From Human-in-the-Loop to Human-on-the-Loop
Cognitive agentic AI replaces pre-specified logic with decisions generated at runtime — and why operational governance has to shift from human-in-the-loop to human-on-the-loop.
Chapter 2 of 7 in the joint white paper "BPM: Where Are We Headed? The Reinvention of Process Management in the Age of Agentic AI," written by BPM&O and bpExperts.
Key Message: Cognitive agentic AI replaces pre-specified logic with decisions generated at runtime. The governance of operational processes must therefore be rebuilt from human-in-the-loop to human-on-the-loop—with risk-based decision limits and auditable agent behavior.
2.1 The Technological Dimension: Breaking with the Deterministic Paradigm
The last two decades of digitalization have given rise to several automation paradigms—and they all share one common characteristic: they are deterministic. Robotic Process Automation (RPA) mimics human clicks using rigid scripts and is highly unstable—if a UI element or data format changes even slightly, the bot crashes. Low-code platforms such as Camunda, Monday.com, Jira, or ServiceNow solve this problem with structured workflow engines: more robust than RPA, but every exception and every new path must be explicitly modeled—flexibility comes at the cost of configuration effort. Application-centric approaches such as SAP or Salesforce take a third path: process logic is deeply embedded in the system, which enforces standardization and auditability but limits the speed of change and customization (see the 'Clean Core' discussion in Chapter 5). Each of these approaches has its merits, its strengths and weaknesses—but none of them decides. They execute what has been specified in advance: classic digitization, in which the human fully defines the logic and the system merely executes it thereafter.
Cognitive agentic AI fundamentally breaks this pattern. An AI agent uses Large Language Models (LLMs) to independently analyze goals, plan sequences of actions, and react dynamically to system changes—it decides probabilistically rather than executing deterministically based on rules. This shift from pre-specified to runtime-generated logic is the real break with everything RPA, low-code, and ERP-centric automation have achieved so far—and the reason why governance and control mechanisms must take on a fundamentally different, more rigorous form here than with any of the classical approaches that came before.
For technology strategy, a simple classification follows from this: classical, rule-based automation remains the tool for stable, structured routine tasks—reliable, but maintenance-intensive and prone to failure. Cognitive agentic AI takes over where unstructured information, exceptions, and dynamic decisions dominate, natively processing documents, emails, and images. Integrated orchestration platforms, finally, bring all three together—people, deterministic workflows, and agents—under a shared control and governance layer. Neither replaces the other; what matters is the orchestrated combination.
2.2 The New Risk: Invisible Autonomy—and How to Measure It
This new autonomy carries what is known as the 'invisible autonomy risk': because AI agents decide probabilistically rather than deterministically, there is a risk that they deviate from internal compliance policies unnoticed. A line of research already exists in response, though no established market practice has yet emerged: work from the process mining field (including RWTH Aachen / Fraunhofer FIT, 2026) proposes converting agent activities—prompts, tool calls, reasoning traces, token costs—into structured event logs modeled on the XES standard, making them analyzable with classical process mining algorithms. Related approaches such as 'Agent Miner' or recent work on 'Agentic AI Process Observability' pursue the same basic idea: making agent behavior visible not through the agents' own reports, but through objectively logged execution data.
For companies that deploy cognitive agentic AI operationally, we are developing a corresponding capability as an organizational control layer: Agent Behavior Mining (ABM) converts agent behavior into analyzable process data. Process owners can thus monitor behavioral patterns, run variance analyses, detect anomalies, and audit target-versus-actual deviations before damage occurs. This is not yet a standard procedure today—all the more reason to embed it early as a governance building block rather than improvising it later.
However, such a tool is only as good as the process foundation it is built on. Without documented target processes, clearly defined responsibilities, and established process governance, there is no reference point against which deviations can even be measured. This is exactly where the organizational dimension comes in.
2.3 The Organizational Dimension: From Human-in-the-Loop to Human-on-the-Loop
Process management means working on the process: consciously designing workflows—including clarifying who performs which step, using which resources, when, with what output, for which recipient—and then implementing, managing, and continuously analyzing and optimizing these workflows. As cognitive agentic AI is deployed, the design of individual process steps is increasingly determined autonomously by the AI—and this changes what human work on the process is actually focused on.
The classic human-in-the-loop (HITL) structure, in which every single decision made by an AI model is manually validated, breaks down under high transaction volumes and destroys the efficiency gain. Human work must therefore shift to the aggregated process level: to the deterministic definition of the process's framework conditions and outcome categories, including risk management and the decision-making authority derived from it.
The organization thus evolves into a human-on-the-loop (HOTL) operating model: by default, the AI acts autonomously within predefined limits, while the human takes on a supervisory role and only intervenes to steer the process in the event of serious exceptions or high risk. This requires clear classification matrices for decision risk: low-risk processes—such as automatically rebooking standard orders—run largely autonomously; high-risk processes—such as approving payments above a certain threshold, or amending framework agreements—mandatorily require multi-level human authorization.
The focus of control thus shifts from real-time approval of individual transactions to the architectural definition and continuous adjustment of these systemic decision limits. These decision limits should not be based on compliance alone, but should also reflect the expected value contribution of the respective process: where fast, autonomous decisions improve delivery capability or customer service, a greater degree of latitude can make sense. Where financial, legal, or reputational damage is possible, a correspondingly smaller degree. Monitoring and actively steering process runs thus gains considerably in importance and becomes the focus of human work (for more on this, see: TÜV Rheinland Podcademy: Process Management: Simply Getting Better and Better, October 2024).
Want the rest of the argument now instead of waiting for next week's chapter? The full white paper — written jointly by BPM&O and bpExperts — is available on request. Write to sales@bpexperts.de and we'll send it straight over.
