Yes, in 2026, AI routinely writes setpoint changes on a process control loop, but the override still requires a signed human approval node whenever the change crosses a pre-agreed risk or safety threshold.
The market pulled this boundary into focus on 25 May 2026, when a Dataiku/Harris Poll of 800 global data leaders reported that 64% of respondents consider their AI agents better at automating operational tasks than at making higher-order business judgments [S2]. The same report places AI decision automation on a spectrum: fully rule-based auto-approval, ML-augmented review of edge cases, and fully autonomous agents, with most enterprises running the middle mode and reserving the high-risk branch for human sign-off [S2].
Where the line sits: rules engine, ML model, human reviewer
An industrial deployment typically routes 80-90% of setpoint traffic through a rules engine for transactions below a defined confidence or value threshold, while the remaining 8-20% goes to a human reviewer for cases the model cannot classify with high confidence [S2]. Translated to a pressure transmitter trim loop, the same pattern means a 0-10% trim band on a stable flow transmitter auto-fires, a 10-25% band routes to a control room operator, and anything above 25% on a Safety Instrumented Function loop halts the agent.
The architecture is built from four components: data inputs, ML models, business rules engines, and workflow orchestration, and the same four pieces are what make the difference between AI decisioning that scales and AI decisioning that creates liability [S2]. A multifunction process calibrator connected to the historian acts as the data-input layer, the ML model scores drift against an HMI panel recipe, the rules engine evaluates against ISA-84 / IEC 61511 trip classes, and the workflow layer writes either a direct setpoint or an approval ticket.
What the controls actually look like in 2026 platforms
Appian's process automation guidance lists human approval as one of the explicit safety mechanisms for AI, alongside escalation paths for errors and activity logs for audit [S1]. Microsoft-aligned process optimization practice follows the same rule: "Retain approvals and accountable decision points where judgment is required" is published as a non-negotiable design constraint, and human review is listed alongside approved information sources, exception handling, and access and data controls as part of the governance layer [S3].
Microsoft-aligned implementations further require that approvals, exceptions, and human decision points be defined before deployment, not retrofitted [S3]. For a process calibration workflow, that means the agent cannot issue a new calibration interval until the metrology lead has signed off on a documented acceptance band, and any deviation greater than the as-found/as-left tolerance routes to a named owner rather than auto-committing [S3].
Which paths are safe to automate, and which are not

Low-risk, high-volume paths are safe to automate. Document and email intake, knowledge and service agents that draw only from approved sources, and management reporting consolidation are the three published starting points for AI process work in 2026, and all three carry explicit exception routing for any case the model returns with low confidence [S3].
High-risk paths are not. Setpoint changes inside a Safety Instrumented Function, overrides on a v-process line cycle, and any action that writes to a hard interlock remain human-only, and the 2026 survey data shows exactly why: 64% of data leaders say their agents are stronger on operational automation than on judgment, and that gap is the reason fully autonomous modes still stall in deployment [S2]. In practice, the IEC 61511 Safety Bypass and Override rules require a named authoriser and a documented restoration step, which no autonomous agent is permitted to substitute for.
Comparison: autonomous, ML-augmented, and rules-based setpoint control
Across the three modes that 2026 governance frameworks allow, the trade-off is consistent: higher autonomy buys throughput and loses accountability auditability. Fully rule-based setpoint control is the lowest-throughput option but the only one that produces a deterministic audit trail with zero human latency; ML-augmented control routes 80-90% of cases through automation and reserves 8-20% for human review, which is the mode most enterprises run in production [S2]. Fully autonomous agents achieve the highest throughput but require the strictest pre-deployment approval design, and 64% of data leaders in the May 2026 survey said their agents cannot yet make the higher-order judgments that autonomous setpoint control would demand [S2].
Operationally, the published governance checklist holds regardless of mode: approved information sources, retained human approvals, exception handling, access and data controls, and post-deployment accuracy review are all mandatory [S3]. Calibration management software that meets the 2026 spec for connected instruments tracks the same five items as machine-readable fields, and the Calibration Management Software and Connected Instruments spec for 2026 lists approval routing as a required attribute on every drift event, not an optional one.
Limits, failure modes, and the audit trail

The dominant failure mode in 2026 is silent override: the agent writes a setpoint that lands inside the rules-engine band, the band is too wide, and no human ever sees the change. Governance guidance counters this by requiring an activity log for every action, an escalation path for every error, and an approval node for every high-risk step [S1]. The same pattern is enforced in the Microsoft-aligned process design: define information sources, access, approvals, exceptions, and human decision points before deployment, then measure processing time, backlog, rework, error rate, and response time against a practical baseline [S3].
Where brownfield Brownfield Line Modernization projects carry legacy control hardware, the human-approval step is also the only reliable place to enforce site-specific management-of-change rules, and that step cannot be removed without breaking the audit trail that the same governance framework requires. Three measurable signals to track in the next quarter: the ratio of auto-approved to human-approved setpoint writes, the median latency of the human approval queue, and the number of exception routes triggered per 1,000 setpoint changes; any drift in those three numbers is a leading indicator that the autonomy band is wider than the documented risk envelope.