Human-in-the-Loop describes an AI approval process in which a human reviews and approves an AI result before it takes effect. AI approval process This is always necessary when an AI result is not only prepared internally, but also has an external impact: as website text, support answer, offer, translation, evaluation or decision with financial, legal or reputational consequences. Human-on-the-Loop This means that a human monitors an ongoing AI process and only intervenes if abnormalities are detected. Human-out-of-the-Loop This means that a process takes place without ongoing human intervention. For SMEs The appropriate option is not a technical question, but a question of take on, Quality Control and risk.
In my work with owner-managed businesses in South Tyrol and the DACH region, I repeatedly see the same pattern: AI rarely fails because of the software. AI fails because of unclear responsibilities. If it's not defined who reviews, who approves, and when a case escalates, what was initially supposed to be time saved quickly turns into additional coordination effort.
AI only saves time if it is clear beforehand who is allowed to say no in case of doubt.
At Berger+Team in Bolzano, we don't think of AI in isolation. We combine branding, websites, content, processes, and automation into a single system. That's precisely why... human checkpoints not at the end of a project, but at the beginning of the planning.
When an AI approval process is necessary for SMEs
The short answer is: whenever a mistake becomes expensive, visible, or has human implicationsNot every AI process requires the same level of control. But every AI process needs a conscious decision about whether human approval is necessary, where it takes place, and who bears the responsibility.
Legally, the direction is clear. For high-risk AI systems, Article 14 of the EU AI Regulation requires effective human oversight, tailored to the risk, level of autonomy, and context of use. Additionally, Article 22 of the GDPR limits exclusively automated decisions with legal or similarly significant effects and requires safeguards such as human intervention in relevant cases. You can find the linked legal sources below in the source block.
For SMEs, this can be translated into three simple practical steps:
- Approval is mandatory or very close to mandatory: when an AI result makes decisions about people, influences contracts, sets prices, assesses creditworthiness, processes sensitive personal data, or triggers significant consequences.
- Release is urgently needed: when content is published, creates brand impact, contains legally sensitive statements, or is directly incorporated into sales and customer communication.
- Approval may be omitted: if the AI performs purely internal preparatory work, has no external impact, and errors are easily recognizable and easily reversible.
The important thing here is that Risk class of the process. For everyday use in small businesses, a simple internal classification into low, medium, and high is often sufficient. This internal risk class does not replace a legal classification, but it helps with practical decision-making.
Human-in-the-loop, human-on-the-loop and human-out-of-the-loop in comparison
The three models sound similar, but in practice they lead to different processes. This is precisely where many misunderstandings arise.
| Model | Human role | Typical use | Risks | Suitable for SMEs? |
|---|---|---|---|---|
| Human-in-the-Loop | It checks and releases before taking effect. | Offers, website content, translations, sensitive support cases, evaluations with decision-making influence | Low to high, depending on the process | Yes, especially regarding external impact and clear responsibility. |
| Human-on-the-Loop | Monitors the ongoing process and intervenes if any anomalies are detected. | Monitoring, ticket pre-sorting, preliminary stages for lead scoring, internal drafts | Medium | Yes, if clear escalation triggers are defined. |
| Human-out-of-the-Loop | No ongoing intervention, only subsequent monitoring | Internal formatting, tagging, summaries without decision-making impact, simple data cleansing | Low if errors have few consequences | Only in cases of clearly limited damage and good roll-back capability |
My rule of thumb for SMEs is simple: As soon as AI communicates externally, influences prices, makes judgments about people, or processes personally identifiable information, the process requires human approval. If the AI only prepares, sorts, or accelerates data, human on-the-loop approval is often sufficient. Human out-of-the-loop approval is only advisable if an error would cause minimal damage.
Human checkpoints: Where you should check in practice
Many companies implement too many controls and consequently lose efficiency. Others implement none at all and create new risks. A few, clear controls are sensible. human checkpoints at the crucial points.
Typical AI checkpoints in everyday life
- Before the start: Define the process goal, responsible parties, data source, and permitted output.
- Before external use: Professional review of statements, figures, sources, tone and legal relevance.
- Before publication or dispatch: Final approval by the responsible person.
- After use: Sampling, error analysis, and refinement of the rules.
Especially with small teams, ten approval levels don't work; two or three clear checkpoints are sufficient. Anything more slows down operations.
You should define these escalation triggers in advance.
- Legal relevance: Contracts, liability, promises, guarantees, sensitive statements.
- Personal data: Profiling, evaluation, prioritization, or decisions relating to individuals.
- Financial impact: Pricing, discounts, quote calculation, approval of Budgets.
- Reputational risk: Public texts, social media posts, email replies, statements on behalf of the brand.
- Safety or health reference: Medical, technical, or safety-critical recommendations.
- Unusual deviations: implausible figures, significantly changed tone, or contradictions to existing data and brand guidelines.
If one of these Escalation trigger When an error occurs, the process switches from human-on-the-loop to human-in-the-loop. It is precisely this switching that makes an AI approval process robust.
A simple AI approval process for SMEs
For most small businesses, a streamlined workflow with clearly defined roles is sufficient:
- 1. Design by AI: The AI creates an initial proposal, a summary, a proposal framework, a response, or a translation.
- 2. Inspection by a specialist: A person with expertise checks the content, plausibility, completeness, and context.
- 3. Approval by responsible parties: A clearly designated person decides on publication, distribution, or operational use.
- 4. Documentation in sensitive cases: For higher risk classes, the source, version, release date and special instructions are recorded.
This process is deliberately kept simple. A good AI approval process is not an end in itself, but a practical system for making sound decisions.
If you want to set up such a process, don't start with tools, but with responsibilities. Ours Strategic advice Therefore, we always start with the goal, risk, and responsibility. Only then do we decide which automation makes sense at all.
Practical examples for SMEs: Where human-in-the-loop is truly needed
Offer review and calculation
AI can effectively prepare templates, service modules, and wording. But as soon as prices, scope of services, or liability issues are involved, human input is needed. That's precisely why a AI-powered offer creation This only makes sense if the final review remains with a responsible expert.
Website texts and published content
Many companies underestimate the risks associated with website content. AI-generated text can appear linguistically sound yet still be factually incorrect, legally problematic, or damaging to a brand. Therefore, when structuring website content, we always consider readers, search engines, and systems simultaneously, as I explained in the article on... Website for three target groups have described.
Support answers
For standard inquiries, a human-on-the-loop approach may suffice: The AI answers simple questions, a human monitors the quality and intervenes in case of escalation. However, as soon as complaints, deadlines, refunds, or sensitive customer data are involved, the process must be handed over to a human.
Translations and brand-defining language
Especially in South Tyrol, German-Italian content is commonplace. AI is fast here, but not automatically brand-safe. Claims, performance promises, legally sensitive texts, or culturally nuanced formulations require human review. The same applies to tone and brand voice, particularly when working with AI and still wanting to remain authentic, as discussed in the article about... AI-friendly storytelling.
Data-based analyses
AI can often effectively prepare internal analyses, clusters, summaries, or prioritization proposals. However, as soon as an evaluation leads to a concrete action for or against a person, a customer, or an applicant, the risk level increases significantly. At that point, simple random sampling is usually no longer sufficient.
Responsibility beats tool selection
A common misconception is that the better the model, the less control is needed. In practice, the opposite is usually true. The more deeply AI integrates into your operations, the more precisely you need to define responsibilities, approval rights, and quality assurance.
Therefore, I always plan AI with SMEs from a process perspective. What decisions are being prepared? Who bears the responsibility? Who is authorized to approve them? What escalation triggers lead to human review? What documentation is necessary in sensitive cases? Only when these questions are answered does the technical implementation become worthwhile. AI solutions and digitalization.
If you're just starting out, a simple inventory often helps: Which AI tasks are already running informally within your organization? Who actually makes the decisions today? And where are there no visible approval points? Usually, it quickly becomes clear that what's needed isn't more automation, but more clarity.
FAQ: The most important questions about the approval process
Is human-in-the-loop always mandatory?
No. Human-in-the-loop is not legally required for every AI process. However, it becomes practically necessary as soon as an AI has an external impact, becomes legally relevant, involves personal data, or could have significant financial and reputational consequences.
Who should approve approvals in an SME?
Approval should not automatically go to the person operating the tool, but rather to the person with genuine professional and organizational responsibility. For website texts, this could be marketing or management; for offers, often sales plus the owner; and in sensitive cases, a legally informed party should also be involved.
How many human checkpoints are reasonable?
For most SMEs, two to three human checkpoints are sufficient: before launch, before external use, and random checks after use. Too many checkpoints negate efficiency gains, while too few increase the risk of errors.
What is the difference between release and random sampling?
Release means that a specific result is reviewed and consciously approved before it takes effect. Sample checks mean that the process is generally running, and only selected results are subsequently checked. Sample checks are more appropriate for human-on-the-loop processes, while releases are more appropriate for human-in-the-loop processes.
How do I get started if my company doesn't yet have a clear process?
Start with a manageable use case and assign it a simple risk class. Then define responsibilities, escalation triggers, and a streamlined process. If you want to approach this in a structured way, an external sparring session is often more useful than immediately purchasing new tools.
Conclusion
Human-in-the-Loop is not a theoretical AI principle, but a business safety and quality decision. For SMEs, the greater the impact of an AI result, the more clearly defined the approval process, human checkpoints, escalation procedures, and responsibility must be. If you want to use AI effectively, think in terms of processes, not prompts.