Attending the EASA AI Days 2026 at EASA headquarters in Cologne on September 9–10, I experienced firsthand how the aviation industry is reaching a decisive milestone. We have officially moved from theoretical exploration to structuring the operational regulatory framework for Artificial Intelligence.

The publication of EASA Concept Paper Proposed Issue 03 and the progress on Rulemaking Task RMT.0742 now set the ground rules. Here is an analysis of the regulatory evolutions and the updated timeline that all aviation stakeholders must anticipate.

1. Strict Alignment with the EU AI Act and Expanded Technical Scope

Integrating AI into aviation now falls directly under the European Artificial Intelligence Act (EU AI Act) framework.

  • Legal Anchor: Article 108 of the EU AI Act and Regulation (EU) 2026/1744 (Digital Omnibus) define the scope for aviation. Two regulatory routes are established: the main aviation route (Route A via Article 108) and the specific UAS route (Route B via Annex I.B.20).
  • Expanded Technical Spectrum: While initial roadmaps focused primarily on Machine Learning / Deep Learning, Concept Paper Proposed Issue 03 now encompasses:
    • Machine Learning in all its forms (supervised, unsupervised, reinforcement learning);
    • Symbolic, logic- and knowledge-based approaches (Logic- and Knowledge-Based — LKB);
    • Hybrid AI;
    • Large Language Models (LLMs), Generative AI, and Agentic AI.
  • Focus on Ground-Based Tools (On-ground): For ground operational tools, EASA highlights the major opportunity presented by RAG (Retrieval-Augmented Generation) architectures, while setting strict limitations on large COTS/LLM models.

2. Extension of Regulatory Scope: From Initial Airworthiness to All Aviation Domains

This is one of the major shifts in this new phase. Historically, EASA's oversight efforts focused narrowly on Initial Airworthiness. Today, the framework covers the entire aviation spectrum governed by the EASA Basic Regulation (Regulation (EU) 2018/1139).

Step 2 of RMT.0742 formally integrates rules applicable to:

  • Newly Added Domains: Air Operations (Air Ops), Aircrew, Air Traffic Control Officers (ATCO), and Aerodromes.
  • Consolidated Domains: Initial & Continuing Airworthiness (CAMO / Part-145), ATM/ANS, Approved Training Organisations (ATO), and Drones/UAS.

3. The "AI Trustworthiness" Framework and RMT.0742 Roadmap

Regulation revolves around Rulemaking Task RMT.0742 (AI Trustworthiness), which harmonizes cross-cutting AI requirements with existing sector-specific rules.

  • Massive Industry Consultation: The consultation for Concept Paper Proposed Issue 03 received 1,112 comments, while NPA 2025-07 (Step 1) gathered 1,494 comments from manufacturers, authorities, ANSPs, and airlines.
  • Updated Timeline:
    • Q1/2027: Final comment review and feedback loop on RMT.0742 NPA.
    • Q2/2027: Joint publication of the full set of Step 2 NPAs (covering new domains) and the final Issue 03 of the Concept Paper.
    • Q1/2028: Publication of EASA AI Roadmap 3.0.
  • Application to Approved Organisations: For software tools used by approved organisations (CAMO, Part-145, operators), EASA introduces a Functional Hazard Assessment (FHA). In the absence of an independent error-detection process, tools require formal Tool Qualification (Tool Qualification Level — TQL).

4. The New AI System Classification: From Level 0 to Level 3B

EASA now structures AI-based systems into four main levels:

  • Level 0 — Low Automation: Automated information acquisition and analysis without direct end-user interaction and without a link to decision-making.
  • Level 1 AI — Assistance to Human:
    • Level 1A: Human augmentation (perception/cognition).
    • Level 1B: Human support in decision and action selection (human retains 100% of authority).
  • Level 2 AI — Human-AI Cooperation or Collaboration:
    • Level 2A (Cooperation): Directed automated decisions and action implementation under active human monitoring and full authority.
    • Level 2B (Collaboration / Human-AI Teaming): Supervised automated decisions and actions with partial authority delegation under shared situation awareness.
  • Level 3 AI — Advanced Automation:
    • Level 3A (Safeguarded): Autonomous decisions and actions under remote reactive human supervision (upon alerting).
    • Level 3B (Non-supervised): Fully unsupervised decision and execution. Human oversight required by Article 14 of the EU AI Act is delegated to an independent Operational Oversight System.

What This Means for Your Compliance Processes

My experience at the EASA AI Days in Cologne confirmed one certainty: authorities now demand full end-to-end traceability and strict data governance for any AI application.

This is precisely the foundation upon which we built RegUp. Powered by a RAG architecture designed for Level 1B applications (decision support maintaining full human authority), RegUp guarantees complete document evidence traceability and data governance aligned with EASA expectations.

Need to demonstrate the compliance and safety of RegUp to your oversight authority? We provide a turnkey technical and regulatory justification package.