News

The Case for SOTIF Testing in Low-Altitude Aviation
Date:2026-08-26 15:14:46 | Page view:


Alex Zhicheng Huang1, Lixi Huang2, Amanda Lim3

1 Research Assistant Professor; Director, Low-Altitude Economy Research Project, Faculty of Law, The University of Hong Kong

2 Professor and Deputy Head, Department of Mechanical Engineering; Executive Dean, Low-Altitude Economy Research Institute, The University of Hong Kong

3 HK Chief Representative & CFO, DIGAUTO

Aug 26, 2026

 图片1_副本.jpg

Executive Summary

As the low-altitude economy transitions toward commercial maturity, robust safety assurance remains the critical barrier to widespread deployment. This paper advocates for the implementation of dedicated SOTIF (Safety of the Intended Functionality) testing laboratories to address the scarcity of transferable operational experience in low-altitude aviation. Unlike traditional testing focused on component failure, SOTIF testing systematically evaluates how integrated aircraft systems perform under challenging environmental conditions, such as urban turbulence and variable lighting. By enabling repeatable, full-scale testing of complete aircraft in controlled settings, these laboratories provide essential empirical evidence to support regulatory approval, enhance public confidence, and accelerate the safe development of the low-altitude economy.

I. Low-Altitude Development and Safety Assurance

The low-altitude economy is moving from technical experimentation toward wider commercial use and regulatory development. China revised its Civil Aviation Law in December 2025. The revised law took effect on 1 July 2026 and introduced a new chapter on development promotion that expressly addresses the institutions and standards needed for the low-altitude economy. The United States is advancing Advanced Air Mobility and eVTOL through pilot programs and flight demonstrations. The European Union and the United Kingdom are also developing corresponding regulatory frameworks.

Hong Kong is developing its own regulatory and infrastructure framework. Regulatory Sandbox X, launched in November 2025 as an advanced stage of the earlier regulatory sandbox, covers low-altitude traffic management, unconventional aircraft, cross-boundary applications, and shared platforms. The Civil Aviation Department is also conducting technical studies on a Smart Low-altitude Traffic Management System.

The underlying challenge is safety assurance. Aircraft and supporting systems must operate safely across the conditions for which they are approved. Safety depends on system design, operating limits, maintenance, and the knowledge accumulated through operation. These mechanisms reduce hazards, keep aircraft within validated conditions, detect degradation, and feed operational problems back into engineering improvement. The quality of safety evidence also matters beyond engineering itself. It affects regulatory acceptance and public confidence, both of which are essential if low-altitude operations are to move from demonstration to sustained commercial use.

Testing provides direct empirical evidence about system performance. It exposes an integrated aircraft to defined conditions and measures its actual response. Interactions may emerge only after propulsion, power, sensing, communications, and flight control are integrated. Testing can also reproduce safety-relevant conditions that would otherwise appear only rarely or unpredictably in service.

For low-altitude aviation, testing matters for two related reasons. The need for direct safety evidence is high while mature and transferable operational experience remains limited. At the same time, the relatively small size of many low-altitude aircraft allows the complete aircraft to be placed inside controlled facilities for forms of full-scale testing that would be much harder to conduct on large transport aircraft.

II. Why Low-Altitude Aviation Needs More Test Evidence

Testing is needed where design, analysis, and available operational experience cannot provide all the evidence required for safety assurance. The larger this evidentiary gap, the greater the role of testing.

Mature commercial aviation shows how powerful operational experience can become as a source of safety knowledge. Large fleets of identical or closely related aircraft operate frequently over long periods. Rare anomalies eventually appear. Investigation, continuing airworthiness measures, maintenance changes, and design modifications then feed new knowledge back into the system. Stable designs and relatively regular operating conditions also make experience more comparable across a fleet.

Low-altitude aviation has not yet developed an equally mature experiential base. Aircraft configurations remain diverse. Multirotor, lift-plus-cruise, and tilt-rotor designs are developing in parallel. Propulsion and energy-storage systems, airframe materials, sensing, communications, and flight-control architectures also continue to change. Logistics, infrastructure inspection, emergency response, and passenger transport involve different speeds, altitudes, ranges, payloads, and operating requirements. Urban, mountainous, and coastal environments add further variation.

Operational experience from one aircraft and one environment therefore cannot automatically support judgments about another design. Rapid technological change further limits the value of earlier data when materials, propulsion systems, control architectures, or operating concepts change substantially.

Operational experience will become increasingly important as the sector matures. Before such experience accumulates at scale, however, regulators and operators must already decide which aircraft can operate, under what conditions, and with what restrictions. Testing therefore carries a larger share of the early burden of producing safety evidence.

III. Conditions for Controlled Testing

The value of testing also depends on whether relevant conditions can be generated repeatedly and measured accurately.

Large transport aircraft undergo extensive ground and flight testing at aircraft level. Some external conditions, however, are difficult to impose repeatedly on a complete large aircraft in a controlled facility. Time-varying aerodynamic or optical inputs can require very large test spaces, while higher speeds and energy levels further increase facility, safety, and cost requirements.

Many low-altitude aircraft are much smaller. This makes some forms of full-scale integrated testing more practical. Prescribed gusts, combinations of mean wind speed and direction, lighting, visibility, communications conditions, and perception targets can be varied while the complete aircraft remains under measurement. When the characteristic scale of a disturbance is large relative to the aircraft, the aircraft may also experience it more nearly as a coherent unsteady input rather than as a strongly varying field across the entire vehicle. The complete spatial and spectral structure of real urban turbulence remains difficult to reproduce, but selected safety-relevant disturbances can be brought under much tighter experimental control.

Digital architectures add another advantage. Sensor inputs, flight-control commands, actuator states, propulsion parameters, and aircraft responses can be recorded synchronously. Engineers can therefore relate changes in external conditions to internal system states and to the final response of the aircraft.

The relevant advantage is not that low-altitude environments are simple. They are often highly complex. It is that a meaningful subset of safety-critical conditions can be generated, varied, and measured on a complete aircraft in a controlled setting.

IV. Why SOTIF Is Needed

More testing is useful only if the right conditions are tested.

Many tests begin with known requirements or identified failures. Engineers can ask whether a system reaches a specified performance level, whether it responds safely when a known component fails, or whether it remains within required limits under a defined environmental condition. These forms of testing remain essential.

A different problem arises when no conventional failure occurs. A system may operate exactly as designed, yet its normal capability may become inadequate under a particular combination of operating conditions. Safety of the Intended Functionality, or SOTIF, addresses this class of risk.

ISO 21448 distinguishes two main sources of functional insufficiency. One is an insufficiency in the specification of the intended functionality at the vehicle level. In aviation, the corresponding level is the aircraft level. The other is an insufficiency in the specification or performance of the electrical or electronic implementation. The standard also addresses reasonably foreseeable misuse and circumstances in which remote users or back-office communication can affect safety.

SOTIF does not replace existing aviation safety frameworks. It adds a structured way to examine situations in which nothing has failed, but normal system performance is still not good enough for the conditions encountered.

A perception system illustrates the problem. Cameras and processing hardware may continue to operate normally, but strong reflection from a glass façade, glare, or poor visibility can reduce target contrast and shorten effective detection range. The relevant safety question is whether the available detection range remains greater than the distance the aircraft needs to avoid the obstacle safely. That required distance depends not only on the sensor but also on processing and decision time, actuator response, and aircraft maneuvering dynamics. Sensor testing alone therefore cannot establish the safety of the integrated response.

SOTIF organizes such problems through scenarios. A scenario describes relevant environmental conditions, aircraft states, objects, actions, and how they change over time. A test program can then vary those conditions and search for the point at which normal functionality ceases to provide sufficient performance.

Testing standards for low-altitude aviation should therefore cover not only specified performance and identified failures, but also functional insufficiencies that arise when normally operating systems encounter demanding conditions. SOTIF provides a systematic framework for this additional dimension of testing.

V. Building a SOTIF Testing Laboratory

A dedicated SOTIF testing laboratory would convert important operating conditions into repeatable engineering inputs. Wind, lighting, visibility, communications conditions, perception targets, and aircraft states could be varied according to defined scenarios while the response of the complete aircraft is measured. Conditions near safety boundaries could be reproduced under controlled conditions while limiting exposure to third parties.

No physical facility can test every possible combination of conditions. Its value lies elsewhere. It can make the most important conditions repeatable and measurable. It can provide physical data to calibrate and validate simulation, allowing models to explore a much larger range of scenarios with greater confidence. It can also turn newly discovered hazardous combinations into repeatable test cases. The body of testable scenarios can therefore grow as engineering knowledge and operational experience accumulate.

The same capability can support both known and previously unidentified problems. Engineers can begin with scenarios derived from design analysis or operational concerns, systematically vary the relevant parameters, and identify combinations that had not initially been recognized as hazardous. Once identified, those combinations become defined conditions that can be reproduced, measured, and incorporated into later testing.

Hong Kong has particular reasons to develop such capability. Dense high-rise development, complex terrain, and coastal weather create substantial local variation in low-altitude operating conditions. Glass façades, changing visibility, local airflow, and dense urban infrastructure can impose demanding conditions on perception and control systems. Building local testing capability would therefore support the assessment of aircraft intended to operate in Hong Kong’s own environment.

Hong Kong is already developing low-altitude traffic management, regulation for unconventional aircraft, technical standards, and related infrastructure. A dedicated SOTIF laboratory would add an engineering-testing capability to this emerging framework. It could turn safety questions into repeatable scenarios and provide empirical evidence for regulatory assessment, operating limits, and future technical standards. The capability could also support testing and validation beyond individual local projects as low-altitude technologies continue to develop.

The overall case is therefore straightforward. Low-altitude aviation needs substantial safety evidence before mature and transferable operational experience is available. Many low-altitude aircraft also make selected forms of full-scale integrated testing more practical. SOTIF extends that testing to an important class of risks in which systems have not failed but their normal performance becomes inadequate under particular conditions. Hong Kong should therefore build a dedicated SOTIF testing laboratory that can reproduce critical scenarios, measure integrated aircraft responses, support credible simulation, and generate the evidence needed for safe regulation and commercial deployment.

VI. Conclusion

SOTIF testing laboratories represent a vital infrastructure requirement for the advancement of the low-altitude economy. By enabling controlled, repeatable, and measurable testing of integrated aircraft systems, these facilities bridge the critical gap between early-stage experimental development and large-scale commercial maturity. The implementation of such laboratories—particularly in complex urban environments like Hong Kong—provides the essential empirical safety evidence required to secure regulatory confidence and ensure the sustainable, safe deployment of low-altitude aviation technologies.

Glossary

LAE (Low Altitude Economy): An economic ecosystem centered on human-led and autonomous flight activities within low-altitude airspace (typically below 1,000 meters).

eVTOL (Electric Vertical Take-off and Landing): Aircraft powered by electric propulsion capable of hovering, taking off, and landing vertically.

SOTIF (Safety of the Intended Functionality / ISO 21448): The absence of unreasonable risk resulting from hazards caused by functional insufficiencies, environmental performance limits, or reasonably foreseeable misuse.

SOTIF-Index: A quantitative residual-risk metric combining known unsafe risk mitigation and unknown unsafe verification credibility.

SMS (Safety Management System): An organization-wide process framework managing safety risks across governance, hazard reporting, change management, and lifecycle monitoring.

Safety Case: A system-specific product artifact delivering a structured argument (typically via GSN) that a system is acceptably safe in its defined ODD.

GSN (Goal Structuring Notation): A graphical argumentation notation linking claims to evidence within defined operational contexts.

ODD (Operational Design Domain): The operating conditions under which an autonomous system is specifically designed to function.

DSSAD (Data Storage System for Automated Driving/Flight): On-board data recorder logging system status and safety-relevant events to support post-operation analysis.

ISMR (In-Service Monitoring and Reporting): Lifecycle feedback process logging field telemetry and incident occurrences to maintain Safety Cases continuously.

HIL (Hardware-in-the-Loop): A testing method where physical controllers or vehicle actuators are connected to high-fidelity simulated environments.

UTM (Unmanned Traffic Management): Airspace management systems enabling safe, coordinated low-altitude operations.

References

1. EASA, Special Condition for VTOL-capable Aircraft (SC-VTOL-01), Issue 2, European Union Aviation Safety Agency, May 2024.

2. Civil Aviation Administration of China (CAAC), Civil Aviation Law of the People's Republic of China (2025 Revision), adopted Dec 27, 2025, effective July 1, 2026.

3. UN ECE WP.29 GRVA, Proposal for a New United Nations Global Technical Regulation on Automated Driving Systems (ADS), ECE/TRANS/WP.29/GRVA/2026/2, 2026.

4. ISO 21448:2022, Road vehicles — Safety of the intended functionality (SOTIF), International Organization for Standardization.

5. ISO 26262:2018, Road vehicles — Functional safety, International Organization for Standardization.

6. Wang, H. (Tsinghua University / CAICV-SOTIF Technical Alliance), Research on SOTIF Index and its role in ADS Driving Safety Evaluation, UN ECE GRVA-23-43, 2025.

7. TÜV SÜD & Qualcomm, Safety in ADAS/AD SOTIF, a risk-based approach, Technical White Paper, 2023.

8. Kelly, T., Arguing Safety — A Structured Approach to Managing Safety Cases, Ph.D. Thesis, University of York, 1998.

9. Transport Department & Civil Aviation Department of Hong Kong, Code of Practice for Trial and Pilot Use of Autonomous Vehicles (Cap. 374AA) & Low Altitude Economy Sandbox Guidelines, 2024–2025.

10. State Administration for Market Regulation (SAC/MIIT China), GB 44497-2024 (DSSAD), GB/T 44721-2024 (General Requirements), GB/T 45312-2025 (ODD Conditions), 2024–2025.


 
 Prev:2026 Testing Expo‑Meet Us Offline for New Opportunities | Digauto awaits you at Booth 11020
 Next: