1. The Received Tradition — Genealogy, Multidimensional Vocabulary, Controversy, and the Boundary Between Authority and Control
1.1. Genealogy
The idea that modes of cognition should be considered in the design of distributed systems does not begin with AI-IoT systems. Hamm (1989) constitutes a confirmed conceptual precedent: the accessible title and abstract of his work explicitly establish that modes of cognition should be considered in the design of systems requiring distributed decision-making. The degree of methodological overlap between that article and the proposal presented here remains, however, undetermined until the full text is examined. The reference also appears in the bibliography of Dhami and Thomson's review on the relevance of Cognitive Continuum Theory, which confirms its membership in the recognized genealogy of the Hammond tradition, but does not allow reconstructing its argument in detail.
That precedent is enough to fix a boundary of originality. This article's contribution is not to claim, for the first time, that modes of cognition are relevant to the design of distributed decision systems. That general link has already been formulated. The contribution lies in a contemporary operationalization for AI-IoT systems: translating the task's structural profile, defined by the properties of Cognitive Continuum Theory, into a conditional autonomy envelope; distributing authority between the algorithmic policy, the human supervisor, and physical safety mechanisms; specifying escalation, veto, suspension, and recovery triggers; and subsequently linking that architecture to an ecological audit of the decision chain.
Illankoon, Tretten, and Kumar (2019) also constitute a relevant, though not identical, antecedent. The authors propose a framework for understanding human cognition in the face of anomalous machine behavior, informed by theories of cognition, explicit and implicit knowledge, situation awareness, and, among other references, Cognitive Continuum Theory. Their contribution confirms that CCT is relevant to human-machine interaction in maintenance and to responding to technical anomalies. It does not, however, substitute for an explicit classification of tasks by CCT's eleven structural properties, nor for a typology of authority distribution between AI, human, and safety mechanisms.
The distinction matters because "considering cognition" is too broad a formula to guide design. A system may recognize that the operator has cognitive limitations and, even so, limit itself to adding more alerts, more dashboards, or more explanations to an architecture whose distribution of authority remains poorly defined. This article's question is more specific: given the structural properties of a cyber-physical task, when should the AI merely inform, when should it propose, when may it act subject to veto, and when — if ever — may it operate without contemporaneous human intervention?
The answer is not a fixed allocation of competences between "human" and "machine." It is a conditional architecture, dependent on regime, risk, available time, reversibility, data quality, and real recovery capacity.
1.2. Multidimensional Vocabulary
The most influential vocabulary for describing these choices was developed in the levels-of-automation tradition. Parasuraman, Sheridan, and Wickens (2000) proposed a model distinguishing four functional stages: information acquisition, information analysis, decision and action selection, and action implementation. The lasting importance of that model lies not only in its ten levels of automation, but in its implicit rejection of a too-simple idea: that a system can be described by a single, global degree of automation.
Automation is not a single variable. A system can automate data acquisition almost entirely — collecting sensor signals, filtering noise, synchronizing time series, and detecting anomalous values — while leaving interpretation to the human. It can automate analysis and classification while requiring human authorization before implementing the action. It can even automate a strictly delimited physical action, such as reducing load or stopping a machine at a safety limit, without automating the broader decision about maintenance, equipment replacement, or process reconfiguration.
The four architectures proposed further on are not, therefore, four points on a single scale of "how much to automate." They are configurations of authority over decision and action, compatible with different degrees of automation at each functional stage.
The genealogy of this tradition traces back to the so-called Fitts list, associated with Paul Fitts's (1951) report on human engineering for air navigation and traffic control. The list sought to distribute functions based on compared human and machine capabilities. This logic later became known, in abbreviated form, as MABA-MABA — Men Are Better At / Machines Are Better At. The attribution should, however, be made carefully: Fitts is the origin of the list and the comparative logic; he should not be presented as the author of the later acronym.
The historical influence of MABA-MABA logic does not make it sufficient. Dekker and Woods (2002) criticized precisely the idea that human-automation coordination could be resolved through a static substitution of functions: identify what humans would be better at, identify what machines would be better at, and divide the work accordingly. The problem is not merely that a fixed table of competences stops working when context changes. It is that the introduction of automation itself alters the human work the table intended to allocate. The operator stops directly executing certain tasks and instead comes to monitor, interpret, confirm, recover, manage exceptions, and respond to failures the earlier design may not have anticipated.
It is this critique that justifies the architecture proposed in this article. The question is not simply "who is better at this task?" It is: "what human work is created by automation, under which regimes is that work viable, and what authority should the human retain when the system leaves the domain it was designed for?"
1.3. Internal Controversy
The levels-of-automation tradition does not arrive at Article 4 as a peaceful set of results. It contains a relevant empirical controversy about the relationship between degree of automation, routine performance, situation awareness, and performance under failure.
Onnasch, Wickens, Li, and Manzey (2014) conducted a meta-analysis based on data from eighteen experiments. They found that higher levels of automation tend to improve routine performance and reduce workload when automation functions correctly, but can impair performance when automation fails and reduce operator situation awareness. This pattern became associated with the metaphor of the lumberjack effect: automation can increase performance while it cuts down the routine "trees," but leave the operator less prepared to act when the tool fails or when the situation stops being routine.
The result should not be turned into a simple law against automation. The literature itself suggests the effects depend on the automated functional stage, the interaction design, system reliability, the possibility of recovery, and the nature of the task. There are indications that negative consequences are especially relevant when automation crosses the boundary between automating information acquisition or analysis and automating decision or action selection. This possibility reinforces this article's thesis: the problem is not merely how much to automate; it is what to automate, at which functional stage, under which task conditions, and with what human recovery capacity.
The generalization of the lumberjack effect to complex work environments remains contested. Jamieson and Skraaning questioned whether the trade-offs identified in more controlled or laboratory tasks transfer directly to complex operational contexts. Wickens, Onnasch, Sebok, and Manzey responded that the critical study did not offer an adequate test of the effect; Jamieson and Skraaning replied, arguing that complex work environments are precisely those in which the generalization needs to be examined. The subsequent controversy further shifted the discussion to a prior conceptual question: Skraaning and Jamieson (2023) argued that "automation failure" is frequently used without a sufficiently clear definition, making comparison between studies, systems, and interventions difficult.
The consequence for this article is direct. The proposed typology does not resolve the controversy over automation and situation awareness; it inherits it. What it can do is make explicit the conditions under which a given distribution of authority appears defensible, and then require that choice to be audited against the system's actual behavior and against the environment.
1.4. Designed Authority vs. Effective Supervisory Capacity
The three preceding subsections share an assumption that must now be made explicit and then broken: that the human's position within an architecture — "in the loop," "on the loop" — describes their actual relationship to the system. It does not. It describes only the intended relationship.
This distinction fortunately has a direct and recent academic anchor. Sterz, Baum, Biewer, Hermanns, Lauber-Rönsberg, Meinel, and Langer (2024), in an article published at the ACM Conference on Fairness, Accountability, and Transparency, propose that human oversight of high-risk AI systems is only effective if the overseer has: sufficient causal power over the system and its effects; adequate epistemic access to the relevant aspects of the situation; self-control; and intentions fitting their role. The authors argue this is equivalent to requiring that the overseer be morally responsible and hold intentions compatible with that responsibility — oversight that is nominally assigned but devoid of any of these conditions is not oversight, it is legal fiction.
This article proposes an engineering operationalization of those four conditions, oriented toward real-time cyber-physical systems, and does not intend to replace or rediscover them: Sterz et al.'s causal power corresponds, in the operational context treated here, to the supervisor's real authority to countermand or suspend an action; epistemic access corresponds to the information available and interpretable at the moment of decision. To this base are added two dimensions that the human-factors literature on high-risk environments already treats as determinants of supervisory performance, even though Sterz et al.'s four philosophical conditions do not isolate them as separate categories: the time available to perceive, decide, and intervene — the same dimension the Onnasch et al. meta-analysis links to situation awareness — and workload, understood as the number of concurrent systems and alerts under supervision. This last dimension, together with competence to understand the situation and the recommendation, closely corresponds to the Performance Influencing Factors already established in high-risk industrial process safety engineering — namely time pressure, workload, and competence — which operators and maintenance engineers in contexts such as Argus's already recognize from their own safety vocabulary.
Effective human control thus depends jointly on five factors — information, time, competence, authority, workload — without this constituting a validated mathematical function; it is, in the same qualitative spirit as the chain equation not yet derived in Article 5, shorthand notation for a joint dependency, not a formula to be computed. An architecture formally human-on-the-loop is only substantively human-on-the-loop if these five factors are, jointly, sufficient. If one of them fails materially — for instance, if the time until harm is shorter than the time needed for detection, interpretation, and intervention — the system enters what this article terms supervisory decoupling: the failure in which the human remains formally responsible but ceases to be functionally connected to the cycle of perception, interpretation, decision, and intervention.
It is worth noting, too, that Sterz et al.'s last two conditions — self-control and intentions fitting the role — are not replaced by this operationalization, but find a direct empirical expression in the auditing architecture already developed in Article 5: the distinction between aggregate and the conditional weight is, properly speaking, a way of measuring precisely whether the supervisor's self-control in the face of the algorithmic recommendation is maintained — the signature of over-reliance is, read in light of Sterz et al., a failure of self-control made statistically visible.
Supervisory decoupling is not a fifth architecture. It is a cross-cutting mode of degradation that can affect any of the architectures formally designed to include human oversight — and it is precisely because it can occur without anything in the formal architecture changing that it is so hard to detect without auditing.
1.5. Positioning and Transition
The stance adopted here echoes that of Article 1 toward the Brunswik tradition and that of Article 3 toward Cognitive Continuum Theory. The levels-of-automation tradition, and now the literature on the effectiveness of human oversight, will be used as shared vocabulary and as a source of well-formulated problems; they will not be treated as validated truth nor as a universal scale of technical maturity.
The next section translates this vocabulary into four authority architectures: assisted human autonomy — the AI informs, recommends, prioritizes, or explains; the human decides and acts; human-in-the-loop — the AI proposes; the action requires explicit human authorization; human-on-the-loop — the AI may act within an envelope; the human monitors and may veto, suspend, or reconfigure in time; and bounded operational autonomy, also referred to as human-out-of-the-loop by design — the AI acts without contemporaneous human intervention in individual decisions, within an explicitly defined operational domain and safety limits. Each architecture will be defined not merely by the abstract degree of human intervention, but by who receives cues, who may authorize an action, who executes it, who may veto it, and who responds when the system leaves its intended regime — and each one, regardless of its formal design, remains vulnerable to the supervisory decoupling defined above.
In the assisted-human-autonomy and human-in-the-loop architectures, the central chain is
which Article 5 formalizes and audits directly. In the human-on-the-loop architecture, the default action chain is
but it can be interrupted, at any point within the available window, by a human intervention chain equivalent to the one above. In bounded operational autonomy, the operational chain reduces to the same form with no case-by-case interruption anticipated, human presence remaining at the level of envelope definition, validation, maintenance, and governance — not individual decision. These last two architectures therefore require an extension or a variant of chain auditing; they cannot be treated as mechanical applications of the two-stage model developed in Article 5.
Recognizing this limit does not weaken the typology. On the contrary: it prevents "human oversight" from being invoked as a comfortable label when, in practice, the person no longer holds contemporaneous decisional authority over the system's action — and it prepares the ground for Section 3, where the supervisory decoupling defined here becomes the instrument for examining the temptation to automate precisely those tasks that Article 3 classified as closest to the analytical pole.
