What Art. 14 specifically requires
Art. 14 AI Act obliges not only providers but, in practice, also deployers of high-risk AI systems: the system must be designed so that natural persons can effectively oversee it “during the period in which it is in use” (para. 1). According to para. 2, the aim is to prevent or minimise risks to health, safety or fundamental rights – including in cases of reasonably foreseeable misuse, not only when used as intended.
Para. 3 distinguishes two ways in which this oversight is ensured: measures already built into the system by the provider (point (a)), and measures the provider identifies but which the deployer implements operationally (point (b)). For deployers, this means: you cannot assume that “human oversight” is solely a matter for the manufacturer. Anyone deploying a high-risk system must actually underpin the oversight mechanisms envisaged by the provider with suitable people, processes and powers.
The five capabilities oversight personnel need
Para. 4 spells out what “effective oversight” means in terms of the people involved. Those assigned to carry out oversight must be able, to an appropriate degree and in proportion to the circumstances, to:
- understand the system’s capacities and limitations and monitor its operation, including detecting anomalies and malfunctions (point (a)),
- remain aware of the risk of automation bias, i.e. the tendency to rely automatically on AI output without critical reflection (point (b)),
- correctly interpret the output, for instance by using available interpretation tools (point (c)),
- decide, in any particular situation, not to use the system or to disregard, override or reverse its output (point (d)),
- intervene in the operation or interrupt it safely via a “stop” button or similar procedure (point (e)).
In practice, this means: it is not enough to give someone an approval button. You need defined roles with genuine subject-matter competence, documented training on system limitations and automation bias, and a way of stopping or reversing a decision that works both technically and organisationally. A typical gap: the stop function exists technically, but nobody is authorised or trained to use it in an emergency – or the person simply has no time to review an AI output before it takes effect.
Special case: biometric identification
For high-risk AI systems under Annex III point 1(a) – i.e. biometric identification systems – para. 5 significantly tightens the requirement: the deployer must not take any action or decision based solely on the identification result produced by the system. A separate verification and confirmation by at least two natural persons with the necessary competence, training and authority is required.
An exception applies to systems used in the fields of law enforcement, migration, border control or asylum, where the two-person check would be disproportionate under Union or national law. For all other use cases, the four-eyes principle is not a recommendation here but an obligation – with corresponding consequences for staffing plans and process design.
Common gaps in practice
Recurring patterns emerge in implementation: oversight personnel are appointed but not trained in the specific system limitations (a breach of para. 4 point (a)). Processes are timed so tightly that there is effectively no time for a genuine substantive review of the AI output – oversight becomes a mere formality, contradicting the purpose set out in para. 2. Stop mechanisms exist but are not embedded in emergency procedures or escalation paths. And for biometric systems, the separate two-person check required under para. 5 is not reflected organisationally, because it is seen as a nuisance in day-to-day operations.
Anyone taking these obligations seriously should document, for each high-risk system concerned: who exercises oversight, with what qualifications, with what powers to intervene, and how understanding of system limitations and automation bias is kept up to date on an ongoing basis. This is not a one-off exercise but must be reassessed with every relevant system change.
Our free risk check at /einstufung will help you clarify in a few minutes whether, and to what extent, your company operates high-risk AI systems and which obligations under Art. 14 specifically apply.