The 30% rule in AI says that AI can do about 70% of the work, while a person keeps the rest: judgment, exceptions and the final say. It is not a standard or a research finding. It is a rule of thumb that spread online in 2026. In our view, the number itself tells you very little. What matters more is who in the company owns each action the AI takes.

What is the 30% rule in AI?

Three different things travel under this name. The only thing they share is the number.

If someone at your company says "let's follow the 30% rule," they almost certainly mean the first one.

Where did the 70/30 rule come from?

Not from research. The phrase started circulating on tech blogs in 2026. One of the first pieces with a named author is a Forbes Business Council column by Luis Antonio Diaz from March 2026. Diaz describes it as his own working principle: AI takes over the routine, and people focus on work that needs experience.

The idea itself makes sense. AI is good at first drafts, sorting and lookups. People are needed wherever a decision has consequences. The problem is the number. Nobody has shown that 30% is the right human share rather than 10% or 60%.

Does the 30% rule come from McKinsey?

No. The 70/30 split has nothing to do with McKinsey. The 30% figure did appear in a 2023 McKinsey report, but it meant something else: a forecast of how many US work hours companies would manage to automate by 2030.

In November 2025, McKinsey published a newer report that measures something different. It finds that today's technology could, in theory, automate 57% of US work hours. McKinsey stresses that this is technical potential, not a forecast of layoffs.

Both reports describe the whole economy. Neither answers the question a business owner actually asks: which tasks can I hand to AI, and who should check them?

What should the human 30% actually be?

In our view, not a share of the work, but ownership. A 30% share that no specific person is responsible for is zero in practice.

A percentage measures how much work there is, and risk does not depend on that. Rejecting a job applicant takes an AI tool a few seconds and can still end in a complaint. A report the AI spent an hour on can contain a mistake with no consequences at all.

So instead of asking what percentage a person checks, ask about each action separately. Can the AI do it on its own? Does it have to wait for a person's approval? Or is it never allowed to do it? Then add one question about people: who exactly gives that approval?

One rule always applies: if an action can't be undone, the AI doesn't do it alone. A payment, an offer sent to a client, deleted data, a signed contract - AI can prepare any of these, but a person makes the final move.

What does this look like in practice?

Take a wholesale company with 15 employees that sets up an AI agent to handle its shared inbox. The agent reads customer emails, answers questions, takes complaints and prepares documents. Before it goes live, the owner sits down with the team for an hour and maps out what it does:

ActionWhat the agent doesWho approves
Question about order status, stock or opening hoursanswers on its ownnobody; once a week someone reviews a sample of replies
Complaintdrafts a reply and waitssales manager
Refundprepares the refund and waitsthe owner or the accountant
Discount or price changeprepares a proposal and waitsthe salesperson who handles that client
Changing a supplier's bank detailsneveronly a person, after calling the supplier
Messaging a client who hasn't written firstnever-

There is no percentage in this table, and it doesn't need one. What it does answer is the question that matters: who owns every case that has consequences.

The last step is turning the table into the agent's settings. An agreement made "in a meeting" is not enough. The agent has to stop on its own before a refund or a discount, and it shouldn't have access to bank details at all. We cover the same logic in our AI governance framework template.

How do you set these lines in your company?

One meeting per tool and five steps. You don't need a policy manual or a consultant for this.

  1. List what the tool can do. Not what you use it for today, but what it has access to. An agent connected to your inbox can read, reply, forward and delete emails, even if right now it only replies.
  2. For each action, ask whether it can be undone. A reply in the wrong tone can be fixed with the next email. A payment, a sent offer or deleted data can't.
  3. Give each action one of three settings. The AI does it alone, waits for approval, or never does it. An action that can't be undone never goes in the first group.
  4. Put a specific person next to each approval. Not "the sales team," but a name, plus a backup for when that person is on vacation. An approval that "someone" can give, in practice, nobody gives.
  5. Set it up in the tool and come back in a month. After four weeks, review what you approved. If something went through a hundred times without a single correction, it can move to the actions the AI does alone. If the AI kept getting something wrong, tighten the oversight.

A table like this also makes a good start for a company AI policy. You'll find a ready structure in our free AI policy template.

When is 30% too little, and when is it too much?

Too little for anything that can't be undone, because a person should approve every single case. Too much for low-risk routine work, where checking every third answer wastes time.

The hard part is telling what counts as routine. AI can handle tasks that look alike in very different ways. In a field experiment with 758 consultants, published in Organization Science in 2026, one task was picked so that AI would struggle with it. Consultants using AI reached the right answer 19 percentage points less often than those working on their own. And the task looked no different from the ones where AI helped.

That's why we recommend starting with broader oversight. For the first few weeks, check more than seems necessary and note where the AI gets things wrong. Then relax the checks where there are no mistakes, and keep them where mistakes repeat.

When does human oversight exist only on paper?

Most often when the rules are written down but nothing enforces them. Four traps are easy to miss:

All four have the same cause: oversight depends on people's good intentions, not on the tool's settings. We describe how to build controls that work regardless in can you trust AI in business.

What does the EU AI Act say about human oversight?

The EU AI Act sets no percentage. Article 14 requires high-risk AI systems to be built so that people can oversee them. The person overseeing must understand the system's limits, be able to disregard or change its output, and be able to stop it.

High-risk systems include, for example, tools used in hiring, employee evaluation and credit scoring. For these, the duties apply from December 2, 2027 (as of September 2026, after changes made by the so-called Digital Omnibus).

The chat assistants and writing tools most companies use are not high-risk. Still, Article 14 works well as a test for any agent: can a specific person see what the agent did, correct it and switch it off? We explain who the regulation covers in our EU AI Act guide for business.

How do you check whether your 30% exists?

Pick one AI tool that takes actions - sends, books, changes or pays - and run this five-question test on it. If any answer is "nobody" or "we assume so," your oversight exists only on paper.

  1. Owner. Is one specific person responsible for what the tool does? A name, not a department.
  2. Lines. Is it clear what the tool does alone, what waits for approval and what it never does?
  3. Enforcement. Does the tool stop by itself and wait for approval, or did you only agree on that in a meeting?
  4. Record. Can you see who approved which output, and when?
  5. Skill. Does the person who approves know where this tool most often gets things wrong?

You can answer the first two questions yourself in an afternoon. The third and fourth are harder to check from the inside. The gaps sit in the tool's settings, which the team doesn't see day to day. That is what an AI audit checks.

We check what your AI agent is allowed to do: what permissions it has, whether it can be tricked by instructions hidden in the content it reads, and what data it can access. You get a report with a fix list in five working days.

See AI Trust Layer
Read us regularly? Add as preferred source

Question five is about skills. Our AI workshops for companies teach your team where AI tools go wrong and how to check them, with documentation for Article 4 of the AI Act. Let's talk.

Frequently asked questions

Is the 30% rule an official standard?

No. No law, standards body or regulator defines a 30% human share. It is a rule of thumb that spread across tech blogs in 2026. The EU AI Act describes what human oversight must be able to do, not how much of the work it covers.

Is there a 30% AI rule for students?

Not an official one. Turnitin defines no allowed share of AI-written text and says its AI score should not be the only basis for action against a student. What counts is the written policy of your school or instructor.

Did McKinsey say AI will automate 30% of jobs?

No. In 2023, McKinsey estimated that up to 30% of US work hours could be automated by 2030 - hours, not jobs. In a November 2025 report, it found that today's technology could, in theory, automate 57% of work hours, and stressed that this is not a forecast of layoffs.

Should a business aim for a 70/30 split?

Not as a target. The 70/30 split can start the conversation, but the decision is made for each action separately: what the AI does alone, what waits for approval and what it never does. Actions that can't be undone always need a person.

Does the EU AI Act require a person to check 30% of AI output?

No. Article 14 sets no percentage. It requires that a person can understand a high-risk AI system, change its output and stop it. For high-risk systems such as hiring tools, the duties apply from December 2, 2027 (as of September 2026).