Your Human Reviewer Is Probably Rubber-Stamping
The standard advice for using AI agents safely, advice we give often, is to keep a human in the loop. New research suggests that advice is incomplete in an uncomfortable way. A large 2026 study, backed by telemetry from real AI coding tools, found that human reviewers failed to block roughly one in three harmful agent requests placed in front of them. Attempts to steal credentials slipped past about 35 percent of the time. The reviewers were not negligent. They were doing exactly what people do when software asks for approval all day long. A human in the loop only protects you if the human is actually looking.
Approval fatigue is a design problem
Nobody decides to rubber-stamp. It happens because of a well-documented failure mode: when a system asks you to confirm something dozens of times a day and almost every request is legitimate, your brain stops evaluating and starts pattern-matching. Approving becomes reflex. AI agents intensify this because they generate a high volume of requests, those requests tend to look technical and similar to each other, and the dangerous one looks almost identical to the ninety-nine safe ones that came before it. The reviewer is not the weak link. The workflow is.
What real oversight looks like
Writing "a human approves this" in your process document is not a control, it is a hope. The difference between oversight that works and oversight that does not comes down to how the approvals are designed.
| Oversight that fails | Oversight that works |
|---|---|
| Approvals many times a day | Rare prompts, only for what matters |
| "Allow this action?" with no context | What is being done, to what, and why |
| One person clicking through everything | Shared load so nobody goes numb |
| Nobody ever revisits approvals | Periodic spot-checks of what was approved |
Fewer, richer, checked approvals beat constant clicking every single time. Spot-checking matters more than it sounds: it catches the misses, and it keeps reviewers attentive precisely because they know someone will look.
Do not make a human your only safeguard
The deeper lesson is about layering. Human review is valuable, but it is an attention-dependent control, and attention is exactly what erodes under repetition. So pair it with safeguards that do not rely on anyone being sharp at 4pm on a Friday: narrow access so an agent simply cannot reach what it should not, spending caps so a runaway cannot run up a bill, and logs you actually review. Those are the same fundamentals we cover in governing the agents you already deployed and in turning on AI spend controls. Limits work while people are tired. Prompts do not.
A quick honesty test
Ask whoever approves AI actions in your business a simple question: when did you last say no? If the answer is never, or they cannot recall, you do not have a review step, you have a formality. That is worth knowing before something slips through, especially as agents take on more unattended work, as we described in AI that keeps working after you log off. Redesign for fewer, better checkpoints, back them with limits that hold on their own, and your human in the loop becomes a real safeguard instead of a comforting sentence in a policy.
Frequently Asked Questions
What does the research actually say?
A large-scale 2026 study, corroborated by telemetry from real AI coding tools, found that human reviewers failed to block roughly one in three harmful AI agent requests put in front of them, with attempts to steal credentials slipping through about 35 percent of the time. The people in these tests were not careless in any unusual way. They were doing what all of us do when a system asks for approval dozens of times a day: skimming, pattern-matching, and clicking yes. The finding is not that humans are bad at judgment. It is that approval prompts are a weak place to put judgment.
Why do humans miss so much?
Because of a well-known failure mode: approval fatigue. When a system asks you to confirm something repeatedly, and almost every request is legitimate, your brain stops evaluating and starts pattern-matching. Approving becomes a reflex rather than a decision. AI agents make this worse because they generate a high volume of requests, the requests often look technical and similar, and the risky one looks almost exactly like the ninety-nine safe ones before it. Nobody decides to rubber-stamp. The design of the workflow decides it for them.
Does this mean human oversight is pointless?
Not at all, but it does mean oversight has to be designed rather than assumed. Writing "a human approves this" in your process document is not a control; it is a hope. Real oversight means fewer prompts, so each one carries weight, enough context in the prompt for the reviewer to actually judge it, and a clear escalation path for anything unusual. Human review works well when it is rare, informative, and treated as a real decision. It fails when it is constant, vague, and reflexive. The difference is entirely in how you set it up.
How do I make human review actually work?
Four changes fix most of it. Reduce the number of approvals by letting the agent act freely within genuinely safe boundaries, and only prompting for the things that matter. Improve what each prompt shows, so the reviewer sees what is being done, to what, and why, not just a request to continue. Rotate or share the review load so no single person becomes numb to it. And spot-check what was approved after the fact, which both catches misses and keeps reviewers attentive because they know someone is looking. Fewer, richer, checked approvals beat constant clicking every time.
What should a small business take from this?
Mostly this: do not let a human checkpoint be your only safeguard. Pair it with limits that do not depend on attention, narrow access so an agent cannot reach what it should not, spending caps, and logs you review periodically. Then use human approval sparingly for the genuinely consequential moments, and make those prompts informative. If your current setup asks someone to approve AI actions many times a day, assume some are being waved through, because the research says they are. Redesigning for fewer, better checkpoints is the fix.
Build oversight that actually catches things
We help Canadian businesses design AI approvals people genuinely read, backed by access limits, spending caps, and logs that work even when nobody is watching.
Related Articles
Using AI to Screen Résumés? Read This First
Should You Tell Customers They Are Talking to AI?
Steal the Enterprise AI Rollout Playbook
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.