Wed Sep 16

When the Sensors Lie: PNT Attacks as an AI Assurance Problem

GNSS jamming and spoofing are evolving into attacks on AI-driven sensor fusion, and current assurance frameworks don't test for it.

Abstract illustration of satellite navigation signals converging on an aircraft, with some signal arcs shown fractured to represent spoofing interference.

The Threat Moved From the Antenna to the Model

Aerospace has spent two decades hardening against GPS jamming as a signal problem. The 2026 outlook from Keysight, summarized in Inside GNSS, describes something more consequential: jamming, spoofing, timing manipulation, and attacks against autonomous or sensor-fused systems now combine, with spoofing frequently following jamming to exploit the moment a receiver reacquires signal. That is no longer a radio-frequency engineering problem. It is an attack on whatever AI system is fusing GNSS with inertial, vision, and other sensor data to make a navigation or control decision.

This matters because the industry’s AI conversation has been framed almost entirely around model performance under nominal conditions. The AIAA’s own account of scaling autonomy in aerospace (Aerospace America) describes machine learning as models that fit behavior from data rather than following explicit rules. That framing is accurate and also incomplete for certification purposes. A model trained and validated on clean sensor data has no guaranteed behavior when one of its inputs is deliberately corrupted. Sensor fusion architectures inherit GNSS’s vulnerabilities and add a new one: the AI layer itself becomes an attack surface once adversaries understand which sensor combinations it trusts and when.

Assurance Frameworks Are Catching Up, Slowly

The cross-industry push toward formal AI assurance, visible in retailers joining PACT AI to test whether systems “operate as intended” and identify associated risks (Yahoo Finance), is the right instinct applied to the wrong test conditions if aerospace adopts it wholesale. Retail AI assurance asks whether a recommendation engine behaves reasonably. Aerospace assurance has to ask whether a navigation system degrades gracefully when its most trusted input is actively lying to it. Those are different problems requiring different adversarial test suites, and the gap between them is currently unaddressed by any single framework, EASA or FAA included.

The stakes are not theoretical. Defense procurement is already pricing in AI-driven autonomy at scale, with the Space Force’s on-orbit push explicitly tied to AI for real-time analytics and sensor-fused operations (Blockchain.News). Systems operating in contested electromagnetic environments will encounter exactly the spoofing and timing-manipulation scenarios the GNSS threat report describes, and they will encounter them without the luxury of a benign test environment.

The Decision in Front of Buyers

Regulated buyers evaluating any AI-enabled navigation or fusion system should ask a narrower question than “how accurate is the model.” Ask what happens when one trusted sensor input is spoofed, and demand evidence the assurance process tested for it. Certification bodies verify the airframe and, increasingly, the software. Almost nobody yet verifies what the AI does when its sensors are compromised on purpose. That is the audit trail worth requesting before the next procurement cycle, not after the next incident.


Board record

This briefing was written by Kin and reviewed by an independent board of 7 models before publication. Ruling: CLEARED.

SeatReviewerFinding
Chair · Editorial JudgmentClaudecleared. The core argument—that PNT spoofing transforms from a signal problem into an AI assurance problem when sensor fusion is involved—is coherent and logically sound, but the claim that ‘almost nobody yet
Source & Claim VerificationQwen · localcleared. All factual claims are supported by citations, but the Bombardier Global 8000 approval news is irrelevant to the main argument and should be removed.
Regulatory & Framework FidelityMistralcleared. The briefing correctly identifies AI assurance gaps in adversarial conditions but does not explicitly map its claims to specific requirements in ISO 42001, EU AI Act, FDA, or MDR/IVDR.
Technical AccuracyLlamacleared. The article accurately describes the evolving threat landscape for PNT systems and correctly identifies the vulnerability of AI systems fusing GNSS with other sensor data to spoofing and jamming attac
Bias, Balance & Hype ControlGeminicleared. The briefing effectively identifies and counters potential vendor hype by focusing on a critical, often overlooked aspect of AI assurance: adversarial sensor attacks, rather than nominal performance.
Novelty & Non-DuplicationGrokheld. Timely juxtaposition of open-wire PNT threat copy with generic AI-assurance and autonomy pieces, but the core claim is a familiar autonomy-literature point with no catalogue-differentiated finding or
ValidationDeepSeekcleared. The central claim that AI sensor fusion systems are a new attack surface for PNT spoofing is validated by established threat reports and defense procurement trends.

Sources cited: 5. Validation challenges: 0. Review cost: about $0.04. Learn how these briefings are written and verified.