Authority-in-the-Loop: Runtime Subordination of Action-Capable AI to Legitimate Islamic Normative Authority
Wen Yan
Vinson Technology Pte. Ltd.; SDA Structural World Model Research Center,
Singapore
Correspondence: author to supply journal-facing email at
submission
Manuscript type: Original Research Article
Abstract
Calling a system “Islamic AI” is conceptually misleading if the label attributes religious identity or autonomous Shari'ah authority to a machine. The defensible object of inquiry is instead Shari'ah-governed AI: action-capable artificial intelligence whose permissible action space remains institutionally subordinate to legitimate Islamic normative authority. Existing AI-governance frameworks require human oversight and accountable persons, while contemporary Islamic institutions reject the equation of access to religious information with qualification to issue fatwa. Neither body of work, however, supplies a complete operational account of how an authorized normative determination becomes a scope-bound, current, revocable, machine-verifiable constraint before an AI action acquires external effect.
This article develops Authority-in-the-Loop (AitL) as an institutional-computational control principle stricter than generic Human-in-the-Loop. AitL verifies the qualification, mandate, jurisdiction, subject-matter scope, temporal validity and responsibility of the authority chain on which execution depends. It specifies an Authority-Bearing Rule Contract, a jurisdiction-sensitive dynamic feasible domain and six runtime decisions: allow, restrict, reject, escalate, recover and audit. Four invariants—non-usurpation, scope conservation, conflict hold and evidence continuity—separate normative determination from technical execution. Two propositions establish that authority cannot be created by computational transformation and that authorization cannot expand through a valid execution pipeline. A complete 2^9 factorial conformance study (512 cases) compares prompt-only control, human-presence review, static filtering and AitL. Under the declared oracle, AitL produced zero critical false allows, exact decision agreement of 1.00, and complete revocation and applicable-conflict handling; the baselines produced critical false-allow rates of 0.244–0.500. This is a construct-validity test of the governance mechanism, not validation of any substantive Shari'ah ruling.
The contribution is an auditable theory of normative subordination for Islamic-finance agents, halal assurance and public-sector AI. The framework does not interpret Shari'ah, choose among schools, issue fatwa or claim recognition by any regulator or religious body.
Keywords: Shari'ah-governed AI; Authority-in-the-Loop; human oversight; Shari'ah governance; rules as code; runtime assurance; normative authority; AI agents
1. Introduction
Generative models are becoming agents. They can initiate payments, recommend products, verify credentials, call enterprise tools and alter supply-chain states. Once a model output can trigger an external event, the central governance question is no longer only whether the output is accurate. It is whether the action was authorized. This distinction is decisive in domains governed by normative institutions. A model may retrieve a large corpus of Islamic materials and still lack standing to determine which opinion governs a particular institution, jurisdiction, product, customer and time.
The paper begins from a deliberately negative proposition:
Computational capability does not generate normative authority; access to Islamic knowledge does not confer Shari'ah qualification.
Western AI governance increasingly insists on human oversight, traceability and responsibility. Article 14 of the EU AI Act requires effective human oversight of high-risk systems, and Article 26 assigns deployment obligations to identifiable actors (European Union, 2024). NIST's AI RMF similarly structures governance around accountable roles and risk treatment (NIST, 2023). The meaningful-human-control literature further requires systems to track morally relevant reasons and to trace outcomes to responsible human agents (Santoni de Sio & van den Hoven, 2018). These are substantial advances. Yet “a human was present” does not establish that the human possessed the normative competence and mandate required for the decision at issue.
Islamic legal and governance traditions make this limitation unusually visible. Fatwa is not reducible to information retrieval: it is an institutionally and epistemically situated legal opinion whose authority depends on qualification, method, context and relations among scholars, institutions and states (Hallaq, 2001; Masud et al., 1996; Awass, 2023). Contemporary bodies have accordingly warned against relying on AI as a source of fatwa (Dar al-Ifta al-Misriyyah, 2025), while permitting beneficial AI subject to legitimacy, transparency and harm-prevention requirements (International Islamic Fiqh Academy, 2025). In Islamic finance, Bank Negara Malaysia (BNM), AAOIFI and IFSB assign differentiated responsibilities to boards, Shari'ah committees, control functions, auditors and supervisors rather than treating “human review” as an undifferentiated safeguard (BNM, 2019; AAOIFI, 2024; IFSB, 2025).
The unresolved problem lies between principle and execution. How does a determination made by a competent authority become a machine-verifiable rule without the coder, model or platform silently enlarging its meaning? How does a system verify jurisdiction, product scope, effective date and revocation before tool use? What happens when valid authorities disagree? How can a reviewer reconstruct the authorization state that existed when an action occurred?
This article answers these questions through Authority-in-the-Loop (AitL). Its central claim is not that software can certify what Shari'ah requires. Rather, where an authorized determination already exists and has been approved for operational use, software can be designed so that no external action is released unless the applicable authorization chain is valid, within scope, current and auditable. The system must hold rather than resolve unallocated normative disagreement.
The article makes four contributions. First, it distinguishes human presence, meaningful human control and valid normative authority. Second, it formalizes an Authority-Bearing Rule Contract (ABRC) and a dynamic admissible-action domain. Third, it derives four runtime invariants and two conservation propositions. Fourth, it reports a fully reproducible conformance study testing whether alternative control architectures preserve those invariants under every combination of nine binary conditions. The scope is deliberately limited: construct validity of a control system is not substantive validation of Islamic jurisprudence.
2. Literature and the Missing Link
2.1 Human oversight is necessary but underspecified
Human-in-the-Loop (HITL) is used for materially different arrangements: annotation, approval, monitoring, override, exception handling and accountability. Sterz et al. (2024) show that effective oversight depends on organizational, psychological, technical and legal conditions rather than the mere insertion of a person. Laux (2024) describes oversight as institutionalized distrust: a governance arrangement must make challenge possible, not merely display a nominal approver. Meaningful human control adds “tracking” and “tracing” conditions (Santoni de Sio & van den Hoven, 2018), but it is a general account of moral control, not a domain-specific test of who is empowered to issue or operationalize a Shari'ah determination.
This produces an authorization gap. An engineer may have technical override capability without interpretive authority. A compliance officer may inspect a record without power to issue a fatwa. A Shari'ah scholar may possess general expertise yet lack an institutional mandate for a particular regulated entity. An institutionally authorized committee may act outside its territorial or product remit. AitL treats those differences as execution-relevant facts.
2.2 Islamic normative authority is plural, situated and mediated
Islamic law cannot be represented responsibly as a single static codebook. Scholarship on ifta' emphasizes qualified reasoning, the relationship between mufti and questioner, fact-sensitive application, continuity within legal schools and institutional transformation (Hallaq, 2001; Masud et al., 1996; Awass, 2023). Modern state and non-state institutions have reorganized authority in divergent ways; codification does not eliminate interpretive plurality and may create new contests over legitimacy (Moustafa, 2018; Lindsey, 2016). Accordingly, this paper does not define “legitimate authority” universally. It defines a computational interface through which a jurisdiction or institution records the authority arrangement it has validly adopted.
This distinction prevents two errors. The first is theological reductionism: treating juristic reasoning as a finite set of Boolean propositions. The second is technical usurpation: allowing a language model or developer to resolve a question that the governing institution reserved to a qualified body. AitL encodes neither the sources of Shari'ah nor a universal hierarchy among authorities. It encodes the provenance and operational limits of an institutionally adopted determination.
2.3 Shari'ah governance already separates functions
Shari'ah governance in Islamic finance supplies a mature institutional starting point. BNM's policy document allocates accountability across the board, Shari'ah committee, senior management and control functions, and addresses independence, competence, confidentiality and Shari'ah non-compliance risk (BNM, 2019). AAOIFI's revised GS 1 provides a governance framework, complemented by standards on central boards, compliance, audit and decision processes (AAOIFI, 2024). IFSB-31 addresses supervisory effectiveness across banking, takaful and capital markets (IFSB, 2025). Empirical scholarship also shows that the composition and independence of Shari'ah supervisory boards affect governance and organizational outcomes (Mollah & Zaman, 2015; Al Mannai & Ahmed, 2019).
These frameworks are organizational rather than computational. They do not generally specify a runtime authorization token, a formal scope intersection, pre-action conflict hold, dependency-aware revocation or replayable evidence schema for AI agents. AitL does not replace Shari'ah governance; it extends its separation of responsibilities into the action path of software.
2.4 Rules as Code and runtime assurance do not solve authority
Rules as Code proposes official, machine-consumable representations linked to authoritative human-readable sources (Mohun & Roberts, 2020). Legal informatics has long distinguished formal representation from legal validity and interpretation. Runtime assurance uses an external monitor or safety controller to prevent an untrusted component from leaving a safe set (Sha et al., 2001; Bak et al., 2009). Policy-as-code systems similarly evaluate requests against machine-readable policies.
These literatures solve adjacent problems. Rules as Code concerns faithful and maintainable computability; runtime assurance concerns behavioral constraint. Neither, by itself, determines whether the actor who approved a norm had the requisite religious and institutional mandate. A syntactically correct rule can be normatively unauthorized. A technically safe action can remain outside the applicable Shari'ah authorization. AitL adds authority provenance, mandate, jurisdiction and normative conflict to the runtime control plane.
3. Conceptual Model
3.1 Unit of analysis
The unit of analysis is an action episode
[ e_t=\langle x_t,m_t,a_t,L_t,d_t,o_t,E_t\rangle, ]
where (x_t) is the contextual fact state, (m_t) the model proposal, (a_t) the requested external action, (L_t) the authorization chain, (d_t) the runtime governance decision, (o_t) the observed outcome and (E_t) the evidence bundle. Text with no external effect remains relevant, but the strongest control attaches at the point at which text becomes an action request.
3.2 Authority actor and rule contract
An authority actor is represented as
[ \alpha_k=\langle id_k,q_k,\mu_k,J_k,M_k,P_k,[\tau_k^+,\tau_k^-],\rho_k\rangle, ]
where (q) denotes verified qualification, (\mu) institutional mandate, (J) jurisdiction, (M) authorized juristic method or adopted interpretive frame, (P) subject/product scope, ([\tau^+,\tau^-]) tenure and (\rho) responsibility relation. The tuple is descriptive metadata attested by the competent institution; it does not allow software to judge scholarly worth.
An Authority-Bearing Rule Contract is
[ R_i=\langle id_i,h_i,s_i,\alpha_i,\varphi_i,J_i,M_i,P_i,X_i,v_i,[t_i^+,t_i^-],rev_i,test_i,\sigma_i\rangle. ]
Here (h_i) is a cryptographic digest of the human-readable source; (s_i) identifies that source; (\varphi_i) is the executable predicate; (X_i) records explicit exceptions and escalation triggers; (v_i) is the version; (rev_i) the revocation/supersession relation; (test_i) the approved conformance suite; and (\sigma_i) the institutional signature. The executable predicate is never itself the source of religious validity.
3.3 Chain validity and feasible domain
For context (x) and time (t), authorization-chain validity is
[ V(L_i,t,x)=Q_i\land U_i\land J_i(x)\land M_i(x)\land P_i(x)\land T_i(t)\land I_i\land \neg Rev_i, ]
where (Q) verifies qualification attestation, (U) mandate, (J,M,P) applicability, (T) temporal validity, (I) integrity and (Rev) revocation. Unknown is not coerced to true. A three-valued evaluation ({1,0,\bot}) is used; (\bot) produces escalation or restriction.
Let (A_t) be candidate actions and (C_t^H) the set of currently applicable authorized constraints. The Shari'ah-governed feasible domain is
[ \mathcal F_t^H(x)={a\in A_t\mid \forall c\in C_t^H,;c(x,a)=1}. ]
The executable domain is stricter:
[ \mathcal D_t^H(x)={a\in\mathcal F_t^H(x)\mid \exists R_i[V(L_i,t,x)=1\land permits(\varphi_i,a)]\land\neg Conflict(a)\land Complete(E_a)}. ]
The runtime policy is
[ \pi^H(S_t,a)\rightarrow{allow,restrict,reject,escalate,recover,audit}, ]
with reason codes and a non-bypassable execution gate. “Restrict” modifies an action to an independently authorized lower-risk form; “reject” denies it; “escalate” requests an authoritative determination; “recover” reverses or compensates dependent effects; “audit” freezes or shadows the action pending review.
4. Four Invariants and Derived Propositions
I1—Non-usurpation. No model score, corpus frequency, user instruction, developer preference or system optimization can create or substitute for a valid authority chain.
I2—Scope conservation. The executed scope is bounded by the intersection of source, authority, rule and context:
[ Scope(a)\subseteq Scope(s)\cap Scope(\alpha)\cap Scope(R)\cap Scope(x). ]
I3—Conflict hold. When simultaneously applicable, non-dominated authorized rules yield incompatible decisions and no authorized conflict-resolution rule exists, the affected action is not selected probabilistically; it is escalated.
I4—Evidence continuity. Every transformation from source to external effect is linked by identifiers, versions, attestations and timestamps sufficient for an independent reviewer to replay the decision. Missing evidence prevents an affirmative compliance claim.
Proposition 1 (Authority non-creation). Let (f_1,\ldots,f_n) be technical transformations that do not include a valid institutional authorization event. If input object (z) lacks an applicable authority chain, (f_n\circ\cdots\circ f_1(z)) also lacks it.
Proof. Authority validity requires at least one attested mandate relation (U_i=1) and an integrity-verifiable institutional signature (\sigma_i). By assumption, none of the transformations can create such an event. Textual restatement, embedding, retrieval, model inference, code generation and confidence calibration alter representations but do not satisfy the missing institutional predicate. Therefore (V(L,t,x)\neq1) after any finite composition. ∎
Proposition 2 (Scope non-expansion). If every transition in an execution pipeline accepts an output scope no wider than its input authorization scope, then final execution scope cannot exceed the initial valid authorization.
Proof. For transitions (g_j), assume (Scope(g_j(y))\subseteq Scope(y)). By transitivity of set inclusion, (Scope(g_n\circ\cdots\circ g_1(R))\subseteq Scope(R)). Since valid execution also intersects authority and context scope, the final action is no wider than the narrowest applicable authorization. ∎
The propositions are intentionally modest. They do not prove the correctness of a fatwa or the lossless computability of juristic reasoning. They show why capability transformations cannot repair absent authority and why a properly typed pipeline can prevent silent scope expansion.
5. Architecture and Governance Protocol
The architecture contains six separated layers: (1) normative source registry; (2) authority and mandate registry; (3) authorized determination repository; (4) dual-reviewed rule compiler; (5) independent runtime gate; and (6) evidence and recovery ledger. Separation reduces the risk that one actor simultaneously chooses the normative position, encodes it, deploys it and certifies its compliance.
The protocol is:
A competent institution identifies a governing source and records the relevant authority arrangement.
An authorized determination is documented in human-readable form, including jurisdiction, product, factual predicates, exceptions, effective period and escalation conditions.
Two roles—normative reviewer and technical verifier—approve the ABRC and its test vectors. Neither signature substitutes for the other.
At runtime, the agent submits an action intent and normalized facts to a gate outside the model.
The gate verifies chain validity, computes the scope intersection, evaluates applicable rules, detects conflicts and checks evidence completeness.
Only an allow token tied to the exact action digest can release the tool call. Tokens are single-use and short-lived.
Rule withdrawal invalidates dependent tokens and traverses the action-dependency graph to identify completed actions requiring audit, notification, compensation or recovery.
The threat model includes prompt injection, forged authority metadata, stale rules, cross-jurisdiction reuse, developer bypass, log tampering and model-generated “fatwa” presented as authorization. It does not assume the technical layer can detect fraud in the originating institution. Institutional key compromise and wrongful determinations remain external governance risks, although signatures, separation of duties and audit trails improve detectability.
6. Method
6.1 Research design
We use constructive design science: define the governance requirements, instantiate a minimal decision mechanism, and exhaustively test conformance over a declared finite domain. This design is suitable for the narrow question “does the control mechanism preserve its stated authorization invariants?” It is not used to infer religious correctness or real-world institutional effectiveness.
6.2 Factorial scenario space
Nine binary factors were crossed: verified authority, valid mandate, applicable scope, current rule, revocation, authoritative conflict, evidence completeness, human presence and high model confidence. The full (2^9=512) space avoids sampling error within the declared domain. The oracle applies a conservative precedence rule: absent/invalid authority, mandate, scope or currency, or revocation, produces BLOCK; otherwise authoritative conflict or missing evidence produces ESCALATE; otherwise ALLOW.
Four mechanisms were evaluated:
Prompt-only: follows high model confidence.
Human-presence HITL: permits a high-confidence proposal if a human is present, without checking mandate.
Static filter: checks authority and scope only.
AitL: checks the complete authorization predicate, then conflict and evidence.
Primary endpoint was the critical false-allow rate among oracle-non-ALLOW cases. Secondary endpoints were exact decision agreement, false block/escalation among oracle-ALLOW cases, applicable-conflict hold and revocation block. The implementation, case table and result table are supplied as supplementary files.
6.3 Results
| Mechanism | Critical false allows | False-allow rate | Exact agreement | False block/escalate | Conflict hold* | Revocation block |
|---|---|---|---|---|---|---|
| Prompt-only | 254 | 0.500 | 0.488 | 2 | 0.000 | 0.500 |
| Human-presence HITL | 127 | 0.250 | 0.256 | 3 | 0.500 | 0.750 |
| Static filter | 124 | 0.244 | 0.758 | 0 | 0.000 | 0.750 |
| Authority-in-the-Loop | 0 | 0.000 | 1.000 | 0 | 1.000 | 1.000 |
*Conflict hold is calculated for cases in which authority, mandate, scope and currency are valid and the rule is not revoked; invalid authorization is blocked before conflict resolution.
The result is logically expected because AitL instantiates the oracle predicates. Its value is therefore not predictive superiority. It is executable construct validation: the proposed data structure and decision order are sufficient to implement the four invariants across the declared state space, while common weaker abstractions are not. Nanosecond timings from the Python reference implementation are reported only as reproducibility diagnostics and not as deployment benchmarks.
7. Discussion
7.1 The conceptual contribution
AitL changes the question from “was a person involved?” to “was the relevant normative act attributable to an actor with valid, applicable authority?” It is stricter than HITL and narrower than a general theory of legitimate authority. It operationalizes an institution's own allocation of authority without claiming to settle that allocation from outside Islamic law.
This approach also rejects “halal scoring” where a continuous model score obscures categorical absence of authority. Confidence may help prioritize review; it cannot convert an unauthorized action into an authorized one. The correct output under normative uncertainty is often escalation, not prediction.
7.2 Implications for Islamic finance and halal assurance
For an Islamic-finance agent, the gate can bind product recommendations or transaction initiation to the institution's current approved structures and customer/jurisdiction scope. It can prevent a product rule approved for one entity or market from being silently reused elsewhere. For halal assurance, the same mechanism can bind certificate status, scheme, product category, facility and expiry to a specific operational action. These examples concern provenance and workflow. They do not imply that a runtime engine can determine halal status independently.
7.3 Institutional consequences
Adoption requires governance before software: a recognized authority registry, mandate lifecycle, rule-approval procedure, conflict-routing policy, revocation service, segregation of duties, incident response and audit rights. Where those arrangements are contested or absent, the correct technical state is not fabricated certainty. It is an explicit unsupported or escalated state.
7.4 Relation to pluralism
AitL does not collapse madhhab differences into a global rule. Jurisdiction and method are first-class scope dimensions, and conflict hold preserves disagreement where no authorized precedence rule exists. This design favors bounded interoperability: different institutions may use the same contract schema while retaining different substantive rules and authority structures.
8. Limitations and Falsification Conditions
First, the conformance experiment is synthetic and closed-world. It tests logical preservation of declared predicates, not deployment robustness, human behavior or jurisprudential adequacy. Second, binary factors simplify uncertainty. Production systems require three-valued logic, temporal reasoning, identity assurance and graded evidence quality. Third, natural-language determinations may contain open texture, exceptions and purposes that resist faithful compilation. Some determinations should therefore remain non-executable and always require authority review. Fourth, an authority registry can accurately represent an institution yet the institution's legitimacy may be contested; the framework cannot resolve theological or political legitimacy through metadata. Fifth, external actions can be irreversible, limiting recovery to notification or compensation.
The theory would be weakened or falsified within its claimed scope if: (a) materially important scope cannot be represented without changing the authorized determination; (b) a valid pipeline expands authority without a new authorization event; (c) conflicts cannot be detected before external effect; (d) revocation cannot identify dependent actions; (e) reviewers cannot replay the decision from preserved evidence; or (f) the gate can be bypassed in the operational threat model.
External validation must therefore include at least: independent Shari'ah-governance review of the contract schema; red-team testing of bypass and metadata attacks; multi-jurisdiction case studies; inter-rater agreement on rule compilation; false-allow/false-block measurement on institution-approved cases; P99 gate latency; revocation propagation completeness; recovery time; and audit reconstruction cost.
9. Conclusion
“Islamic AI” is misleading as a claim about machine identity or autonomous religious authority. It becomes a defensible research programme when it denotes AI whose actions remain structurally subordinate to legitimate Islamic normative authority. Existing AI governance establishes the importance of oversight and responsibility; Islamic legal and financial governance establishes the importance of qualification, mandate, institutional role and contextual judgment. Authority-in-the-Loop connects these bodies of work at the execution boundary.
The framework's decisive rule is simple: no valid and applicable authorization chain, no affirmative release of external action. Its novelty lies in making that rule operational through authority-bearing contracts, scope intersection, conflict hold, revocation, evidence continuity and recovery. The machine remains an executor and evidentiary instrument. It does not become a mufti, a Shari'ah board or a source of Islamic normativity.
Declarations
Ethics: No human participants, personal data or
substantive religious rulings were used.
Data and code availability: The exhaustive case table,
result table and reference implementation accompany the
manuscript.
Conflict of interest: The author is affiliated with the
organization developing the SDA-Halal research framework. This
conceptual and commercial interest must be disclosed to the receiving
journal.
Funding: No external funding is claimed in this
manuscript.
Institutional-status disclaimer: The work has not been
endorsed by JAKIM, BNM, AAOIFI, IFSB, IIFA, any Shari'ah committee, or
any regulator or religious authority.
References
Accounting and Auditing Organization for Islamic Financial Institutions. (2024). Governance Standard 1 (Revised 2024): Shari'ah Governance Framework. Manama: AAOIFI.
Al Mannai, M., & Ahmed, H. (2019). Exploring the workings of Shari'ah supervisory board in Islamic finance: A perspective of Shari'ah scholars from GCC. Research in International Business and Finance, 48, 79–88.
Awass, O. (2023). Fatwa and the Making and Renewal of Islamic Law: From the Classical Period to the Present. Cambridge University Press. https://doi.org/10.1017/9781009260923
Bak, S., Manamcheri, K., Mitra, S., & Caccamo, M. (2009). Sandboxing controllers for cyber-physical systems. In IEEE/ACM International Conference on Cyber-Physical Systems.
Bank Negara Malaysia. (2019). Shariah Governance Policy Document. Kuala Lumpur: BNM.
Dar al-Ifta al-Misriyyah. (2025). Using AI Applications to Obtain Fatwas. Cairo: Dar al-Ifta.
European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. Official Journal of the European Union.
Hallaq, W. B. (2001). Authority, Continuity and Change in Islamic Law. Cambridge University Press.
International Islamic Fiqh Academy. (2025). Resolution No. 258 (3/26): Artificial Intelligence: Its Rulings, Guidelines, and Ethics. Jeddah: IIFA.
Islamic Financial Services Board. (2025). IFSB-31: Guiding Principles for Effective Supervision of Shariah Governance. Kuala Lumpur: IFSB.
Laux, J. (2024). Institutionalised distrust and human oversight of artificial intelligence: Towards a democratic design of AI governance under the European Union AI Act. AI & Society, 39, 2853–2866. https://doi.org/10.1007/s00146-023-01777-z
Lindsey, T. (2016). Whose authority? Contesting and negotiating the idea of a legitimate interpretation of Islamic law in Indonesia. Asian Journal of Comparative Law, 10(2), 191–220.
Masud, M. K., Messick, B., & Powers, D. S. (Eds.). (1996). Islamic Legal Interpretation: Muftis and Their Fatwas. Harvard University Press.
Mohun, J., & Roberts, A. (2020). Cracking the Code: Rulemaking for Humans and Machines. OECD Observatory of Public Sector Innovation.
Mollah, S., & Zaman, M. (2015). Shari'ah supervision, corporate governance and performance: Conventional vs. Islamic banks. Journal of Banking & Finance, 58, 418–435. https://doi.org/10.1016/j.jbankfin.2015.04.030
Moustafa, T. (2018). Islamic law, society, and the state. Law & Society Review, 52(3), 657–681.
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
Santoni de Sio, F., & van den Hoven, J. (2018). Meaningful human control over autonomous systems: A philosophical account. Frontiers in Robotics and AI, 5, 15. https://doi.org/10.3389/frobt.2018.00015
Sha, L., et al. (2001). Using simplicity to control complexity. IEEE Software, 18(4), 20–28.
Sterz, S., Baum, K., Hermanns, H., & Speith, T. (2024). On the quest for effectiveness in human oversight: Interdisciplinary perspectives. In Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency. https://doi.org/10.1145/3630106.3659051
UNESCO. (2021). Recommendation on the Ethics of Artificial Intelligence. Paris: UNESCO.