Space governance has spent years circling the wrong question. Lawyers and engineers alike ask whether autonomous systems fit inside legal categories drafted in 1967, as though the decisive issue were whether a robot on the lunar surface can be treated as an agent, instrument or extension of the launching state. That debate matters, but only up to a point. By mid-2026, the more consequential gap is not conceptual but procedural: there is still no generally accepted requirement that operators of extra-terrestrial AI assemble a structured, testable and revisable safety case before deployment and after anomalies. Space law is not empty; it is underspecified where machine agency meets delayed human control.
The distinction matters because space autonomy is no longer a futuristic edge case. Robotic systems already perform navigation, fault management, targeting of observations, planning under uncertain terrain and adaptive coordination with other subsystems. As operations move further from Earth, communication delays, intermittent links and environmental uncertainty make constant human steering impossible. In that setting, the practical failure mode is not that a machine becomes legally mysterious. It is that states authorise missions without a disciplined account of what the system may do, how its risks have been bounded, what data can reconstruct events, and what intervention remains feasible when conditions diverge from simulation.
The treaty architecture is broad but thin
The Outer Space Treaty remains the foundation. It anchors freedom of exploration, non-appropriation, international responsibility for national activities, and the duty to avoid harmful contamination and harmful interference. Article VI is especially important because it makes states internationally responsible for national activities in outer space, whether undertaken by governmental or non-governmental entities, with the latter requiring authorisation and continuing supervision. Article VII and the Liability Convention reinforce the attribution logic by attaching responsibility and liability to launching states and space objects, not to software modules or machine decision paths.
That framework still works, as far as it goes. It prevents the most obvious legal dodge: no operator can plausibly claim that an autonomous planner, rover or orbital servicing system has slipped beyond state responsibility simply because its behaviour was not individually commanded in real time. Yet the treaty architecture is notably spare on what counts as adequate supervision when a system must act independently for hours, days or longer. It says little about evidentiary thresholds for authorisation, auditability standards, software change control after launch, or disclosure duties after AI-related incidents short of physical damage.
The central governance problem is evidentiary rather than metaphysical
There is a temptation to frame extraterrestrial AI as a problem of legal personality or machine agency. That is intellectually interesting and operationally secondary. Regulators do not need to answer whether a rover “decided” in any philosophically rich sense to determine whether its conduct was acceptably bounded. What they need is evidence: a documented argument linking intended functions, operational design domain, hazard analysis, validation results, fallback behaviours, logging architecture, update procedures and human oversight constraints.
This is familiar in other high-consequence fields. Safety-critical sectors have long relied on assurance cases or safety cases: structured arguments, supported by evidence, showing that a system is acceptably safe for a given context. The technique is imperfect, and it can become performative if treated as paperwork. But it offers something that current space governance conspicuously lacks: a way to convert general legal responsibility into concrete pre-launch obligations and post-incident scrutiny.
The central governance problem is evidentiary rather than metaphysical.
Why space is harder than terrestrial AI regulation
Terrestrial AI regulation, including the EU AI Act and the OECD and NIST frameworks, is often built around controllability assumptions that weaken with distance. A regulator can require human oversight, incident reporting, logging, robustness testing and risk management. On Earth, these duties can often be satisfied through frequent updates, local intervention and continuous connectivity. Extra-terrestrial systems face another geometry of control. Latency stretches human-in-the-loop models; energy constraints limit redundancy; sensors degrade; hardware cannot be recalled; and environmental conditions exceed training data in ways that are difficult to reproduce.
Space law is not empty; it is underspecified where machine agency meets delayed human control.
That means imported terrestrial language can mislead. “Human oversight” in cislunar or Martian contexts cannot mean the same thing it means in a factory or hospital. The meaningful questions become narrower and tougher: under what conditions must the system defer action, shift to a safe state or reduce operational ambition; what information is preserved for later reconstruction; which model updates are prohibited after launch; and how much autonomy is being relied upon because of physical necessity rather than commercial convenience.
A safety case would translate Article VI into practice
Article VI’s formula of authorisation and continuing supervision is often quoted and rarely operationalised. A safety-case regime would give it content. Before launch, an operator seeking national authorisation would submit a mission-specific assurance dossier. At minimum, it would identify autonomous functions; define the environments and contingencies in which they are expected to operate; list hazards to the spacecraft, other space objects, planetary protection obligations and third parties; and set out evidence from testing, formal methods where feasible, simulation limits, and known failure modes.
Crucially, the dossier would not treat autonomy as a binary label. Navigation assistance, adaptive scheduling, collision avoidance, sample handling and multi-agent coordination create different risk profiles. A credible regime should regulate autonomy as a changing risk profile, not a binary feature. As missions evolve, software patches, retrained models, revised mission goals or degraded hardware could trigger a duty to update the safety case and, in some circumstances, obtain renewed authorisation.
What the dossier should contain
The substance matters more than the label. A workable standard would require at least seven elements. First, a precise description of the autonomous functions and their operational design domains, including environmental assumptions. Secondly, a hazard analysis that includes not only safety and mission loss, but interference with other operators and contamination risks. Thirdly, verification and validation evidence, with explicit treatment of what has not been tested and what cannot be tested realistically on Earth.
Fourthly, a control architecture that identifies escalation thresholds, safe modes, action budgets and prohibited behaviours. Fifthly, telemetry and logs sufficient for later reconstruction, recognising bandwidth limits but not using them as an excuse for opacity. Sixthly, software configuration management, especially for foundation models or adaptive planners whose performance may shift after fine-tuning. Seventhly, an incident response and disclosure plan explaining how anomalies will be classified, preserved and reported to the authorising state and, where relevant, to affected foreign operators.
- Function register: what the system can do without fresh human command.
- Boundary conditions: where the evidence no longer supports safe operation.
- Fallback logic: how the system fails safely under uncertainty, sensor loss or contradictory objectives.
- Forensic record: what data survive to explain disputed actions.
The central governance problem is evidentiary rather than metaphysical.
Registration should include autonomy-relevant metadata
The Registration Convention was not written with machine autonomy in mind, yet it offers an underused governance lever. States already maintain registries of space objects and transmit certain information to the United Nations. The standard data are basic. By 2026, a modest but significant reform would be to append autonomy-relevant metadata at national level and, where politically feasible, through international practice: the presence of mission-critical autonomous functions, categories of update authority after launch, and a point of contact for anomaly coordination.
This would not require public disclosure of sensitive code or detailed capabilities. The point is not radical transparency. It is to reduce ambiguity when an incident occurs and to strengthen the link between a registered object and the evidentiary package supporting its operation. If registration remains purely descriptive while autonomy becomes mission-critical, investigators will be left matching legal identity to technical opacity after the fact.
Planetary protection is the neglected test case
Much discussion of autonomous systems in space concentrates on collision risk or military escalation. A more revealing case is planetary protection. The Outer Space Treaty’s Article IX requires states to avoid harmful contamination of celestial bodies and adverse changes in the environment of the Earth resulting from the introduction of extraterrestrial matter. For missions involving autonomous drilling, sampling, traversal or in-situ experimentation, contamination risk may turn on machine choices made far from immediate human supervision.
Here the safety-case approach is especially useful because it forces operators to state, in advance, which behaviours are barred even if they appear locally efficient. An autonomous planner may identify a path, excavation site or sample sequence that improves scientific yield while increasing contamination risk. The governance question is whether those trade-offs were anticipated, bounded and auditable. A treaty duty framed at high level becomes meaningful only if translated into mission logic and evidentiary artefacts.
A credible regime should regulate autonomy as a changing risk profile, not a binary feature.
Liability after damage is too late
The Liability Convention remains important, but it is a poor primary tool for governing autonomous operations. Liability allocates consequences after damage; it does not by itself tell authorising states what proof to demand before launch. Nor does it cope elegantly with non-catastrophic but serious incidents: near misses, contamination scares, software-induced interference, or mission behaviour that forces another operator into costly avoidance manoeuvres without obvious physical damage.
That is why a safety-case regime should be tied not only to liability but to licensing and supervision. The real regulatory leverage sits upstream. States can require assurance evidence as a condition of authorisation, preserve power to limit software updates, mandate anomaly reporting, and inspect whether operators are maintaining the mission within its approved autonomy envelope. These are ordinary tools of administrative governance, but they have not yet been harmonised for off-world AI.
Standards should be layered, not monolithic
A credible regime should regulate autonomy as a changing risk profile, not a binary feature.
One reason the field has drifted is the search for a grand unified code for autonomous space systems. That is unrealistic. The better model is layered governance. At the top sit treaty principles and general duties of responsibility, supervision and due regard. Below that sit national licensing rules. Below that again sit technical standards, mission profiles and sector-specific guidance, borrowing from software safety, autonomy assurance and systems engineering.
Such layering is not a weakness. It allows international agreement on minimum process requirements without pretending that every mission shares the same hazards. A cislunar logistics craft, a Mars surface explorer and an orbital servicing vehicle pose different combinations of collision, contamination, cyber and interpretability risk. What should be common is the obligation to make the safety argument legible and reviewable.
The hardest question is software change after launch
The most awkward governance issue is not initial approval but adaptation over time. Spacecraft software has always been updated, but AI systems intensify the problem because performance may change in ways that are difficult to predict from patch notes alone. A post-launch update can alter the effective operational design domain, interaction between subsystems, or sensitivity to sensor anomalies. Yet some capacity to update is indispensable, especially on long-duration missions.
A workable standard would distinguish between classes of change. Minor fixes that do not affect autonomous decision boundaries could proceed under pre-approved configuration rules. Material changes to planning logic, action selection or model weights used in safety-relevant functions should trigger a revised assurance submission to the authorising state. Emergency changes would need retrospective review, with preserved evidence explaining necessity, expected impact and observed outcomes. This is less glamorous than debates about machine rights, but vastly more likely to prevent foreseeable failures.
International politics favours process over prohibition
Calls for a sweeping treaty on space AI are understandable and, in the current geopolitical climate, improbable. The politics of dual-use technology, strategic mistrust and commercial competition make substantive prohibitions hard to negotiate and harder to verify. Process obligations stand a better chance. States may disagree about acceptable levels of autonomy, but many can agree that high-risk missions should be documented, reviewed, logged and reportable.
That is also consistent with the path international governance often takes when technology outruns treaty text. Broad principles are retained; specific duties emerge through national regulation, technical standards and convergent administrative practice. The Long-term Sustainability Guidelines point in that direction, even if they do not address AI in detail. The likely route to order is incremental institutionalisation of assurance requirements rather than a sudden constitutional moment for robots in space.
What a workable standard looks like by 2026
By mid-2026, the outline of a sensible regime is visible. States remain the legal anchor under existing space law. National authorisation regimes require mission-specific AI safety cases for systems with safety-relevant or contamination-relevant autonomous functions. Registration practice expands to include limited autonomy metadata. Operators must preserve mission logs adequate for forensic reconstruction, disclose significant anomalies, and seek renewed approval for material changes to autonomous behaviour. Independent review is used where missions exceed predefined risk thresholds.
None of this resolves every dispute. It will not settle strategic competition in orbit, nor eliminate the ambiguity inherent in remote operations under severe uncertainty. But it would close the most dangerous governance gap: the ability to deploy powerful off-world autonomy without a shared evidentiary discipline. The 1967 treaty falls silent not because it lacks principles, but because it does not specify the paperwork, proofs and update rules that make those principles operational for software acting beyond immediate human reach.
That is where the next standard should begin. Not with speculative arguments over whether machines can bear obligations in space, but with a stricter demand on the humans and states that send them there: show the case, preserve the record, and update the authorisation when the system changes. In the austere environment beyond Earth, accountability will depend less on eloquent doctrine than on whether governance can travel in the form of evidence.


