The red flag for AI?
Proper governance of AI agents is essential, just as proper governance of people and systems has always been essential, if you want to achieve objectives without undue risk.
The focus on 'human in the loop' as the control for managing this risk is concerning, however: it is probably the wrong control, and one that will stop us benefitting from AI.
In Britain in 1865, the legislative response to the increasing number of self-propelled vehicles on the roads was the Locomotives Act (Locomotives Act 1865) (known as the Red Flag Act). It required that these vehicles be preceded by a man walking 60 yards ahead carrying a red flag to warn other road users of the vehicle's approach.

Today we risk doing the same with AI. Common requirements, often driven by reasonable data protection or fairness concerns, for 'substantive' human review converge on four fairly consistent elements: timing (review before the decision takes effect, not after), authority (the reviewer can change the outcome), competence (the reviewer understands the system's logic, limitations and the underlying data), and independence from the output (the reviewer engages with the evidence rather than deferring to the AI).
Formally these requirements apply to only on a narrow class of significant decisions, but in practice the expectation of a human checkpoint bleeds into procurement standards, internal policies and guidance well beyond it.
Most of this works fine, but expectations for human review of AI output before decisions take effect do not. Authority, competence and independence remain essential; they should attach to the oversight system as a whole, with clear routes to contest and rapidly correct a decision, rather than to a human checkpoint inside every one.
AI's great strength is speed of analysis. If we constrain that by having every AI decision audited by a human in real time, we will fail to win the benefits, just as cars in 1865 were restricted to human walking speed. The distinctive risk of AI, the same error repeated at scale, is real, but it is better controlled by pre-deployment testing, live monitoring and circuit breakers that halt a misbehaving system than by a person walking in front of every decision. The benefits are lost, as others with more sensible controls move ahead faster.
There are other means of managing AI, and they look very much like managing a person: recognising where single-model or single-agent AI autonomy is appropriate, and where (or when) independent review through human or AI oversight is needed.
While operational practice has moved on and already routinely works this way, policy and guidance have some way to go to catch up. The AI Playbook for Jersey (Digital Jersey, 2026) (review of which triggered this article) is one example that seems to understand this, acknowledging the need for proportionality in human review, although it does not yet give consideration to review by independent AI models.
Others such as the Global Privacy Assembly seem to have more catching up to do (Global Privacy Assembly, 2025), stating that "the organization should ensure that the oversight occurs at a time and in a manner that permits the overseer to agree with, contest, or mitigate the potential impacts of the AI system's decision; that is, human oversight of an AI system is unlikely to be meaningful or effective if recourse is only available after the impacts of a decision are experienced by an individual".
However independent AI review, using a genuinely different model rather than the same system marking its own homework, can provide the same or greater benefit without the human bottleneck. The controls we already use for human work can also apply just as well to AI: cultural and behavioural expectations, clear goals and objectives, management oversight, peer discussion, task-based restrictions on data access and use, selective management review of outputs aligned with earned trust, and audit and assurance of the supporting processes and controls.
Universal pre-decision human review is disproportionate. Instead we should design AI oversight to the risk, as we do for humans and systems today. For a small class of decisions that seriously affect an individual, a human who can hear the person and change the outcome will remain the right control; the mistake is treating that exception as the default for everything else.
Cars don't have brakes so they can slow down. They have brakes so they can drive faster than walking pace, safely.
AI governance should be the brakes that let AI run at pace, not a man with a flag walking sixty yards ahead.
References
- artificialintelligenceact.eu Article 14: Human Oversight | EU Artificial Intelligence Act. Available at: https://artificialintelligenceact.eu/article/14/ (Accessed: 1 August 2026).
- Bird & Bird CJEU confirms preparatory acts can be automated individual decisions: the SCHUFA cases. Available at: https://www.twobirds.com/en/insights/2023/global/key-takeaways-from-the-schufa-case-of-the-cjeu (Accessed: 1 August 2026).
- Data (Use and Access) Act 2025, s. 80. Available at: https://www.legislation.gov.uk/ukpga/2025/18/section/80 (Accessed: 1 August 2026).
- Digital Jersey (2026) AI Playbook V3. Available at: https://www.digital.je/wp-content/uploads/2026/03/AI-Playbook-V3-2.pdf (Accessed: 1 August 2026).
- DLA Piper Data Protection Laws of the World Data protection laws in Jersey. Available at: https://www.dlapiperdataprotection.com/?t=law&c=JE (Accessed: 1 August 2026).
- Global Privacy Assembly (2025) GPA Resolution: Human Oversight of Automated Decisions, European Data Protection Supervisor. Available at: https://www.edps.europa.eu/system/files/2025-10/2029_09_19_gpa-resolution-human-oversight-of-automated-decisions_en.pdf (Accessed: 1 August 2026).
- Information Commissioner's Office What is the impact of Article 22 of the UK GDPR on fairness?. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-fairness-in-ai/what-is-the-impact-of-article-22-of-the-uk-gdpr-on-fairness/ (Accessed: 1 August 2026).
- Jersey Financial Services Commission Guidance on the use of AI in Jersey's financial services sector. Available at: https://www.jerseyfsc.org/industry/guidance-and-policy/guidance-on-the-use-of-ai-in-jersey-s-financial-services-sector/ (Accessed: 1 August 2026).
- Locomotives Act 1865. Available at: https://www.legislation.gov.uk/ukpga/Vict/28-29/83 (Accessed: 1 August 2026).
- Office of the Data Protection Authority Artificial intelligence. Available at: https://www.odpa.gg/guidance/artificial-intelligence (Accessed: 1 August 2026).
- UK Government Artificial Intelligence Playbook for the UK Government. Available at: https://gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html (Accessed: 1 August 2026).
About the author
Matt Palmer is an award winning cyber security leader. He currently runs national cyber defence for a small island state. He can be found on linkedin or on bluesky.
Matt Palmer