AviaCert News

7 Reasons Why AI Puts Your EASA Compliance at Risk

AI tools are also increasingly being used for regulatory issues—including the analysis of EASA NPAs, AMCs/GMs, or the entire Easy Access Rules. We conducted internal tests to determine what could go wrong in this context: Our team specifically fed various AI systems regulatory documents and technical questions related to EASA and evaluated the results from a technical perspective. The following seven points are based on these practical experiences—supplemented by structural risks that extend beyond the scope of individual tests.

1. Imaginary References and Sources

AI cites AMC references, part numbers, or GMs that do not exist or are long obsolete—and can present them with the same conviction as correct content. In our practical tests, sources that do not actually exist were cited on multiple occasions. When asked, the AI either corrected the reference and concluded that the underlying guideline was fictitious. In fact, the content did exist—just in a different section of the rulebook. Manual analysis was unavoidable. In other cases, despite clear evidence to the contrary, the AI could not be dissuaded from trying to find certain content in individual guidelines that had never existed.

Without specialized knowledge, such errors go undetected. Furthermore, AI systems often simply confirm the user’s query rather than highlighting uncertainties.

2. Results that cannot be replicated

The same query does not necessarily yield the same result. Even minor changes in the wording can shift the focus and lead to different conclusions. In our practical test, the AI gradually lost sight of the original task and provided answers that no longer matched the document being analyzed—even though the content of the question had hardly changed.

For compliance applications, this means that there is no guarantee that all relevant regulations, AMC, GM, or even previously published drafts of new regulations will be fully taken into account. Without extensive expertise and detailed quality assurance, it is impossible to determine whether a response is complete.

3. Loss of regulatory context

AI often identifies requirements correctly but omits crucial contextual information. In our practical test, it was not apparent that certain requirements applied exclusively to specific operational circumstances—such as Reduced Runway Length Operations. As a result, the requirements were presented in more general terms than they actually are.

This becomes particularly critical when it comes to exceptions, transitional provisions, or special cases. These are often treated as standard cases. Anyone who works within the EASA context knows that it is not just the requirement itself that matters, but also its scope.

4. Too vague to be compliant

AI paraphrases regulatory language, thereby smoothing out precisely the nuances that matter most in an audit. What applies in the original only under certain conditions suddenly appears in the AI summary as a universally applicable requirement.

In a field test, the KI presented a new illuminated “X” marking for closed slopes as a future standard requirement. In fact, it was merely an additional option. The previous marking remains permissible. The KI had thus presented an alternative regulation as a universally applicable requirement.

Added to this is an incorrect weighting: Less relevant aspects are sometimes heavily emphasized, while safety-critical requirements do not receive the necessary attention. The result sounds complete and technically accurate—but it is not.

5. Data Leakage Due to Operator Error

Not every data breach or loss of confidential information is caused by the technology itself. Anyone who copies internal compliance documents, audit reports, or security assessments into unauthorized AI applications may unintentionally cause a data leak. Precisely because AI tools are easily accessible to everyone and deliver quick results, this risk is often underestimated. It is rarely possible to track exactly what happens to the data and sources that are entered.

For organizations in the regulated aviation sector, the following applies: In addition to technical safeguards, clear internal guidelines are needed so that employees know what information may and may not be entered into AI systems.

6. Loss of Data Sovereignty

Most common AI tools process and store data on servers outside the EU, often in the United States. Users of public AI systems partially relinquish control over the processing of the information they enter to the provider. Users often cannot determine with sufficient certainty where data is processed, how long it is stored, and who has access to it.

For government agencies and organizations subject to the GDPR, this poses a legal risk—regardless of whether training data is used or not. Before using such data, it is therefore important to determine which contractual and data protection provisions apply.

7. Lack of Clarity Regarding Liability

If an AI analysis is flawed and a compliance or security decision is made based on it, the responsibility remains with the organization. The AI assumes neither liability nor accountability for its recommendations. It is often impossible to trace how a conclusion was reached after the fact.

Especially in aviation, where regulatory misjudgments can have operational and safety-related consequences, responsibility must not be delegated to a system that bears no responsibility. AI can provide support and conduct research. The technical assessment and the final decision must rest with qualified individuals.

Would you like to know what a compliant analysis actually looks like?

AviaCert supports airport operators and aviation authorities in interpreting and efficiently applying EASA regulations—based on technical expertise, regulatory experience, and verifiable sources.

Contact

Do you have questions about one of our projects? Are you planning a similar one? We are looking forward to your call or message!

First and last name *
E-mail address *
Phone number
Your message
0
Success message!
Warning message!
Error message!