Law / Frameworks / FINOS AIGF / Preventative
FINOS AIGF AIR-PREV-024Human-in-the-Loop Action Approval Gate
A Human-in-the-Loop (HITL) Action Approval Gate is a preventive control that interrupts an agent immediately before it executes a designated high-risk action and holds execution until a human with the appropriate authority explicitly decides on the proposed action. Unlike privilege scoping (which governs what an agent may access) or feedback loops (which collect evaluative input for detection and improvement but do not themselves authorize the release of a particular action), the approval gate operates on the specific proposed action at the moment of execution, evaluating its resolved parameters and context against policy before any side effect occurs.FINOS AI Governance Framework, version 2, as maintained on , AIR-PREV-024
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: governance.
- 223
- laws
- 132
- places
- 0
- with court rulings behind them
- 35
- not yet in force
- 6
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
- CIS Controls3.2 A maintained catalogue of the sensitive data the enterprise holds and where it sits.
- CIS Controls8.2 Turning on and gathering logs from the enterprise's systems.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
72 laws, 71 placesShow the other 62 laws
Enforcement supervision
64 laws, 64 placesShow the other 54 laws
Sector security regimes
40 laws, 38 placesShow the other 30 laws
AI risk obligations
14 laws, 8 placesShow the other 4 laws
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance duty. What it requires |
AI governance
10 laws, 7 placesSecurity baseline statutes
9 laws, 9 placesAI sector rules
7 laws, 7 placesProduct security requirements
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance duty. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
AI transparency
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings |
Through its governance duty. What it requires |
Data subject rights
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Through its governance duty. What it requires |
Sensitive categories
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Law No. 025/2023, sensitive categories of personal data and children's data |
Through its governance duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.