"What human oversight exists over your AI outputs?" — the oversight question
Every AI section asks this, and the tempting answer is pure adjectives: "human-in-the-loop", "humans always review outputs". Buyers do not buy adjectives. They want the mechanism — and they want you not to overclaim what that mechanism does legally. Here, a true description of a modest control beats a grand claim every time, because oversight claims are the easiest ones for a buyer to test in a demo.
Why buyers ask this
The buyer's risk team wants to know whether your AI outputs can cause harm silently: whether anything is auto-executed, who catches errors, and how a bad output gets corrected. The instruments buyers now use — the AI-CAIQ, the SIG 2026 AI domain, the EU's model contractual clauses for AI — all probe vendors' controls over AI output, and your answer feeds the buyer's own risk assessment. It is also a competence test: vendors who understand the EU AI Act describe oversight accurately; vendors who do not wave it around as proof of compliance. That distinction is what this guide is about.
What oversight does — and does not do — under the AI Act
One thing to get straight before drafting. Under Regulation (EU) 2024/1689, mandatory human-oversight requirements (Article 14) apply to high-risk systems — the Annex III use cases, whose obligations apply from 2 December 2027. Most B2B SaaS is limited or minimal risk, and a limited-risk system's obligations are the Article 50 transparency duties (from 2 August 2026), full stop. Two consequences:
- Human oversight does not make a system limited risk. Classification follows the use case, not your controls.
- Human oversight does not exempt you from Article 50. If your feature triggers a transparency duty, a reviewer in the loop does not remove it. (The one narrow place where human review changes an Article 50 duty is the deployer-side text carve-out in 50(4) — for published text that has undergone human review with editorial responsibility — which is your customer's context, not a general vendor shield.)
The honest answer structure
Describe the real mechanism in three parts — where review happens, what triggers escalation, and how a human overrides — then position it correctly relative to the Act.
Illustrative template — placeholders in brackets, verify every clause against your own facts before submitting.
"[Your product] generates [outputs, e.g. draft responses / summaries] which are presented to users as drafts. Review: [e.g. every AI-generated output requires explicit user approval before it is applied; no output is auto-executed]. Thresholds and escalation: [e.g. outputs involving [category] are routed to [role] before release; below-threshold cases are sampled at [frequency]]. Override and correction: [e.g. users can edit, reject or regenerate any output; corrections are logged and retained for [period]]. Classification note: as a limited-risk system under Regulation (EU) 2024/1689, our obligations are the Article 50 transparency duties, not the Article 14 human-oversight requirements that apply to high-risk systems; the measures above are voluntary good practice that supports [buyer]'s own risk management."
That closing sentence does the heavy lifting: it shows the buyer exactly where you sit in the Act, claims the oversight as a real control, and does not attribute to the Regulation something it does not ask of you.
The mistake that costs deals
Using oversight as a talisman. The failing answer reads: "All outputs are human-reviewed, so the system is low-risk and the AI Act's requirements are addressed." Three defects, each discoverable. First, classification does not move: a reviewer does not turn an Annex III use case into limited risk, nor waive Article 50 duties. Second, writing that your measures "comply with" or "align with" the Act's oversight requirements implies your system is high-risk — the one classification you were trying to avoid — and invites a legal reviewer to test that implication. Third, overstated mechanics ("mandatory review" that is actually an optional button) collapse the moment the buyer runs a trial. Describe what exists; if it is thinner than you would like, state the gap with a plan — the formula is in the method guide, step 4.
Mini-FAQ
Does human oversight make our system limited risk under the EU AI Act?
No. Classification depends on the use case — the high-risk list is Annex III — not on the controls around it. Oversight neither downgrades a high-risk system nor removes Article 50 duties from a limited-risk one. Check the use case itself in the Annex III guide.
Should we cite Article 14 in our oversight answer?
Only if you are actually high-risk. For a limited-risk system, invoking Article 14 implies a classification you do not want. Frame your measures as voluntary good practice and let Article 50 carry your actual obligations.
What if our oversight is thinner than the buyer expects?
Say so, with the gap formula: current state + compensating control + in progress + a target date your leadership actually approved. Never describe optional review as mandatory.
Related: check which Article 50 duties your feature actually triggers with the free Article 50 checker, see the full role map in who owes what under Article 50, and if the questionnaire just landed, start with the first-24-hours playbook. Previous question in the series: the provider question.
- Regulation (EU) 2024/1689 — Art. 14, Art. 50, Annex III
- Digital Omnibus, adopted 16/29 June 2026 (Annex III high-risk obligations to 2 Dec 2027; Art. 50 unchanged)
- CSA AI-CAIQ (Oct 2025); Shared Assessments SIG 2026; EU MCC-AI clauses (Mar 2025)