Applications

Human in the loop: how people and AI agents run a business process together

Beau Jonkhout

Human in the loop in practice: where an AI agent fits in a process model, where a person decides, what BPMN, BPMM and DMAIC add and what the AI Act requires.

Twee mensen aan een houten caféterras met laptop, tablet, smartphone en een ijskoffie met rietje

Human in the loop means that an AI agent prepares and carries out work in a business process, while a person decides at fixed points. In a well-designed hybrid agent workflow, a person first approves the plan; specialised agents then work in parallel, a counter-role challenges the result and a reviewer weighs it all. Anything you can capture in fixed rules is better left to ordinary process automation.

In short

  • A hybrid agent workflow is a business process in which people, AI agents and ordinary automation each do what they do best.
  • Draw the process in BPMN first. That shows you where judgement is needed and where rules are enough.
  • The pattern that works: plan, approval gate, parallel specialists, counter-role and reviewer.
  • Let a person decide where the work gets its direction, where it becomes irreversible and where it affects someone.
  • The EU AI Act requires human oversight (Article 14) only for high-risk AI systems. For most knowledge work, an approval gate is good practice, not a legal duty.

What is a hybrid agent workflow, and what does human in the loop mean?

A hybrid agent workflow is a defined process in which AI agents carry out steps and a person decides at named moments. "Hybrid" refers to the mix: people, agents and ordinary automation in one process.

An AI agent is software that uses a language model to decide for itself which steps a task needs. It looks things up, reads documents and writes an intermediate result. That is powerful, but not fully predictable. So you give an agent a place in a process, with boundaries around it.

Human in the loop then means: at agreed points, the process does not continue without a person's judgement. With human on the loop, a person only monitors and can step in. With human out of the loop, the system decides alone. Which form fits depends on what is at stake.

What are BPM and BPMN, in plain language?

BPM (business process management) is how an organisation designs, runs, measures and improves its processes. BPMN (Business Process Model and Notation) is the drawing language you use to record such a process, so that everyone reads the same picture.

BPMN is an open standard from the Object Management Group (OMG). The current version is BPMN 2.0.2, from January 2014. Version 2.0.1 was also adopted as the international standard ISO/IEC 19510:2013. You do not need to know the whole standard. Five building blocks cover most processes:

BPMN elementShapeMeaningIn an agent workflow
EventCircleSomething starts, happens or endsThe assignment comes in, the deliverable is ready
TaskRounded rectangleWork that someone or something doesAn agent analyses, a person reviews
GatewayDiamondA split or a mergeApprove or revise; four specialists at once
LaneHorizontal bandWho performs the taskOne lane for people, one for agents
TimerCircle with a clockTime passesAfter a day of waiting, a reminder goes out

The value is in the lanes. With one lane for people and one for agents, you see exactly where the work changes hands. Those handovers are where control belongs.

Where does an AI agent fit in a process model, and where not?

Use an agent where judgement is needed on messy input: reading, sorting, weighing and summarising. Use ordinary automation where the rule is fixed. Let a person decide where there are consequences.

Many process steps are deterministic: the same input always gives the same outcome. Think of posting an invoice, filing a document in the right folder or sending a reminder on day thirty. That is what RPA (robotic process automation, software that repeats actions on a screen) and workflow tools such as Power Automate and n8n are for. They are cheaper, faster and easier to test. A language model only adds uncertainty there.

An agent earns its place where the input is messy and the rule cannot be fully written down. Think of a data room with hundreds of contracts, a case file with letters from both parties or a pile of policy documents. Someone has to read, see connections and weigh. Language models have become good at exactly that.

A rule of thumb: if you can write the decision rule on one sheet of A4, do not use an agent.

Type of stepCharacteristicWho or whatExample
Fixed ruleSame input, same outcomeRPA, Power Automate, n8nSave a file, send a deadline reminder
Judgement on messy inputReading, sorting, weighingAI agentScreen contracts by topic, draft findings
Decision with consequencesChoosing a direction, irreversible, affects a personHumanSet the scope, issue advice, reject an application

People who build AI systems distinguish workflows, where the route is fixed, from agents, which choose their own route. In a business process you usually want a fixed route with agents inside the steps. That is something you can draw and control.

What does the hybrid pattern look like?

The pattern has five building blocks: a plan, an approval gate, parallel specialists, a counter-role and a reviewer. An editor then turns the result into the deliverable.

Hybrid agent workflow in BPMN style: the person selects the documents and approves the plan, four agents work in parallel, a counter-role and a reviewer weigh the result.

Hybrid agent workflow in BPMN style: the person selects the documents and approves the plan, four agents work in parallel, a counter-role and a reviewer weigh the result.

1. Plan. A planning agent turns the assignment into a work plan. Which questions need answering, with which documents, and what is missing? The plan is short and easy to check.

2. Approval gate. A person reads the plan and chooses: approve, revise with an explanation, or abort. This is the cheapest moment to intervene. A scoping error is fixed here with one sentence; after the analysis, all the work has to be redone.

3. Parallel specialists. Once approved, several agents work at the same time, each on its own part. Each specialist gets its own instructions and its own sources. That keeps each part manageable and stops topics from bleeding into each other.

4. Counter-role. One agent takes the position of the party on the other side: the opposing party, the tax inspector or the regulator. It looks for exaggeration, weak spots and anything the specialists missed. That prevents a one-sided or overly alarming result.

5. Reviewer. A final agent weighs the specialists' work against the counter-role. It merges duplicate findings, adjusts severity and turns every claim without a source into an open question.

Each building block catches a weakness of language models. The plan stops the agent from answering the wrong question. Parallel specialists keep each task small. The counter-role works against a model's tendency to agree with itself. The reviewer enforces source citations.

Where should a person make the decision?

Let a person decide at three kinds of moments: where the work gets its direction, where it becomes irreversible and where it affects someone personally. In between, the agent can keep working.

In practice, these are often the moments:

  • At the start. Which assignment, which documents, for which side? Whoever selects the documents sets the boundaries of the work.
  • After the plan. Is the scope right, is anything missing, is the threshold well chosen?
  • Before anything leaves the building. Advice, a letter to the other side, a decision about a client or an employee.

If a decision affects someone personally, the GDPR also applies. Article 22 gives people the right not to be subject to a decision based solely on automated processing. That applies when the decision has legal effects or similarly significantly affects them. A person who only presses a button is not genuine human involvement.

A gate only works if the person can actually assess something there. In July 2025, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) published guidance on meaningful human intervention, organised around four factors: people, technology and design, process, and governance. Translated to an agent workflow:

Checklist: a good approval gate

  • The reviewer sees the intermediate result itself, not just a summary.
  • The gate states what the reviewer should check.
  • The reviewer can approve, revise with an explanation or abort.
  • The process really waits: without a decision, nothing happens.
  • Anyone who waits long gets a reminder. A gate must not quietly gather dust.
  • Every decision is recorded: who, when, which choice and why.
  • The reviewer has the knowledge and the mandate to say no.

Watch out for automation bias: the tendency to trust a system too quickly. A gate that always turns green protects nobody. So measure how often people revise.

How it works at Prudai: a data room due diligence, step by step

In LEO, our platform for legal work, most workflows follow this pattern. Below is the "Dataroom due diligence" template as it appears in our code.

In a due diligence, a buyer investigates a company before acquiring it. The documents sit in a data room. The work is large, spread across disciplines and time-critical: a good example for the hybrid pattern.

  1. Intake (human). You select the data room in your case file and state which side you advise, the type of transaction, the chapters in scope and, optionally, a materiality threshold. LEO can pre-fill the card from the conversation, but you always select the documents yourself. The run only starts when you confirm; the AI cannot start it on its own.
  2. Planner (agent). The planner divides the documents over four chapters: corporate, employment law, IP/IT and privacy, and tax. For each chapter it lists the key questions and the documents it is missing. If no threshold was given, it proposes one.
  3. Plan approval (human). The run pauses. The gate states what you check: is the transaction context right, and are the documents in the right cluster? You approve, revise with an explanation or abort. After a revision, the planner updates the plan and the gate comes round again.
  4. Four specialists (agents, in parallel). A corporate, an employment law, an IP/IT and a tax specialist each work on their own cluster, with their own instructions. The corporate specialist, for example, consults the Dutch Trade Register. Every finding has a fixed format: severity, source with exact location, explanation and follow-up action.
  5. Counter-role (agent). Opposing counsel puts findings into perspective where that is fair and gives its own reading of the documents. Whatever survives, it marks as "holds up".
  6. Reviewer (agent). The reviewer, called "judge" in this template, merges duplicate findings and re-weighs severity after the counter-role. A finding without an exact location becomes an open question.
  7. Editor (agent). The editor drafts three deliverables: a risk matrix, a DD memo per chapter and a chronology of key facts, with a management summary on top.
  8. Delivery. The run delivers the documents. You review them and decide what happens with them. The run makes no decision for you.

This template is one of 74 in LEO and LEO Fiscaal (as of 2 October 2026). The pattern is recognisable throughout, but not every workflow has every step. Each of the 73 templates that run as a workflow has exactly one human gate. In 72 of them, it sits directly after the plan. 53 templates have a counter-role, such as the tax inspector, opposing counsel or the regulator. To see which kinds of document analysis LEO does, have a look at legal document analysis (in Dutch).

Three details make the gate reliable in practice:

  • Notification and reminder. When a gate is waiting for you, you get a notification straight away, by default also by email. If the gate is waiting for your decision, a reminder follows after a day, and then one for each further day of waiting.
  • Recorded decision. Every human decision is recorded with who, when and in which round, before the run continues. If recording fails, the run does not continue either.
  • A limit on revisions. Every revision makes the planner work again. So by default a gate comes round at most three times. In the third round, you choose approve or abort.

Does a template not quite fit your practice? Then you copy it and turn it into a workflow of your own. In the workflow editor you add steps, decision points and human checks. The copy only gets sources that are included in your subscription.

The same principle sits in the process editor of IRMA, our software for risk management and information security. You draw a process with a start, steps, decisions, subprocesses and an end, and attach control points to it. IRMA can suggest which risk or control belongs to a step. Every suggestion must have a rationale and at least one source reference, or it is not saved. A suggestion only becomes a real link once a staff member approves it. A rejected suggestion stays on record and does not come back. AI suggestions are switched off by default for each organisation; the registers also work without AI.

Why is process maturity a precondition?

An agent speeds up the process you have, even if that process is messy. Only start with agents once the process is repeatable and defined.

The OMG's Business Process Maturity Model (BPMM), from 2008, distinguishes five levels of process maturity:

LevelName in BPMMCharacteristicWhat an agent can do here
1InitialAd hoc, outcomes hard to predictLittle: describe the process first
2ManagedRepeatable per team, teams work differentlySupport individual tasks, per team
3StandardizedStandard processes across the whole organisationA fixed agent workflow with a gate: the first real gain is here
4PredictablePerformance is managed with numbersMeasure what the agent adds: lead time, revisions, errors
5InnovatingTargeted, continuous improvementRedesign the process around what agents do well

At level 1, an agent fills the gaps in the process by itself, and that is exactly what you do not want. At level 3, you know where the gate belongs and what the specialists must deliver.

A second precondition is that your information is in order. An agent that finds two versions of the same policy picks one, and not always the right one. Read more in One fact, one place and in our article on information alignment.

What does Lean Six Sigma have to do with it?

Lean Six Sigma improves processes with the DMAIC cycle: Define, Measure, Analyze, Improve and Control. That cycle suits the introduction of an agent workflow well, because you first measure where the waste is and only then automate.

DMAIC phaseQuestionIn a hybrid agent workflow
DefineWhich process, for whom, with what goal?Draw the process in BPMN, with lanes for people and agents
MeasureHow does it perform now?Lead time, waiting time and number of rework rounds
AnalyzeWhere are the waste and the variation?Which steps are rules, which need judgement?
ImproveWhat changes?Rules to RPA or n8n, judgement to agents, decisions to people
ControlHow does it stay good?Gate, decision log, reminders and a periodic sample check

Lean pays attention to, among other things, waiting. In a hybrid workflow, the waiting shifts: the agents are fast, and the person at the gate becomes the bottleneck. So measure the waiting time at the gate separately. Our article on the Lean Six Sigma AI Consultant shows how an agent can support the DMAIC cycle itself.

What does the AI Act require for human oversight, and what not?

Article 14 of the AI Act requires human oversight only for high-risk AI systems. Since the Digital Omnibus, those obligations apply to the systems listed in Annex III only from 2 December 2027. For most knowledge work, an approval gate is sensible, but not a legal duty.

What the AI Act does say:

  • Article 14 is a design requirement for whoever provides a high-risk AI system. The system must enable the people overseeing it, as appropriate, to understand how it works, stay alert to automation bias, disregard or reverse the output and stop the system.
  • Article 26(2) requires the organisation that uses such a system (in the Act: the deployer) to assign oversight to people with the necessary competence, training and authority.
  • Annex III lists the high-risk areas. Examples are recruitment and selection, the creditworthiness of individuals and AI that assists a judicial authority in interpreting and applying the law.
  • The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed those obligations. They now apply from 2 December 2027 to systems in Annex III and from 2 August 2028 to AI in products covered by Annex I.

What the AI Act does not say:

  • It does not require an approval gate in every process that uses AI. An agent that screens a data room for a law firm generally does not fall under Annex III. A system that helps a judge apply the law does.
  • A person between the steps does not automatically make a system "compliant". A system with a gate can still be high-risk, and then all requirements apply, not just oversight.

Article 4 does apply to everyone: providers and deployers take measures to support the AI literacy of their staff. Since the Omnibus, you no longer have to ensure a particular level. On top of that, the GDPR and your professional rules still apply. Whoever gives advice remains responsible for that advice. An approval gate makes that responsibility visible.

If you work in the public sector, also read our article on the IAMA for municipalities.

For the specialist

The gate as a state machine. A run that reaches the gate waits for a human in LEO. A decision always names the round it answers, so a double click never counts twice. On resuming, the run receives the decision maker's current source rights: a source that was revoked during the wait drops out.

Wait or continue. A gate can wait until there is a decision, or continue on its own after a set time with the proposal as it stands. In the templates, the run waits indefinitely at 68 of the 73 gates. In five templates, the run continues by itself after four or 24 hours.

The instruction at the gate. Every gate in a template has a fixed instruction for the reviewer. It only describes the process: what you check. Deadlines, amounts and statutory articles are deliberately left out; they belong in the document itself, with their exact location. If you build your own workflow and leave the instruction and description empty, LEO proposes an instruction when the run starts. If that fails, the reviewer sees a general instruction.

BPMN modelling. Model the review as a user task in the human lane and the agents as tasks in their own lane. The reminder is a non-interrupting timer boundary event: the task stays open while the reminder goes out in parallel. Revising is an exclusive gateway with a loop back to the planner. Standard BPMN has no dedicated symbol for an AI agent yet. Researchers proposed a BPMN extension in late 2024, published at SEAA 2025 (Ait, Cánovas Izquierdo and Cabot). It lets you record who is responsible for a task, which strategy an agent follows and how a decision is made when agents propose different outcomes.

Workflows and agents. In the terms of Anthropic's "Building effective agents", this is a workflow, not an autonomous agent: the route is fixed. The specialists are parallelisation. The counter-role and reviewer resemble an evaluator, but they do not send the work back automatically. Revision happens at the gate, by a person.

Article 6(3). A system listed in Annex III is nevertheless not high-risk if it poses no significant risk of harm. That is only possible if it performs one of four defined tasks, such as a narrow procedural task or a preparatory task for an assessment. That exception never applies when the system profiles individuals.

Frequently asked questions

What does human in the loop mean?

Human in the loop means that a process using AI waits for a person's judgement at fixed points. The AI prepares and carries out the work; the person decides on direction and consequences.

Is a human approval gate mandatory under the AI Act?

Not in general. Article 14 requires human oversight for high-risk AI systems, such as in recruitment or creditworthiness assessments. For systems in Annex III, those obligations apply from 2 December 2027. For other processes, a gate is a sensible design choice, not a legal requirement.

When should I choose Power Automate or n8n instead of an AI agent?

Choose ordinary automation if you can write the rule down completely and the same input must always give the same outcome. An agent only makes sense where something has to be read and weighed. Often you use both in one process.

For a side-by-side comparison and a checklist per process, see AI agent or Power Automate: which do you choose?.

What does a counter-role do in an agent workflow?

A counter-role is an agent that looks at the work from the other party's point of view, such as the opposing party, the tax inspector or the regulator. It looks for exaggeration and missed risks. A reviewer then weighs the findings against that counter-reading.

How many human checkpoints are enough?

As few as possible, in the places that matter. A gate after the plan intervenes when revising costs least. Add a second moment where the work becomes irreversible or affects a person. Too many gates lead to box-ticking.

Sources

Want to know how a hybrid agent workflow fits your own processes? In an AI workshop we map together where AI strengthens your processes and where people decide.

Updated on 2 October 2026

Photo: rawpixel via Pixabay

AgentsAutomationAI ActMultiple Agents

Beau Jonkhout

Technical Director

Beau is co-founder and technical director of Prudai. He is the driving force behind the technical architecture of the Prudai platform. He leads the development of the multi-agent frameworks, manages the developers, and is responsible for the integration quality, security, and privacy by design of all solutions.