Skip to main content
Download free report
Softblues
Softblues
Back to Blog
Business Process Automation
July 28, 20267 min readLast updated: July 29, 2026

Human-in-the-Loop AI: Where the Human Belongs in an Automated Workflow

Nearly 80% of companies bolt AI onto processes they never redesigned. Human-in-the-loop is how you keep control. A UK mid-market guide to where the human belongs in an automated workflow.

Human-in-the-Loop AI: Where the Human Belongs in an Automated Workflow

By Ivan Pylypchuk, CEO of SoftBlues

Nearly 80% of companies using generative AI have layered it on top of processes they never redesigned, even though workflow redesign is the change that correlates most strongly with real financial impact (McKinsey, Mar 2025). Drop a model into an old process and let it run unchecked, and you get speed without control. The fix is not less automation. It is deciding, on purpose, where a human stays in the loop.

Human-in-the-loop is the line between an AI that drafts while a person approves, and an AI that acts on its own. For UK mid-market teams in regulated or high-stakes work, getting that line right is what makes automation safe enough to trust and useful enough to keep.

Key facts

  • About 80% of organisations using generative AI have not redesigned their workflows; only around 21% have redesigned any (McKinsey, Mar 2025).
  • The EU AI Act (Article 14) requires human oversight for high-risk AI systems, with high-risk obligations enforced from August 2026 (Scrut, 2025).
  • Gartner expected at least 30% of generative AI projects to be abandoned after proof of concept by end-2025, with weak risk controls among the causes (Gartner, Jul 2024).
  • Oversight only works when the person has the tools, information, and authority to change the outcome, not just a screen to watch (Kiteworks, 2025).

  • What does human-in-the-loop actually mean?

    Human-in-the-loop (HITL) means a person is built into the workflow at the points where judgement or accountability matters. The AI does the heavy lifting (reading, drafting, sorting, calculating) and a human makes or approves the decision that carries risk.

    It is not the same as having someone available if things go wrong. Real oversight means the person sees the AI's output, understands it, and has the authority and the time to change it. Oversight only counts when the human can genuinely influence the outcome rather than rubber-stamp it (Kiteworks, 2025).

    Note
    A checkbox that says "reviewed by a human" is not oversight. Oversight is a person with the information and the power to say no.

    Why does the human matter if the AI is accurate?

    Accuracy is not the same as accountability, and it is never 100%. Three reasons put a person in the loop.

    Judgement. Some decisions need context the model does not have: a client relationship, a commercial nuance, a reason to make an exception. The model can prepare the decision, and a person should own it.

    Accountability. When a decision affects someone's money, job, or health, a named person has to be answerable for it. Regulators, clients, and courts do not accept "the model decided".

    Compliance. For high-risk uses, oversight is now a legal requirement. The EU AI Act's Article 14 mandates human oversight for high-risk systems, with enforcement from August 2026, and UK regulators expect the same principle of meaningful control (Scrut, 2025).

    Where should the human sit in the workflow?

    Not everywhere. Put a human on every step and you kill the speed you automated for. Remove them entirely and you create risk you cannot defend. The skill is choosing the checkpoints by how much a mistake costs.

    Human-in-the-loop. The AI proposes, a person approves before anything happens. Use it where an error is expensive or hard to reverse: payments, contracts, clinical or credit decisions, anything a regulator watches.

    Human-on-the-loop. The AI acts, a person monitors and can step in. Use it for high-volume, low-stakes work where speed matters and mistakes are cheap and recoverable, like triage, routing, and first-draft classification.

    Human-out-of-the-loop. The AI runs unattended with logging and alerts. Reserve it for the lowest-risk, well-bounded tasks where you have strong data and a clear audit trail.

    The mistake most teams make is applying one setting to everything. Match the checkpoint to the cost of being wrong.

    ModelWho decidesBest forAvoid when
    Human-in-the-loopPerson approves each actionPayments, contracts, regulated decisionsVolume is huge and errors are trivial
    Human-on-the-loopAI acts, person monitorsTriage, routing, classificationA single error is costly or irreversible
    Human-out-of-the-loopAI runs, humans auditLow-risk, well-bounded tasksData is messy or the decision is high-stakes

    How does this work in a regulated process?

    Take a monthly compliance file review in financial advice. The AI reads every file, checks it against the rules, and flags the ones that look wrong, with its reasoning attached. A compliance officer reviews the flagged files and makes the call. The AI does the reading that used to eat days, and the human owns the judgement the regulator cares about.

    That is the pattern in our financial-advice compliance file review work: automate the search, keep the person on the decision. The value is not that the AI replaces the reviewer. It is that the reviewer spends their time on the files that need a human, not on the ones that were always fine.

    💡Tip
    Design the checkpoint around the decision that carries the risk, and let the AI take everything up to it. That is where automation pays back without adding exposure.

    What breaks human-in-the-loop in practice?

    Good intentions fail in predictable ways.

    Rubber-stamping. Give the human too many items and too little time, and they approve on autopilot. The checkpoint exists but the control does not. Keep the review load realistic.

    No context. If the AI shows a decision but not its reasoning or its sources, the reviewer cannot judge it. Every flagged item needs its evidence attached.

    No authority. If the reviewer cannot overturn the AI without escalating three levels, oversight is theatre. Give the person the power the role implies.

    No trail. If you cannot show who approved what and why, you cannot defend the decision later. Log the human step, not just the AI one.

    How do we set this up without over-engineering it?

    Start by mapping decisions, not tasks. For each decision the workflow makes, ask what a mistake costs and how hard it is to reverse. That answer sets the oversight model. High cost and hard to reverse means human-in-the-loop. Low cost and recoverable means human-on-the-loop.

    Then redesign the process around those checkpoints rather than bolting AI onto the old steps. This is the redesign McKinsey found most companies skip, and it is where the return actually comes from (McKinsey, Mar 2025). If you are weighing agents against rules-based automation for this, our comparison of AI agents versus RPA covers where each belongs, and our AI governance guide covers the policies and sign-off around it.

    Who this matters most for

    Any UK mid-market team automating decisions that touch money, compliance, employment, or health. Finance, legal, operations, and HR functions carry the accountability that makes oversight non-negotiable. Our business process automation work is built to automate the volume and keep the human exactly where the risk sits, with no more checkpoints than the work needs and no fewer than the regulator expects.

    Frequently asked questions

    What is human-in-the-loop AI?

    A workflow design where AI does the heavy lifting and a person makes or approves the decisions that carry risk. The human is built into the process at defined checkpoints, not just available on standby.

    What is the difference between human-in-the-loop and human-on-the-loop?

    In-the-loop means a person approves each action before it happens, used for high-stakes decisions. On-the-loop means the AI acts while a person monitors and can intervene, used for high-volume, low-stakes work.

    Does the EU AI Act require human oversight?

    Yes. Article 14 requires human oversight for high-risk AI systems, with high-risk obligations enforced from August 2026. UK regulators expect the same principle of meaningful human control (Scrut, 2025).

    Where should we put the human checkpoint?

    Where a mistake is expensive or hard to reverse, such as payments, contracts, and regulated or clinical decisions. For cheap, recoverable errors in high-volume work, monitoring after the fact is usually enough.

    Doesn't keeping a human in the loop slow everything down?

    Only if you put a human on every step. Match the checkpoint to the cost of being wrong: automate freely up to the risky decision, and keep the person on that decision alone.

    How do we stop oversight becoming a rubber stamp?

    Keep the review load realistic, attach the AI's reasoning and sources to every item, give the reviewer real authority to overturn, and log the human decision for audit.

    Is human-in-the-loop only for regulated industries?

    No, but regulated and high-stakes work needs it most. Any decision someone must be accountable for is a candidate for a human checkpoint.


    SoftBlues is an Anthropic Partner Network member and a Google Cloud Partner. We are practitioners, not slide-deck consultants: we build automation that keeps people in control of the decisions that matter, because that is the only kind our own clients can put their name to. If you want to automate a process without giving up oversight, book a discovery call.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles