**Article 14**

### Design and Development of Effective Human Oversight Mechanisms

The Guardian Signal Controller has been architected to integrate human-machine interface (HMI) tools that support continuous and effective human oversight throughout its operation. Prior to deployment, Aegis Mobility Technologies conducted a detailed task analysis to identify operational points at intersections where traffic controllers require real-time situational awareness. Consequently, the system includes a multi-modal dashboard interface that aggregates live video feeds, processed event alerts, and sensor data summaries in an intuitive visualization format. The dashboard enables traffic operators to monitor system decisions—such as predicted red-light violations or pedestrian conflicts—with real-time confidence scores generated by the Random Forest classifier module. The design prioritizes clear presentation of uncertainty and event criticality to prevent cognitive overload and facilitate timely human intervention.

The CNN module’s spatial feature extraction outputs are distilled into human-interpretable anomaly indicators, such as “unusual pedestrian crossing behavior” or “vehicle stopped in a crosswalk,” which are displayed alongside sensor-derived speed and distance estimations. This layered information supports operators in verifying and contextualizing the AI’s assessments, thereby aligning with the requirement that natural persons can oversee system activity effectively while it is in use. User experience trials involving 30 professional traffic controllers across multiple European municipalities confirmed a mean monitoring task accuracy of 94% and an intervention reaction time below 5 seconds under standardized testing conditions, demonstrating operational feasibility.

### Risk Mitigation Through Targeted Human Oversight

Human oversight is explicitly designed to minimize safety risks such as collisions and traffic violations that might arise from both intended usage and foreseeable misuse scenarios, including sensor occlusions, extreme weather conditions, and atypical road user behaviors. Aegis Mobility performed a comprehensive hazard analysis using Failure Modes and Effects Analysis (FMEA) methodology focused on use cases with elevated risk profiles. This analysis identified the persistence of residual risks, such as false negatives in pedestrian detection during heavy rain, despite algorithmic mitigations including image enhancement and sensor fusion.

To address these residual risks, the system embeds real-time alerts for anomalous operating conditions, prompting immediate operator review. Moreover, the system’s probabilistic output scoring allows operators to weight decisions according to confidence intervals. For example, when the CNN module’s pedestrian detection confidence falls below 70%, the system flags the intersection state for heightened human attention. This approach is complemented by operator training modules emphasizing the recognition of known system limitations and the appropriate escalation protocols, thereby reducing hazards that may survive other technical safeguards.

### Proportionate Oversight Measures Embedded and Assigned

Oversight measures have been implemented both within the Guardian Signal Controller system and through recommended deployer procedures to ensure a risk-commensurate governance framework. Internally, the system includes automated self-diagnostics that continuously validate sensor inputs and model stability, issuing error reports when anomalies such as camera misalignment or sensor drift are detected. The integration of Random Forest classifiers—characterized by interpretability and resilience to overfitting—supports robustness under uncertainty and facilitates transparent explanation of decisions to end-users.

Prior to being placed on the market, Aegis Mobility developed a comprehensive oversight protocol guideline, which specifies operational checkpoints for system deployers, including regular sensor calibration, periodic model retraining schedules using recent validated datasets, and monthly human review of system logs to detect performance drifts or false positive trends. These deployer measures complement the built-in features by tailoring human oversight intensity based on intersection-specific risk profiles and system autonomy levels determined through preliminary risk assessments covering interaction complexity and traffic density.

### Enabling Informed and Active Human Oversight by Natural Persons

The Guardian Signal Controller is delivered with an extensive operator manual and tailored training curriculum to ensure that assigned natural persons fully understand the system’s capabilities, limitations, and normative operating envelope. The manual details the architecture of the CNN and Random Forest components, explaining their distinct roles in feature extraction and classification, supported by visual aids and case study analyses of typical traffic scenarios and anomalies. To facilitate anomaly detection and response, the HMI includes customizable alert thresholds and interactive logs presenting temporal sequences of relevant sensor data and model outputs, enabling operators to trace and interpret decisions.

The system explicitly addresses automation bias by incorporating recurring user prompts emphasizing the provisional nature of AI-generated outputs and recommending verification steps before critical interventions. For example, when suggesting signal timing changes, the system requires operator confirmation via an active decision interface, preventing unattended automatic overrides. This decision design empowers operators to disregard or override system outputs, supported by clearly labeled override controls and an emergency stop button that immediately transitions the traffic signal controller into a fail-safe default state (e.g., flashing amber mode) designed to maintain intersection safety during system halts.

Operator interfaces include decision support tools, such as confidence bands and explanation overlays, which assist in correctly interpreting outputs, especially under ambiguous conditions. Continuous logs of processing activities are maintained in compliance with GDPR obligations, documenting data usage rationales, including why processing special categories of personal data (e.g., pedestrian images) was strictly necessary for bias detection and correction. These records are accessible via the oversight dashboard, providing transparency into the data-driven processes underpinning traffic anomaly detection and the steps taken to minimize algorithmic biases related to demographic or behavioral attributes.

In summary, Guardian Signal Controller aligns its human oversight capabilities with a risk-based, transparent, and interactive framework. This ensures that natural persons entrusted with oversight roles are sufficiently equipped to monitor, interpret, and intervene in system operations safely and effectively.