
The Human in the Loop Owns Nothing
The most common fix for the accountability gap is the one most likely to hide it.
When you point out that an automated decision had no human owner, the answer comes quickly, and it is almost always the same. There is a human in the loop. A person reviews the output. A person signs off. The decision was not made by the machine alone.
It is a reassuring answer, and it is the one regulators have reached for too. Human oversight is the standard the newest rules on automated decision-making are built around, from New York City's hiring-audit rule to the high-risk AI regimes taking effect this year. The institution's instinct and the regulator's instinct are the same: put a person beside the machine, and accountability follows.
It usually does not. The human in the loop is the most common response to the accountability gap, and it is the one most likely to hide it. The failure is worth understanding, because it is structural. It is not a matter of lazy reviewers or bad employers.
In an earlier piece I argued that the accountability gap is symmetric. The same mechanism that leaves an automated decision unowned inside an organization leaves it unowned for the candidate outside it, and the disciplines that would close it (disclosure, contestability, auditability, named ownership) extend across both sides. The human in the loop is how organizations try to satisfy the last of those, named ownership, in practice. This piece is about why the naive version of that fix does not work, and what would.
The loop is supposed to be the place where judgment re-enters. The system narrows, ranks, and recommends. The human looks, weighs, decides, and owns the outcome. On the org chart, that is exactly what happens. In the minute the decision is actually made, three things usually break it.
Visibility. The human only sees what the system surfaced. In hiring, the reviewer opens a ranked shortlist. The applications the system scored low are not in front of them. The people the decision most affected, the ones filtered out, never reach the loop at all. The human is overseeing the survivors.
The rejection that needed a human was completed before the human arrived.
Attention. Even inside what is surfaced, the order the machine assigns directs where the human looks. The top of the list gets read. The bottom gets a glance. The reviewer believes they are exercising judgment when they are mostly ratifying a sort. This has a name in the human-factors literature. Automation bias is the documented tendency to over-rely on a system's output, and it is strongest exactly where the loop is supposed to help: under time pressure, at volume, when the machine sounds confident. The most developed AI regulation yet written names automation bias directly, as a risk the human overseer must be built to resist. The law that promises oversight concedes, in its own text, that the loop can be hollow.
Volume. A person assigned to review thousands of applications, or to approve a running queue of agent actions, cannot exercise independent judgment at that rate. The oversight that exists in the policy does not exist in the second the decision passes. Speed was the reason to automate in the first place. A human who genuinely slowed down to weigh each output would defeat the purpose, so the loop is designed, implicitly, so the human does not.
Put these together, and the human in the loop stops being a source of judgment and becomes something else. The cultural anthropologist Madeleine Clare Elish gave it a name while studying automated systems in aviation, nuclear power, and driverless cars. She called the nearest human a moral crumple zone.
the moral crumple zone protects the integrity of the technological system
Her point was that when a largely automated system fails, the human positioned beside it absorbs the blame, the way a car's crumple zone absorbs a crash, while the system's design escapes scrutiny. The human had limited real control and full nominal responsibility.
The hiring loop runs the same trade, in advance. The human's presence does not add judgment to the decision. It adds a name to it. An automated rejection that no one owned becomes, on paper, a decision a person made. The institution can now point to a responsible human. The vendor can point to the institution. The candidate, told that a person reviewed their application, has even less to contest than before, because the decision now wears the appearance of a human judgment it never received. This is worse than no human in the loop, because it manufactures the exact accountability that was missing without supplying any of it. Call it accountability laundering: the loop converts an unowned machine decision into a nominally owned human one and changes nothing about what actually decided.
This is not a hiring problem. It is the central design problem of every system that puts an agent in front of a person. The question that decides whether oversight is real is not whether there is a human in the loop. It is what the human in the loop can actually do.
A human is only oversight if three things are true. They can see what the system excluded, not only what it surfaced. They have time proportionate to the stakes of the decision, rather than a queue that guarantees a glance. And they hold real authority to override, exercised often enough that overriding is a live option and not a theoretical one. A loop missing any of these is a loop where the human's decision was foreordained the moment they were handed a recommendation, a default, and a clock.
This is the same boundary question that decides whether any agentic deployment can be trusted: what the system is allowed to do on its own, and what it must bring back to a human who can genuinely act on it. Drawing that boundary so the human can really act is the hard and expensive part. Putting a human nominally in the loop is the cheap part, and it is the part most deployments stop at.
Regulation will not settle this, and American readers should not file it as Europe's problem. The most concrete human-oversight requirement on the books, the EU AI Act's, takes effect for high-risk systems this August, and it reaches the Americas sideways: the vendors selling screening tools to US employers increasingly build to that standard, while US law (New York City's audit rule, and the state bills following it) moves the same direction on a slower clock. The requirement is that oversight be effective. It leaves most of what effective means undefined, and it does not require a human to review every decision before it takes effect. After it lands, high-risk deployments will document an oversight function. Whether that produces oversight, or only documentation, is a different question the documentation is not designed to answer.
So the extension to the earlier argument is this. Naming a human owner is necessary, and it is not enough. A name attached to a decision the human did not actually make is not ownership. It is a liability shield wearing ownership's clothes. Real accountability requires that the loop be built so the human can own the decision: see what was excluded, have the time to judge it, hold the authority to reverse it, and leave a record that shows judgment was exercised rather than merely logged.
Until then, the reassurance keeps its shape and means nothing.
The human is in the loop. The decision still belongs to no one.
