Human-in-the-loop (HITL) describes an AI system or workflow in which a person must review, approve, correct or reject what the AI produces or proposes before it takes effect. The person is a required step, not an optional observer. The term also has an older meaning in machine learning, where people label data or correct predictions to help train a model; for most buyers today it means human approval points in AI-assisted work and agentic AI.
At a glance
- HITL puts a named person between the AI’s output and the real-world effect, such as sending an email, issuing a refund or changing a record.
- It is a common control for high-impact uses and a typical requirement in AI governance policies.
- It catches some errors, such as AI hallucination, but reviewers can miss mistakes, especially at volume.
- It is usually applied by risk tier, not to every output, because review costs time and money.
- Related patterns include human-on-the-loop (a person monitors and can intervene) and fully automated operation.
What problem it solves
AI systems can be confidently wrong, misread instructions or be manipulated, and agents can act on those errors quickly and at scale. Without a review point, a bad output can reach a customer, a payment system or a production database before anyone notices. HITL keeps a person accountable for decisions that matter, gives a chance to catch errors before they cause harm, and creates a record of who approved what.
It also answers questions buyers increasingly face from customers, auditors, insurers and regulators: who checks the AI, and who is responsible when it is wrong.
How it works
A HITL design defines three things:
- Where the checkpoint sits. For example, before an AI-drafted message is sent, before an agent executes a transaction or before an AI recommendation about a person is acted on.
- Who reviews. A role with the knowledge and authority to judge the output, not just whoever is available.
- What the reviewer sees and can do. Good designs show the AI’s output alongside its sources or reasoning, and let the reviewer approve, edit, reject or escalate.
Approvals and edits are logged, ideally in an audit trail, so the organization can show who decided what. Many teams also feed reviewer corrections back to improve prompts, rules or models.
The weak point is the reviewer. When most outputs look right, people tend to approve quickly without checking, a pattern often called automation bias. Sampling, spot checks, clear criteria and limits on volume per reviewer help keep review meaningful.
When it matters for buyers
- When deploying AI agents. Agents that can send messages, change systems or spend money should usually have approval steps for high-impact actions, at least at first. Ask whether the product supports them natively.
- For decisions about people. Hiring, credit, benefits, discipline and similar decisions often attract legal rules on human review. Requirements vary by jurisdiction; check with counsel. The EU AI Act includes human-oversight obligations for some high-risk uses.
- For customer-facing output. Contact center replies, quotes and public content may need review until accuracy is proven.
- When customers ask. Security questionnaires increasingly ask how AI outputs are reviewed. See our artificial intelligence overview for help evaluating AI products with these controls.
Questions to ask vendors
- Which actions can be set to require human approval, and can we set that by action type, value or risk?
- What does the reviewer see: sources, reasoning, confidence or only the final output?
- Are approvals, edits and rejections logged, and can we export those logs?
- Can we route reviews to specific roles, with escalation and time limits?
- What happens if no one approves: does the action wait, expire or proceed?
- How do reviewer corrections feed back into the system?
How it differs from autonomous AI agents
Agentic AI refers to AI systems that plan and take multi-step actions toward a goal, often with little or no human input between steps. HITL is a control that can be applied to those agents, among other AI systems: it requires a person to approve some or all of their actions before they take effect. An agent can run fully autonomously, with a human on the loop monitoring, or with human-in-the-loop approval at key steps. Many organizations start agents with more HITL checkpoints and remove some as the agent proves reliable on lower-risk tasks.
