{"id":750655,"date":"2026-06-21T10:45:13","date_gmt":"2026-06-21T10:45:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/750655\/"},"modified":"2026-06-21T10:45:13","modified_gmt":"2026-06-21T10:45:13","slug":"why-amazon-hates-human-in-the-loop-ai-governance","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/750655\/","title":{"rendered":"Why Amazon hates &#8216;human-in-the-loop&#8217; AI governance"},"content":{"rendered":"<p>Humans tend to be \u201ca little bit precious about humans,\u201d according to Eric Brandwine, distinguished engineer and VP at Amazon Security.\u00a0<\/p>\n<p>We like to think we are all very good at our jobs, and we have high opinions of ourselves, he explained during a phone interview with The Register. \u201cBut when you actually get down to it, humans are not terribly consistent,\u201d Brandwine said.\u00a0<\/p>\n<p>Humans, like AI agents and systems, are non-deterministic. Neither can be guaranteed to produce the same output given the same input twice. Both will make mistakes and even make stuff up. However, we\u2019ve got millennia of experience dealing with humans and less than a decade with more modern LLMs and the AI systems built on top of them.\u00a0<\/p>\n<p>\u201cWe know how humans fail,\u201d Brandwine said. \u201cWe&#8217;re comfortable with it. So human-in-the-loop isn\u2019t necessarily the gold standard.\u201d<\/p>\n<p>For years, vendors have told companies that the solution for dealing with any automated system was to put a human in the loop. That battle cry became much louder with the advent of modern AI systems and reached a fever pitch when enterprises started deploying agents into their IT environments.<\/p>\n<p>More recently, however, big tech is changing the way it talks about agentic governance and rethinking the whole human-in-the-loop concept.<\/p>\n<p>Normalization of deviance<\/p>\n<p>In 2017, Brandwine gave a talk on the <a href=\"https:\/\/www.youtube.com\/watch?v=KJiCfPXOW-U\" rel=\"nofollow noopener\" target=\"_blank\">normalization of deviance<\/a> at AWS\u2019 annual re:Invent conference.\u00a0<\/p>\n<p>It\u2019s a gradual process that happens when people in an organization take shortcuts, or don\u2019t follow the established procedures or standards, and sometimes it occurs over years. As long as nothing catastrophic happens, this deviant behavior becomes the norm.<\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/06\/5258659.webp\" width=\"480\" height=\"471\" alt=\"\" loading=\"lazy\" style=\"\"\/><\/p>\n<p>\n            Eric Brandwine, distinguished engineer and VP at Amazon Security<\/p>\n<p>\u201cIt\u2019s a thing all humans fall prey to, and one of the most heartbreaking stories I read in this area was about emergency departments and emergency rooms,\u201d Brandwine said during a phone interview with The Register. \u201cYou\u2019ve got all these machines, and they\u2019re all beeping. Your first day on the job, you jump every single time one of the alarms beeps \u2013 but the patient is fine. It&#8217;s a spurious alarm. You go back to your station, you sit down, and over time, after enough of these false alarms, enough of these repeated beeps with no actual consequence, your discipline slips, and you stop responding. And eventually some tragic outcome occurs.\u201d<\/p>\n<p>This, he admits, is a very high-stakes example. And yet it\u2019s a documented occurrence among <a href=\"https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC2821100\/\" rel=\"nofollow noopener\" target=\"_blank\">healthcare workers<\/a>, <a href=\"https:\/\/www.firefighterclosecalls.com\/firefighter-safety-the-normalization-of-deviance\/\" rel=\"nofollow noopener\" target=\"_blank\">firefighters<\/a>, and even <a href=\"https:\/\/safety.army.mil\/MEDIA\/Risk-Management-Magazine\/ArtMID\/7428\/ArticleID\/7233\/The-Normalization-of-Deviance\" rel=\"nofollow noopener\" target=\"_blank\">Army pilots<\/a>.<\/p>\n<p>\u201cLiterally, someone\u2019s life is on the line, and people still struggle to maintain discipline,\u201d Brandwine said. \u201cThat\u2019s the human condition.\u201d<\/p>\n<p>Here\u2019s how this all applies to agentic AI governance and security. Humans build LLMs and AI systems, and having a \u201chuman-in-the-loop\u201d ensures that a person reviews the AI\u2019s output and approves (or not) any actions before the AI performs them.<\/p>\n<p>\u201cIf you put a human inside of this tight loop, and ask them to make approval decisions for agentic tools repeatedly, time after time, they&#8217;ll do a good job,\u201d Brandwine said. \u201cAnd then they&#8217;ll do an okay job. And pretty quickly they&#8217;ll be doing a poor job.\u201d<\/p>\n<p>This is why at Amazon, \u201cwe\u2019re not huge fans of human-in-the-loop,\u201d he added. \u201cIt&#8217;s something that you should use judiciously, where you absolutely need it. But it\u2019s not something that you can do at high velocity. You will not get the results that you want to get.\u201d<\/p>\n<p>Big tech pulls the human-in-the-loop<\/p>\n<p>Amazon isn\u2019t the first or only tech giant to start talking differently about the role humans should play in agentic governance.\u00a0<\/p>\n<p>&#8220;It is very clear that we have moved from a human-led defense strategy, to a human-in-the-loop defense strategy, to an AI-led defense strategy that&#8217;s overseen by humans,&#8221; Google Cloud chief operating officer Francis deSouza <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/22\/google-unleashes-even-more-ai-security-agents-to-fight-crims\/5221298\" rel=\"nofollow noopener\" target=\"_blank\">told reporters<\/a> during a press conference ahead of Google&#8217;s annual Cloud Next shindig in April. &#8220;Our model for the future is an agentic fleet that does a lot of the routine cyber security work at a machine pace and then is overseen by humans.&#8221;<\/p>\n<p>Microsoft CEO Satya Nadella, in an X missive earlier this week, argued for \u201c<a href=\"https:\/\/x.com\/satyanadella\/article\/2066182223213293753\" rel=\"nofollow\">loop learning<\/a>,\u201d instead of having a human check an AI\u2019s output at every step.\u00a0<\/p>\n<p>\u201cCompanies need to turn their workflows, domain knowledge, and accumulated judgment into AI systems that improve with each use,\u201d Nadella wrote. \u201cPrivate evals should capture whether a model is actually improving against outcomes that matter to the business (not just external benchmarks!). Private reinforcement learning environments should let models grow stronger on real traces from inside the organization.\u201d<\/p>\n<p>Also this week, IBM execs called for <a href=\"https:\/\/www.ibm.com\/think\/insights\/liability-laundering-problem-human-in-the-loop-not-governance-strategy\" rel=\"nofollow noopener\" target=\"_blank\">human accountabilit<\/a>y \u2013 not humans in the loop \u2013 at all stages of AI development, deployment, and governance.\u00a0<\/p>\n<p>Amazon\u2019s alternative to human-in-the-loop is &#8220;accountability end to end,&#8221; according to Brandwine. This means human identity and ownership track through the entire workflow, even when humans aren&#8217;t directly approving every step.<\/p>\n<p>\u201cIf I sit down at my keyboard and I type a command that takes a service down, I caused an outage,\u201d Brandwine explained. \u201cIf I run a script that takes a service down, it&#8217;s still me that caused the outage. If my agent writes a script that they then run, and it causes an outage, that&#8217;s still my responsibility.\u201d<\/p>\n<p>(Secret) keys to the kingdom<\/p>\n<p>This also highlights the importance of <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/01\/29\/unaccounted-for-ai-agents-are-being-handed-wide-access\/5120939\" rel=\"nofollow noopener\" target=\"_blank\">managing and securing agentic identities<\/a>\u00a0\u2013 the accounts, tokens, and credentials assigned to AI agents so they can access corporate apps and data. At Amazon, all of the agents have independent identities assigned to them, we\u2019re told.\u00a0<\/p>\n<p>\u201cSo, as we track agentic activity across our systems, it does not show up in the logs as: \u2018Eric did this.\u2019 It shows up as: \u2018this agent did this on behalf of Eric,\u2019\u201d Brandwine said, adding that this isn\u2019t to \u201cmake people afraid to use this technology.\u201d<\/p>\n<p>\u201cIt\u2019s to make people pause and think: is this the right way to use this technology? Is this how I should be deploying this?\u201d We still have the humans involved, we still have the humans making decisions, but we&#8217;re trying to play to the strengths of the humans rather than placing them in this unfair, repeated decision making, human-in-the-loop position.\u201d<\/p>\n<p>Brandwine told us that Amazon has run into a couple of hurdles when it comes to deploying agents across its businesses, and one of the biggest is what he calls \u201cgoal-seeking behavior.\u201d This is when a person asks an agent to do a specific task &#8211; for example, upgrade a database\u00a0\u2013 and the agent becomes laser-focused on just one action to achieve this goal, ie, deleting the database.\u00a0\u00a0<\/p>\n<p>This is separate from prompt injection because there\u2019s no malicious input. \u201cIt\u2019s just the agent getting stuck on the wrong action,\u201d Brandwine said. Simply telling the agent, \u201cyou don\u2019t have permission to do this,\u201d is likely going to cause the agent to look for a different path to do the same thing (delete the database).\u00a0<\/p>\n<p>Telling the agent why it doesn\u2019t have permission to do something tends to produce a better outcome, according to Brandwine. This means telling the agent it\u2019s not allowed to do that, and the reason why is because it would cause a production impact. And also include \u201cdon\u2019t cause a production impact\u201d as part of the prompt.<\/p>\n<p>\u201cGiving it that extra feedback has gotten us dramatically better results,\u201d Brandwine said.\u00a0<\/p>\n<p>Of course, this is not a fail-proof method. \u201cYou still need to be careful with agents,\u201d Brandwine told us. \u201cWe have millennia of experience with humans. Agentic AI is a very, very new field, we don&#8217;t have an intuition for this, and one of the fundamental differences between agents and humans is that humans fear consequences,\u201d such as losing a job or even going to jail. Agents don\u2019t have these fears.<\/p>\n<p>This is where setting permissions on what the agent can and can\u2019t do or access comes in. Much like everything else with AI, it\u2019s nuanced, and it depends on the employee&#8217;s role in the company, and the company\u2019s tolerance for risk.<\/p>\n<p>\u201cThe person that wants to run the agent wants to give the agent many permissions because that makes the agent more powerful,\u201d Brandwine said. &#8220;It could do more things for them, it can recoup more of their time, it can deliver more.\u201d<\/p>\n<p>The security lead, on the other hand, wants to limit an agent\u2019s permissions, and this causes yet more tension between the security and development teams.\u00a0<\/p>\n<p>There is no one right solution or policy answer to solve this, according to Brandwine. Instead, it involves dynamic policies that set permissions based on the agent\u2019s specific task.<\/p>\n<p>There are some overarching, static guardrails \u2013 such as an agent must never perform destructive actions or delete entire servers\u00a0\u2013 and then there are policies underneath that establish the maximum set of privileges that the agent can have.<\/p>\n<p>\u201cThen we\u2019ll have a further scoped-down policy for this action, and there&#8217;s various techniques for automatically generating policies based on prompt and the end-user&#8217;s intent,\u201d Brandwine said.\u00a0<\/p>\n<p>Even for Amazon, it\u2019s not always easy. \u201cIt&#8217;s all driven by risk,\u201d he said. \u201cThis is a space that&#8217;s changing quickly, and so we&#8217;re trying to balance the risk of using untried, untested software against the risk of falling behind and not being able to deliver for our customers. As with all such things, it&#8217;s complicated.\u201d \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Humans tend to be \u201ca little bit precious about humans,\u201d according to Eric Brandwine, distinguished engineer and VP&hellip;\n","protected":false},"author":2,"featured_media":750656,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":["post-750655","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/750655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=750655"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/750655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/750656"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=750655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=750655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=750655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}