intent.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
Prompt injection
Attacker-controlled input overrides system instructions, either directly or via retrieved/tool content treated as trusted.
Excessive agency in autonomous agents
An agent is granted more permission, tool access, or autonomy than the task requires.
Inadequate human oversight design
An AI system's human-oversight mechanism exists on paper but isn't actually usable or effective in practice.
Automated decision-making without safeguards
AI is used to make solely-automated decisions with legal or similarly significant effects on individuals, without the safeguards UK GDPR requires.
Misinformation and confabulation
A model states false or fabricated information with the same linguistic confidence as accurate information.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| ISO/IEC 42001:2023 | Clause 6 | Planning & risk |