ISO/IEC FDIS 42105
(Main)Information technology — Artificial intelligence — Guidance for human oversight of AI systems
General Information
- Abstract
This document provides guidance on human control and monitoring of AI systems, which is referred to as human oversight. This document extends ISO/IEC TS 8200. This document is applicable to all types of organizations. This document is applicable throughout the AI system life cycle.
- Status
- Not Published
- Technical Committee
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- Drafting Committee
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- Current Stage
- 5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
- Start Date
- 26-Aug-2026
- Completion Date
- 26-Aug-2026
Buy Documents
ISO/IEC FDIS 42105 - Information technology — Artificial intelligence — Guidance for human oversight of AI systems
REDLINE ISO/IEC FDIS 42105 - Information technology — Artificial intelligence — Guidance for human oversight of AI systems
Overview
ISO/IEC FDIS 42105:2026 specifies essential guidance for human oversight of artificial intelligence (AI) systems. Developed by ISO and IEC Joint Technical Committee for Information Technology and Artificial Intelligence (JTC 1/SC 42), this standard addresses the necessity of effective human control, monitoring, and intervention in AI operations across all organizational types and at every stage of the AI system life cycle. As AI becomes increasingly central to critical processes, this document provides organizations with frameworks to ensure responsible, controlled, and transparent AI use-effectively mitigating risks and unintended outputs such as bias or operational errors.
Key Topics
Human Oversight Definition
The standard defines human oversight as all activities by a human intended to control or monitor an AI system, either in real time or after incidents, to ensure operational integrity and compliance with governance objectives.Levels of Oversight
Guidance is structured across three layers:- Governance/Management: Alignment with organizational strategy, policies, and mandates (see also ISO/IEC 38507, ISO/IEC 42001).
- Operational: Direct monitoring and control of AI system output and behavior.
- Controllability: Technical capacity to observe or intervene in AI systems, as set out in ISO/IEC TS 8200.
Stakeholder Roles
Key stakeholders include:- AI customers (organizations deploying AI)
- AI developers (solution providers)
- AI users (end-users)
- AI subjects (individuals affected by AI outputs)
- Human oversight supervisors
- AI system operators
Oversight Mechanisms
- Real-time monitoring and intervention (e.g., autonomous vehicles)
- Post-incident review and intervention (e.g., recruitment tools)
- Use of supporting tools for observation, explainability, and transparency
Managing Risks and Bias
The standard details human oversight as a risk mitigation activity, emphasizing the reduction, not total elimination, of AI-associated risks. It highlights the necessity to understand and address both technical and human sources of bias.Training and Competence
Human oversight supervisors must be trained to understand AI risk, domain context, and recognize biases, ensuring effective intervention and system improvement.
Applications
Practical application of ISO/IEC FDIS 42105 spans the entire AI system life cycle and is relevant in diverse contexts, such as:
AI Deployment and Monitoring:
Organizations can establish human oversight frameworks during the deployment and operational phases of AI, ensuring outputs align with intended objectives and policies.Compliance with Governance:
ISO/IEC FDIS 42105 helps organizations demonstrate alignment with governance, risk management, and compliance mandates, supporting the responsible use of AI technologies.Incident Investigation and Response:
With clear guidance on post-incident analysis and intervention, the standard assists in investigating root causes and preventing repeated occurrences of AI failures or adverse events.Fostering Trust in AI:
By defining roles and supporting transparent human-AI interaction, the guideline helps build user and stakeholder trust in AI systems.Sector-Specific Adaptability:
The guidance is applicable to healthcare, finance, transportation, manufacturing, and more-anywhere AI-driven automation demands accountable and transparent oversight.
Related Standards
To provide a comprehensive governance and technical foundation for human oversight of AI, ISO/IEC FDIS 42105 references and extends several key standards:
- ISO/IEC TS 8200: Controllability of automated artificial intelligence systems
- ISO/IEC 22989: AI concepts and terminology
- ISO/IEC 38507: Governance implications of AI
- ISO/IEC 42001: Artificial intelligence management system
Each of these standards contributes to a robust ecosystem, ensuring organizations can effectively integrate human oversight into AI governance, operation, and technical architectures.
Keywords: AI human oversight, ISO/IEC 42105 standard, AI risk management, AI system monitoring, artificial intelligence oversight, AI lifecycle, AI governance, bias in AI, controllable AI systems, responsible AI deployment.
Buy Documents
ISO/IEC FDIS 42105 - Information technology — Artificial intelligence — Guidance for human oversight of AI systems
REDLINE ISO/IEC FDIS 42105 - Information technology — Artificial intelligence — Guidance for human oversight of AI systems
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
ISO/IEC FDIS 42105 is a draft published by the International Organization for Standardization (ISO). Its full title is "Information technology — Artificial intelligence — Guidance for human oversight of AI systems". This standard covers: This document provides guidance on human control and monitoring of AI systems, which is referred to as human oversight. This document extends ISO/IEC TS 8200. This document is applicable to all types of organizations. This document is applicable throughout the AI system life cycle.
This document provides guidance on human control and monitoring of AI systems, which is referred to as human oversight. This document extends ISO/IEC TS 8200. This document is applicable to all types of organizations. This document is applicable throughout the AI system life cycle.
ISO/IEC FDIS 42105 is classified under the following ICS (International Classification for Standards) categories: 35.240.01 - Application of information technology in general. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC FDIS 42105 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 42
Information technology — Artificial
Secretariat: ANSI
intelligence — Guidance for human
Voting begins on:
oversight of AI systems
2026-08-26
Voting terminates on:
2026-10-21
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 42
Information technology — Artificial
Secretariat: ANSI
intelligence — Guidance for human
Voting begins on:
oversight of AI systems
Voting terminates on:
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
5 Concept of human oversight of AI systems . 2
5.1 General .2
5.2 Objectives of human oversight .3
5.3 Various types of human oversight .3
5.3.1 Considerations for human oversight implementation .3
5.3.2 Target AI system of human oversight .3
5.3.3 Timing and level of human intervention .4
5.3.4 Effectiveness of human oversight .6
5.4 Implementing human oversight .6
5.4.1 General .6
5.4.2 Human oversight supervisor and AI system operator .6
5.4.3 Observation of testing by the human oversight supervisor .7
5.5 Human oversight in AI system life cycle .8
6 Stakeholder roles . 8
6.1 General .8
6.2 AI customer .9
6.3 AI developer .9
6.4 AI subject .9
6.5 AI user .9
6.6 Human oversight supervisor .9
6.7 AI system operator .10
7 Human-AI system configuration . 10
8 Understandings of systems . 10
8.1 Introduction to system understanding .10
8.2 Overall systems, AI systems and human oversight systems .11
8.2.1 Differentiating between overall systems, AI systems and human oversight
systems .11
8.2.2 Overall system . 12
8.2.3 Systems related to human oversight . 12
8.2.4 The AI system itself . 13
8.2.5 Interaction between systems . 13
8.2.6 Internal structure: subsystems and relationships (static aspect) .14
8.2.7 Operational status: real-time inputs, outputs and current system status
(dynamic aspect) .14
8.3 Static aspect of the system: components and their interactions . 15
8.3.1 Introducing static aspects of the system . 15
8.3.2 System architecture . 15
8.3.3 Components and interaction between components . 15
8.3.4 Understandability in static design .16
8.4 Understanding dynamic aspect of the system .17
8.4.1 Introducing dynamic aspects of systems .17
8.4.2 Real-time understanding .17
8.4.3 Interpretability, explainability and transparency .18
9 Human-machine interface to support human oversight . 19
10 Human intervention .20
© ISO/IEC 2026 – All rights reserved
iii
10.1 General . 20
10.2 Range of intervention . 20
10.3 Severity and ability to reverse actions .21
10.3.1 General .21
10.3.2 Severity of harms .21
10.3.3 Ability to reverse actions . 22
10.3.4 Balancing severity and reversibility . 22
11 Bias .22
11.1 General . 22
11.2 Bias from interaction between AI system operators and AI systems . 23
Annex A (informative) Rationale for avoiding the use of specific terminology in this document .24
Bibliography .27
© ISO/IEC 2026 – All rights reserved
iv
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 42, Artificial intelligence.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
v
Introduction
AI systems can collect more data, analyse them faster and control other systems in more precise manners
than human experts. At the same time, AI systems can have unintended outputs such as unintended bias,
which can have disastrous effects.
The ability to monitor and control the target AI system enables to suppress the unintended outputs, and
enables to support safe and controlled operation of the AI system. The process to achieve the system to
follow organizational policies set by governance frameworks with the ability is called human oversight.
Human oversight comprises activities at various levels. The first level is governance and management level
activities. From the top to the bottom, these activities set goals to be achieved (e.g. the level of transparency
[1] [2]
the AI system should achieve) and addressed in ISO/IEC 38507 and ISO/IEC 42001 . The second is
operational level activities (e.g. the details of the information to be monitored and controlled) based on the
capability of the AI system. This activity is the focus of this document. The third is the controllability that
defines the capability of the AI system to be controlled and monitored (e.g. the ability to display and change
[3]
the internal states of AI systems) and is described in ISO/IEC TS 8200 . The capabilities to respond to the
mandate goes from the bottom to the top.
Human oversight comprises activities at various levels. The first level is governance and management level
activities. These activities set goals to be achieved (e.g. the level of transparency the AI system should
[1] [2]
achieve) and addressed in ISO/IEC 38507 and ISO/IEC 42001 . The second is operational level activities
(e.g. the details of the information to be monitored and controlled) based on the capability of the AI system.
This activity is the focus of this document. The third is the controllability that defines the capability of the
AI system to be controlled and monitored (e.g. the ability to display and change the internal states of AI
[3]
systems), and is described in ISO/IEC TS 8200 .
© ISO/IEC 2026 – All rights reserved
vi
FINAL DRAFT International Standard ISO/IEC FDIS 42105:2026(en)
Information technology — Artificial intelligence — Guidance
for human oversight of AI systems
1 Scope
This document provides guidance on human control and monitoring of AI systems, which is referred to as
[3]
human oversight. This document extends ISO/IEC TS 8200 .
This document is applicable to all types of organizations developing and using AI systems during their whole
life cycle.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC TS 8200, Information technology — Artificial intelligence — Controllability of automated artificial
intelligence systems
ISO/IEC 22989, Information technology — Artificial intelligence — Artificial intelligence concepts and
terminology
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 22989, ISO/IEC TS 8200 and
the following apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http:// www .electropedia .org/
— ISO Online browsing platform: available at http:// www .iso .org/ obp
3.1
human oversight
activities by a human intended to control an AI system
Note 1 to entry: Human oversight typically allows either exercising control, in the case of a controllable system, as
[4]
defined in ISO/IEC TS 8200:2024 , or invoking post-hoc procedures to modify the outputs, or making operational
and other changes to the AI system.
Note 2 to entry: This operational-level oversight accomplishes some goals of governance-level oversight in the sense
[5]
of ISO/IEC 38507:2022 , but is not identical to it, and may involve human decisions of when to exercise control, as
[4]
defined in ISO/IEC TS 8200:2024 .
3.2
human oversight supervisor
designated person
designated human with responsibility or authority for human oversight (3.1)
Note 1 to entry: This role involves supervision of the AI system, not a supervisory role within an organization.
Note 2 to entry: Human oversight supervisor can be multiple people.
© ISO/IEC 2026 – All rights reserved
3.3
AI system operator
human handling an AI system
[6]
[SOURCE: ISO 81060-1:2007 , 3.14 - modified, changed person to human, and changed equipment to AI
system.]
3.4
Organization
human or group of people that has its own functions with responsibilities, authorities and relationships to
achieve its objectives
[7]
[SOURCE: ISO/IEC 42001:2023 , 3.1, removed notes to entries.]
4 Abbreviated terms
AI artificial intelligence
SaaS software as a service
5 Concept of human oversight of AI systems
5.1 General
As shown in Figure 1, human oversight comprises activities at various levels, and supported by various
characteristics of AI systems. There are three-levels of activities on oversight, governance and management-
level, operational-level, and controllability. Governance activity sets the goal and mandates to the bottom.
[5] [7]
They are described in ISO/IEC 38507:2022 and ISO/IEC 42001:2023 , and is out of scope of this
document. Controllability provides the capability to respond to the mandate, from bottom to the top. It is
[4]
described in ISO/IEC TS 8200:2024 , and is also out of scope of this document.
As shown in Figure 1, human oversight is achieved based on controllable AI systems, which are described
[4]
in ISO/IEC TS 8200:2024 . The controllable AI system is monitored and controlled primarily by humans,
which is described in this document. The controllable AI systems are part of the target of governance and
[5] [7]
management activities described in ISO/IEC 38507:2022 and ISO/IEC 42001:2023 .
Figure 1 — Three-layer structure of ISO/IEC human oversight standards
© ISO/IEC 2026 – All rights reserved
5.2 Objectives of human oversight
An AI system does not always work as intended by its AI developer and its AI customer because of high levels
of system complexity and the system’s ability to operate in a highly automated manner. In addition, because
not every potential outcome can always be foreseen beforehand, unwanted side effects or consequences
can be identified only after the deployment of the AI system. For example, sometimes important cases are
found that were not included in training data after AI system deployment. In many cases these problems are
identified not by its AI developer, but by its AI customers including AI users, or sometimes bystanders.
Accordingly, it is therefore necessary to ensure AI systems do not deviate from their business objectives
when it exhibits such unintended behaviour. This is achieved by a human who directly supervises the target
AI system and closely controls the output of AI systems through its human–machine interface, and activities
that makes such oversight and control easier. The governing body sets appropriate rules and intended
behaviours for the target AI system. The human who oversees the system monitors and controls the system
to ensure it does not violate the policy (e.g. unknown side effects).
An AI system can have multiple objectives to achieve (e.g. performance and security). In human oversight, it
is important to balance the objectives. The relative priority of the multiple objectives depends on the context
and the target system including risks and level of automation.
Human oversight is a risk mitigation activity, and if done correctly, it partially mitigate specific risk. Risk
(possibly AI-specific risk) mitigation activity reduces risks to make the risk tolerable, but does not eliminate
risks completely. In this context, handling of risks of AI system are equivalent to managing the risks of
traditional systems.
5.3 Various types of human oversight
5.3.1 Considerations for human oversight implementation
There are various types of human oversight. The target AI system can be a subsystem of another AI system
and a human oversight supervisor can access the target AI system through other subsystems such as
supporting tools. Timing and the ability of intervention can vary. Finally, there can be various difficulties for
achieving effective human oversight.
NOTE Some sources use terminology such as “human on/in-the-loop” or “human-in-command”. While these
terms have engineering origins, they have increasingly been adopted by policymakers, the media and others for policy,
legal or other purposes. In the context of AI systems, “loop” and “command”-related terminology can be ambiguous,
imprecise and often suggestive of a level or form of oversight or controllability that is not, in reality, possible. Annex A
details the rationale for why the authors of this standard purposefully decided to not make use of terms involving
“loop” or “command” in connection with humans and AI systems.
5.3.2 Target AI system of human oversight
5.3.2.1 Range of target AI system
The term 'AI system includes whole AI products and related services, i.e. AI functionalities as well as
system interfaces, business logic implementations, computing resources and physical facilities. See
[4]
ISO/IEC TS 8200:2024 , Figure 1 for more details.
The AI system to be overseen is sometimes comprises multiple subsystems. In some cases another system,
or a supporting tool is added as a subsystem. The human oversight supervisor, responsible for conducting
human oversight, is expected to supervise the whole system even if such tools are added.
Depending on who develops the system, there can be three patterns for the target AI system and human
oversight supervisor, as shown in Figure 2.
Pattern 1: human oversight supervisor directly monitors and controls the AI system provided by AI
developer, or the target AI system.
© ISO/IEC 2026 – All rights reserved
Pattern 2: AI developer provides AI or non-AI system (supporting tool) as well as main AI system. Target AI
system includes both main AI system and supporting tool.
Pattern 3: AI customer adds third party’s additional AI or non-AI systems to main AI systems provided by AI
developer. Target AI system includes both main AI system and supporting tool.
Pattern 2 and 3 can co-exist (e.g. when different tools are used by different operators).
Figure 2 — The target AI system of human oversight
The reason why a target AI system can include supporting tools is so that human oversight can be applied
to final output that affect either the AI user(s) or AI subject(s), or both. In the event of a malfunction of
supporting tools, the human oversight supervisor can provide relevant input or observations; however,
responsibility for the root cause analysis remains with the AI developer or the AI customer.
5.3.2.2 Supporting tools
[4]
According to ISO/IEC TS 8200:2024 , 6.1, when an AI system is controllable, it can implement a set of
facilities for system state observation that provide views of system parameter values and appearance
to external humans or agents. In the context of human oversight, such facilities can be directly used or
indirectly invoked or operated by humans through other systems (see 5.3.2.1).
Those facilities for system state observation can be programmatically encapsulated or physically operated
by supporting tools that implement more complex workflows according to requirements of oversight.
Various supporting tools should be designed and implemented for human oversight and used in addition
to the system state observation facilities provided by the AI system itself. There can be a safety jacket
that filters unfavourable output and prevents dangerous behaviour of automated systems, translation
system or remote monitoring system. See 8.4.3 for more details on supporting tools for explainability and
transparency.
5.3.3 Timing and level of human intervention
In human oversight, there are a variety of factors that can materially change the character of the oversight.
For example, timing of monitoring and resulting execution of human control and intervention, preciseness
of how the control is reflected to the target AI systems and whether the output of AI systems is modified
© ISO/IEC 2026 – All rights reserved
because of the intervention, affects the result of the human oversight activity (e.g. if the output of the AI
system is changed before it affects other systems). In addition, the preciseness of the control is described
[4]
as the controllability level in ISO/IEC TS 8200:2024 , 7.3, from not controllable to completely controllable.
a) Real-time monitoring and intervention (e.g. autonomous bus)
b) Real-time monitoring and post-incident intervention (e.g. stock brokering system)
c) Post monitoring and intervention (e.g. recruitment supporting system)
Figure 3 — Timing of monitoring and intervention
The monitoring activity of human oversight can be done in a real-time manner, with structured triage
mechanisms (e.g. in an automated bus monitored by human oversight supervisor) as shown in Figure 3 a), or
stock brokering system in Figure 3 b). It can also be done as a post-incident activity as shown in Figure 3 c),
e.g. in a recruitment supporting system by collecting the output of AI systems and by analysing it using the
statistical method.
Control and intervention activities are done in real-time manner as in Figure 3 a), or are done in post-incident
manner as in Figure 3 b) Figure 3 c) including, when processes operate very fast and handle huge amounts of
data, which would make it impossible for humans to understand the situation and react in a timely manner
even when the system is otherwise completely controllable. See Clause 8 and 10.2 for more details.
The output of the target AI system is changed before it affects other systems in real-time monitoring and
intervention, if controllability level is sufficient. It can be changed in post-incident intervention by providing
[8]
corrected outputs on logged errors (see ISO/IEC FDIS 24970 for details). Post-incident intervention can
involve preventing repetition of errors by changing the configuration, debugging and updating the system
and other means, noting however that this is not an exhaustive list.
[9]
ISO/IEC 22989:2022 , 5.13 describes 7 levels of automation, no automation (level 0) to autonomy (level 6).
At high automation (level 4), the system performs parts of its mission without external intervention. At full
automation (level 5), the system is capable of performing its entire mission without external intervention.
For systems whose level of automation is equal to or less than four, real-time control and intervention is
more feasible. In these systems, to obtain the final result, a human takes some action, which influences the
© ISO/IEC 2026 – All rights reserved
result. For systems whose level of automation is more than four, post-incident intervention becomes an
important method. However, quasi-real-time intervention (e.g. pushing a stop button) can often be designed
and built in.
5.3.4 Effectiveness of human oversight
As described in 5.3.3, human oversight is sometimes not able to or is insufficient for meeting broader
objectives. That is, it is not always possible for a human oversight supervisor to:
— intervene and change the output of AI systems when such intervention would be desirable, or
— prevent undesirable AI system outputs from adversely affecting others or leading to other forms of harm.
There are several considerations for effective human oversight. One key consideration is context dependency:
what constitutes a preferable output—and the acceptable degree of deviation from it—depends on the
context. Another important consideration is human factors. Human behaviour is influenced by various
factors. Issues that have no direct relationship with the target AI systems, such as recent airplane accidents
or personal conditions like hunger, can influence human behaviour and, consequently, the performance of
human oversight.
Human factors engineering therefore takes into account factors such as individuals, teams, technology,
organizational structures, procedures, and the operating environment, and contributes to the design of
socio-technical systems. This includes task allocation, interfaces, procedures, training, workload, and
organizational conditions, all of which together influence how humans interact with and oversee AI systems.
[10] [11] [12]
IEC 62366-1 , ANSI/AAMI HE75 and can be a starting point.
AI systems are usually deployed in scenarios where there are challenges for direct human control (e.g.
places where the amount of data, requested processing speed, complexity of algorithms) are uneconomical,
difficult or impossible for human operators to realize. It is therefore difficult or impossible for human
experts, including the human oversight supervisors or the human operators to understand all data in real-
time. Organisations should take into account the following factors when selecting methods:
— timing and level of human intervention;
— level of understanding of the situation; the environment of the system is sometimes well-understood,
and prediction is precise, while sometimes vague and irregular incidents are common;
— time allowed for human reaction; some transactions end in microseconds, while some transactions can
wait hours;
— reliability of systems, in particular communication; sometimes connection between human oversight
supervisor and the system is down;
[3]
— AI system controllability (ISO/IEC TS 8200 ).
5.4 Implementing human oversight
5.4.1 General
As described in 5.2, human oversight activity is necessary at various level in order to reduce the potential
risk of AI systems. Some human oversight approaches could even allow intervention by a human outside of
the direct human oversight chain (e.g. a bystander) in order to prevent disastrous consequences.
However, there are two key personnel in human oversight: human oversight supervisor and AI system
operator. In some cases, these roles can overlap or even be the same people.
5.4.2 Human oversight supervisor and AI system operator
Human oversight in operation and monitoring phase is implemented by an AI developer, an AI deployer or
an AI customer, by using methods provided by the AI developer. The AI customer can assign the task to a
© ISO/IEC 2026 – All rights reserved
human oversight supervisor, who can be an AI customer or can be a third-party human delegated with the
task by the AI customer.
The target AI system is operated by its AI system operator, and both AI system and AI system operator are
overseen by a human oversight supervisor.
Human oversight supervisors are humans, and are trained in at least these areas:
— good knowledge of AI system risks;
— good knowledge of biases related to AI system;
— sufficient subject matter expertise on the context and goals of the AI system;
— understanding of the relevant capacities, limitations and possible risks of the target AI system;
— ability to monitor, detect and mitigate risk using the tools provided by the AI developer.
The training should not just be initial or static. Oversight is strengthened by periodically reviewing training
as experience develops.
In addition, a human oversight supervisor has sufficient authority and incentive ascribed by an AI customer
to intervene in the operation of an AI system. And should consider issues e.g.
— Human oversight supervisor incentives should be aligned with quality rather than just throughput.
Compensation or performance structures which emphasize volume over careful evaluation can
encourage superficial review;
— Conflicts of interest are important in some circumstances, for example if someone is overseeing AI
grading of tests/exams, they should not oversee the grading of a family member exam;
— Human oversight supervisor need breaks to mitigate fatigue. Time pressure should also be limited.
People need time to engage in critical thinking about AI operation and outputs;
— When human oversight supervisors works as a team, diversity should be considered.
AI system operators are experts in the operation of the AI system (e.g. a crew of an automated bus), or are
users of the AI system (e.g. a recruiter using recruitment AI system). If the AI system is highly automated
[9]
(level 5, 6 of ISO/IEC 22989:2022 , 5.13), AI system operators are not always operating the target system.
AI system operators can identify risks during their operations. They can mitigate the risks by themselves or
by notifying the human oversight supervisor.
AI system operators can also be a human oversight supervisor if the policy of the AI customer allows, and
in this case collaboration with an independent human oversight supervisor can further enhance safety.
Operators with expertise can also be human oversight supervisors, if AI customer's policy allows this
responsibility. AI system operators can have less knowledge of AI systems and less ability to detect risks. AI
customers can decide if AI system operators can act as human oversight supervisors or if they should assign
others, factoring in the risks of the AI system and the capabilities of the operator. AI system operators, AI
supervisors and all involved humans can themselves be a cause of unwanted bias, and supervisors can even
affirm unwanted biases. It is therefore important that they are sufficiently trained to recognize biases in
their own thinking and actions in the processes, in addition to other risks.
5.4.3 Observation of testing by the human oversight supervisor
It is desirable for human oversight supervisors to participate in the testing of the target system, in particular
testing in design and development phase or verification and validation phase, in order to deepen their
understanding of the system and to improve the system from the viewpoint of human oversight. Human
oversight supervisors can carry out different activities as decided by the organization based on its policies.
AI customers integrate AI systems provided by AI developers into their own business systems, use them
after conducting the necessary learning. The following benefits are expected from the involvement of a
human oversight supervisor in testing of AI systems.
© ISO/IEC 2026 – All rights reserved
Understanding of the behaviour of the AI system: in order for the human oversight supervisor to judge
anomalies in the AI system, it is necessary to understand its normal behaviour. It is useful to witness tests
carried out on various cases and to oversee the behaviour of the AI system.
Understanding of changes in the AI system due to continuous learning: the human oversight supervisor
is expected to understand that the AI system can change day by day due to continuous learning. The changes
in the behaviour of the AI systems should be monitored during the continuous validation phase of the life
cycle.
Understanding diversity and unwanted bias: the human oversight supervisor should be able to recognize
unwanted biases in the AI system and determine whether they are problematic in the context of the
particular AI system and its purpose. The ability for understanding the target AI system can be improved
through joining the testing and reviewing diverse inputs and outputs of the AI system.
For newly appointed human oversight supervisor, witnessing the testing can be part of their training, while
experienced human oversight supervisor can advise the testers based on their experience.
5.5 Human oversight in AI system life cycle
[9]
ISO/IEC 22989:2022 , Figure 3 shows the AI system life cycle model stages and high-level processes. A
[13]
more detailed life cycle is described in ISO/IEC 5338 .
Human oversight is done in every stage of AI system life cycle.
Inception, Design and development: AI producers should design their AI systems to facilitate human
oversight by AI customers and incorporate supportive features and tools (see Clause 7).
[9]
Verification and validation: In ISO/IEC 22989:2022 , Figure 3, "verification and validation" is supposed as
a process on the AI producer side, and is positioned prior to "deployment". However, from the perspective of
human oversight, "verification and validation" by AI customer should also be positioned after "deployment",
because impacts can be arising from integration with other systems, additional training of AI systems,
characteristics (e.g. human bias) of human users, prompts to input, and other factors.
Deployment: AI system can be deployed to different environments. Human oversight functionalities should
be configured in an optimized manner for each environment.
Operation and monitoring: This process includes both conventional operation and monitoring by personnel
of IT departments, and the human monitoring defined by this document. Ideally, these two types of activity
should be conducted independently and in parallel, because human monitoring is related to user-side aspects
such as human bias, transparency, explainability, etc. It is also effective that personnels of IT department
perform basic human oversight during operation and human oversight supervisor conducts comprehensive
human oversight including those personnel.
Re-evaluate: By reviewing the results of the AI systems in the operation and monitoring stage, AI systems
[9]
can be modified, e.g. its objective can be refined as described in ISO/IEC 22989:2022 , 6.2.8. This is a
governance and management level activity and details are not described in this document.
Retirement: Systems should be designed up front to support updates and retirement, and designed to
support adequate human oversight over the updating and retiring processes. Overseeing AI specific issues
(e.g. data disposal) by human oversight supervisor can increase trustworthiness of the process.
Other AI systems can be used to assist the human oversight supervisor in the supervisor's monitoring role
at some stages.
6 Stakeholder roles
6.1 General
[9]
For the purposes of this document, stakeholder roles given in ISO/IEC 22989:2022 , 5.19 apply, with
explanations in human oversight, and with two new stakeholders (human oversight supervisor and AI system
© ISO/IEC 2026 – All rights reserved
operator). Note that these roles vary greatly with details of the system in question, and the managerial and
operational structure. The decisions about how each role interacts with other roles and with the system are
[2] [14]
design, management and governance decisions as discussed in ISO/IEC 42001 and ISO/IEC 22989 .
Critical stakeholders (AI developer, AI customer, human oversight supervisor, AI system operator or AI user
and AI subje
...
ISO/IEC DISFDIS 42105
ISO/IEC JTC 1/SC 42
Secretariat: ANSI
Date: 2026-06-1008-12
Information technology — Artificial intelligence — Guidance for
human oversight of AI systems
DISFDIS stage
Voting begins on: 2025-11-24
Voting terminates on: 2026-02-16
ISO/IEC DISFDIS 42105:2026(en)
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 20252026 – All rights reserved
ii
ISO/IEC DISFDIS 42105:2026(en)
Contents
Foreword . iii
Introduction . iii
Scope . iii
Normative references . iii
Terms and definitions . iii
Abbreviated terms . iii
Concept of human oversight of AI systems . iii
General . iii
Objectives of human oversight . iii
Various types of human oversight . iii
Imprementing human oversight . iii
Human oversight in AI system life cycle. iii
Stakeholder roles . iii
General . iii
AI customer . iii
AI developer . iii
AI subject . iii
AI user . iii
Human oversight supervisor . iii
AI system operator . iii
Human-AI system configuration . iii
Understandings of systems . iii
Introduction to system understanding . iii
Overall systems, AI systems and human oversight systems . iii
Static aspect of the system: components and their interactions . iii
Understanding dynamic aspect of the system . iii
Human-machine interface to support human oversight . iii
Human intervention . iii
General . iii
Range of intervention . iii
Severity and ability to reverse actions . iii
Bias . iii
General . iii
Bias from interaction between AI system operators and AI systems . iii
(informative) Rationale for avoiding the use of specific terminology in this document . iii
Bibliography . iii
Foreword . v
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
© ISO/IEC 20252026 – All rights reserved
iii
ISO/IEC DISFDIS 42105:2026(en)
5 Concept of human oversight of AI systems . 2
5.1 General . 2
5.2 Objectives of human oversight . 3
5.3 Various types of human oversight . 4
5.4 Implementing human oversight . 9
5.5 Human oversight in AI system life cycle . 10
6 Stakeholder roles . 11
6.1 General . 11
6.2 AI customer . 12
6.3 AI developer . 12
6.4 AI subject . 12
6.5 AI user . 13
6.6 Human oversight supervisor . 13
6.7 AI system operator . 13
7 Human-AI system configuration . 13
8 Understandings of systems . 13
8.1 Introduction to system understanding . 13
8.2 Overall systems, AI systems and human oversight systems . 15
8.3 Static aspect of the system: components and their interactions . 18
8.4 Understanding dynamic aspect of the system . 21
9 Human-machine interface to support human oversight . 23
10 Human intervention . 24
10.1 General . 24
10.2 Range of intervention . 24
10.3 Severity and ability to reverse actions . 25
11 Bias . 26
11.1 General . 26
11.2 Bias from interaction between AI system operators and AI systems . 27
Annex A (informative) Rationale for avoiding the use of specific terminology in this document 28
Bibliography . 31
© ISO/IEC 20252026 – All rights reserved
iv
ISO/IEC DISFDIS 42105:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directivesor www.iec.ch/members_experts/refdocs). or
www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patentswww.iso.org/patents and https://patents.iec.ch.https://patents.iec.ch. ISO
and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.www.iso.org/iso/foreword.html. In the IEC, see
www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 42, Artificial intelligence.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national-
committees.
© ISO/IEC 20252026 – All rights reserved
v
ISO/IEC DISFDIS 42105:2026(en)
Introduction
AI systems can collect more data, analyse them faster and control other systems in more precise manners than
human experts. At the same time, AI systems can have unintended outputs such as unintended bias, which can
have disastrous effects.
The ability to monitor and control the target AI system enables to suppress the unintended outputs, and
enables to support safe and controlled operation of the AI system. The process to achieve the system to follow
organizational policies set by governance frameworks with the ability is called human oversight.
Human oversight comprises activities at various levels. The first level is governance and management level
activities. From the top to the bottom, these activities set goals to be achieved (e.g. the level of transparency
[5]
the AI system should achieve,) and addressed in ISO/IEC 38507ISO/IEC 38507 and ISO/IEC 42001.ISO/IEC
[7]
42001 . The second is operational level activities (e.g. the details of the information to be monitored and
controlled,) based on the capability of the AI system. This activity is the focus of this document. The third is
the controllability that defines the capability of the AI system to be controlled and monitored, (e.g. the ability
[4]
to display and change the internal states of AI systems,) and is described in TS 8200.ISO/IEC TS 8200 . The
capabilities to respond to the mandate goes from the bottom to the top.
Human oversight comprises activities at various levels. The first level is governance and management level
activities. These activities set goals to be achieved (e.g. the level of transparency the AI system should achieve,)
[5] [7]
and addressed in ISO/IEC 38507ISO/IEC 38507 and ISO/IEC 42001.ISO/IEC 42001 . The second is
operational level activities (e.g. the details of the information to be monitored and controlled,) based on the
capability of the AI system. This activity is the focus of this document. The third is the controllability that
defines the capability of the AI system to be controlled and monitored, (e.g. the ability to display and change
[4]
the internal states of AI systems,), and is described in ISO/IEC TS 8200.ISO/IEC TS 8200 .
© ISO/IEC 20252026 – All rights reserved
vi
ISO/IEC DISFDIS 42105:2026(en)
Information technology — Artificial intelligence — Guidance for
human oversight of AI systems
1 Scope
This document provides guidance on human control and monitoring of AI system ssystems, which is referred
[4]
to as human oversight. This document extends ISO/IEC TS 8200.ISO/IEC TS 8200 .
This document is applicable to all types of organizations developing and using AI systems during their whole
life cycle.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC TS 8200, Information technology — Artificial intelligence — Controllability of automated artificial
intelligence systems
ISO/IEC 22989, Information technology — Artificial intelligence — Artificial intelligence concepts and
terminology
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 22989 , ISO/IEC TS 8200 and
the following apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obp
3.1
human oversight
activities by a human intended to control an AI system
Note 1 to entry: Human oversight typically allows either exercising control, in the case of a controllable system, as defined
[4]
in ISO/IEC TS 8200:2024,ISO/IEC TS 8200:2024 , or invoking post-hoc procedures to modify the outputs, or making
operational and other changes to the AI system.
Note 2 to entry: This operational-level oversight accomplishes some goals of governance-level oversight in the sense of
[5]
ISO/IEC 38507:2022,ISO/IEC 38507:2022 , but is not identical to it, and may involve human decisions of when to
[4]
exercise control, as defined in ISO/IEC TS 8200:2024.ISO/IEC TS 8200:2024 .
3.2
human oversight supervisor
designated person
designated human with responsibility or authority for human oversight (3.1)
Note 1 to entry: This role involves supervision of the AI system, not a supervisory role within an organization.
Note 2 to entry: Human oversight supervisor can be multiple people.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
3.3
AI system operator
human handling an AI system
[6]
[SOURCE: ISO 81060-1:2007,ISO 81060-1:2007 , 3.14 - modified, changed person to human, and changed
equipment to AI system].]
3.4
Organization
human or group of people that has its own functions with responsibilities, authorities and relationships to
achieve its objectives
[7]
[SOURCE: ISO/IEC 42001:2023,ISO/IEC 42001:2023 , 3.1, removed notes to entries.]
4 Abbreviated terms
AI artificial intelligence
SaaS software as a service
AI artificial intelligence
SaaS software as a service
5 Concept of human oversight of AI systems
5.1 General
As shown in Figure 1, human oversight comprises activities at various levels, and supported by various
characteristics of AI systems. There are three-levels of activities on oversight, governance and management-
level, operational-level, and controllability. Governance activity sets the goal and mandates to the bottom.
[5]
They are described in ISO/IEC 38507:2022ISO/IEC 38507:2022 and ISO/IEC 42001:2023,ISO/IEC
[7]
42001:2023 , and is out of scope of this document. Controllability provides the capability to respond to the
[4]
mandate, from bottom to the top. It is described in ISO/IEC TS 8200:2024,ISO/IEC TS 8200:2024 , and is also
out of scope of this document.
As shown in Figure 1, human oversight is achieved based on controllable AI systems, which are described in
[4]
ISO/IEC TS 8200:2024.ISO/IEC TS 8200:2024 . The controllable AI system is monitored and controlled
primarily by humans, which is described in this document. The controllable AI systems are part of the target
ISO/IEC 38507:2022 and ISO/IEC 42001:2023.ISO/IEC
of governance and management activities described in
[5] [7]
38507:2022 and ISO/IEC 42001:2023 .
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
Figure 1 — Three-layer structure of ISO/IEC human oversight standards
5.2 Objectives of human oversight
An AI system does not always work as intended by its AI developer and its AI customer because of high levels
of system complexity and the system’s ability to operate in a highly automated manner. In addition, because
not every potential outcome can always be foreseen beforehand, unwanted side effects or consequences can
be identified only after the deployment of the AI system. For example, sometimes important cases are found
that were not included in training data after AI system deployment. In many cases these problems are
identified not by its AI developer, but by its AI customers including AI users, or sometimes bystanders.
Accordingly, it is therefore necessary to ensure AI systems do not deviate from their business objectives when
it exhibits such unintended behaviour. This is achieved by a human who directly supervises the target AI
system and closely controls the output of AI systems through its human–machine interface, and activities that
makes such oversight and control easier. The governing body sets appropriate rules and intended behaviours
for the target AI system. The human who oversees the system monitors and controls the system to ensure it
does not violate the policy (e.g. unknown side effects).
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
An AI system can have multiple objectives to achieve, (e.g. performance and security.). In human oversight, it
is important to balance the objectives. The relative priority of the multiple objectives depends on the context
and the target system including risks and level of automation.
Human oversight is a risk mitigation activity, and if done correctly, it partially mitigate specific risk. Risk
(possibly AI-specific risk) mitigation activity reduces risks to make the risk tolerable, but does not eliminate
risks completely. In this context, handling of risks of AI system are equivalent to managing the risks of
traditional systems.
5.3 Various types of human oversight
5.3.1 Considerations for human oversight implementation
There are various types of human oversight. The target AI system can be a subsystem of another AI system
and a human oversight supervisor can access the target AI system through other subsystems such as
supporting tools. Timing and the ability of intervention can vary. Finally, there can be various difficulties for
achieving effective human oversight.
NOTE Some sources use terminology such as “human on/in-the-loop” or “human-in-command”. While these terms
have engineering origins, they have increasingly been adopted by policymakers, the media and others for policy, legal or
other purposes. In the context of AI systems, “loop” and “command”-related terminology can be ambiguous, imprecise
and often suggestive of a level or form of oversight or controllability that is not, in reality, possible. Annex A details the
rationale for why the authors of this standard purposefully decided to not make use of terms involving “loop” or
“command” in connection with humans and AI systems.
5.3.2 Target AI system of human oversight
5.3.2.1 Range of target AI system
The term 'AI system includes whole AI products and related services, i.e. AI functionalities as well as system
interfaces, business logic implementations, computing resources and physical facilities. See ISO/IEC TS
[4]
8200:2024,See ISO/IEC TS 8200:2024 , Figure 1 for more details.
The AI system to be overseen is sometimes comprises multiple subsystems. In some cases another system, or
a supporting tool is added as a subsystem. The human oversight supervisor, responsible for conducting human
oversight, is expected to supervise the whole system even if such tools are added.
Depending on who develops the system, there can be three patterns for the target AI system and human
oversight supervisor, as shown in Figure 2.
Pattern 1: human oversight supervisor directly monitors and controls the AI system provided by AI developer,
or the target AI system.
Pattern 2: AI developer provides AI or non-AI system (supporting tool) as well as main AI system. Target AI
system includes both main AI system and supporting tool.
Pattern 3: AI customer adds third party’s additional AI or non-AI systems to main AI systems provided by AI
developer. Target AI system includes both main AI system and supporting tool.
Pattern 2 and 3 can co-exist (e.g. when different tools are used by different opertorsoperators.).
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
Figure 2 — The target AI system of human oversight
The reason why a target AI system can include supporting tools is so that human oversight can be applied to
final output that affect either the AI user(s) or AI subject(s), or both. In the event of a malfunction of supporting
tools, the human oversight supervisor can provide relevant input or observations; however, responsibility for
the root cause analysis remains with the AI developer or the AI customer.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
5.3.2.2 Supporting tools
[4]
According to ISO/IEC TS 8200:2024,ISO/IEC TS 8200:2024 , 6.1, when an AI system is controllable, it can
implement a set of facilities for system state observation that provide views of system parameter values and
appearance to external humans or agents. In the context of human oversight, such facilities can be directly
used or indirectly invoked or operated by humans through other systems (see 5.3.2.1).
Those facilities for system state observation can be programmatically encapsulated or physically operated by
supporting tools that implement more complex workflows according to requirements of oversight.
Various supporting tools should be designed and implemented for human oversight and used in addition to
the system state observation facilities provided by the AI system itself. There can be a safety jacket that filters
unfavourable output and prevents dangerous behaviour of automated systems, translation system or remote
monitoring system. See 8.4.3 for more details on supporting tools for explainability and transparency.
5.3.3 Timing and level of human intervention
In human oversight, there are a variety of factors that can materially change the character of the oversight.
For example, timing of monitoring and resulting execution of human control and intervention, preciseness of
how the control is reflected to the target AI systems and whether the output of AI systems is modified because
of the intervention, affects the result of the human oversight activity, (e.g. if the output of the AI system is
changed before it affects other systems.). In addition, the preciseness of the control is described as the
[4]
controllability level in ISO/IEC TS 8200:2024,ISO/IEC TS 8200:2024 , 7.3, from not controllable to
completely controllable.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
a) Real-time monitoring and intervention (e.g. autonomous bus)
b) Real-time monitoring and post-incident intervention (e.g. stock brokering system)
c) Post monitoring and intervention (e.g. recruitment supporting system)
Figure 3 — Timing of monitoring and intervention
The monitoring activity of human oversight can be done in a real-time manner, with structured triage
mechanisms, (e.g. in an automated bus monitored by human oversight supervisor,) as shown in Figure 3
(a),Figure 3 a), or stock brokering system in Figure 3 (b).Figure 3 b). It can also be done as a post-incident
activity as shown in Figure 3 (c),Figure 3 c), e.g. in a recruitment supporting system by collecting the output
of AI systems and by analysing it using the statistical method.
Control and intervention activities are done in real-time manner as in Figure 3 (a),Figure 3 a), or are done in
post-incident manner as in Figure 3 (b)(c)Figure 3 b) Figure 3 c) including, when processes operate very fast
and handle huge amounts of data, which would make it impossible for humans to understand the situation
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
and react in a timely manner even when the system is othersiweotherwise completely controllable. See Clause
8 and 10.2 for more details.
The output of the target AI system is changed before it affects other systems in real-time monitoring and
intervention, if controllability level is sufficient. It can be changed in post-incident intervention by providing
[8]
corrected outputs on logged errors (see ISO/IEC FDIS 24970ISO/IEC FDIS 24970 for details). Post-incident
intervention can involve preventing repetition of errors by changing the configuration, debugging and
updating the system and other means, noting however that this is not an exhaustive list.
[9]
ISO/IEC 22989:2022,ISO/IEC 22989:2022 , 5.13 describes 7 levels of automation, no automation (level 0) to
autonomy (level 6). At high automation (level 4), the system performs parts of its mission without external
intervention. At full automation (level 5), the system is capable of performing its entire mission without
external intervention. For systems whose level of automation is equal to or less than four, real-time control
and intervention is more feasible. In these systems, to obtain the final result, a human takes some action, which
influences the result. For systems whose level of automation is more than four, post-incident intervention
becomes an important method. However, quasi-real-time intervention (e.g. pushing a stop button) can often
be designed and built in.
5.3.4 Effectiveness of human oversight
As described in 5.3.3, human oversight is sometimes not able to or is insufficient for meeting broader
objectives. That is, it is not always possible for a human oversight supervisor to:
— intervene and change the output of AI systems when such intervention would be desirable, or
— prevent undesirable AI system outputs from adversely affecting others or leading to other forms of harm.
There are several considerations for effective human oversight. One key consideration is context dependency:
what constitutes a preferable output—and the acceptable degree of deviation from it—depends on the
context. Another important consideration is human factors. Human behaviorbehaviour is influenced by
various factors. Issues that have no direct relationship with the target AI systems, such as recent airplane
accidents or personal conditions like hunger, can influence human behaviorbehaviour and, consequently, the
performance of human oversight.
Human factors engineering therefore takes into account factors such as individuals, teams, technology,
organizational structures, procedures, and the operating environment, and contributes to the design of socio-
technical systems. This includes task allocation, interfaces, procedures, training, workload, and organizational
conditions, all of which together influence how humans interact with and oversee AI systems. IEC 62366-1,
[12] [10] [11] [12]
ANSI/AAMI HE75 and IEC 62366-1 , ANSI/AAMI HE75 and can be a starting point.
AI systems are usually deployed in scenarios where there are challenges for direct human control (e.g. places
where the amount of data, requested processing speed, complexity of algorithms) are uneconomical, difficult
or impossible for human operators to realize. It is therefore difficult or impossible for human experts,
including the human oversight supervisors or the human operators to understand all data in real-time.
Organisations should take into account the following factors when selecting methods:
— timing and level of human intervention;
— level of understanding of the situation; the environment of the system is sometimes well-understood, and
prediction is precise, while sometimes vague and irregular incidents are common;
— time allowed for human reaction; some transactions end in microseconds, while some transactions can
wait hours;
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
— reliability of systems, in particular communication; sometimes connection between human oversight
supervisor and the system is down;
[4]
— AI system controllability (ISO/IEC TS 8200).ISO/IEC TS 8200 ).
5.4 ImprementingImplementing human oversight
5.4.1 General
As described in 5.2, human oversight activity is necessary at various level in order to reduce the potential risk
of AI systems. Some human oversight approaches could even allow intervention by a human outside of the
direct human oversight chain (e.g.,. a bystander) in order to prevent disastrous consequences.
However, there are two key personnel in human oversight: human oversight supervisor and AI system
operator. In some cases, these roles can overlap or even be the same people.
5.4.2 Human oversight supervisor and AI system operator
Human oversight in operation and monitoring phase is implemented by an AI developer, an AI deployer or an
AI customer, by using methods provided by the AI developer. The AI customer can assign the task to a human
oversight supervisor, who can be an AI customer or can be a third-party human delegated with the task by the
AI customer.
The target AI system is operated by its AI system operator, and both AI system and AI system operator are
overseen by a human oversight supervisor.
Human oversight supervisors are humans, and are trained in at least these areas:
— good knowledge of AI system risks;
— good knowledge of biases related to AI system;
— sufficient subject matter expertise on the context and goals of the AI system;
— understanding of the relevant capacities, limitations and possible risks of the target AI system;
— ability to monitor, detect and mitigate risk using the tools provided by the AI developer.
The training should not just be initial or static. Oversight is strengthened by periodically reviewing training as
experience develops.
In addition, a human oversight supervisor has sufficient authority and incentive ascribed by an AI customer
to intervene in the operation of an AI system. And should consider issues e.g.
— Human oversight supervisor incentives should be aligned with quality rather than just throughput.
Compensation or performance structures which emphasize volume over careful evaluation can encourage
superficial review;
— Conflicts of interest are important in some circumstances, for example if someone is overseeing AI grading
of tests/exams, they should not oversee the grading of a family member exam;
— Human oversight supervisor need breaks to mitigate fatigue. Time pressure should also be limited. People
need time to engage in critical thinking about AI operation and outputs;
— When human oversight supervisors works as a team, diversity should be considered.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
AI system operators are experts in the operation of the AI system (e.g. a crew of an automated bus), or are
users of the AI system (e.g. a recruiter using recruitment AI system). If the AI system is highly automated (level
[9]
5, 6 of ISO/IEC 22989:2022,ISO/IEC 22989:2022 , 5.13), AI system operators are not always operating the
target system.
AI system operators can identify risks during their operations. They can mitigate the risks by themselves or
by notifying the human oversight supervisor.
AI system operators can also be a human oversight supervisor if the policy of the AI customer allows, and in
this case collaboration with an independent human oversight supervisor can further enhance safety.
Operators with expertise can also be human oversight supervisors, if AI customer's policy allows this
responsibility. AI system operators can have less knowledge of AI systems and less ability to detect risks. AI
customers can decide if AI system operators can act as human oversight supervisors or if they should assign
others, factoring in the risks of the AI system and the capabilities of the operator. AI system operators, AI
supervisors and all involved humans can themselves be a cause of unwanted bias, and supervisors can even
affirm unwanted biases. It is therefore important that they are sufficiently trained to recognize biases in their
own thinking and actions in the processes, in addition to other risks.
5.4.3 Observation of testing by the human oversight supervisor
It is desirable for human oversight supervisors to participate in the testing of the target system, in particular
testing in design and development phase or verifiationverification and validation phase, in order to deepen
their understanding of the system and to improve the system from the viewpoint of human oversight. Human
oversight supervisors can carry out different activities as decided by the organization based on its policies.
AI customers integrate AI systems provided by AI developers into their own business systems, use them after
conducting the necessary learning. The following benefits are expected from the involvement of a human
oversight supervisor in testing of AI systems.
Understanding of the behaviour of the AI system: in order for the human oversight supervisor to judge
anomalies in the AI system, it is necessary to understand its normal behaviour. It is useful to witness tests
carried out on various cases and to oversee the behaviour of the AI system.
Understanding of changes in the AI system due to continuous learning: the human oversight supervisor
is expected to understand that the AI system can change day by day due to continuous learning. The changes
in the behaviour of the AI systems should be monitored during the continuous validation phase of the life
cycle.
Understanding diversity and unwanted bias: the human oversight supervisor should be able to recognize
unwanted biases in the AI system and determine whether they are problematic in the context of the particular
AI system and its purpose. The ability for understanding the target AI system can be improved through joining
the testing and reviewing diverse inputs and outputs of the AI system.
For newly appointed human oversight supervisor, witnessing the testing can be part of their training, while
experienced human oversight supervisor can advise the testers based on their experience.
5.5 Human oversight in AI system life cycle
[9]
ISO/IEC 22989:2022,ISO/IEC 22989:2022 , Figure 3 shows the AI system life cycle model stages and high-
[13]
level processes. A more detailed life cycle is described in ISO/IEC 5338.ISO/IEC 5338 .
Human oversight is done in every stage of AI system life cycle.
Inception, Design and development: AI producers should design their AI systems to facilitate human oversight
by AI customers and incorporate supportive features and tools (see Clause 7).
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
[9]
Verification and validation: In ISO/IEC 22989:2022,ISO/IEC 22989:2022 , Figure 3, "verification and
validation" is supposed as a process on the AI producer side, and is positioned prior to "deployment".
However, from the perspective of human oversight, "verification and validation" by AI customer should also
be positioned after "deployment", because impacts can be arising from integration with other systems,
additional training of AI systems, characteristics (e.g. human bias) of human users, prompts to input, and other
factors.
Deployment: AI system can be deployed to different environments. Human oversight functionalities should be
configured in an optimized manner for each environment.
Operation and monitoring: This process includes both conventional operation and monitoring by personnel
of IT departments, and the human monitoring defined by this document. Ideally, these two types of activity
should be conducted independently and in parallel, because human monitoring is related to user-side aspects
such as human bias, transparency, explainability, etc. It is also effective that personnels of IT department
perform basic human oversight during operation and human oversight supervisor conducts comprehensive
human oversight including those personnel.
Re-evaluate: By reviewing the results of the AI systems in the operation and monitoring stage, AI systems can
[9]
be modified, e.g. its objective can be refined as described in ISO/IEC 22989:2022,ISO/IEC 22989:2022 , 6.2.8.
This is a governance and management level activity and details are not described in this document.
Retirement: Systems should be designed up front to support updates and retirement, and designed to support
adequate human oversight over the updating and retiring processes. Overseeing AI specific issues (e.g. data
disposal) by human oversight supervisor can increase trustworthiness of the process.
Other AI systems can be used to assist the human oversight supervisor in the supervisor's monitoring role at
some stages.
6 Stakeholder roles
6.1 General
[9]
For the purposes of this document, stakeholder roles given in ISO/IEC 22989:2022,ISO/IEC 22989:2022 ,
5.19 apply, with explanations in human oversight, and with two new stakeholders (human oversight
supervisor and AI system operator). Note that these roles vary greatly with details of the system in question,
and the managerial and operational structure. The decisions about how each role interacts with other roles
and with the system are design, management and governance decisions as discussed in ISO/IEC 42001 and
[7] [14]
ISO/IEC 22989.ISO/IEC 42001 and ISO/IEC 22989 .
Critical stakeholders (AI developer, AI customer, human oversight supervisor, AI system operator or AI user
and AI subject) with relevant objects (e.g. AI system) are shown in Figure 4.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 42105:2026(en)
Key
solid arrow action always taken
dashed arrow action possibly taken
Figure 4 — Stakeholders of human oversight
6.2 AI customer
An AI customer can conduct a risk assessment before deploying, using or providing AI systems, and can
delegate human oversight to a hu
...







