Statement
AI may change specialist workloads and the speed of learning, but every safety-critical function must remain safe and operable when every generative model is unavailable, compromised, stale, or intentionally isolated.
Evidence dimensions
- Basis
- normative
- Readiness
- early research
- Confidence
- supported
Assessment rationale
Current AI risk and generative-AI guidance identifies useful human-AI configurations alongside confabulation, information-integrity, privacy, security, and overreliance risks. NASA software assurance establishes an evidence discipline for safety-critical software. Requiring safe AI-off operation is a GShips resilience boundary; the cited sources do not demonstrate it across a closed habitat or generations.
Citations and locators
- Artificial Intelligence Risk Management Framework (AI RMF 1.0) (opens external site in a new tab)
Sections 3 and 4 on AI risks, trustworthy characteristics, human-AI interaction, and the Govern, Map, Measure, and Manage functions. · direct normative authority - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (opens external site in a new tab)
Confabulation, human-AI configuration, information integrity, data privacy, value-chain risk, measurement, incident, and disclosure sections. · direct normative authority - Software Assurance and Software Safety Standard (opens external site in a new tab)
Sections 1 through 4 and requirements mapping on lifecycle software assurance, software safety, objective evidence, security, independence, IV&V, maintenance, and retirement. · direct method
Assumptions and limits
The assessment applies to this bounded statement and the cited source scopes. A source can support one relationship without validating a generation ship, and an editorial grade does not substitute for independent review or representative demonstration.
What would change this conclusion?
Representative long-duration trials showing that safety-critical functions remain equally or more reliable when they depend on a generative model, including model loss, compromise, staleness, runtime failure, and succession of operators, could narrow this boundary. Evidence of unsafe AI-off workload would require redesign rather than silent dependence.
Editorial record
- Prepared by: GShips Project
- Last reviewed: 2026-07-25
- Review status: substantive editorial review
- Reviewer: GShips Project editorial synthesis
- Independent review: pending two person required
- Conflicts: Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
- High-consequence domains: ai-autonomy, cybersecurity, life-support-continuity, human-factors