Back to Insights
Platform VigilAero
Industry Paper  ·  No. 01
VigilAero
A Paper on the Future of Drone Operations

The Operational Accountability Gap in Drone Operations

Why commercial drone operations need a new operating model.

Every drone operation leaves behind two records: the flight record, which closes the moment the aircraft lands, and the organizational record, which can stay open for years.

By Uthman Muhammad
Founder, VigilAero
June 2026
Introduction

Why This Paper Exists

Commercial drone operations are becoming larger, more autonomous, and more critical to the systems people depend on every day. Fleets that once numbered a handful of aircraft now number in the hundreds. Missions that once required a pilot's constant attention now unfold through automated decisions made in fractions of a second.

At the same time, the scrutiny surrounding these operations is increasing on every front. Regulators are building new frameworks around accountability as much as airworthiness. Insurers are re-pricing risk around what can and cannot be proven after the fact. Litigation is testing, case by case, what organizations can actually demonstrate about their own decisions. Public trust is being asked to extend further than it has before.

This paper argues that these are not four separate trends. They are different manifestations of the same structural transition: an industry that spent a decade optimizing for flight performance is now being asked, by every institution downstream of it, to prove what it does. What follows is an attempt to name that transition clearly.

Section One
I

The Incident Does Not End When the Aircraft Lands

In December 2024, a holiday drone show over Lake Eola in downtown Orlando went wrong. Several drones, out of a fleet of five hundred, broke formation mid-air and fell into a crowd of roughly twenty-five thousand spectators. One drone struck a seven-year-old boy, who required emergency surgery.

This paper is not about that night. It is about everything that came after.

The FAA suspended the operator's Part 107 waiver. The NTSB opened a formal investigation. Public reporting on the agency's preliminary review has referenced operational and redundancy-related factors, though the NTSB has not issued a final determination of cause, and any such characterization should be treated as preliminary.

Eight months later, the boy's family filed suit in Florida state court against the city and four companies, alleging negligence and product liability. Those allegations are contested and remain unresolved. As of this writing, the case is active and headed toward trial.

A few months later, on the other side of the world, a related pattern emerged. In June 2026, during a drone display at Sydney's Vivid festival, roughly ninety of one thousand drones fell out of formation over Darling Harbour. No one was hurt. The operator stated that an unexpected change in the radio frequency environment occurred shortly after takeoff. The Australian Transport Safety Bureau opened a formal investigation. As of this writing, no findings have been published, and festival organizers cancelled the remaining drone performances for the year as a precaution.

This paper will not speculate about causation in either case. That determination belongs to the investigators, and in the NTSB's case it can take up to two years to arrive. What can be observed, without speculation, is the shape of what happens once an incident like this occurs.

A drone may fall once. The organization may keep falling for months.

Every investigation like this involves real people trying to understand what happened: engineers tracing a malfunction, regulators trying to protect the public, families and communities waiting for answers that arrive slower than they need them to. That human reality is not a footnote to the argument this paper makes. It is the reason the argument matters.

Most operators, and most of the industry built around them, are still organized around the assumption that an incident is primarily a technical event: something to diagnose, patch, and move past. The Lake Eola and Vivid Sydney cases suggest otherwise, independent of how either investigation concludes. Both triggered regulatory review that has extended well past the question of what failed.

This paper treats this pattern as structural, not incidental: an industry transition already underway, intensifying as drone operations move further into public safety, infrastructure, utilities, logistics, energy, and increasingly autonomous flight. The central claim is simple to state and harder to act on.

The Central Claim
Most drone operations are built to fly.
Far fewer are built to prove what happened.

That gap, the Operational Accountability Gap, is the subject of this paper.

Section Two
II

The Industry Optimized for Flight Performance

It is worth being honest about how far the industry has come, because the achievement is real and the gap described in this paper is not a criticism of it.

A decade ago, commercial drone operations were a novelty constrained by line of sight rules, short battery life, and manual piloting. Today, fleets of hundreds or thousands of aircraft fly coordinated formations with sub second timing. Beyond Visual Line of Sight operations, once a rare exception requiring a lengthy waiver process, have scaled dramatically.

20×
Growth in federal BVLOS approvals between 2020 and 2023, from roughly 1,200 to nearly 27,000.
Source: Federal audit data

Docked, autonomous drone in a box deployments now patrol infrastructure and respond to 911 calls without a human walking out to launch them. Public safety has been one of the fastest moving frontiers. Drone as First Responder programs, which dispatch an aircraft ahead of officers on a 911 call, have gone from a handful of pioneering departments to a model being adopted nationwide, accelerated by a reworked FAA waiver process that approved several hundred new waivers within months.

All of this is performance: the capability to execute more complex missions, at greater scale, with less direct human intervention, more reliably than before.

None of it is accountability.

Performance is what the aircraft does. Accountability is what the organization can prove.

A fleet can fly a flawless formation for ninety nine shows and then, on the hundredth, generate an incident the operator cannot fully reconstruct, not because anything was hidden, but because nothing was built to be reconstructed in the first place. The flight logs exist. The telemetry exists. Existence and usability under scrutiny are different things, and the industry has spent its engineering effort almost entirely on the former.

The industry has invested a decade in making drones fly better. It has not invested the same decade in making drone operations explainable.

Section Three
III

The Accountability Burden Is Moving Upstream

The pressure to close that asymmetry is not coming from drone manufacturers, and it is not coming from operators themselves. It is coming from the institutions that sit downstream of every operation: regulators, insurers, courts, and the public.

This progression follows a familiar arc, one visible across other mature transportation and technology sectors before this one reached the same point. Operations grow larger. Missions grow more complex. Autonomy increases, which means more decisions happen without a person directly in the loop at the moment they occur. Regulatory scrutiny rises in response, and public expectations rise with it, because more of daily life now depends on these systems working as described.

Organizational accountability becoming more important is not a separate trend running alongside these others. It is what happens, almost mechanically, once enough of them compound at once.

Scale does not just multiply operations. It multiplies the number of people entitled to ask what happened.

Consider the regulatory direction of travel. The FAA's emerging Beyond Visual Line of Sight framework, discussed publicly as the foundation for a future Part 108, links three things explicitly: visibility through Remote ID, access through coordinated airspace systems, and accountability through expedited enforcement. Industry analysis has pointed to the FAA's existing Part 135 air carrier rules, built around operational control and organizational discipline rather than aircraft technology alone, as a likely template for what will be expected of drone operators at scale.

Part 135 is a governance standard, not a technology one. It assumes a serious aviation operation must be able to demonstrate organizational discipline, not just airworthy hardware.

Public safety programs are already living this shift. Departments running Drone as First Responder programs have learned that community trust depends on more than capable hardware; it depends on being able to show, on demand, where a drone flew, why it was launched, and what policy governed the decision. Industry commentary on these programs draws a sharp distinction between "a collection of flights" and "a true program," the difference being whether operations are governed by standardized procedure and a system of record that survives turnover, scale, and scrutiny.

Insurers and compliance practitioners are converging on the same point from different angles. As drones became standard tools for property and catastrophe claims, insurers discovered that the evidentiary value of drone captured data depends almost entirely on whether its chain of custody can be defended: metadata, timestamps, and processing history showing when something was captured, by whom, and whether it was altered afterward.

Compliance practitioners who work closely with Part 107 operators describe a related pattern from the regulatory side: enforcement exposure often traces back to incomplete or unavailable records rather than to unsafe flying itself. Neither is a formal statistic, but both point in the same direction: a record is only as useful as its provenance, and the record, as much as the flight, is frequently where exposure begins.

The burden of proof in commercial drone operations is moving upstream: away from "did this comply with the rule at the time" and toward "can the organization demonstrate, after the fact, on someone else's timeline, that it complied, who decided what, and on what basis."

That is a governance question wearing the costume of a technical one, and most operators have not yet recognized it as such.

Section Four
IV

Operational Accountability, and the Gap That Defines It

We can now name both the capability and the gap precisely.

Definition · One

Operational Accountability

An organization's ability to reconstruct, defend, and demonstrate its operational decisions, using trusted evidence, after execution.

Operational Accountability is not a synonym for compliance, and it is not a synonym for safety. An organization can be fully compliant and entirely safe and still lack Operational Accountability, simply because no one has ever tested whether its records would hold up once someone outside the organization asked a hard question on a timeline the organization did not choose.

Compliance asks whether you followed the rule. Accountability asks whether you can prove it.

The gap is what remains when that capability does not exist.

Definition · Two

The Operational Accountability Gap

The gap between an organization's ability to execute a drone operation and its ability to defensibly reconstruct that operation afterward.

The word "defensibly" is doing the important work here. Most organizations can produce something after an incident: a flight log, a screenshot, a memory of what someone thinks happened. The Operational Accountability Gap is not the absence of information. It is the absence of information that holds up when someone outside the organization, with no obligation to be generous, starts asking pointed questions.

This is why the gap is largely invisible during normal operations. An organization can fly thousands of missions without ever discovering whether its records would survive scrutiny, because nothing has yet demanded that they do. It typically becomes visible at the worst possible moment: during an NTSB inquiry, a regulatory audit, an insurance dispute, or a deposition. A defensible record cannot be built retroactively for a flight that already happened. The capability has to exist before the incident, or it does not exist when it is needed.

The same logic extends past FAA enforcement into every audience an organization will eventually answer to: an insurer evaluating a claim, an attorney building discovery, a customer asking whether their contract was honored. Each of those audiences is made up of people making a judgment call of their own, often under scrutiny of their own, which is part of why these questions rarely get softer with time.

It is worth being precise about what this gap is not. It is not a claim that drone operators are careless, or that the industry is unsafe. It is a structural observation: the capability to operate has scaled far faster than the capability to account for operating, and the two do not arrive together on their own. One has to be deliberately built. The industry has, so far, mostly built the other one, and operators deserve the chance to close that gap on their own terms, before someone else forces the question.

Section Five
V

Why Existing Tools Are Necessary but Incomplete

None of this is an argument against the tools operators already use. Flight logs, mission planning software, maintenance spreadsheets, and compliance checklists are necessary, and many are well designed for the job they were built to do. The argument here is narrower: each answers a fragment of the accountability question, and fragments do not add up to a defensible whole on their own.

Digital forensics practitioners who specialize in reconstructing drone incidents describe this fragmentation directly. A single thirty minute flight can generate data across onboard logs, a paired mobile application, cloud synced telemetry, and embedded media metadata, sources that live on different devices, in different formats, rarely telling the whole story individually. If reconstructing your own flight requires a specialist forensic process after the fact, your organization does not currently possess accountability. It possesses raw material that a sufficiently motivated third party can turn into accountability, at your expense.

The same fragmentation problem shows up in public safety contexts, where the stakes of getting it wrong are reputational as much as legal. An approach built on individual officers' personal logging habits is serviceable for ten flights and unworkable for ten thousand.

The deeper issue is not volume. It is design intent. Most tools in a typical drone operation were built to support the mission while it is happening: situational awareness, fleet status, live video, navigation. Almost none were built with the question "will this record still make sense to a skeptical outsider eighteen months from now" as a design requirement. That is a different engineering problem entirely, one of provenance, tamper evidence, completeness, and the ability to correlate fragmented sources into a single coherent account.

Today's tools are not poorly built. They were built to answer a different question than the one organizations are now being asked.
Section Six
VI

When Incidents Become Organizational Incidents

The investigation, once opened, tends to expand rather than narrow. Regulators request not just the incident flight's records but historical patterns: prior maintenance, prior near misses, prior training. Insurers, who were not party to the operation at all, ask pointed questions about whether procedures were followed and whether the loss was foreseeable. Attorneys request the full record, not a summary of it, because summaries are exactly what gets challenged first in discovery. Customers want direct answers, often faster than the organization can responsibly provide them. And leadership, people who may never have been in the room where a flight operations decision was made, end up explaining that decision to a board, a city council, or a press inquiry.

These are not five separate complications triggered by one bad night. They are facets of a single, continuous organizational event that begins the moment the aircraft comes down and does not end until every one of those audiences has been satisfied, settled, or has simply moved on. The aircraft incident is the trigger. The organizational event is what follows, and it is the real event.

It is worth naming what sits behind each of those audiences, because it is easy to discuss them as abstractions. The regulator is an investigator trying to protect the public, who will eventually have to explain a conclusion publicly and wants to be certain before doing so. The insurer is a person putting real money behind a judgment about what was foreseeable. The attorney represents a client with a genuine stake in the outcome, whichever side they are on. The customer is a partner whose own reputation is now tied to a decision they did not make.

None of them are looking for a villain. They are looking for a clear, honest account of what happened, which is exactly what an Operational Accountability Gap makes impossible to provide quickly. None of this exists to punish anyone. It exists because people deserve trustworthy answers.

Organizations rehearse flight operations and emergency procedures. They almost never rehearse accounting for an incident to five audiences with five standards of proof, on a timeline none of them control, because it does not feel like an operational risk until the moment it becomes one.

The Lake Eola timeline is instructive here, not because of what caused the incident, but because of how long the organizational consequence has run. The malfunction happened in seconds. The waiver suspension followed within days. The NTSB investigation, which can run up to two years, followed within weeks. The lawsuit followed within eight months and remains active well over a year later, its allegations still contested. By any measure, the organizational event has now outlasted the technical event by a wide margin.

A drone incident is not an aircraft event with organizational side effects. For any operation serious enough to attract regulatory, insurance, or legal attention, it is an organizational event that happens to have begun with an aircraft.

Figure 01  ·  The Duration Mismatch

The technical event ends in seconds.
The organizational event is just beginning.

Aircraft lands
Investigation opens
Insurance review
Litigation
Regulatory review
Public trust
Organizational learning
the one constructive outcome
Technical event
Seconds
Organizational event
Months to years

The aircraft incident is the trigger. The organizational event is the real event, and it can run for months or years after the drone has landed.

Section Seven
VII

The Questions Every Operator Must Be Ready to Answer

Every operator above a certain scale should be able to answer the following, immediately, regardless of who is asking.

01
Can you prove who authorized the mission, and on what basis?
02
Can you prove what each aircraft actually did, as distinct from what it was planned to do?
03
Can you prove what the remote pilot could see and know at each relevant moment?
04
Can you prove which actions were taken by a person, and which occurred automatically?
05
Can you prove what procedures were in effect, and that they were followed?
06
Can you prove what changed, in configuration, software, or personnel, before the incident?
07
Can you prove that none of the relevant records were altered afterward?
08
Can you reconstruct the full sequence of events without gaps filled by memory or assumption?

Most operators, asked these questions cold, will find that some answers exist clearly, some require real effort to assemble, and one or two do not exist in usable form at all.

That gap is the Operational Accountability Gap made concrete.

Most organizations encounter this list during a deposition, an audit, or a board meeting called because something has already gone wrong. The purpose of this section is to move that encounter earlier, into a calm moment, before anything has happened.

Section Eight
VIII

Toward an Accountability Chain

If accountability cannot be reconstructed after the fact from fragments, it has to be built as a connected chain, established before an incident occurs rather than assembled in response to one. Serious drone operations will need an accountability chain connecting authority, operational events, evidence, integrity, and reconstruction. At a conceptual level, that chain rests on five pillars.

I
Authority.  Who had responsibility for the mission, and who approved it?
II
Operations.  What was planned, and what actually occurred?
III
Evidence.  What records exist to substantiate the above, captured in a form that can be examined later?
IV
Integrity.  Can those records be trusted? A record that cannot demonstrate its own freedom from alteration is not evidence in any meaningful sense. It is simply a claim.
V
Reconstruction.  Can the organization explain the event afterward, completely, to an audience that was not present and has no reason to extend the benefit of the doubt?

These pillars are deliberately stated at a conceptual level. This paper is not a technical specification, and it is not attempting to prescribe the internal mechanics of how any organization, including ours, should build this capability.

Any organization serious about operating in this next phase of the industry should be able to look at these five questions and know, honestly, where it currently stands. Most cannot, today.

Section Nine
IX

From Safety Infrastructure to Accountability Infrastructure

Most readers in this industry have already felt some version of the Operational Accountability Gap this paper describes, in the moment after an audit request landed, or a customer asked a pointed question, without having language for what they were feeling. This paper is not introducing a new requirement. It is naming a pattern that has already been operating on the industry for some time.

Aviation has built infrastructure layers before, and each one followed the same arc. Air traffic control did not exist because anyone anticipated it. It existed because the volume of aircraft in shared airspace eventually exceeded what individual pilot judgment alone could coordinate safely. Flight data recorders did not exist because they were an obvious feature. They existed because investigators kept reaching the limits of what witness accounts and wreckage alone could explain, crash after crash, until reconstruction had to be built into the aircraft itself. In each case, the infrastructure looked like a solution in search of a problem until enough incidents revealed that informal practice could no longer carry the weight being placed on it. In each case, aviation came out the other side more capable and more trusted, not less.

Drone operations are living an early version of that same arc now, except this time the gap is not about whether the aircraft is fit to fly. It is about whether the organization operating it can account for what happened once it already has.

Safety infrastructure governs whether an aircraft is fit to fly. Accountability infrastructure governs whether an organization can answer for what it did once it already has.

This is not another feature to add to a flight platform, and it is not a compliance checklist to complete after the fact. It is a new layer of aviation infrastructure, built for a question safety infrastructure was never designed to answer. The organizations that recognize this distinction early will operate with a fundamentally different relationship to risk, one in which an incident, when it eventually happens, is a manageable event rather than an existential one.

Section Ten
X

The Economic Weight of Operational Accountability

Everything described so far is usually discussed as a governance concern. It is also, increasingly, an economic one, and this is the part of the argument that belongs in front of executives rather than only compliance teams.

Consider where the cost of the Operational Accountability Gap actually lands, even though it rarely appears on a balance sheet with that name attached to it. An investigation that should take weeks stretches into months because records have to be manually assembled and explained by people who were not present for the original flight. Operations get paused, voluntarily or by order, while the organization works out what it can currently demonstrate. Insurers, facing a claim they cannot independently verify, price the uncertainty into the settlement, the renewal, or both. Customers, watching an incident unfold without a clear account, quietly reconsider contracts that have nothing to do with the specific aircraft involved.

The inverse is just as real, and it is the more useful half for an executive audience to focus on. Organizations that can demonstrate Operational Accountability move through investigations faster, experience less operational disruption, and tend to retain customer trust through an incident rather than losing it, because the relationship was never resting on the assumption that nothing would ever go wrong, only that the organization could explain it if it did.

Operational Accountability is becoming an economic capability, one that determines how quickly an organization returns to normal operations after something goes wrong, and how much that return costs.
Section Eleven
XI

What Strong Operational Accountability Makes Possible

Everything described so far treats Operational Accountability as something an organization reaches for when things go wrong. That framing undersells what the capability is worth.

Organizations that build genuine Operational Accountability run differently day to day, in ways that have nothing to do with crisis. A clear, trusted record of what happened on every mission becomes a record of what worked and what did not, which is another way of saying Operational Accountability is also organizational learning. Regulators who have seen an organization demonstrate this kind of discipline consistently tend to extend more confidence to that organization's next request, because trust between an operator and a regulator is built the way trust is built anywhere: through a track record that holds up when checked. Insurers price risk more favorably for organizations that can show their risk rather than simply describe it. Customers commit to longer relationships with operators whose governance they do not have to take entirely on faith.

None of this requires an incident to matter. It compounds quietly, mission after mission, in faster audits, smoother renewals, and a kind of organizational memory that does not depend on any one person's recollection.

People do not aspire to compliance. They aspire to becoming organizations others trust. Operating well and being able to prove it are becoming the same job.
Section Twelve
XII

From Flight Records to Operational Evidence

Documentation and evidence are often treated as interchangeable, but they answer different questions. Documentation exists to show that a rule was followed; it is judged by whether it exists. Evidence exists to support a conclusion under scrutiny from someone who was not present and has no reason to be generous; it is judged by its integrity, completeness, and ability to survive a challenge.

Documentation proves you followed the rules. Evidence proves you can defend what happened.

The industry today speaks the language of flight records: logs, checklists, compliance paperwork. That vocabulary assumes the purpose of documentation is to demonstrate, internally, that a rule was followed. The direction of travel, visible in BVLOS scaling, public safety program maturation, and insurance industry practice, points toward a different vocabulary: operational evidence, built for examination by someone with no obligation to interpret it charitably.

This is not a hypothetical evolution. The insurance industry has already made this transition for drone captured claims data, treating chain of custody as a first class requirement, because disputed claims taught the industry that timestamped existence is not the same as defensible proof. Aviation accountability is following the same arc, a few years behind, for the same underlying reason: the moment a record's purpose shifts from internal memory to external defense, its design requirements change completely.

The operators who treat their operational data as evidence rather than paperwork will experience an incident, however serious, as a manageable event rather than an existential one. The operators who do not will learn the distinction the hard way.
Section Thirteen
XIII

The Next Layer of Trust

Every layer of trust in aviation has historically been built into the aircraft itself: airworthiness standards, redundant systems, pilot certification, maintenance regimes. That layer is necessary, and the drone industry has made real progress building it.

A new layer of trust is forming on top of it, one that has nothing to do with whether the aircraft can fly safely, and everything to do with whether the organization operating it can account for itself once something goes wrong, slowly, in public, under scrutiny it does not control.

The Next Layer of Trust
Flight performance earns the mission.
Operational Accountability earns the trust to fly the next one.

It is what keeps an organization standing after it lands, and after the regulators, the insurers, the attorneys, and the public have all had their turn asking the same question in different language: prove it.

None of this reflects an industry in crisis. It reflects an industry maturing quickly enough that its informal practices have started to show their seams, the same maturing aviation has moved through before, each time emerging more capable and more trusted than before. The Operational Accountability Gap is not evidence of failure. Closing it is what maturity looks like at this stage of an industry's growth.

Safety management systems, maintenance regimes, and pilot qualification all began as informal practices before becoming so fundamental that operating without them became unthinkable. Operational Accountability is on the same path. It will not remain a differentiator for long. It will become one more thing every serious aviation organization is simply expected to have.

The organizations that define the next decade of drone operations will not simply fly better. They will account for their operations better.

Aviation has always evolved by adding new layers of trust. Airworthiness. Pilot qualification. Safety management. Flight recorders. Each became essential not because the industry wanted more complexity, but because growth demanded greater confidence. Operational Accountability represents the next layer. Not because regulators will require it tomorrow, but because the industry itself is becoming too important to operate without it.

Founder's Note

This paper was written from the perspective of a founder working at the intersection of cybersecurity, governance, and commercial drone operations.

Over time I noticed a recurring pattern. Conversations about drone operations almost always focused on flight capability. Far fewer focused on what organizations would need to demonstrate after those operations were complete.

The more I studied incidents, investigations, and regulatory developments, the more that pattern repeated itself.

This paper is my attempt to give that pattern a name. Because I believe the industry is already living it.

Uthman Muhammad
Founder, VigilAero