- Should humans always make the final decision?
- Who has the authority to override an AI system?
- What happens when nobody wants to be the person who overrides it?
- Can a human meaningfully challenge a system they cannot inspect?
Whoever was assigned the authority before deployment. If nobody was, the answer is nobody, whatever the policy document says.
This is the question most oversight arrangements leave unanswered while appearing to answer it. A named reviewer exists, a sign-off step exists, and the power to actually stop the thing has never been given to a person who could use it.
What the regulation requires
The EU AI Act is worth reading here rather than reading about, because the summaries drop the paragraph that matters. Graded entry.
Article 14 requires that a person given oversight of a high-risk system be enabled to understand its capacities and limitations, to interpret its output correctly, to decide not to use it or to disregard, override or reverse its output, and to intervene or interrupt it through a stop button that brings the system to a safe halt.
It also requires that they remain aware of the possible tendency to over-rely on the output, and it names automation bias in the legislative text. A regulator writing a known human-factors failure mode into a binding requirement is unusual and worth noticing.
Then paragraph 5, on biometric identification, which is the only place the Act says who: no action may be taken on an identification unless it has been separately verified by at least two natural persons with the necessary competence, training and authority.
Those three words are the whole test, and they are usually separated in practice. Competence without authority produces someone who can tell the system is wrong and cannot stop it. Authority without competence produces a signature.
Two limits belong with that. These provisions do not apply until December 2027 at the earliest. And the two-person rule covers one narrow category rather than high-risk systems generally.
Why a universal human veto is not a safety principle
"A human makes the final decision" is the most common answer to this question and it does not survive contact with the evidence.
The relevant questions are which party performs better on the specific case, how serious and how reversible the error would be, whether the human can detect a machine error at all, and who remains accountable afterwards. None of those is answered by inserting a person at the end.
Where the human cannot detect the error, the veto is decorative and adds delay. This estate handles the measured version at how humans and AI make decisions together, where the common configuration underperforms whichever party was stronger alone, and at human in the loop is not a safeguard.
Which leaves a position that suits neither camp. Some systems warrant no routine human intervention. Others warrant a great deal. The universal rule is the thing that fails.
Challenging a system you cannot inspect
A narrower version of the question, and the answer is narrower than people would like.
Someone experienced can often tell that an output is wrong without being able to say why the system produced it. That is a real form of challenge and it operates entirely on the output. It works where the answer is implausible, and it fails precisely where the answer is plausible and wrong, which is the case that matters.
It also degrades. The ability to sense that something is off comes from having done the work, and it declines with the practice that produced it. The decay rates are here. Which means the challenge capability of an oversight function falls over time unless something is done to maintain it, and nothing usually is.
The asymmetry that decides it in practice
Even where the authority exists and the competence exists, the override can quietly stop happening, and the reason is structural rather than personal.
Overriding is a costly act. Deferring is free. An override is visible, attributable to a named person, and reviewed if it turns out to have been wrong. Going along with the system is none of those things: if that turns out wrong, the system was wrong.
Nobody has to decide to stop overriding for overrides to disappear. The asymmetry does it. And an organisation that wants a real override function has to make deferring as accountable as overriding, which means recording the decision to accept as a decision rather than as the absence of one.
Weick and Sutcliffe's principle of deference to expertise rather than to rank is the organisational counterpart. Managing the Unexpected. Authority that sits with seniority rather than with the person who can see the problem is authority in the wrong place.
What this page does not establish
The Act is a legal requirement, not evidence. It contains no demonstration that oversight constituted this way works, and its provisions are not yet in force.
The asymmetry argument is reasoning from how accountability normally operates rather than a measured finding about AI systems specifically. It is consistent with the automation-bias literature and it has not been tested in this setting.
And there is a cost the other way. Making acceptance as accountable as override adds friction to every routine case in order to catch rare ones, which is a trade rather than an improvement, and where the balance sits depends on how often the system is wrong and how much it matters when it is.
Key sources
- European Union (2024). Regulation (EU) 2024/1689, Article 14: Human Oversight. Graded entry.
- Skitka, L. J., Mosier, K. L. and Burdick, M. (1999). Does automation bias decision-making? Graded entry.
- Parasuraman, R. and Manzey, D. H. (2010). Complacency and Bias in Human Use of Automation. Graded entry.
- Weick, K. E. and Sutcliffe, K. M. (2001). Managing the Unexpected. Jossey-Bass. In the essential works.
Related SuperSkills research
On oversight that does not work, human in the loop is not a safeguard and meaningful human oversight. On when to do it, when should I override AI and how do I know when AI is wrong. On what the role costs, the invisible work of oversight. On withdrawing the system altogether, deployment is not a ratchet. On whether the reasons help, does explaining an AI's reasoning help.
About this research
Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. Article 14 is quoted from the consolidated regulation rather than from a summary, because the summaries omit paragraph 5.
Cite this
Hirji, R. (2026). Who can override an AI system? The SuperSkills Intelligence Company. Last reviewed 30 August 2026. thesuperskills.com/research/who-can-override-an-ai-system
