Connect with us

NEWS

EASA Says Aviation Is Late as Airlines Move First

EASA’s Florian Guillermet said air transport is late to AI after cars and a European airline moved first, while cockpit models stay capped at DAL C.

Published

on

EASA executive director Florian Guillermet said on Sept. 9 that his agency and commercial air transport are late in adopting artificial intelligence. He opened the fourth EASA AI Days in Cologne, held Sept. 9 to 10 at headquarters on Konrad-Adenauer-Ufer.

Airline planning rooms, maintenance shops and climate trials already run models. Flight-critical machine learning still has no means of compliance above DAL C, and the next full rule package is dated Q2 2027.

Aviation Is Late, EASA’s Director Said in Cologne

Guillermet took the EASA job in April 2024 after running France’s air traffic service and the SESAR Joint Undertaking. He told the room the agency, and the airline industry around it, had lagged on AI while other fields moved.

The Cologne meeting was built as a rulemaking show, not a product launch. Guillaume Soudain, EASA’s programme manager for artificial intelligence, gave the roadmap status. Christine Berg, head of unit for aviation safety at the European Commission, set the EU scene. Giovanni Cima walked through RMT.0742, the trustworthiness task that answers the EU AI Act, Regulation (EU) 2024/1689.

A first-day panel put the FAA, Brazil’s ANAC, Transport Canada, the UK CAA and China’s CAAC in the same room as EASA to talk about lining up methods. Day two put Thales, Safran, Amazon Prime Air, Airbus Defence and Space, Boeing and Technische Universität Braunschweig on advanced automation. EUROCAE took a flash talk on the industrial standard that is supposed to make those talks certifiable.

THE COLOGNE SCOREBOARD

  • The meeting: Fourth edition of EASA AI Days, hybrid, Sept. 9 from 08:30 to 18:00 CET and Sept. 10 from 08:00 to 17:30 CET.
  • The Olympics: Fifty AI cases hit the cap on July 7, two days before the July 9 deadline, and ten finalists went on stage.
  • The paper: Proposed Issue 03 of the AI Concept Paper runs 239 pages and was the last concept deliverable under Roadmap 2.0.
  • The next gate: A joint Step 2 NPA with an updated Step 1 is scheduled for a full-spectrum consultation in Q2 2027.

Medals were on the agenda at 16:00 on Sept. 10, with Airbus Protect’s Thiziri Belkacem among the judges. EASA’s public agenda papers did not name the gold, silver and bronze cases.

He Thought Cars Would Trail a Controlled Sky

Guillermet compared air transport with cars. Some countries have already authorized autonomous driving on new vehicles, and he said he had not expected that order.

He had assumed cars would come later because a street is a messy place, full of people, signs, weather and surprise. A jet, by contrast, flies in a controlled system of routes, clearances and trained crews. The car industry still got to authorized autonomy first.

Cockpit computers have been kept off the public internet for decades, on purpose. Popular generative models that invent confident answers were a poor fit for that culture. Guillermet still argued that AI, used as an extra barrier rather than a replacement, could add protection in the seconds when a crew is already loaded.

He said applications can add a layer of safety if they sit on top of the layers already there, and that building those extra barriers should be treated as urgent because they could save lives in the critical moment. The tension in Cologne was simple to hear. The models that move fastest are the ones that do not have to prove, path by path, what they will do next.

The QNH Scare an Airline Already Caught

His hardest case was not a chatbot. It was a pressure setting.

Pilots set a local air-pressure value called QNH so the altimeter reads height above sea level. A wrong QNH makes the jet think it is higher than it is. In May 2022, Guillermet said, an Airbus A320 at Paris Charles de Gaulle got down to 6 ft when it was still 0.9 NM from the runway. He tied the close call to a QNH value that was passed incorrectly between the controller and the crew.

He asked how anyone could explain a crash of that kind to families when cars already drive themselves and the error was a single number on the radio. About two and a half years later, he said, EASA began a fuller look at how to add more barriers around that class of mistake.

Then a European airline walked in. A few months before Cologne, Guillermet said, the carrier came to EASA with an advanced AI system that watches operations. The system had flagged the CDG-style event and had found similar cases in more than one place. The airline asked where EASA stood on certifying new altimeter software. The agency’s engineers, he said, did not know of such a project.

The airline had already told its supplier to change the software and add another barrier. Guillermet said the carrier had basically done EASA’s job, and that the visit was a serious wake-up call.

FROM A LOW PASS TO A WAKE-UP CALL

  1. May 2022: An A320 at Paris CDG descends to 6 ft at 0.9 NM from the runway after a bad QNH exchange, in Guillermet’s account.
  2. About two and a half years later: EASA begins a fuller effort on extra barriers around that failure mode.
  3. A few months before Sept. 9, 2026: A European airline brings EASA an operations AI that already caught matching events and asks about altimeter-software certification.
  4. Sept. 9, 2026: Guillermet tells Cologne the visit was a serious wake-up call.

That is the lag that bothered him. Not empty labs. A safety fix born in an airline ops centre, then presented to the regulator as a certification question the regulator had not opened.

Why Certified Cockpit AI Stops at DAL C

Classic airborne software is approved under a determinism bargain. Each input should map to a defined output, and testers show they covered the paths. Design assurance levels scale the rigor with the harm. DAL A is the catastrophic end. DAL C is major. Learned models do not live in that bargain. They fit correlations from training data, and the same input can shift with context the tests never listed.

EASA’s concept papers have said the same limit in each issue. With the current state of knowledge, the agency does not treat AI or machine-learning pieces as valid when they include IDAL A or B items, or the matching ATM software levels. No one is supposed to lower the assurance level to sneak those pieces through. The limit will be revisited when there is more in-service experience. In plain terms, DAL C is the ceiling.

That ceiling is why so much of the “aviation AI” that already exists never files for a type certificate. A planner, a chatbot or a hangar scanner can fail without putting a hull in the dirt. A learned go-around cue cannot.

WHERE EASA PUTS AI TODAY

Band What it covers What is actually approved
Level 1 Assistance to a human Guidance in Concept Paper Issue 02; Roadmap 2.0 step for 2023-2025+
Level 2 Human-AI teaming Guidance in Issue 02; roadmap step for 2025-2035+
Level 3 Advanced automation, human remote or absent Opened in Issue 03 in June 2026; roadmap step for 2035-2050+
DAL A or B functions Catastrophic or hazardous failure paths No current means of compliance for AI/ML constituents
DAL C and below Major or lesser failure paths Present ceiling for AI/ML constituents

Roadmap 2.0, published May 10, 2023, was blunt about pace. First usable Level 1 guidance in 2021, Level 2 guidance in 2023, Level 3 guidance in 2025, then a consolidation that was supposed to finish Level 1 and 2 policy in 2026. First Level 1 approvals were sketched around 2025. Safeguarded Level 3 sits near 2035 as a prediction, not a hard target. Unsupervised autonomy is written as 2035-2050+.

Swiss firm Daedalean has spent years seeking FAA and EASA approval for PilotEye, a camera-based traffic sensor aimed at DAL C, not at autopilot. That file was still open in mid-2026, which matches the ceiling in the table: even a look-out aid at DAL C is a multi-year fight, and nothing above that line has a method.

Paper Rules Outran Flying Hardware

On paper, EASA is not idle. It released the final Concept Paper on aviation AI as Proposed Issue 03 on June 3, 2026, for a 10-week comment period that closed Aug. 12, 2026. Issue 02 had covered Level 1 and Level 2. Issue 03 adds reinforcement learning and symbolic AI and walks into Level 3.

These applications open the way to novel types of operations in which the human end user may be either remotely present, or not present during the operation.

EASA, Concept Paper on Artificial Intelligence, Proposed Issue 03

NPA 2025-07, published Nov. 10, 2025, proposed detailed specifications and acceptable means of compliance for AI trustworthiness, aimed at the aviation domains named in Article 108 of the EU AI Act. Comments ran until March 10, 2026 after an extension. That NPA is Step 1, a generic trust layer. Step 2, which is supposed to embed that layer in airworthiness, ATM/ANS and drone rules, is the Q2 2027 package, published jointly with an updated Step 1.

Soudain’s June 30, 2026 Safety Forum slides still limited the safe subset: no adaptivity in operations, meaning offline learning only, and no critical failure contribution. EASA has also issued special condition SC-AI-01 on trustworthiness of machine-learning systems, an interim path while the domain rules are written.

Industry was supposed to meet that paper with a process standard. EUROCAE WG-114 and SAE G-34 have been drafting the joint ED-324 machine learning standard, also tracked as ARP6983. A June 2026 publication target slipped. EUROCAE’s working-group page, updated Aug. 26, 2026, still listed ED-324 as a draft with a target date of 31/12/2026. Issue 1 is limited to a subset of machine-learning methods.

Sandrine Serres of Airbus, Fateh Kaakai of Thales and EUROCAE’s Thuc Nguyen gave the Cologne flash talk with Soudain. The standard is the closest thing aviation has to a learned-system version of the old software assurance manuals, and it is still not on the shelf.

WHAT A CERTIFIED MODEL STILL CANNOT DO

  • Update in flight: Weights are frozen after approval, so the model does not keep learning on the line.
  • Learn online: Issue 1 of ED-324 is built around supervised, offline training, not live adaptation.
  • Use every technique: Reinforcement learning sits in Issue 03 of the concept paper and is queued for a later issue of the standard.
  • Own a DAL A or B function: Catastrophic and hazardous paths stay with deterministic code unless a classical barrier carries the risk.

That is a bounded assistant, not a crew member. The informed objection writes itself: if a model ever preferred an uncertified action over a certified one in a messy moment, the crew would be stuck arguing with a black box at the worst time. EASA’s human-factors work under Andrew Kilner is aimed at that seam. It does not dissolve it.

On the Ramp, the Models Are Already Live

Guillermet’s “late” line lands badly if you only look at customer chat and planning tools, because those are already in service. It lands cleanly if you look at what can fail a hull.

Google and Cathay Pacific have taken an AI contrail-avoidance tool onto ultra-long-haul flying in Asia-Pacific. Early work covered more than 80 flights that followed avoidance routes inside a trial targeting more than 100. Google’s satellite analysis put the 40% drop in contrail warming impact on those flown routes, with the Hong Kong-Singapore corridor accounting for more than 50% of the trial’s reductions. Dispatchers and pilots are shifting altitude around predicted ice-supersaturated layers. That is operations, with a human still signing the plan.

IAG said Aer Lingus signed a multi-year deal with AISmartPlan, a maintenance-planning platform that came through the IAGi Accelerator. The carrier and the start-up took the tool from a trial to a live planning desk in three months, folding schedules, aircraft availability and staffing into one board.

Those projects do not need a DAL A compliance story. They need data rights, a fallback human and a business case. The AI Olympics EASA ran into Cologne was built to surface exactly that class of work: fifty entries, ten on the floor, attendees voting while they walked the cases. The regulator wanted to see what the market had actually built, which is an admission of its own. Concept papers do not tell you what is already running in an airline’s operations centre.

Domain Rules Catch Up in 2027

On June 18, 2026, in Chantilly, Virginia, the FAA and EASA restated a joint list that included the safe integration of automated flightdeck technologies. FAA Administrator Bryan Bedford called the period one of the most innovative moments in aviation for the United States and its partners. The pledge also named portable electronic devices in the cockpit, simulator training in automated environments, and faster paths for new aircraft. It did not create a means of compliance for a DAL A neural net.

The FAA’s own 2024 AI safety-assurance roadmap is still a statement of approach, not guidance an applicant can cite. It prefers use cases over a single AI rule and says advisory functions with a pilot in the loop come before authority-holding ones. That is the same queue EASA drew, reached by a different drafting habit. Harmonization talk in Cologne will not move the DAL C ceiling by itself.

Until the Q2 2027 NPA turns trust clauses into airworthiness, ATM and drone law, the extra QNH barrier Guillermet wants will keep arriving the way the last one did. An airline will train a model on its own events, ask a supplier for a software change, and then knock on the agency’s door to ask where certification stands. Cars will keep driving with systems aviation still would not put on a jet. The rulebook will keep getting thicker. The hardware that can kill people will stay frozen, offline, and capped at DAL C.

Harry is the editor of THE LITTLE BINGER and writes most of what appears on it, running the site as an independent title after ten years in journalism that took him from reporter to editor. His working rule is that the story usually sits in what the announcement leaves out, so the underlying document is read in full. Earnings reports, court filings, patent applications, match reports and hearing transcripts are gone through from the first page to the last before a line is written, because the detail that changes a story rarely makes it into the press release. That approach covers all ten sections he publishes for an international readership, from news, sports and business to gaming, technology, travel, science, lifestyle, entertainment and auto. Numbers are checked twice, once against the source and once against the arithmetic, and any correction is added to the article with a note explaining what changed and when, as the site's published corrections policy sets out. Reader mail is opened and answered by him rather than by a form, at support@thelittlebinger.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending