As uncrewed aviation becomes increasingly dependent on shared digital position, global navigation satellite system (GNSS) degradation can propagate far beyond navigation — affecting containment, conformance, human decision-making and ultimately the trust on which digital airspace is built, writes Manuel Ignacio Pérez Pan
A complete loss of GNSS is comparatively easy to understand. The navigation solution disappears, the aircraft generates an alert, and the remote crew recognises that a capability has been lost. The consequences may be serious, particularly during beyond visual line of sight (BVLOS) flight, but the situation itself is clear: something that was available is no longer available, and the crew should transition into the degraded-navigation or contingency procedure defined before departure.
The more difficult case begins when very little appears to have failed. Latitude and longitude are still available. Ground speed looks plausible. The aircraft icon continues moving smoothly across the control-station map. The flight-control system still has a navigation solution, the aircraft appears to remain inside its expected operational volume, and connected services may continue receiving position information. To the remote pilot, the operation may look normal. Yet the position may no longer represent reality.
That distinction between position unavailable and position available but untrustworthy deserves more attention as BVLOS operations scale. The European Union Aviation Safety Agency (EASA) distinguishes jamming, which can deny or degrade GNSS reception, from spoofing, where counterfeit signals can induce erroneous positioning, navigation or timing information. In July 2026, EASA issued Revision 4 of Safety Information Bulletin 2022-02 after analysing recent occurrences. Earlier that year, EASA and EUROCONTROL published a European action plan aimed at improving resilience, while ICAO’s current roadmap includes complementary position, navigation, timing (PNT) and independent timing sources.
For uncrewed aviation, however, there is an additional complication: aircraft position is increasingly useful to systems outside the aircraft.
For years, GNSS in UAS operations was discussed mainly as a navigation capability. Could the aircraft follow the route, hold position, return home or remain inside a programmed boundary? Those questions still matter, but they no longer describe the entire dependency. In a contemporary BVLOS architecture, position can support flight control, containment, contingency behaviour, sensor georeferencing and the remote pilot’s situational awareness. Some representation of that position may also reach identification, monitoring or traffic-management functions. GNSS is then providing information from which other systems and people may make safety decisions.
The European U-space framework makes this visible. Commission Implementing Regulation (EU) 2021/664 requires network identification to include information such as UAS position, altitude, course, ground speed, emergency status and message time. That architecture is logical; scalable digital airspace cannot work if participants have no dependable way to represent where aircraft are. But it also raises a question that sounds simple until it is placed inside a safety case: what happens when the position being shared is wrong?
The important word is wrong, not missing. When position data disappears, systems can often detect the absence through a timeout, stale track or lost-data indication. A plausible but incorrect position is different because information continues to arrive in the form receiving systems expect. Silence is observable; misplaced confidence can look normal. A system that reports no position forces the operator and automation to confront uncertainty. A precise but incorrect position can hide uncertainty behind apparent precision.
In BVLOS, that has a direct human-factors consequence. The remote pilot usually does not perceive the aircraft’s geographical position through direct observation. Instead, position is mediated by instruments: a map, an aircraft symbol, latitude and longitude, altitude, track, velocity, route lines and containment boundaries. Those elements create the pilot’s mental model of the flight. If the underlying position becomes unreliable while the interface remains authoritative, the pilot’s understanding can become wrong without immediately feeling wrong.
Apparently redundant architectures deserve scrutiny. Imagine the ground control station shows the aircraft following the intended trajectory. A second tracking interface displays the same position. The flight controller reports no route deviation. A UTM interface also shows the operation inside its expected volume. Four systems appear to agree. Yet the systems-safety question is not whether the displays agree; it is whether they reached their conclusions independently. If all four depend on the same onboard position solution, the apparent redundancy may be weaker than it looks.
Several displays of one coordinate do not necessarily constitute several independent position sources. They may simply be several displays of the same error.
This distinction between duplication and independence is familiar in aviation safety engineering, but connected UAS architectures can hide shared dependencies. Two processors may be separate while consuming the same navigation estimate. Two GNSS receivers may protect against hardware failure while remaining exposed to the same radio-frequency environment. A flight-control computer and a UTM service may use different software while relying on position information from the same onboard source. The relevant question is not how many systems are installed, but how many independent means exist to establish whether the aircraft’s position remains credible.
That becomes especially important when moving from navigation into traffic management. The FAA’s UTM concept is built around a cooperative ecosystem in which operators, service suppliers and government systems exchange information to support complex low-altitude operations, including BVLOS. Information exchange makes the architecture scalable, but also creates a dependency on information quality. A conflict-management system can calculate correctly and still reach an operationally wrong conclusion if the state information entering the calculation does not reflect physical reality.
Consider two BVLOS aircraft operating on strategically deconflicted trajectories. Their planned volumes do not overlap. Now imagine one aircraft begins moving away from its route. If the reported position shows the deviation, conformance monitoring may identify that the operation is no longer nominal. NASA has studied this through Conformance Monitoring for Situational Awareness, examining how reported positions can complement strategic deconfliction when aircraft become contingent. Now change one assumption: the aircraft physically departs the expected trajectory, but its reported position still shows it inside. The flight-control system may believe the vehicle is conforming, the remote pilot may see the same apparent conformance, and a traffic-management service may reach the same conclusion. The algorithms need not have failed; the system may simply be reasoning from an incorrect premise.
This is why accuracy alone is not enough. Accuracy asks how close an estimated position is to reality. Integrity addresses whether the information can be trusted for the intended operation and whether the system can warn when that trust can no longer be assured. For BVLOS, the distinction is fundamental. An aircraft with increased position uncertainty is not perfectly represented by a point on a map; its possible physical location occupies an area that grows as confidence decreases. Navigation integrity engineering already deals with protection levels. The question for UTM is how much of that uncertainty should propagate into traffic-management decisions.
The same dependency appears in geographical containment and contingency procedures. A geofence compares estimated aircraft position with a defined boundary. The boundary may be correct and the software may execute correctly, yet if the position does not correspond closely enough to physical reality, successful logic does not necessarily mean successful containment. Return-to-home, a recovery waypoint, a holding area or a flight-termination volume are geographical responses. They can be excellent responses to command and control (C2) degradation when navigation remains trustworthy. But if the initiating problem concerns the position solution itself, the contingency may depend on information whose integrity is in question.
A procedure is not a safety barrier merely because it is automatic. It remains a barrier only while the assumptions required to execute it remain valid.
That changes contingency analysis. It is not enough to ask what procedure follows a failure; we should also ask what capabilities that procedure assumes. If C2 loss triggers an autonomous route, what navigation performance is assumed? If GNSS confidence deteriorates, what independent information remains? If uncertainty grows beyond containment margins, what prevents a new air or ground risk? These questions are why “add another GNSS receiver” is not a complete resilience strategy. Multiple frequencies, constellations, inertial integration, authentication and alternative navigation technologies add value, but address different failure mechanisms. ICAO’s roadmap frames resilience more broadly through complementary PNT and independent timing.
For the remote pilot, GNSS should not always be understood as a simple healthy-or-failed state. Navigation can remain available with reduced performance. Independent sources may disagree. Inertial propagation may preserve continuity while uncertainty grows. Spoofing may be suspected without being confirmed. A position can remain available while no longer supporting required margins. Those states are different, and the pilot needs to understand what capability remains and which decisions are still supported by it.
Automation can help by cross-checking sensors and detecting inconsistencies quickly, but it can also make a degraded condition look deceptively calm. Attitude may remain stable, propulsion normal and the C2 link healthy while the aircraft follows a trajectory based on an erroneous estimate of its position. Stable flight is not necessarily correct flight.
The implication is that unmanned aviation may need to move from navigation resilience toward information resilience. Navigation resilience asks whether the aircraft can continue safely when a positioning source deteriorates. Information resilience asks whether the operational chain can recognise that deterioration and prevent uncertain information from becoming the basis for later decisions. That chain can include sensor measurement, navigation estimate, flight-control logic, remote-pilot display, network transmission, UTM interpretation and a human or automated decision. Every component may function according to design while the conclusion remains wrong because the original positional assumption was wrong. A navigation error can become a containment error, then a conformance error, and ultimately distort traffic awareness.
This suggests that future UTM may eventually need a degraded mode of its own. What happens when an aircraft continues transmitting position but can no longer demonstrate that it meets the confidence required for normal operations? Should the flight become contingent? Should an uncertainty region replace the nominal point for conflict calculations? Should nearby operators receive an indication that confidence has deteriorated? There will not be one universal answer, and overly conservative responses could reduce capacity. But the distinction remains important: position received and position sufficiently trustworthy for the intended safety function are not equivalent states.
Perhaps the most useful principle is that position should not automatically be treated as truth; it should be treated as evidence. Evidence has a source, an age, a quality and an uncertainty. It can be independently corroborated, contradicted or become stale.
Imagine a future U-space environment with many simultaneous operations. Flights are authorised, strategic conflicts removed, conformance monitoring active and traffic information flowing. The algorithms work correctly and the networks are available. Now imagine one aircraft begins transmitting a plausible but incorrect position. The aircraft may believe it. Its automation may believe it. The remote pilot may believe it. The containment function may believe it. A traffic-management service may believe it, and other operators may act on it.
The question may no longer be whether the aircraft detects its own navigation anomaly. It may be something more uncomfortable:
How long will the rest of the system continue believing it?
That is where GNSS degradation becomes a human-factors, containment, conformance, traffic-management and system-safety problem. Safe BVLOS may depend on knowing when position is no longer certain.
References
European Union Aviation Safety Agency (EASA). Safety Information Bulletin 2022-02R4 — Global Navigation Satellite System Outage and Alterations Leading to Communication / Navigation / Surveillance Degradation, Revision 4, corrected 22 July 2026. The SIB addresses current jamming and spoofing risks and associated operational, airworthiness and ATM/ANS considerations.
European Union Aviation Safety Agency (EASA). Global Navigation Satellite System (GNSS) Outages and Alterations. EASA describes jamming and spoofing and lists observed operational symptoms, including navigation discrepancies, time shifts, abnormal speed relationships, spurious TAWS alerts and hybrid GNSS/IRS deviations.
EASA and EUROCONTROL. European Aviation Action Plan for Ensuring Safe Operations during GNSS Interferences, Version 1.0, March 2026. The plan addresses immediate operational mitigation and longer-term GNSS robustness and complementary positioning and timing capability.
International Civil Aviation Organization (ICAO). Global Navigation Satellite System (GNSS) Manual — Doc 9849, Fifth Edition, 2025. The fifth edition includes new material on dual-frequency multi-constellation GNSS, performance monitoring and RFI detection and mitigation.
International Civil Aviation Organization (ICAO). GNSS RFI Roadmap. ICAO’s programme covers short-, medium- and long-term measures intended to improve aviation resilience to radio-frequency interference, including complementary PNT and independent timing sources.
European Commission. Commission Implementing Regulation (EU) 2021/664 on a regulatory framework for U-space. Article 8 specifies network-identification information including UAS position, altitude, course, speed, emergency status and message time; Article 11 addresses traffic information.
Federal Aviation Administration. UAS Traffic Management Concept of Operations, Version 2.0. FAA UTM material describes the cooperative information-service architecture developed to support scalable low-altitude unmanned operations.
Kuo, V. H., et al., NASA. Safety Assessment of Conformance Monitoring for Situational Awareness in UTM Operations, NASA Technical Reports Server, 2024. The study evaluates strategic deconfliction combined with CMSA for mixed conforming and contingent UAS traffic.
(Image: Shutterstock AI)



