GirderGroup

Human oversight and the accountability gap in AI

Regulators and standards bodies have converged on a common requirement: AI used for consequential decisions needs meaningful human oversight and a record of how decisions were made. Here is what that means in practice.

Girder GroupAI Governance Practice
December 3, 2025 · 6 min read

Key takeaways

  • The EU AI Act requires that high-risk AI systems be designed for effective human oversight (Article 14).
  • The NIST AI Risk Management Framework centres governance, traceability, and documentation across the AI lifecycle.
  • Accountability requires records: who decided, on what basis, and with what human involvement.
  • Governance built in during design is cheaper and more defensible than governance bolted on afterwards.

A converging requirement

Across jurisdictions and standards bodies, the expectations for AI used in consequential decisions are converging on a common core: human oversight, transparency, and traceability. This is no longer aspirational language. It is being written into regulation and formal frameworks.

The European Union's AI Act, for example, requires that high-risk AI systems be designed and developed so that they can be effectively overseen by people while in use. The aim is that a person can understand the system's output, decide not to rely on it, and intervene or stop it.

Accountability is not a policy document. It is the ability to reconstruct, after the fact, who decided what and on what basis.

From principles to records

The NIST AI Risk Management Framework approaches the same problem through governance. It emphasises mapping and measuring risk and, crucially, documenting decisions and maintaining traceability across the AI lifecycle, so a system's behaviour can be understood and its risks managed rather than assumed away.

What both have in common is a shift from principles to records. Oversight that leaves no trace cannot be audited. Accountability, in practice, means being able to reconstruct after the fact who decided what, on what basis, and with what human involvement.

Building it in, not bolting it on

The expensive way to meet these expectations is to retrofit them: to add logging, review steps, and documentation to a system that was never designed to produce them. The cheaper and more defensible way is to treat oversight and traceability as design requirements from the start.

That means scoping each automation, recording its inputs and actions, gating the consequential steps, and keeping a durable record of human approvals. Done up front, compliance stops being a scramble and becomes a property of the system.

Sources

  1. 1.European Parliament and Council (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act), Article 14 (Human oversight).EUR-Lex
  2. 2.National Institute of Standards and Technology (2023). AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1.NIST

Girder Group · AI Governance Practice

Senior engineers who build and operate the software they write about.

Talk to the team

Newsletter

Get new insights when we publish them.

Occasional writing on operational software and modernisation. We send something only when it is worth your time.

Unsubscribe anytime. We never share your email.

Enterprise engagement

Bring the problem. We will make the path clear.

Share the context, constraints, and timeline. We'll respond with a practical next step, even when the right answer is not to start a build yet.

info@girdergroup.com