Can Artificial Intelligence Keep  Skies Safe?

The true test of the Kingston tower will not be whether the screens can replace the windows. It will be whether the regulatory system can replace neither prudence nor accountability.

15 mins read
Rheinturm, Düsseldorf, Germany [Deniz Fuchidzhiev/Unsplash]

Flight operations not only have to be safe, but also orderly and quick. — Jens Bartels, Ramp Control Manager, Munich Airport

The Transition

There was a time when the air traffic control tower represented the very personification of aviation safety. Perched above the airport, its windows offered the controller an unobstructed view of runways, taxiways and aircraft. The controller watched, listened, interpreted, anticipated and, when necessary, intervened. The tower was therefore more than a building. It was the physical embodiment of human judgement standing between the orderly movement of aircraft and the consequences of error.

The proposed introduction of an unmanned, artificial-intelligence-operated air traffic control tower at Kingston Airport in Ontario challenges that deeply ingrained conception. The tower may no longer need a human being sitting behind the glass. Cameras, sensors, communications systems, computer screens and artificial intelligence could potentially provide the eyes, ears and cognitive processing traditionally associated with the air traffic controller.

The proposition is both exhilarating and unsettling. It is exhilarating because aviation has always progressed by replacing the limitations of human perception and physical infrastructure with technology. It is unsettling because air traffic control is not simply another technological process. It is an essential safety function in which decisions are made in real time, under conditions of uncertainty, with consequences that can be measured not merely in dollars but in human lives.

The Test

The question therefore should not be whether artificial intelligence is capable of controlling aircraft. The more important question is whether a non-human control system can be trusted with the responsibility of maintaining the safety of navigation and, if so, under what legal and regulatory conditions. This is where Kingston assumes a significance far greater than the geographical boundaries of Ontario. It could become a laboratory for the future of air traffic management.

The first point that must be made is that an unmanned tower need not necessarily mean an autonomous tower. The distinction is fundamental. A remote tower may remove the human controller from the physical airport environment while retaining the controller as the decision-maker. Cameras and sensors transmit an electronic representation of the airport to a controller located elsewhere. In such a system the tower becomes remote, but control remains human.

An AI-operated tower introduces another dimension. Here, the machine may not merely transmit what the human sees. It may interpret what the sensors detect, identify aircraft, assess traffic, predict conflicts, determine sequencing and potentially issue instructions. The machine thus moves from being an instrument of perception to becoming an instrument of cognition and, ultimately, decision-making. It is at that point that the philosophical character of air traffic control changes.

Advantages

For more than a century, aviation has been governed by a simple proposition: human beings operate aircraft, human beings control aircraft movements, and human institutions are responsible for ensuring that both are competent to perform their functions. Artificial intelligence disrupts this neat chain of accountability. Yet it would be wrong to approach this development with technological pessimism. There are compelling safety arguments in favour of AI.

The human controller, however highly trained, is subject to fatigue, distraction, workload, stress, sensory limitations and cognitive bias. A machine does not become tired at three o’clock in the morning. It does not lose concentration because traffic has become repetitive. It can process enormous quantities of data simultaneously. It can monitor several aircraft, weather systems, runway conditions, surveillance feeds and communications streams at once.

Artificial intelligence can also detect patterns that may escape human perception. A system capable of continuously comparing the actual movement of aircraft with expected trajectories could identify a developing conflict before a human controller recognizes it. Machine learning could potentially identify precursors to runway incursions, unusual aircraft behaviour or abnormal traffic patterns. In this respect, AI may offer something that the human controller cannot easily provide: persistent vigilance.

There is another advantage. Human beings must construct a mental picture of the airport environment. The AI system can maintain a digital representation of that environment continuously and update it in real time. Every aircraft becomes a data point with a position, velocity, altitude, trajectory and relationship to other traffic. The potential consequence is that situational awareness may actually be enhanced rather than diminished by removing the human from the physical tower.

The traditional tower has always been an exercise in limited perception. The controller looks outward through a window. The AI tower could look everywhere. Cameras can provide different fields of view. Infrared systems may operate in darkness. Radar and other surveillance technologies can supplement visual information. Sensors can monitor runway occupancy, surface movement and weather. Data can be integrated rather than compartmentalized.

The question then becomes whether the machine’s expanded field of perception can compensate for the absence of human intuition. There is reason for optimism. Aviation has repeatedly embraced technologies that initially appeared to diminish the role of human perception. Radio replaced reliance upon visual signalling. Radar extended the controller’s awareness beyond the horizon. Instrument flight allowed pilots to operate without seeing the ground. Digital navigation replaced many forms of traditional visual navigation. Automation has transformed the cockpit.

The Philosophy

The history of aviation is therefore not a history of human beings resisting machines. It is a history of human beings learning how to place machines within a framework of safety. The positive case for an AI tower is consequently powerful. It could provide more consistent surveillance. It could reduce certain categories of human error. It could operate continuously. It could analyse more information than a human controller. It could provide predictive warnings rather than merely reactive instructions. It could reduce the costs associated with maintaining conventional towers and potentially make controlled air traffic services economically viable at airports where conventional tower operations are expensive.

It could also improve resilience. If the system is appropriately designed, multiple remote operators or facilities could potentially assume responsibility for an airport in the event of a local emergency. The physical destruction or evacuation of a tower would not necessarily result in the loss of the air traffic service. The architecture of the tower would thus become less important than the architecture of the network.

There is a larger philosophical issue here. Air traffic control has traditionally been understood as a human profession. The controller does not merely apply rules. The controller exercises judgement within rules. Law itself operates in much the same way. Rules provide structure, but circumstances require interpretation.

The danger of autonomous systems is therefore that they may transform aviation regulation from a system of judgement into a system of algorithmic optimization. Efficiency, however, is not the same thing as safety. The fastest route is not necessarily the safest route. The most efficient sequence is not necessarily the most prudent sequence. A system designed to maximize runway capacity may discover that it can safely reduce separation under most circumstances. But aviation safety is concerned not only with what is safe most of the time. It is concerned with what happens when the assumptions upon which safety depends suddenly change.

The human controller has an instinct for conservatism because the human understands consequences emotionally as well as mathematically. Whether AI can acquire the equivalent of prudence is one of the great unanswered questions.

Challenges

But every technological advantage contains a corresponding regulatory question. If AI can process more information, can it also understand the significance of information that is incomplete? If AI can predict conflict, can it recognize an unusual human behaviour that has no precedent in its training data? If AI can make decisions more rapidly, can it determine when the correct decision is to do nothing?

These questions bring us to the negative connotations of the non-human tower. The greatest danger may not be that artificial intelligence makes a stupid decision. It may be that it makes a perfectly logical decision based upon an incorrect understanding of reality.

Consider the difference between a human controller and a machine confronted with an uncertain situation. A human controller may experience doubt. The controller may look again, listen more carefully, contact the aircraft, ask for clarification or simply recognize that something does not seem right. A machine does not possess doubt in the human sense. It has confidence levels, probabilities and programmed responses. That distinction is critical.

The future of AI safety in air traffic management must therefore be based not merely on accuracy but upon the transparent expression of uncertainty. If a camera cannot reliably determine whether an aircraft is on a runway or taxiway, the system must not present an unequivocal answer merely because its architecture requires one. It must communicate uncertainty. If two surveillance sources disagree, the disagreement must become visible. If the system encounters a situation outside the parameters for which it has been validated, it must know that it is outside those parameters.

In other words, an AI controller must be capable of saying, in its own technological language, “I do not know.” That may be one of the most important safety requirements for autonomous air traffic management.

There is another difficulty: automation complacency. When humans work with machines that are highly reliable, they can become less attentive. The very success of automation may weaken the ability of the human supervisor to detect a rare failure. A human who spends thousands of hours monitoring an AI system that is almost invariably correct may not be psychologically prepared for the moment when it is catastrophically wrong.

This creates a paradox. The more reliable the machine becomes, the more difficult it may become for humans to remain an effective safeguard against its failure. The human-in-the-loop therefore remains important, particularly during the developmental stage of autonomous air traffic control. But that human must be genuinely capable of intervening. It is not sufficient to place a controller before a screen and declare that human oversight exists. The controller must have the necessary information, authority, training and reaction time to override the machine. A human who is merely present is not necessarily a human safeguard.

There is also the question of cyber resilience. The digital tower is, by definition, a connected tower. It depends upon cameras, sensors, telecommunications, software, data links and computer networks. Each of these creates a potential point of vulnerability. The aviation community has spent decades developing physical redundancy. We understand the need for multiple engines, alternative navigation systems, backup communications and emergency power. The AI tower requires the same philosophy in the digital domain.

What happens when a camera fails? What happens when a communications link is interrupted? What happens when a software update introduces an unexpected behaviour? What happens when a malicious actor manipulates the data upon which the system relies? The most dangerous cyberattack on an AI tower would not necessarily shut it down. A silent manipulation of its information could be far more dangerous. An AI system making decisions on false information may continue operating normally while producing abnormal consequences.

This is why cybersecurity must become indistinguishable from aviation safety. The distinction between an information-technology system and a safety-critical aviation system disappears when the information determines whether an aircraft is cleared to take off.

Legal and Regulatory Aspects

Kingston is particularly interesting in this respect because the airport has already experienced unauthorized interference with digital airport systems. While that incident did not compromise critical air traffic control operations, it demonstrated that the airport’s digital environment is not immune from attack. A future AI tower must therefore be constructed on the assumption that it will be targeted, tested and challenged.

The regulatory principle should be simple: no single cyber failure should be capable of producing a catastrophic aviation consequence. This leads naturally to the question of redundancy. The non-human tower should not be designed as one computer making one decision from one data source. It should be an ecosystem of independent and mutually validating systems. Multiple sensors should be capable of corroborating information. Critical decisions should be subject to integrity checks. Communications should have alternatives. Power should be redundant. The system should possess a clearly defined degraded mode.

The most important word here is “degraded.” An AI tower must be capable of becoming less autonomous without becoming unsafe. If one camera fails, the system should continue with reduced capability. If several sensors fail, human intervention should become mandatory. If the AI’s confidence falls below a prescribed threshold, control should be transferred to a qualified human operator. If the entire system fails, an alternative air traffic service should be available. The safest autonomous system may therefore be one designed to relinquish autonomy.

This proposition has an important legal consequence. Canadian aviation regulation is traditionally built around identifiable human responsibility. Air traffic controllers are licensed. Air traffic service units operate under certificates. Operational procedures are documented. Safety management systems identify hazards and allocate responsibilities.

Artificial intelligence introduces a new actor that is not legally an actor. The machine cannot hold an air traffic controller licence. It cannot possess a medical certificate. It cannot be suspended. It cannot be prosecuted. It cannot appear before a tribunal and explain its conduct. Yet it can make the decision that caused the accident.

The law must therefore preserve accountability by ensuring that the autonomy of the machine never becomes an escape route for the humans and organizations responsible for deploying it. This is why the legal question at Kingston is not merely whether the system is technically certified. It is whether the regulatory system can identify who remains responsible when the machine makes the decision.

If an AI system clears an aircraft for take-off and the clearance contributes to an accident, responsibility could potentially implicate NAV CANADA, the system developer, the hardware manufacturer, the airport operator, the system integrator or others depending upon the circumstances. The law must therefore move from a model of individual fault to a more sophisticated model of system accountability.

This does not mean that AI should be treated as a legal person. Quite the contrary. The more autonomous the machine becomes, the more important it is that a human legal entity remain responsible. The principle should be that autonomy is granted to the machine but accountability remains with the organization. That principle should become the cornerstone of AI air traffic regulation.

There is also a particularly important international dimension at Kingston. Kingston is not an isolated Canadian airfield. Its proximity to the United States means that air traffic operations take place within an environment where Canadian sovereignty, American airspace interests and ICAO standards intersect. An AI system must therefore understand more than geography. It must operate within a legal geography.

An international boundary is not merely a line on a map. It represents sovereign jurisdiction and requires coordination between States and their respective air navigation service providers. A machine trained to optimize traffic purely according to efficiency might, in theory, produce a solution that is operationally attractive but inconsistent with the procedural requirements governing cross-border coordination.

This is where the Chicago Convention and ICAO standards remain indispensable. The genius of international aviation law has always been that States retain sovereignty over their airspace while agreeing to common standards and procedures. Technology does not eliminate that principle. It makes compliance with it more technologically complex. The AI tower must therefore be capable of translating legal and operational rules into machine-readable parameters without losing their meaning.

Perhaps the greatest positive contribution of AI will therefore not be to replace human controllers but to augment them. The future tower could become a partnership between human judgement and machine intelligence. AI could monitor everything while humans retain authority over exceptional circumstances. AI could provide predictions, warnings and recommended actions. Human controllers could retain final responsibility for decisions requiring contextual judgement.

Such a model would preserve the greatest strength of both systems. The machine provides computational scale. The human provides contextual judgement. The machine does not become the controller; it becomes the controller’s extraordinarily powerful assistant. That may be the most prudent path toward autonomy.

Yet the economic attraction of complete automation should not be underestimated. If AI can perform air traffic control functions with fewer personnel, airports and service providers will naturally ask whether human controllers are still necessary. The answer cannot be determined solely by economics. Aviation safety is not a commodity to be optimized against staffing costs.

If the principal justification for an autonomous tower is that it is cheaper, the regulatory question should immediately become whether the reduction in cost creates a corresponding increase in systemic risk. Conversely, if AI demonstrably improves safety while reducing operating costs, the law should not stand in the way merely because the technology is unfamiliar.

The proper philosophy is neither resistance nor surrender. It is evidence. Let the machine prove what it can do. Let the regulator establish what it must prove. Let operational experience determine the permissible degree of autonomy. And let safety remain the ultimate criterion.

This is particularly important because Kingston could become a precedent. If the technology proves successful, other Canadian airports may wish to follow. Remote and smaller airports may find the concept particularly attractive because traditional towers can be expensive to operate. AI could make controlled air traffic services economically feasible where they might otherwise be reduced or discontinued.

That would be a positive development if the technology improves the safety and accessibility of air navigation services. But it could also create a dangerous incentive if airports begin viewing AI as a means of replacing skilled personnel before the technology has demonstrated equivalent or superior safety. The regulator must therefore avoid a false equivalence between technological capability and regulatory readiness.

A machine may be capable of performing a function long before the law is capable of allocating responsibility for that function. The Kingston proposal consequently presents an opportunity for Canadian aviation regulation to move ahead of the technology rather than follow behind it.

There should be a dedicated regulatory framework for AI-enabled air traffic services. There should be graded levels of autonomy, beginning with observation and decision support and progressing only through evidence-based stages toward autonomous execution. There should be an AI safety case demonstrating performance under normal, abnormal and emergency conditions. There should be mandatory cybersecurity requirements, algorithmic change control, continuous monitoring, independent validation and rigorous recording of AI decisions.

Above all, there must be an effective fallback to human control. The most reassuring feature of an autonomous tower may therefore be the presence of a human being somewhere outside it. That is not a contradiction. It is the essence of resilience. The tower may be empty, but the system must never be without responsibility.

The proposed Kingston AI tower therefore deserves neither applause merely because it is innovative nor criticism merely because it is unfamiliar. It deserves something more valuable: serious regulatory scrutiny.

The positive connotations are substantial. Artificial intelligence could extend situational awareness, reduce certain forms of human error, detect potential conflicts earlier, process vast quantities of information, provide consistent surveillance and perhaps make sophisticated air traffic services available to airports that cannot sustain conventional tower operations.

The negative connotations are equally real. AI can fail silently. Sensors can be compromised. Algorithms can encounter situations outside their training or validation. Automation can produce complacency. Cyberattacks can manipulate information. Human supervisors can become detached from the decision-making process. And responsibility can become blurred when a machine is the immediate cause of an unsafe decision.

But there is one conclusion that should govern the debate. The issue is not whether the future of air traffic control will be human or artificial. It will almost certainly be both. The real question is how intelligently the two are combined.

The traditional tower was a physical manifestation of human judgement. The AI tower will be a physical manifestation of distributed intelligence. Screens may replace windows, sensors may replace eyesight and algorithms may supplement or eventually replace elements of human cognition. But the essential objective remains unchanged: to preserve the safety, regularity and efficiency of air navigation.

The tower without a human controller may therefore become one of the most significant symbols of aviation’s technological future. But its success should not be measured by whether it eliminates the human being from the tower. It should be measured by whether it eliminates the possibility of avoidable error from the system.

That is a much higher standard. And it is the only standard worthy of aviation.

My Take

The Kingston project should, in my view, be welcomed, but welcomed with the cautious optimism that aviation law has traditionally reserved for technologies capable of transforming the safety architecture of air navigation. The empty tower should not frighten us merely because it is empty. After all, aviation has never been an industry in which safety depended upon human eyesight alone. Radar enabled the controller to see beyond the horizon; digital navigation enabled the pilot to navigate beyond visual reference; automation enabled the aircraft to perform functions that once required continuous human intervention. Artificial intelligence is the next logical progression in that continuum.

But there is a profound difference between assisting human judgement and replacing it. The former enriches the safety system; the latter challenges its philosophical foundation. An AI system can calculate probabilities with astonishing speed, but aviation safety is not merely a mathematical exercise. It is an exercise in prudence under uncertainty. A controller may confront an unusual situation and decide to create additional separation, delay a departure or ask a pilot to confirm an apparently innocuous transmission. Such decisions may not maximize efficiency, but they may maximize safety.

This is why I would resist the proposition that the objective of Kingston should be to build a “controller without a controller.” The objective should instead be to create a system in which artificial intelligence becomes the most vigilant assistant the human controller has ever possessed. Let the machine observe everything, calculate everything and warn about everything. Let it identify a developing conflict before the human eye recognizes it. Let it monitor runway occupancy, weather, surveillance and traffic continuously. But retain human authority over those circumstances in which the system encounters ambiguity, uncertainty or novelty.

There is also a deeper legal principle at stake. The machine must never become the bearer of responsibility. It can become autonomous in function, but it cannot become autonomous in accountability. Someone must remain answerable when the system fails. NAV CANADA, the airport operator, manufacturers, software developers, system integrators and regulators may have different responsibilities, but the chain of responsibility must never disappear into the algorithm.

The true test of the Kingston tower will therefore not be whether the screens can replace the windows. It will be whether the regulatory system can replace neither prudence nor accountability. If AI can demonstrate that it sees more, understands more, predicts more accurately and responds more consistently than humans in defined operational circumstances, then the law should have the courage to embrace it. But if the technology cannot demonstrate how it recognizes uncertainty, how it fails safely, how it can be overridden and how its decisions can be reconstructed after an occurrence, then autonomy should remain beyond its legal reach.

I therefore see Kingston not as the beginning of the end of the human controller, but as the beginning of a new relationship between human intelligence and artificial intelligence in air navigation. The tower may cease to be a place. It may become a network. Control may cease to be exercised through a window and increasingly through a screen. Yet the fundamental compact between aviation and society must remain unchanged: those who place aircraft into the sky must be able to demonstrate that the system governing their movement is safe.

The future tower may have no human occupant. But it must never have no human responsibility. That, ultimately, is my take.

Ruwantissa Abeyratne

Dr. Abeyratne teaches aerospace law at McGill University. Among the numerous books he has published are Air Navigation Law (2012) and Aviation Safety Law and Regulation (to be published in 2023). He is a former Senior Legal Counsel at the International Civil Aviation Organization.

Leave a Reply

Your email address will not be published.

Latest from Blog