Trustworthy by Design
What EASA’s Proposed Issue 03 Tells Us About Building AI the Training Community Can Defend
By Cedric Paillard, CEO, Amris Aviation (previously The Airline Pilot Club)
A 239-Page Signal the Training World Should Not Miss
In June 2026, the European Union Aviation Safety Agency released the proposed Issue 03 of its Concept Paper, “Guidance for safety-related artificial intelligence applications.” It is not light reading: 239 pages of objectives, anticipated means of compliance, and use cases. But buried in its density is one of the clearest statements any regulator has yet made about how artificial intelligence will be permitted to enter the safety-critical heart of aviation. For anyone building or buying AI in this industry, it is the most important document of the year.
https://www.easa.europa.eu/en/downloads/143701/en
Issue 03 follows the March 2024 paper on Level 1 and 2 machine-learning applications, and it widens the lens dramatically. It now spans four levels of automation — from Level 0 (“low automation”) through Level 1 (“assistance to human”), Level 2 (“human–AI cooperation and collaboration”) and Level 3 (“advanced automation”) — and it explicitly extends beyond machine learning to logic- and knowledge-based (symbolic) AI, hybrid AI, and, notably, generative AI and large language models. It is positioned as a reference for Phase II of the EASA AI Roadmap 2.0, ahead of formal rulemaking under task RMT.0742, and it is bound by Article 108 of the EU AI Act to stay aligned with the Act’s requirements.
Here is the part the training community should sit up for: the paper is written almost entirely in the language of airworthiness, flight operations, and air traffic management. Its use cases are visual landing guidance, auto-taxi, trajectory prediction. Pilot competency assessment — the domain where AI is arguably being adopted fastest and with the least scrutiny — is barely mentioned. That silence is not a reprieve. It is a question waiting to be answered.
If a regulator is prepared to hold an auto-taxi system to a learning-assurance standard, why would the AI shaping a pilot’s competency record be held to anything less?
Four Building Blocks, One Underlying Demand: Evidence
EASA’s framework rests on four “building blocks” of trustworthy AI. Trustworthiness analysis comes first and is always required — a characterisation of the application together with safety/risk, security, and ethics-based assessments. It acts, in EASA’s words, as “a gate to the three other technical building blocks.” Those three are AI assurance (including the new concept of learning assurance), human-centred design for AI, and safety risk mitigation for advanced automation.
Two design choices in that structure matter enormously. The first is proportionality: only the trustworthiness analysis must be applied in full to every application; the depth of the other blocks flexes with the system’s classification and criticality. The second is candour. EASA concedes that for learning and knowledge-based systems, trustworthiness “cannot converge towards exhaustive verification coverage, but rather towards bounded and managed uncertainty.” That is a regulator admitting, in print, that AI cannot be proven correct the way a hydraulic line can — only managed within defined limits. Everything else in the paper follows from that admission.
This connects directly to a theme we explored earlier this year in “Governance-First AI in Aviation Training,” where we argued, following the enterprise-AI analysis of strategist Aliya Nur Babul, that the organisations which succeed with AI are those that treat it as accountable infrastructure rather than an experimental side project. EASA has now, in effect, codified that instinct for aviation. The supervision tax, the rework spiral, and the governance reckoning that Babul described are precisely the failure modes Issue 03 is engineered to prevent — not through slogans, but through objectives an applicant must evidence.
Where the Paper Is Strong — and Where Training AI Falls Through the Gap
The single most consequential idea for our field is learning assurance. Traditional development assurance verifies that code does what its requirements say. But an AI system, as the EU AI Act defines it, infers outputs rather than executing pre-written rules. So assurance, EASA argues, must shift to the “correctness, completeness and representativeness of the data, scenarios, or knowledge bases used during development,” and must demonstrate that models “generalise well on unseen operational data and remain robust under foreseeable conditions.”
Read that against how competency-assessment AI is often built and sold. A model trained on one fleet’s grading history, one operator’s instructor culture, one region’s phraseology — and then offered as a general tool. EASA’s data-representativeness objective is a direct challenge to that practice. An assessment model whose training data does not cover the operational design domain it is deployed into is, by this standard, unassured. The discipline EASA demands for a vision system landing an aircraft is the same discipline that should govern an algorithm influencing whether a pilot is judged competent.
The paper is equally sharp on the human layer. Its human-centred design block introduces “operational explainability” — the obligation to give end users understandable, reliable, and relevant information, at the right level of detail and the right time, about how an AI system reaches its results. It develops the concepts of human–AI cooperation and, at Level 2B, human–AI teaming, where partial authority is released to the system but the human remains predominantly responsible and a formal responsibility-scheme assessment is required. This is the regulator drawing, with care, the line between a tool that assists a human and a system that acts in concert with one.
And then there is the warning almost nobody is talking about. In its provisions for organisations, EASA requires competence and awareness training for everyone in the chain — designers to end users — and explicitly names two threats the syllabus must address: “the risk of overreliance on the AI-based system” and “the risk of de-skilling of end users.” Overreliance and de-skilling are not abstract IT risks. In a training department they are competency drift by another name — the slow erosion of the very judgment the system was meant to support. A regulator has now made guarding against them an organisational obligation.
A Necessary Tension: Ambition Versus the State of the Art
It would be easy to read Issue 03 as a green light. It is more honest to read it as a carefully hedged one, and here it is worth pushing back on the document on its own terms. EASA itself cautions that “the current AI technology may not be at a level commensurate with the perspective opened by some of the objectives,” and its own limitations table flags where means of compliance simply do not yet exist. The paper sketches a future of remote and delegated oversight for Level 3 automation that today’s technology cannot fully assure. The objectives are aspirational by design; the capability is not yet there to meet all of them.
That gap creates a real hazard for buyers, and it is one the paper does not dwell on. A vendor can wrap a product in the vocabulary of Issue 03 — “trustworthy,” “explainable,” “human-in-the-loop” — long before it can produce the evidence those words are supposed to stand for. The framework is a checklist of objectives, not a seal of approval. Until RMT.0742 delivers binding means of compliance, the burden of telling genuine assurance from assurance theatre falls on the operator. We would gently contest, too, the paper’s centre of gravity: by anchoring its examples in airborne and ATM systems, it implicitly treats ground-based training intelligence as lower-stakes. We think that is the wrong instinct. A flawed landing system fails one approach; a flawed competency model can quietly distort an airline’s entire picture of who is fit to fly.
The other tension worth naming is the net safety benefit concept, one of the genuinely new ideas in Issue 03. Borrowing from Certification Memorandum CM-SA-001, EASA proposes that an AI system demonstrated to deliver an operational safety benefit — with no degradation to existing requirements — could earn a one-level reduction in its assurance level, adjudicated by a dedicated EASA governance and decision board (though never below a floor, and never for catastrophic failure conditions). It is a thoughtful way to stop safety-enhancing technology from being penalised by conservative certification. But it places enormous weight on a qualitative judgment of “benefit.” In training, the temptation will be to dress up efficiency claims — less paperwork, faster turnarounds — as safety benefit. They are not the same thing, and the industry should be disciplined about the difference.
Building to the Standard: What “Trustworthy by Design” Looks Like in Practice
The constructive answer to all of this is not to wait for RMT.0742. It is to build, now, to the spirit of the four building blocks — and to be able to show the evidence. This is the philosophy behind the Amris Competency Management System (previously Amelia AI), developed within the Amris Aviation ecosystem, and the reason we have argued consistently that competency intelligence must be governance-first from inception rather than retrofitted later.
Start with EASA’s firmest line: the human decides. Issue 03 reserves its heaviest assurance for systems that take authority away from people. The Amris Competency Management System deliberately sits at the assistance-to-human end of the scale. Its ORCA workflow — Observe, Record, Classify, Assess — keeps the instructor as the source of truth at every stage. The instructor observes pilot behaviour, records it, classifies it against ICAO-aligned competency baselines, and makes the assessment. The platform’s role is to structure, validate, and persist that judgment, not to supplant it. In EASA’s terms, that is a Level 1 design choice, and it is a choice — one that keeps the responsibility scheme exactly where forty years of crew-resource-management thinking says it belongs.
On learning assurance, the discipline is data provenance. Every observation in the Amris system carries an origin: who recorded it, when, against which Observable Behaviour, in what training context. That is the raw material EASA’s data-correctness and representativeness objectives demand, and it is what makes an assessment defensible rather than merely produced. Where a model surfaces a longitudinal pattern — competency drift across a series of sessions — it surfaces a signal for an instructor to interpret in context, not an autonomous verdict. The system provides the signal; the human provides the judgment. That is the difference between decision-grade evidence and a black box.
On operational explainability and human-centred design, the test EASA sets is whether an end user can understand, at the right moment and the right depth, how a result was reached. A competency tool meets that test when an instructor can trace any grade back to the behaviour that earned it and the framework it maps to — and when a review board, a regulator, or the pilot themselves can follow the same trail. Explainability, in other words, is not a feature bolted on for compliance; it is what audit-ready evidence looks like when it is built correctly.
And on the threat EASA names directly — overreliance and de-skilling — the response is the one our whole ecosystem is organised around: mentorship. A system designed to make instructor judgment more visible and better calibrated, rather than to replace it, is a system that builds competence instead of quietly eroding it. The competence and awareness training EASA now expects of organisations is not a burden to us; it is the core of what Amris® Academy does. This is the through-line from our earlier work on adaptive learning paths and EASA certification: the regulator’s direction of travel and a competency-first philosophy point the same way.
The Window Is Open — Literally
There is a practical detail in this release that deserves a closing word. Issue 03 is a proposed issue, and it ships with a Comment-Response Document — a structured form inviting the industry to submit substantive comments and objections before the guidance is finalised. That form, in the version circulated, is still largely blank. The training community has a rare opportunity to put competency-assessment AI on the regulator’s map before the rules harden, rather than after. This is not a distant prospect for us: Amris has taken part in that conversation directly, contributing to the industry input provided to EASA on artificial intelligence through the ATPG Group. Silence now is a decision to be governed by a framework written for someone else’s use cases.
For training department heads, chief pilots, and heads of recruitment, the questions Issue 03 forces are worth asking of every AI tool already in your building. Can the vendor show you the data their model was trained on, and prove it represents your operation? Can an instructor explain any output the system produces? Where does authority sit — and who is responsible when the model is wrong? And does the tool guard against overreliance, or quietly encourage it? These are EASA’s questions now, not just ours.
The arrival of a serious regulatory framework is not a constraint on good AI in aviation. It is the moment good AI is finally distinguishable from the rest. The organisations that thrive will be the ones that were already building to the standard — treating trustworthiness, evidence, and human judgment not as compliance overhead but as the whole point. At Amris, that is the only way we have ever known how to build.
Amris® Aviation — raising the standard in aviation performance. Learn more https://www.amrisaviation.com
Source: EASA Concept Paper — Guidance for safety-related artificial intelligence applications, Proposed Issue 03 (June 2026), and its accompanying Comment-Response Document. Related Amris/APC articles: “Governance-First AI in Aviation Training” (March 2026) and “EASA Certification of Adaptive Learning Paths in Aviation Training.”
