Unit 11 / 11

End-to-End Workflow, Ship-Company Governance, Cyber Security and Responsible Use

Gains:

  • Ability to consistently deploy AI at every stage of the campaign, from the beginning to the end, with human verification gates and decision records
  • Ability to establish a ship-company governance framework including approved vehicle list, data classification, ISM integration, cyber security (critical system isolation, data confidentiality, redundancy)
  • Ability to embed human responsibility, transparency, avoidance of excessive claims, safety-environment priority and confidentiality principles into the workflow

Previous units processed AI individually in route, fuel, weather, documentation, cargo, machinery monitoring, diagnostics, legislation and bridge decision support. This unit combines it all: how to position AI consistently, controllably and safely from the beginning to the end of a campaign. How do the ship and company manage this? And how are these tools themselves (data, connectivity, cybersecurity) protected? The aim is to establish a framework that captures the value of AI in maritime while never forgetting its safety-critical nature.

End-to-end workflow: human verification gates

Think of an expedition as a chain; Put a human verification gate (the point at which a human confirms that a condition is met before passing) on each ring:

  1. Voyage planning: AI generates route/fuel alternative → Gate: captain confirms and confirms UKC/no-go and restrictions in ECDIS.
  2. Weather monitoring: AI forecast summaries → Gate: multi-source + official warning confirmation, decision to take shelter is up to the captain.
  3. Cargo: YZ stowage recommendation → Door: loading computer with stability/strength approval, chief officer approval.
  4. Machine: AI anomaly sign → Door: physical verification, diagnosis and maintenance decision is up to the chief engineer.
  5. Documentation: AI blueprints → Gate: real data verification and signature in human.
  6. Legislation: AI directs → Gate: provision is verified from the official source.
  7. Bridge: AI prioritizes → Gate: COLREG maneuver and navigation decision is in the officer's hands.

Rule: without passing one door, you cannot move on to the next. This layered structure prevents a single AI bug from leaking into the expedition or report. Every door leaves a record: what was proposed, who confirmed it, what was decided.

Tip: Keep a short “decision log” for each AI use: which tool, what input, what the AI ​​said, how it was verified, who approved it. In an accident investigation or audit, this record protects you and enables continuous improvement.

Ship-company governance

AI tools should not be used randomly, but within a framework:

  • Approved tool list: Which AI tools are approved for which jobs? Sensitive data is not uploaded to random tools and public services.
  • Data classification: Freight manifest, route, commercial contracts, crew personal data are sensitive; It is defined which data goes where.
  • Role and authority: Who can use AI in which decision, who approves it? The captain and chief engineer have clear final say.
  • Training: Crew must know the limits of AI (hallucination, ambiguity, verification); Discipline is taught rather than tools.
  • ISM integration: The use of AI is procedurally added to the ship's safety management system (ISM); becomes auditable.
  • Continuous verification: The performance of vehicles is monitored; Incorrect suggestions are recorded and the tool or usage is revised.

Cybersecurity: a tethered ship is a target

The modern ship is a connected system: ECDIS updates, satellite communications, remote monitoring, AI services. This connection is an attack surface. Maritime cybersecurity (also associated with IMO's ship cyber risk management guidelines and ISM) cannot be neglected:

  • Isolate critical navigation/machinery systems: Systems such as ECDIS, machinery control are kept separate from the internet and AI tools.
  • Data privacy: Route, cargo and commercial data must not leak to insecure AI services; mask if necessary.
  • Risk of manipulation: GPS/AIS signal may be spoofing; With this corrupted data, the AI ​​produces wrong suggestions. Input security is a prerequisite for output security.
  • Redundancy: If the system crashes or a cyber incident occurs, traditional navigation (paper map, basic procedure) capability is preserved.
Caution: Any data you load into an AI tool may be out of your control. Ship location, cargo details, crew information and trade secrets; processed in an approved, safe and, if necessary, masked manner. Pasting sensitive data to a public service "for convenience" is a serious breach of security and privacy.

Ethical and responsible use

  • Human responsibility: Every safety-critical decision is made by a competent human; The AI's output is not a substitute for its approval.
  • Transparency: When AI is used (especially in reporting and analysis) it is stated honestly.
  • Avoiding overclaiming: A vague estimate is not presented as a certainty; The level of trust is expressed honestly.
  • Environment and safety priority: Commercial gain never comes before maritime safety and environmental protection.
  • Privacy: Crew and commercial data are protected.

three mini cases

Case 1 — The door system stops an error. On a ship, AI suggests a route to save attractive fuel; but at the "voyage planning gate" the captain finds a flaw in the ECDIS confirmation and rejects the proposal. The tiered door prevents the bug from passing into the sea. The decision record documents that the process is working correctly.

Case 2 — Data leakage is prevented. An officer is about to paste the cargo manifest into a public AI service; company policy (approved tool + masking) prevents this. Business data is protected. Lesson: governance framework prevents well-intentioned but risky behavior.

Case 3 — Fake GPS signal. GPS spoofing occurs in an area; AI recommends an incorrect course correction with corrupted location data. The team confirms the location by independent methods (radar, eye, cross bearing), notices the deviation and rejects the AI ​​proposal. Lesson: if the input is corrupt, the output is also corrupt; Independent verification and redundancy save lives.

Four copyable templates

1) End of campaign AI usage audit:

This time I used AI for: [list]. Draft a decision record table for each: work, tool used, input, AI output, how verified, who approved, result. Mark any that remain missing/unverified.

2) AI usage policy draft:

Write a DRAFT of a "responsible use of AI" procedure for our ship: approved tools, data classification, who approves which decision, verification obligation, cybersecurity and privacy rules. Note: this draft will be approved by the company DPA/ISM team.

3) Data masking control:

Check for sensitive data before entering the following text into an AI tool: [text]. Suggest ship location, cargo detail, personal data, trade secret and how I can mask it. If you are not sure, say "don't enter, check first".

4) Cyber/redundancy exercise scenario:

Produce a cyber incident or system crash scenario on bridge/machine systems; Write a 5-step drill outline and discussion questions that will help the crew practice their transition to traditional navigation/engine management.

Weak prompt / Strong prompt

Weak prompt:

How do I use AI on the ship?

Very general; There is no security, data, governance and verification dimension.

Powerful prompt:

Your role: ship digitalization consultant. Ship type [x], company affiliated with fleet management. Task: draft an end-to-end framework for the use of AI in route, fuel, machinery tracking and documentation: human verification gate at each stage, approved vehicle and data rules, cyber security measures, decision recording. Emphasize that safety-critical decisions remain human and AI is not a substitute for approval. Mark areas that are unclear/require company approval.

Requiring gates, governance, and cybersecurity makes the output enterprise-usable.

End-to-end frame table

Stage

AI contribution

human verification gate

Expedition planning

Route/fuel alternative

Captain ECDIS approval

weather monitoring

Forecast summary

Multi-resource + captain

cargo

Stack recommendation

Loading computer + 1st officer

machine

anomaly sign

Physical confirmation + chief engineer

Documentation

draft

Real data + signature

legislation

redirect

Official source confirmation

bridge

prioritization

COLREG decision, officer

Common mistakes

  • Bypassing verification gates. Removing intermediate confirmations for speed will allow the single error to leak into the expedition.
  • Not keeping a record of decisions. If there is no record, defense and improvement in audit and investigation becomes difficult.
  • Giving sensitive data to an insecure tool. Route, load, personal data are processed with approval and masking.
  • Not isolating critical systems. ECDIS/machine control is kept separate from the internet and AI tools.
  • Neglecting redundancy. Conventional navigational capability must be maintained in the system/cyber incident.
  • Putting commercial profit before safety. Safety and the environment are always a priority.

In summary

The key to using AI end-to-end in maritime is a layered framework that puts a human verification gate and a decision record at each stage. This framework is complemented by ship-company governance (approved instrument, data classification, role, training, ISM integration), cybersecurity (critical systems isolation, data confidentiality, input security, redundancy) and principles of responsible use (human responsibility, transparency, avoidance of excessive assertion, safety priority, confidentiality). AI creates real value in shipping; But safety-critical decisions are always owned by a competent human, and AI output does not replace that approval.

Application task

Consider a start-to-finish expedition for your own ship. For each stage (planning, air, cargo, machinery, documentation, regulatory, bridge), fill out a one-line “what does AI do / what is human gate / how do I verify / who approves” table. Then add a “data masking” and a “cyber/redundancy” measure. Finally, create a template of the decision record you will keep this time.

checklist

  • [ ] I placed a human verification gate at each stage.
  • [ ] I kept a record of decisions for each AI use.
  • [ ] I have complied with the approved tool and data classification rules; I protected/masked sensitive data.
  • [ ] I isolated critical navigation/machinery systems and maintained redundancy capability.
  • [ ] I have ensured that security-critical decisions are made by a competent human and are not a substitute for AI approval.

Module Exam

1. Which of the following is the most accurate positioning for artificial intelligence in maritime?

  • A) Artificial intelligence is a decision support tool; Responsibility for safety-critical decisions such as route confirmation, maneuvering and machinery decisions remains with the captain and chief engineer ✔
  • B) Since artificial intelligence is more reliable than humans at sea, route and maneuver decisions should be left to it.
  • C) Artificial intelligence only works in summarizing text, it has nothing to do with navigation and machine work
  • D) Artificial intelligence can enter the route into ECDIS and execute it without human approval

Description: Maritime is a security-critical area; Artificial Intelligence is a decision support tool that saves time in route, fuel, weather, documentation, machine monitoring and legislation. However, it is the captain and chief engineer who are legally responsible for maritime safety, environment and property security; manoeuvring, machine stopping and emergency decisions are human, and artificial intelligence output is not a substitute for competent expert approval.

2. What is the most critical step to take before executing a route alternative suggested by artificial intelligence?

  • A) Check the route against no-go areas in ECDIS and UKC and approve it by the captain ✔
  • B) Directly executing, not making additional checks, as artificial intelligence calculates it
  • C) Making sure you only choose the shortest distance
  • D) Switching to the one that saves the most fuel without checking the route at all

Description: The route generated by artificial intelligence is a draft and has not been verified on the official map. No route is run without checking ECDIS for no-go areas and sub-keel clearance (UKC) at tide. Time/fuel savings can never outweigh this security confirmation.

3. What is the most accurate approach when having artificial intelligence predict consumption for fuel optimization?

  • A) Assuming a general ship model and asking for the lowest fuel consumption without giving constraints
  • B) Basing the estimate on the actual performance curve of the ship and giving commercial-legal constraints ✔
  • C) Applying the first number given by artificial intelligence without verifying it
  • D) Just reducing the speed is sufficient; charter and port window are irrelevant

Explanation: The prediction produced by assuming a general 'ship model' may be seriously offended on your ship. The estimate should be based on the ship's actual performance curve (sea trial and service data); Additionally, commercial-legal restrictions such as charter minimum speed and port window should be given. Trim/speed changes are also applied with human approval at the limit of stability and machine health.

4. What can be said about a CII (carbon intensity indicator) value calculated by artificial intelligence?

  • A) Can be declared directly as official CII report
  • B) It is only a prediction; The official report is produced by an approved method and must be confirmed with an up-to-date source ✔
  • C) It is always true because artificial intelligence calculation is better than human
  • D) There is no need for confirmation since emission thresholds have never changed

Explanation: Emission figures such as CII are official outputs produced by approved methods and verified data. The value given by artificial intelligence is only a prediction; can use old coefficient or produce hallucination. It cannot be used as an official report and must be confirmed with an up-to-date official source.

5. What makes artificial intelligence most valuable in weather and sea state assessment?

  • A) Based on a single model and giving a precise wave height
  • B) Hiding uncertainty and presenting every prediction as certainty
  • C) Comparing different models and making separation and uncertainty visible ✔
  • D) It replaces official maritime warnings and makes them unnecessary.

Explanation: Weather forecasting is probabilistic and the most important magnitude is uncertainty. AI is most valuable when it compares different models and makes divergence (and therefore uncertainty) visible; This ensures planning on the safe side. It is dangerous to hide uncertainty and present the central prediction as certainty.

6. What is the constant principle when preparing content with artificial intelligence for a cruise log or official incident report?

  • A) Having artificial intelligence complete incompletely remembered details in a reasonable manner
  • B) Only the actual observation is recorded; Artificial intelligence cannot make up data or details, missing places are marked ✔
  • C) If the text is fluent, the numbers and events added by artificial intelligence are accepted without verification.
  • D) Artificial intelligence can estimate time and location information, there is no need for observation

Explanation: Official records are legal evidence and their content must correspond exactly to the truth. Artificial intelligence cannot fabricate time, location, speed and event information; It simply translates the actual observation you give into a proper sentence. The missing place is not filled with 'reasonable fiction', it is marked; The responsibility for accuracy and signature lies with the human. Otherwise, there is a risk of forgery of documents.

7. How should the ship's stability (GM) and longitudinal strength be determined in the loading plan?

  • A) Relying on the rough GM and trim value given by artificial intelligence
  • B) Calculated on the approved loading computer and approved by the chief officer/captain ✔
  • C) Estimated by experience, without using any tools
  • D) Only looking at the total weight, without considering the weight distribution

Description: Stability and strength are safety-critical; one mistake could topple the ship or damage the hull. These calculations come only from the approved loading computer and are approved by the chief officer/captain. A rough GM value given by the AI ​​is not an official calculation; for example, it may miss the effect of free fluid and falsely make the ship appear 'safe'.

8. What should be the role of artificial intelligence in the separation and stacking rules of hazardous cargo (IMDG)?

  • A) Artificial intelligence gives the exact separation rule and the stacking plan is directly applied
  • B) Discrimination rules are determined by the general knowledge of artificial intelligence, no formal code is needed
  • C) Artificial intelligence guides which section to look at; exact separation/stacking rule confirmed from official IMDG Code ✔
  • D) No separation rule is required for dangerous loads, they can all be stacked together

Explanation: If some hazardous substances are placed side by side, they may react and cause fire or explosion. AI can remind you which UN number and IMDG section to look at; however, the exact separation/stacking rule must be confirmed from the official IMDG Code. AI may give an outdated or incorrect rule, so the official code determines the final decision.

9. How should one act when AI flags an anomaly in machine sensor data (for example, a deviation in the exhaust temperature of a cylinder)?

  • A) The signal is considered a definitive fault and the equipment is stopped immediately.
  • B) The signal is a hypothesis; It is evaluated in context, physically verified and the diagnosis-maintenance decision remains with the chief engineer ✔
  • C) There is no need for additional verification because artificial intelligence says it
  • D) If the artificial intelligence does not say anything, it is assumed that the equipment is absolutely healthy

Explanation: Artificial intelligence saying 'there is an anomaly/malfunction' is a hypothesis, not a diagnosis. The deviation is first evaluated in context (could it be a load, air, speed change), then it is verified physically (gauge reading, equipment check) and the diagnosis-maintenance decision remains with the chief engineer. Additionally, the silence of artificial intelligence is not a guarantee of 'no problem'.

10. How to use artificial intelligence when many alarms (alarm floods) sound at the same time in the engine room and what is its limit?

  • A) Artificial intelligence determines the root cause and automatically makes the decision to stop the machine
  • B) Artificial intelligence generates root cause hypothesis; the hypothesis is physically verified and the decision to stop/intervene remains with the engineer ✔
  • C) If one of the alarms is silenced, the others will also pass, there is no need for verification.
  • D) AI's root cause ranking is accurate even if timestamps are incorrect

Description: A fault often triggers a chain of secondary alarms; The root cause is single. AI can sort through the timestamped alarm log and generate a root cause hypothesis. However, this hypothesis must be verified by physical indicators, and decisions such as stopping the machine or disabling the safety trip belong to the human engineer; cannot be automated.

11. How should AI be used when a precise article number or numerical threshold is required in legislation such as SOLAS?

  • A) The item number and threshold given by artificial intelligence are written directly into the report.
  • B) Artificial intelligence guides; The exact substance and threshold are read and confirmed from the current official source ✔
  • C) Since the rules do not change, artificial intelligence's knowledge is always up to date.
  • D) Saying 'artificial intelligence said so' is a valid basis in auditing

Description: Artificial intelligence can convincingly make up an item number, date or threshold value that does not actually exist (hallucinate), and the rules are constantly updated. Therefore, AI is used only as a guide to which contract/code and topic to look at; The verdict is always read from the current official source. In an audit, 'artificial intelligence said so' has no validity.

12. What is the role of artificial intelligence/automation in the bridge collision avoidance (COLREG) maneuver decision?

  • A) The system gives the maneuver order and the officer executes it
  • B) The system prioritizes goals and directs attention; The maneuver decision belongs to the officer and the captain within the framework of COLREG ✔
  • C) It is sufficient to rely on AIS; Radar and visual confirmation is not required
  • D) The officer can leave control because the automation works reliably

Description: Modern systems can calculate CPA/TCPA and prioritize targets; This is valuable in directing the officer's attention. However, the decision to maneuver - how many degrees, when, which direction - belongs to the officer of the watch and the captain within the framework of COLREG and good maritime practice. Even if the system says 'pass safely', the responsibility for the collision lies with the officer who performed or did not perform the maneuver.

13. Why is 'automation complacency' (over-reliance on automation) dangerous on the bridge?

  • A) It is not dangerous; If the system is reliable, there is no need to look visually.
  • B) It reduces human attention and creates dependence on a single source; Missing data such as boat without AIS may be missed ✔
  • C) It is a problem only because it increases fuel consumption.
  • D) Only seen on old ships, there is no risk on modern bridges

Explanation: As systems operate reliably, human attention may wane and control may be abandoned. Whereas a small boat without AIS is only visible to radar and eyes; The system operates with incomplete data. Therefore, radar, AIS, ECDIS and eye should cross-confirm each other, and when sources are separated, the most dangerous interpretation should be taken as basis.

14. What principle applies before entering ship location, cargo manifest, or crew information into an AI tool?

  • A) Sensitive data can be pasted directly into a public service for speed
  • B) Data classification is unnecessary; Any data can be entered into any vehicle
  • C) Sensitive data is processed only in approved, secure tools and masked when necessary; critical systems are isolated ✔
  • D) Crew and commercial data are not sensitive and do not need to be protected

Explanation: Data uploaded to an AI tool can get out of control. Route, cargo details, commercial contracts and crew personal data are sensitive; It should only be processed in approved, safe vehicles and masked where necessary. Pasting sensitive data to a public service 'for convenience' is a serious breach of security and privacy. In addition, critical navigation/machinery systems are isolated.

15. What is the most effective way to use AI consistently and safely from the beginning to the end of a campaign?

  • A) Establish a layered framework that puts a human verification gate and decision record at each stage ✔
  • B) Delegating all expedition decisions to a single AI tool and taking a look at the end
  • C) Remove intermediate verifications for speed and only check on arrival
  • D) Each officer can use his own vehicle freely without keeping a record of decisions.

Description: The voyage is thought of as a chain, with a human verification gate and a transition condition placed at each stage (planning, air, cargo, machinery, documentation, legislation, bridge); You cannot pass through one door without passing through another. Every door leaves a record of decision. This layered structure prevents a single AI error from leaking into the expedition or report and provides defensibility in the audit.