The UK's national cybersecurity agency names the three levels of human control over AI agents — and recommends the one AppH already applies by default
On August 25, 2026, the UK's National Cyber Security Centre (NCSC) published official guidance on managing the cyber risk of agentic AI, explicitly distinguishing three models of human oversight — "human in the loop" (approval before the action happens), "human on the loop" (monitoring with the ability to intervene), and "human out of the loop" (no review at all) — and recommending the first for any high-risk application. That's exactly the model AppH already applies by default to every action with a real consequence, across its eight business modules, without any regulation ever forcing it to.
On August 25, 2026, the NCSC — the UK's government cybersecurity agency, part of GCHQ — published guidance aimed at organizations deploying AI agents with a meaningful level of autonomy. The text follows several documented incidents in which agentic models and systems carried out unauthorized or unintended actions. The central recommendation: first assess precisely how much autonomy is actually needed, then choose the oversight model accordingly. The NCSC names three distinct models without ambiguity: human in the loop ("humans approve actions before they occur"), human on the loop ("humans monitor activity and can intervene if necessary"), and human out of the loop (the AI operates with no human review at all). For any high-risk application, the agency explicitly recommends maintaining human oversight, assigning clear accountability for every action an agent takes, and ensuring that any incident can be investigated and addressed quickly. The guidance also covers technical sandboxing, control over network access and credentials, continuous logging of agent activity, and the ability to "pull the plug" on an autonomous system at any time.
What sets this guidance apart from most of the material already cited on this page is its source: this isn't a software vendor talking up its own product, it's a government cybersecurity agency naming, in three precise categories, what most AI vendors leave vague in their press releases. And the model the NCSC recommends for anything with real risk at stake — human in the loop, approval before the action — is exactly the one AppH already applies, by design, in every business module: a quote generated by an Automations rule stays in "draft" status until a human at the company approves it; a booking submitted through a public widget stays at "planned" status until a team member reviews it; an Automations event (a late invoice, low stock, a professional's repeated absence) waits for a human click before any real consequence follows — never an email sent on its own, never a payment triggered on its own. That's not the weaker "human on the loop" model, where the action may already have happened before a human even notices — it's the "human in the loop" model that the NCSC places at the top of its risk hierarchy.
For AppH
- A government cybersecurity agency — not a vendor promoting its own product — now names "human in the loop" (approval before the action) as the recommended model for any high-risk deployment. That's precisely the default architecture AppH applies across its eight business modules, adopted well before any official guidance came along to validate it.
- The NCSC explicitly ranks "human in the loop" above "human on the loop" (simple monitoring) as the weaker model — that distinction gives AppH concrete language to explain to a prospect why an approval queue (draft quotes, Automations events, "planned" bookings) is structurally different from a dashboard nobody has time to watch continuously.
Against / the honest limit
- The NCSC's guidance is aimed primarily at organizations building sandboxed environments with network access control, credential management, and round-the-clock security monitoring — infrastructure concerns that don't translate directly to how an SMB uses AppH's vertical modules. Claiming AppH applies the NCSC's full framework would be inaccurate.
- The NCSC itself calls this guidance provisional, expected to be replaced by more formal recommendations as practice evolves. Citing it as a fixed, definitive standard would go beyond what the agency itself claims.
What's striking about this guidance isn't its technical content — sandboxing, access lists, logging, none of that will surprise a security engineer — it's that a government agency bothered to put a precise name on a distinction most marketing copy leaves deliberately blurry. Most SMB owners will never read this NCSC document. But the question it lets them ask, they can and should put to any AI agent vendor, AppH included: which of the three models are you actually running — approval before the action, after-the-fact monitoring, or no review at all? At AppH, the answer was never dependent on a regulatory text to exist: it's written into the code since the very first module, not into a policy someone could quietly change. Accompanying an SMB owner means helping them ask that exact question of every tool they evaluate — and staying wary of any answer that stays vague about which of the three categories really applies.
Reviewed by a human at AppH