Human oversight in enterprise AI has a structural problem. Review every AI output individually and you've reintroduced the bottleneck the system was supposed to eliminate. Skip the review and you've built a compliance liability with nobody watching. Most enterprises are toggling between those two modes, and both of them erode ROI for different reasons. Humans should be involved in some capacity; that's a given. The question is where in the process their involvement actually adds value.
Krishnamurthy Rajesh is the CIO of Digital Transformation and AI Strategy at Vinmegham, an XRMROI brand, where he leads enterprise AI adoption, cybersecurity, and digital governance. A Certified Chief AI Officer (CAIO) from Copenhagen Compliance, he is a CIO100 Honoree (2024) by IDC, a CSO100 - The Resilient 100 (2024) honoree by IDC & Foundry, and a World CIO 200 - Legend (2025) honoree. Rajesh is also a CyberEdBoard member with a track record spanning greenfield IT setup, Zero Trust implementation, AI governance, and large-scale process transformation.
Rajesh argued that the framing itself is wrong. The choice isn't between human involvement and AI autonomy. It's between governing at the transaction level, where humans become bottlenecks or rubber stamps, and governing at the outcome level, where AI runs the workflow and humans monitor whether the system is performing within defined thresholds. "It shouldn't be 'in the loop.' It should be 'on the loop,'" he said. "Transactional authority should sit with AI. But managing outcomes, making sure the model isn't drifting or hallucinating, that has to be done by a human."
Transactional authority belongs to AI: Rajesh used invoice processing as the example. If AI handles invoice validation and a human checks every single output, you've introduced a bottleneck that cancels the efficiency gain. If the human rubber-stamps instead, you've created the appearance of oversight without any real governance. Neither version works. "If you're validating each invoice individually, your efficiency drops because you've reintroduced the human bottleneck. And if you skip the review entirely, there's a chance the output is wrong, and the person just rubber-stamps it," Rajesh said.
Outcome governance belongs to humans: The alternative is to let AI handle individual transactions while humans monitor whether the model is drifting, hallucinating, or producing outputs outside the expected range. "Once a model's been tested and it's producing the right result, it'll produce the right result again. But there's always a chance the model drifts and starts hallucinating, and that's what needs to be controlled, not every individual transaction," he said. This is what Rajesh means by "on the loop": humans aren't reviewing every output, but they're watching the system's behavior over time and intervening when it deviates.
The on-the-loop model requires clear governance infrastructure before any AI deployment begins. Rajesh was direct about this: most organizations launch AI projects without defining ownership, success criteria, exit thresholds, or cost ceilings, and then wonder why ROI turns negative. "Most organizations are under pressure. Some of it's peer pressure, some of it's because competitors are doing it and they feel they need to as well," he said. "But they're not clear on what the outcome should be, who owns it, or what the governance strategy looks like." The result is projects built on urgency rather than clarity, where nobody owns the outcome and nobody knows when to stop.
Process before technology: Rajesh argued that AI fails when it's layered on top of broken workflows. If invoices come in three different ways, through a phone call, an email, and a system entry, the inconsistency is a process problem. Fixing it after deployment is exponentially harder. "Set the process first, bring uniformity across all of it, and then put technology on top. If you try to do it piecemeal, it won't work," he said.
Checks at the board level, not the transaction level: Accountability has to be joint and hierarchical, not concentrated in a single person. Rajesh compared it to Master Data Management: just as MDM requires an agreed-upon structure across the organization, AI governance requires alignment on baselines, authority levels, and accountability that extends well beyond the initial deployment. "When you're setting up authority, setting up the structure, setting up the baseline, accountability has to be shared. It can't sit with one person," he said.
Define the exit before the entry: One of Rajesh's sharpest points was that enterprises need predetermined thresholds for when to kill a project. AI initiatives aren't guaranteed to succeed, and the cost of not knowing when to stop can exceed the cost of the project itself. "You need to know exactly when to say, 'I'm closing this.' Not every project is going to be 100% successful, and you need to accept that upfront," he said.
Shadow AI, in Rajesh's framing, is what happens when governance is absent. It isn't inherently wrong for employees to use AI tools outside formal channels. The problem is that uncontrolled usage leaks data outside the platform, creates compliance exposure, and burns through token budgets that nobody approved. "People think they can just ask as much as they want. The tokens get burned, the account gets blocked for a few hours, or the subscription bill shows up and finance says, 'What is this? We never signed off on this,'" he said.
Zero-based budgeting for AI: Rajesh applies the same zero-based approach to AI spend that he uses for broader IT budgets. Rather than starting from last year's allocation and adjusting, he starts from zero and justifies every dollar against current reality. "I don't take Capex and OPEX as a baseline. I always start from zero, based on where the organization actually is, and look for ways to reduce the overall cost." That discipline extends to prompt design and token consumption: if what you're asking isn't well-defined and specific, every query costs more than it should.
ROI is a composite metric: Rajesh pushed back on narrow ROI definitions that only track output or cost reduction. ROI for AI should include process efficiency, waste reduction, the broader value the model brings to decision-making, and whether the organization can see a wider picture without compromising its ecosystem. "ROI isn't just implementing a project and pulling a report. It's something you have to track in real time while things are happening, and that has to be done by a responsible person," he said. If model drift or security issues erode gains in one dimension while the topline shows 2% growth, the real number might be negative.
Rajesh's bottom line is that AI governance isn't a layer added after deployment. It's the precondition for deployment. Set the structure, define the thresholds, standardize the process, and assign accountability before the first model is trained. "Governance, roadmap, control mechanisms, checks and balances, cost projections, and knowing when to pull the plug. All of that needs to be clearly defined before you start," he said.