The override rate nobody has ever pulled
Human review is the control that justifies most of your AI risk tiering, but unlike every other control you own it produces no measurement, so the override rate has to be made computable before it can be evidence.
Ask what share of your busiest AI tool’s suggestions your people changed last quarter. Most organizations cannot produce the number quickly, and a good many cannot produce it at all, because nothing in the workflow records whether anything was changed.
That gap is worth more attention than the number would be.
Human review is the control doing the heaviest lifting in your register. It is what moves a tool from something that decides to something that assists, and almost every tiering decision you have made rests on it. It is also the only control you own with no instrument attached.
Look at the company it keeps. Access control produces an audit log. Downtime produces a monitor with a threshold. Encryption produces a scan somebody runs on a schedule. “A qualified person reviews the output before it is used” produces a checkbox on an approval form, ticked once, at deployment, and nothing after that. The control is asserted at the start and never sampled again.
The measurement that would sample it is unglamorous: how often the output is accepted without edit, by user, over time. A single reading of that rate tells you little. A tool may be accepted unchanged because it is good. What the rate cannot do is stay unexamined, because the direction is where the information is. A rate that climbs while the mix of cases stays flat is telling you something changed about the reviewing, and that is a question for the operational owner rather than the vendor.
Most systems cannot answer it because of how they were built, not because of who is asking. Workflows tend to persist the final state, not the difference between what was suggested and what was signed. So the honest answer is often “we would have to add capture for that” — which is a build question with a lead time, and a field that was never captured cannot be captured retroactively. That makes this a thing to ask now rather than in the quarter somebody needs the evidence.
The frameworks already treat oversight as measurable rather than merely designed. The NIST AI Risk Management Framework, published by NIST in January 2023, places human-AI configuration among the things to be measured, inside MEASURE. The Joint Commission’s September 2025 guidance with the Coalition for Health AI puts performance monitoring in the same structural position. Read either way, a policy stating that review occurs is not evidence that review is occurring, and the difference is exactly one number nobody has pulled.
Monday
Take the tool with the highest daily volume, find the analyst who owns its data, and ask one question: can we compute the accept-without-edit rate for last quarter? Do not ask what it is. Ask whether it is computable, write down the answer, and date it. If the answer is no, you have found the gap while it is still a configuration change instead of a finding.
You cannot govern a control that has never produced a number, and right now the strongest thing in your risk assessment is the one thing you have never measured.
One operational argument a week
The Operations Edge lands each Monday: a hook, one thing to use before lunch, and the full argument here in the archive. No vendor sponsorship, ever.
The instruments behind the writing
Every framework in the series is published as a working file: registers, protocols, audit rubrics and unit-economics models, sized to be used rather than admired.
See the toolkits The library← Your AI arrived in a release note, not a purchase order Trained in March, hired in July →
Published under the Institute's editorial standard.
Author: Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed against the standard on 2026-08-31.
Drafted as issue 10 of The Operations Edge, argued from operating experience rather than from a dataset. No rate is supplied because no dated, named source for a general figure exists; the two framework references are cited by publisher and date.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.