Sectors
Loop applies wherever AI acts
The governance question (who reviews, who monitors, who owns) is the same across industries. The regulatory context, stakes, and failure modes differ.
Each sector below shows how Human-in-the-Loop, Human-on-the-Loop, and Human-Accountable-for-the-Loop (HAL) map to real workflow types.
Legal
Legal
Governance challenge
Legal AI systems handle privileged information, create client obligations, and operate in a regulated environment where error carries professional and reputational consequence.
Regulatory context
SRA Principles and Codes of Conduct; GDPR for personal data; sector-specific rules for regulated legal activities; and EU AI Act Annex III, which lists specified uses by or on behalf of judicial authorities and comparable alternative-dispute-resolution uses. Ordinary private legal advice is not generally listed as high-risk.
Worked examples
Legal Research Assistant
The system surfaces authorities and summaries for a lawyer to assess. It produces outputs; the lawyer acts on them.
Contract Review and Summarisation
The AI extracts clauses and flags risk. The lawyer decides whether to rely on the summary. Reliance remains human.
Regulatory Change Monitoring
The system monitors regulatory sources at scale and routes material changes for review. Humans investigate exceptions.
Client Communication Drafting
The AI drafts; a human approves before any communication is sent. Autonomous external send would require HAL with approval gates.
Matter Intake and Triage
The system classifies matters, routes work, creates records, and escalates risk. It takes action; individual review does not scale.
Contract Obligation Tracker
The system may trigger reminders, escalate overdue obligations, and update matter records. A named owner is accountable for what it does.
Financial Services
Financial Services
Governance challenge
Financial AI makes or influences decisions that affect customer outcomes, create regulatory obligations, and can cause systemic harm if controls fail.
Regulatory context
FCA Consumer Duty and operational resilience rules where the firm and activity are in scope; PRA SS1/23 for in-scope banks, building societies and PRA-designated investment firms; and EU AI Act Annex III, which lists natural-person creditworthiness and credit scoring (excluding fraud detection) and life and health insurance risk assessment and pricing.
Worked examples
Fraud Detection and Alerting
The system monitors transactions in real time and flags suspected fraud for investigator review. Humans decide whether to act on alerts.
AML Transaction Screening
Automated screening identifies potentially suspicious activity. Humans review matches and make the decision to file a SAR. The filing step itself is HITL.
Credit Decisioning
Where the model scores and the decision is automated, HAL applies. Authority must be bounded, evidence complete, and a named owner accountable for the workflow. Critical controls should be implemented and tested before deployment.
Customer Collections Communication
Automated outreach to customers in arrears is external and consequential. HAL governs the workflow; approval gates are required for initial contact and for any escalation to formal action.
Know Your Customer Verification
Automated identity checks assist the process, but the verification decision carries regulatory weight and typically requires human sign-off. The AI supports; the human decides.
Human Resources
Human Resources
Governance challenge
HR AI affects employment decisions: who is hired, assessed, promoted, or dismissed. These decisions carry discrimination risk, legal liability, and profound impact on individuals.
Regulatory context
Equality Act 2010; GDPR and UK GDPR, including special-category rules for health data and biometric data processed to uniquely identify a person; EU AI Act Annex III for specified employment uses, subject to its classification rules and revised application date of 2 December 2027; and ICO work on AI tools used in recruitment.
Worked examples
CV Screening and Shortlisting
AI generates a ranked shortlist; a human reviews it before anyone is progressed or rejected. Automated rejection creates significant discrimination, data-protection and oversight risk and, once applicable, may create compliance issues under the EU AI Act’s high-risk employment provisions.
Performance Review Support
AI surfaces patterns, flags inconsistency, and assists calibration. The performance decision is made by a human manager. No automated performance outcome.
Pay Equity Monitoring
The system continuously monitors for pay gaps across protected characteristics and alerts HR for investigation. It detects; humans decide what to do.
Shift and Resource Scheduling
Automated scheduling operates at scale, assigns shifts, and manages resource allocation within defined authority. A named owner is accountable for the system's decisions and must be able to override or suspend it.
Employee Wellbeing Monitoring
Systems that surface wellbeing signals from engagement data must route concerns to a human for sensitive handling. Automated action on wellbeing data creates significant risk.
Healthcare
Healthcare
Governance challenge
Healthcare AI operates in life-affecting contexts where error can cause direct patient harm, and where clinical governance and regulatory oversight are non-negotiable.
Regulatory context
CQC fundamental standards; MHRA software and AI-as-a-medical-device guidance where the product qualifies; NHS assurance controls including DTAC, DCB0129 and DCB0160; and the NICE Evidence Standards Framework. Under the EU AI Act, emergency-healthcare triage is listed in Annex III; other clinical AI may be high-risk through Annex I product rules. The EU MDR and IVDR apply within the EU medical-device regime.
Worked examples
Patient Triage Prioritisation
AI suggests a priority based on presenting symptoms and history. The clinical triage decision remains with a qualified clinician. AI supports; the clinician is accountable.
Diagnostic Imaging Assistance
AI flags findings in imaging for radiologist review. In this illustrative workflow, the diagnostic conclusion remains with the clinician and AI-flagged cases are routed for human review.
Prescription Safety Checking
Automated drug interaction and allergy checking alerts the prescriber or pharmacist. The prescriber makes the clinical decision. The system prevents oversights; it does not prescribe.
Appointment and Referral Scheduling
Automated appointment management and routine referral routing can operate at scale under HAL governance, with clear authority limits, escalation for complex cases, and a named owner accountable for the system.
Administrative Record Updating
Systems that update patient records, code diagnoses, or process administrative workflows require HAL governance. Errors in clinical records carry serious downstream risk.
Not sure which model applies to your workflow?
Use the decision tree and calculator to identify the right governance pattern, then take the HAL assessment if your workflow involves action, autonomy, or scale.