01

Onboard AI is already operational

The UK expects artificial intelligence to change how space systems are designed and operated.

Published on 8 September 2026, the new UK Space Strategy says AI will enable increasingly autonomous capabilities, particularly where speed, resilience and decision advantage matter. It also commits public investment to in-orbit servicing, satellite communications, space-domain awareness and other strategically important capabilities.

This is more than a technology forecast. As intelligence moves from a ground-control centre into an orbiting system, the location of decision-making changes. A satellite may process observations before sending them to Earth. A servicing vehicle may eventually navigate near another spacecraft. A constellation may coordinate tasks between several assets.

The commercial question is no longer simply whether AI can operate onboard. It is what the onboard system has been authorised to do when a person is not reviewing each proposed action.

ESA's Φsat-2 provides a practical starting point. The miniature Earth-observation satellite completed commissioning and began delivering scientific data in 2025. Its onboard AI applications can process and compress imagery, identify clear images, discard images obscured by cloud and detect features including ships, wildfires and marine pollution.

Instead of transmitting every raw image for processing on Earth, the satellite can examine information onboard and determine which data is useful. That can reduce unnecessary transmission and provide relevant information more quickly.

In this application, the immediate consequence is largely informational: retain an image, discard it, compress it or derive an observation. Even here, governance matters.

ESA is careful to describe Φsat-2 as a demonstrator designed to expose limitations and build understanding of onboard AI processes. Demonstrating an autonomous capability does not automatically qualify it for every operational use.

  • Which application is allowed to examine which sensor data?
  • May it discard the original image?
  • How confident must it be before filtering information?
  • Must particular observations always be retained?
  • Who may change an onboard application?
  • What evidence must return to Earth?
02

Physical autonomy raises the consequence

The UK's ambitions extend beyond processing images. The new Space Strategy allocates £117 million in civil funding between 2026–27 and 2029–30 to in-orbit servicing, assembly and manufacturing. This includes up to £77 million for a national active-debris-removal mission and £40 million for technology demonstrations.

The Government's objective is to demonstrate rendezvous, proximity operations and docking capabilities by 2030.

Related UK-funded projects show what this involves. Proximus Prime is described as a UK-built demonstration mission for autonomous vision-based rendezvous and proximity operations in low Earth orbit. ARGUS is developing autonomous rendezvous technology for a planned geostationary-orbit inspection satellite. RANGER is advancing relative autonomous navigation for a future commercial servicing mission.

These are development and demonstration activities—not evidence that unrestricted autonomous servicing is already in routine operation.

Nevertheless, they illustrate a change in consequence. Choosing not to transmit a cloudy image is materially different from changing a spacecraft's trajectory near another orbital asset. An incorrect data-filtering decision may lose useful information. An inappropriate proximity manoeuvre could affect valuable equipment, create safety concerns or interfere with another operator's mission.

The same AI label can therefore describe very different levels of operational authority.

03

Autonomy needs a delegation envelope

An autonomous system should not receive general permission to ‘complete the mission’ and then determine every acceptable means for itself. Authority should be bounded around the proposed effect.

For an orbital system, those bounds might include the identified spacecraft or observation target, the permitted action class, the maximum change in position or mission state, the valid time window, the information that must be available, the conditions requiring ground authority and the conditions under which the action must not proceed.

Consider three progressively more consequential proposals: discard a cloud-covered image; retask a sensor to observe a newly identified area; or initiate a proximity manoeuvre towards another spacecraft.

The first may fall within standing onboard authority. The second may be permitted only within a defined geographic, operational or time limit. The third may require additional authority and current evidence about identity, position, trajectory and mission state.

This is PF Systems' interpretation of the governance requirement—not a requirement stated by the UK Government or ESA.

The inability to review every action live should lead to more precise delegation, not broader implied permission.

04

A stopped action need not mean a stopped spacecraft

This distinction also clarifies the role of Stop the Line. In an edge-autonomy deployment, Stop the Line should not automatically mean switching off the satellite, disabling the AI model or terminating the entire mission.

It means that the proposed governed effect cannot proceed under the available authority.

Depending on the proposal, PF Kernel could return Allow, Deny, Modify, Step Up or Stop the Line.

The intervention must have practical effect at the protected execution boundary. PF Systems should not claim that it can enforce this in an orbital system unless the deployment architecture makes the relevant execution path subject to that authority.

Nor should a stopped proposal silently proceed through a different interface or be restored by the requesting agent itself.

  • An image-processing application could continue while a sensor-retasking proposal is stopped.
  • Routine observations could continue while one proximity operation is prevented.
  • One spacecraft could lose authority to approach a target while other authorised assets continue their missions.
  • An entire manoeuvre class could be suspended without disabling unrelated analysis.
05

What a PF Systems space trial could examine

PF Systems has not publicly demonstrated flight heritage or production deployment in a space system. The appropriate next step would therefore be a controlled, non-actuating trial.

A mission simulator or digital twin could generate representative proposals such as filtering an image, reprioritising a downlink, retasking a sensor, updating an observation plan, changing an application state or initiating a simulated proximity manoeuvre.

PF Systems could evaluate copies of those proposals without issuing commands to a spacecraft or operational ground system.

PF Memory would supply approved mission context to the evaluation. PF Kernel would determine the governed outcome. PF Core would preserve the linked material needed to trace, check and deterministically replay that evaluation.

Evidence that PF Kernel permitted an action would not prove that a spacecraft executed it. Trusted acknowledgement from the simulator, executor or affected system would be needed to connect the authority decision to the reported result.

Proof Harness could help qualify the evidence produced by the trial, but would not certify the system or the mission.

  • Can each asset and proposed effect be identified reliably?
  • Is authority specific enough to distinguish observation, processing and manoeuvre?
  • Can an overly broad proposal be narrowed?
  • Does missing or contradictory mission information produce the intended outcome?
  • Can authority be withdrawn independently of the AI?
  • Does one suspended action class leave unrelated activity available?
  • Can reviewers reconstruct the governed evaluation afterwards?
06

Sovereign autonomy is operational, not merely geographic

The UK Space Strategy connects autonomy with resilience, national security and sovereign capability.

Sovereignty in this context cannot be reduced to where a model was developed, where data is stored or which organisation owns the satellite. Those factors matter, but operational control also depends on who can authorise consequential action.

A country or operator does not possess meaningful sovereign control if an autonomous system can exceed its delegated authority, bypass an intervention or leave no adequate evidence of the decision.

Conversely, useful autonomy should not require a person to approve every routine operation. That would undermine many of the advantages of onboard processing and autonomous response.

The commercially valuable middle ground is bounded autonomy: standing authority for defined, lower-consequence actions; narrower execution when a proposal exceeds its permitted scope; additional authority for exceptional cases; enforceable intervention when required conditions fail; and linked evidence that survives the operation.

PF Systems does not claim to make spacecraft safe, establish regulatory compliance or qualify an autonomous system for flight. It does not make the underlying probabilistic AI deterministic.

Its forward-looking proposition is more precise: when AI moves onboard, an organisation should be able to move its authority boundary with it—governing what may become effective without removing the useful intelligence or autonomy of the wider system.

07

Sources

Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.