What runtime assurance does
Conventional runtime assurance monitors defined properties while a system operates and intervenes when continued use of an advanced function could violate an established boundary.
BIT extends the operational question to include mission authority, policy and trusted context while preserving the separate role of platform-specific safety monitors.
From observation to enforceable response
A useful runtime mechanism needs more than an alert. It must connect observed conditions to a defined, enforceable response.
Handle uncertain localization and world state
For position-dependent actions, BIT is being designed to use TRUSTED, DEGRADED, CONFLICTED and UNTRUSTED. A system may retain valid mission authority while losing sufficient localization confidence for a particular action.
The response should be predetermined by mission policy and consequence profile rather than improvised after failure.
Runtime evidence for review
Runtime decisions should preserve the relevant input state, policy, authority status, configuration, selected outcome and resulting action.
This evidence can support defect analysis, operational review, TEVV and configuration control. Its sufficiency must be tested for the specific implementation and use case.
Frequently asked questions
What is runtime assurance?
Runtime assurance uses monitoring and response mechanisms to keep behaviour within defined boundaries while a system operates.
Is it a watchdog or health monitor?
Not by itself. Runtime assurance connects monitored properties to a justified intervention, fallback or restriction.
Does BIT replace the flight controller?
No. BIT is designed as an independent assurance and authority layer that works with existing controllers and safety mechanisms.
Can it operate without connectivity?
Bounded local operation can be designed, but the exact link-loss response is mission-specific and must not grant broader authority.
Sources and technical basis
- ASTM F3269-21 — Run-Time Assurance for Complex Aircraft Functions — Reference inclusion establishes technical context only; it does not claim conformity, approval or certification.
- NASA — Leveraging ASTM F3269 for Run-Time Assurance
- NASA — Dynamic Assurance of Autonomous Systems
- NIST Artificial Intelligence Risk Management Framework
- DoD Directive 3000.09 — Autonomy in Weapon Systems
Define runtime boundaries before deployment.
Scope monitored conditions, authority rules, intervention outcomes, integration points and TEVV evidence for one autonomous mission.
Discuss reference integrationUnclassified · scoped workshops and pilot design
