4 Takeaways: Autonomous Systems Are Driving New Approaches to Space Regulation
Autonomous decision making is becoming a routine part of spacecraft operations, from collision avoidance to onboard responses that occur faster than any human review cycle. As missions grow more complex and operators rely more heavily on algorithmic judgment, long-standing legal assumptions about supervision, liability and system authorization are being reexamined. The shift is forcing governments and commercial operators to interpret existing treaties in ways that reflect a new operational reality.
Read our top four takeaways from our conversation with IURUS Consulting Founder and Director Jesús Bernal Allende, or listen to the full episode.
Takeaway 1: Existing space law contains structural gaps that autonomy is making harder to ignore.
The current legal framework was built for a world where human oversight was continuous and spacecraft acted only as commanded, Bernal Allende noted.
“Right now, the law only knows two categories, a tool or a legal person. An autonomous system that makes its own operational calls doesn’t fit either box,” Bernal Allende said.
At the same time, Article VI of the Outer Space Treaty requires states to maintain continuing supervision of national space activities. The provision assumes humans are able to oversee decisions as they occur – a premise that does not hold when thousands of satellites act independently faster than any operator can review, he said.
Liability also becomes harder to parse once private operators and autonomous subsystems contribute to the same incident, Bernal Allende noted.
“The liability convention runs through states and that framework still holds. But once you have private operators and autonomous subsystems all contributing to the same incident, the chain of causation, the law was built to trace just breaks down,” he said.
Space law was also designed to address individual incidents, not cumulative orbital debris or cascading conjunction risks across entire constellations, he added.
The gaps are not errors, Bernal Allende noted, but they reflect a framework designed for earlier mission profiles and now strained by modern operating tempos.
Takeaway 2: Autonomy does not change how liability attaches, but it changes where the legal analysis begins.
If an autonomous system acts without a direct command, how does the law let us respond to or use that information?
“Here’s the part that surprises people – it doesn’t matter,” Bernal Allende said. “Legally, it makes zero difference whether a human pushed the button or an algorithm made the call. Under the Outer Space Treaty and the Liability Convention, responsibility attaches to the activity and to the space object, not to whatever decided to move it.”
Strict liability concerns only whether damage occurred, he said. Fault-based liability shifts the inquiry to design, deployment and supervision.
The absence of a human command does not remove the human from the analysis. It moves responsibility earlier in the operational timeline, to decisions made during development and system integration, he said.
“The way I evaluate this is through what I call functional intentionality. You look at what the system was optimized to do, not its intent in any moral sense,” Bernal Allende said. “Could the operator have anticipated this outcome knowing how the system was designed? That’s the question that actually holds up in court.”
Takeaway 3: Assigning responsibility will require layered accountability supported by defensible evidence standards.
Modern incidents are likely to involve multiple operators and autonomous subsystems, making single-party fault attribution unreliable, Bernal Allende noted. “The instinct is to find one responsible party and assign the blame. That instinct breaks down fast when you have multiple autonomous systems, multiple operators and multiple jurisdictions all contributing to the same incident.”
Bernal Allende outlined a five-layer accountability architecture designed to match responsibility to the part of the problem each actor created:
The first layer is a guarantee fund tied to the system itself that pays out automatically for demonstrated harm. Compensation does not wait for fault to be assigned. The second layer is the operator responsible for supervision and maintenance. The third addresses the designer and any mismatch between advertised and actual capabilities. The fourth layer involves the certifier whose approval carries weight if it was granted in error. The fifth layer is the regulatory framework when standards were inadequate given known conditions.
“The point of the architecture is proportionality, not punishment. Each layer absorbed the part of the problem it actually created,” Bernal Allende said.
Takeaway 4: Licensing and oversight are shifting from mission-based approvals to architecture-based authorization.
Regulators are beginning to evaluate spacecraft based on whether their architectures can safely manage autonomous operations, Bernal Allende said.
“The old model was: Describe your mission, get a license, operate accordingly. The new model asks a different question: Does your system have the architecture to handle what is actually going to encounter? Can it make safe decisions autonomously when it has to? That shift changes what you have to demonstrate to get authorized in the first place,” he said.
Bernal Allende pointed to the FCC’s 2024 orbital debris order, which incorporates autonomous collision avoidance capability into end-of-life requirements. He noted that regulators are not waiting for treaty revisions. They are updating operational standards through rulemaking.
The role of human oversight is also changing, Bernal Allende said. Human supervision is constrained by communication latency and rapid decision cycles. As a result, operators need to embed safeguards and constraints in system design and preserve detailed logs for later review.
“Oversight has to stop being about the moment when there’s no human-in-the-loop, the supervision has to happen before the decision and in the record it leaves behind,” he said.
“Conflicts between autonomous systems operating under different frameworks are going to happen. Deliberation mechanisms give you a structured way to resolve them before the conflict becomes an incident,” he said.
Conflicts between autonomous systems operating under different frameworks are inevitable, but proactive measures such as structured communication processes and technical records allow for traceability and resolving cross-architecture conflicts before they become unmanageable, Bernal Allende said.
“Without traceability, there’s no accountability. Without accountability, there’s no trust,” he said. “You want that plumbing in place before the incident that makes it unavoidable, not after.”