By Dr. Jose Ramirez
Europe has spent the past few years building two of the world’s most ambitious regulatory frameworks: the world’s first comprehensive legal framework for artificial intelligence and a sophisticated regulatory architecture for unmanned aviation.
The problem is that they were not originally designed together and the aviation framework could hardly have anticipated the speed and scale of recent advances in artificial intelligence.
The EU AI Act now coexists with the European regulatory framework for drones, while artificial intelligence is becoming increasingly relevant to detect-and-avoid systems, navigation, flight planning and higher levels of automation, including systems whose behaviour may not always be entirely predictable.
This does not necessarily mean that the two frameworks conflict. But it does mean that manufacturers and operators may increasingly find themselves at the intersection of two regulatory systems developed from different perspectives. Fitting them together is not always straightforward.
Aviation regulation starts with safety. AI regulation takes a risk-based approach to the technology. An autonomous drone may have to satisfy both.
The question is therefore no longer simply whether AI will transform drone operations. It is whether Europe’s legal infrastructure can evolve quickly enough (and coherently enough) to govern that transformation.
Two frameworks, one emerging interface.
The EU AI Act, Regulation (EU) 2024/1689, establishes a horizontal framework governing AI systems across sectors.
For aviation, however, its application requires some care.
Under Article 6(1), an AI system may be classified as high-risk where it is a product or safety component covered by EU harmonisation legislation listed in Annex I (EU product safety legislation, including aviation) and requires third-party conformity assessment.
This distinction matters. It would be too simplistic, and potentially misleading, to say that every drone incorporating artificial intelligence automatically becomes a high-risk AI system.
But as AI moves closer to safety-critical functions (and occasionally malfunctions), the interaction between aviation safety regulation and the AI Act becomes increasingly important.
The European drone framework was built primarily around operational risk. Regulations (EU) 2019/947 and 2019/945 address matters such as operational categories, UAS requirements, pilot competency and the conditions under which operations may take place.
Artificial intelligence introduces a different set of questions and some disruptive new challenges.
How predictable is its behaviour? Can its decisions be explained? What happens when the system behaves in ways its developers did not anticipate? And what happens when the machine makes a decision that the human operator cannot realistically reverse?
These are no longer theoretical questions for aviation regulators.
As researchers Benjamyn Scott, Bart Custers and Henning Lahmann observed in Air and Space Law (2024): “While drone rules do not address AI directly, they do indirectly, as autonomous drone operations are permitted in the single European sky. The general AI legal framework also applies to drone activities, despite such not being mentioned.”
EASA is already moving towards advanced automation
EASA, to its credit, recognised the issue well before the AI Act became fully operational.
Its Artificial Intelligence Roadmap 2.0 established a human-centric approach to AI in aviation and envisaged a gradual progression from human assistance to human-AI teaming and, ultimately, advanced automation.
EASA has since taken this further.
In November 2025, EASA published NPA 2025-07 (EASA’s first regulatory proposal on AI trustworthiness in aviation) under Rulemaking Task RMT.0742 (EASA’s AI rulemaking programme). The proposal develops specifications on AI trustworthiness for aviation, initially covering Level 1 (human assistance) and Level 2 (human-AI cooperation).
Then, in June 2026, EASA released Proposed Issue 03 of its Concept Paper on Artificial Intelligence (EASA guidance outlining its approach to AI in aviation).
This is particularly interesting for unmanned aviation because the paper moves into Level 3 AI: advanced automation. EASA describes this as opening the way to operations in which the human end user may be remotely present or may not be present during the operation at all.
That changes the regulatory landscape, our understanding of autonomy and, ultimately, its legal consequences.
At lower levels of automation, the regulatory model remains relatively familiar (nothing fundamentally new): technology assists a human being who retains an identifiable operational role.
As autonomy increases, however, something fundamentally new emerges: the relationship between human and machine becomes more difficult to define.
EASA’s Roadmap distinguishes between Level 3A (decisions and actions remain overridable by the human) and Level 3B (the AI-based system may perform non-overridable decisions and actions). The latter may be relevant, for example, where human oversight or the communication and control link is lost. The system must then manage the situation on its own.
For drone operations, that distinction could prove fundamental.
The human oversight paradox
Article 14 of the AI Act places human oversight at the centre of the regime for high-risk AI systems.
The underlying logic is understandable. Where an AI system can affect safety or fundamental interests, human beings should retain an appropriate capacity to understand its operation, identify anomalies and intervene when necessary, while remaining responsible for their role in the operation.
Aviation, however, exposes an uncomfortable question: what happens when increasing automation makes human intervention less relevant? What if the machine must react faster than the human or when communication with the operator is unavailable?
In such circumstances, human oversight remains important at the level of system design, supervision and operational architecture. But it may no longer mean that a human being can approve or reverse every individual decision.
This is where the legal question becomes particularly interesting.
There is an intriguing parallel here with the legal concept of necessity: causing or accepting a lesser harm in order to avoid a greater one. But what happens when that assessment is made not by a human being, but by an autonomous system?
Who determines which harm is the lesser one? On the basis of which criteria? And who bears responsibility when the machine makes that choice?
This is the paradox of human oversight: safety may sometimes require the system to act without immediate human intervention.
EASA appears conscious of this tension. Its work on Level 3 is explicitly exploring advanced automation while maintaining the broader human-centric approach of the AI Roadmap.
But greater autonomy inevitably leads to another question: where does responsibility lie when something goes wrong?
When responsibility becomes harder to locate
It is tempting to draw a simple line: human decision, operator responsibility; autonomous decision, manufacturer responsibility.
The law is unlikely to be so simple. Society may not be willing to accept it either.
Even highly automated operations remain embedded in a wider system of responsibilities involving operators, manufacturers, software providers, maintenance organisations and potentially other actors. A failure involving an autonomous aircraft may therefore require examination of operational decisions, system design, software behaviour, maintenance, data and the circumstances in which the AI was deployed.
Increasing autonomy does not automatically transfer liability to the manufacturer; it makes attribution more complex.
At Level 1, identifying the role of the human decision-maker may be relatively straightforward. At Level 2, human and machine increasingly cooperate. At Level 3, the system may perform decisions and actions with decreasing opportunities for immediate human intervention.
The traditional investigation into “pilot error” therefore risks becoming only one part of a much broader inquiry: Was the operation properly designed? Was the AI system functioning as intended? Was the relevant behaviour foreseeable? Was sufficient human oversight built into the system? Was the software defective? Crucially, who controlled the source of the failure?
Product liability enters the cockpit
Directive (EU) 2024/2853 on liability for defective products adds another important element.
The Directive expressly brings software, including AI systems, within the modernised European product liability regime. For products placed on the market or put into service after 8 December 2026, a person suffering covered damage may seek compensation where the necessary elements of defect, damage and causation are established without having to prove fault on the part of the manufacturer. This is a form of strict liability designed to strengthen the protection of injured persons.
That is highly relevant to autonomous aviation.
A defect may no longer be confined to a physical component. It may also involve software, including updates or upgrades under the manufacturer’s control.
For AI-enabled drones, this broadens the legal landscape considerably.
Imagine that a detect-and-avoid system incorrectly classifies an obstacle. Or that an autonomous navigation system behaves unexpectedly following a software update. Or, more troublingly, that the system makes a decision on its own that departs from the instructions or parameters it was given.
The legal analysis would not end simply because no human made the immediate decision.
Nor, however, would manufacturer liability automatically follow merely because AI was involved. Questions of defectiveness, damage and causal connection would still have to be addressed. Or, in classical terms, causa causae est causa causati: how far back through the causal chain should responsibility extend?
This is precisely why the interaction between aviation regulation, AI governance and product liability deserves more attention.
Each framework can make sense independently but the difficulty appears where they meet.
The convergence Europe now needs
EASA’s work is an important attempt to build a bridge between AI governance and aviation safety.
NPA 2025-07 is particularly significant because EASA expressly presents it as part of the response to the AI Act and as the foundation of an AI-trustworthiness regulatory framework for aviation.
But the work is necessarily incremental.
Level 1 and Level 2 applications provide a relatively manageable starting point. Level 3 takes the discussion into much more difficult territory: advanced automation, reduced immediate human control and eventually operational concepts that challenge assumptions on which traditional aviation responsibility has been built.
Europe therefore does not necessarily need another independent layer of regulation: what it needs is convergence.
Manufacturers and operators need to understand how aviation safety requirements, AI governance obligations and product liability rules fit together in a practical compliance architecture.
Otherwise, Europe risks having highly developed aviation and AI frameworks while leaving industry to bridge the gap between them.
AI is already flying
Europe has built much of the legal architecture for unmanned aviation. It has also built a horizontal legal framework for artificial intelligence.
The next challenge is connecting them.
That challenge will become more important as AI moves from assisting remote pilots to making decisions and eventually acting without immediate human intervention.
For manufacturers, AI compliance and aviation safety must converge; for operators, automation may change rather than remove responsibility.
And for regulators, the challenge is to preserve meaningful human oversight without limiting the safety and operational benefits of AI.
The companies that understand this intersection early will be better placed to design systems, operational concepts and compliance strategies capable of surviving regulatory scrutiny, while strengthening their competitive position in the market.
Those that treat the AI Act, aviation safety and product liability as three separate legal exercises may discover that the most difficult risks lie precisely in the spaces between them.
AI is already in the air. Its legal foundations are still being built on the ground. Bridging the gap is another challenge for Europe.
As The Economist recently observed, humans transformed the wolf into the dog, gaining a companion whose capabilities complemented their own. AI may present a similar challenge: not simply how to control it, but how to benefit from capabilities that complement our own.
About the author
Dr Jose Ramirez is a Spanish business and aviation lawyer with 28 years of legal practice and a member of the Madrid Bar Association (ICAM). He holds an MBA from ESADE, a Master’s in Aviation Management and a PhD in Airport Marketing, and is currently a doctoral researcher in EU aviation competition law. He advises internationally on drone regulation, cross-border aviation law and European aerospace regulation. He can be reached at jose.ramirez@icam.es
(Image: Shutterstock/AI generated)



