Aerospace · 11 min read · Rody Nigel, PhD

Certifying AI in Safety-Critical Aerospace Systems: A Framework Primer

DO-178C was not written for machine learning. Neither was ARP4754A. But airworthiness authorities are starting to issue guidance on AI in safety-critical systems.

DO-178C and ARP4754A assume a development process that produces deterministic, traceable, fully specified software behaviour. Machine-learned components do not fit that model cleanly: behaviour emerges from training data and model architecture rather than an explicit specification.

Where the gap bites

Traceability: a trained model does not have a specification in the DO-178C sense, so certification-relevant evidence must be generated through data provenance and validation testing rather than code review alone. Change control: a retrained or fine-tuned model is functionally a new version, even when nothing else changed. Verification scope: verification must also characterize behaviour across the operational envelope, including edge cases the training data may not represent well.

What we build into aerospace engagements

PMAIS engagements in aerospace structure change control, traceability, and design-assurance evidence to be generated during delivery, not reconstructed afterward. The Data Governance Record captures training-data provenance; the Test & Validation Evidence Package is scoped to the operational envelope; and the Risk Classification & Regulatory Crosswalk maps against DO-178C, ARP4754A, and emerging authority guidance.

If you're evaluating where an AI component sits relative to your certification basis, book a discovery call to walk through the specific evidence gaps.

Book a discovery call →