**Article 14**

**Design of Human-Machine Interface for Effective Oversight**

The Guardian Signal Controller is designed to provide aggregated risk assessments and binary safety alerts exclusively through a static, non-interactive dashboard interface installed in municipal traffic control centers. This interface purposely omits detailed explanations, confidence intervals, or real-time updates of model states to limit cognitive overload and reduce possible misinterpretation by traffic operators. The dashboard presents a rolling summary of intersection risk levels, updated at fixed intervals of five minutes, and issues binary alerts signaling either “Normal Operation” or “Potential Traffic Safety Hazard.” This approach supports focused human oversight by emphasizing high-level situational awareness without extraneous complexity, thereby facilitating timely human intervention when necessary.

**Human Oversight to Mitigate Safety Risks**

The system’s human oversight framework is based on delivering concise alerts that prompt manual review and action by traffic management personnel. Given the critical nature of traffic safety and the potential consequences of system errors, the Guardian Signal Controller’s design reduces risks by avoiding ambiguous output formats. The binary traffic safety alerts enable operators to promptly identify intersections requiring further investigation or manual signal control adjustments, thus minimizing risks such as collisions or pedestrian hazards. Additional operational safeguards include daily system health checks and automated diagnostic reports, which inform maintainers of any functional anomalies unrelated to model prediction outputs, ensuring overall system reliability without reliance on operators to interpret internal model complexities.

**Provider-Implemented Oversight Measures Proportionate to Risk and Autonomy**

Prior to deployment, the Guardian Signal Controller integrated several technical measures to ensure effective oversight aligned with its operational context as a semi-autonomous traffic safety assistant. The combination of Convolutional Neural Networks for spatial feature extraction and Random Forest classifiers for decision-making provides robust, ensemble-based output resilience, which is further reinforced by thresholding logic implemented in software to ensure only aggregated risk scores exceeding preset safety thresholds trigger alerts. The system’s autonomy is limited to advising traffic control staff via the dashboard; no decisions are made or enforced automatically, thereby enabling direct human judgment as the final control point. Model training and validation leveraged a balanced dataset sourced from over 1 million annotated intersection video frames and sensor logs collected across various European municipalities, resulting in a binary classification accuracy of 92% (±2% variability across deployment environments), which informed the conservatively set alert thresholds to minimize false positives and negatives.

**Information and Control Capabilities Provided to Natural Persons**

Operators responsible for oversight receive targeted, proportionate information designed to meet the requirements under Article 14(4). They can readily understand the system’s functional scope and limitations, knowing the system communicates only aggregate risk scores and binary alerts without further explanatory detail or confidence estimates. This clarity is achieved through operator training materials highlighting the non-explanatory nature of outputs and instructing on standard procedures for manual intervention upon alert reception. Real-time monitoring of the internal states or model uncertainty is not provided to operators, intentionally mitigating risks of automation bias and over-reliance by underscoring the advisory nature of the system. Operators can override any system alerts by manually adjusting traffic signals at intersections, facilitated by existing municipal traffic control protocols. Furthermore, the system incorporates an emergency halt feature accessible to operators, which immediately suspends data processing and alert generation to place the system in a safe standby state, ensuring human intervention remains the ultimate authority.

**Record-Keeping of Data Processing Activities Related to Oversight**

Comprehensive logs are maintained for all processing activities involving personal data, strictly limited to the minimum necessary categories (e.g., anonymized video frames and sensor metadata) for system training and bias detection. The provider documents that processing of any special category data (such as visual recordings involving individuals) was strictly necessary to develop and verify non-discriminatory detection capabilities for traffic anomalies potentially affecting vulnerable road users. Alternative processing methods lacking such data were evaluated but failed to achieve comparable accuracy and fairness metrics during development. Audit trails include rationale statements and impact assessments, compliant with GDPR provisions, demonstrating that data use was justified and aligned with bias mitigation objectives. These records are available to authorized personnel under data governance policies to support transparency and accountability in system deployment and operation.