Signato signato.ai

Human oversight that holds up

Edition 05. A reading time of about 5 minutes.

The hook

Of all the high-risk obligations, human oversight is the one you can start doing today, with no budget and no vendor sign-off. It is also the one that most protects you when a rejected candidate asks how the decision was made. And it is the one most often hollowed out into a checkbox: a human "in the loop" who, in practice, rubber-stamps whatever the system returns. The Act asks for something sturdier. The good news is that the sturdier version is also the cheaper one to build, as long as you start before a deadline forces it.

What this means

The obligation is specific about who, not just whether. As a deployer, you must assign oversight to people who have the necessary competence, training, authority, and support to carry it out (AI Act, Article 26(2)). Read "authority" closely: oversight that cannot overrule the system is not oversight. A reviewer who can see the score but not change the outcome is a witness, not a safeguard.

Two related deployer duties shape what good oversight looks like in practice. You have to monitor the system in use, and if it begins to present a risk, suspend it and inform the provider and the relevant authority without undue delay (AI Act, Article 26(5)). And before you put a high-risk system to work on people in your workplace, you must inform the affected workers and their representatives (AI Act, Article 26(7)). For hiring, that last point lands directly: the people a system judges are entitled to know it is in use.

None of this waits on the law being final. Hiring AI is high-risk by classification today (Annex III, point 4), and oversight is a habit, not a one-time install. The teams that will be ready in 2027 are the ones practicing in 2026, on real decisions, while the cost of getting the routine wrong is still low.

What to do with this

Build oversight that would survive being questioned. Four steps.

  1. Name a person, not a team. Oversight spread across "the hiring committee" is oversight no one owns. Pick someone with the competence to understand the tool and the authority to overrule it, which is the exact standard Article 26(2) sets.
  2. Write down what they can override, and when. "Can set aside the system's ranking and proceed with a human shortlist" is a real power. "Can review the dashboard" is not.
  3. Record the review, lightly but consistently. One line, who reviewed, what they confirmed or changed, and why, is enough. That note is the entire difference between "we had oversight" and "we can show we had oversight."
  4. Tell the people affected. Inform candidates and, where they exist, worker representatives that an AI system is part of the process, as Article 26(7) requires. It is an obligation, and it is also the cheapest trust you will ever buy.

Do this now, on live decisions, and by the time the deadline is real, oversight is not a project you scramble to stand up. It is simply how your team already hires.


This is educational material and a starting point, not legal advice. The EU AI Act is still being amended, and the high-risk timeline rests on an agreement that is not yet final law. For how the human oversight duties apply to your specific tools and workforce, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.


AI that drafts at scale can also send the wrong thing at scale. See the Signato chamber block a forbidden send before it happens: run the free local trial, no card, nothing leaves your machine.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Know someone who hires in the EU? Forward this to them.

AI hiring law, made operational. Free, weekly.

Plain-language, sourced intelligence for HR and legal teams. Start with the free Starter Kit.

No spam. Unsubscribe in one click. See our Privacy Policy.

Run a newsletter on Beehiiv? Add Signato to your recommendations in one click, and send your readers a clear, sourced read on AI compliance.

Add Signato to your recommendations →