Questionnaire answers · AI topics · Article 14(1) · Article 26(2)
How to answer human oversight questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Say who can review, override or stop each AI system's output, and show it. For a high-risk system the provider designs it so people can oversee it effectively (Article 14) and the deployer assigns that oversight to people with the competence, training, authority and support to do it (Article 26(2)). Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Can a person review or override the AI's output?”
- Q2“Who oversees the AI system in use?”
- Q3“How do you prevent over-reliance on AI output?”
- Q4“Can the system be stopped?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: Can a person review or override the AI's output?
- Direct answerYes, partly or no first
- Yes, for the two AI features that draft text for users.
- ControlWhat you actually do
- The user accepts, edits or rejects every draft before anything is sent.
- ScopeWhich AI systems
- Reply drafting and ticket summaries. Not the spam filter.
- EvidenceWhat you can show
- A screenshot of the review step and the log entry of one accepted draft, dated 1 October 2026.
- ExceptionsBe honest
- The spam filter moves messages without review; each move is logged and can be undone.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCA screenshot of the review, override or stop step as the user sees it.
- DOCThe log entry of one decision a person made on the output.
- DOCFor a high-risk system, the training record of the people assigned to oversight.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
Article 14(1)- a high-risk system is designed, including with appropriate human-machine interface tools, so that natural persons can effectively oversee it while it is in use.
- Article 14(4) lists what those persons are enabled to do, as appropriate and proportionate: understand the system's capacities and limitations and monitor it, stay aware of automation bias, interpret the output, decide not to use it or to override it, and intervene or stop it safely.
- For remote biometric identification under point 1(a) of Annex III, Article 14(5) adds that no action or decision is taken on an identification unless at least two natural persons with the necessary competence, training and authority have verified it, except for law enforcement, migration, border control or asylum where Union or national law considers that disproportionate.
Read Article 14 on EUR-Lex ↗ Article 26(2)the deployer assigns human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.
Read Article 26 on EUR-Lex ↗
What Complipath does
- ✓Named owners A person behind every system and every duty
- ✓Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
- ✓Evidence management A file linked to the requirements it proves, with the passage and its page
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Full risk-management lifecycle Not supported Article 9 is listed as a duty with its date. There is no risk register to run the cycle in.
Questions
Do we need human oversight if our AI is not high-risk?
The duties of Articles 14 and 26(2) attach to high-risk systems. For other systems a buyer may still ask, and the honest answer is what you do: who reviews the output, and how. Say plainly that the Act's oversight duties do not apply, with the classification that shows why.
Is a human in the loop enough?
Only if the person can actually act on the output. Article 14(4) is about what the person is enabled to do: understand the system, notice over-reliance, interpret the output, override it and stop the system. A reviewer who cannot do those things is a step in the process, not oversight.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.