Does EU AI Act require Human Oversight?
European Union • phased enforcement
Yes — 1 provision
Requirements at a glance
This regulation imposes 10 specific requirements for Human Oversight across 1 provision:
- Effective oversight — High-risk AI must enable oversight by natural persons (Article 14(1))
- Proportionate enablement — Oversight measures must be commensurate with the risks, autonomy, and context of use; the system must be provided so assigned natural persons are enabled, as appropriate and proportionate, to perform the Article 14(4)(a)-(e) functions below (Article 14(3)-(4))
- Understand capabilities — Enable assigned persons to properly understand relevant system capacities and limitations (Article 14(4)(a))
- Monitor for anomalies — Enable assigned persons to duly monitor operation, including detecting and addressing unexpected performance, anomalies, and dysfunctions (Article 14(4)(a))
- Address automation bias — Enable assigned persons to remain aware of automation-bias risk in oversight (Article 14(4)(b))
- Interpret output — Enable assigned persons to correctly interpret output, taking account of available interpretation tools and methods (Article 14(4)(c))
- Override/reverse — Enable assigned persons to decide not to use the system or to disregard, override, or reverse its output (Article 14(4)(d))
- Intervene or halt — Enable assigned persons to intervene or interrupt system operation via a stop button or similar procedure that allows a halt in a safe state (Article 14(4)(e))
- Competent personnel — Deployers must assign persons with necessary competence, training, authority, and support (Article 26(2))
- Dual verification (biometric) — For Annex III point 1(a) systems (remote biometric ID), oversight measures must ensure that the deployer takes no action or decision on the basis of the resulting identification unless that identification is separately verified and confirmed by at least two natural persons with necessary competence, training, and authority. The two-person verification requirement does not apply to systems used for law enforcement, migration, border control, or asylum where Union or national law considers that requirement disproportionate (Article 14(5))
Human Oversight (Article 14)
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.
Requirements
| Requirement | Details |
|---|---|
| Effective oversight | High-risk AI must enable oversight by natural persons (Article 14(1)) |
| Proportionate enablement | Oversight measures must be commensurate with the risks, autonomy, and context of use; the system must be provided so assigned natural persons are enabled, as appropriate and proportionate, to perform the Article 14(4)(a)-(e) functions below (Article 14(3)-(4)) |
| Understand capabilities | Enable assigned persons to properly understand relevant system capacities and limitations (Article 14(4)(a)) |
| Monitor for anomalies | Enable assigned persons to duly monitor operation, including detecting and addressing unexpected performance, anomalies, and dysfunctions (Article 14(4)(a)) |
| Address automation bias | Enable assigned persons to remain aware of automation-bias risk in oversight (Article 14(4)(b)) |
| Interpret output | Enable assigned persons to correctly interpret output, taking account of available interpretation tools and methods (Article 14(4)(c)) |
| Override/reverse | Enable assigned persons to decide not to use the system or to disregard, override, or reverse its output (Article 14(4)(d)) |
| Intervene or halt | Enable assigned persons to intervene or interrupt system operation via a stop button or similar procedure that allows a halt in a safe state (Article 14(4)(e)) |
| Competent personnel | Deployers must assign persons with necessary competence, training, authority, and support (Article 26(2)) |
| Dual verification (biometric) | For Annex III point 1(a) systems (remote biometric ID), oversight measures must ensure that the deployer takes no action or decision on the basis of the resulting identification unless that identification is separately verified and confirmed by at least two natural persons with necessary competence, training, and authority. The two-person verification requirement does not apply to systems used for law enforcement, migration, border control, or asylum where Union or national law considers that requirement disproportionate (Article 14(5)) |
Penalties
| Violation | Fine |
|---|---|
| Provider non-compliance through Article 16(a), or deployer non-compliance with Article 26 | Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date. |