The definition
"Human in the loop" started in machine learning, where people label data or check a model's output. This guide is about something else: AI agents that take actions in a business. There, the loop is the path from the agent's decision to a real effect, and the person is the check on that path.
Three levels of oversight
| Level | What it means | When it fits |
|---|---|---|
| Human in the loop | A person approves before the action runs | Actions that reach a customer, change a record or spend money |
| Human on the loop | The agent acts; a person monitors and can step in | Routine work with a record and a way to stop it |
| Human out of the loop | The agent acts alone | Low-risk work inside the system, still recorded |
A person behind every action is not the goal. That makes agents slow, and people start approving without reading. Match the level of oversight to the risk of the action.
Where to put people
Ask three questions about each action an agent can take:
- Does it reach someone outside? A customer email or a message in a shared channel cannot be unsent.
- Does it change a record that matters? A customer record, a deal stage, a price.
- Does it spend? An action with a cost above a set amount.
If the answer to any is yes, put a person in the loop. If all three are no, let it run and record it.
40%+
of agentic AI projects predicted to be canceled by the end of 2027, citing cost, unclear value and weak risk controls.
Source: Gartner, June 2025
The reasons given for cancellation include weak risk controls and unclear value. A person in the loop, and a record of their decisions, address both.
Who should approve
- A named person. Not a shared inbox and not "the team". Someone who answers for the decision.
- With the right role. The approver should have authority over the thing being changed.
- Never the requester alone. A person should not approve their own request. A company may allow an exception for its owner.
What the approver needs to see
To decide well, the approver needs the action (what the agent wants to do), the context (why) and the consequence (who or what it affects). Then a clear yes or no, recorded with their name and the time.
Common mistakes
- Approval everywhere. Too many requests lead to rubber-stamping. Reserve approval for high-risk actions.
- No owner for the queue. Requests wait and work stalls. Name who handles them and how fast.
- No record. Without a log of who decided what, oversight cannot be shown later.
- No stop button. A person needs a way to pause all agent work at once.
Human in the loop and AI governance
Human approval is one control inside AI agent governance. Governance adds the register of agents, limits on access and spend, and the record that proves the oversight happened. See the wider definition in what is AI governance?.
How MFDIO applies this today
In MFDIO, workflow steps that send or write outside MFDIO wait for an approver with the right role before they run, and this is on by default. Approvals work like this:
- Today: workflow steps that send an email, post to chat or write to a record wait for approval. Approvers need the right role, and no one approves their own request unless they are the Owner. An Emergency Stop pauses all AI work for an organization. Every decision is recorded in the append-only audit log.
- Roadmap: per-agent blocked actions, and enforcement on live actions in customer systems through built-in connections.
See the full list at what works today.
Questions people ask
Is human in the loop the same as human on the loop? No. In the loop means approval before the action. On the loop means monitoring with the ability to intervene.
Does human in the loop slow AI down? Only where it should. Low-risk work runs on its own, so people see the few actions that matter.
Does human oversight make a company compliant? Not by itself. It is one working control. Ask a qualified adviser what your rules require.
How do we start? Pick the three riskiest actions your agents can take, name an approver for each, and keep a record of every decision.
Limits of this guide
This guide is general information and not legal advice. MFDIO is in invite-only early access and is pre-revenue. MFDIO does not hold SOC 2 or ISO 27001 today. Market figures are analyst or survey estimates and vary between sources.
Sources
- Cloud Security Alliance, "Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises", 21 April 2026 (418 IT and security professionals; commissioned by a security vendor)
- Gartner, June 2025: over 40% of agentic AI projects predicted to be canceled by the end of 2027, citing cost, unclear value and weak risk controls
- MFDIO product facts: checked against /platform/approvals and the Today list at /status on 5 October 2026
Published . Last updated . Written by the MFDIO team.