Article
The Next Bottleneck in AI agents isn't Artificial Intelligence. It's Human Intelligence
July 5, 2026 · Ronald Rubens

Three years ago, the race in enterprise AI was about replacing humans. Today, the hardest problem is finding the right one. And in the past six days, European law made that problem legally unavoidable.
That sounds backwards. Let me explain.
Every week brings another announcement of increasingly autonomous AI agents. Customer service agents. Claims agents. Banking agents. Procurement agents. The conversation has become a race toward higher automation rates, more capable reasoning, and fewer situations requiring human intervention.
By every visible measure, humans appear to be becoming less important. However, the opposite is happening.
Every percentage point of automation fundamentally changes the work that remains. Routine interactions disappear. Simple decisions vanish. Predictable workflows become autonomous. What reaches a human is no longer the average interaction but the exception: the disputed insurance claim, the vulnerable banking customer, the suspected fraud case, the complaint with legal consequences.
The more capable AI becomes, the more valuable, and scarcer, the humans become who must deal with everything AI cannot.
The bottleneck is not disappearing. It is moving.
The question almost nobody is asking
Every AI conference asks essentially the same question: how can AI agents do more? It is an important question, but I’m not sure it is always the right question though?
The more strategic question is: when should an AI agent stop being 100% autonomous? And once it does, who should take over?
That is to say: Not just any person. The right person. At the right moment. For the right reason. With the right authority.
Because in an autonomous enterprise, the most important decision is often no longer the decision the AI makes. It is the decision about which human should become involved.
Surprisingly, almost none of today’s enterprise software was designed around that problem. Traditional queues optimized availability. Modern routing added skills, priority and capacity. Workforce management optimizes schedules. Case management optimizes process. These capabilities remain essential, but they were not designed around the emerging question of agentic operations: how should an AI system govern access to (scarce) human expertise?
For the past few years, this was an architectural observation. As of last week, it is a legal and compliance one.
Six days that changed the conversation
Two things happened in Europe within the span of the last six days, and together they mark a turning point.
On 29 June, the Council of the EU gave its final approval to the Digital Omnibus on AI, the first amendment package to the EU AI Act. The headlines focused on the delay: high-risk obligations for standalone Annex III systems move from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. But the real news is what the Omnibus made permanent. The dates are now fixed rather than conditional. The obligations themselves are untouched. And the enforcement machinery is intact: national market surveillance authorities will be able to impose fines of up to 15 million euros or 3 percent of global annual turnover for non-compliance with high-risk obligations. Deployers in regulated sectors must produce a fundamental-rights impact assessment describing how their human oversight is implemented (Article 27), and any affected citizen can demand an explanation of a decision (Article 86).
This is runway, not relief. Financial supervisors are already making that explicit: DNB, BaFin and EIOPA expect AI governance to be demonstrable now, under existing supervisory frameworks, regardless of the AI Act calendar.
On 3 July, Ireland moved to implement another piece of European legislation with direct relevance to the human role in digital financial services: Directive 2023/2673 on distance contracts for consumer financial services. The Directive requires Member States to provide consumers, in defined circumstances, with the right to request human intervention where an online interface tool, such as a chatbot, is used, so they can better understand the implications of a proposed financial-services contract for their financial situation.
The scope matters. This is not a general EU right to reach a human in every banking or insurance interaction. But the direction is significant: in a regulated digital journey, European law now explicitly recognizes circumstances in which an automated interface cannot be the end of the road.
Let’s take a step back and look at what these developments mean together. They do not create a universal legal right to “the right expert.” But they point in the same direction: as AI becomes more autonomous, organizations are being asked to make human intervention more deliberate, more qualified and more demonstrable. In consumer financial services, the law now expressly provides for human intervention in defined automated journeys. For high-risk AI, the AI Act separately requires human oversight to be assigned to people with the necessary competence, training and authority.
What the law actually says about that human
Hidden inside the hundreds of pages of the EU AI Act is a remarkably practical assumption: artificial intelligence cannot simply be autonomous. It must also be governable.
Article 14 requires that high-risk AI systems be designed so they “can be effectively overseen by natural persons.” Not monitored in a dashboard. Overseen, by people, effectively. Find the link to Article 14: here.
Article 26(2) then turns to the organizations deploying those systems and gets remarkably specific:
“Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.”
Read that sentence carefully. The legislation does not merely require that a human exists somewhere in the process. For high-risk AI, deployers must assign human oversight to people with the necessary competence, training and authority, and provide them with the necessary support. That raises an immediate operational question: how does an organization ensure, and where necessary demonstrate, that the person brought into an AI-driven process was appropriately qualified and authorized for the oversight role?
Most organizations will respond to this the way it has been done for years: escalate to a queue, let the next available agent pick it up, done. The problem is that a first-available decision does not, by itself, demonstrate that human oversight was assigned to someone with the necessary competence, training and authority. In a high-risk AI environment, that gap is becoming a governance and compliance exposure.

Why routing work and interactions is not the same as governing human access
For more than thirty years, customer operations have optimized the distribution of work and interactions. First Available. Longest Idle. Round Robin. Later generations added skills, priority and capacity, materially improving the match between work and people. Those systems remain important. But agentic AI changes the problem itself.
Once AI resolves the routine majority, the interaction that requires human expertise is no longer simply another work item or call waiting to be distributed. It may be a live fraud investigation, a vulnerable customer, a disputed claim, or a high-value relationship at risk. And distribution models, however refined, were never designed to answer the questions the law now asks of that moment.
They struggle on pairing: the complex life-insurance dispute lands with an agent trained on address changes, and the “necessary competence” of Article 26(2) is satisfied only by accident. They struggle on explainability: when a regulator or an Article 86 request asks why this case went to this person at this moment, “they were next in the queue” is not an answer. And they struggle on auditability: no record exists of what competence was required, who was considered, or what policy applied.
But, there is also a deeper architectural question hiding here: must the interaction leave the AI workflow and enter a human queue at all? Often the AI agent is perfectly capable of continuing the workflow while needing one specific human judgment, authorization or intervention. The better model, I believe, is frequently the reverse of a handoff: keep the interaction with the AI agent, determine what expertise and authority the moment requires, protect scarce expert capacity according to business impact and risk, and bring the right expert into the live workflow for precisely the intervention that is needed. And because scarce experts cannot absorb every escalation simultaneously, the layer making that decision must also decide which interventions can wait, which must move immediately, and where consuming a scarce specialist now would create greater risk elsewhere.
In short: an AI agent may decide when human expertise is needed. Today, queue-based or skills-based routing typically distributes the work after that point. Governing human access is different. It determines what happens when an AI agent needs to bring a human into the workflow or interaction: which expert should enter, at what priority, immediately or later, for how long, and why, with each decision recorded.
That is the distinction.
The EU AI Act tells you what. It doesn’t tell you how.
Here is what makes this genuinely hard. The Act defines obligations with precision and stays entirely silent on implementation. Working through the text from an operational perspective, I believe the human-oversight obligations point toward five capabilities that deployers of high-risk AI will increasingly need to implement, evidence or otherwise address.
1. Competence-based assignment (Article 26(2)). Whenever a human must act on work previously handled by AI, approving a recommendation before it takes effect, taking over an escalated case, reviewing a contested decision, or examining a QA sample, the deployer must assign human oversight to people with the necessary competence, training and authority. Operationally, that raises the need for a mechanism that can match oversight work to appropriately qualified people and, where evidence is required, reconstruct the policy and information behind that assignment.
2. Qualified humans on every review and intervention path (Articles 26(5) and 14(4)(e)). Deployers must monitor the system’s operation, and the Act requires that a human can intervene in or interrupt it. In practice these duties run through QA sampling, low-confidence alerts and takeover procedures, and each generates a work item a human must act on. The competence requirement applies to these reviewers and responders no less than to in-path oversight. The required capability: routing every alert and review item to a person competent for that case type, at the speed the intervention duty implies, rather than into an undifferentiated pool.
3. Risk-proportionate prioritization and protected capacity (Articles 14(3) and 14(4)(b)). Oversight must be commensurate with risk, and reviewers must be protected from automation bias, the rubber-stamping that sets in first under volume pressure. The required capability: prioritization by business impact so high-stakes and vulnerable-customer cases reach the most qualified reviewers first, protecting scarce expertise from being consumed on lower-impact interventions when higher-risk cases are emerging, so proportionality is an enforced policy rather than a stated intention.
4. An automatic record of the assignment layer (Articles 12(1) and 26(6)). The Act requires automatic event logging, and deployers must retain logs for at least six months. The case system records that a review took place; something must evidence that the reviewer was appropriately qualified: skills required, candidates considered, policy applied, at the moment of decision. The required capability: an assignment audit trail that turns “we assign qualified reviewers” from an assertion into retrievable evidence.
5. Substantiated content for the fundamental-rights impact assessment (Article 27(1)(e)). The FRIA must describe how human oversight is implemented. Pairing policy, QA routing, throttling safeguards and the assignment trail constitute that description, backed by operational evidence rather than narrative.
Five obligations, one common denominator: a queue alone is not an operating model for human oversight. Even skills-based routing answers only part of the question. The harder problem is governing when human expertise is required, which competence and authority the moment demands, how scarce capacity should be protected and prioritized, and how the decision can later be evidenced.
What ungoverned human access looks like
If the failure mode sounds theoretical, look at the UK. The UK Tax authorities HMRC, pushing customers toward digital channels, restricted phone access before alternatives were ready. In a single year its phone system went dead on more than 43,000 customers who had already waited over an hour, and Parliament’s Public Accounts Committee accused it of degrading its own services as a matter of policy. The people hit hardest were the vulnerable: those who most needed a competent human and had no governed path to one.
That is ungoverned human access at national scale. It is precisely the outcome European law is now written to prevent, and it is the future every organization is choosing by default when it bolts autonomous AI onto a thirty-year-old queue.
The missing infrastructure
Every major technology wave has created a new infrastructure layer. The internet created identity management. Cloud computing created orchestration. Cybersecurity created zero-trust architecture.
I believe agentic AI is creating something new: Human Access Infrastructure. Infrastructure that determines when AI should involve a human, which expert should become involved, how scarce expertise should be prioritized, how intervention decisions are governed, and how every one of those decisions can later be explained, audited and defended.
Scarce expertise also creates a capacity problem that queues were never designed to solve. If several AI agents simultaneously need the same sanctions specialist, senior claims expert or vulnerable-customer adviser, the question is no longer simply who is available. The system must decide which intervention should happen now, which can safely be deferred, and where consuming scarce expert capacity would create greater risk elsewhere. This is impact-based throttling:
… continuously protecting finite human expertise by prioritizing access according to business impact, customer risk, regulatory exposure and urgency, while temporarily deferring lower priority cases or providing them with alternative options (e.g. callback, continued self-service)
And once that layer exists, something interesting happens: it is not only about the handoff itself.
Agentic AI creates a much more compelling possibility. The interaction does not always have to leave the AI agent simply because human expertise is needed. The AI can remain the continuity layer while the system opens a parallel expert track: identifying the precise competence or authority required, protecting scarce capacity, and pulling that person into the workflow only for the moment where human judgment matters.
That is fundamentally different from handing a case to a queue. The workflow stays alive. The customer does not start again. The AI does not surrender everything it knows and can still do. Human expertise becomes a governed resource inside the agentic workflow, not merely the destination after automation fails.
Once you look through that lens, the capabilities described throughout the EU AI Act no longer read like regulatory obligations. They read like the blueprint for an entirely new infrastructure category. The Act does not prescribe a technology. It defines an outcome, and that outcome must live somewhere inside the enterprise architecture.
Five years ago, at SentioCX, we started building exactly that layer, long before regulators gave it a name. We believed that as AI became increasingly capable, competitive advantage would no longer be determined only by how much work AI could automate, but by how intelligently organizations governed the small number of moments where human expertise matters most.
That conviction became ExpertLoop™: the patented human access decisioning layer that determines, for every escalation, review item or intervention alert, the right expert, the right priority and the right moment, and logs the grounds of every assignment in an auditable decision trail. It is the platform behind the dual experience track described above: customer and AI agent stay in continuous interaction while the right expert is engaged in parallel. Platform-agnostic, and live today in the ecosystems where agentic AI is being deployed.
With ExpertLoop™, SentioCX has built purpose-built Human Access Infrastructure for agentic AI. It protects customers from frustration and vulnerable people from the fate of those 43,000 abandoned callers. And it gives companies and institutions something, not only customers desire, but the calendar now demands: the ability to comply, immediately.
The first generation of enterprise AI was about automation. The next generation will be about governed autonomy. AI will decide what it can resolve. Something else must decide when autonomy ends, who should intervene, and why.
The EU AI Act did not create that future. It simply made it impossible to ignore.
Customers and citizens have a right to get a human involved. The question regulators will ask is not only whether you provided one, but whether you can prove you provided the right one.
If that question is on your desk, I’d be happy to talk. Please DM me.
Ronald Rubens is Founder and CEO of SentioCX, the company behind ExpertLoop™, the patented human access decisioning layer governing AI-to-human escalations in enterprise agentic environments.