The FSB's Consultation on AI Governance: Human Oversight Takes More Than One Form
In practice, "human oversight" bundles together several different jobs. The FSB's consultation report separates them by when they operate.
This article is based on publicly available information and is provided for informational purposes only. It does not constitute investment, legal, regulatory, or risk management advice. The FSB document discussed here is a consultation report published on June 10, 2026, not a binding international standard. The information in this article was verified as of July 2026.
In practice, the term “human oversight” covers several distinct functions: setting boundaries before an AI system is deployed, approving individual decisions, allowing the system to operate autonomously while intervening when exceptions arise, using AI to strengthen monitoring, halting operations in an emergency, and providing a route for appeal after a decision has been made.
All of these fall under human oversight, but they operate at different stages and serve different purposes.
In its consultation report published on June 10, 2026, the Financial Stability Board (FSB) presents human oversight not as a single approval step, but as a set of distinct forms. Rather than covering all twelve proposed sound practices, this article focuses on the different forms of oversight described in sound practice 10.
What Was Published, and Where It Sits
According to the FSB’s published materials, the consultation report “Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report” was released on June 10, 2026. Responses were due by July 22, 2026, and a final report is expected in October 2026.
The status of the document deserves attention before its contents do. The FSB states that the sound practices are not intended to establish an international standard, impose a prescriptive approach to responsible AI adoption by financial institutions, or influence decisions about whether to adopt any particular AI technology. It also makes clear that adopting these practices does not relieve financial institutions of their obligations to comply with applicable local laws and regulations.
The report further explains that the practices were not developed to address recent risks that have emerged related to frontier AI models, although some of them may help financial institutions respond to such risks.
The twelve proposed practices are grouped into three areas: organization-wide AI governance, management of AI risks through the development and deployment stages, and AI-related cyber, IT, and third-party risks. The subject of this article, human oversight, is sound practice 10, which sits in the second group. There, the FSB asks financial institutions to implement appropriate and effective human oversight commensurate with the AI’s materiality, risk, autonomy, complexity, and explainability.
Why AI Agents Make Human Oversight Harder
The report is direct about the challenges AI agents pose. It notes that AI agents present a distinct challenge for human oversight, given the impracticality of real-time human monitoring of agent decisions as their use scales.
It identifies a specific consequence: agents may pursue objectives or take actions that deviate from the institution’s intentions or risk appetite, without staff becoming aware in time to intervene. The report also acknowledges that monitoring may need to be continuous, or to be performed by AI.
But it draws a clear line at that point. Even when active monitoring is primarily undertaken by machines, financial institutions and individuals retain ultimate accountability.
The use of the term "accountability" here does not establish individual legal liability under any particular jurisdiction. It expresses a governance principle: delegating monitoring tasks to AI does not erase the organization's internal allocation of responsibility.
AI may perform more of the monitoring, but responsibility does not shift with it. That distinction lies at the heart of the report’s treatment of human oversight.
”Human Oversight” Is Not a Single Step
The report does not prescribe one form of oversight. Instead it lists several—human-in-the-loop, AI-in-the-loop, human-on-the-loop, human-in-command, kill switch, and contestability—and expects institutions to apply them according to circumstance. Because these terms are used inconsistently across the literature and across regimes, this article follows the definitions given in the FSB consultation report.
What stands out is that these six forms are not mutually exclusive alternatives. Approval, emergency shutdown, and appeal operate at fundamentally different moments. Treating them as mutually exclusive options is not particularly useful in practice.
A Time-Based View of Human Oversight
The forms the FSB lists can be read less as six items on one level and more as functions positioned at different points in time: before the AI system is deployed, while it operates, when something goes wrong, and after a decision has been issued.
Setting Boundaries Before Deployment — human-in-command
Human-in-command is less about reviewing individual outputs than about deciding in advance the extent of autonomy, the permitted actions, the guardrails, and how overall impact is managed. The report frames it as the form aimed at AI with high levels of autonomy, such as agentic AI. Even where humans cannot review every transaction, the range within which the AI may operate is still set by people.
Approving Each Decision — human-in-the-loop
Under human-in-the-loop, humans approve all decisions made by the AI. The report suggests this may be appropriate where accuracy matters more than speed of decision-making, offering the approval of a health insurance claim as an example.
The presence of a human in the workflow does not by itself make oversight effective. If the approver lacks the evidence, the time, the competence, or the authority to act, approval becomes a formality.
Intervening When Exceptions Arise — human-on-the-loop
Under human-on-the-loop, the AI operates normally and humans intervene periodically or only where necessary. The report cites low-confidence outputs and cases requiring an override as examples.
Where volume and speed rule out approving every case, the key question is not whether a human reviews every case, but what triggers escalation to a human.
Strengthening Oversight with AI — AI-in-the-loop
AI-in-the-loop integrates AI into human oversight to augment performance monitoring, rather than merely using humans to oversee AI. The report describes it as using AI as a supportive layer while keeping humans in control, and notes that it may be warranted as financial institutions expand the number of AI use cases.
Reinforcing monitoring with AI does not remove the question of allocation: who receives the alerts or findings, who acts on them, and who verifies the response.
Halting Operations in an Emergency — kill switch
A kill switch is a mechanism enabling human intervention to halt or constrain AI operations. As the report describes it, this ranges from complete shutdown to dynamic or graduated degradation, where systems transition from autonomous to human operation.
Allowing Reconsideration After the Fact — contestability
Contestability provides mechanisms through which people can challenge an AI-enabled decision and seek human review or redress. The report offers the example of allowing customers to appeal AI-enabled loan denials if they suspect unacceptable bias.
Oversight therefore extends beyond the decision-making process to what happens after a decision has been issued.
Layering Several Forms of Oversight on One Process
Consider a lending operation that uses AI to review loan applications. What follows is not a statement of what any regime requires; it is a hypothetical, meant to show that several forms of oversight can coexist within a single process.
Before the system is deployed, people define the data that may be used, the factors that may not enter the decision, and the scope of decisions the AI may handle autonomously. That is human-in-command.
If routine applications are processed by the AI, with cases routed to staff only when confidence falls below a threshold or an exception condition is met, that is human-on-the-loop. Where a decision carries particularly significant consequences for the customer, requiring human approval before the decision is implemented is human-in-the-loop.
If a separate monitoring system watches for performance drift, or for skew in outcomes affecting particular groups of applicants, it is functioning as AI-in-the-loop, supplementing human oversight. When serious performance degradation or anomalies are detected, automated processing is halted and cases are routed to human staff: that is the kill switch. And the route by which an affected applicant can appeal and obtain human review is contestability.
The six forms are not a menu from which an institution chooses only one. They can be layered across different moments and purposes within the same process.
The Hard Part Is Defining the Trigger for Human Intervention
Listing six names does not make oversight work. The practical difficulty lies in defining the conditions under which a case, decision, or process must be escalated to a human.
Is it when confidence drops? When an amount or an impact crosses a threshold? When a prohibited operation is attempted? When a monitoring model flags an anomaly? When a customer asks for reconsideration?
Notification alone is also not enough. It must be clear whether the person receiving the notification can halt downstream processing, reverse the decision, and access the logs and evidence needed to assess the case. All of this must be determined in advance.
This is why the FSB points to analyzing patterns of human oversight. The report suggests examining whether human reviewers consistently approve agent recommendations without modification—a pattern it describes as rubber-stamping—or override those recommendations in ways that indicate pervasive misalignment. What matters is not that a reviewer was assigned, but whether the record of reviewer behavior shows that the oversight is functioning in practice.
The central implication we draw from the FSB’s proposals is not that institutions should simply add more human-in-the-loop controls. It is that oversight should be separated into distinct functions—boundary setting, routine monitoring, exception handling, shutdown, and after-the-fact redress—with explicit conditions governing the transitions between them.
Closing Thoughts
What distinguishes the FSB’s proposals is not simply the claim that humans should be involved. It is that human oversight is presented not as a single approval step covering every decision, but as a set of functions spanning boundary setting before deployment, monitoring during operation, intervention in exceptional cases, emergency shutdown, and appeal after a decision has been issued.
As the use of AI agents expands, reviewing every intermediate decision in real time will become impractical, and more of the monitoring may be carried out by AI. Even so, responsibility remains for deciding what is monitored, when control shifts to a human, who has the authority to stop the process, and who reviews appeals.
The question is not simply whether a human has the final say. It is when human involvement is required and what purpose it serves. That is the question the FSB’s proposals bring into focus.
About This Information
This article is based primarily on the Financial Stability Board (FSB) consultation report published on June 10, 2026. The information was verified as of July 2026.
The report is a consultation-stage proposal; responses were due by July 22, 2026. A final report is expected in October 2026 and its contents may change. Please refer to official announcements for the latest information.
Key References
- Financial Stability Board, Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report, 10 June 2026.