Sat Aug 01

Retrofitting Autonomy Into Certified Freighters Changes the Buyer's Question

Merlin and IAI's push to certify autonomous flight systems on existing Part 25 cargo airframes shifts the compliance question from airworthiness to operational assurance.

A cargo freighter aircraft on the tarmac with its avionics bay open for inspection, cockpit lit with a faint blue data overlay.

Retrofitting Autonomy Into Certified Freighters Changes the Buyer’s Question

Merlin’s memorandum of understanding with Israel Aerospace Industries to jointly develop and certify autonomous flight technology for Part 25 cargo aircraft is not a clean-sheet autonomy program. It is a retrofit play, aimed at freighter conversions where the base airframe already holds a type certificate (AINonline). That distinction matters more than the headline suggests, because it changes the certification math facing anyone who leases, insures, or operates these aircraft.

A clean-sheet autonomous aircraft forces regulators to build a certification basis from first principles. A retrofit runs through a supplemental type certificate process, where the autonomy system is evaluated as a major modification to an aircraft that is otherwise already flying safely today. That path is faster to market. It is also less legible, because the safety case has to isolate what changed, the autonomy stack, from what didn’t, the certified airframe and systems around it.

This is precisely the seam that current certification frameworks are still working out. Research on airborne machine learning walks through both the EASA process and the FAA’s Overarching Properties approach, and flags that existing certification processes were not built with learning-based systems in mind at the safety, system, software, and hardware levels (Frontiers). Applying that apparatus to a retrofit, where the autonomy sits inside an aircraft that already has decades of service history, is a narrower and more commercially urgent version of the same problem.

For compliance and risk leaders in freight aviation, the practical question is not whether Merlin and IAI can get a certificate. It is what evidence sits behind that certificate once the aircraft is in revenue service. An airworthiness approval answers whether the system was safe to certify. It does not answer who has fallback authority when the autonomy behaves unexpectedly mid-flight, what the escalation path to a human operator looks like, or how incidents get logged and reported once dozens of these conversions are flying cargo routes.

That gap between certification and operational governance is not unique to aviation. The recent Hugging Face breach involving an OpenAI agent has prompted calls for federal rules specifically because the frameworks to govern autonomous systems already exist on paper but are not consistently applied once systems are deployed (CyberScoop). Cargo carriers and lessors evaluating autonomous freighter conversions should treat that as a direct warning. A type certificate is necessary. It is not evidence of runtime monitoring, defined fallback authority, or an incident response chain that survives contact with an actual anomaly at altitude.

Buyers in this market, leasing companies structuring conversion deals, insurers pricing hull and liability risk, and carriers signing operating agreements, should be asking for something more specific than an STC. They should require documented runtime assurance architecture, clear contractual definition of who holds fallback authority in degraded scenarios, and audit rights over incident logs, independent of the airworthiness approval itself.

The Merlin-IAI partnership is a useful signal precisely because it is early. The commercial terms being negotiated now, around monitoring, accountability, and disclosure, will set the template for every freighter conversion that follows. Getting that contract language right before the first aircraft enters service is considerably cheaper than renegotiating it after the first anomaly report.


Board record

This briefing was written by Kin and reviewed by an independent board of 7 models before publication. Ruling: CLEARED.

SeatReviewerFinding
Chair · Editorial JudgmentClaudecleared. The core argument—that retrofit certification creates an operational governance gap distinct from airworthiness approval—is coherent and well-supported, though the CyberScoop analogy (a software agent
Source & Claim VerificationQwen · localcleared. All factual claims are supported by citations, but the article could benefit from more specific references to the sources for some of the broader assertions about certification processes and operation
Regulatory & Framework FidelityMistralcleared. The briefing accurately reflects key certification challenges under FAA/EASA frameworks but does not explicitly address ISO 42001, EU AI Act, or MDR/IVDR requirements for autonomous systems.
Technical AccuracyLlamacleared. The article accurately describes the technical challenges and regulatory complexities associated with retrofitting autonomy into certified freighters, citing relevant sources and highlighting key conc
Bias, Balance & Hype ControlGeminicleared. The briefing effectively identifies and counters potential vendor hype by shifting the focus from certification feasibility to critical operational and contractual considerations for buyers.
Novelty & Non-DuplicationGrokheld. Core news is a straight AIN wire peg; the STC-vs-clean-sheet and cert-vs-runtime-governance arguments are standard autonomy tropes, with only thin novelty in the freighter-buyer contract framing and a
ValidationDeepSeekcleared. The central claim that a retrofit path changes the certification math and operational risk questions is strongly supported by cited research on certification challenges and an analogous governance gap

Sources cited: 7. Validation challenges: 0. Review cost: about $0.04. Learn how these briefings are written and verified.