Bassam Alotaibi
AI Governance8 min read

Beyond Human-in-the-Loop: Governing Agentic AI at Operational Speed

Human-in-the-loop was designed for systems that recommend. Agentic systems act. Governance now has to work at the speed of the machine while keeping authority firmly with people.

Bassam Alotaibi

Bassam Alotaibi

AI Governance & Cybersecurity Researcher

For most of the past decade, 'human-in-the-loop' has been the reassuring phrase at the centre of responsible AI. Put a person between the model and the consequence, the argument goes, and accountability is preserved. It was a reasonable answer for systems that classify, score, and recommend — systems whose output waits patiently for a human to act on it.

Agentic systems do not wait. They plan, call tools, execute multi-step workflows, and adapt to feedback in seconds. When an AI agent can triage an alert, isolate a host, open a ticket, and notify a regulator's reporting channel before an analyst has finished reading the first line, the loop we imagined the human sitting inside has already closed without them.

The quiet failure of the loop

The failure mode is rarely dramatic. It looks like approval fatigue: a queue of machine-generated actions, each individually plausible, approved in bulk because the volume makes genuine review impossible. The human is still formally in the loop. Substantively, they have become a rubber stamp with a login.

This is not a technology problem; it is a governance design problem. We placed the human at the wrong point in the process — at the moment of execution, where speed pressure is highest and context is thinnest — instead of at the moments where human judgement genuinely changes outcomes.

A human who approves everything is not oversight. They are latency.

Decision speed is a governance variable

Boards and risk committees are used to governing decision quality. Agentic AI forces them to govern decision speed as well. Every autonomous capability carries an implicit question: how fast are we willing to let this class of decision happen without a person?

Treating speed as a governed variable changes the design conversation. Instead of asking 'should a human approve this?', we ask 'what is the maximum blast radius we will accept at machine speed, and where must the system slow down to human speed?' The answer differs by decision class: blocking a suspicious IP address is not the same as freezing a customer account, and neither is the same as communicating externally on the organisation's behalf.

From approval to authority

The durable role for people is not approving individual actions but holding authority over the envelope within which the system may act: the objectives it optimises, the actions it is permitted, the thresholds at which it must stop and escalate, and the evidence it must leave behind.

This is governance-by-design in its practical form. Escalation thresholds are written down before deployment, not negotiated during an incident. Authority boundaries are encoded as controls the agent cannot cross, not as policy statements it is trusted to remember. And every autonomous action produces an audit record rich enough that a human can reconstruct, after the fact, what the system believed, what it did, and why.

Accountability cannot be automated. What can be engineered is the evidence that makes accountability possible.

Continuous oversight, not ceremonial review

If humans are no longer approving each action, oversight must become continuous rather than transactional. That means monitoring the agent's behaviour in aggregate — drift in the kinds of actions it takes, changes in escalation frequency, near-misses at authority boundaries — the way a control function monitors a trading desk rather than the way a clerk countersigns a form.

It also means rehearsal. Organisations run incident response exercises for cyber attacks; very few run exercises for their own automation misbehaving. An agent pursuing a subtly wrong objective at machine speed is an incident category of its own, and it deserves the same muscle memory.

What this asks of leadership

None of this removes people from the picture. It relocates them: from the loop to the perimeter, from approving actions to owning outcomes. That relocation must be explicit. Someone accountable signs off the action envelope. Someone accountable owns the escalation thresholds. Someone accountable reviews the audit trail — and has the standing to switch the system off.

Human-in-the-loop was never really about the loop. It was about ensuring a person remains answerable for what the system does. Agentic AI does not change that principle. It simply forces us to build it properly. [1]

← Back to all writing