Nominal supervision does not constitute actual control
Aliases: nominal supervision · human-in-the-loop fallacy · effective control
What it is
Meaningful human control requires a supervisor to understand relevant state, foresee consequence, and alter or stop action within an effective window. Sitting at a screen, signing approval, or having a stop button establishes presence, not causal control over a decision.
Why it happens
Control depends jointly on information, attention, time, authority, and reversibility. Automation can process rapid events while supervision sees delayed aggregates. If intervention is slower than hazard and braking, the human becomes an accountability buffer. Nominal oversight can also discourage automatic safeguards.
Studying it
Preventability analysis should identify when enough information arrived, when action was possible, and when it took physical effect. Comprehension, response distributions, authority barriers, and prevented outcomes matter more than presence. Long quiet periods and simultaneous events are necessary.
Where it stops holding
Meaningful control does not require manual execution or reject high autonomy; it requires real capability at the accountable level. Fast hazards belong to automatic protection. Sufficient control still does not make the operator responsible for every failure.
Applying it
- For every “human supervision” claim specify information, judgement, entry point, total delay, and preventable consequence.
- If high-percentile human and worst system delay cannot prevent harm, remove the human-backstop assumption and automate protection.
- Drill nonresponse, diverted attention, and concurrent anomalies to audit presence versus controllability.