Bob Michaels/ai
Episode 05July 30, 20267:26Built with AI

Who Signs Off When the AI Acts?

Human in the loop means a person is present. Human in control means a person can inspect the evidence, stop the action, and own the decision. Bob Michaels walks through the approval map to draw before you automate anything, and the seven actions an AI agent should never take without a named human owner.

Written up in full

Transcript

An AI agent at a company you do business with just did something on its own. Sent a message, changed a permission, committed money.

Now the simple question. If it was wrong, who is responsible?

If the answer takes longer than five seconds, that company has a problem. And most companies, right now, cannot answer it at all.

Hi! I am Bob Michaels, and this is Evolving the Web. Every two weeks I talk through the essays I just published, plainly, as one story. This episode covers two essays that belong together so tightly I wrote them as a pair. They are about the least glamorous and most important question in all of AI. Who is in charge?

Start with a phrase you have heard a hundred times. Human in the loop. It is supposed to be reassuring. Do not worry, there is a human in the loop.

Here is what it usually means in practice. A person is present. A person is somewhere nearby while the machine works. Like a lifeguard who cannot swim, technically on duty.

The first essay draws the line I care about. Human in the loop means a person is present. Human in control means three specific things. The person can inspect the evidence behind the action. The person can stop the action before it lands. And the person owns the decision, by name, afterward.

Present is a body. Control is a power. The difference between them is the whole subject.

And this is no longer just my opinion about good practice. In Europe, rules now coming into force for high risk AI systems require exactly this. Overseers who can understand the system, override it, and stop it. Not watch it. Stop it.

So how do you actually build control without strangling the thing you automated? You draw a map before you build the workflow. I mean that literally. The approval map comes first, the automation second.

Here is how you draw it, and the first cut is beautifully simple. Every action the system can take is either reversible or consequential.

Reversible actions, let them run. A draft, an internal note, a report. If it is wrong, you fix it, no harm done. Automate freely, review afterward, enjoy the speed. That is the whole point of having the machine.

Consequential actions are the ones you cannot easily take back. Anything the public sees. Money leaving the building. Someone's access changing. Data being destroyed. Those get a gate, and every gate gets a name. A specific human who owns that class of decision.

And the person at the gate has to see something real before deciding. Not a red dot that says approve. An evidence packet. What is about to happen, why the system thinks it should, what it is based on. Because an approver who cannot see the evidence is not deciding anything. They are just a rubber stamp with a pulse, and a rubber stamp is human in the loop all over again.

One more piece, and it is the piece everyone forgets. Approvals expire. That standing permission you granted in March should not still be quietly running in November. Expiry is what keeps an approval from rotting into a permanent permission nobody remembers granting.

The second essay gets concrete, because sooner or later somebody asks, fine, but which actions exactly? So I wrote the list. Seven classes of action an AI agent should never take without a named owner, no matter how automated the execution gets.

Talking to the outside world, messages to customers or anyone beyond your walls. Publishing anything the public can see. Committing money, at any amount. Changing who has access to what. Destroying data. Pushing changes into live systems. And making promises, anything that sounds like a commitment or a legal position.

Notice what they have in common. Every one is hard to take back, and every one has a blast radius beyond the person who set the agent running.

Now, the objection I hear immediately. If a human signs off on all that, what did I automate? Fair, and the answer is that named ownership does not mean approving every instance one at a time. It means bounded pre approval. The owner sets the bounds. Refunds under this amount, yes, from these templates, to these recipients. Inside the bounds, the agent runs at machine speed. Outside the bounds, it stops and asks. The log shows who set the bounds and when.

That is still ownership. The owner decided, the decision is on the record, and there is a name to call when it goes wrong. What it never becomes is the failure mode I see everywhere, which is permissions granted by whatever the connection screen offered, so that nobody decided anything and the agent can do whatever the integration happens to allow.

And two safety features come standard on every red line. An emergency stop that actually stops it, tested, not assumed. And an expiry date on the authority itself.

Here is the pattern hiding under both essays, and it might be the most counterintuitive thing I believe about this subject.

The companies with the clearest red lines automate the most, not the least. Because when everyone knows exactly which actions are gated, nobody has to fear the other ninety percent. The reversible work runs at full machine speed, and the consequential work has a name on it.

The map is not the brake. The map is what lets you take your hands off the wheel everywhere it is safe to.

Bounded autonomy is fast. Unbounded autonomy is just liability with good marketing.

Both essays are on the blog at bobmichaels dot ai, including the full seven action list you can hand to your team, linked from the episode page.

Drawing this map for a company, deciding what runs free and what gets a gate and who owns it, that is the work I do, as a consultant or fractionally, a slice of my week for as long as you need it.

Thanks for listening. Here is your homework, and it takes one minute. Pick the one AI tool your company already uses, and ask out loud, if this thing acts and it is wrong, who owns that? If the room goes quiet, you know where to start.

← All episodesJuly 30, 2026 · 7:26