← Maritime AI and Governance

Maritime AI and Governance · Published

AI Governance in Maritime: How to Control AI-Supported Work Through Your Safety Management System

Why approved tools are not enough—and how verification, document control, competence and accountability apply when AI enters operational work.

By Phillip Inzaghi · Founder, AxiomOrdo; Maritime QHSE Specialist · Published 1 August 2026

Maritime officer reviewing AI-supported information onboard a vessel

AI is already influencing safety management systems, audit reports and operational decisions inside maritime companies—often without formal approval or governance.

The question is no longer whether people are using AI. It is whether companies know where, how and under what controls it is being used.

The risk is not simply that people use AI. The risk is uncontrolled data, unchecked output and misplaced accountability.

It may be used to draft risk assessments, summarise procedures, prepare toolbox talks, rewrite audit findings, compare requirements, or make safety management documents sound more polished. Some of that use may be helpful. Some of it may be harmless. Some of it may create serious control problems.

The mistake is treating AI governance as a choice between “ban it” and “allow it”.

That is too crude.

The real question is operational: what information is being entered, what output is being produced, who checks it, what evidence supports it, and who remains accountable when AI-supported material enters company use.

At the time of writing, I have not identified an IMO instrument specifically governing routine employee use of generative AI for tasks such as drafting risk assessments, preparing toolbox talks, reviewing audit findings, summarising regulations, or supporting safety management documentation. IMO has adopted a non-mandatory code for AI-enabled and remotely operated autonomous ships, but that is a different regulatory problem.

That does not mean companies should wait.

It means AI use has to be controlled through existing governance duties: safety management, competence, verification, confidentiality, document control, and accountability.

The First Misunderstanding: AI Is Treated as an IT Issue

Many companies will first see AI as an IT or cybersecurity issue.

That is partly correct, but incomplete.

Tool access, account type, data retention, permissions, and security settings matter. A company-approved enterprise AI tool is not the same risk as an employee pasting vessel, client, investigation, or personal data into an uncontrolled personal account under time pressure.

But tool selection does not solve the maritime governance problem.

A better-controlled tool may reduce some risks. It does not remove the need for review, competence, document control, or operational judgement.

The company still has to decide:

  • what may be entered into AI tools
  • what must never be entered
  • which tools are approved
  • which tasks require verification
  • who is competent to review the output
  • how AI-supported work is recorded where evidence matters

Without those controls, AI becomes an informal parallel system. It can influence safety documents, audit records, investigation material, and operational decisions without being visible inside the company’s actual management system.

Existing Duties Already Cover the Control Problem

The ISM Code does not regulate AI.

But AI-supported work can enter areas the safety management system already controls: procedures, risk controls, competence, records, investigations, audits, review, and company accountability.

AI Governance QuestionExisting SMS Control Area
Who remains accountable if AI-supported material is used?Company responsibility and authority
Can this output be used operationally?Approved procedures and shipboard operational controls
Who is competent to check it?Resources, personnel, competence, and familiarisation
Has the source been verified?Company verification, review, and audit
Can the document be changed casually?SMS documentation and revision control
Could this distort a finding, incident, or corrective action?Reporting and analysis of non-conformities, accidents, and hazardous occurrences

Existing maritime regulation was not written for AI.

However, AI can affect work already controlled by the safety management system. Once AI-supported material enters that system, it still has to be checked, approved, controlled and owned by the company.

The Second Misunderstanding: Polished Output Is Treated as Reliable Output

AI output often sounds confident.

That is part of the problem.

In maritime compliance and safety work, a well-written answer is not the same as a verified answer. A risk control can sound sensible and still be unsuitable. A regulatory reference can look plausible and still be wrong. A summary can appear balanced while omitting the controlling requirement.

Early in my own use of AI, I asked it to help identify an ISM Code reference for a finding. It produced a reference that sounded plausible. When I checked it against the Code, the reference did not exist.

That was the point where the issue became clear: custom instructions are not controls, and confident output is not evidence.

The same issue applies to AI-assisted review. A tool can appear to review a document while filling gaps with plausible content that is not actually present in the source.

In audit, compliance, and safety work, that is not a harmless drafting issue. It can create false findings, false assurance, wasted review time, and misplaced confidence.

The control is simple in principle, but often missing in practice:

AI output must be checked against the source before it is relied on.

Confident output is not evidence.

If the output cites a regulation, the regulation must be checked.

If it summarises a procedure, the procedure must be checked.

If it proposes a control, the control must be assessed by someone competent to judge whether it is suitable for the operation.

If it drafts safety management content, the company must still decide whether that content is correct, controlled, and approved.

The Third Misunderstanding: Accountability Moves to the Tool

AI does not take responsibility.

The person using the output remains responsible for deciding whether it is suitable. The company remains responsible for the management system it operates. A vessel, department, auditor, DPA, superintendent, HSE manager, or master cannot avoid accountability by saying that a tool produced the wording.

This is where maritime companies should be careful.

AI can make weak work look complete. It can make uncertain work look confident. It can make generic controls look like a finished risk assessment. It can make an inexperienced user feel as though they have produced something more reliable than they actually have.

That does not mean AI should never be used.

It means AI should be treated as an assistant, not an authority.

What Controlled Use Looks Like

A practical maritime AI governance model does not need to begin with a 40-page policy.

It should begin with clear operating rules.

At minimum, companies should define:

  • approved AI tools and account types
  • prohibited information and upload rules
  • permitted and prohibited task types
  • review requirements for AI-supported outputs
  • source verification requirements
  • document control requirements
  • record retention where AI materially supports a decision or controlled document
  • competence expectations for users and reviewers

The strongest control is not the tool itself. It is the workflow around it.

The strongest control is not the tool itself. It is the workflow around it.

A Practical Governance Workflow

The workflow can be expressed through four connected controls:

CONTROL

Define the approved tool, permitted task and information boundaries.

VERIFY

Check claims and proposed controls against the authoritative source and operational context.

APPROVE

Require a competent person with the proper authority to accept or reject the output.

RECORD

Retain the evidence, review and document history where the output affects a controlled decision or document.

Human and organisational accountability applies throughout every stage. It does not appear only at the end of the process.

For example, using AI to improve the readability of a toolbox talk is a different risk from using AI to generate the underlying task risk assessment. Summarising a public guidance note is different from uploading an incident report. Drafting general training prompts is different from asking AI to classify audit findings against a code or regulation.

Those differences matter.

A governance system should separate low-risk support tasks from tasks that could affect safety, compliance, legal exposure, client confidentiality, or operational decision-making.

AI should be treated as an assistant, not an authority.

A Simple Control Test

Before using AI in maritime QHSE, SMS, audit, or operational assurance work, the user should be able to answer four questions:

  1. Am I allowed to enter this information into this tool?
  2. Is this the right type of tool and account for this task?
  3. What source will I check the output against?
  4. Who remains responsible if this output is used?

If those questions cannot be answered, the task is not controlled.

The Real Risk Is False Assurance

The danger is not that AI makes a spelling mistake.

The danger is that AI-supported work enters the business looking complete, reviewed, and authoritative when it has not been properly verified.

That matters in maritime because many documents are not just documents. They are part of a safety management system. They shape work planning, risk control, training, audits, investigations, corrective action, and management review.

If AI helps draft or review that material, the company needs to know where the output came from, what source supports it, and who checked it.

Otherwise, the company may create the appearance of control without the substance of control.

The Operational Dilemma

Master reviewing an officer's hours-of-rest disclosure and compliance records

A deck officer hands the Master a written statement.

For the past two weeks, the officer has been signing rest hour records showing full STCW compliance while actually working beyond legal limits. The vessel is short-handed, the watch schedule is stretched, and the officer has been covering gaps to keep operations moving.

He is now dangerously fatigued and afraid he will make a navigation error. He comes clean because he would rather face discipline than cause a collision.

The vessel docks tomorrow for port state control. The rest hour records will be audited. The SMS requires immediate reporting of falsified legal records, disciplinary action, and correction of the official record.

The Master now has two bad options.

OptionImmediate OutcomeGovernance Risk
Correct the records, stand the officer down, and follow the SMS.The record becomes honest. The vessel may face a clear STCW violation, possible detention, and operational disruption. The officer may be disciplined for admitting the truth.The crew may learn that honesty destroys the person who reports the problem, making future fatigue reporting less likely.
Protect the officer, adjust the watch schedule quietly, and leave the records unchanged.The vessel may pass inspection. The officer keeps his job and the crew sees that coming forward is protected.The Master has knowingly retained falsified legal records. If discovered, the issue becomes concealment, not just fatigue management.

That is the governance problem.

A system that only punishes the falsified record may discourage the next exhausted officer from speaking up. But a system that protects honesty by preserving false records destroys the integrity of the SMS and exposes the Master to personal liability.

Good governance has to deal with both truths at the same time: falsified legal records cannot be ignored, and fatigue reporting cannot be treated as betrayal. If the only available choices are concealment or career destruction, the system has already failed before the officer walks into the Master’s office.

Key Takeaways

  • Maritime AI governance is a management-system issue, not simply an IT issue.
  • Existing safety management controls already provide much of the necessary governance framework.
  • AI-supported outputs must be verified against authoritative sources and the actual operational context.
  • Accountability remains with the people and organisation using the output.
  • Practical operating controls matter more than lengthy AI policies.

Conclusion

Maritime companies do not need to wait for AI-specific IMO guidance before acting.

The basic control problem is already visible.

AI use should be governed through the same principles that already apply to safety management and assurance: controlled information, competent people, verified sources, approved documents, clear accountability, and evidence where evidence matters.

The companies that handle this well will not be the ones with the longest AI policy.

They will be the ones that make AI use visible, controlled, and reviewable before it affects operational work.

AI will continue to evolve. The principles of good governance will not. Companies that embed AI within their existing management systems, rather than allowing it to operate alongside them as an informal parallel process, will be better placed to use the technology safely, consistently and with confidence.