RedubIDX

Mission series · F

Human-in-the-loop, redefined for regulated assessment

What human-in-the-loop must mean when the output is a conformity assessment judgment: authority, inspectability, disposition control, qualification boundaries, and traceability as the basis of trust.

6 minRedubIDX Perspectives

“Human-in-the-loop” has become one of the most overused phrases in software that touches high-stakes work. Often it means little more than: a person can click approve on something a model already decided. That is not a safety architecture. It is a checkbox next to an opaque process.

In medical-device conformity assessment, the phrase has to mean more, because the product of the work is not a draft email or a summary slide. It is a judgment that institutions stand behind under Regulation (EU) 2017/745 and related frameworks: qualified professionals evaluating evidence, identifying deficiencies, and recording dispositions that protect patients. Series E argued that generative tools will deepen the gap between creation speed and assessment capacity unless review infrastructure improves (The AI acceleration gap). This essay defines the accountability boundary that improvement must respect.

Human-in-the-loop, for regulated assessment, means authority, inspectability, disposition control, and qualification boundaries, not a cosmetic review step after an invisible decision.

Why empty HITL fails here

In low-stakes domains, a thin human loop can be a pragmatic compromise: speed first, correction later. Conformity assessment does not work that way. The certificate and the assessment record are the point of the process, not a byproduct. If the human’s role is reduced to rubber- stamping fluent machine text, three failures follow at once.

  • Authority fails: the person who “approved” cannot honestly own a conclusion they could not practically contest.
  • Inspectability fails: peers, quality systems, and authorities cannot reconstruct why a claim was accepted if the pathway to evidence is hidden.
  • Institutional responsibility fails: Notified Bodies are designated and overseen as organisations that perform conformity assessment; tools do not inherit that mandate by sounding confident (MDR).

Empty HITL is especially dangerous under the load described earlier in this series. When queues are long and packages are hard to navigate (series A) (series B), pressure rises to accept fluent assistance as a shortcut. That is exactly when the loop must be thickest, not thinnest.

An operational definition

For regulated technical-documentation assessment, human-in-the-loop means four properties - authority, inspectability, disposition control, and qualification boundaries - if any is missing, the phrase is marketing.

1. Authority

The qualified professional remains the decision-maker for conclusions that enter the formal assessment record. Software may propose; it may not dispose. “Authority” is not a courtesy title. It means the human can revise, reject, reframe, and record a different judgment without fighting the tool for control of the official outcome.

2. Inspectability

Every assisted claim that matters must be openable to its basis: document, page or section, requirement or clause, and the review history that led to the current text. If a reviewer cannot see why a draft says what it says, they are not in the loop; they are after the fact.

3. Disposition control

Findings, acceptances, residual issues, and the path from draft analysis to formal language must be explicitly owned. Assisted output is material for professional review until a qualified person records disposition. Silence or auto-promotion into the record is not a loop; it is capture.

4. Qualification boundaries

Tools do not create competence. A system that drafts clinical or technical analysis does not qualify the user as an auditor. Access, role, and organisational procedure still determine who may conclude what. Human-in-the-loop that ignores qualification is cosplay of professionalism.

If a human cannot change the conclusion, cannot see its basis, does not own the disposition, or is not qualified for the decision, there is no human-in-the-loop worth the name.

What software may and must not do

A clear may/must-not boundary prevents both panic (“never use AI”) and hype (“AI will certify”). The line is functional, not fashionable.

Software may

  • Make complex submissions navigable as dossiers and workstreams.
  • Retrieve and surface candidate evidence against requirements or checklists.
  • Compare versions, highlight changes, and preserve review context across revisions.
  • Draft analysis text as material for professional editing, always with a path back to sources.
  • Surface missing context, weak links, and ambiguity rather than papering over them.
  • Support consistency of framework, shared structure across reviewers, without enforcing sameness of conclusion (series D).

Software must not

  • Make autonomous conformity or certification decisions.
  • Hide uncertainty behind confident language when evidence is missing or contested.
  • Present unlinked assertions as if they were assessed conclusions.
  • Substitute for reviewer qualification, designation, or institutional quality-system responsibility.
  • Quietly replace the Notified Body’s procedures with an opaque external process the organisation cannot inspect or govern.

That boundary is the same family of commitments we state on the company page: no autonomous regulatory judgment, no invisible basis for a conclusion, and no false precision when evidence is missing (Company · responsible AI). Perspectives states them as sector logic, not as a product brochure.

Traceability is not a feature; it is the basis of trust

In ordinary software, “citations” can be a nicety. In assessment, they are load-bearing. A conclusion that cannot be walked back to evidence is not merely hard to audit; it is hard to defend as professional work. Traceability turns assistance from a black box into a reviewable artifact.

In practice, assisted work should preserve:

  • Source links: document identity, location, and the fragment supporting the claim.
  • Requirement linkage: which obligation or checklist item the analysis addresses.
  • History: what changed after a revision, who reviewed a finding, and what remains open.
  • Explicit open questions: gaps stay visible until a qualified person decides what they mean.

Without those properties, “human-in-the-loop” collapses into “human adjacent to a loop they cannot enter.” With them, assistance can reclaim the waste work of series B, search, reconstruction, coordination, while leaving the authority of judgment intact.

What this definition rejects

  • Approval by click without real review: sign-off with no practical ability to inspect or change.
  • Confidence without evidence: polished text standing in for linked support.
  • Positioning the model as the assessor: marketing that treats software as the conformity-assessment authority.
  • Silent takeover of process: tools that quietly overwrite an organisation’s quality system instead of fitting inside it.

Why the definition belongs to the mission

Our mission is to expand the effective capacity of conformity assessment without diluting rigor. A real human loop is how those aims hold together. Assistance earns a place only if it returns time to judgment and keeps judgment ownable. The next essay turns from definition to implication: Infrastructure for judgment.

Sources

  1. 01
    Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices (MDR)

    Primary EU legal framework for medical devices, including notified-body designation, conformity-assessment procedures, and manufacturer obligations. Cited for institutional responsibility of assessment, not for product claims.