Scenario boundary. The cited railway programmes document real AI-assisted dispatching, conflict detection and operational decision-support work. The poisoned-telemetry attack described here is a forward-looking engineering scenario, not a reported railway incident.

Decision support is becoming operationally relevant

Europe's Rail has documented AI-assisted railway traffic-management work, including automated in-station train dispatching validated at TRL 5 and demonstrations of real-time conflict detection and corrective action. These programmes still retain human confirmation in current validation scenarios, but the direction of travel is clear: AI is moving closer to operational decision support.

That makes the control boundary worth designing before decision support becomes exceptional authority. Imagine an AI traffic-management agent infers a cascading disruption from network telemetry and proposes many coordinated route changes. A deterministic broker sees the same emergency state and temporarily relaxes request limits so the changes can proceed.

If both decisions depend on the same poisoned telemetry, the broker is not independent defence. It is a common-mode failure wrapped in a second control layer.

What this diagram shows

Independent supervision requires independent evidence. Two decision layers derived from one compromised observation channel remain one trust domain.

Common-mode decision riskDefence in depth fails when every layer inherits the same corrupted perception of railway state
ObservationPoisoned telemetryOne corrupted state estimate feeds several consumers
Probabilistic layerAI proposesThe agent recommends exceptional route changes
Deterministic layerBroker relaxes limitsThe safety envelope expands from the same false emergency
Independent authorityInterlocking + operatorMovement safety and exceptional authority remain separately governed
Decision gate

Does exceptional authority require corroboration from evidence outside the AI observation and inference path?

YESThe supervisory layer can challenge the AI's perception.
NOMultiple controls still share one failure mode.

Diversity matters more than volume

Ten feeds derived from the same compromised source are still one source. A control layer supervising a probabilistic system should require corroboration from genuinely independent evidence such as separate train-position channels, signalling or infrastructure state outside the AI trust domain, system-health telemetry and, where the consequence warrants it, operator confirmation.

The same rule applies to dynamic availability controls. Static rate limits may block legitimate mass reconfiguration during a real disruption. Dynamic limits can improve resilience, but only if the decision to relax them comes from independently verified operational state rather than from the AI asking for more authority.

When evidence conflicts, automation should narrow and escalation should accelerate. The AI proposes. The deterministic layer constrains. The interlocking preserves movement safety. The operator retains exceptional authority.

The authority rule is consistent with the broader agentic AI control problem: a privileged system should not approve its own expansion of authority. In rail, the same separation principle appears when FRMCS is treated as transport rather than trust: a service can carry evidence without becoming the authority that validates it.

Safety and AI governance meet at the authority boundary

The EU AI Act treats certain AI safety components in critical infrastructure, including transport, as high-risk where failure can endanger life or health, subject to the regulation's application timetable. Railway assurance must also remain compatible with established safety-engineering principles and sector cybersecurity governance.

The engineering question is therefore not whether AI can make useful recommendations. It is which evidence can expand its authority, which independent layer can reject a false state estimate, and which actions remain impossible regardless of the model's confidence.

A deterministic control layer is only independent if its evidence and authority boundaries are independent too.
The decision
Require independent operational corroboration before AI-derived emergency state can relax deterministic limits or expand railway control authority.
Operational checks
  • Map which sensors and data pipelines feed both AI and supervisory controls.
  • Define independent evidence required for exceptional authority.
  • Prevent the AI from self-authorising higher rate limits or broader action scope.
  • Fail toward narrower automation when evidence sources disagree.
  • Keep movement-safety enforcement and exceptional human authority outside the AI trust domain.
Source record

Sources & further reading

← All analysis
Where to go next

Continue this decision.

Choose the next decisionContinue through a guided Reading Path

Move from this analysis into a curated route across related incidents, evidence and operating constraints.