PSU Aeronautical Professor points the ODYSSEY to an AI system that provides EFFECTIVE SAFETY

JDA Aviation Technology Solutions

 

AIAA published the attached instructive presentation by the head of PSU Department of Aerospace and Engineering AMY PRITCHETT[1] as she defines how AI and the cockpit crew SHOULD INTERACT. This esteemed aerospace expert’s opinion tacitly[2] refutes that recurrent rant of the pilot profession THAT single or NO pilot cockpits are UNSAFE and UNACCEPTABLE.

Her basic point (excuse the attempt to summarize her full review- read next section) is that AI, the PIC and SIC must be INTERDEPENDENT AND NOT DEPENDENT. All three participants must

  • announce what it/he/she is doing
  • be conscious of when it/she/he is reaching limits and explicitly asks for help
  • be able to adapt to changing goals and conditions
  • explains its/his/her strategies in operationally relevant terms that a busy pilot or controller can quickly grasp

Dr. Pritchett (MIT- BS,MS, MIT thesis- Non-Conformance to Alerting Systems Commands During Closely-Spaced Parallel Approaches) sets forth this demanding challenge by stating that ““It is HARDER TO DESIGN AN INTERDEPENDENT interactive system than to design an independent system,”

Recognizing that all aviation professionals may not fully comprehend what that entails; so, Copilot AI provided this summary:

►Designing interactive systems for commercial aircraft involves balancing safety, reliability, and human factors. While independent systems operate in isolation, interdependent systems must coordinate across multiple subsystems (including the humans that interact with the autonomous participant)—each influencing the other. This complexity makes design, testing, and certification significantly more challenging.

    • Multiple systems (e.g., avionics, flight controls, engine management) must share real-time data.
    • Timing mismatches or latency can cause inconsistent states.
    • Designers must ensure deterministic behavior even under variable loads.
    • Pilots interact with integrated displays combining flight, navigation, and performance data.
    • Cognitive load increases when systems cross-reference each other.
    • Interface design must prevent confusion between automated and manual control modes.
    • A fault in one subsystem (e.g., sensor input) can affect others through shared data buses.
    • Requires advanced fault isolation and redundancy strategies.
    • Certification demands exhaustive failure mode and effects analysis (FMEA).
    • Independent systems can be verified individually.
    • Interdependent systems require end-to-end validation across interfaces.
    • DO-178C and ARP4754A standards mandate traceability between requirements, code, and test results.
    • Interactions between subsystems can produce unexpected outcomes not visible in isolated testing.
    • Simulation environments must model these emergent effects accurately.

Interdependent interactive systems in commercial aircraft are harder to design because they require holistic integration across mechanical, electrical, and software domains. Each subsystem’s behavior affects others, demanding rigorous coordination, testing, and certification. The challenge lies not only in technical complexity but also in ensuring that pilots can interact seamlessly with a system that behaves predictably under all conditions.◄

Aviation’s technical challenges are numerous, but even more formidable is the FAA’s development of standards to determine the airworthiness of the INTERDEPENDENT machine.

Professor Amy Pritchett Calls for “Team Autonomy” to Safeguard Global Airspace

By Anne Wainscott-Sargent

At AIAA AVIATION Forum, Penn State aerospace chair warns that today’s autonomy architectures misplace responsibility on humans while asking them to do a job they’re fundamentally bad at: monitoring rare failures.

SAN DIEGO – On the final day of AIAA AVIATION Forum 2026, AMY PRITCHETT[3], head of the Department of Aerospace Engineering at Penn State University, challenged the aerospace community to RETHINK HOW IT DESIGNS AUTONOMY FOR THE GLOBAL AIRSPACE SYSTEM – SHIFTING FROM A FOCUS ON “HUMAN VS. AUTONOMY” TO HUMAN-AUTONOMY TEAMS built on interdependence, shared responsibility, and explainable behavior.

The AIAA Fellow argued that aviation still treats autonomy as an independent actor that “grabs the controls” while humans are relegated to passive overseers. That model, she suggested, is FUNDAMENTALLY FLAWED for a tightly coupled, safety-critical system like global airspace.

Watch the full Transforming the Global Airspace: Rethinking the Human-Autonomy Team Architecture session.

AIbut is anything fully autonomous? Should it be?” she asked. “Do we clear any aircraft for takeoff saying, ‘Hey, go do whatever you want’? No, we do not.”

Citing U.S. Air Force planning guidance, she noted that even in defense contexts, autonomy is increasingly framed as A TEAM MEMBER, not a standalone agent. The real design challenge, she said, is creating interdependent architectures where human and machine roles are explicitly coordinated, not just partitioned function-by-function.

“It is HARDER TO DESIGN AN INTERDEPENDENT interactive system than to design an independent system,” she said. “But this is the challenge for our age right now in human-autonomy teaming.”

Authority vs. Responsibility: A Misaligned Contract

A central theme of Pritchett’s talk was the legal and ethical gap between authority and responsibility in current aviation regulations. Under FAA rules, including Part 91.3, the pilot in command – even a remote pilot – is legally responsible for the outcome of the flight, regardless of how much automation is in use.

“A human can delegate authority to another agent, like the autonomy,” she explained. “They can revoke it. But the human cannot delegate responsibility for the safe outcome. THAT’S ON THEM.”

The result, she warned, is an architecture where autonomy is free to “do what it wants, how it wants,” while humans are expected to supervise increasingly complex systems, detect subtle problems in time, and then instantly take overoften in situations they rarely practice.

“Human operators are poor monitors,” Pritchett said, referencing a 1951 National Research Council report that is still, in her view, underappreciated. “It is hard to just sit and stare at this thing. We are humans – we have many superpowers, but that is not one of them.”

She called out a core design failure: most autonomy lacks the ability to recognize its own limits and call for help. Without that, she said, “the supervisor’s job is to sit there and wait for something to happen and make certain that you intervene fast enough to recover the situation,” often with incomplete observability and eroding hands-on skills.

Humans Are Doing Much More Than “Causing Errors”

Pritchett pushed back against the narrative that autonomy is needed primarily to eliminate “pilot error.”

“I’ve often heard that we need more autonomy because pilot error is so common,” she said. “Well, of course they’re involved in accidents – they’re on the airplane trying to fix it. Pilots are involved in 100% of accidents. They’re there.”

DRAWING ON OPERATIONAL DATA, she highlighted that technical malfunctions occur in roughly 20% of normal commercial flights, typically handled quietly by pilots as part of routine work. In just over half of accidents, something technical fails and pilots are unable to resolve it BUT THAT STATISTIC IGNORES THE COUNTLESS TIMES THEY SUCCEED.

“Normal includes constantly dealing with things that are off and need to be corrected,” she said. “Pilots routinely, frequently mitigate safety and operational risk – because that’s normal.”

She tied this to aviation’s extraordinarily high dispatch reliability. “We get this amazing dispatch rate in large part because the pilots can take over for anything that fails,” she noted.

Designing Autonomy that Works as a Teammate

Looking ahead, Pritchett urged the community to measure autonomy by its TEAMWORK SKILLS, NOT JUST ITS TECHNICAL PERFORMANCE.

“If you want to say that we have a human-autonomy team, then I want to see all the members of the team behaving healthy and proud,” she said. That means autonomy that:

  • Announces what it is doing and why
  • Knows when it is reaching its limits and explicitly asks for help
  • Adapts to changing goals and conditions
  • Explains its strategies in operationally relevant terms that a busy pilot or controller can quickly grasp

“One pilot would say to the other, ‘I’m going to decrease the speed to maneuvering speed if we hit any turbulence,’ and explain their strategy,” she said. “It’s not enough to say we’ll make a learning system that will adapt that way. It also needs to explain what’s going on as part of the team.”

She also suggested REASSIGNING SOME “BORING AND DULL STUFF” TO AUTOMATIONsuch as routine radio calls and wide system checks – while preserving pilot flying skills and engagement.

The FAA has already issued a safety alert to promote pilots flying more,” she noted. “That’s a change from our assumptions in engineering, where we assume we want autonomy to do everything.”

Following the session, Rhea Liem, an associate professor of aeronautics at Imperial College London, who helped chair the multidisciplinary design optimization session, said students shouldn’t fear being replaced by autonomy in one of the world’s safest and most complex transportation systems.

“Students worry they’ll be useless because of machines and autonomy, but we just have to outsmart the machine,” Liem said. “We’ll always be useful if we make ourselves useful. As technology evolves, our education has to evolve too.”

She predicted that the human-machine relationship in aviation will keep evolving, but in ways that shift roles rather than erase them, putting pressure on education to prepare students to “control the autonomy instead of being controlled by the machine.”

 


[1] Congress has convened an ad hoc study committee, chartered by the National Academies of Sciences, Engineering and Medicine, of nine experts to study risks and protocols and to issue a report with key findings and recommendations. Among the nine experts named to the committee was Amy Pritchett, department head and professor of aerospace engineering at Penn State.

[2] Later in the article Assistant Professor Rhea Liem explicitly refutes this “fear”.

[3] Congress has convened an ad hoc study committee, chartered by the National Academies of Sciences, Engineering and Medicine, of nine experts to study risks and protocols and to issue a report with key findings and recommendations. Among the nine experts named to the committee was Amy Pritchett, department head and professor of aerospace engineering at Penn State.

Sandy Murdock

View All Posts by Author