Human oversight is the control everybody claims and few implement. It is also the one the EU AI Act names directly for high risk systems, so it is moving from good practice to obligation.
The three arrangements
A human decides, the system advises. The model produces a suggestion and a person makes the call. Safest, most expensive, and the right arrangement where a wrong decision is costly and irreversible.
A human reviews, the system decides. The system acts and a person checks, either every case or a sample. Cheaper, and it only works while the reviewer retains the ability and the time to disagree.
A human can stop it. The system runs unsupervised and somebody is watching the aggregate, able to intervene or switch it off. Appropriate at high volume and low stakes, and it depends on having something worth watching, which is a monitoring problem rather than an oversight one.
The mistake is claiming the first, staffing the second and operating the third.
What makes review real
The reviewer can judge the output. Somebody checking a legal summary needs to be able to read the contract. A reviewer without the expertise is a delay rather than a control.
They have the time. Review capacity is the binding constraint, and it is what quietly turns oversight into rubber stamping. If the volume is a hundred an hour, the review is a glance.
Disagreeing is expected and cheap. If overriding the system is slower, requires justification, or is treated as an error, people stop. What is measured decides this more than what is written in the policy.
They see what the system is unsure about. Confidence, the sources used, or the cases flagged as unusual. A bare answer gives a reviewer nothing to work with.
Designing for it
Route by risk rather than reviewing everything. Send the low confidence, the unusual and the high consequence to a person, and let the rest through. That concentrates a fixed amount of attention where it changes outcomes.
Make the override the easy path in the interface. Show the reasoning, or at least the sources, so review is possible. And measure the override rate, because a rate near zero usually means the reviewer has stopped reading rather than that the system is perfect.
The obligation
The EU AI Act requires that high risk systems be designed so a person can oversee them effectively, which explicitly includes understanding the system's limits, staying alert to automation bias, being able to disregard the output, and being able to stop it. That is a design requirement rather than a staffing one, and it lands on the product rather than on the operations team.