Blog

AI Regulations for Aviation: FAA, EASA, and ICAO

A plain-English guide to FAA, EASA, and ICAO AI regulations for US aviation decision-makers navigating compliance today.

Phos Team ·
aviation AI Strategy

Aviation has always been one of the most tightly regulated industries in the world. Now artificial intelligence is moving into the cockpit, the control tower, and the maintenance hangar, and regulators are racing to keep up.

For US-based aviation executives, operators, and technology leads, understanding where the rules stand today is not optional. Procurement decisions, deployment timelines, and liability exposure all hinge on regulatory clarity.

This guide breaks down the current AI regulatory landscape across the three bodies that matter most: the FAA, EASA, and ICAO. If you are already evaluating AI solutions for aviation, this is the compliance context you need before committing to any deployment path.


Where the FAA stands on AI

The Federal Aviation Administration has not yet issued a comprehensive AI regulation. What exists instead is a patchwork of guidance documents, policy statements, and ongoing rulemaking activity.

In 2023, the FAA published its Artificial Intelligence Safety Strategy, signaling that the agency treats AI as a cross-cutting safety issue rather than a narrowly technical one.

The FAA’s approach centers on three pillars:

  1. Airworthiness certification for AI components integrated into certified aircraft systems
  2. Operational approval for AI-assisted tools used by pilots, dispatchers, or air traffic control
  3. Safety oversight for AI used in maintenance, inspection, and predictive analytics

The agency relies heavily on its existing regulatory framework, particularly Title 14 of the Code of Federal Regulations (14 CFR), and applies it to AI through issue papers and special conditions rather than new rules.

The FAA’s AI Rulemaking Committee (ARC), convened in 2023, is tasked with recommending how existing certification pathways can accommodate machine learning and adaptive systems. Its findings are expected to inform formal rulemaking in the coming years.

For now, the practical takeaway is this: the FAA is not standing still, but it is moving methodically. Operators should not wait for final rules before building compliant programs.

Key FAA reference documents

DocumentPurpose
FAA AI Safety Strategy (2023)Agency-wide framework and priorities
AC 20-115DSoftware considerations for airborne systems
FAA ARC Report (expected 2024-2025)Recommendations on ML certification
Issue Papers (case-by-case)Aircraft-specific AI approvals

EASA’s AI roadmap and regulatory approach

The European Union Aviation Safety Agency has taken a more structured, published approach to AI regulation than the FAA.

EASA released its Artificial Intelligence Roadmap 2.0 in 2023, building on the first version published in 2021. The roadmap defines a four-level risk classification system for AI applications in aviation.

The four EASA AI risk levels are:

  • Level A: AI provides information only; human makes all decisions
  • Level B: AI recommendations influence human decisions
  • Level C: AI takes action with human supervision
  • Level D: AI operates autonomously with no human in the loop

Each level carries different design assurance, explainability, and robustness requirements. Higher levels face more rigorous scrutiny.

EASA also introduced the concept of trustworthy AI, borrowing directly from the EU AI Act’s language around transparency, human oversight, robustness, and accountability.

EASA’s Concept Paper on AI and its First Usable Guidance on Level 1 and 2 Machine Learning Applications provide the most actionable compliance direction available today for operators in European airspace.

One important distinction: EASA is both a rulemaking authority and a certification agency. Its guidance carries direct regulatory weight in EU member states, making it structurally more binding than equivalent FAA advisory material.


ICAO’s role in the global framework

The International Civil Aviation Organization sets standards and recommended practices (SARPs) that member states are expected to adopt into their national regulations. ICAO does not certify aircraft or issue operating approvals directly.

On AI, ICAO has focused its energy on two primary areas.

First, data governance and AI ethics, addressed through the ICAO AI Task Force and the Long-Term Aspirational Goals (LTAG) framework.

Second, human factors and automation, particularly as AI increases workload shifting between human operators and machine systems.

ICAO’s Manual on AI Safety (Doc 10164) is the most comprehensive framework document the organization has produced. It covers AI lifecycle management, safety risk assessment, and the responsibilities of states and operators.

“States should ensure that AI systems deployed in civil aviation are developed, validated, and monitored in a manner consistent with ICAO SARPs and the principles of safety management.”

; ICAO Doc 10164

For international operators, ICAO’s framework documents are the connective tissue between FAA requirements and EASA’s more detailed rulemaking. They set the common vocabulary and baseline expectations that both agencies reference.


How these frameworks intersect for international operators

If your operation touches both US and European airspace, you are subject to multiple regulatory regimes simultaneously. This creates real complexity.

Here is a simplified view of how the frameworks currently align:

AreaFAAEASAICAO
AI risk classificationNot formalized4-level model (Roadmap 2.0)Principle-based
Certification pathwayIssue papers, special conditionsEASA Opinion and Decision processSARPs implemented by states
Explainability requirementsImplicit in safety caseExplicit per risk levelRecommended
Human oversightRequired for certified systemsRequired, level-dependentRecommended

The good news for US operators is that the FAA and EASA coordinate through a bilateral aviation safety agreement (BASA). AI-specific annexes to this agreement are expected as both agencies’ frameworks mature.

For now, the safest strategy is to design AI systems to the higher of the two standards. In most cases, EASA’s published guidance is currently more specific, making it a useful proxy for what the FAA will likely require.


What “certifiable AI” means in practice

The phrase “certifiable AI” refers to AI systems designed and documented in a way that a regulatory authority can approve them for use in aviation.

This does not mean every AI tool in your operation needs FAA or EASA certification. It depends on where the AI sits in the safety chain.

Certified vs. non-certified contexts:

  • Safety-critical systems (flight control, navigation, collision avoidance): Full certification required
  • Operational decision support (scheduling, dispatch, maintenance alerts): Approval or operational authorization may be required
  • Back-office and administrative AI (HR, finance, vendor management): Generally outside certification scope

The core elements regulators look for when evaluating certifiable AI:

  1. Determinism: Can the system’s outputs be predicted and bounded under all operating conditions?
  2. Explainability: Can the decision process be described in terms a safety assessor can evaluate?
  3. Training data assurance: Is the data used to train the model known, curated, and free of bias that affects safety?
  4. Robustness: Does the system fail safely when it encounters out-of-distribution inputs?
  5. Monitoring: Is there a process to detect performance degradation after deployment?

Certifying AI systems requires documentation that spans the full AI lifecycle, from data collection through model training, validation, deployment, and ongoing monitoring. The paperwork burden is substantial and should be scoped into project timelines from day one.


Common compliance pitfalls

Aviation companies frequently run into the same problems when approaching AI compliance. Knowing them in advance saves time and money.

1. Treating AI as software under DO-178C

DO-178C is the dominant software certification standard in aviation. It was designed for deterministic, rule-based software. Machine learning models are not deterministic in the same way, and applying DO-178C directly to them creates gaps regulators will flag.

EASA’s guidance specifically addresses this. The FAA is expected to follow with updated advisory circulars.

2. Skipping the safety case

Many vendors deliver AI tools without a safety case document. A safety case is a structured argument, supported by evidence, that the system is safe for its intended use. Regulators expect it. Skipping it is not an option for safety-critical applications.

3. Assuming approval in one jurisdiction transfers automatically

A system approved under EASA’s framework does not automatically satisfy FAA requirements, and vice versa. Bilateral agreements help, but parallel documentation is often required.

4. Underestimating data governance requirements

Both the FAA and EASA expect operators to demonstrate control over the data used to train and update AI models. Ad hoc data pipelines are a red flag in any safety audit.

5. Ignoring post-deployment monitoring obligations

Approval is not a one-time event. Regulators expect ongoing performance monitoring, incident reporting, and a defined process for handling model updates.

Building compliant AI deployments requires treating the deployment environment as part of the safety case, not an afterthought that gets addressed during the audit.


What aviation companies need to do now

Regulatory frameworks for AI in aviation are still forming. That creates both risk and opportunity.

Companies that begin building compliant, documented AI programs now will have a significant advantage when formal rules arrive. Those that wait will face retrofit costs and potential operational disruptions.

A practical starting checklist:

  • Map all current and planned AI tools against the EASA risk level taxonomy
  • Identify which systems may require FAA or EASA certification or operational approval
  • Engage your Designated Engineering Representative (DER) or Authorized Representative (AR) early
  • Build a data governance program that can withstand regulatory scrutiny
  • Establish a safety case process for any AI touching safety-critical functions
  • Review your ICAO SMS documentation for AI-related risk assessments
  • Monitor FAA ARC outputs and EASA Opinion publications for rulemaking updates

For operators evaluating data security alongside compliance, private AI options can reduce exposure by keeping sensitive operational data out of third-party model training pipelines entirely.


Regulatory ambiguity is itself a compliance risk. Every AI deployment decision you make today is either setting a foundation you can build on or creating technical debt you will pay for later.

AI regulation in aviation is moving from guidance to enforcement; operators who understand the current requirements are better positioned to adapt as the rules tighten.

Path one: identify every AI system currently in use in your operation. List all tools that use machine learning or AI, including scheduling assistants, maintenance analytics, and safety monitoring platforms. For each one, document what decision it influences and whether that decision has regulatory implications. That inventory is the starting point for a compliance review.

Path two: bring in a partner. Phos AI Labs designs AI implementations for aviation organisations; regulatory-compliant AI deployment, compliance integration, and the private AI environment your team will actually use. We have run 400+ AI engagements. Clients include Zapier, Coca-Cola, Medtronic, Dataiku, and American Express. Thirty minutes, no deck. Start here.

Related articles

The fastest way to know whether we're the right fit, is a conversation.

STEP 1/2 · ABOUT YOU