TL;DR: The EU AI Act sets a four-tier, risk-based compliance model for AI systems, requires human oversight for high-risk use cases, and warns that non-compliance can trigger fines of up to 7% of global annual turnover or €35 million, according to Knowbe4. Human oversight is no longer a policy statement; it is a control obligation that must be operationalised across access, decision rights, and accountability.
NHIMG editorial — based on content published by Knowbe4: What Is the EU AI Act, Who It Will Impact, and How Can Human Risk Management Help?
By the numbers:
- Non-compliance can result in fines of up to 7% of global annual turnover or €35 million.
Questions worth separating out
Q: How do organisations keep human oversight meaningful in AI workflows?
A: Human oversight stays meaningful only when humans have enough context, time, and authority to intervene.
Q: Why does this kind of kernel flaw matter to identity and access teams?
A: Because it compromises the host material that identity systems rely on.
Q: What do teams get wrong about human risk management in AI governance?
A: They often treat it as awareness training rather than a control layer.
Practitioner guidance
- Map AI systems to EU AI Act risk tiers Create and maintain an inventory of AI use cases, owners, data sources, and deployment contexts.
- Define and test human override authority Assign named individuals or roles the authority to interpret, intervene, and override high-risk AI decisions.
- Bind oversight roles to training and attestations Require role-specific training for people who supervise AI systems and retain evidence that they understand the decision context, limits, and escalation duties.
What's in the full report
Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Detailed explanation of the EU AI Act's four risk categories and how obligations scale by tier
- Specific interpretation of Article 14 human oversight requirements for high-risk AI systems
- How human risk management and security awareness training support compliance evidence
- Why organisations should align oversight, accountability, and intervention processes before deployment
👉 Read Knowbe4's whitepaper on the EU AI Act and human risk management →
EU AI Act compliance: what human oversight now means for teams?
Explore further
The EU AI Act turns human oversight into an access and accountability problem, not just a policy obligation. High-risk AI systems must support interpretation, intervention, and override, which means organisations need defined authority boundaries and auditable decision rights. For IAM and governance teams, the challenge is to prove that specific humans are authorised, trained, and able to act when an AI system needs to be stopped or corrected. The practical conclusion is that oversight cannot be separated from identity governance.
A question worth separating out:
Q: Who is accountable when an AI system makes a harmful decision?
A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.
👉 Read our full editorial: EU AI Act compliance turns human oversight into a governance test