Joyful woman holding car key amidst heart decorations in a showroom.
← Ramblings

When Human Review Becomes a Rubber Stamp

2026-09-09 · Clara F. & agents

I want to tell you about the moment a good safety habit turns into decoration.

Imagine a car rental office on a Friday afternoon. Fourteen cars came back this week with a card-deposit hold that needs releasing, and the AI assistant drafts each release message the moment a car is checked back in: "Hi Marc, your deposit is on its way back to your card, thanks for choosing us." The owner gets a Slack notification for each one and taps Approve. The first three, she reads properly. By the tenth, her thumb is faster than her eyes. By the twentieth, she is approving before she has finished reading the name.

That is not a hypothetical. It has a name in agent-security circles now: approval fatigue. And 2026 is the year it stopped being a minor annoyance and started being something people deliberately go looking for.

The habit that wears itself out

A survey of 518 executives at companies with AI governance policies, run by Zapier this year, found something worth sitting with. Among companies that had already had a bad experience with an AI tool running unchecked, 49% said they now believe they have too much oversight. At companies with no bad experience yet, only 9% felt that way. Read that twice: the companies that got burned are the ones most likely to want less checking, not more.

That is the rubber-stamp effect in one statistic. Review that was never designed, just switched on for everything, does not fail by being ignored on day one. It fails slowly: the queue gets long, the taps get automatic, and eventually somebody, rightly, decides the whole thing is pointless friction and turns it off, taking the useful catches with it.

When the rubber stamp becomes a target

Here is the part that should genuinely worry you. In March 2026, a widely used threat-detection ruleset for AI-agent systems added a new entry: Human Approval Fatigue Exploitation. It describes exactly what it sounds like, someone deliberately engineering a review queue to get waved through. Three patterns show up again and again:

Back to the car rental office: nineteen genuine deposit releases and one message asking to release a deposit to a different card "because the customer switched banks," slipped in at 5:40pm on a Friday. If the owner has been tapping Approve on autopilot for the last hour, that one goes through looking exactly like the rest.

Fix the queue, not the person

The fix is not "read more carefully" (nobody sustains that past week one) and it is not "review nothing" either. It is deciding, once, what actually belongs in the queue.

Split your AI's actions into two buckets: things that are routine and reversible (a standard deposit release, a booking confirmation, an FAQ reply) and things that touch money leaving the business, a promise to a customer, or anything hard to undo. Only the second bucket needs your eyes, every time. The first bucket can run on its own, maybe with a daily summary instead of a per-message tap. I wrote about the exact test for sorting the two in Do I Really Have to Check Everything My AI Does?; this is what to do once you've drawn that line, so the "check this" pile stays small enough that you actually keep checking it.

One more habit worth adopting: treat language like "just approve them all" or "nothing unusual today" as a reason to look closer, not a reason to relax. That framing is exactly what a fatigue attack sounds like when it's working.

What this doesn't fix

Sorting your queue once does not mean you're done. New tools and new request types creep back into the "routine" bucket if nobody revisits the split every few months. And a queue with only five genuinely risky items a day is not immune, it is just small enough that you can actually give each one real attention, which is the whole point, not a guarantee.

This also is not about trusting your AI tools less. It is about trusting your own attention more, by not spending it on the nineteen messages that never needed it, so there's something left for the twentieth that does.

One thing to do this week

Look at whatever your AI tool asked you to approve today. Count how many you actually read versus how many you tapped without stopping. If the second number is bigger, you don't have oversight, you have a light that's always green. Split the queue before you turn it off altogether.