Agenda

Who Gets to Pull the Plug? Identity Governance and the AI Act's Oversight Gap [Intermediate]

Who Gets to Pull the Plug? Identity Governance and the AI Act's Oversight Gap [Intermediate]

Combined Session
Thursday, November 26, 2026 10:30—10:50

The EU AI Act obliges providers and deployers of high-risk AI systems to ensure "effective human oversight" (Art. 14) - including the ability to intervene or stop the system when needed. What reads like a straightforward process requirement turns out, on closer inspection, to be an identity and access governance problem that the regulation never actually solves:

The regulation never requires that the "natural person" assigned oversight duties be demonstrably qualified or certified - competence is assumed, never verified.
The technical access rights needed to actually intervene (stop button, override) are not tied to any privileged access framework - who gets these privileged rights, at what scope, with what logging, and with what revocation process, remains open.
Art. 12 requires logging the identity of the reviewing person for certain systems - but without any link to a broader identity lifecycle (role changes, offboarding, delegation), and without connection to a behavioral baseline against which "anomaly" could even be recognized.
The human overseer is expected to detect anomalies and intervene at the right moment - a requirement that's barely operational without identity threat detection-style mechanisms (continuous verification, context-aware access control) applied to the overseer's own access itself.

This talk bridges the legal analysis of the AI Act's oversight obligation with the concepts of modern identity-centric security — privileged access management, continuous authorization, identity governance - and shows how organizations can close this regulatory gap using existing IAM/PAM architectures, rather than waiting for the regulation to catch up.

Key Takeaways:

"Effective human oversight" under Art. 14 AI Act is not operationally meaningful without an underlying privileged access and identity governance framework - the regulation assumes it without actually mandating it.
Logging obligations under Art. 12 AI Act partially capture the identity of acting persons, but without any tie to identity lifecycle management or a reliable behavioral baseline.
Organizations can close this gap using existing ITDR/PAM/continuous authorization approaches - the talk offers concrete points of connection.

Bettina Sterner
Information Security & GRC Professional
Independent
Bettina Sterner, BA BA works across Data Protection, IT security, and AI governance — as practitioner, trainer, and author — always at the fault line most compliance work tries to...
Almost Ready for the ICC Summit 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.