In plain terms
A train driver's cab has a dead man's switch, an airliner has two pilots and a way to switch off the autopilot, and a bank has a second signature for large payments. Each is a way of keeping a person in a position to notice and to intervene. Human oversight is that requirement applied to AI: for every system that matters, someone must be able to see what it is doing, to disagree with it and to halt it.
Why it matters
It is the control that regulators, auditors and courts look for first, and for high-risk systems in the EU it is a legal requirement. It is also the easiest control to fake. A person who approves two hundred AI recommendations an hour, with no time and no information to judge them, provides a signature and no oversight; the tendency to accept what a system suggests is known as automation bias. Real oversight costs staff time and slows the process, so it should be concentrated where an error is costly or hard to reverse.
Example
A lender has a reviewer confirm every credit refusal that its model proposes. An audit finds that reviewers confirm 99.4% of proposals and spend eleven seconds on each. The lender redesigns the step: reviewers see the three factors that drove the score, a tenth of the cases arrive with no recommendation attached, and each reviewer handles 40 cases a day, down from 300. Overturned refusals rise from 0.6% to 7%.
Most often confused with
Human Oversight vs. Human-in-the-loop (HITL)
Human oversight is the goal; human-in-the-loop is one design for reaching it, in which nothing proceeds without approval. Human-on-the-loop, where a person monitors and steps in when needed, is another, and for low-risk work periodic review can be enough. Choosing among them, by the stakes of the task, is itself part of oversight.
Under the hood
In the EU AI Act, Article 14 requires high-risk systems to be designed so that natural persons can oversee them effectively: understand capacities and limits, stay aware of automation bias, interpret outputs correctly, decide to disregard or reverse an output, and interrupt the system through a stop function. Article 26 obliges deployers to assign oversight to people with the necessary competence, training and authority. Under the GDPR, a person subject to a solely automated decision with legal or similarly significant effect has a right to human intervention. Oversight is effective under four conditions: competence, authority, time and information. Design practices: show the evidence and the uncertainty with every recommendation; route cases by risk; measure override rates and review times, since values near zero signal rubber-stamping; test reviewers with seeded errors; log decisions; and rehearse the stop procedure. For agents, oversight is implemented through approval gates on consequential tool calls, budgets, monitoring and an interrupt that works.