article
Satellite autonomy needs boring failure modes
Autonomy in orbit is valuable precisely where communication is limited, but novelty is least useful during a fault.
Emil Shirokikh · Published September 15, 2026 · Updated September 23, 2026 · 3 min read

Abstract
A spacecraft cannot depend on an operator being immediately available. Autonomous behavior must therefore fail into simple, observable and energy-aware states.
Design the safe state first
Autonomy adds mission value when links are constrained, but a novel recovery behavior is hardest to diagnose when power, sensing or communications degrade.
Failure rehearsal
Enumerate transitions into and out of safe mode. Simulate stale sensors, partial commands, low power and lost contact; define observable telemetry for every transition.
Acceptance evidence
The review artifact is a state-transition table tied to verification cases.
Challenge the conclusion
More autonomy can increase mission yield. It earns that role through verification, not ambition.
Use this in a working session
Ask operators to recover from three injected faults using only the telemetry and procedures expected in mission conditions.
BELTO editorial analysis. It does not describe a client engagement or claim a commercial result.
References
2 sourcesAuthor
Emil ShirokikhFounder
Founder of Belto Inc. Writes on engineering, venture building and applied intelligence.
Related
Read next
Downlink is a product decision
A mission that collects more than it can move has not solved sensing; it has moved product selection into orbit.
The ground segment is the mission
Space programmes celebrate hardware while ground software quietly determines whether operators can command, understand and recover it.
Edge inference after the demo
Running a model once on target hardware is not evidence that it belongs in a mission.