Human oversight
Under Article 14, human oversight does not require a human to be in the loop, but requires that a high-risk AI system be designed to enable genuine oversight. The person exercising oversight must understand the system's limitations, be aware of automation bias, and have a real right to override, disregard the output of, or halt the system.
The design obligation is set out in Article 14(1)–(5), with point 2(e) and point 3 of Annex IV adding the documentation side. On the deployer's side, this connects to Article 26(2), which imposes competence, training and authorisation duties — not only on the provider, but on the deployer — regarding the specific individual performing oversight; this is one of the most commonly under-fulfilled, yet fineable, obligations. "Automation bias" — the tendency to blindly trust a machine's recommendation — is an explicitly named risk that the person performing oversight must be trained to counter. Oversight is not a formal presence: the overseer must be genuinely capable of overriding a decision, and must be given sufficient time, information and authority to do so. This standard is closely linked to AI literacy (Article 4): Article 4 sets the general baseline, while Articles 14 and 26(2) set the specific competence level expected for high-risk systems.
If an SME deploys high-risk AI, it is not enough to designate someone as "overseer" — that person must genuinely be able and willing to override the system, and a regulator can check this under Article 26(2).
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- AI literacyAI literacy means the skills, knowledge and understanding that allow a person to make an informed use of AI systems and to be aware of AI's opportunities, risks and possible harm. Under Article 4, providers and deployers must take measures to support the AI literacy of their staff — regardless of the risk category involved.
- DeployerA deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
- ProviderA provider is a natural or legal person that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers bear the Regulation's most extensive package of obligations: risk management, data governance, documentation, conformity assessment, CE marking.
- High-risk AI systemAn AI system is high-risk if it is a safety component of, or is itself, a product covered by the Union product-safety legislation listed in Annex I, or if it falls within one of the eight areas and listed use cases of Annex III. Classification attaches to the intended purpose, not to the underlying technology.
Related questions in the knowledge base (Hungarian)
- Mit jelent jogilag az emberi felügyelet az AI Act 14. cikke szerint?A 14. cikk nem azt követeli, hogy legyen ember a folyamatban, hanem hogy a rendszer tervezésileg tegye lehetővé a tényleges felügyeletet. A felügyelő személynek értenie kell a rendszer korlátait, tudatában kell lennie az automatizálási elfogultságnak, és valós joga kell legyen a kimenet felülbírálására, figyelmen kívül hagyására vagy a rendszer leállítására.
- Hogyan viszonyul az AI-jártasság az emberi felügyelethez (14. és 26. cikk)?A három norma koncentrikus. A 4. cikk általános alapszint minden AI-rendszerre és minden érintett munkatársra. A 26. cikk (2) ezen felül, magas kockázatú rendszernél, a felügyeletet ellátó konkrét személytől követel kompetenciát, képzést és felhatalmazást — és ez már bírságolható. A 14. cikk mögötte a szolgáltatói tervezési kötelezettség.