The EU AI Act places human oversight at the centre of responsible AI use, but it does not treat oversight as a simple training assignment. For high-risk systems, Article 26 requires organisations to put capable people in the loop and ensure they have the competence, training, authority and support to act. This article breaks down what those four conditions mean in practice, why managers own more of the requirement than they may expect, and how to tell whether employees can genuinely challenge an AI system when the situation demands it.
Eventually, a manager will receive a list of names.
These employees have been assigned to oversee an AI system. Please confirm they are qualified.
The request will look administrative. It is not.
Article 26(2) says deployers of high-risk AI systems must assign human oversight to natural persons with the necessary competence, training and authority, as well as the necessary support.
Four conditions.
A course may contribute to two.
The manager creates—or destroys—the other two.
Organisations tend to blend the four terms into a general idea of readiness. That makes the requirement easier to discuss and harder to meet.
Can the person perform the required judgment in context?
Competence is demonstrated through action, not inferred from attendance.
Has the person been prepared for the task?
Training matters. It is an input. Its quality depends on relevance, practice and assessment.
Is the person genuinely empowered to challenge, disregard, override or stop the system?
Permission in a policy is not enough if the workflow, incentives or leadership behaviour punish its use.
Will the organisation back the person when they act responsibly under uncertainty?
Support becomes visible after a difficult decision, especially when the decision turns out to be wrong.
This is why Article 26 is not merely an L&D requirement.
It is an operating-model requirement.
Imagine a claims analyst reviewing an AI recommendation.
The model is usually accurate. This case feels wrong. The analyst overrides it. Later, the override proves costly.
What happens next?
Does the review examine whether the analyst followed a sound process with the information available at the time?
Or does the organisation simply compare the human decision with the machine’s eventual result and conclude that the employee should have trusted the system?
Employees learn quickly from that distinction.
A company may say, “Use your judgment.”
Its incident process may say, “Do not be the person who disagrees.”
When those messages conflict, the process wins.
A person does not have meaningful authority when:
That design produces nominal oversight and practical deference.
A manager cannot fix every interface problem. A manager can identify when the work makes responsible challenge impossible and escalate it as an operational control failure.
That is part of the job.
Completion data answers one question:
Did the person finish the assigned activity?
It does not answer:
Those are performance questions.
The cleanest way to assess them is to place people in realistic decisions before the live system forces the issue.
Not every scenario needs an expensive simulation. But the practice must contain uncertainty. The correct answer cannot be signposted. The person must make a decision and live with the consequence long enough for judgment to become visible.
Otherwise, the organisation is assessing recall.
Ask for decisions, not topics.
“Model limitations” is a topic.
“Deciding whether to reject a high-confidence recommendation with conflicting source evidence” is a decision.
The second can be observed.
Generic AI awareness can establish a baseline. It cannot prepare every role for every consequence.
A recruiter, clinician, claims analyst and customer-service supervisor do not need identical judgment.
If every practice case rewards acceptance, the programme has trained compliance with the machine.
Include moments where the system is right. Include moments where it is wrong. Do not tell the learner which is which.
Look beyond the written policy.
Review metrics, escalation paths, staffing, queue pressure and the behaviour of supervisors after exceptions.
People need access to expertise, a clear escalation path and a fair review process.
“Use your judgment” without those conditions is delegation without support.
The Digital Omnibus moved major high-risk obligations to later dates: 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for high-risk systems embedded in regulated products.
That gives organisations more implementation time.
It does not make competence, authority or support fast to build.
Training can be purchased. Culture cannot.
A manager can approve a policy in one meeting. Employees will decide whether it is real after watching what happens to the first colleague who uses it.
That learning cycle has no shortcut.
You do not need to wait for a final oversight roster.
Start with the AI systems already shaping work.
For each one:
This is management work in the most literal sense.
It aligns responsibility, authority, process and support.
A company can train someone and still leave them unable to act.
It can authorise someone and still punish them for using the authority.
It can place a human in the loop while designing the loop so that the human almost always agrees.
Article 26(2) exposes those contradictions.
The manager’s task is not to certify that people sat through material. It is to create the conditions in which a competent person can exercise judgment when the AI is persuasive, the clock is running and certainty is unavailable.
That is a much higher bar.
It is also the only version of human oversight worth having.
See what performance-based evidence can look like. The Cognistry EU AI Act page shows role-based decision practice and measurable evidence.