BVLOS Safety Is an Admissibility Problem, Not Just an Automation Problem
Systems Thinking / BVLOS Safety
BVLOS Safety Is an Admissibility Problem, Not Just an Automation Problem
A systems-building reflection on airspace safety, degraded assumptions,
and why AI should inform execution boundaries rather than become the boundary itself.
The Observation
Recent reporting about a helicopter collision in Rio de Janeiro raises a
difficult systems question: when aircraft share low-altitude, visually
complex, and potentially congested airspace, what does safety actually
depend on?
It is too early, and not responsible, to make claims about the specific
cause of that incident. Investigators will need to determine the operating
conditions, airspace context, visibility, communications, procedures, and
aircraft state.
But from a systems-building outlook, the broader question is worth asking:
what happens when the assumptions that normally keep aircraft separated
stop being reliable?
The Assumption Layer
In aviation, the distinction between VFR and IFR is not just procedural.
It reflects different safety assumptions.
Under visual flight rules, the pilot depends heavily on direct visual
awareness, judgment, and cockpit instruments. Under instrument flight rules,
the aircraft operates through procedures, instruments, clearances, and air
traffic control coordination.
Both models depend on structured assumptions about visibility,
communication, instrumentation, traffic awareness, airspace density, and
authority.
BVLOS drone operations challenge those assumptions directly.
When an aircraft operates beyond visual line of sight, the system can no
longer depend on a human simply seeing the conflict in time. The aircraft
needs a layered way to detect risk, interpret context, constrain action,
and preserve safety when confidence degrades.
Not “Just Add AI”
This is where the AI conversation often becomes too broad.
AI may be useful for perception, classification, anomaly detection,
traffic prediction, sensor fusion, and operator assistance. Those are
valuable functions.
But a probabilistic system that recommends an action is not the same as a
safety system that determines whether that action is allowed.
That distinction matters.
A BVLOS safety system should not merely ask:
**What does the model think is the best action?**
It should ask:
**
Is this action admissible under the current evidence, constraints,
authority chain, vehicle state, and airspace conditions?
**
Admissible Execution
In a safety-critical environment, the most important system behavior may
not be acting quickly. It may be refusing to act outside a verified
envelope.
A credible BVLOS architecture needs more than perception. It needs an
execution gate that can decide whether to permit, deny, pause, reroute,
return, hold, land, or escalate.
That gate should not be driven by confidence theater. It should be driven
by explicit constraints:
- airspace boundaries;
- vehicle health;
- separation requirements;
- traffic awareness;
- sensor integrity;
- communications status;
- operator authority;
- mission rules;
- degraded-mode procedures;
- and evidence that can be reviewed after the fact.
This is not anti-AI. It is a clearer separation of roles.
AI can help the system see, classify, summarize, and predict. But the
safety boundary should be deterministic, inspectable, and capable of
saying no.
A Systems-Builder View
Many failures in complex systems do not happen because no information
existed. They happen because the system lacked a reliable way to determine
which information was authoritative, which assumptions were still valid,
and which actions were still permitted.
That is the deeper BVLOS problem.
The aircraft may have sensors. The operator may have telemetry. The model
may have a prediction. The mission may have a route. But the system still
needs to answer a harder question:
What is this aircraft allowed to do right now?
If that question cannot be answered clearly, the safest behavior should
narrow. The system should become more conservative, not more creative.
When evidence degrades, authority should tighten. When communication is
uncertain, execution should become bounded. When the operating assumptions
no longer hold, the system should preserve safety before mission
completion.
Closing Thought
BVLOS safety is not primarily a question of whether machines can fly.
Machines can already fly.
The harder question is whether every action can be constrained, justified,
denied, and reviewed when the environment becomes uncertain.
That is not just an autonomy problem.
It is an admissibility problem.
And for shared airspace, that may be the more important system to build.