{
  "node_id": "mitre-atlas-mitigation-human-in-the-loop-for-ai-agent-actions",
  "title": "MITRE ATLAS Mitigation Human In-the-Loop for AI Agent Actions (AML.M0029) - Human In-the-Loop for High-Impact AI Agent Actions",
  "domain": "AI Governance & Law",
  "version": "1.0.1",
  "last_updated": "2026-07-22",
  "bluf": "This node operationalises MITRE ATLAS mitigation AML.M0029 (Human In-the-Loop for AI Agent Actions). Systems should require the user or another human stakeholder to approve AI agent actions before the agent takes them. The human approver may be technical staff or business unit SMEs depending on the use case. Separate tools, such as dedicated audit agents, may assist human approval, but final adjudication should be conducted by a human decision-maker. The security benefits from Human In-the-Loop policies may be at odds with operational overhead costs of additional approvals. To ease this, Human In-the-Loop policies should follow the degree of consequence of the task at hand. Minor, repetitive tasks performed by agents accessing basic tools may only require minimal human oversight, while agents employed in systems with significant consequences may necessitate approval from multiple stakeholders diversified across multiple organizations. It maps the mitigation to EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations and drives a 10-gate verification workflow that an AI agent can execute against any production system.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-ai-rmf-1-0",
    "eu-ai-act-2024",
    "iso-iec-42001-ai-management-system-2023",
    "owasp-agentic-top10",
    "owasp-llm-08-excessive-agency"
  ],
  "primary_citations_count": 6
}