Public information siteInstitutional framework and operating programs continue to evolve

Practical AI Governance · Updated July 22, 2026

Human-Centered AI Framework

A practical way to keep human purpose, judgment, accountability, privacy, evidence, and correction at the center of AI—from the first use-case decision through monitoring and retirement.

What is human-centered AI?

AI should expand human capability without erasing human responsibility.

Human-centered AI is an approach to designing, deploying, and governing AI around the people who use it and the people affected by it. The goal is not simply to keep a person somewhere in the process. The goal is to make sure human needs define the purpose, human judgment remains meaningful, and people can understand, challenge, correct, or stop consequential outcomes.

This working framework translates that idea into seven connected controls. It is intended for leaders, product teams, domain professionals, technologists, reviewers, and communities deciding whether an AI-enabled workflow should exist—and under what limits.

Seven connected controls

Start with purpose. End with a real correction path.

01

Human purpose

02

Accountable ownership

03

Appropriate data

04

Meaningful human control

05

Understandable operation

06

Evidence before expansion

07

Monitoring and redress

01

Human purpose

What human outcome should improve?

Name the people affected, the problem being addressed, the benefit sought, and the outcome that must not be traded away for speed or scale.

02

Accountable ownership

Who is responsible when the system acts?

Assign a business owner, a domain owner, a technical owner, and an escalation owner. A model cannot accept responsibility or resolve a conflict.

03

Appropriate data

Should this data be used at all?

Limit collection to what the use case requires. Verify permission, quality, representativeness, retention, access, and the consequences of missing or incorrect data.

04

Meaningful human control

Where can a person review, override, or stop it?

Place human authority at the point where judgment changes an outcome—not after an irreversible action has already occurred.

05

Understandable operation

Can people understand the system well enough to use it safely?

Disclose when AI is involved, communicate limitations, preserve useful records, and provide explanations appropriate to the person making or receiving a decision.

06

Evidence before expansion

What proves the system is useful and acceptably safe?

Test accuracy, failure modes, accessibility, security, privacy, bias, user comprehension, and operational fit against predefined acceptance thresholds.

07

Monitoring and redress

How will problems be detected and corrected?

Monitor real outcomes, not only model performance. Give affected people a correction path, record incidents, and pause or retire systems that cross defined limits.

A six-step operating cycle

Move from principle to a controlled real-world decision.

Begin with one bounded workflow. Broad AI policies matter, but they do not reveal whether a specific use case has the right data, owners, control points, tests, and correction route.

  1. 01

    Define one decision

    Start with a specific workflow and decision boundary. “Use AI in operations” is too broad; “summarize support tickets for a human queue manager” can be evaluated.

  2. 02

    Map the people and consequences

    Identify users, subjects, reviewers, operators, people who may be excluded, and anyone who bears the cost of a wrong or delayed result.

  3. 03

    Set the control level

    Decide whether AI may inform, recommend, draft, act with approval, or act within narrow limits. Higher consequence requires stronger review and stopping power.

  4. 04

    Build the evidence plan

    Choose test cases, unacceptable failures, quality thresholds, security and privacy checks, accessibility checks, and a baseline for comparison with the current process.

  5. 05

    Pilot with visible ownership

    Run a bounded pilot with named owners, trained reviewers, feedback channels, event records, and a rollback path. Do not use hidden experimentation on people.

  6. 06

    Monitor, correct, and reapprove

    Review actual outcomes, overrides, complaints, drift, incidents, and changed conditions. Material changes to the model, data, purpose, or population require another review.

Human review must be capable, not ceremonial

The reviewer needs information, time, authority, and a safe way to disagree.

AI informs

The system organizes or summarizes information. A person still interprets the evidence and makes the decision.

Useful for lower-consequence support when sources and limitations remain visible.

AI recommends

The system proposes an action. A qualified reviewer checks the inputs, reasoning signals, alternatives, and potential impact.

Requires a genuine ability to reject the recommendation without penalty or friction.

AI acts within limits

The system may act only inside predefined boundaries, with monitoring, exception routing, rollback, and named stop authority.

Higher-consequence actions require stronger evidence and tighter boundaries.

Responsibility cannot be delegated to a model

Give each part of the decision a named human owner.

RoleOwns
Executive or program owner

Purpose, resources, risk appetite, accountable decision, and stop authority

Domain professional

Real-world requirements, judgment boundaries, failure severity, and review criteria

Product and operations

Workflow design, user communication, escalation, training, support, and outcome monitoring

Technical team

Data and model behavior, testing, observability, security, reliability, and change control

Privacy, security, legal, or compliance

Applicable requirements, sensitive-data controls, threat review, documentation, and required approvals

Independent reviewer or affected user

Challenge assumptions, test comprehension and accessibility, surface harms, and validate correction routes

Twelve questions before scale

If an answer is unclear, the next step is evidence—not expansion.

  1. The use case names a human outcome—not only efficiency, automation, or cost reduction.

  2. The people affected and the consequences of a wrong result are documented.

  3. A named person owns the decision, escalation path, and authority to stop the system.

  4. The system uses only data that is necessary, permitted, protected, and fit for purpose.

  5. Human reviewers have enough time, context, skill, and authority to disagree with the AI.

  6. Users can tell when AI materially shapes an interaction, recommendation, or decision.

  7. Known limitations and prohibited uses are visible to operators and reviewers.

  8. Tests include realistic edge cases, affected groups, accessibility, privacy, security, and misuse.

  9. Acceptance thresholds and unacceptable failures were defined before the pilot result was known.

  10. Logs support investigation without collecting unnecessary sensitive information.

  11. People can question, correct, appeal, or report an outcome through a usable route.

  12. Monitoring has an owner, review schedule, incident threshold, and retirement or rollback path.

Use established public guidance

A practical layer—not a replacement for recognized frameworks.

This guide is designed to work alongside established guidance. Teams can use its seven controls to organize the human questions inside broader risk-management and governance programs.

NIST AI Risk Management Framework

NIST organizes AI risk work through Govern, Map, Measure, and Manage. The human-purpose, ownership, evidence, and monitoring controls on this page can help teams ask who is affected and how those functions operate in a specific workflow.

Review the NIST AI RMF

OECD AI Principles

The OECD principles address inclusive growth, human rights and democratic values, transparency, robustness and safety, and accountability. They provide a policy-level reference for the operational questions in this guide.

Review the OECD AI Principles

References indicate source alignment only. They do not imply affiliation, endorsement, certification, or approval by NIST, OECD, the University of Maryland, IBM, or any other organization.

Human-centered AI FAQ

Clear boundaries make the framework usable.

What is human-centered AI?

Human-centered AI is an approach to designing, deploying, and governing AI around human needs, values, capabilities, judgment, and well-being. It uses automation to support people while preserving clear responsibility, appropriate human control, and a way to correct harm.

How is human-centered AI different from responsible AI?

The two approaches overlap. Responsible AI is a broad governance discipline covering safety, fairness, transparency, accountability, privacy, and compliance. Human-centered AI adds a persistent design question: does the system actually help the people affected, and do they retain meaningful agency and recourse?

Is having a human in the loop enough?

No. Human review is meaningful only when the reviewer has the information, competence, time, independence, and authority to change the outcome. A ceremonial approval click does not create human control.

Can a highly automated system still be human-centered?

Yes, when automation is appropriate to the consequence and people retain effective control through clear limits, monitoring, override, escalation, and redress. The right control design depends on what can happen when the system is wrong.

Where should an organization start?

Choose one bounded decision or workflow. Define its human purpose, affected people, consequence level, owner, control points, test thresholds, and correction route before selecting or configuring a model.

Does this framework certify an AI system?

No. This is an educational working framework. It is not a certification, accreditation, legal opinion, regulatory approval, or substitute for the professional and technical review required for a specific system or industry.

Continue through the Institute

Connect the AI framework to broader standards and accountability.