Insights · September 2026 · AI & Legal Tech

Human in the loop: what it means, and what the law actually requires

Mid-century abstract illustration: human oversight of automated decisions
Human in the loop means a person is positioned to change the outcome before it takes effect — not merely present, not merely notified afterwards. Canada has no general AI statute, so the obligation comes from four places: the federal Directive on Automated Decision-Making for government systems, section 12.1 of Quebec's private-sector privacy Act for automated decisions about people, section 8.4 of Ontario's Employment Standards Act, 2000 for AI in hiring, and the ordinary law of contract and negligence for everyone else. None of them asks whether a human was in the loop. They ask whether a human was accountable and able to act.

It arrives in customer procurement questionnaires, in insurers' renewal forms, and in the AI policies businesses are now expected to have on file. Everywhere it appears it is offered as a reassurance — a box that, once ticked, closes the subject.

It does not close the subject. Putting a human in the loop can increase your exposure rather than reduce it. A person who signs off on output they had no realistic capacity to check has not added a safeguard. They have added a name to the file.

Where the phrase came from, and its three settings

It is borrowed from control-systems engineering and, later, from military doctrine on autonomous weapons, where the taxonomy matters a great deal and is stated precisely. The distinction is not whether a human exists. It is when the human acts.

SettingWhat the human doesHow it fails
In the loopThe system proposes; the human decides. Nothing takes effect until a person acts.Volume. The human becomes a bottleneck, then a formality.
On the loopThe system decides and acts; the human supervises and can intervene.Attention. Nobody watches a system that is right 98% of the time.
Out of the loopThe system decides and acts; the human reviews afterwards, if at all.Everything already happened.

Most organisations that describe themselves as having a human in the loop are on the loop, and a fair number are out of it. Three prepositions, three different systems, three different failure modes. Most AI policies pick the wrong one.

What does Canadian law require?

Start with what does not exist. There is no general Canadian AI statute. The Artificial Intelligence and Data Act died with Bill C-27 when Parliament prorogued, and the federal government's "AI for All" national strategy, launched 4 June 2026, is a strategy rather than a law. Anyone telling you that Canada's AI Act requires human oversight is describing a bill that never passed.

Four things do bite.

1. The federal Directive on Automated Decision-Making

This binds federal departments, and it matters to private businesses because it flows down through procurement — if you sell an automated system to the Government of Canada, you are building to it. It is also the only Canadian instrument that says plainly what the loop must contain.

Appendix C sets requirements by impact level. At Levels I and II, the Directive says the system "may make decisions and assessments without direct human involvement." At Levels III and IV it says something quite different:

"The final decision must be made by a human. Decisions cannot be made without having clearly defined human involvement during the decision-making process. Humans review the decisions or recommendations made by the system for accuracy and appropriateness."

Read the second sentence twice. Not "a human is involved" — clearly defined human involvement. Systems in place before 24 June 2025 had until 24 June 2026 to meet the updated requirements. That deadline has passed.

2. Quebec section 12.1 — the closest thing to a private-sector right

If you make decisions about people in Quebec, this applies to you whether or not you have an office there. Section 12.1 of the Act respecting the protection of personal information in the private sector requires any enterprise using personal information to render a decision "based exclusively on an automated processing" to tell the person, and on request to explain the information, reasons and principal factors used.

Then the sentence that actually builds the loop:

"The person concerned must be given the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision."

Not a person. A person in a position to review the decision. Quebec's legislature anticipated the customer-service employee who can only apologise, and drafted around them. It is the best short definition of a real loop in Canadian law, and it appears in a privacy statute rather than an AI one.

Note the trigger, though: decisions based exclusively on automated processing. Insert a genuine human decision and s. 12.1 does not apply — which is a reason to build the loop properly rather than a loophole, because a nominal review will not survive the question of who actually decided.

3. Ontario: disclosure, not oversight

Since 1 January 2026, section 8.4(1) of the Employment Standards Act, 2000 requires an employer who uses artificial intelligence "to screen, assess or select applicants" to say so in the job posting. O. Reg. 476/24 exempts employers with fewer than 25 employees and defines artificial intelligence broadly — "a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions."

That definition catches the résumé-ranking feature in your applicant tracking system, whether or not anyone at your company chose to switch it on. And notice what Ontario asks for: Ontario requires you to disclose that a machine is in the loop. It does not require a human to be.

4. Everything else: contract, negligence, and Air Canada's chatbot

For most businesses this is the live one. In Moffatt v. Air Canada, 2024 BCCRT 149, a passenger relied on the airline's chatbot about bereavement fares. The chatbot was wrong. Air Canada argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal member's answer: "It should be obvious to Air Canada that it is responsible for all the information on its website."

The award was roughly $650. An airline took that argument to a tribunal over $650, and the reason the case is now cited everywhere is that it needed deciding at all.

Why "there was a human in the loop" is not a defence

Two problems, and they compound.

The first is automation bias — the tendency to accept what the machine produced because the machine produced it. The EU AI Act writes it into the statute: Article 14(4)(b) requires that the people assigned to oversee a high-risk system be enabled to "remain aware of the possible tendency of automatically relying or over-relying on the output." The most developed AI law in the world tells the humans in the loop to watch out for being in the loop.

The second is what the researcher Madeleine Clare Elish named the "moral crumple zone": responsibility for a failure lands on the human who had least control over it. Put a junior employee in the loop over a system they cannot interrogate, and you have not distributed the risk. You have concentrated it on the person least able to bear it — and, if the loop is described in your customer terms or your insurance application, you have made a representation about a control that does not function.

What a real loop looks like: five conditions

These are drawn from the Directive and Article 14, translated into things you can actually check.

That last point is the one I would push hardest. An override rate of zero does not mean the system is perfect. It means nobody is reviewing.

What to put in your contracts

With your AI vendor. Say who the decision-maker is. Get audit rights and log retention long enough to be useful — a 30-day log is worthless when a claim surfaces at month five. Establish what happens when the system is confidently wrong, and read the vendor's limitation of liability against what a failure would actually cost you; these clauses are not automatically enforceable in Canada, but you should not be relying on that.

With your customer. Do not promise a review you cannot staff. "All output is reviewed by our team" is a contractual term the moment it appears in your terms of service, and it is a representation before that. If your process is supervision rather than review, say supervision.

In your internal policy. Name the systems, name the reviewers, and set the override log. A two-page policy that does those three things is worth more than a twenty-page one that recites principles.

The question underneath all of this

When somebody asks whether you have a human in the loop, they are not really asking about your process. They are asking who they can hold responsible, and whether that person could have stopped it.

The same test applies when you are the one buying the review. If you drafted something with AI and want a lawyer to check it, what you are paying for is a reviewer with the time, the information and the authority to say no — how to hire a lawyer to review a contract you drafted with AI sets out how to ask for exactly that.

A loop with nobody able to open it is not a loop. It is a signature.

Common questions

What does “human in the loop” mean?

It means a person is positioned to change an outcome before it takes effect, rather than being merely present or notified afterwards. The term is borrowed from control-systems engineering, where it is distinguished from “on the loop” (the system acts, a human supervises and can intervene) and “out of the loop” (the system acts, a human reviews afterwards, if at all).

Does Canadian law require a human in the loop?

There is no general Canadian AI statute; the Artificial Intelligence and Data Act died with Bill C-27. Human involvement is required in specific places: the federal Directive on Automated Decision-Making requires that the final decision be made by a human for Level III and IV systems, and Quebec’s s. 12.1 requires that a person subject to an exclusively automated decision be able to submit observations to an employee in a position to review it.

What is the difference between human in the loop and human on the loop?

Timing and authority. In the loop, nothing takes effect until a person acts. On the loop, the system acts and a person supervises with power to intervene. Most organisations that describe themselves as in the loop are on it, which matters because the two fail in different ways — in-the-loop fails on volume, on-the-loop fails on attention.

Does Ontario require employers to keep a human in the loop when hiring?

No. Since 1 January 2026, s. 8.4(1) of the Employment Standards Act, 2000 requires an employer who uses AI to screen, assess or select applicants to disclose that in the job posting. O. Reg. 476/24 exempts employers with fewer than 25 employees. The requirement is disclosure, not oversight.

Can a company blame its AI system for a mistake?

No. In Moffatt v. Air Canada, 2024 BCCRT 149, the airline argued its chatbot was a separate legal entity responsible for its own statements. The tribunal rejected that, holding that Air Canada is responsible for the information on its own website. The company that deploys the system answers for its output.

Can having a human in the loop make things worse?

It can. A reviewer who lacks the time, information or authority to disagree adds a name to the file without adding a control — what the researcher Madeleine Clare Elish called a “moral crumple zone,” where responsibility lands on the person with least control. If the loop is also described in customer terms or an insurance application, a nominal review becomes a representation that may be wrong.

What should an AI policy actually say?

Name the systems in use, name the people responsible for reviewing each one, and require that overrides be logged. Those three things are checkable. A policy that recites principles without naming a reviewer cannot be tested, and cannot be evidence that a control existed.

How do I prove there was a human in the loop?

Through override records. If a human has authority to change outcomes, some outcomes get changed, and the log shows it. An override rate of zero over a long period does not demonstrate an accurate system; it suggests nobody is reviewing, and it is the first thing an opposing party will ask for.

KS
Written by Koby Smutylo

Koby is a business lawyer and the principal of Smutylo Law+ in Ottawa. Called to the Bar of Ontario in 2001, he has over two decades of experience in corporate, commercial, securities, and technology law, acting for business owners across Canada and for U.S. companies operating in Canada. He is also a trained mediator. More about Koby →

Legal information, not legal advice. For advice on your own situation, book a free 20-minute call.
Let's Talk

Questions about your own sale?

Twenty minutes, no charge — a straight read on where you stand.

Book a 20-Minute Call
Free & no obligation·20 minutes·Fees quoted up front
British Columbia
California
By Appointment
Ottawa, Ontario
Remote & in-person available