Here is the wrong question: ‘Which decisions can we hand to a machine?’ Here is the right one: ‘Which decisions, when they go wrong, legally and ethically require a human to own the outcome?’ The gap between those two framings looks small on paper but separates well-run organisations from those accumulating quiet liability. Most companies are drawing the boundary in exactly the wrong place — automating decisions that carry reputational and legal consequence while keeping humans waiting on routine steps where speed and consistency are what actually matter. That inversion is not just inefficiency; under the EU AI Act, now in active enforcement across its phased timeline, it is becoming a documented compliance gap.Consider a representative scenario that reflects a pattern seen repeatedly in the field. A mid-sized textiles exporter in Gaziantep, 312 employees, running three operational decision points through an AI agent fed by a RAG architecture: freight rate negotiation, stock replenishment triggering, and customer credit limit updates. The first two work well. The agent compares carrier quotes against historical performance, ranks suppliers by on-time delivery and damage rate, and surfaces a recommendation. An operations team member approves in under three minutes. On the credit limit side, however, the agent began proposing automatic increases to long-standing customers during contract renewal windows — a period when the firm’s relationship data showed positive signals but cash flow data showed deteriorating patterns. The operations manager approved without scrutiny. Three months later, two of those accounts left overdue receivables. The agent did not malfunction. The boundary definition did.The EU AI Act classifies certain decision categories — including commercial credit decisions and employment-related assessments — as high-risk AI systems, with corresponding human oversight requirements. Turkish companies exporting to EU markets are directly subject to this classification. But the Act provides a framework, not a checklist. The operational definition of ‘meaningful human oversight’ is left to each organisation to specify and document. Filling that gap is concrete management work. A practical structure uses three axes: consequence magnitude (how large is the financial and reputational damage if this decision is wrong?), reversibility (can the decision be undone within a reasonable window after execution?), and explainability (can you describe how the decision was reached to a customer or auditor in plain language?). Scoring each decision point on these three dimensions gives you the skeleton of your authority matrix — before you buy any software.The matrix resolves into three tiers. Tier one covers decisions delegated entirely to the agent: reversible, low financial exposure, rule pre-defined. Invoice matching, standard freight route selection, reorder-point breach notification to a supplier — these should write directly to the system. Waiting for a human approval on a reorder alert that fires 60 times a week is not governance; it is process drag. Tier two is where the agent proposes and a human authorises: customer credit limit changes, senior staff compensation adjustments, new supplier contracts. Here the agent produces the analysis; a qualified person signs. The qualifier matters — ‘qualified’ means the approver understands the underlying variables, not merely that they hold the right job title. Approval lag in tier two should not exceed 48 hours; if it does, either the process design is broken or the wrong person is in the approval seat. Tier three is reserved for decisions where a human decides and the agent supports: major workforce restructuring, terminating a primary supplier relationship, entering a new export market. The agent runs scenario analysis; the decision sits on a human manager’s shoulders. Do not frame tier three as ‘what AI cannot do.’ Frame it as ‘where human accountability is non-negotiable and legally documented.’How do you know the system is working? Three metrics give you the signal. First, approval lag: in tier-two decisions, what percentage of approvals complete within 24 hours? If fewer than 65 percent do, the bottleneck is structural — fix the process, not the agent. Second, override rate: how often do humans reject or materially change the agent’s proposal? A very low override rate is not a sign of accuracy; it is a sign that human review has become a formality. At a retail chain in İzmir operating 445 points of sale, stock replenishment recommendations were being modified less than nine percent of the time. When asked whether staff were reviewing or clicking, the silence was the answer. A healthy override rate — somewhere in the range of 16 to 32 percent depending on decision complexity — signals that the human in the loop is actually in the loop. Third, error cost distribution: track what share of total operational error cost originates from agent-initiated decisions, and whether that share is trending up or down quarter on quarter. If it is rising while override rates fall, the rubber-stamp dynamic is already entrenched.It is worth saying plainly: human-approved automation is far less safe than most organisations assume, and the assumption that an approval step equals human oversight is the single most dangerous misreading in the field right now. Oversight requires a person who understands the decision content, can evaluate an alternative, and is willing to reject the recommendation. Visibility — which is what most approval workflows actually deliver — means a human name appears in the audit log but functions as no real filter. The EU AI Act’s enforcement interpretations emerging through 2026 are beginning to distinguish between the two. Documented training records for approvers, approval logs with timestamps and decision rationale fields, and periodic override analysis are increasingly expected as evidence of real oversight, not just procedural presence. This is administrative work, but it is also the difference between a compliant system and one that looks compliant until an audit.Knowing where to draw the line matters more than which agent software you purchase. Build the authority map first; the technology follows the map, not the reverse. On Monday morning, three actions are available to any management team: list every decision point in your current automated workflows and score each on consequence magnitude and reversibility; pull your last six months of approval logs and flag every decision type where the override rate sits below 16 percent; then go one level back and assess whether the people currently sitting in approval seats for tier-two decisions have the domain knowledge to actually evaluate what they are signing. The Gaziantep textiles firm that inspired this piece — or the many like it — is not succeeding because it deployed better technology. It is succeeding because it defined accountability before it defined automation. The question remains open: which decisions does your organisation genuinely need a human to own — and does that human currently have the capacity to own them?
This article was originally published in Turkish by Gökhan MERCANOĞLU on August 12, 2026. The English edition has been reviewed and edited by the author.