Research topic · regulatory analysis

Thirty thousand hours, and no test for sharing them.

The flight-hour ladder in SORA is not a policy figure. It is one line of statistics, exact at every rung, and it closes the route where the arithmetic says it must. The clause that lets two operators combine their hours is carried by three jurisdictions in identical words and defined by none of them.

The Hall Lab, with The Charlot Lab

A UAS operator seeking a higher assurance level may show operational reliability by flying. The number of hours is published: 30 for SAIL I, 300 for SAIL II, 3,000 for SAIL III and 30,000 for SAIL IV, with no failures. Those figures look like a regulator’s judgement about how much flying is enough. They are not a judgement at all.

With zero failures in n hours the 95% upper bound on the rate is −ln(0.05)/n = 2.9957/n, which is the Rule of Three’s 3/n. Solve n = 3/λ for a decade of hazard rate per level and the published ladder falls out exactly, at all four rungs. CAP 3017 names the target it lands on — loss of control below 10-4 per flight hour at SAIL IV — and EASA’s Annex E footnotes the Rule of Three itself. The same arithmetic explains why the route stops: SAIL V asks for 300,000 zero-failure hours, about thirty-four aircraft-years of continuous flight, so “not feasible” is a statement of fact rather than of preference.

One of the three jurisdictions stops a rung earlier than the arithmetic requires. EASA closes functional testing at SAIL IV and above, where JARUS and the UK close it at V; nothing in the mathematics distinguishes 30,000 hours from 3,000 in kind. That ceiling is a regulatory judgement sitting on top of the statistics, and it is the only one of the three that is.

The clause

All three then permit something the ladder alone does not: two operators may add their hours together. JARUS Annex E §E.3(d)(ii), EASA’s Annex E and the UK’s GM.FTB carry the same sentence — an authority “may accept accumulation of FTB hours between operators if the UAS configuration, operational procedures, training, etc. are demonstrated to be equivalent”. The UK edited that sentence to name its own regulator and left the condition untouched, so it was adopted attentively rather than copied.

Those five words are doing statistical work. The bound 3/n is valid for n draws from one population with a common rate; pooling two operators and using 3/(nₐ+nₑ) assumes they are exchangeable. “Demonstrated to be equivalent” is that assumption, written in natural language with no test attached. Across 1.69 million characters of primary regulatory text — four complete corpora, counted rather than sampled — the phrase appears four times and is elaborated nowhere.

The exposure is the reciprocal of a contribution. Half a pool and the bound granted is twice what your own flying supports; a hundredth of a pool and it is a hundred times. If the two operations really are exchangeable that is correct and is the entire point of pooling. If they are not, that factor is the error — and the flight hours cannot settle which it is, because two zero-failure samples carry no information about whether their rates differ. The evidence has to be structural: configuration, procedures, training. Which is what the clause names, and what no text defines.

This matters because the rung is not out of reach. One operator’s published flying clears SAIL IV by between forty and a hundred and forty times, across a threefold span of assumed cruise speeds, so the conclusion does not depend on the assumption. Pooling is therefore not how anyone reaches the top rung. It is how an operator without hours comes to stand on the record of one that has them — and of the three largest operators, this review found none that publishes flight hours at all, so which of those is happening is not a fact an outside party can check.

Run it

Compute the ladder, then compute what sharing it is worth.

Move the target hazard rate and watch n = 3/λ reproduce the published ladder at every rung, with the three jurisdictions’ ceilings side by side. Then set your share of a pool and read your own bound against the pooled one.

Open it full width →

Binding constraint variesRegulatoryMeasurement

SORA prices operational assurance in flight hours, and the price is exact: 30, 300, 3,000 and 30,000 hours for SAIL I to IV is the Rule of Three, n = 3/λ, solved for a decade of target hazard rate per level. CAP 3017 states the target it lands on, a probability of loss of control below 10-4 per flight hour at SAIL IV, and EASA’s Annex E footnotes the Rule of Three directly. The same arithmetic closes the route, because SAIL V would ask for 300,000 zero-failure hours. What no text closes is the clause that lets two operators add their hours together, which JARUS, EASA and the UK all carry in the same words — configuration, procedures and training “demonstrated to be equivalent” — and none defines; across 1.69 million characters of primary regulatory text the phrase occurs four times and is elaborated nowhere. That clause is not a formality around the statistics, it is the exchangeability assumption the statistics rest on, and the exposure is the reciprocal of an operator’s share: contribute one per cent of a pool and the bound granted is a hundred times stronger than that operator’s own flying supports. The binding constraint is measurement rather than policy, because the demonstration cannot come from the flight hours themselves — two zero-failure samples carry no information about whether their rates differ, so the evidence has to be structural. The engineering change that moves it is an equivalence schedule: the facts two operators must publish for their hours to be poolable, each graded by whether it can be evidenced by a digest, by a record, or only by an assessor’s judgement. What becomes possible is a pooled safety argument an outside party can check — on a route whose top rung the largest operators already clear by forty to a hundred and forty times, and whose unit, the flight hour, none of the three largest operators publishes at all.

One of eight, and only one of them is physics. How we read a frontier →