Social media is buzzing with people sharing their first-hand experiences building AI agents to manage their day-to-day activities and workflows.
The pace of it all is hard to keep up with.
Thanks for reading Sky High Standards by Irene! Subscribe for free to receive new posts and support my work.
Like many, I have been tempted to dive in and start experimenting myself.
However, I have noticed that many of these people are careful to run their tests within sandboxes or on dedicated laptops, specifically to avoid putting their personal accounts and data at risk and to keep security implications firmly in check.
This awareness has only strengthened my conviction that these systems must operate within controlled and governed environments.
This challenge becomes even more critical in industries like aerospace.
From the Center…
Now, the real question isn’t technical.
It’s about governance:
who approves
who audits
who is ultimately accountable…
And more broadly, governance encompasses:
Compliance with laws, regulations, policies.
Ethics
Oversight of risks and opportunities
Oversight of performance
Alignment with the organisation’s strategic goals, long-term direction, and values
When AI agents execute end-to-end workflows, traditional guardrails around validation, compliance and responsibility start to be unclear.
The risk is not about AI is moving too fast.
The actual risk is about applying old governance, old metrics and old assumptions to a completely new execution layer.
I can see how the centre of gravity is shifting from tools to trust frameworks.
Challenges in safety-critical environments
Unclear accountability for automated decisions
When AI agents execute workflows autonomously, responsibility for safety-relevant decisions can become fragmented across humans, systems and vendors.Validation after execution
AI agents may complete actions before traditional verification steps occur, shifting assurance from preventive controls to post-analysis, which may be unacceptable in safety-critical operations.Certification and compliance misalignment
Existing certification frameworks assume deterministic software behaviour. Agent-based systems introduce challenges for certification under current standards.Loss of deterministic behaviour
Safety-critical systems rely on predictable and bounded behaviour. AI agents operating across tools and data sources can introduce variability that is difficult to constrain and validate.Traceability gaps
Reconstructing decision paths, assumptions, and system interactions becomes complex, undermining incident investigation, root-cause analysis and regulatory reporting.Human authority erosion
As agents gain autonomy, there is a risk that human oversight becomes nominal rather than effective, weakening the principle of meaningful human control.Speed exceeding safety controls
Execution at machine speed can outpace hazard analysis, monitoring, and intervention mechanisms designed for human-in-the-loop systems.
Case Study
When the Agent Acts Faster Than the Procedure
A maintenance planning team at an aerospace MRO organisation deploys an AI agent to manage task card scheduling, parts ordering and engineer allocation. Connected to the maintenance tracking systems, the agent begins executing workflows autonomously and starts re-scheduling safety-critical inspections based on parts availability, optimising for efficiency but bypassing the regulatory priority logic required under EASA Part-145.
No human approved the re-sequencing. No audit trail identified when or why the decision was made.
Not a technical failure. A governance failure. The agent performed exactly as designed, but the organisation simply had not defined what it was allowed to decide.
This is precisely the type of scenario EASA is moving to regulate. As explored in “AI-Based Operational Tools: What’s Coming in the EASA Landscape”, EASA’s emerging framework aims to ensure AI operating within approved organisations remains bounded, traceable and subject to human authority.
Resources
I recommend exploring a few of my earlier articles.
In “AI-Based Operational Tools: What’s Coming in the EASA Landscape”, I examined how EASA is approaching the regulation of AI-based operational tools within the approved organisation framework. A landscape that is evolving fast and demands attention.
For those less familiar with the foundations of organisational governance, “Governance vs. Management Systems: Understanding the Key Differences for Organisational Success” lays out the key distinctions in a clear and practical way.
And if you really want to go deep, the Governing HCAI within Aerospace Organisations 8-part series is where I take a comprehensive look at Human-Centred AI in aerospace, covering a range of critical topics including:
Monthly Recommendation
Pick one workflow in your organisation that could realistically be automated by an AI agent in the next 12 to 24 months. Then ask yourself three questions:
Who approves the agent’s decisions?
How do you audit its actions?
Where must human authority remain non-negotiable?
You don’t need the answers yet. You just need to be asking the questions before the technology arrives, because in safety-critical environments, governance cannot be retrofitted.
See you soon. 👋
Disclaimer: The information provided in this newsletter and related resources is intended for informational and educational purposes only. It reflects both researched facts and my personal views. It does not constitute professional advice. Any actions taken based on the content of this newsletter are at the reader’s discretion.
Thanks for reading Sky High Standards by Irene! Subscribe for free to receive new posts and support my work.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.