Netenrich Blog | Expert Cybersecurity Insights on SecOps, threats & more

AI Governance in Security: Human In or On the Loop

Written by Raju Chekuri | Thu, Jul 30, 2026 @ 05:00 AM

"Human in the loop" appears in virtually every AI governance in security conversation in security today — typically as a reassurance that humans remain in control, without much specificity about what that means operationally. I want to be more precise, because in security operations, precision matters.

There are two meaningfully different governance models that both get described as "human in the loop," and they produce very different operational outcomes.


1. Human In the Loop (HITL): High-Consequence Guardrails

Human-in-the-loop AI governance means a human reviews and approves each significant AI output before action is taken. Every alert that the AI scores as high priority is reviewed by an analyst before escalation. Every containment recommendation is approved before execution. This model is appropriate for consequential, irreversible, or genuinely ambiguous decisions — where the cost of an AI error is high enough and the action is specific enough that individual human judgment before execution is warranted.

  • Isolating an endpoint.
  • Blocking a user account.
  • Creating an external notification.
  • Escalating an incident to executive leadership.


2. Human On the Loop (HOTL): High-Volume Scalability

Human-on-the-loop cybersecurity means the AI acts autonomously within defined scope, and humans review system performance at the aggregate level rather than approving individual decisions.

This model is appropriate for high-volume, well-defined, low-consequence, and reversible tasks.

  • Alert enrichment with contextual data.
  • Threat intelligence lookup for indicators.
  • Alert classification into priority tiers for routing.
  • Post-incident report drafting from structured inputs.

For these tasks, requiring individual human approval before each action is impractical at the volumes security operations generate — and the value added by individual approval does not justify the overhead.


Operational Comparison: Structuring SOC AI Guardrails

Operational Dimension Human In the Loop (HITL) Human On the Loop (HOTL)
Governance Trigger Pre-execution review required for every individual action. Autonomous execution with post-action aggregate auditing.
Operational Scope High-consequence, irreversible, or high-ambiguity decisions. High-volume, highly repeatable, low-consequence, reversible tasks.
Impact on SOC Velocity Higher latency; bounded by analyst review speed. Zero latency; operates at machine execution speed.
Primary Oversight Metric Per-alert analyst approval rate and override ratio. Output distribution consistency, error rate, and drift telemetry.



Dynamic Governance: Trust Earned, Autonomy Expanded

The line between these models is not fixed — it moves based on two variables: the consequence category of the action and the demonstrated performance of the AI system for that specific task.

A task that starts as "human in the loop" during initial deployment may transition to "human on the loop" as the AI system demonstrates reliable performance over time and analysts develop calibrated confidence in its outputs for that task. The transition should be explicit, documented, and based on observed performance data rather than assumed after a period of time.

The phrase I use internally is: trust earned, autonomy expanded. Each agent's autonomy level is the current expression of the trust it has earned through demonstrated performance. We monitor that performance continuously — not at periodic audits. Output distribution shifts, error rate increases, or analyst disagreement patterns that exceed defined thresholds trigger immediate review and potential autonomy reduction.


Governed Agentic Operations in Production

At Netenrich, this framework is applied explicitly to each of our nine production agents. The governance architecture is documented:

  • What actions require "in the loop" approval,
  • What operates "on the loop,"
  • What conditions trigger escalation to human judgment.

Analysts know exactly what each agent does and where the human authority boundaries are.That clarity is what earns and maintains analyst trust. Trust is the foundation of effective AI-assisted security operations.

Operationalize Your AI Guardrails

Stop letting theoretical governance debates stall your SOC modernization. Deploy a Netenrich Agentic SOC to establish proven, dynamic human-in-the-loop guardrails, eliminate analyst burnout, and achieve a guaranteed 3-minute threat triage SLA.

*Part of my ongoing series on data science and the future of security operations.*

 
About the Author 


 

Raju Chekuri

A serial Silicon Valley entrepreneur and technology leader, Raju founded Netenrich and leads the company as chairman, president and CEO. Previously, he founded Velio Communications, Inc., and led its acquisition by LSI Logic and Rambus. He also served as chairman of the board at OpsRamp before it was acquired by HPE. He currently serves as an investor and advisor at early-stage startups Two Brothers Organic Farms and the Department of Lore. Raju earned an MBA at St. Mary’s College of California and a Bachelor of Technology at Kakatiya University.

Follow Raju on LinkedIn