Week 43 | October 2026
On the Lavik–Oppedal crossing in western Norway, Fjord1 is working toward ferries that cross and dock autonomously, overseen from an onshore control centre in Florø. Between ship and shore sits Telia's 5G network, which Telia describes as the backbone of the operation. Fjord1's IT manager, Ørjan Midttun, put it more bluntly: "Without reliable 5G, the ferries could not operate safely or efficiently."
That's an honest sentence, and Telia hasn't left it to chance. It has built dedicated 5G masts either side of the fjord, with public mobile networks and then Starlink as fallbacks. If all of it fails, Fjord1 says the ferries go to a minimum risk condition and stop.
So how good does each layer have to be, and how long can the silence last before the ferry stops? I went to the adopted text of the IMO's MASS Code to find out. The answer, in the Code's own words, is "adequate".
Why the link carries the weight
In the Week 37 brief I asked where the captain was. The Code's answer was that a human master keeps overall responsibility even from a remote operations centre (ROC) hundreds of kilometres away. Follow that through. If the person accountable for the vessel is ashore, the data link to them is the only route command has to the ship. Lose it and what's left is a hull and a fallback routine.
My Week 16 Deep Dive covered what an attacker can do to that link. This brief is about what anyone is required to build.
New in the archive: the September Maritime Deals Tracker. Seasats booked more than US$24 million in committed Navy and Marine Corps orders in a single month, and Saildrone won a US$10 million Navy seafloor-mapping task order. The tracker breaks down what each deal actually buys.
The opening analysis is free to read. Read the tracker
What the Code actually says
The International Code of Safety for Maritime Autonomous Surface Ships (Code) was adopted as resolution MSC.595(111) on 21 May 2026 and has been open for voluntary use since 1 July. Chapter 17 is titled Connectivity. Its goal is a link between vessel and ROC that is maintained and "sufficient for the effective monitoring and/or control of MASS functions".
The requirements underneath have teeth, in places. Connectivity must hold at capacity after a single failure (17.2.5). Transmitted data must be integrity-checked and come from authorised, authenticated sources (17.2.10). Performance has to be monitored against stated requirements, with a fallback state when it degrades (17.2.9).
None of that is soft. Read the chapter again, though, and look for a number.
There isn't one. The chapters either side of it, 16 and 18, set out "Expected Performances" under their functional requirements. Chapter 17 has none. Quality of service must be "adequate to ensure the safe operation of MASS", taking into account bandwidth, data integrity, reliability, resilience and latency (17.2.3). Adequate against what? The Code sends you to the ROC Record, the document attached to each ROC's certificate. Under 5.3.3.3, that Record holds the connectivity infrastructure "and its performance and quality of service as accepted by the Administration".
That clause is where the standard lives. The Code fully expects numbers: the ROC Record has a field for bandwidth and latency, and 17.2.9 measures performance against "stated requirements". So every ROC writes its own figures down, and the only floor under them is whatever each flag state accepts, one ROC at a time.
Redundancy follows the same path. The single-failure rule is fixed, but how many links there must be, and how independent, goes to the risk assessment (17.2.6). Encryption isn't mentioned at all. The nearest the Code gets is one line: "measures should be taken to protect the security of transmitted data". Its footnote points to the IMO's general cyber-risk guidelines, and a neighbouring one to the IACS cyber rules. No algorithm. No named standard.
Class: one outlier and a lot of risk assessment
If the Code delegates, you'd expect the classification societies to fill the gap. Some have tried, and one has gone well past the others.
ABS's Requirements for Autonomous and Remote Control Functions (October 2024) are mandatory for its AUTONOMOUS and REMOTE-CON notations, and they get specific about the link. For medium- and high-risk functions, data flows and command paths between vessel and remote station must be protected in both directions, and the network has to keep critical tasks running through a single failure and through intermittent loss. Where voice communication is needed, two channels are required, and the shore station needs uninterruptible power sufficient to hand off control safely. Most strikingly, link testing happens with surveyors attending at both ends, ship and ROC, checking what losing and degrading the connection does. That is class reaching ashore.
And the latency requirement? Network latency must be "sufficient for the required latency of the function". Circular, by design.
Everyone else stops short of ABS on verification, though not always on design. DNV's class guideline for autonomous and remotely operated ships calls for at least two independent communication channels, preferably on different technologies and suppliers, with full capacity through a single failure. Maximum latency, though, is whatever the applicant specifies, and DNV's own senior principal engineer describes the risk-based approach behind its newer AROS notations as "not prescriptive in nature and is deliberately broad".
IACS UR E26, mandatory for new cargo ships of 500 GT and above on international voyages contracted from July 2024, treats anything outside the ship's scope as an untrusted network, so a ROC counts. It requires authenticated, encrypted tunnels across that boundary. That's a real floor, though it governs the ship's side only. Bureau Veritas has the one notation I found built specifically for the ship-shore control link, SYNC-COM (SYNC-COM-R where the system is redundant), granted in principle to Seafar in 2024.
Where the gap is widest
This is the part procurement offices should sit with. The Code applies to SOLAS cargo ships, and then only when the flag state deems other instruments impracticable or insufficient. For vessels under 500 GT, the IMO merely invites governments to apply it "as far as practicable". Warships and other government non-commercial vessels are excluded outright.
That carve-out covers most of what's being delivered right now. Small commercial survey USVs. Navy drone boats.
Military buyers aren't working from a stricter rulebook either. The US Navy's Unmanned Maritime Autonomy Architecture, the interface standard its autonomy vendors build to, says it is independent of specific cybersecurity measures and that compliance is handled "on a program-specific basis". When the AUKUS partners ran their 2025 maritime innovation challenge on undersea communications and autonomy, encryption was "highly desirable".
So both sides delegate: commercial operators to the flag state, defence programs to the individual program office. Nobody publishes a common floor.
What's being shipped
Builders publish the shape of their links, and occasionally a number. Seafar runs its remotely operated fleet across multiple 4G and 5G operators with automatic switching to satellite, and advertises an average latency of 42 ms inside an encrypted tunnel. Sea Machines advertises wireless IP, cellular and satellite with failover. Saildrone sends data home over Starlink and Iridium. Fjord1's stack is above. I couldn't find a builder that publishes its encryption scheme or how many seconds of silence trigger a fallback. That's probably deliberate. Publishing it would hand an attacker the map.
No accident investigator has yet published a finding that pins an autonomous vessel event on link loss. The most advanced case is the MAIB's investigation into the September 2025 collision between the crew transfer vessel Iceni Legend and XOCEAN's remotely piloted survey USV X18, which sank. The MAIB says its investigation is complete, with a draft report being prepared for a 30-day stakeholder consultation. Its scope includes how the two vessels could see and communicate with each other. The cause isn't public yet.
The best public evidence of what link loss looks like comes from the Navy rather than an accident board. Reuters reported in April, from internal Navy documents, that a global Starlink outage in August 2025 left two dozen uncrewed surface vessels off California unable to connect, halting operations for almost an hour. An earlier Navy safety report found Starlink struggled under the load of controlling multiple vehicles. It's the same constellation at the bottom of Fjord1's stack and carrying Saildrone's data home. Redundancy chosen one ship at a time can still share a single point of failure across a fleet.
The best case against me
Goal-based regulation is deliberate. A ferry crossing a Norwegian fjord inside 5G coverage and a USV loitering 400 nautical miles offshore need completely different links, and any single latency figure in the Code would be wrong for one of them. E26 already forces encryption at the ship boundary. ABS already makes surveyors pull the plug and watch what happens, and insurers will price whatever the rules miss: the International Group's P&I clubs opened pooled cover to MASS in July, and shipping lawyers expect cyber resilience to be on the underwriting list.
That's a serious argument. Its weak point is verification. Without Expected Performances in Chapter 17 there's no common test of whether a link is adequate, so two Administrations can certify materially different architectures and both be compliant. The rules the argument leans on don't reach the gap either. E26 is only guidance for warships and cargo ships under 500 GT, and ABS's both-ends testing applies only to ships carrying its notations. Insurers aren't closing that yet. Stephenson Harwood's July rundown of what underwriters will assess ties cyber risk to other chapters of the Code. Connectivity, Chapter 17, isn't among them.
So what?
The voluntary phase runs for at least two years. Its purpose is to generate the operating experience that becomes the mandatory Code, which the IMO starts drafting in 2028. MSC 112 meets in December to design how that experience gets collected. The numbers Chapter 17 leaves blank will be written somewhere between now and 2030, by the flag states and operators who turn up with data.
Program offices buying USVs this year can get ahead of that. A specification with an availability floor and a defined time to fallback is exactly the evidence the IMO will end up weighing.
The master is ashore. Someone still has to decide how good the line to them must be.
This one isn't finished. The MAIB's X18 report will be one of the first official accounts of what happens when a remotely piloted hull meets a crewed one. MSC 112's data template will show whether the IMO plans to measure link performance at all.
$1,000 USD a year or $100 a month gets you every Deep Dive, the Maritime Deals Tracker, Foreign Signal Digests, Intel Drops and the full archive.
Multi-seat corporate tiers are also available. Reply to this email or connect on LinkedIn to discuss.
Next Week
Japan has Level 4 autonomous vessels in commercial service and is funding a networked autonomous defence layer across the Nansei islands, largely without the alliance machinery AUKUS has spent years constructing. Next week's Deep Dive, for paid subscribers, looks at how Japan quietly assembled a complete autonomous maritime stack, commercial through military, and whether building for Japan first is a failure of alliance coordination or simply the faster route.
Since you have been, thanks for reading.
Cheers,
Mick
Ocean Tech Intelligence provides informational analysis only. Nothing in this publication constitutes financial, investment, legal, or strategic advice. Readers act on this content at their own risk. For full details see our Disclaimer.

