Skip to content

The Organization After Cheap Intelligence

Fewer Approvals, Stronger Controls

An approval is not a control, and volume is about to prove it. Cheap intelligence exposes the conflation, and what replaces the signature is a layered architecture with a named, equipped human owner.

A long strip of identical signature boxes recedes across a dark bench, the nearest signature crisp and the far ones fading to almost nothing. At right angles, warm-lit: a dial gauge, a padlocked gate, and a compartment tray holding one pulled item, with a hand and pen beyond.
An approval is a gate on one instance; a control is a property that holds across all of them.

Every approval in your organization was created for a reason. Somebody said: before this goes out, a person should look. For a while, a person did.

Then the volume changed. The drafts got faster because a model wrote the first version, and the evidence packets got thicker because assembling them got cheaper. The approval, same signature, same calendar slot, same person, kept running at the same speed.

What you have is a gate that produces a signature. What you need is a control that holds without one.

That is the argument. An approval chain is not automatically a control. It is a synchronous human gate on individual instances, and volume degrades it. The replacement is not a longer chain, and it is not "trust the machine." It is a layered set of controls with a named, equipped human owner. Total oversight goes up; what goes down is the number of instances requiring a synchronous signature.

This is not less governance. The approval chain and the control system are different instruments, and the two got conflated back when volume was low enough for a signature to be a judgment.

The distinction and why it was invisible

Approval chains were built to solve real problems. Somebody had to check the change against policy, check the exception against the criteria, and be answerable when the answer was wrong. At low volume, one person reading each instance did all three at once: the reading was the check, the check was the decision, and the signature was the record. Nobody drew the distinction.

The arrangement had a hidden dependency: the reviewer's attention, per instance, above some minimum threshold. Nobody wrote it down because it was implicit in the work rate. Then generation got cheap.

Now the reviewer sees many more packets in the same calendar, each looking like the last. Evidence complete, formatting clean, reasoning tracks. Somewhere down that queue the reading stops being the kind of reading the first packet got. That is not laziness; it is what attention does under load. When the reading stops being a check, the signature stops being a control, and the chain produces an artifact that looks like oversight and functions like a stamp.

I have no measured threshold for this and want to say so in the paragraph that makes the claim. No study in the evidence base measures approval quality as a function of throughput. What we have is the direction of the effect, documented in the automation-bias literature for three decades, plus the observation anyone who has run a review queue at rising volume can supply. The mechanism is defensible. The number is not.

A gate whose effectiveness falls as volume rises fails exactly when it is needed most, and the audit trail hides that, because a signed record looks the same whether or not the signer read it. The chain was a control by coincidence, and the coincidence held because volume was low. That is a thinner foundation than it looked.

Why accountability does not compress

Part 4 ended on a distinction this essay has to make good on: coordination work compresses and consequence does not. That is easy to assert and easy to wave away, so here is the argument rather than the assertion. The reasoning is mine and it is inferred. Nothing in the evidence base measures it.

Coordination is a flow of information, and information deduplicates. If two people need the same reconciled number, the second copy is nearly free. Improve the channel and the cost of every future transfer falls, because what moves is a good that copies without being diminished. That is why cheap intelligence is doing what it is doing to routing, synthesis, and status: those are transfers, and transfers get cheaper when the medium does.

Accountability is not a transfer, and it does not deduplicate. It is an assignment of consequence to a person. Two people held answerable for the same outcome do not each carry half of it. Either they carry it jointly, which is how a chain becomes cover, or one carries it and the other has a title. The second copy is not free and it is not a copy. There is no channel to improve, because nothing is being moved. What is allocated is exposure: who will be asked to explain, who absorbs the cost, and whose judgment is on the record when the answer turns out wrong.

Two consequences follow. Efficiency gains in the information layer do not propagate to the accountability layer, so a system can get much faster at producing decisions without getting better at owning them. And accountability cannot be spread thinner as volume rises. Coordination absorbs volume through throughput; consequence absorbs it by attaching to more instances than one person can attend to, which is not absorption. It is dilution, and dilution is what the degrading signature looks like from the inside.

The honest objection is that the number of accountable humans a system needs may be small, so the floor binds loosely. Possibly. But it binds above zero, per consequential decision rather than per organization.

How human oversight actually fails

Parasuraman and Riley's 1997 taxonomy has four categories: use, misuse, disuse, and abuse. Most compliance frameworks skip the fourth. Abuse is not the operator misusing the tool; it is deploying automation without regard for its effects on the people expected to oversee it. A signature at the end of a fast pipeline, called oversight, is that pattern. The failure is upstream of the reviewer, in the design.

Skitka, Mosier, and Burdick characterized in 1999 how the reviewer then fails. Automated decision aids induce two errors: omission, where the reviewer misses what the automation did not flag, and commission, where the reviewer follows the automation against contradictory correct information. Parasuraman and Manzey extended the result in 2010 to trained professionals with domain expertise, and complacency did not go away. So much for the theory that skilled reviewers are immune.

The opposite failure is documented too. Dietvorst, Simmons, and Massey showed in 2015 that after seeing an algorithm err, people lose confidence in it more sharply than in a comparable human, and will choose an inferior human forecast even after watching the algorithm outperform. Algorithm aversion, they called it. The pair matters: no general trust policy corrects both failures at once. "Trust the model" produces commission errors. "Check everything" collapses into automation bias under volume. What is required is calibration per task, per model, per context, which is my inference rather than a measured protocol. The two-sided error structure is what the studies establish.

The same authors found the lever that moves. In 2018 they showed people will use an imperfect algorithm considerably more readily when allowed to modify its output, even slightly. That tells you what an equipped owner needs: standing to adjust, not only to accept or reject. Part 6 makes a design rule of it.

The named human fails not because they are the wrong person but because a signature at the end of a fast pipeline is the wrong tool for the load. The failure then gets labeled human error, and the response is more training, more attestation, a stricter signing policy. None of it addresses the load, and none of it gives the name on the responsibility matrix time, context, or standing to override or halt anything.

The governance floor

Three independent regimes converge here, and the convergence is where the argument turns.

The first is the National Institute of Standards and Technology's AI Risk Management Framework of January 2023. It is voluntary, so its value here is convergence rather than authority. It organizes governance around four functions, GOVERN, MAP, MEASURE, and MANAGE, with GOVERN cross-cutting and continuous, and "accountable and transparent" among its seven trustworthiness characteristics.

The second is binding. Article 14 of Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, applies to high-risk systems as the Act defines them and requires that those systems be designed so natural persons can effectively oversee them during use. It enumerates five capabilities the overseer must be able to exercise: understand the system's capacities and limitations, remain aware of automation bias, correctly interpret the output, override or disregard it, and halt operation. Two scope caveats travel with every use of this. It binds high-risk systems as the Act defines them, not all AI, and the two-person verification rule in Article 14(5) is specific to certain biometric identification systems and does not generalize.

Article 14(4)(b) lands hardest. In 2024 the European Union wrote into binding regulation that the overseer of a high-risk AI system must remain aware of automation bias. Skitka, Mosier, and Burdick had characterized automation bias experimentally twenty-five years earlier. Regulation caught up to the science, and to the researchers' own term for the mechanism.

The third is ISO/IEC 42001 of 2023, the international management-system standard for AI. It is certifiable, architected on the ISO 27001 and ISO 9001 pattern, with assigned organizational responsibility central to it. I carry it at the level of architecture and intent, without a clause number or quotation, because the normative text sits behind a paid license I have not retrieved.

Voluntary, binding, certifiable. American, European, international. None wrote the other, and all three land on the same structural requirement: a named human who is answerable and equipped rather than nominal. Be precise about how far that goes. Only the Act enumerates the five capacities, and only for high-risk systems as it defines them. NIST and ISO/IEC support the architecture without sharing that enumeration, and borrowing the Act's list as though three regimes had written it would be its own small overclaim. Reading the convergence as a structural floor on flattening is my argument rather than any regime's finding. But three independent bodies do not land there by accident, and it is incompatible with a governance model in which the accountable human is a signature at the end of a fast pipeline.

Oversight is work, not policy

The equipped owner is not only an aspiration. The labor market is producing one.

Anders Humlum and Emilie Vestergaard, in the March 2026 revision of NBER Working Paper 33777, Still Waters, Rapid Currents, describe how Danish employers absorbed generative AI across eleven exposed occupations. Their account is task reorganization, with new tasks appearing in content generation, AI oversight, and AI integration, and workers shifting toward content generation and toward supervisory roles overseeing AI output. The authors read that as consistent with chatbots altering the hierarchical structure of production.

Four hedges travel with that and none is optional. It is paraphrase, not quotation, because I have not re-checked the wording character for character against the revision. Consistent with is the authors' own standard, and it is not the same as shows. The window is early and largely pre-agentic. And I cite no share or prevalence figure for the oversight category, because the figures in circulation are ones I could not locate in the full text. The paper evidences that oversight work appeared, not how large the category becomes.

Oversight is showing up in task data as work, in a national administrative dataset, in a working paper by labor economists. The labor market is producing the category. And if the equipped owner is going to exist, the role has to be resourced rather than designated: time, context, standing, and access, the four inputs most likely to go unbudgeted.

The control taxonomy

If the signature is not a control, what is?

Gates in series, controls in layers

Adding gates does not add oversight past a certain volume; adding layered controls does.

Gates in series degrade as volume rises, while layered controls hold and require one named, equipped owner. Two panels: three gates on the left, three control bands plus one owner node on the right. The owner's five connectors carry the Article 14(4) capacities: understands limits, aware of automation bias, interprets, overrides, halts.

The serial chain

inbound volume

Inbound work, thickening as volume rises.
Three identical gates in series, the third drawn dashed and faded.Each gate is a narrow vertical bar carrying a signature mark. The third gate's mark is dashed and reduced in opacity, marking a gate that has stopped producing judgment.
yesyesyes

the gate stops producing judgment and starts producing signatures

gates in series / controls in layers

Layered controls

inbound volume

Inbound work, thickening as volume rises.
  • Constraintmakes a class of action impossible to submit
  • Detectionsampled audit with consequences
  • Escalationa stated condition that routes the exception
named ownercan, across all three bands:
  • understands limits
  • aware of automation bias
  • interprets
  • overrides
  • halts
Schematic — not to scale. Adding gates does not add oversight past a certain volume; adding layered controls — constraint, detection, escalation — with one named owner does. The five owner capacities are compressed from Article 14(4) of the EU AI Act and apply to high-risk systems as the Act defines them; the two-person verification rule in Article 14(5) is specific to certain biometric identification systems and does not generalize.

The classical control taxonomy has four categories, standard vocabulary from the internal-controls literature, applied against AI-driven volume.

Preventive controls make a class of action impossible or impractical to submit. They operate on the action space rather than the instance: a submission system that rejects entries failing a validation rule, a delegation-of-authority structure routing commitments above a threshold. They absorb volume because they do not depend on per-instance attention.

Detective controls identify exceptions, violations, or drift after the fact, sampled or continuous, with defined consequences: an audit with the rate and consequence stated in advance, monitoring of defined signals with a named responder, reconciliation between independent records. They are what make "fewer approvals" mean "stronger oversight" rather than "unmonitored output." The signature checked every instance and degraded; the detective control checks a defined fraction and does not, because the check sits in the rhythm rather than the queue.

Corrective controls restore a process, decision, or state after a failure is detected: a defined rollback, an escalation path to an owner with standing to reverse, a remediation protocol that fires when a detective control does. This is how the named owner exercises two of the five Article 14(4) capacities, override and halt. Without them the owner has the title but not the instrument.

Accountability controls establish who is answerable and evidence that the assignment was exercised: a named person per decision category with defined scope and cadence, a ledger recording the decision, its basis, and its owner, and an assurance exercise that asks the owner to demonstrate those capacities rather than attest that they signed.

Preventive absorbs. Detective catches what preventive missed. Corrective restores. Accountability assigns and evidences. Where the signature alone stood in for all four, that was adequate at low volume and is not adequate when generation is cheap.

Where human preapproval remains necessary

I cannot argue "fewer approvals" without naming where the approval is the right instrument. Three cases share one property: the human is deciding, not signing.

Irreversible high-consequence commitments, where one action creates an obligation the organization cannot unwind: a binding commitment above a defined materiality, a regulatory filing, a public disclosure, a capital commitment that moves the balance sheet. The synchronous human decision is the control, not a gate on one.

Novel situations outside established policy. A request outside the categories the preventive and detective controls were built for should route to a human, which is the escalation condition working. Write the condition down and make the path lead to someone equipped to decide.

Regulated pre-clearance obligations. Where a regime requires affirmative sign-off before a specific action, the approval is a legal requirement and it remains.

The property matters more than the enumeration, and the signature-that-was-once-a-judgment is in none of these categories.

The strongest steelman

The better objection is not technical. It is political.

Approvals distribute cover. They spread ownership of a risk across enough named people that nobody carries the exposure alone. Remove them and the exposure concentrates on whoever holds the pen, which is often the actual reason the chain persists.

The cover function is real. Two things follow. A chain that exists for cover produces a signature rather than a judgment, and under volume the signature becomes automatic, which is the commission error. Cover that does not survive contact with volume was never cover.

And the concentration risk argues for equipping the remaining owner rather than keeping a chain that is failing. Equipping is not free: time, context, standing, and access cost money that has to come from somewhere. Concentration without equipping is worse than the chain it replaces, and I would rather name that than assume it away.

A quantity-free example

Consider a category of standard change carrying a serial approval chain. Each signature was created for a reason and read with attention when the volume justified it. Then drafting and evidence assembly get automated. The flow into the chain rises; the chain does not.

The reviewers begin approving in batches, on the strength of the packet looking like the last one. That is the commission error. What would have caught the one genuinely bad change is not another signature. It is a constraint making that change impossible to submit, a sampled audit with real consequences, and one named owner with time to look at exceptions and standing to stop them.

The people who used to sign are not removed. Their role changes, from signing instances to designing and staffing those controls and exercising them when they fire. Different work, different tooling, not less work. Work that holds at volume, which the signature did not.

This example is illustrative and sanitized. It names no employer, system, person, proprietary process, metric, volume, proportion, threshold, or identifiable event.

The Monday approval-inventory test

Pick one approval in your organization. Any one.

Ask three questions in order. What would go wrong without it? Has that ever actually happened? Who would answer for it if it did?

If you cannot answer the second with an instance, you have a ritual. If you cannot answer the third with a name, you have a signature.

Then the harder one. Take the five Article 14 capacities listed above and ask whether the person you named can exercise all five today, with the time and access they actually have. The scope caveats still apply. Even so, those capacities make a defensible design specification anywhere a wrong outcome has consequences.

If the named owner cannot do all five, you have not assigned accountability. You have assigned blame in advance.

What this leaves for Part 6

Fewer approvals and stronger controls describes the replacement instrument. It does not tell you where to start, and starting in the wrong place is how two years go into automating approvals that did not matter while the consequential decisions go untouched.

I have argued elsewhere that "You don't 'trust' the agent. You bound it," in the case for bounding the system with a deterministic shell. That bounds the machine; this essay bounds the organization. A shell constrains what an agent may do, not who is answerable when the bounded action was wrong anyway. Nearby, "agent-washing misprices risk in both directions," sorts governance weight by autonomy level, where this essay sorts oversight quality by instrument type. And "Nine entities and a handful of foreign keys turn 'we think AI is governed' into 'we can prove it to a regulator in an afternoon,'" builds the ledger that evidences accountability. A ledger proves who was nominally responsible, not that they had the time, context, and standing to intervene. Translating that into policy-as-code is Part 6's territory.

Fewer gates, layered controls, one named owner actually equipped to oversee. But an instrument without a unit is a tool in search of a problem. The unit of redesign is not the task and not the approval. It is the decision. That is where this series ends.

Sources

  • Parasuraman, Raja, and Victor Riley. "Humans and Automation: Use, Misuse, Disuse, Abuse." Human Factors 39, no. 2 (1997): 230–253. DOI.
  • Skitka, Linda J., Kathleen L. Mosier, and Mark Burdick. "Does Automation Bias Decision-Making?" International Journal of Human-Computer Studies 51, no. 5 (1999): 991–1006. DOI.
  • Parasuraman, Raja, and Dietrich H. Manzey. "Complacency and Bias in Human Use of Automation: An Attentional Integration." Human Factors 52, no. 3 (2010): 381–410. DOI.
  • Dietvorst, Berkeley J., Joseph P. Simmons, and Cade Massey. "Algorithm Aversion: People Erroneously Avoid Algorithms after Seeing Them Err." Journal of Experimental Psychology: General 144, no. 1 (2015): 114–126. DOI.
  • Dietvorst, Berkeley J., Joseph P. Simmons, and Cade Massey. "Overcoming Algorithm Aversion: People Will Use Imperfect Algorithms If They Can (Even Slightly) Modify Them." Management Science 64, no. 3 (2018): 1155–1170. DOI.
  • National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. January 2023. Publisher.
  • European Union. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act), Article 14. Adopted 13 June 2024; published in the Official Journal of the European Union, L series, 12 July 2024. Publisher.
  • International Organization for Standardization and International Electrotechnical Commission. ISO/IEC 42001:2023 — Information Technology — Artificial Intelligence — Management System. Geneva: ISO, 2023. Cited at the level of architecture and intent; normative text not quoted.
  • Humlum, Anders, and Emilie Vestergaard. "Still Waters, Rapid Currents: Early Labor Market Transformation under Generative AI." NBER Working Paper 33777, May 2025, revised March 2026. DOI.

Operate. Publish. Teach.