No. 150 / 339
AI runs the simulations and generates the design candidates — is certification the last human-only step in aerospace/safety-critical engineering?
The shift
AI makes design-candidate generation and analysis abundant: exploring the option space, running load cases and simulations, and drafting the trade studies at near-zero marginal cost and at volumes no team could staff. It does not make legal accountability, physical-test interpretation, or judgment on failure modes with no precedent abundant — and it splits the act of deriving a design apart from the act of vouching for it, which used to be the same person's work.
The axioms
- The certifying engineer's core value is the analysis and design work — deriving load cases, running simulations, generating and narrowing candidates — rests on that cognitive work being scarce, slow, and expensive.
- Fees, timelines, and headcount scale with analysis effort — rests on analysis-hours being the real cost driver of a certification program.
- A named, licensed person signs the certification and carries personal legal liability for safety — rests on accountability being scarce (a tool can't be sued, lose a license, or answer to a board).
- Physical test interpretation grounds the analysis in reality — rests on action in the physical world, and judgment about what a test actually showed, being scarce.
- Novel failure modes need judgment where no rule or precedent applies — rests on judgment-under-novel-stakes being scarce.
- Certification is a regulatory precondition to flight/operation and legally requires a human's sign-off — rests on regulatory structure, not on engineering competence; a legal fact independent of whether the analysis is correct.
- The person who signs derived the design and its analysis, so the signature is grounded in authorship — rests on derivation and sign-off being the same act, done by the same mind.
Invalid axioms
- The engineer's core value is producing the analysis and design candidates. Exploring the option space, running the simulations, and drafting the load-case work is now abundant and cheap — a model generates and evaluates more candidates before lunch than a team used to carry through a program. The habit-trap: firms still hire, promote, and define seniority around who can produce the analysis, and juniors are still put on the analysis grind as the path to competence — when the scarce act has moved to judging and verifying that output.
- Certification cost and schedule scale with analysis effort. Pricing a program by analysis-hours assumes generating the analysis is the bottleneck. It isn't anymore. The habit-trap: fee structures and timelines still bill the modelling and simulation effort as the expensive part, so the freed time gets pocketed as margin or schedule compression rather than redirected to the verification burden that actually grew.
Unchanged axioms
- A named, licensed party carries personal legal liability for the sign-off. This is an accountability problem, not a verification one. A model can't hold a license, carry professional indemnity, be struck off, or stand in front of an accident investigation board. Until liability law and the certification framework change, someone has to actually stand behind the design — which means genuinely knowing it's right, not initialling a report.
- Physical test interpretation stays a human, physical-world act. Test-rig automation for safety-critical qualification remains low (well below ~20% by most accounts), and the harder half is interpretation: what the instrumentation actually showed, whether an anomaly is a fixture artefact or a real margin problem, whether the test even exercised the case that matters. AI can predict a test result; it can't run the coupon to failure or be the judgment that reconciles a surprising reading with the model.
- Novel failure modes need judgment, not lookup. Load paths, material behaviour, or coupling effects with no precedent are exactly where AI is weakest — no dense pattern to match, and a wrong answer arrives with the same confidence as a right one. Confidently-wrong-by-default is the worst possible failure mode when the consequence is loss of an airframe or a life. This is also the call most exposed to model progress, so calibrate it: reliability on genuinely out-of-distribution physics is improving, but the bar here is verified correctness, not plausible output, and that gap is not closing on the same curve as fluency.
- The engineer must verify the AI's work against the actual certification rules. Someone has to confirm the model ran on the right configuration, the current rule set and applicable amendments, and the correct assumptions — and that the candidate it produced actually satisfies the requirement rather than merely looking compliant. Choosing and checking those inputs is a judgment call; a wrong input yields a clean-looking, wrong result.
New axioms
- Certification is now asked to cover designs the certifier didn't derive. The signature used to rest on authorship — you vouched for what you built. When the model generates the candidate and the human signs, sign-off and derivation split apart, and "I understand this design well enough to be liable for it" quietly becomes "I checked the output of a design I didn't originate." Nobody has defined how much independent re-derivation the signature now requires.
- Verification burden per sign-off rises even as production gets cheaper. When AI can throw far more candidates and analysis at the certifier, the human's task shifts from producing the case to interrogating a large volume of generated work for the errors that matter — a harder, easier-to-do-badly task. The one real margin problem can hide inside hundreds of plausible outputs, and the sign-off process hasn't been rebuilt around auditing volume rather than authoring it.
- Juniors aren't learning the analysis that qualifies a future certifier. The grind that AI now absorbs — hand-deriving load cases, sitting with the simulation until the physics is intuitive — was also how an engineer earned the judgment to eventually sign. Remove the rung and you keep today's certifiers productive while starving the pipeline of the people who can verify novel work in fifteen years. This one compounds silently; the cost shows up a career later.
Where it breaks
Firms are already banking the cheap-analysis dividend — pricing and staffing as if producing the case is still the expensive part (INVALID #1 and #2) — while the signature legally still means a named human is liable for a design being right (STILL HOLDS #1). The scope of what that human actually did to earn the signature is shrinking toward "reviewed the model's output" precisely as the design being signed is one they no longer derived (NEW #1), and nobody has settled how much independent re-derivation "reasonable" sign-off now demands. That gap is invisible until an accident investigation deposes the real scope of the human review.
The slower collision: AI absorbing the analysis grind (INVALID #1) removes the apprenticeship that produced people able to exercise novel-failure judgment (STILL HOLDS #3) and verify volume (NEW #3). The field is optimising away the training ground for the one role it agrees must stay human.
Related axioms
Other axioms
Architecture
What changes for architecture with AI?
Product Management
Is "customer empathy" still a PM's job when AI can summarize every support ticket and call transcript?
Marketing
What changes for marketing and advertising with AI?
HR
What changes for HR with AI?
Research
What changes for scientific research with AI?
Healthcare
If AI refraction and retinal-scan reads produce the prescription and the screening, is the in-person optometrist the gatekeeper or just the legal signer?