Human-in-the-Loop
Human-in-the-loop means a person reviews or approves a specific action before it happens, rather than the system acting entirely on its own. An AI agent that drafts a refund but waits for someone to click approve before it actually issues the money is human-in-the-loop for that one action — everything else it did to get there can still be fully automated.
Two different shapes
Approval before the action (gating). The system pauses and waits for a person to say yes before something happens — the usual case for anything irreversible or externally visible: sending money, sending an email, deleting data, deploying code.
Review after the fact (auditing). A person checks a sample of completed actions rather than approving each one individually — used for lower-stakes, high-volume actions where gating every single one would be pure friction, but where someone should still occasionally verify the system is behaving as expected.
Which actions actually warrant gating
The same test that governs tool permissions generally: the more costly and harder to undo an action is, the stronger the case for a person reviewing it first. And the review has to be real — the prompt injection page's own checklist makes this point directly: show the person the content that actually triggered the action, not just a bare "approve?" button with no context. An approval screen that just says "Issue refund?" gets clicked without anyone really checking.
The real cost: it doesn't scale to everything
Requiring approval for every single action a system takes isn't free, and it isn't automatically safer. It adds real latency, since a person now has to actually look before anything happens. And past a certain volume, requiring approval for too much — including plenty of genuinely low-risk actions — teaches people to click approve without really checking, the same way constant low-value alerts eventually get ignored. A gate that's asked to approve everything ends up approving everything, which defeats the point of having a gate at all. Gating fewer, genuinely higher-stakes actions works better than gating everything a little.
When to skip it
Reversible, low-stakes, high-volume actions are usually better served by auditing after the fact, or no human check at all, than by gating every one — searching documentation, running a read-only query, drafting something nobody sees until it's reviewed anyway. Save gating specifically for the actions where being wrong actually costs something real.
In this guide
FAQ
Is human-in-the-loop the same as having a human do the whole task instead of the AI?
No. The system still does the work — deciding, drafting, investigating — and a person's role is narrowly to approve or reject one specific step, usually the point where a real, hard-to-undo effect would otherwise happen. It's a checkpoint on one action, not a replacement for the system.
If a system requires approval for every action it takes, is that the safest possible design?
Not necessarily. Gating everything tends to produce reviewers who click approve out of habit rather than genuine scrutiny, because most of what they're approving is low-risk. A system that reserves approval for the genuinely high-stakes actions and lets the rest run tends to get more real attention on the approvals that actually matter.