
AI Agent Human Oversight: Why Humans Missed 1 in 3 Threats Approving Commands
When a human reviews an AI agent’s commands before they run, they miss roughly one in three threats. That is the headline finding of a study of more than 40,000 sessions and 409,000 individual approve-or-deny decisions, where players reviewed an AI coding agent’s shell commands under time pressure and achieved a mean accuracy of just 66.3%. The result is not a verdict on human competence — it is a verdict on a design pattern. Sustained vigilance is something humans are measurably bad at, and any security model that depends on it as the sole safeguard is built to fail. The fix is not better humans; it is better systems that layer sandboxing, scoped credentials, and surgical gating on top of human review. ...