The Authority Map for AI in Mission Operations
The action layer behind the core verdict: how to give AI a bounded, preauthorized job in the loop without granting authority the assurance case cannot carry.
Use this as a screen for any AI claim in mission operations, flight or ground. The question is never whether the model is impressive. The question is what authority the function holds: what it may decide, what it may command, who owns the exception, which deterministic safeguard bounds it, and how the operation reverses it. Authority design comes first; model selection is downstream. Every deployed case in the ledger below earned its place that way.
First moves before any AI function holds authority
For each proposed AI function, write down the input, the decision, the permitted action, the prohibited action, the escalation owner, the deterministic safeguard, and the reversal path. Separate detection, recommendation, scheduling, and command authority; most autonomy arguments dissolve once those four are separated.
Telemetry prioritization, science-data triage, contact and activity scheduling, and nominal health monitoring match the strongest deployed evidence: AEGIS target selection, the Perseverance onboard planner, TECO scheduling, and console anomaly alerts. Leave novel, coupled, or hazardous conditions on the human side of the map.
Score the function on false alarms, missing data, configuration drift, conflicting constraints, degraded communications, operator override, and reconstruction after an event. Nominal accuracy alone proves a demo, not an operating capability.
Require requirements traceability, versioned data and model inputs, operations-like simulation, shadow operation, named shift procedures, and a rollback plan before changing authority or staffing. Hubble ran eight months of 24x7 shadow operations and anomaly simulations before cutting to 8x5.
For any function that can cause, or fail to prevent, a catastrophic hazard or an abort, start from the applicable human-rating and safety requirements: fault tolerance, recovery, situational awareness, configuration control, crew override. A generic AI governance review is not a substitute, and a model score is not a safety case.
Owner, briefing, proof
Owner
A named operating owner for each AI function's authority envelope, accountable for the escalation path, the deterministic safeguards, the shadow-operation record, and the decision to suspend or roll back.
Briefing
A routine-use / demonstration / claim decision brief per capability, so a one-mission demo or a contractor-reported metric never buys the authority that only routine, verified operational use has earned.
Proof
The trail from telemetry to alert to decision to authorized action to verified outcome, plus off-nominal test results and shadow-operation records, rather than model accuracy scores.
Start with owner, briefing, and proof for one system and one play. If the gap is material, widen to a readiness look across the operation's monitoring, scheduling, and command loops, and build the operating machinery only when the operator wants it run.
Claim ledger
Three boundaries hold after verification. Telemetry-model accuracy does not establish autonomous diagnosis or recovery authority: the KETTY prototype produced too many false alarms on real telemetry, and the strongest recent metrics are contractor-reported rather than independent. Workload, staffing, and savings figures, including the 90% number, are agency program-reported results, not generalizable ROI. And the most detailed human-rating language comes from a superseded document; formal compliance work starts from the current authorities.
- A human-rated program publicly certifies an AI or adaptive system for a crew-critical control, recovery, abort, or hazard-mitigation function.
- A mission publishes multi-year, independently assessed evidence of an AI system autonomously diagnosing and resolving anomalies, beyond alerting, recommending, or executing preauthorized procedures.
- NASA or another spaceflight authority issues binding AI-specific assurance, configuration-control, or human-rating requirements for adaptive systems.
- An operational incident or postmortem attributes mission harm, loss of control, or averted harm to AI-assisted mission operations.
- A follow-on AEGIS, Perseverance-planner, or station and ground-operations evaluation publishes before-and-after workload, safety, or science-return results with methods and limits.