KarminaAI StudioAgents · Services · Training
A process assisted by AI with human reviews before the most impact actions.

INSIGHTS · GUIDE

Human review is not the last step: it is part of the agent’s design

Checking at the end is not enough if no one knows what to check. Supervision must be designed according to the impact of each action and must include responsibilities, information and intervention capacity.

Karmina AI Studio · Governance · 2025

Adding “revised by a person” at the end of a process can convey reassurance, but does not guarantee effective supervision. If the person does not know what source the agent has used, what errors are likely or what authority he has to stop the action, the review becomes a formality. Automation bias can also appear: the tendency to rely on a result because the system has presented it with security and appearance of precision.

Human supervision should not function as a net at the end. It must be designed at the same time as the agent's mission, permissions, and flow.

Not all actions need the same control.

Preparing an internal summary, suggesting a headline, submitting a public response, or modifying a budget have different consequences. A good architecture classifies actions according to the impact, reversibility, the data involved and the possibility of detecting the error.

Low-risk tasks may be performed with periodic samples or subsequent checks. Actions affecting customers, money, reputation, rights or personal data may need prior approval. Certain decisions should not be automated, even if it is technically possible.

This criterion avoids two extremes: manually reviewing each step until automation stops providing value, or granting autonomy simply because the tool allows it.

What the person overseeing needs

The responsible person must know the purpose of the agent, its capabilities and its limits. You also need to see what sources have supported the result, detect when information is missing and understand the consequences of approving an action.

The interface or review document should facilitate this work. It is not enough to show one answer and two buttons. It may be necessary to highlight the sources, the changes, the sensitive data, the level of trust, the exceptions and the reason why the case has come to review.

The person should also be able to ignore, correct, reverse, or stop the outcome. If it can only confirm, it is not monitoring; it is formally validating a decision that the system has already made.

Human Gates within the process

A Karmina AI Studio Human Gates the points where an action changes level of responsibility. They can appear before publishing, sending, modifying, deleting, sharing data or assuming a commitment with an external person.

A Ads Monitor can detect anomalous spending and prepare a recommendation, while a manager approves of any budget changes. A Support Desk can answer authorized frequently asked questions, but escalates a claim or a commercial exception. A Blog Publisher can prepare the text, the SEO structure, and metadata, but publication is blocked until editorial review.

Checkpoints should be documented with alternate controllers, deadlines and a procedure for unanswered cases. An approval that no one attends to can paralyze the process or lead the team to skip control.

Supervision, registration and learning

The revised errors are a source to improve the system, as long as they are recorded. It is convenient to differentiate between an editorial preference, an obsolete source, an ambiguous instruction, a technical problem and an action that should never have been proposed. Every cause needs a different correction.

The registry also allows detecting if the agent is degrading, if a new version has changed behavior, or if a person systematically approves without review. Governance is a continuous process: defining, observing, measuring, and correcting.

NIST’s voluntary risk management framework organizes this work around governance, mapping, measurement and management, and includes the definition and documentation of human oversight processes. It is a useful reference for structuring controls, although it does not replace the legal obligations applicable in each case. NIST AI Risk Management Framework.

The Legal Context Matters

The European Artificial Intelligence Regulation includes specific human monitoring requirements for systems classified as high risk. The article 14 points out, among other capabilities, to understand limitations, detect anomalies, avoid excessive confidence and be able to ignore or reverse results. Not all marketing agents are high-risk systems, but these questions offer a useful design reference when the impact increases. Article 14 of the European Regulation of AI.

When the process processes personal data, the supervision does not eliminate the obligations of purpose, minimization, security or responsibility. The organisation remains responsible for complying with the applicable principles and being able to demonstrate this. Principles of GDPR as explained by the European Commission.

The legal classification and the necessary measures must be reviewed according to the use, the sector and the people affected; a commercial page cannot certify this compliance.

Responsibility must have a name.

Saying “there will always be a person” is not enough. Each agent needs an owner, authorized users, responsible for approval and an incident circuit. It also needs an update policy and a decision on who can expand permissions or change sources.

Human supervision works when the person has information, time, authority and training. If one of these conditions is missing, control can exist on the diagram and disappear in actual operation.

People do not have to check because we distrust all automation. They must intervene at the points where criteria, rights and responsibility cannot become a simple instruction.