DISPATCHES · Summit Cognitive

← All dispatches

GovernanceThe FrontierJuly 27, 20265 min read

What "a human in the loop" has to mean

A human who can only watch is not in the loop; they are in the audience — and the difference is the whole of whether anyone was accountable at all.

There is a phrase that has become the standard reassurance whenever an automated system is allowed to do something that matters: there is a human in the loop. It is offered the way a talisman is offered — to end the conversation rather than to open it. It sounds like a safeguard. It has the grammar of a safeguard. And it is almost never accompanied by the one thing that would let you know whether it is a safeguard at all, which is a description of what, precisely, that human can do at the moment the system acts. The phrase reassures by referring to a person, and trusts you not to ask what the person is actually positioned to do.

This is worth dwelling on, because agentic systems — systems that do not merely score or advise but take actions, call tools, move money, file the ticket, send the message — have made the phrase load-bearing in a way it was not before. When a model produced a recommendation and a person decided, the human was unavoidably in the loop: the action did not happen until they made it happen. An agent inverts that. The action happens unless someone stops it, and often faster than anyone could. So "a human in the loop" stops being a description of how the work is structured and becomes a claim about a capability — the capability to intervene — that either exists or does not. The words are the same. What they have to prove is entirely different.

I want to be exact about what the phrase must mean if it is to mean anything, because the vagueness is not accidental. Vagueness is what lets the phrase launder autonomy: it lets a system that acts on its own borrow the moral standing of a system that is supervised, without paying for it. So here is the test. For a human to be genuinely in the loop, three conditions have to hold at the moment of the act — not in principle, not on the org chart, not in the design document, but there, then, when the action is about to occur.

The three conditions that make a loop real

The first is information. The human must have the material to judge — the decision's actual inputs and the rule in force — in a form they can read in the time available. This cuts two ways, and both matter. A human handed a firehose is not informed; they are drowning, and drowning is indistinguishable from ignorance in its effects. A human handed a reassuring one-line summary is not informed either; they are being managed, shown a version curated to produce assent. Real information sits in the narrow band between those failures: enough to see what the action rests on and what rule it claims to follow, shaped so a person can actually take it in before the moment passes. If the human cannot reconstruct why this action, on what basis, from what they were shown, they are not judging. They are nodding.

The second is authority and time. The human must be able to say no, and the no must stick. This is the condition most often quietly absent. An approval that cannot practically be withheld is not an approval; it is a ceremony. If the queue moves at four actions a second and the human has two hundred milliseconds per item, there is no loop — there is a person whose hand is being moved across a stamp. If saying no means halting a process that everyone is measured on keeping fast, the authority to refuse exists on paper and nowhere else. Time is part of authority here, not separate from it: the power to intervene is exactly as real as the interval in which intervention is possible. Compress the interval to nothing and you have abolished the power while keeping the person.

The third is a record. What the human was shown, and what they chose, has to be captured — so that their presence in the loop is a fact that can be checked rather than a claim that can be asserted. Without it, "a human reviewed this" is a sentence with no truth conditions. It cannot be confirmed and it cannot be refuted, which means it is doing no work except reassurance. A Decision Receipt that carries the inputs the reviewer saw, the rule that was in force, and the choice they made turns oversight from a position on a chart into evidence with standing — something a later party can contest, replay, and either uphold or break. Presence that leaves no trace is not oversight anyone can rely on. It is a story told after the fact by whoever is telling it.

A loop that fails any one of these is decoration. Fail the first and the human cannot see; fail the second and they cannot act; fail the third and no one can ever confirm they were there. Meaningful human control is the conjunction of all three. Nominal human presence is any subset dressed up as the whole.

A human placed where they cannot see, cannot pause, and leave no trace is not oversight. They are insulation — a layer of person between the system and the blame.

The automation of the human

Once you see the three conditions, you can see the failure they describe, because it is everywhere and it has a shape. The failure is not that the human is removed. It is that the human is retained in a role that has been hollowed out — kept in the diagram, stripped of the capacity. This is the automation of the human: the person is still there, but the loop has been engineered so that their only available move is assent, and assent has been made frictionless while refusal has been made costly, slow, or impossible.

Two mechanisms do most of the hollowing. One is rubber-stamping by design: the approval step is preserved because a policy or a regulator requires an approval step, but everything about its ergonomics — the pace, the defaults, the summary in place of the inputs — is tuned to produce yes. The other is alert fatigue, which does the same thing without anyone intending it. A human asked to meaningfully review the tenth action attends; asked to review the ten-thousandth, they pattern-match and click. This is not a character flaw to be trained away. It is what attention does under volume, and a system that routes high volume through a single human is not supervising its actions; it is manufacturing consent and calling it review.

What makes this worse than honest full autonomy is the incentive underneath it. A nominal human is cheap — they require no real authority, no readable information, no time budget, none of which is free. And a nominal human absorbs blame. When something goes wrong, there is a name on the approval, a person who signed off, and the institution can point to them instead of to the system it built and the pace it chose. This is the worst of both arrangements: a person who is accountable in name and could not have intervened in fact. They exercised no judgment and they carry the liability — which is precisely backwards, because accountability was supposed to follow the capacity to act, and here it has been severed from it and hung on whoever was standing closest.

So the correct posture toward the phrase is not to accept it and not to dismiss it, but to make it prove itself. When someone says a human is in the loop, the question is not whether a human exists somewhere in the system. It is whether that human could have seen what the action rested on, could have stopped it and made the stop hold, and left a record that they were there and what they chose. If the answer to all three is yes, the loop is real and the reassurance is earned. If the answer to any is no, the human is not in the loop. They are in the audience — watching an action they cannot change, so that later someone can say a person was watching.

— Dispatches · Summit Cognitive

Continue from here

Turn the argument into a practice.

Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.