Osmos
Articles

Osmos Global Publication · Osmos Perspective

Human Override Must Work When the Network Does Not

Fallback capability is credible only when people can use it under the conditions that make it necessary.

Osmos Global Research & Knowledge Centre4 min readSign in to download

A button is not a fallback plan

A platform may advertise manual override, but the option can be inaccessible when the network, identity service or remote interface fails. A genuine fallback depends on the physical design, local controls, competent staff and approved procedures. It cannot be established by a screenshot in the software manual.

NIST’s incident-response guidance stresses preparation, recovery and validation of restored services [NIST].

Hong and Li highlight the need to document the context in which building-AI systems are evaluated [HONG].

Osmos applies these principles by treating fallback as an operational capability that must be designed and exercised.

Define the degraded operating state

The responsible engineers should identify how the affected service can operate safely when some digital capability is unavailable. The answer varies by system and must not be improvised from generic advice. It may involve a local control mode, an alternative process or a controlled suspension of a non-critical function.

Specify what information staff will still have, which alarms remain available and what limits apply. Loss of analytics may be tolerable while loss of essential control is not. A plan that treats every digital outage identically can either overreact or leave a critical dependency unaddressed.

Figure 1. Choose the authority boundary explicitly Original Osmos Global conceptual framework, 2026. Categories are not a maturity score. Prepared 1 September 2026.

What this means: More accurate predictions do not automatically justify more control authority.

Match authority with competence

The person allowed to intervene must understand the equipment, the intended operating state and the consequences of the change. Give staff access to current approved procedures through a route appropriate to the failure scenario. Training should include when not to act and when to escalate.

Avoid making the fallback dependent on one expert who may be unavailable. Define cover arrangements, handover information and decision authority across shifts. The ability to contact a remote supplier should support local capability, not substitute for every aspect of it.

Exercise without creating unnecessary risk

Use engineering-approved tests and tabletop exercises proportionate to criticality. A test should demonstrate that the relevant people can find the procedure, understand the state, communicate and perform their assigned role. It should not introduce uncontrolled changes to live safety-critical equipment.

Record observed gaps and close them. If a procedure was inaccessible, a contact failed or an alarm was misunderstood, the exercise has produced useful evidence. Repeating the same nominal test without resolving its findings creates reassurance rather than resilience.

Illustrative decision rehearsal

A useful hypothetical exercise begins with the primary interface unavailable and the usual specialist off shift.

Ask the duty team how it would establish the equipment’s state, locate approved instructions and reach a competent decision-maker. The exercise may expose that the documented override depends on the same network or credentials that have failed.

Do not solve that discovery by improvising an unapproved manual intervention. Escalate it as a design and procedure issue for the responsible engineers. The remedy may involve access arrangements, local information, training or a different fallback design, but its suitability must be established for the actual plant.

During the first assurance cycle, test the information and communication path as well as the control itself.

Confirm that procedures are current and that a replacement team can understand them. Check how temporary changes will be recorded and communicated to the next shift.

The final part of the exercise should rehearse return to normal operation. If staff changed local settings during the degraded period, those settings must be reconciled before automated control resumes. A successful fallback can still be followed by a poor restoration. Evaluating the complete cycle helps prevent resilience from being reduced to a single emergency action and makes the boundary between human and automated authority understandable to everyone responsible for the service.

Control the return to automation

Restoring connectivity does not automatically justify returning all authority to the platform. Confirm system integrity, configuration, current data and any changes made during the outage. The responsible team should decide when normal operation can resume and verify that the transition did not create new problems.

This article is not an operating instruction for any particular plant. Qualified professionals must determine the safe design and sequence. The management requirement is straightforward: if human override is part of the risk case, demonstrate the people, access, information and recovery process that make it real.

Source notes

[NIST] Alexander Nelson, Sanjay Rekhi, Murugiah Souppaya and Karen Scarfone. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. National Institute of Standards and Technology, 2025-04-03. Section 2; Table 2 GV.SC-05/08; Table 3 RC.RP. DOI: 10.6028/NIST.SP.800-61r3. Accessed 1 September 2026.

https://csrc.nist.gov/pubs/sp/800/61/r3/final

[HONG] Tianzhen Hong and Han Li. Good practices for documenting AI-based studies on energy and buildings. Energy & Buildings / Elsevier; author copy hosted by Lawrence Berkeley National Laboratory, 2026-01-20. Sections 2, 3.1–3.6 and 4; pp. 1–4. DOI: 10.1016/j.enbuild.2026.117043. Accessed 1 September 2026. https://eta-publications.lbl.gov/sites/default/files/2026-06/1-s2.0-s0378778826001039-main.pdf

Editorial and visual note

This is original Osmos Global analysis informed by the cited publications. Reported findings are distinguished from Osmos recommendations and illustrative scenarios. Source findings and trademarks remain attributable to their owners. Original visual designs do not imply endorsement by source organisations. The content is general research and does not replace site-specific professional advice.

Cite this

Osmos Global Research & Knowledge Centre (2026). Human Override Must Work When the Network Does Not. Osmos Perspective, Osmos Global. https://www.osmosglobal.org/articles/human-override-must-work-when-the-network-does-not

Keep reading

Download this paper

The full PDF, formatted for circulation. Downloads are for members, so that we know who our research reaches.

Discussion

Add what you are seeing on the ground.

Members can add their input here.

Comments appear under your own name and company.

Join Osmos