Search the Atlas

Search risks, controls, and glossary terms

Non-AgenticAccountability & Oversight

Human-in-the-Loop

Explanation

Human-in-the-Loop checks that a qualified person reviews high-stakes AI decisions rather than letting the model act unsupervised, and it watches how often that reviewer disagrees with the model. This matters because accountability rules require a human to own consequential outcomes such as a declined loan, and a sustained pattern of reversals is an early warning that the model is drifting or miscalibrated. It is measured by the Human Override Ratio, computed as Override Ratio = Count(Human_Overrides) / Count(AI_Decisions_Reviewed), specifically for credit decisions with human review of declines. To implement it, route the relevant decisions (for example, all credit declines) into a review queue, capture each reviewer's accept-or-override action with reason codes and reviewer identity, and log timestamps and the model's original recommendation as evidence; the control sits at the decision-egress point of the lending pipeline and feeds a governance dashboard. The threshold is <10%, where a higher override rate indicates model issues; a breach should trigger investigation of the model and the affected decisions, with escalation to model risk owners and roles defined under the AI policy. Because this control is rated Immediate priority, treat any sustained breach as a signal to pause reliance on automated declines pending review.

Metric calculation

Override Ratio = Count(Human_Overrides) / Count(AI_Decisions_Reviewed) For credit decisions with human review of declines.

Risks mitigated

48
ZYR-SA-001Critical
Objective Substitution & Proxy Gaming
AI System Safety
ZYR-SA-002Medium
Longitudinal Goal Drift
AI System Safety
ZYR-SA-003High
Resource & Control Accumulation
AI System Safety
ZYR-SA-004High
Strategic Concealment & Misrepresentation
AI System Safety
ZYR-SA-005High
Unintended Environmental Impact
AI System Safety
ZYR-SA-006Medium
Metric Exploitation at Expense of True Intent
AI System Safety
ZYR-SA-008High
Self-Interested Adversarial Behaviour
AI System Safety
ZYR-SA-009High
Resistance to Correction
AI System Safety
ZYR-AU-001High
Oversight Gap in Autonomous Execution
Agent Autonomy
ZYR-AU-002Medium
Runaway Multi-Step Planning
Agent Autonomy
ZYR-AU-003High
Non-Rollbackable State Changes
Agent Autonomy
ZYR-AU-004High
Agent Self-Directed Configuration Changes
Agent Autonomy
ZYR-AU-005Low
Uncontrolled Agent Spawning
Agent Autonomy
ZYR-AU-006High
Silent Permission Expansion
Agent Autonomy
ZYR-AU-007Medium
Inefficient & Duplicative Execution
Agent Autonomy
ZYR-AU-008Medium
Self-Reinforcing Execution Cycles
Agent Autonomy
ZYR-AG-001High
Authority Scope Violation
Accountability & Governance
ZYR-AG-004High
Unregistered Agent Operations
Accountability & Governance
ZYR-AG-005High
Validation Coverage Gaps
Accountability & Governance
ZYR-AG-007Medium
Non-Deterministic Agent Behaviour
Accountability & Governance
ZYR-AG-008Medium
Governance Attention Exploitation
Accountability & Governance
ZYR-AG-009Medium
Low-and-Slow Policy Bypass
Accountability & Governance
ZYR-SE-001High
Human Oversight Erosion
Societal & Economic Risk
ZYR-SE-002High
Labour Market Disruption
Societal & Economic Risk
ZYR-SE-003Medium
Compute-Driven Carbon Footprint
Societal & Economic Risk
ZYR-SE-004High
AI-Enabled Authority Centralisation
Societal & Economic Risk
ZYR-SE-006Medium
Approval-Optimised Dishonesty
Societal & Economic Risk
ZYR-AG-010High
MCP Server Confused-Deputy
Accountability & Governance
ZYR-AU-009High
OAuth Scope Misbinding in MCP
Agent Autonomy
ZNR-TE-001High
Black-box unexplainable output
Transparency & Explainability
ZNR-TE-002Medium
Lack of contestability / recourse
Transparency & Explainability
ZNR-TE-003Medium
Missing content provenance / watermarking
Transparency & Explainability
ZNR-TE-004Medium
Undisclosed AI interaction
Transparency & Explainability
ZNR-TE-005Medium
Inadequate model documentation / model cards
Transparency & Explainability
ZNR-TE-006Medium
RAG source-attribution gaps
Transparency & Explainability
ZNR-GA-001High
Regulatory non-compliance
Governance, Accountability & Compliance
ZNR-GA-002High
Inadequate pre-deployment evaluation / red-team
Governance, Accountability & Compliance
ZNR-GA-003High
Missing human oversight
Governance, Accountability & Compliance
ZNR-GA-004Medium
Model & version change-management gaps
Governance, Accountability & Compliance
ZNR-GA-005High
Third-party / value-chain model risk
Governance, Accountability & Compliance
ZNR-GA-006Medium
Inadequate monitoring & incident response
Governance, Accountability & Compliance
ZNR-GA-007High
Shadow AI / ungoverned usage
Governance, Accountability & Compliance
ZNR-GA-008Medium
Unclear accountability / ownership
Governance, Accountability & Compliance
ZNR-SE-001High
Over-reliance / automation bias
Societal & Economic
ZNR-SE-002Medium
Workforce displacement
Societal & Economic
ZNR-SE-003Medium
Environmental / compute & energy cost
Societal & Economic
ZNR-SE-004Medium
Erosion of human skill / deskilling
Societal & Economic
ZNR-SE-005Medium
Accessibility & digital-divide exclusion
Societal & Economic