The control everything else rests on
Across every framework in this area, human oversight is the mitigation of last resort. The model may be wrong, the data may drift, the guardrails may be bypassed, and the answer offered is that a person checks.
Which makes it the control most worth examining, because if it is nominal then every risk it supposedly mitigates is actually unmitigated, and the risk register is wrong in a way that is invisible from inside.
The uncomfortable finding when organisations look properly is that oversight is frequently a signature. A reviewer approving nearly everything a system proposes is not providing independent judgement; they are providing throughput with a name attached. The control appears in the register, appears in the process document, and does nothing.
The AI Act treats this seriously enough to legislate both halves. Article 14 requires the system to be built so oversight is possible. Article 26 requires the deployer to assign it to natural persons with the necessary competence, training and authority.
So oversight is a joint product of a system property and an organisational arrangement, and it fails if either is missing. A well-designed interface reviewed by someone with no time is as ineffective as a competent reviewer facing an opaque score.

