Back to Insights

Aviation AI Cannot Afford a Jurisdiction Question at 35,000 Feet

Picture a chief maintenance officer, six weeks after a serious incident, sitting across from investigators from the Bureau d'Enquêtes et d'Analyses — the French agency that investigates civil...

Aviation AI Cannot Afford a Jurisdiction Question at 35,000 Feet The scenario that makes the gap concrete: Investigators ask for AI-generated maintenance recommendations from the 72 hours before an incident. The AI system came from the OEM. Data flowed to vendor cloud. Log retention: 90 days commercial policy. The investigation was six weeks in. The logs were gone. AVIATION REQUIRES • Every maintenance action documented • Operator-controlled retention • Investigation-ready audit trails • Jurisdiction: local regulatory body • No gaps in safety-critical records EASA, ICAO, FAA: all mandate this. VENDOR AI PROVIDES • AI outputs logged per vendor policy • Retention: 30–90 days typically • Jurisdiction: vendor's server location • CLOUD Act applies to US providers • Operator cannot audit the stack Gap: commercial policy ≠ safety regulation SIA LEVEL 3 (AIR-GAPPED) • Operator-controlled infrastructure • Retention policy set by operator • Recorder: immutable audit trail • Jurisdiction: where operator operates • Full audit by regulator on demand Every recommendation. Timestamped. Yours. THE SOVEREIGN INSTITUTE thesovereigninstitute.org

Aviation AI Cannot Afford a Jurisdiction Question at 35,000 Feet

Picture a chief maintenance officer, six weeks after a serious incident, sitting across from investigators from the Bureau d'Enquêtes et d'Analyses — the French agency that investigates civil aviation accidents. They want every AI-generated maintenance recommendation the aircraft received in the 72 hours before the event. The AI system came from the OEM. The maintenance data flowed to vendor cloud infrastructure. The vendor's standard API log retention is 30 days. The investigation request arrived at day 43. The logs no longer exist.

An aircraft must be airworthy before it leaves the gate. The AI that informs whether it is airworthy must be auditable after it lands.

---

The Arithmetic Gap No One Fixed

The timeline collision at the center of aviation AI governance is precise and documented. Standard cloud API retention windows run 30 days for most commercial tiers. Aviation accident investigations routinely begin requesting primary data 60 to 90 days after a triggering event — after initial safety responses, crew interviews, and preliminary review. The gap between when AI logs expire and when investigators ask for them is not a regulatory ambiguity. It is an arithmetic problem that current aviation AI infrastructure consistently fails.

EASA's AI Roadmap 2.0, published in 2023, requires that AI systems used in safety-relevant aviation applications be explainable and auditable. EASA AMC-20-42, the acceptable means of compliance for machine learning in airborne systems, establishes that organizations must be able to explain any AI-assisted decision that contributed to a safety-relevant outcome. The FAA's 2024 roadmap for AI in aviation echoes the same direction. Neither regulatory body has yet defined enforcement deadlines with the precision of, say, DO-178C for onboard software certification — a gap that closes between 2026 and 2027, when both EASA and FAA frameworks are expected to move from advisory to binding.

Aviation built DO-178C — the software certification standard governing every line of code in an aircraft system, from autopilot to terrain warning — over decades of meticulous development. Every update to flight-critical software requires documented testing, traceability from requirement to code, and certification by recognized airworthiness authorities. The AI informing maintenance decisions at the gate has none of that certification history. It runs on commercial cloud infrastructure, under terms of service written for general enterprise use, retained for 30 days.

---

The Platforms Moving the Data

Airbus's Skywise platform connects health monitoring data for more than 10,000 commercial aircraft, built on Microsoft Azure. Microsoft is headquartered in Redmond, Washington. The CLOUD Act — a 2018 US law empowering federal agencies to compel any US-headquartered company to produce data regardless of where it is stored — applies to every flight health data record Skywise processes. A European airline whose maintenance data flows to Skywise's Azure infrastructure has its fleet health intelligence under US legal jurisdiction.

Rolls-Royce TotalCare uses predictive maintenance AI to reduce unscheduled engine removals — a genuinely valuable service that has improved engine reliability across the fleets that use it. The data flows to Rolls-Royce's infrastructure in the UK with cloud processing on UK and international data centers. GE Aviation's OnPoint and Digital Aviation Solutions process fleet health data under GE's infrastructure, with GE Aerospace headquartered in Evendale, Ohio. Each of these programs represents a transfer of fleet intelligence to vendor infrastructure through commercial agreements that airlines signed for their maintenance benefits, not their data governance implications.

GE Aviation's commercial aviation services revenue exceeds $10 billion annually — substantially built on data-driven services derived from fleet health monitoring. When fleet intelligence sits on vendor infrastructure, the vendor can calibrate service contract pricing based on usage patterns, identify aircraft approaching maintenance milestones before the airline's own team does, and develop cross-fleet models of failure modes using aggregate data from multiple operators. The airline bought maintenance reliability. The vendor retained operational intelligence.

A commercial aircraft generates roughly one terabyte of sensor and operational data per flight. Multiplied across major fleet operations, this represents among the most valuable and structurally sensitive industrial data in aviation. The sovereignty question isn't whether OEM AI programs provide value — they do. The question is whether an airline's regulatory and investigative accountability can depend on data it cannot independently access, retained under terms it did not negotiate.

---

The Boeing Precedent

Boeing's 737 MAX MCAS software malfunctioned in two accidents that killed 346 people. The investigations required complete documentation of every software design decision, test result, certification submission, and organizational communication related to MCAS. Boeing ultimately settled claims exceeding $20 billion and faced criminal liability because investigators could reconstruct exactly what happened, what was known, and when. The accountability was possible because the data existed, retained in Boeing's own systems, subject to investigation authority.

Apply that standard to the next AI-assisted maintenance scenario. If an AI-informed maintenance recommendation contributed to an incident, investigators will require complete reconstruction: what data the model had access to, which model version generated the recommendation, what training data it used, and what confidence level applied at the moment of recommendation. If that data exists on OEM vendor infrastructure with standard commercial retention, the airline may face the same accountability questions Boeing faced — without the documentation Boeing had to answer them.

EASA's AI roadmap makes the accountability chain explicit: the operator is responsible for demonstrating that AI used in safety-relevant functions meets explainability and audit requirements. Not the OEM vendor. Not the cloud provider. The operator. An airline that cannot produce AI recommendation logs is not facing a vendor failure — it is facing a compliance failure of its own.

---

Maintenance Engineers Who Already Know

Maintenance engineers regularly receive AI-generated recommendations for go/no-go decisions on aircraft repairs. The recommendation increasingly informs the decision, even when the engineer formally approves it. That informal reliance is neither surprising nor wrong — AI-assisted recommendation systems are more accurate than unaided estimation for many maintenance categories, which is precisely why airlines adopted them.

The governance gap is not that engineers rely on AI recommendations. The gap is that when the recommendation record needs to be produced — for a regulator, for an investigation, for a legal proceeding — the engineer's organization may not control that record. The decision was made inside the approved system, by a qualified professional, following standard procedure. The audit trail exists on infrastructure the organization cannot access independently.

Aviation safety culture produced the black box — a device engineered from first principles to survive conditions that kill everything around it, ensuring every significant flight parameter is recoverable regardless of the severity of the event. The same industry is deploying AI for maintenance decisions with no equivalent. Standard commercial cloud infrastructure doesn't survive an investigation timeline.

---

What Investigation-Ready Infrastructure Looks Like

The SIA methodology's audit completeness principle — every AI interaction logged, timestamped, and stored on organization-controlled infrastructure — maps directly to what aviation safety investigators actually require: complete, unbroken, independently accessible records of every AI inference that contributed to a safety-relevant decision.

An airline deploying sovereign AI infrastructure runs the OEM intelligence programs it needs for maintenance reliability while maintaining a parallel record under its own control. The SIA Recorder logs every AI recommendation the airline's maintenance team receives — timestamped, model-versioned, data-contextualized — in on-premises infrastructure subject to the airline's own retention policy. When the BEA or NTSB requests AI logs, the airline produces them within 24 hours from its own systems. Not from a vendor portal. Not subject to commercial retention defaults. From infrastructure the airline controls.

The SIA Firewall principle prevents AI models from exfiltrating fleet intelligence to external endpoints without explicit airline authorization. Fleet health patterns, predictive failure data, and maintenance effectiveness intelligence stay in the airline's own data environment. The airline benefits from OEM AI recommendations through controlled access channels; the OEM does not receive unrestricted access to fleet data that builds its own commercial models.

This is not the false choice between OEM AI programs and data sovereignty. The SIA Level 1 architecture handles exactly this hybrid reality — cloud access for non-sensitive AI functions, sovereign infrastructure for safety-relevant data and audit records. Airlines that adopt this architecture can demonstrate EASA AMC-20-42 compliance with specific documentation. Those on standard commercial AI platforms cannot yet demonstrate what they'll need to demonstrate by 2026.

---

The Enforcement Window Is Closing

EASA and FAA AI governance requirements are building toward a 2026-2027 enforcement window. Architecture change cycles in aviation — procurement review, integration validation, regulatory approval — run 18 to 24 months. Airlines that begin the transition in 2026 will complete it as frameworks become binding. Airlines that begin after frameworks become binding will complete it with active regulatory scrutiny throughout the process.

Airlines that establish sovereign AI audit infrastructure before enforcement begins will meet EASA's explainability requirements with documentation that already exists. Airlines that don't will face the same investigative questions — with the same accountability standard — running a compliance catch-up under time pressure.

Aviation invented the black box because the industry learned that accountability without documentation is not accountability at all. AI audit sovereignty is the black box for the maintenance layer. The engineering principle hasn't changed. The implementation is overdue.

---

The Sovereign Institute publishes the SIA standard for AI deployments meeting seven non-negotiable criteria: Data Residency, Model Sovereignty, Vendor Independence, Audit Completeness, Hybrid Intelligence, Governance by Design, and LLM Agnosticism. Certified practitioners advise on aviation AI governance frameworks at thesovereigninstitute.org.

← Previous Anthropic Was Banned by the Pentagon in 48 Hours. Here's What That Means for You.

Full SIA methodology documentation and certification programs at thesovereigninstitute.org