Skip to main content
Neurastruct
UnderstandBeginnerBy Peter McLean, founder9 min readLast checked 1 October 2026

Human in the loop: where a person must stay in the process

Short answer

Human in the loop means an AI system stops and waits for a person before an action that matters, such as paying money, messaging a customer or changing a record. Put the approval where a mistake would be costly or hard to undo, and let the AI handle the steps before it. Show the person exactly what will happen, so the approval is a real check rather than a reflex.

What does human in the loop mean?

means an AI system stops and waits for a person before an action that matters. The AI can do the steps that come before it: read the email, look up the job, draft the reply. Then it pauses, shows a person what it is about to do and waits to be told.

There are three parts, and each one matters.

  • The pause. The action has not happened yet. Nothing is sent, paid or changed until the person answers.
  • The person's decision. They can say yes, say no or change the action before it goes ahead. They are deciding, not being informed.
  • A no that holds. If the answer is no, the system does not do it anyway, and it does not try the same thing another way.

Take away any one and it stops being an approval. A message that tells you afterwards what the AI just sent is a notification. A screen where the action goes ahead whatever you click is decoration.

It is also different from a person reading a report later. Checking last week's work is auditing, and the action has already happened. If the vocabulary is new, our plain-English guide to what agentic AI is covers the rest.

Which decisions should always have a person?

Not every step needs one. Looking up a job, reading a supplier email or drafting a reply changes nothing until somebody uses the result. The pause belongs in front of actions where a mistake costs something or is hard to take back. Four kinds should always have a person.

  • Money going out. Paying an invoice, approving a refund or placing an order. A wrong payment can be hard to recover, and a false invoice can look like a real one.
  • Messages to customers. A message carries your name and cannot be unsent. It can promise a price or a date you cannot keep.
  • Anything you cannot undo. Deleting a record, cancelling a booking or changing a live schedule.
  • Decisions about a person. Whether a job applicant goes further, whether a customer gets credit or keeps an account. The AI can gather the facts and draft a recommendation. A person weighs them and answers for the outcome.

Here is a quick test for any action. If the AI got this wrong, who would find out, and how hard would it be to fix? If the answer is "the customer, and not easily", put a person in front of it.

A pause also gives you a chance to catch a trick. Text in an email, web page or file can be written to look like an instruction, which is called . The AI may be fooled, but a person reading the exact action has a chance to stop it.

Our guide to what agentic loops can be used for shows where the approval sits in real jobs. The fourth kind connects to the Australian sources in the next section.

What do Australian rules expect?

This is general information from public sources, not legal advice. Ask the Office of the Australian Information Commissioner (OAIC) about your own situation.

Who the Privacy Act covers. It does not cover every business. The OAIC says Australian Government agencies and organisations with an annual turnover of more than $3 million have responsibilities under the Act, subject to some exceptions. Some smaller businesses are covered anyway, such as a private sector health service provider or a business that sells or purchases personal information. Check that page if you are unsure.

A new rule about telling people. Part 15 of Schedule 1 of the Privacy and Other Legislation Amendment Act 2024 adds APP 1.7 to 1.9 to the Australian Privacy Principles. It commences on 10 December 2026 and applies to decisions made after it commences, even if the system was set up earlier. It applies when an entity has arranged for a computer program to make a decision, or to do something substantially and directly related to making it; the decision could reasonably be expected to significantly affect the rights or interests of an individual; and personal information about that individual is used in the program's operation.

When it applies, the entity's privacy policy must describe the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making them. The Act's examples of decisions that may affect rights or interests include granting or refusing a benefit under legislation, affecting rights under a contract, agreement or arrangement, and affecting access to a significant service or support. It says "computer program", not "AI".

This is a rule about what your privacy policy says. The text we read does not say a person must approve each decision. The OAIC's guidelines on this rule say a decision may be within its scope "even where a computer program output does not replace the entire decision-making process or is subject to human review". They also say a program a person uses for something other than facilitating the decision, such as a word processor used to document it, is not captured.

The OAIC's guidance on AI products. The OAIC's guidance on privacy and the use of commercially available AI products is guidance, not law. It says privacy obligations apply to personal information put into an AI system and to output that contains personal information. It says organisations should have appropriate human oversight of AI outputs, treating them as statistically informed guesses, and that a person should be responsible for checking the accuracy of personal information obtained through AI and be able to overturn decisions. It also calls AI use in decisions with a legal or similarly significant effect on someone's rights likely a high privacy risk activity.

The Australian Government's AI adoption guidance. The National Artificial Intelligence Centre says on its Voluntary AI Safety Standard page that on 21 October 2025 it published the Guidance for AI Adoption, six essential practices for safe and responsible AI governance, which evolves the standard. Its sixth practice is to maintain human control: organisations need to make sure a person appropriately oversees any AI systems in use, and the person should know how to override the system if something goes wrong.

Put together, none of these sources says a person must approve every AI action. From 10 December 2026, a business the Privacy Act covers must describe the kinds of decisions set out above in its privacy policy, and the guidance says to keep appropriate human oversight. The OAIC says its guidance does not cover other regulatory regimes that may apply to AI use, so ask the OAIC or a lawyer about anything specific.

How does an approval step work in practice?

In an the pause is a step in the code: before an action that changes something runs, the loop stops and asks.

  1. The loop pauses. The AI has asked to do something, such as send an email. The action is held, not run.
  2. The person sees the exact action. The actual email to the actual recipient, or the actual amount and payee. Not a summary of it.
  3. A yes runs it. If your system allows it, the person can change the action first.
  4. A no goes back to the AI as a decline. The AI is told that a person declined, not to try it again, and to say what it would have done instead. It explains rather than retrying.
  5. No answer means no action. If nobody responds, the action stays held.

If you build software, Step 4 of our guide to stop conditions and budgets shows the pause and the decline in tested TypeScript and Python. There, if you pass an approval function, the tool runs only when it says yes, and a no goes back to the model with a message not to try again.

We work this way ourselves. Our own social media posts publish only after the owner approves each one. Each post starts as a draft, either written by us or drafted by an AI model. The owner reads it in a private admin page and approves it, or does not. A scheduled job then publishes only the posts marked approved. It never picks up a draft, and a draft that stays unapproved is eventually marked expired, so it can no longer be posted. Where an AI model is used, it drafts. It does not choose the steps and it does not publish. That is a fixed workflow with an approval gate, not an agent, and a no there simply means the post is never published.

How do you stop approvals becoming a rubber stamp?

An approval only counts if the person is really deciding. Ask someone to approve request after request and they can start clicking yes without reading. The OAIC's guidance describes a related risk: staff can come to over-rely on an AI assistant and overestimate its accuracy. Four habits help.

  • Show the specific change, not a summary. "Send follow-up to customer" invites a quick yes. The full message, the recipient and what it replaces give the person something to check. For a payment, show the amount, the payee and the account. For a changed record, show before and after.
  • Approve fewer, higher-stakes actions. Let reads and drafts through, and keep the pause for the four kinds above. A person who is asked about everything can stop looking, so each needless approval can weaken the ones that matter.
  • Batch the low-risk ones. Group routine items into one review, such as a list of drafts read together, instead of interrupting a person for each. Every item in a batch should still be visible and easy to reject. Keep money and decisions about a person out of it.
  • Sample what passed without approval. For the actions you let through, have a person check a few picked at random, on a regular schedule. If they find mistakes, put the approval back. If they find none, you have some evidence that loosening the rule was safe.

If a person has approved everything for weeks, that may mean the AI is very good at that job or that nobody is reading. A sample can tell you which.

A practical way to begin: list every action your AI can take, mark the ones that spend money, message a customer, cannot be undone or decide something about a person, and put the pause on at least those. Show the exact action, read a sample of the rest, and loosen the pause on other actions one job at a time, only when the evidence supports it. Keep it on the four kinds.

Common questions

Does every AI action need approval?

No. Steps that only read or draft, such as looking up a job or writing a reply for someone to check, can run without a pause. Put the approval in front of actions that spend money, message a customer, cannot be undone or decide something about a person. For other actions, start with more approvals than you think you need and loosen them one job at a time as the evidence builds.

What happens if nobody approves in time?

The action waits or the request expires, and it does not go ahead. Silence must never count as a yes. Decide in advance how long a request waits, who is reminded and what happens when the time runs out.

Is human in the loop required by law in Australia?

It depends on the decision, and none of the sources this guide checked says a person must approve every AI action. From 10 December 2026, if the Privacy Act covers your business, a new rule requires its privacy policy to describe the kinds of decisions a computer program makes, or does something substantially and directly related to making, using personal information, where they could reasonably be expected to significantly affect an individual, and the OAIC's guidance on AI products says organisations should have appropriate human oversight of AI outputs. This is general information, not legal advice, so ask the OAIC or a lawyer about your own situation.

Want this built for you instead? See how we build AI workflows, or book a free 30-minute consultation.

Peter McLean

Peter McLean

Founder, Neurastruct

Australian small-business operator since 2001 and 16 years as a national account manager; AI certificates from Anthropic (2026) and Google (2025).

© Neurastruct Pty Ltd. Text licensed CC BY 4.0. Code samples licensed MIT. CC BY 4.0 · MIT