| Validating eVTOL Safety: Applying ADS Testing Rigor to the Low Altitude Economy |
| Date:2026-08-18 10:39:58 | Page view: |
Validating eVTOL Safety: Applying ADS Testing Rigor to the Low Altitude Economy Authors: Rainer Hoffmann, Dr. Amanda Lim, Li Xiao Ying Date: 18 AUG 2026
Market Growth and the Certification BottleneckThe Low Altitude Economy (LAE) is approaching commercial deployment in several markets. In Europe, EASA has issued special conditions (SC-VTOL, Enhanced category) for commercial passenger transport [1]. In China, the Greater Bay Area (GBA) is preparing cross-border autonomous aerial logistics and air taxi operations [2]. CCID Consulting projects the Chinese LAE to grow from RMB ¥1.5 trillion in 2025 to ¥3.5 trillion (approx. $490 billion) by 2035 [3]. These operations fall under the revised Civil Aviation Law, effective July 1, 2026, which tightens commercial airworthiness requirements [4]. Certification practice has not kept pace. Type-approval regimes built on deterministic specifications and compliance checklists do not adequately cover autonomous operation [1, 5]. Open-world Operational Design Domains (ODDs), micro-climate urban turbulence, and non-deterministic, opaque machine-learning components require a shift from prescriptive rules to structured, evidence-based safety arguments [5, 6]. Process vs. Product: Key ADS LearningsA common failure mode when transferring automotive assurance practice to aviation is conflating process maturity with outcome arguments [5]. For eVTOL programs building on Automated Driving Systems (ADS) technology, the relevant distinction is between the organizational process and the system-specific product artifact [5]: 1. Safety Management System (SMS) — the organization-wide process. The SMS answers the question: how does the organization manage risk over time? [5] It covers governance, safety policy, periodic internal risk assessment, hazard reporting, change management, and post-deployment monitoring [5, 6]. 2. Safety Case — the system-specific product artifact. The Safety Case answers: is this specific system acceptably safe in its defined operating environment? [5] It is a structured argument, typically expressed in Goal Structuring Notation (GSN), linking claims to evidence from simulation, proving-ground testing, and field data within a bounded ODD [5, 8]. The 2026 UN Global Technical Regulation (GTR) on ADS (ECE/TRANS/WP.29/GRVA/2026/2) makes an audited SMS a prerequisite for a credible Safety Case [5, 6]. The SMS establishes the provenance and integrity of the evidence cited in the Safety Case argument [5]. Open-World Complexity: eVTOL vs. ADSGround ADS safety frameworks — ISO 26262 for functional safety [7], ISO 21448 for SOTIF [8], and ISO/PAS 8800 for AI safety [9] — address open-world validation, but commercial eVTOL operation raises the requirements in three areas: 1. Reliability targets. The EASA SC-VTOL Enhanced category requires a catastrophic failure rate below 10−9 per flight hour [1, 5]. Demonstrating this without a human pilot as fallback requires combining functional safety analysis with probabilistic verification and validation (V&V) methods derived from SOTIF [5, 8]. 2. System-of-systems scope. The safety argument cannot be limited to aircraft airworthiness [1]. It must also bound UTM (Unmanned Traffic Management) data-link availability, vertiport ground infrastructure, and micro-climate wind shear [1, 2, 5]. 3. Cross-domain integration. Commercial eVTOL operation combines aerospace software assurance (DO-178C/DO-254), automotive SOTIF standards (ISO 21448 [8], ISO/PAS 8800 [9]), and drone operational risk assessment (JARUS SORA) [5, 10]. Recommendations: Operationalizing Safety CasesTo resolve the bottleneck, LAE operators need to treat Safety Cases as maintained engineering artifacts rather than static documentation: • Do not substitute process for argument. SMS compliance is not a Safety Case [5]. Regulators will reject airworthiness claims based only on adherence to organizational process, without quantified residual-risk evidence such as a SOTIF-Index baseline [5, 8]. • Implement in-service monitoring and reporting (ISMR). The Safety Case must be maintained over the system lifecycle [5]. Field data — following the Data Storage System for Automated Driving (DSSAD) approach, supplemented by flight telemetry such as wind vectors and sensor point clouds — must feed back into the SMS [5, 6]. This supports reassessment of residual risk and keeps the Safety Case current after over-the-air (OTA) updates to aircraft software or UTM protocols [4, 5, 6]. Digauto: Validation Infrastructure for LAE AssuranceDigauto works at the intersection of automotive SOTIF testing and aerospace airworthiness assurance [1, 5, 10]. Verifying AI-based perception and control in dense urban environments such as Hong Kong and the GBA requires physical validation infrastructure, which Digauto is building [2]. This work builds on Digauto's established position as a leading supplier of active safety test technology for intelligent driving. Digauto provides complete test and validation solutions for ADAS and intelligent connected vehicles (ICVs), and developed VTEHIL (Virtual Testing Environment Hardware-in-the-Loop), a method for assessing the safety performance of complete vehicles in ADAS and ADS scenarios under laboratory conditions [11]. VTEHIL couples the physical vehicle, including its full sensor set, to a simulated environment, so that critical and hazardous scenarios can be executed repeatably, indoors, and without risk to test personnel or hardware. The Physical AI Safety Lab (PAIS-Lab) extends this approach from road vehicles to eVTOL. High-fidelity hardware-in-the-loop (HIL) simulators support non-destructive, indoor stress testing of flight control algorithms against extreme environmental conditions and sensor degradation — the same closed-loop test principle applied under VTEHIL, transferred to the airborne ODD. The objective: enable OEMs to produce audit-ready Safety Cases. References1. EASA, Special Condition for VTOL-capable Aircraft (SC-VTOL-01), Issue 2, European Union Aviation Safety Agency, May 2024. 2. Hong Kong SAR Government, Working Group on Developing Low-altitude Economy Holds First Meeting, press release, November 2024. 3. CCID Consulting, Research Report on China's Low-Altitude Economy Development, 2024 (LAE projected at RMB ¥1.5 trillion in 2025, ¥3.5 trillion by 2035). 4. Civil Aviation Law of the People's Republic of China (2025 Revision), adopted December 27, 2025, effective July 1, 2026. 5. Automobile Digauto Technology GmbH, Safety Case and SMS in Autonomous Systems and Low Altitude Economy, Technical Whitepaper, 2026. 6. UN ECE WP.29 GRVA, Proposal for a New United Nations Global Technical Regulation on Automated Driving Systems (ADS), ECE/TRANS/WP.29/GRVA/2026/2, 2026. 7. ISO 26262:2018, Road vehicles — Functional safety, International Organization for Standardization. 8. ISO 21448:2022, Road vehicles — Safety of the intended functionality (SOTIF), International Organization for Standardization. 9. ISO/PAS 8800:2024, Road vehicles — Safety and artificial intelligence, International Organization for Standardization. 10. JARUS, JARUS Guidelines on Specific Operations Risk Assessment (SORA), Joint Authorities for Rulemaking on Unmanned Systems, 2024. 11. Digauto, VTEHIL — Virtual Testing Environment Hardware-in-the-Loop, http://digauto.biz/en/index.php?catid=35, accessed August 2026. GlossaryLAE (Low Altitude Economy): An economic ecosystem centered on human-led and autonomous flight activities within low-altitude airspace (typically below 1,000 meters). eVTOL (Electric Vertical Take-off and Landing): Aircraft that use electric power to hover, take off, and land vertically. ADS (Automated Driving Systems): The hardware and software that are collectively capable of performing the entire dynamic driving task on a sustained basis. SMS (Safety Management System): A systematic approach to managing safety, including the necessary organizational structures, accountabilities, policies, and procedures. GSN (Goal Structuring Notation): A graphical notation used to document and present safety arguments. SOTIF (Safety of the Intended Functionality): The absence of unreasonable risk due to hazards resulting from functional insufficiencies or reasonably foreseeable misuse. SOTIF-Index: A quantitative residual-risk metric derived from SOTIF verification and validation activities, used as a baseline for outcome-based safety acceptance. ODD (Operational Design Domain): The specific conditions under which a given driving automation system or feature thereof is designed to function. HIL (Hardware-in-the-Loop): A technique where real signals from a controller are connected to a test system that simulates reality, so the controller behaves as if installed in the assembled product. VTEHIL (Virtual Testing Environment Hardware-in-the-Loop): A full-vehicle test method that couples a physical vehicle and its sensors to a simulated environment to assess safety performance in ADAS and ADS scenarios under laboratory conditions. UTM (Unmanned Traffic Management): The systems and services that enable safe, coordinated access to low-altitude airspace for unmanned and autonomous aircraft. DSSAD (Data Storage System for Automated Driving): An on-board data recorder that logs the status of the automated driving system and relevant events to support post-operation analysis. |
| Prev:Navigating the "Ghost Days" of Aviation: Why SOTIF is the Mathematical Key to eVTOL Safety Next:2026 Testing Expo‑Meet Us Offline for New Opportunities | Digauto awaits you at Booth 11020 |