Many organizations are fooling themselves when they implement human-in-the-loop AI safeguards, delivering instead a human watching the loop with minimal power to halt results or change decisions, according to IT security experts speaking at the recent CIO 100 Awards and Conference in Frisco, Texas. The warnings, shared in a CIO.com article published this week, highlight how supposed oversight mechanisms often function as rubber stamps rather than genuine controls. Experts caution that these systems frequently deny employees both the control and the time needed to address problems.

For human-in-the-loop frameworks to genuinely function, workers monitoring AI applications must possess the domain expertise and background to handle the task the AI addresses when automation isn't involved, and they must hold the power to overturn the AI's choice, according to Doug Shepherd, head of offensive security at Cloudflare. "If your human in the loop can flag something but can't actually stop it, that's not human in the loop, that's a human adjacent to the loop," Shepherd said. "That's performative governance." Darren Kimura, CEO of AI integration platform vendor AISquared, echoed the concern: "Most companies that say they have a human in the loop actually have a human watching the loop." The person can observe the choice and mark a worry, but they can't halt it, alter it, refuse it, or push it up the chain.

Another critical weakness emerges when workers face decision fatigue after reviewing excessive AI choices, ultimately button mashing rather than considering consequences, experts note. Even qualified and authorized reviewers may slowly abandon independent thinking when the AI proves consistently accurate, according to Eric Billingsley, COO and CTO of AI assurance company TrustScale. When systems achieve 95% accuracy, the reviewer's role becomes waiting for the uncommon instance of error. "Humans are not particularly good at sustained vigilance of a highly reliable automated system," Billingsley explained. "Eventually, review becomes confirmation." Robert Blumofe, EVP and CTO at Akamai, observed that large language models deliver correct output frequently enough to lull people into false confidence about their reliability. Following repeated checks that find no mistakes, diligence fades and human-in-the-loop transforms into automatic approval.

The underlying issue stems from organizations treating human-in-the-loop as political cover rather than tested risk management, according to Shepherd, who emphasized that nobody stress tests these controls even though many companies reach for them as vital safeguards. IT leaders should ask whether reviewers can stop actions before they take effect, whether they can modify the output, and whether their overrides are recorded and enforced downstream—if any answer is no, the human is merely monitoring AI, Kimura said. Billingsley recommends evaluating human-in-the-loop systems the same way organizations monitor other security controls, requiring evidence that the person possessed necessary context, applied independent judgment, and held authority to override the AI. A log showing someone clicked "approve" isn't sufficient.

Looking ahead, experts suggest organizations should explore deploying non-AI technologies as guardrails instead of relying on unreliable human monitoring. These tools would automate testing and validation of AI results, flag issues, and possess the capability to pause AI work, keeping humans out of approval loops while reducing risk, Blumofe recommended. For certain use cases like cybersecurity incident response, human-in-the-loop systems may not fit at all—when an endpoint is compromised, isolation should happen immediately rather than waiting 20 or 30 minutes for someone to approve the action, which could let attacks spread, Kimura noted. The goal isn't inserting a human into every AI decision but rather placing the right human, with appropriate context and authority, at the right point in the workflow. Leaders who fail to push AI initiatives will fall behind, but blind adoption without meaningful outcomes and genuine guardrails can trigger major setbacks. The challenge for IT executives is distinguishing between oversight systems that actually work and those designed merely to get projects approved.