AI governance
From human-in-the-loop to AI-on-the-loop
In several operational domains AI now checks work more reliably than human reviewers, particularly at scale and over long horizons. The governance regimes still assume a person is accountable, so the architecture has to change, not just the tooling.

Human review degrades in exactly the conditions where checking matters most: high volume, long duration, low base rate of defects. An automated checker does not get bored on the four-thousandth item. That is a real advantage and it is worth taking.
The complication is that both EU and Singapore governance regimes assume a human is ultimately accountable for the outcome. Replacing the reviewer with a model does not transfer that accountability, so the oversight architecture has to be redesigned around a person who is now supervising a checker rather than performing the check.
What the redesign requires
- Redefined human oversight: the person's job becomes sampling, threshold-setting and exception handling, and the competence required changes with it.
- Multi-layered independent controls, so one automated checker is not both the reviewer and the only thing reviewing the reviewer.
- Full auditability of the checking layer itself, not only of the system being checked.
- A maintained human fallback and override path that is exercised rather than merely documented.
The regulatory test
The question a regulator asks is not whether the control layer is automated. It is whether the control layers are explainable, monitored, and attributable to someone by name.
For smart city and infrastructure operations that is the difference between an oversight design which survives an incident review and one that collapses into nobody having been responsible.