Skip to content
Changefy Research — State of Governed AI Operations 2026Read it
Changefy
← Blog

Aug 25, 2026 · 5 min read

"Human in the loop" is not a safety property

"Human in the loop" gets treated as a binary — either a person is in the approval chain or they aren't, and if they are, the system is safe. That's not true. A person can be technically in the loop while providing almost no meaningful oversight at all.

Give an engineer 100 agent-generated approval requests a day, and if 99 of them are correct, their review behavior changes: they scan, then click, then eventually trust. That's not a hypothetical — research on deployed coding agents has found exactly this pattern, with the most experienced users approving in bulk far more often than newcomers.

The fix isn't asking humans to be more vigilant. Humans are poor deterministic policy engines; expecting sustained attention over routine approvals is expecting people to do a machine's job. The fix is designing approval requests that are actually decidable — not "allow agent to continue? yes/no," but the exact resource, the exact action, the blast radius, and the rollback path, stated plainly enough that a reviewer can reason about it in seconds instead of trusting a label.

Changefy's plans are built around that distinction. Every plan states risk, blast radius, dependencies, and rollback explicitly — not because it's more thorough, but because that's the difference between an approval that means something and one that's rubber-stamped.