One of the cornerstones of AI regulation over the past decade has been the principle of Human in the Loop (HITL). The idea is simple: no matter how capable an AI system becomes, a person should remain involved in important decisions, review outcomes, and ultimately be accountable.
When this principle was introduced, it was absolutely the right approach. AI systems at the time were primarily decision-support tools. They analyzed information, detected anomalies, ranked alternatives, or recommended actions, while humans made the final decision. Regulators, compliance officers, and business leaders could confidently embrace AI because meaningful human oversight remained part of the process.
The world has changed much faster than regulation.
We are rapidly moving from AI systems that support decisions to AI Agents that perform work. This is far more than a technological upgrade. It represents a fundamental change in how organizations operate.
An AI Agent does not simply generate a recommendation and wait for approval. It receives an objective, develops a plan, gathers information from multiple sources, interacts with external tools, adapts its strategy during execution, collaborates with other agents, and completes business processes with little or no human intervention.
That is exactly where the governance challenge begins.
It is easy to argue that every AI Agent decision should be approved by a human. On paper, that sounds reasonable. In practice, it is becoming impossible.
The first reason is scale.
A claims manager, underwriter, or compliance officer might review dozens or even hundreds of decisions in a day. An enterprise AI Agent may execute thousands of actions every hour and tens of thousands every day. As organizations deploy multiple agents simultaneously, those numbers will increase dramatically. No human oversight process can realistically keep pace.
The second reason is speed.
AI Agents operate in milliseconds. By the time a person reviews one action, the agent may already have completed thousands of additional tasks, updated its execution plan, and triggered downstream processes across multiple systems. Oversight that arrives after the fact is no longer operational oversight; it is merely retrospective review.
The third reason is autonomy.
Modern AI Agents do not simply execute predefined workflows. They determine how to achieve objectives, choose which tools to use, decide when to change strategy, identify new information sources, and even orchestrate other agents. The more capable they become, the less meaningful it is to ask whether a human approved every individual decision.
In my view, the greatest risk is therefore not the absence of oversight but the illusion of oversight.
If compliance officers are expected to approve hundreds or thousands of AI-generated actions every day, approval quickly becomes procedural rather than meaningful. Organizations may satisfy a governance requirement on paper while failing to achieve genuine supervision in practice.
This is why the discussion must change.
The question is no longer how to place a human inside every decision.
The real question is how to ensure that autonomous AI systems consistently operate within clearly defined boundaries, remain transparent, and can always be held accountable.
Instead of supervising every action, organizations should supervise the policies that govern those actions.
This is the shift I believe regulators and businesses should embrace.
Every AI Agent should operate within clearly defined policies that establish authority limits, acceptable risk levels, operational constraints, and mandatory escalation rules.
Every significant event should generate automated reporting rather than waiting for manual approval.
Every material decision should create a complete audit trail documenting the data used, the governing policies applied, and the outcome produced.
Human intervention should become risk-based rather than universal. Routine activities should remain autonomous, while high-impact decisions, policy violations, or exceptional situations should automatically escalate to people.
Insurance will be among the first industries to experience this transformation. Underwriting, claims handling, fraud detection, customer service, compliance, and operational decision-making will increasingly rely on autonomous AI Agents. Attempting to manage these systems through traditional Human in the Loop processes will not strengthen governance. It will simply make large-scale deployment impossible.
Human accountability is not disappearing. On the contrary, it is becoming even more important.
But accountability can no longer depend on manually approving every AI-generated action.
My recommendation to regulators, insurers, and enterprise leaders is straightforward.
Stop trying to fit AI Agents into yesterday’s governance frameworks.
Instead, build Governance by Design.
Require every AI Agent to operate within predefined policies.
Require mandatory reporting for material events and policy deviations.
Require complete auditability for every significant decision.
Require automatic escalation only when risk thresholds are exceeded.
Most importantly, redefine the human role.
People should stop trying to remain inside every operational loop.
Their responsibility should be to design the governance framework, define the boundaries, monitor outcomes, and continuously improve the system.
Human in the Loop was the right model for introducing AI into organizations.
Governance by Design is the model that will allow organizations to scale AI Agents safely, responsibly, and with genuine accountability.
The future challenge is not whether AI Agents will transform business operations. They already are.
The real challenge is ensuring that our governance frameworks evolve just as quickly as the technology itself.