Human control must be designed
Many AI systems are described as human-in-the-loop. The phrase is reassuring, but it does not explain what the person controls, when they become involved or what information they receive before making a decision.
Effective authority is specific. The organisation needs to define the difference between preparing work, recommending an action, approving it and carrying it out. It also needs to know who can change those boundaries.
Start with decision rights
Before assigning work to AI, identify the decisions within the workflow. Some actions may be routine and reversible. Others may create financial exposure, affect a customer, change a technical outcome or involve personal information.
- Preparation: AI assembles context or drafts the next step.
- Recommendation: AI proposes an action and explains the relevant basis.
- Approval: an authorised person accepts, changes or rejects the proposal.
- Execution: an approved action is completed within defined permissions.
- Escalation: the work moves to a designated person when conditions fall outside those permissions.
Give the reviewer enough context
An approval button is not meaningful control if the reviewer cannot see what they are approving. The review should present the relevant source information, the proposed action, material exceptions and the consequence of proceeding.
The person should also be able to change the action, request more information or stop the workflow. Good governance supports judgement rather than converting it into a ceremonial click.
Record the decision and the outcome
For important work, the operating record should show what was proposed, who held authority, what was approved and what happened afterwards. That evidence makes review, correction and continuous improvement possible.
It also separates accountable use of AI from invisible automation. When an unexpected outcome occurs, the organisation can reconstruct the path rather than guessing which system or agent acted.
Privacy is part of authority
Authority over an operational action does not automatically create authority to use every item of information available to the organisation. Personal and sensitive information require their own purpose, access and handling controls.
The Office of the Australian Information Commissioner advises organisations to assess privacy risks when using commercially available AI products and notes that the Privacy Act applies where AI use involves personal information. This should be considered before information is entered into a workflow, not after deployment.
The practical objective is controlled capability: AI doing more useful work inside boundaries the organisation understands, monitors and can change.
