EngineeringLead

Regulated engineering

AI in regulated engineering

In aerospace, defense, medical devices and licensed engineering, the question is not whether an AI tool is useful. It is whether its use can be controlled, recorded and defended to an auditor, a regulator or a court.

Not legal advice. Export-control, licensing and certification obligations depend on your products, contracts and jurisdiction. Involve your export-control, quality and legal functions before rolling out AI tools.

Accountability does not transfer

A licensed Professional Engineer who seals a drawing is responsible for it, however it was produced. An aerospace supplier certifying a part conforms is responsible for that statement. A design authority signing off a safety analysis owns its conclusions. AI tools can assist every one of these activities, but none of them can hold the responsibility. The lead's job is to make sure that the person who signs understands what they are signing.

Controlled technical data and AI tools

Technical data controlled under the ITAR or the EAR can't be shared with unauthorized foreign persons, and export rules also govern where and how it is stored and transmitted. Before any controlled drawing, model, specification or source code goes into an AI tool, establish:

The safe default is simple: no controlled technical data goes into a tool until export compliance has approved that specific deployment. Train engineers on it before they get access, not after.

Records and quality systems

Quality management systems such as AS9100 and ISO 9001 expect controlled processes, documented information and competent people. When AI tools participate in design, analysis or inspection:

  1. Define the process. Say where AI assistance is permitted and where it isn't.
  2. Record its use. Note when an artifact was AI-assisted and which tool and version were used, where your quality system requires traceability.
  3. Verify independently. Check AI-assisted analysis by methods that don't depend on the same tool.
  4. Qualify the tool where required. Some safety and certification frameworks require tools whose output isn't independently verified to be qualified. Check what your domain demands.
  5. Keep people competent. Auditors will ask whether the engineers could do the work without the tool, and whether they can recognize when it is wrong.

Safety-critical software and hardware

Domains with established assurance standards, such as airborne software and hardware, automotive functional safety and medical device software, have strict expectations for requirements traceability, verification and tool confidence. AI-generated artifacts need to fit those expectations, not bypass them. Engage your certification authority or assessor early when AI tools will touch certified work.

A rollout checklist for regulated teams

For team-level practices that apply everywhere, see leading engineers who build with AI.

Last reviewed 2026-09-17