July 18, 2025
Photo credit Sasun Bughdaryan via Unsplash.

Autonomous Shipping’s Achilles Heel – Cybersecurity?

By Mehrangiz Shahbakhsh

 Autonomous Ships: Steel Hulls with Digital Nerves

While we are discussing the development of autonomous ships, one concerning thought that often dominates the conversation is:

“a jobless workforce and a vessel operated by advanced technologies with AI at its centre”

But do we truly understand how Artificial Intelligence (AI)—alongside other advanced technologies like the Internet of Things (IoT), often referred to as the digital nervous system of the modern world—has progressed to the point where it could potentially dominate the job market and replace certain roles traditionally performed by human operators?

In this article, we explore the hidden risks in autonomous ship operations and why cybersecurity, safety, and aligned AI governance should go hand in hand to enable a new, evolutionary model of operational resilience in an era of increasingly cyber-physical connected workplaces.

As you may already be aware, the International Maritime Organization (IMO) is developing Maritime Autonomous Surface Ship (MASS) Code, with the non-mandatory version scheduled for finalisation and adoption in May 2026, followed by an experience-building phase. While the regulatory aspects of autonomous ships are progressing to ensure the safety, security, and environmental soundness of this new class of ships and emerging Remotely Operated Centers (ROCs), a question may arise:

Are we sufficiently and adequately considering and addressing the complexity of advanced technologies, particularly AI, human-AI interaction, and cybersecurity which are among the vital pillars for the safe, secure, and effective operation of autonomous ships?

While the integration of advanced technologies and emergence of remotely operated and autonomous ships offers a promising horizon, the current draft language of the non-mandatory MASS Code does not seem to adequately capture the emerging requirements and risks associated with the deep integration and intertwining of the physical and digital worlds. These risks include, but are not limited to, AI misalignment—where AI systems deviate from intended goals, potentially compromising AI alignment principles, such as robustness, interpretability, controllability, and ethical integrity—leading to unintended or unsafe outcomes; the evolving nature of Human-Automation interaction; and cybersecurity-related issues due to growing system connectivity and dependency to digital-infrastructure. This is especially concerning as the maritime industry moves towards greater reliance on complex technologies and their core functionality and connectivity.

Autonomous Ships & Cybersecurity  

As the operation and functionality of remotely operated and autonomous ships and their associated ROCs heavily rely on digital infrastructure and continuous connectivity as core elements, it is concerning that, in the current draft version of the Code, cybersecurity appears to be treated more as a peripheral concern or an “add-on approach”, rather than as an integral component. This could represent a gap that may be viewed as a potential source of failure over time, as digital risks—including, but not limited to, technical weaknesses, usage-related risks, and a broader digital vulnerabilities such as manipulation risks—may remain a regulatory blind spot, with unclear protections, inadequate measurement and response protocols, and insufficient resilience to handle and recover from cyberattacks.

While the industry gradually shifts towards widespread, interwoven digitalisation, automation, and sustainability—placing AI as a supportive tool at the center of operations across various scales—the safety of autonomous ships and Remote Operation Centers (ROCs), in terms of both system functionality and operation, is becoming increasingly interdependent on both physical security, and, more importantly, cybersecurity, which is emerging as one of the key operational pillars.

That is why Shipping Australia, through different rounds of comments for the MASS Code, has strongly recommended that wherever safety is addressed in the key operational and functional contexts of MASS and ROCs, cybersecurity should be given adequate consideration and appropriate regulatory weight—whether within the same section of the Code, through cross-referenced instruments, or via dedicated annexes or a separate cybersecurity code.

It should also be acknowledged that MASS operations differ from those of traditional ships, and a “one-size-fits-all” approach is not sufficient.

Furthermore, in advocating for cybersecurity to be increasingly recognised as one of the foundational components, alongside safety, in the critical operational sections of MASS—as part of fostering a twin-pillar culture of safe and cyber-secure maritime workplaces—it is also recommended that regulators take into account the limitations and risks associated with AI, alongside its well-recognised benefits.

Autonomous Ships & AI

In simple words, Artificial Intelligence (AI) refers to human-made systems designed to mimic human thinking, learning, and problem-solving. AI was formally introduced as a specialised research field in 1956 at the Dartmouth Conference and has since evolved from basic systems into more advanced ones.

Today, alongside other advanced technologies, AI is being used to analyse and process data collected from various sensors, supporting human operators in decision-making and assisting with specific stages of operational processes. In the context of remotely operated and autonomous ships, and their associated Remote Operation Centres (ROCs), AI is expected to play a significant role.

While AI offers a promising future with many benefits for the maritime industry, it is recommended to remain vigilant about its shortcomings—including limitations under novel conditions, systemic vulnerabilities, lack of transparency, and biases. Broader risks such as misalignment from intended goals, misuse by users, and in some cases, unpredictable or unethical outcomes should also be acknowledged—especially since intelligent systems are not yet capable of replicating human reasoning or consistently adhering to ethical standards. This is particularly concerning when such systems are designed primarily to prioritise efficiency and cost savings, as highlighted by AI research labs and evaluation organisations.

That is why, during the early stages of transition, it is critical to acknowledge that, for safety- and cybersecurity-critical related operations of MASS and ROCs, human operators—where appropriate and critical—should remain either in the loop or on the loop to enable timely intervention and decision making. Regardless of the scale of integration, it is not safe to place partial or complete reliance on AI outputs until the technologies have sufficiently matured, been rigorously approved and validated as safe, and human operators have gained the required competencies and digital resilience to work alongside and coexist safely and securely with AI and other complex technologies in MASS and ROCs operations.

As the recent DeepMind report recommended, as AI matures and more advanced versions—such as Artificial General Intelligence (AGI)—emerge, becoming increasingly capable and potentially able to operate independently with human-level thinking, it is recommended from the outset that such AI systems also be treated with caution, as “untrusted insiders.”

This highlights that, in the context of MASS operations, where AI will be used at various scales and across multiple layers within both MASS and ROCs, gradually becoming more mature and giving rise to new categories, a cautious and structured approach should be adopted from the outset, particularly during the early stage of transition. This should include the development of standard frameworks for feasible continuous monitoring, calibration, and auditing for alignment and compliance check, as well as anomaly detection. Equally important is ensuring appropriate human oversight, along with enabling both technical and ethical intervention and override mechanisms at critical operational levels, regardless of the mode of operation.

Autonomous Ship: AI vs. Human Element

It is important to recognise that AI itself in the context of autonomous ship and ROCs is not inherently dangerous. However, its risks depend on how deeply the maritime industry and regulators understand and govern its structure, safety, security, and behaviours; how it is integrated into MASS, ROCs, and related maritime sectors under a specifically designed framework; and how effectively human operators are trained to thrive alongside AI development—trained to monitor and control both AI and human-AI interactions within the operational context of autonomous ship and ROCs.

While advanced technologies and AI will play a significant role in future maritime operations, we must remind ourselves that they are here to augment—not replace—human operators’ capabilities and cognitive functions. While some jobs may become obsolete, new technology-oriented roles will emerge, as these technologies aim to enhance maritime safety, operational efficiency, and sustainability, in alignment with environmental protection goals. Therefore, training requirements and programs for human operators should evolve in line with the pace of technological advancement and integration within the maritime industry.

As we do not intend to sleepwalk into a future of unregulated or poorly governed AI and technological dominance in our industry—without robust systems and oversight—we must remain vigilant. It can be argued that overreliance on technology, especially when combined with poor training and inadequate digital competencies and resilience among human operators to coexist with, diagnose technological faults, or detect AI-generated errors, could lead to operational incidents in MASS and ROCs. Therefore, a balanced approach is needed—one that ensures full awareness and accountability in AI adoption, while aligning with the training and preparedness of the maritime workforce to work alongside intelligent agents in cyber-dependent environments.

More importantly, we must clearly define the boundaries between humans and intelligent systems (machines, software, AI), which act as two distinct agents in the operation of MASS and ROCs. If these boundaries become blurred—more specifically in the context of critical functions and operational decision-making—it could be considered as a double-edged sword, potentially leading to future challenges concerning liability, accountability, ethics, and safety. Concerns may arise regarding the level of autonomy and the degree of trust placed in software or AI-generated outputs, especially when such systems perform safety- and cybersecurity-critical functions without sufficient human supervision or involvement.

This risk becomes even more serious due to the potential for AI misalignment, as well as the malicious use of AI by hackers. Notably, while AI and digital infrastructure are rapidly advancing, hackers and digital piracy are also evolving—potentially even faster than the knowledge and capabilities of the people and organisations relying on complex technologies and AI to increase safety, security, efficiency, and environmental protection.

Given these risks, we are recommended that the MASS Code ensure human operators’ involvement in critical operational processes, regardless of the mode of operation. It should also address potential risks whether within the Code itself, through cross-referenced instruments, or via dedicated annexes by establishing appropriate mitigation measures, including feasible oversight, intervention, and the development of specific logical, ethical, and technical override protocols.

MASS Code:  Cybersecurity, AI, and Master Responsibility

As the IMO develops the MASS Code to define the operational framework for autonomous ships and ROCs, it is recommended that the Code explicitly outline the respective responsibilities, authority, and accountability of both human operators and software agents (including AI, intelligent systems, or machines). This should ideally be developed by a structured decision-making hierarchy or decision tree. Additionally, the Code should clearly define cybersecurity-related duties, obligation, and escalation protocols.

For instance, the current draft version of the non-mandatory MASS Code states:

“Safe operation of a MASS is the responsibility of the designated Master.”

While the above statement clearly assigns responsibility to designated Master for safe operation of MASS, a question may arise:

What about the cyber-secure operation of a MASS? Who holds responsibility in that context?

Given that the MASS will be increasingly integrated with advanced technologies and AI at its core— with greater complexity across different modes of operations—and considering that the current Standards of Training, Certification and Watchkeeping (STCW) Convention does not require Master to possess advanced knowledge of cybersecurity, emerging technologies, or AI, there is a clear competency gap.

As based on current requirements, it is understandable that many Masters may not be equipped with the necessary skills to independently protect a ship from cyberattacks or respond effectively to incidents involving cyber threats, AI misalignment, or algorithm misanalysis. This competence gap will need to be bridged prior the MASS Code becomes fully operational.

As, additionally this gap raises potential concerns about accountability and liability in MASS operation:

Who could be considered responsible for the cybersecure operation of MASS, or for addressing MASS-AI misalignment? Who would make the final decision in chain of command to protect the MASS vessel during an incident or accident involving AI malfunction or a cyberattack?

As Shipping Australia suggested in its comments on MASS Code development, there could be different scenarios to address this kind of gap, including the possibility that the Master onboard a MASS or operating from a ROC may need to be supported by a counterpart or a technical lead responsible for cybersecurity and AI reliability—indicating that responsibility and accountability for the cybersecure operation of a MASS could potentially be shared between these two roles.

This is an area that requires careful consideration. Therefore, such issues could be addressed either through the Human Element chapter of the MASS Code or through a revised version of a STCW Convention, by developing related training requirements that include, but are not limited to, foundational digital and AI competencies. This would help ensure that Masters are adequately equipped with sufficient knowledge of AI-related risks, functions, and potential misalignments, and are capable of operating MASS safely and securely in cyber-reliant environments.

Recap

While the IMO’s effort to regulate autonomous ships and ROCs through the MASS Code is a significant step forward—helping to make this new class of ships a reality and making an evolution in maritime operations alongside smart and semi- or fully autonomous ports and terminals—it is suggested that this transition be gradually complemented by a shift in mindset and attitude. Traditional operations are evolving towards Human-Automation interaction in increasingly technology-oriented workplaces.

It is recommended that the industry avoid blindly progressing toward a future of heavy reliance on advanced technologies without the support of adequate policies, safe system design, regulation, validation and ethical frameworks—alongside the necessary preparation of human operators to work effectively in a cyber-physical connected workplace.

As we recommended, the MASS Code should explicitly ensure that cybersecurity, AI safety, and accountability for both these aspects are not treated as add-on regulatory approach or as parallel issues, but rather as core, interwoven pillars of MASS and ROCs functionality and operation. These should be embedded alongside safety as part of a twin-pillar culture of safe and cyber-secure workplaces, and must not be left as regulatory blind spots.

For further information refer to the sources below:

Can Artificial Intelligence be trusted?

An Approach to Technical AGI Safety and Security

Current cases of AI misalignment and their implications for future risks

Mind Meets Machine: Towards a Cognitive Science of Human–Machine Interactions

What is AI alignment?

Digital Vulnerability

Autonomous shipping

Report Open AI o1 System Card – OpenAI

Scheming reasoning evaluations

Facebook
Twitter
LinkedIn
Email

Search

Become a Member

Membership is open to all ship owners, operators and agents both Australian and International providing services to or within Australia.

Upcoming Events

Oct 10
Industry Gala Night 2026
Industry Gala Night 2026 – A Masquerade Affair Shipping Australia Limited Queensland is delighted to announce the return of our highly anticipated Industry Gala Night 2026. Following the outstanding success of last year’s sold-out event, we are excited to once again bring together industry leaders, valued partners, sponsors, and supporters for an unforgettable evening of...
Sep 3
SAL’s New South Wales State Committee Spring Luncheon
PROUDLY SPONSORED BY MAIN SPONSOR  SUPPORT SPONSOR    GUEST SPEAKER The Hon. Natalie Ward MLC Shadow Minister for Transport and Roads Deputy Leader of the Liberal Party Sydney Harbour Marriott on Pitt Street, Sydney CBD Thursday, 3 September 2026 1200hrs for 1230hrs  

Latest News

GCMD welcomes DBJ to tackle CO2
The Global Centre for Maritime Decarbonisation (GCMD) and Development Bank of Japan Inc. (DBJ) have announced a five-year Impact partnership to accelerate the adoption of maritime decarbonisation solutions through innovative financing approaches. The partnership combines GCMD’s experience in conducting real-world pilots with DBJ’s transition financing expertise and extensive shipping and maritime portfolio. It builds on...
AMSA’s 2026-2027 national compliance plan is published
A new compliance plan for 2026-2027 has been published by the Australian Maritime Safety Authority. The plan outlines AMSA’s priority compliance activities from 01 July 2026. “The plan helps industry and our compliance partners understand the areas AMSA will focus on during the year. These priorities are informed by inspection data, marine incident trends, investigations,...

Latest Magazine

Shipping Australia Winter 2026
June, 2026

Subscribe to the Signal Newsletter

Be the first to know about releases and industry news and insights or catch up on any editions you missed.

Search