The Mind Is the Instrument Nobody Calibrated: AI Governance and Human Oversight
The Mind Is the Instrument Nobody Calibrated examines the overlooked cognitive dimension of AI governance in financial institutions. As banks, regulators and boards increasingly deploy and supervise AI systems, the assumption that a human remains capable of independently challenging an AI recommendation is becoming a governance risk in its own right. The article concludes that the human being responsible for supervising AI should itself become an explicit object of AI governance. The technology may be calibrated, validated and monitored, but the human instrument performing the oversight must be calibrated too.
By Dr Ohio O. Ojeagbase FICA, SFIDR // KREENO Global // ProbitasReport
Most AI governance rests on a quiet assumption. Somewhere in the system, a human remains in control, watching the machine, ready to intervene if it goes wrong. The EU AI Act codifies this belief, requiring effective human oversight for high-risk systems. But the regulatory timetable has shifted. The 2026 AI Omnibus deferred the application of high-risk rules for Article 6(2)/Annex III systems to 2 December 2027, and for Article 6(1)/Annex I systems embedded in regulated products to 2 August 2028. The delay creates room to ask a more uncomfortable question.
What if the human designated to provide oversight is not cognitively equipped to do it?
For a financial institution, this is not an abstract concern. A bank using AI to support credit assessment may meet every technical requirement for model governance. It may document its validation processes, track performance metrics, and maintain a formal approval workflow. A human officer formally approves every decision. But if that officer has gradually learned to accept the model's recommendations without independently testing borderline cases, the institution may have satisfied the architecture of human oversight without achieving its substance.
The cognitive condition of the human overseer is becoming a financial-risk variable.
Oversight as cognitive activity
Oversight is a cognitive activity, not a procedural checkbox. It requires understanding the task, recognising uncertainty, detecting when an answer is wrong, and having enough domain knowledge and confidence to override the system. Yet most governance frameworks measure the technology around the human while paying almost no attention to the cognitive condition of the human inside it.
Julie Hendry's 2026 review makes this argument directly. She points out that the evidence base for assuming humans can fulfil this role is surprisingly weak. Her central observation is that AI maturity and governance considerations rarely explore whether the people tasked with monitoring and responding to these systems actually possess the psychological and organisational capacity to do so effectively.
The problem usually doesn't announce itself as a dramatic failure. It creeps in. A system performs well repeatedly, users grow comfortable with it, its answers arrive quickly and confidently, and checking every output starts to feel inefficient. Attention drifts. Eventually, the human remains formally responsible while becoming progressively less involved in the reasoning. This is the familiar territory of automation bias and complacency. Goddard and colleagues showed that effective oversight depends on whether the human mind is free from the influence of expectations, workload, task complexity, time pressure, and the design of the decision-support system itself.
Jovchevski, Buijsman, and Neerincx distinguish between weaker and stronger forms of automation bias. In the weaker form, users follow automated recommendations without seeking contradictory evidence. In the stronger form, they defer to the system even when they are aware that contrary evidence exists. They describe this as an epistemic transfer of authority from the human decision-maker to the machine. That is precisely why cognitive readiness should be treated as a governance concern, not a soft issue for human resources.
- Protecting Africa's Mineral Value Chain Through Beneficiation Governance and Recovery Assurance
- Financial Fraud Prevention and Corporate Integrity in Nigeria: The Role of Feelers, Thinkers and Institutionalised Trust
The inheritance problem
One of the more disturbing findings in the emerging literature is that AI influence does not necessarily stop when the AI disappears. Vicente and Matute ran three experiments in which participants exposed to biased AI recommendations later reproduced those biases even when the AI was no longer present. They described this as evidence that humans can inherit AI bias.
The governance implication is substantial. The human overseer cannot always be treated as an independent corrective mechanism standing outside the technology. The interaction itself changes the person doing the overseeing. If repeated exposure alters what a person finds plausible or familiar, the oversight problem becomes recursive. The system influences the very judgment meant to supervise it. That is a different order of risk from a software defect, which can usually be located, corrected, and tested. Cognitive dependence is harder to see because the system may continue producing impressive productivity numbers while the human capacity to challenge it gradually weakens.
Cognitive surrender and knowledge collapse
Shaw and Nave give this problem a particularly useful name: cognitive surrender. In three preregistered experiments involving 1,372 participants and more than 9,500 trials, they examined what happened when people could consult an AI system while solving reasoning problems. Their Tri-System Theory proposes that AI can function as a third cognitive system outside the human mind—System 3—supplementing human reasoning but also creating the possibility that people will adopt AI outputs with minimal scrutiny, overriding intuition and deliberation. The danger is not that people use AI. The danger is that they stop recognising when they have transferred the act of reasoning to it. A calculator can perform a calculation while the human remains responsible for deciding what calculation is appropriate. An AI system can generate an answer while the human remains responsible for testing its assumptions, evidence, context, and consequences. Cognitive surrender occurs when that second layer disappears. The person does not merely use the answer. The person begins to adopt the answer as their own judgment.
That is why AI literacy cannot be defined simply as knowing how to operate the tool. A person can be highly proficient at prompting and deploying AI while becoming less willing to challenge its outputs. Technical fluency and cognitive independence are different capabilities.
There is a second, deeper risk. Not simply that people become less vigilant, but that they gradually stop acquiring the knowledge required for independent judgment. Acemoglu, Kong, and Ozdaglar model this as knowledge collapse. Their NBER working paper examines how agentic AI may substitute for human cognitive effort and thereby weaken the incentive to acquire and contribute to the general knowledge on which collective decision-making depends. A person cannot reliably identify a bad recommendation in a domain they no longer understand. The ultimate governance risk may therefore be less about AI making occasional mistakes and more about humans gradually losing the expertise necessary to recognize those mistakes.
The neuroscience question
This is where the evidence becomes more preliminary and deserves a cautious reading. In May 2026, Lardi and Partners released a Swiss workplace study using wearable EEG technology to measure cognitive workload during realistic tasks with and without AI support. The company reported significant differences in concentration, creativity, familiarity, and relaxation and argued that traditional productivity metrics fail to account for such differences. Lardi subsequently reported on LinkedIn a more than five hundred percent increase in familiarity with AI-generated outputs and a decrease in vigilance.
That result is interesting, but the publicly available information comes from a company press release and does not yet contain sufficient methodological detail, sample information, or statistical verification to establish the precise effect. A proper academic reading would treat it as an unsubstantiated pilot finding requiring further verification. This caution matters because neuroscience claims can acquire an authority that exceeds the evidence behind them. A 2025 Nature report on an MIT experiment examining brain activity during ChatGPT-assisted writing made precisely this point. The study attracted substantial attention, but scientists warned against drawing broad conclusions from a small experiment. EEG may eventually become useful for understanding human–AI interaction, but a governance framework should not depend on a dramatic neurological statistic before the underlying science has been independently replicated. The stronger argument already exists at the behavioral level.
- 5 Corporate Governance Failures That Cost African Companies Billions - And How to Avoid Them
- Nigeria's 2026 Banking Reset: Why NPLs Hit 9.85% and the NGN 500 Billion Recapitalisation Matters
The financial dimension
This is where the argument becomes directly relevant to financial institutions. The Financial Stability Board, in a consultation report published on 10 June 2026, set out twelve sound practices spanning organization-wide AI governance, risk management across the AI lifecycle, and management of AI-related cyber and third-party risks. The FSB strongly encouraged boards and senior management to reference the practices as they consider business strategy, technology adoption, and risk management in an increasingly AI-enabled environment. The board and senior management of financial institutions are strongly encouraged to reference the sound practices.
The Reserve Bank of India has proposed going further. In draft guidelines released on 24 June 2026, the RBI proposed mandating kill switches for all AI models deployed in banks and regulated entities—the ability to instantly override, suspend, or deactivate any AI model if it produces harmful or erroneous outputs. The draft framework also requires robust human oversight of all AI-driven decision-making, including override, suspension, and deactivation mechanisms. For the first time, the RBI is placing AI and model governance squarely at the board level, requiring every regulated entity to have a board-approved model risk management framework covering all models. The RBI has also flagged the risk of automation bias—the tendency of bank employees to over-rely on AI outputs without applying their own judgment.
The Office of the Superintendent of Financial Institutions in Canada issued a Technology Risk Bulletin on 13 July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions manage the technology's effect on their operations. OSFI warned that AI adoption can outpace governance frameworks, that AI systems can act with limited human oversight and with heightened reliance on third-party models, and that gaps in senior management understanding can lead to over-reliance on vendor-provided assessments, limiting effective scrutiny of AI behavior. Institutions should treat AI-generated output as an input to a decision, not the decision itself, while keeping a human accountable for anything material.
The Bank of England has signalled the need for bespoke AI regulation to contain risks to the financial system posed by increasingly capable agentic systems. In a speech on 30 June 2026 at the European Central Bank Forum, Deputy Governor Sarah Breeden set out how AI is reshaping finance at speed and explored how agentic AI is transforming cyber risk, markets, and payments. She argued that central banks must adapt fast, strengthen resilience, and cooperate globally to ensure the next technology surprise does not become a test of financial stability. Breeden warned that autonomous artificial intelligence agents risk causing "market meltdown" and may need tighter regulation. She noted that agentic AI systems can autonomously chain together sequences of actions and that the financial system looks likely to evolve quickly into one that operates more autonomously, at scale, and speed.
These regulatory developments share a common assumption: that human oversight is available, capable, and reliable. But they do not ask whether the humans providing that oversight remain cognitively capable of doing so. The regulatory architecture is being built on an assumption that the evidence suggests may be unwarranted.
Consider a concrete scenario. A bank deploys an AI system to assist with credit underwriting. The model has been validated and meets accuracy thresholds, and the institution documents its governance process. A human credit officer formally approves each decision. Over time, the officer notices that the model is almost always right. Checking its recommendations begins to feel like a waste of time. The officer approves faster, handles more cases, and meets productivity targets. Then a borderline application arrives. The model says approve. The officer, now accustomed to the model's reliability, approves it without close examination. The loan later defaults. The officer is still formally responsible, but the cognitive work of evaluation was never really performed.
The scenario is hypothetical, but the mechanism is not. It is the natural endpoint of automation bias in a high-volume, time-pressured environment. And it scales across the institution. If every credit officer has learned to defer to the model in the same way, the institution has a systemic problem that no individual governance document will capture. The same logic applies to investment management, fraud detection, compliance monitoring, insurance underwriting, and algorithmic trading. In each case, the architecture of human oversight may remain intact while its substance erodes.
- Kingdom Debt Management in Africa: Biblical Principles and Practical Strategies for Individuals, Businesses, and Faith-Based Organizations
- Integrity-Based Partnerships Strengthen Global Ecosystem Performance
Measuring cognitive sustainability
One response emerging from this literature is to treat human cognitive capability as something that can be assessed alongside technical capability. Kabashkin puts forward a Cognitive Sustainability Index with indicators such as autonomy, reflection, creativity, delegation, and reliance. The approach is useful because it does not presume delegation to be inherently questionable. Delegation can be efficient, reliance can be rational, and AI can increase productivity. The governance question is whether the overall configuration leaves the human able to understand, challenge, correct, and eventually operate without the system when circumstances require it.
That suggests a different type of organizational measurement. Instead of asking only how accurate the model is, how quickly it produces answers, and how much money it saves, organizations should also be asking how often employees independently verify AI outputs, whether they can identify deliberately seeded errors, and whether domain skills are being maintained. They should ask whether users can explain why an AI recommendation should be accepted or rejected and whether employees feel authorized to challenge AI-generated recommendations.
These are governance questions because they concern the reliability of the control itself.
The positive case for AI
A serious analysis must also resist the temptation to treat AI use as inherently corrosive. The evidence is more complicated. Research involving 250 employees at a technology consulting firm found that access to ChatGPT was associated with higher creativity ratings, particularly among employees with stronger metacognitive skills. These employees appeared more capable of using AI deliberately rather than passively.
This finding changes the policy question. The issue is not simply AI versus human cognition. It is the quality of the relationship between them. The same technology can support one person's thinking and substitute for another person's thinking. The difference may lie in metacognition, domain knowledge, task design, incentives, accountability, and the amount of authority transferred to the system. A blanket prohibition on AI would miss the point. The objective should be cognitive augmentation without cognitive abdication.
What organizations should measure now
The practical response does not require organizations to wait for a mature neuroscience of AI. They can begin with behavioral measures. A board, risk committee, or chief risk officer could establish a baseline of human oversight capability using controlled exercises. Employees responsible for reviewing AI-assisted decisions could be presented with deliberately flawed outputs and assessed on whether they identify the errors. The exercise could then be repeated under different conditions of workload, AI confidence, time pressure, and familiarity. The organization would then have something far more useful than a policy statement. It would have evidence about whether its human control actually works.
The second step is to examine skill retention. If employees increasingly delegate a task to AI, organizations should ask whether they can still perform the task independently when necessary. Critical functions should retain enough human expertise to allow meaningful challenge and recovery. The third is to examine the design of the human–AI interface. Automation bias is affected by how recommendations are presented, the level of information provided, accountability arrangements, workload, and user expectations.
A governance system should therefore make disagreement possible. A reviewer should have the time, information, authority, and organizational protection required to say the machine is wrong. If saying that is practically impossible, the organization does not have meaningful human oversight. It has ceremonial human presence.
Apostle Kreeno of KREENO GLOBAL (L) and Professor Emmanuel Ayodeji—CEO of ABUAD Business School (R)
From human-in-the-loop to human-capable governance
This is where the governance conversation needs to move. The phrase "human in the loop" tells us that a human occupies a position in the process. It tells us nothing about whether that person remains capable of exercising independent judgment.
A stronger model would ask whether the human is human-capable. That means retaining independent judgment: the ability to form and defend a view without simply inheriting the system's recommendation. It means domain competence: enough knowledge to recognize implausible or contextually inappropriate outputs. It means metacognition: the ability to recognize when one's own reasoning has been influenced by the system. It means attention: sufficient cognitive capacity and time to perform meaningful review. It means authority: the organizational power to reject or escalate an AI recommendation. And it means accountability: clear responsibility for decisions rather than allowing responsibility to disappear into the phrase "the algorithm recommended it."
This is a more demanding standard than simply placing a human somewhere in the workflow.
The EU AI Act timetable
The regulatory context for these concerns is shifting. The original EU AI Act, adopted in 2024, set 2 August 2026 as the date when high-risk rules would become applicable. The 2026 AI Omnibus deferred these obligations. For standalone high-risk AI systems covered by Annex III, the rules now apply from 2 December 2027. For high-risk AI systems embedded in regulated products covered by Annex I, the rules apply from 2 August 2028.
The important nuance is that 2 August 2026 was still a significant implementation date. The Commission began enforcing other AI Act provisions and transparency requirements on that date, while the high-risk rules received the extended timetable. The deferral creates an opportunity for institutions to prepare, but it also risks creating a false sense of security. The governance challenges described here are not waiting for the regulatory deadline. They are already present in organizations using AI today.
The boardroom dimension
Boards are beginning to recognize these risks. In April 2026, Cognizant became a test case by bringing AI oversight directly under its board and linking executive compensation to AI adoption. According to its proxy statement filed with the US Securities and Exchange Commission on 17 April 2026, the board provides active oversight of the company's AI strategy, governance, and risk management through a combination of full board review and delegated committee responsibilities. The compensation committee now factors AI-related initiatives into executive pay, including metrics linked to generative AI innovation and productivity improvements. The audit committee oversees internal controls, data security, and responsible AI practices, while the finance committee tracks AI's impact on pricing, productivity, and potential revenue streams. The company flagged risks related to the use of AI, including inaccurate outputs, bias, intellectual property concerns, and data privacy issues, underscoring the need for structured oversight and controls. This represents a significant shift toward treating AI governance as a core board responsibility rather than a technology initiative delegated to the chief technology officer.
The emerging regulatory consensus
The regulatory direction is becoming clearer. The FSB's consultation on sound practices for responsible AI adoption in finance, issued on 10 June 2026, explicitly addresses AI-specific aspects and risks that are relevant to financial institutions and financial stability. The Bank of England has signaled the need for bespoke AI regulation. Singapore has introduced the Safeguards for Agentic Finance at Runtime framework, which proposes governance checkpoints to verify and record an AI agent's proposed actions before execution. The FINOS AI Governance Framework for Financial Services has been designed to help financial institutions adopt responsible AI practices.
These developments share a common feature: they focus on governing the technology. They establish requirements for model validation, risk assessment, transparency, and oversight. But they do not address the cognitive condition of the humans providing that oversight. The assumption remains that human oversight is available and effective simply because it has been mandated.
The calibration problem
The central weakness in much AI governance is not that organizations have forgotten the human. They have remembered the human in the wrong way. They have treated the person as a passive component sitting at the end of a workflow, clicking approve, monitoring an alert, or remaining available for intervention. But the person is not a passive component. The person is the instrument through which oversight happens.
And instruments require calibration. A measuring device that has drifted cannot reliably measure the system it is supposed to monitor. The same goes for humans. If an AI is used repeatedly in a process where confidence, attention, knowledge, trust, and willingness to challenge are factors, the capacity of the human overseer may drift as well.
This is the governance issue lurking in the well-meant phrase "human oversight." It is not enough to know that a human is present. What is needed is assurance that the human retains the ability to see beyond what the machine sees.
The evidence currently supports concern about cognitive dependence, offloading, automation bias, and skill erosion more strongly than it supports a general claim of neurological or intellectual decline. That distinction matters. The emerging evidence does not warrant a conclusion that AI inevitably causes cognitive decline, but it does warrant that human cognitive capability should be an explicit object of AI governance. Organizations already measure models, cybersecurity, data quality, financial exposure, operational resilience, and regulatory compliance. They should begin measuring the capability on which meaningful human oversight depends.
For financial institutions, the implication is straightforward. A control that depends on human judgment cannot be treated as effective merely because a human has been assigned to it. Boards and regulators will increasingly need evidence that the people exercising AI oversight retain the competence, independence, and authority necessary to challenge the systems they supervise.
The mind is the instrument nobody calibrated. AI governance will remain incomplete until it does.
References
Acemoglu, D., Kong, D., & Ozdaglar, A. (2026). *AI, human cognition and knowledge collapse* (NBER Working Paper No. 34910). National Bureau of Economic Research. https://www.nber.org/papers/w34910
Bank of England. (2026, June 30). *Agents of change — speech by Sarah Breeden*. https://www.bankofengland.co.uk/speech/2026/june/agents-of-change-speech-by-sarah-breeden
European Union. (2024). *Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)*. Official Journal of the European Union. http://data.europa.eu/eli/reg/2024/1689/oj
European Commission. (2026, July 27). *AI Omnibus enters into force*. Digital Strategy. Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689, published 24 July 2026, entered into force 27 July 2026. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
Financial Stability Board. (2026, June 10). *Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report*. https://www.fsb.org/2026/06/sound-practices-for-responsible-adoption-of-artificial-intelligence-ai-consultation-report/
Gerlich, M. (2025). AI tools in society: Impacts on cognitive offloading and the future of critical thinking. *Societies, 15*(1), 6. https://doi.org/10.3390/soc15010006
Gerlich, M. (2025). Correction: Gerlich, M. AI tools in society: Impacts on cognitive offloading and the future of critical thinking. *Societies, 15*(9), 252. https://doi.org/10.3390/soc15090252
Goddard, K., Roudsari, A., & Wyatt, J. C. (2012). Automation bias: A systematic review of frequency, effect mediators, and mitigators. *Journal of the American Medical Informatics Association, 19*(1), 121–127. https://doi.org/10.1136/amiajnl-2011-000089
Jöhnk, J., Weißert, M., & Wyrtki, K. (2021). Ready or not, AI comes— An interview study of organizational AI readiness factors. *Business & Information Systems Engineering, 63*(1), 5–20. https://doi.org/10.1007/s12599-020-00676-7
Jones, N. (2025). Does using ChatGPT change your brain activity? Study sparks debate. *Nature, 643*(8070), 15–16. https://doi.org/10.1038/d41586-025-02005-y
Jovchevski, P., Buijsman, S., & Neerincx, M. (2026). What is wrong with automation bias? *Philosophy & Technology, 39*(2), 84. https://doi.org/10.1007/s13347-026-00852-1
Kabashkin, I. (2025). Cognitive atrophy paradox of AI–human interaction: From cognitive growth and atrophy to balance. *Information, 16*(11), 1009. https://doi.org/10.3390/info16111009
Lardi & Partner Consulting GmbH. (2026, May 22). *New neuroscience study reveals how AI is reshaping human thinking at work* [Press release]. EIN Presswire. https://www.einpresswire.com/article/xxxx [Use official EIN link – grey literature]
Office of the Superintendent of Financial Institutions. (2026, July 13). *Generative and Agentic Artificial Intelligence: Implications for Technology, Cyber Security, and Operational Resilience*. Government of Canada. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/generative-agentic-artificial-intelligence
Reserve Bank of India. (2026, June 24). *Draft framework on Model Risk Management – Guidance on Regulatory Principles for Model Risk Management*. https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=60610
Shaw, S. D., & Nave, G. (2026). *Thinking—fast, slow, and artificial: How AI is reshaping human reasoning and the rise of cognitive surrender*. Wharton School, University of Pennsylvania. https://doi.org/10.31234/osf.io/yk25n_v1
Vicente, L., & Matute, H. (2023). Humans inherit artificial intelligence biases. *Scientific Reports, 13*, 15737. https://doi.org/10.1038/s41598-023-42384-8
What's Your Reaction?







