Get started
AI governanceAI agentsHITLGovernance

Human in the loop only works if the approval is real

Adam Cowles2026-09-21T10:00:00.000Z4 min read
An AI agent action paused at a lit checkpoint where a human decision is recorded before it proceeds, cyan and amber over near-black

Human in the loop is not a person in the room. It is a person who saw what was about to happen, understood it, and can be pointed to afterwards. Take any of those away and the loop is decorative.

"Human in the loop" is the phrase everyone reaches for when someone asks whether their AI agents are safe. It sounds like control. Often it is not.

The test is simple. When a human approves an agent's action, did they actually see what they were approving, could they tell what it would touch, and can anyone later show what they knew when they clicked yes? If the honest answer is no, the loop is there on the org chart and absent in practice. A human approving things they cannot see is not oversight. It is a rubber stamp with a pulse.

What a rubber stamp looks like

It looks responsible, which is the problem. An approval queue fills with requests. A person works through them, clicking approve, because the work has to move and each item on its own looks fine. But the request says "run task 47", not what task 47 will actually do. It does not show what the action can reach if it goes wrong. And once approved, nothing binds the yes to that specific action, so what runs can quietly be broader than what was shown. Afterwards, when it matters, there is no record of what the approver was actually looking at.

That is not a human in the loop. It is a human next to the loop, providing cover.

What a real approval carries

Four things, and a loop that is missing any of them is weaker than it looks.

  1. The actual action, in terms a human can judge. Not "run task 47", but what it will do, to what, and why it is being asked now.
  2. Its blast radius, before the click. What this action can touch if it misbehaves: which systems, which credentials, which data. You cannot weigh a risk you cannot see. Quox computes this as an agent's governed reach, so the scope is on the card, not in someone's head.
  3. Identity on both sides. Which agent is asking, from an identity it cannot fake, and which human approved, recorded, not assumed.
  4. A witnessed record of the decision. Who approved what, when, and on what basis, in a form that cannot be rewritten later. "Who signed off on this" should be a lookup, not an argument.

What Quox does today, and what it is still building

Being precise, because this is exactly where vendors blur. Quox's human-in-the-loop approvals put risky actions in front of a person before they run, and the decision is witnessed: the approval is recorded with the agent identity that asked and the human who answered, holder and actor both, in a tamper-evident log. The blast radius of an agent is computable and can be shown alongside the request. That much is real and running.

The honest edge: binding the approval to the exact action, so that what executes can never be broader than what was shown, is the property we are hardening next, not one to claim as finished. It is the difference between "a human approved around this time" and "a human approved this, and only this, ran." We would rather name that gap than let "human in the loop" imply a guarantee we have not shipped.

None of this makes the human optional. A real approval is not about replacing judgement with a better form, it is about giving judgement something to work with: the action stated plainly, the reach shown, the identities pinned, the decision recorded. Do that and the person in the loop can actually be in it. Skip it and you have built a queue that manufactures consent and calls it governance.

So before you tell a customer or a regulator that your AI agents run with a human in the loop, ask what the human actually sees at the moment they approve. If it is a task name and a green button, the loop is theatre. If it is the action, its blast radius, the identity behind it, and a record that outlives the click, the loop is doing its job. That gap is most of the distance between governed AI agents and the appearance of them, and it is the part of agentic AI that decides whether anyone can trust what your agents did.