**Article 14**

**Design and Development for Effective Human Oversight**  
Gas Safety Insight has been architected with an emphasis on facilitating effective human oversight throughout its operational lifespan. The AI core integrates Gradient Boosted Decision Trees (GBDT) with encoder-only Transformer models that process multimodal inputs from over 120 distinct sensor channels and real-time operational logs sampled at 1 Hz frequency. This hybrid architecture ensures robustness and interpretability by combining the relatively transparent, tree-based decision mechanisms with the contextual sequence modeling accuracy of Transformers. To directly support human-in-the-loop interaction, the system includes an intuitive dashboard designed for gas network operators and field technicians. The dashboard visualizes anomaly scores, confidence intervals, and sensor health metrics with latency below 500 milliseconds, enabling near real-time monitoring. Additionally, visual explainability features such as feature importance heatmaps and temporal attention overlays accompany each alert to clarify which data patterns triggered the system’s predictions. This explicit attention to explainability and latency targets operators’ situational awareness and rapid response capability, ensuring that the design inherently supports meaningful human oversight.

**Mitigation of Risks to Health, Safety, and Fundamental Rights through Oversight**  
Recognizing the critical safety context, Gas Safety Insight incorporates multiple risk-mitigation mechanisms integrated into the system prior to deployment. These measures address potential residual risks such as undetected leaks or false negatives that could impact health and safety. A multi-tier alert escalation protocol embedded in the system triggers warnings based on anomaly severity thresholds balanced by precision-recall tradeoffs, validated through testing on a real-world dataset of 10 million sensor readings encompassing diverse operational scenarios. The model was stress-tested against 3,200 simulated fault conditions to evaluate robustness against reasonably foreseeable misuse, including sensor failures and network outages. Complementing these technical safeguards are operator training modules that explicitly address system limitations, promoting appropriate human interpretation and counteracting automation bias. Together, these design and procedural layers minimize risks persisting despite modeling advances, reflecting a proactive and comprehensive approach to safety-critical oversight.

**Proportionate Oversight Measures Reflecting System Autonomy and Use Context**  
Given the high-risk classification and semi-autonomous nature of Gas Safety Insight—providing real-time recommendations without automatic actuation—the oversight framework is calibrated proportionally. The provider embedded technical safeguards before placing the system on the market, including configurable alert thresholds, explicit confidence scoring, and anomaly explainability to limit blind reliance. These in-built features allow deployers to tailor sensitivity according to local operational policies. Beyond the system design, Norwin Industrial Technologies provides deployment guidelines recommending procedural controls such as mandatory operator review of all alerts and periodic system performance audits, to be locally implemented by deployers. This division aligns with Article 14(3) by combining provider-designed technical oversight elements with deployer-implemented organizational controls, both adjusted to the safety-critical oil and gas operational context and the system’s advisory role.

**Empowering Natural Persons through Transparency and Control Mechanisms**  
To support operators’ comprehensive understanding and effective monitoring, Gas Safety Insight’s user interface delivers detailed, real-time diagnostic feedback and model confidence metrics. Supplementary training documentation details the system’s predictive scope and limitations, including boundary conditions identified during premarket testing. The interface includes active reminders and prompts to mitigate automation bias, such as periodic alerts encouraging reevaluation of system outputs and explicit warnings when confidence intervals are wide, signaling lower prediction certainty. Operators retain full discretion to override or disregard system alerts; the interface incorporates dedicated override buttons accompanied by mandatory logging fields to document decisions and rationale, facilitating audit trails. A safety-centric ‘stop’ function halts the system’s anomaly detection and triggers a fallback monitoring mode that alerts supervisors, ensuring safe cessation without data loss. Additionally, processing records maintained per applicable data protection regulations document the justifications for using special categories of data solely to identify bias in training datasets, with supporting evidence demonstrating the necessity of this approach due to the inadequacy of non-sensitive data alternatives. These transparency and control features reflect a deliberate effort to comply with oversight provisions, equipping natural persons with comprehensive tools to supervise and intervene effectively.