The EU AI Act places human oversight at the centre of responsible AI use, but it does not treat oversight as a simple training assignment. For high-risk systems, Article 26 requires organisations to put capable people in the loop and ensure they have the competence, training, authority and support to act. This article breaks down what those four conditions mean in practice, why managers own more of the requirement than they may expect, and how to tell whether employees can genuinely challenge an AI system when the situation demands it.
Eventually, a manager will receive a list of names.
These employees have been assigned to oversee an AI system. Please confirm they are qualified.
The request will look administrative. It is not.
Article 26(2) says deployers of high-risk AI systems must assign human oversight to natural persons with the necessary competence, training and authority, as well as the necessary support.
Four conditions.
A course may contribute to two.
The manager creates—or destroys—the other two.
Start with the words separately
Organisations tend to blend the four terms into a general idea of readiness. That makes the requirement easier to discuss and harder to meet.
Competence
Can the person perform the required judgment in context?
Competence is demonstrated through action, not inferred from attendance.
Training
Has the person been prepared for the task?
Training matters. It is an input. Its quality depends on relevance, practice and assessment.
Authority
Is the person genuinely empowered to challenge, disregard, override or stop the system?
Permission in a policy is not enough if the workflow, incentives or leadership behaviour punish its use.
Support
Will the organisation back the person when they act responsibly under uncertainty?
Support becomes visible after a difficult decision, especially when the decision turns out to be wrong.
This is why Article 26 is not merely an L&D requirement.
It is an operating-model requirement.
The override test
Imagine a claims analyst reviewing an AI recommendation.
The model is usually accurate. This case feels wrong. The analyst overrides it. Later, the override proves costly.
What happens next?
Does the review examine whether the analyst followed a sound process with the information available at the time?
Or does the organisation simply compare the human decision with the machine’s eventual result and conclude that the employee should have trusted the system?
Employees learn quickly from that distinction.
A company may say, “Use your judgment.”
Its incident process may say, “Do not be the person who disagrees.”
When those messages conflict, the process wins.
Authority must exist inside the workflow
A person does not have meaningful authority when:
- the system’s recommendation is preselected;
- overriding requires several additional steps;
- the interface hides uncertainty;
- the employee cannot see the evidence behind the recommendation;
- the queue penalises slower review;
- exceptions require senior approval;
- performance metrics reward throughput alone;
- no one knows who owns the final decision.
That design produces nominal oversight and practical deference.
A manager cannot fix every interface problem. A manager can identify when the work makes responsible challenge impossible and escalate it as an operational control failure.
That is part of the job.
Training is not the evidence you think it is
Completion data answers one question:
Did the person finish the assigned activity?
It does not answer:
- Did they notice a plausible error?
- Did they ask for the right evidence?
- Did they distinguish confidence from correctness?
- Did they override when appropriate?
- Did they escalate at the right point?
- Could they explain the decision afterward?
Those are performance questions.
The cleanest way to assess them is to place people in realistic decisions before the live system forces the issue.
Not every scenario needs an expensive simulation. But the practice must contain uncertainty. The correct answer cannot be signposted. The person must make a decision and live with the consequence long enough for judgment to become visible.
Otherwise, the organisation is assessing recall.
Five questions before you attest
1. What did the person actually practise?
Ask for decisions, not topics.
-
“Model limitations” is a topic.
-
“Deciding whether to reject a high-confidence recommendation with conflicting source evidence” is a decision.
The second can be observed.
2. Was the practice drawn from the real operating context?
Generic AI awareness can establish a baseline. It cannot prepare every role for every consequence.
A recruiter, clinician, claims analyst and customer-service supervisor do not need identical judgment.
3. Has the person ever challenged the system?
If every practice case rewards acceptance, the programme has trained compliance with the machine.
Include moments where the system is right. Include moments where it is wrong. Do not tell the learner which is which.
4. Can the employee override without organisational penalty?
Look beyond the written policy.
Review metrics, escalation paths, staffing, queue pressure and the behaviour of supervisors after exceptions.
5. What support exists after a difficult call?
People need access to expertise, a clear escalation path and a fair review process.
“Use your judgment” without those conditions is delegation without support.
The timing is deceptive
The Digital Omnibus moved major high-risk obligations to later dates: 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for high-risk systems embedded in regulated products.
That gives organisations more implementation time.
It does not make competence, authority or support fast to build.
Training can be purchased. Culture cannot.
A manager can approve a policy in one meeting. Employees will decide whether it is real after watching what happens to the first colleague who uses it.
That learning cycle has no shortcut.
What managers should do now
You do not need to wait for a final oversight roster.
Start with the AI systems already shaping work.
For each one:
- Identify the decisions people are expected to review.
- Define when they must check, escalate, override or stop.
- Examine whether the workflow makes those actions possible.
- Give employees realistic practice.
- Review what happens after an override.
- Measure decision quality, not only completion.
This is management work in the most literal sense.
It aligns responsibility, authority, process and support.
The uncomfortable conclusion
A company can train someone and still leave them unable to act.
It can authorise someone and still punish them for using the authority.
It can place a human in the loop while designing the loop so that the human almost always agrees.
Article 26(2) exposes those contradictions.
The manager’s task is not to certify that people sat through material. It is to create the conditions in which a competent person can exercise judgment when the AI is persuasive, the clock is running and certainty is unavailable.
That is a much higher bar.
It is also the only version of human oversight worth having.
See what performance-based evidence can look like. The Cognistry EU AI Act page shows role-based decision practice and measurable evidence.
