It feels like ages ago since I virtually attended the EASA Artificial Intelligence Days.
Yet here we are, with 2026 starting under growing expectations around the AI regulatory landscape within the EASA context.
As part of my ongoing exploration of the intersection between artificial intelligence and the highly regulated aerospace environment, today I’m focusing on what lies ahead for AI-based operational tools.
In particular, those tools that require approval as part of an organisation’s approval framework (such as Part 145, Part M, DOA, POA, etc.), including solutions that make use of Generative AI and Large Language Models.
While large language models offer great potential for information summary, they are considered large commercial off-the-shelf products.
Future guidance will likely focus on the transworthiness of the output and human-led verification rather than traditional software certification processes.
Innovation in aerospace happens where technology, regulation and responsibility meet.
AI is no longer a future concept to observe from a distance.
It is becoming an operational reality, and the way we choose to govern, integrate, and trust it will shape not only compliance, but the very standards of safety and professionalism we stand for.
In the near future, the aviation industry anticipates a significant wave of AI-based operational tools designed to enhance safety, efficiency and sustainability.
These tools are defined as applications that allow an organization, such as a maintenance provider, airline, or air traffic management (ATM) unit, to perform the specific regulated activities for which they were approved by a competent authority.
EASA’s risk assessment concept
EASA is currently developing a prefigured risk assessment concept to help organizations determine if an operational tool requires formal qualification. This process involves three “gateways”:
Process Assessment: Does the tool automate or eliminate a process inherent to the organization’s approved scope?
The organization first evaluates if the AI system reduces, automates, or eliminates a process that is inherent to the organization’s approved scope. If the tool is used for non-regulated activities, such as general human resources management, qualification is generally not required.
Independent Verification: Are all AI outputs independently verified by a human capable of detecting and mitigating errors?
The assessment looks at whether every AI output is independently verified by a human. To bypass formal qualification at this stage, the human must be specifically trained and capable of detecting and mitigating potential AI errors.
Safety Risk Characterization: If errors are not consistently detectable, the organization must perform an operational safety assessment.
If outputs are not consistently verified, the organization must perform a thorough assessment to identify any operational safety risks or hazards the tool might contribute to. This includes mapping the tool’s impact against the organization’s existing Safety Management System (SMS).
If the assessment identifies a safety risk, the tool is assigned a Tool Qualification Level (TQL).
• Proportionality: The TQL is designed to be proportionate to the identified risk, ensuring that the regulatory requirements are not overly burdensome for low-risk applications.
• Building Blocks: The criteria for achieving a TQL are drawn from EASA’s trustworthiness framework, focusing on AI assurance, human-AI teaming, and ethics.
This will ensure that the regulatory burden is balanced against the potential hazard the tool contributes to.
Evolution of Human Roles (Human-AI Teaming)
What is coming is not just the software, but a change in how humans work based on three different levels:
• Human-AI Teaming (Level 2): Moving toward a “mission commander” role where AI provides suggestions or templates, but the human remains in active control.
• Advanced Automation (Level 3): Humans may eventually move into a purely oversight role, where the AI performs tasks autonomously and only alerts the human during non-normal events or when it reaches the edge of its operational envelope.
• Interaction Design: Future tools will prioritize “human-centric design,” using techniques like STPA (System Theoretic Process Analysis) to identify potential interaction failures early in development.
Authority Oversight
Finally, the assessment criteria are applied at an organizational level through process oversight.
Rather than the authority qualifying every single tool individually, they verify the organization’s internal process for assessing and qualifying tools, using sampling to ensure the process is followed correctly.
AI is being integrated across all sectors of the aviation ecosystem to handle complex data that is often overwhelming for humans.
Examples of key upcoming applications include:
• Maintenance and Continuing Airworthiness: Tools for AI-assisted troubleshooting (using Generative AI to parse manuals), predictive maintenance, and aircraft digital twins to monitor real-time health.
• Flight Operations and Design: Systems for interpreting non-destructive testing (NDT) results, autocoding tools for software development, and assessments of outlanding severity based on flight data.
• Air Traffic Management (ATM): Training simulations that explain syllabus content to student controllers and tools for risk-based oversight used by authorities to monitor aircraft safety scores.
Methods for Showing Compliance
To meet these assessment criteria, organizations could use specific analytical methods such as:
• STPA (System Theoretic Process Analysis): This is used to identify unsafe control actions and “non-normal” scenarios early in development. It helps generate the interaction requirements between the human and the AI that are necessary to show regulatory compliance.
To learn more about this method:
STPA Handbook: step-by-step guide for implementing the process.
Tutorial Videos and lecture slides from the MIT covering everything from basics to formal scenario development.
• Verification Agents: For complex systems like Generative AI, a “verification agent” or “monitor” may be assessed as a way to contextually check AI outputs against a trusted source database to prevent hallucinations.
If you’d like to explore this topic further, I recommend going straight to the source: the Day 2 conference recording (from 4:30:00 onward), where it was discussed in depth.
See you soon. 👋
EASA (2025). EASA Artificial Intelligence Days 2025 – Hybrid event (partially online and on-site). European Union Aviation Safety Agency. Retrieved from https://www.easa.europa.eu/en/newsroom-and-events/events/easa-artificial-intelligence-days-2025 EASA
Disclaimer: The information provided in this newsletter and related resources is intended for informational and educational purposes only. It reflects both researched facts and my personal views. It does not constitute professional advice. Any actions taken based on the content of this newsletter are at the reader’s discretion.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.