The more an AI system can do, the more important its boundaries become.
An AI writing a first draft presents a very different level of risk from an AI that can modify a customer account, trigger a payment, send an external message or access confidential business data.
The UK government’s voluntary AI cyber
security code calls for defined business requirements, security risk assessment, staff training, audit trails, controlled permissions, testing and human responsibility.
EU requirements also impose human-oversight duties in specified high-risk uses.
This is why “human in the loop” needs to mean more than somebody glancing at an answer.
A sensible AI workflow should make it clear what the AI can access, what it is allowed to do automatically, what requires approval, what gets logged and when a person must take over.
That becomes particularly important around money, personal information, contractual commitments, security and regulated decisions.