By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Knowbe4Published January 19, 2026

TL;DR: The EU AI Act sets a four-tier, risk-based compliance model for AI systems, requires human oversight for high-risk use cases, and warns that non-compliance can trigger fines of up to 7% of global annual turnover or €35 million, according to Knowbe4. Human oversight is no longer a policy statement; it is a control obligation that must be operationalised across access, decision rights, and accountability.


At a glance

What this is: This whitepaper explains the EU AI Act’s risk-based structure, the organisations most affected, and how human risk management supports compliance.

Why it matters: It matters because AI governance now intersects with IAM, accountability, and oversight controls, especially where human intervention, access approval, or override rights must be demonstrated.

By the numbers:

👉 Read Knowbe4's whitepaper on the EU AI Act and human risk management


Context

The EU AI Act is a governance framework for AI systems, but its practical burden lands on the organisations that build, deploy, and oversee those systems. For security and identity teams, the key issue is not only model behaviour but also who can approve, monitor, intervene in, and audit AI-driven decisions.

That makes the Act relevant to IAM and governance programmes even when the subject is not traditional identity. Human oversight requirements create a control problem: organisations must prove that people with the right authority, training, and access can intervene when high-risk AI systems behave outside acceptable bounds.


Key questions

Q: How do organisations keep human oversight meaningful in AI workflows?

A: Human oversight stays meaningful only when humans have enough context, time, and authority to intervene. If the AI output is acted on automatically or too quickly to challenge, oversight becomes ceremonial. Effective oversight requires review points, clear escalation rights, and the ability to halt or reverse the decision.

Q: Why does this kind of kernel flaw matter to identity and access teams?

A: Because it compromises the host material that identity systems rely on. SSH host keys support trust relationships, and shadow-file exposure can support offline credential cracking. When those assets leak, the issue is not only infrastructure hardening. It becomes an identity confidence problem that can affect privileged access across Linux estates.

Q: What do teams get wrong about human risk management in AI governance?

A: They often treat it as awareness training rather than a control layer. The Act requires humans who can actually interpret outputs, intervene, and override system behaviour. That means role design, competency, and evidence collection matter as much as policy content.

Q: Who is accountable when an AI system makes a harmful decision?

A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.


Technical breakdown

How the EU AI Act risk tiers change control requirements

The Act uses a four-tier risk model to scale obligations to the potential harm of an AI system. Prohibited systems are barred, minimal-risk tools face lighter expectations, and high-risk systems require structured governance around risk management, documentation, transparency, and human oversight. The important operational point is that compliance is not uniform. Teams must map each AI use case to the correct tier, then align controls to that tier rather than treating every model the same.

Practical implication: maintain an inventory of AI use cases and classify each one before assigning controls or approval workflows.

What human oversight means in practice for high-risk AI systems

Human oversight under the Act is not symbolic review after the fact. It requires people to interpret AI outputs, intervene when needed, and override system behaviour where risk or error demands it. That creates a governance dependency on trained humans, documented authority, and operationally usable escalation paths. If people cannot understand the decision context or cannot act quickly enough, oversight exists only on paper.

Practical implication: define who can intervene, when they can override, and how that authority is logged and reviewed.

Why human risk management becomes a compliance control

Human Risk Management and Security Awareness Training matter because the Act assumes people can carry out oversight responsibilities consistently. That means organisations need more than policy acknowledgements. They need role-based training, evidence of comprehension, and process checks that connect human behaviour to AI governance outcomes. In identity terms, this is a control issue around accountability, delegated authority, and assurance that the right people can exercise the right action at the right time.

Practical implication: tie oversight roles to access, training, and attestations so compliance evidence is operational rather than theoretical.


NHI Mgmt Group analysis

The EU AI Act turns human oversight into an access and accountability problem, not just a policy obligation. High-risk AI systems must support interpretation, intervention, and override, which means organisations need defined authority boundaries and auditable decision rights. For IAM and governance teams, the challenge is to prove that specific humans are authorised, trained, and able to act when an AI system needs to be stopped or corrected. The practical conclusion is that oversight cannot be separated from identity governance.

Risk tiering creates a useful governance boundary, but only if organisations maintain a live inventory of AI use cases. The Act’s four-tier structure works only when teams can classify systems accurately and keep those classifications current as models, data, and use cases change. Without that inventory discipline, high-risk systems can drift into production with weaker controls than the law expects. The practical conclusion is that AI inventory management becomes a compliance control in its own right.

Human Risk Management is the operational bridge between AI policy and enforceable control. The whitepaper is right to connect oversight with training, because oversight fails when staff cannot interpret outputs or exercise authority under pressure. That creates a direct link to role-based access, approval workflows, and evidence of competency. The practical conclusion is that organisations should treat human readiness as part of AI control design, not as a soft awareness exercise.

For identity programmes, the real lesson is that delegated decision-making needs delegated control. AI governance cannot rely on informal escalation paths or ad hoc intervention. If the people responsible for oversight are not mapped to explicit authority, the control environment will not satisfy regulators or internal audit. The practical conclusion is to align AI oversight with identity governance, privilege management, and attestable accountability.

What this signals

The EU AI Act will push security and governance teams toward more explicit accountability mapping, especially where AI outputs influence operational decisions. For programmes already managing identities, the next step is to tie oversight roles to access rights, training evidence, and auditable intervention paths. The control question is not whether people can be involved, but whether they can intervene at the right moment with the right authority.

AI oversight maturity: organisations will increasingly need proof that human reviewers are not only designated but competent, available, and empowered to act. That pushes AI governance closer to IAM and PAM disciplines, where authority, escalation, and auditability are already familiar control patterns. Teams that cannot show this connection will struggle to demonstrate effective oversight under the Act.


For practitioners

  • Map AI systems to EU AI Act risk tiers Create and maintain an inventory of AI use cases, owners, data sources, and deployment contexts. Classify each system against the Act’s risk tiers before it enters production and review the classification whenever the use case changes.
  • Define and test human override authority Assign named individuals or roles the authority to interpret, intervene, and override high-risk AI decisions. Document the conditions for intervention and test the escalation path in exercises so the authority is usable in practice.
  • Bind oversight roles to training and attestations Require role-specific training for people who supervise AI systems and retain evidence that they understand the decision context, limits, and escalation duties. Use periodic attestations to show competency is current, not assumed.
  • Align AI governance evidence with audit-ready controls Capture logs, approvals, exceptions, and intervention records in a form that supports regulatory review and internal audit. Treat oversight records as compliance evidence, not as informal operational notes.

Key takeaways

  • The EU AI Act makes human oversight a regulatory control, not a soft governance ideal.
  • Risk tiers matter because compliance obligations change materially as AI systems become more consequential.
  • Security and identity teams should connect oversight duties to named roles, training evidence, and auditable intervention paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF and NIST CSF 2.0 set the technical controls, while EU AI Act, ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
EU AI ActArt.14Article 14 is central because the whitepaper focuses on human oversight obligations.
NIST AI RMFGOVERNThe whitepaper links AI compliance to accountability, oversight, and governance structure.
NIST CSF 2.0PR.AT-1Training and competency evidence are core to human risk management in this context.
ISO/IEC 27001:2022A.5.15Access control is relevant where human override and supervision rights must be bounded.
GDPRArt.32The Act’s transparency and oversight themes intersect with controls for personal data processing.

Map high-risk AI use cases to Article 14 and require explicit intervention and override procedures.


Key terms

  • High-Risk AI System: A high-risk AI system is one whose outputs can materially affect a person’s rights, opportunities, or safety. These systems need stronger oversight because errors, bias, or unauthorized actions can create legal exposure as well as security and trust problems.
  • Human Oversight: Human oversight is the requirement that a person remains responsible for reviewing, approving, or correcting AI-driven output before it causes a material action. In governance terms, it is the control that prevents automation from becoming unowned authority.
  • Risk tiering: Risk tiering is the practice of grouping vendors by the level of exposure they create based on data access, system criticality, and business dependency. It lets organisations spend more control effort where the blast radius is largest and keep lower-risk relationships under lighter governance.
  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.

What's in the full report

Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Detailed explanation of the EU AI Act's four risk categories and how obligations scale by tier
  • Specific interpretation of Article 14 human oversight requirements for high-risk AI systems
  • How human risk management and security awareness training support compliance evidence
  • Why organisations should align oversight, accountability, and intervention processes before deployment

👉 The full Knowbe4 whitepaper covers the risk tiers, human oversight obligations, and compliance framing in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It helps practitioners connect accountability, access, and operational evidence across identity programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org