NACH
·Tarek Nachnouchi

Autonomous AI agents: why human oversight remains a legal obligation, not an option

With AI agents flooding into business software, a governance question becomes central: how far can an agent act without human approval, legally speaking?

The flood of AI agents into business software, driven by a shift Gartner puts at 40% of business applications by end of 2026, raises a governance question few SMBs have addressed yet, how far can an agent act alone, with no human approval, without exposing the company to legal or operational risk. The answer is not a matter of personal judgment, it is already, in part, a legal obligation.

The AI Act requires, for high-risk systems in particular, effective human control measures. This requirement is not a mere statement of intent, it concretely means a person must understand the actual capabilities of the system in use, be able to monitor its operation continuously, and have the ability to intervene or stop its action if abnormal or harmful behavior is detected. An AI agent left entirely to its own devices, with no identifiable control point, does not meet this requirement, even when it works correctly most of the time.

Not all AI agent actions carry the same level of risk, and the oversight requirement should be proportionate to that risk rather than applied uniformly. An agent that reworks an internal document for strictly personal use carries limited risk. An agent that commits the company to a third party, sending a sales email, confirming an order, responding to a customer complaint, deserves an explicit oversight point, even when that use does not formally fall under the AI Act's strictest high-risk regime.

The most common confusion on this topic is pitting human oversight against systematic validation of every individual action. Requiring human approval before every action would simply cancel out the automation benefit the company is seeking. Human oversight, as expected, instead relies on alert thresholds, regular sampling of completed actions to check compliance, and above all a real, immediate ability to stop the agent if abnormal behavior is detected, rather than exhaustive, systematic review of each individual action.

The most concrete step an SMB can take right now is explicitly defining, for each agent activated in its software, two categories of actions, those the agent can carry out alone with no intervention, and those requiring human approval before execution. This distinction, often absent from the default settings vendors ship, considerably reduces legal and operational risk, and can usually be configured directly in the software's own settings.

If an autonomous agent makes an error harmful to a customer or third party, the company remains responsible, exactly as with any classic automated decision. The absence of an identifiable oversight point significantly worsens the situation in a dispute, revealing insufficient governance rather than an isolated incident despite controls actually in place. This difference, between an incident that occurred despite a documented control system and a total absence of one, carries the most weight before a judge or regulator.

An SMB with no in-house legal expertise should not be discouraged by the apparent scale of this obligation. The most realistic approach is to start simply, a written list of actions allowed without approval and those requiring it, revised after the first weeks of real use once actual risk areas are better understood, rather than trying to produce an exhaustive, perfect legal framework upfront that would indefinitely delay going live.

This is what the Framing step of the IMPACT method should incorporate for each AI agent activated, an explicit definition of its autonomous scope of action and the associated human control points, before it goes into actual service rather than after a first incident. Human oversight of autonomous agents is not a brake on their adoption, it is the condition that allows adopting them without suffering their least predictable consequences. A five-business-day diagnostic defines the oversight points suited to your AI agents.

Let's take action

Ready to structure your AI transformation?

Free 30-minute diagnostic to identify your top priorities and estimate concrete ROI for your organization.

Book my free diagnostic →

Related articles