By: Gustavo Leite Neves da Luz
Maritime regulation has traditionally organised the master’s authority around a physical place: the bridge. The IMO’s new International Code of Safety for Maritime Autonomous Surface Ships (MASS Code) unsettles that premise without displacing the office itself. It contemplates a human master located in a Remote Operations Centre (ROC), while remaining responsible for the ship’s safe operation. The office remains; its geography changes.
That shift raises a narrower question than whether autonomous ships create a general “responsibility gap”. The Code does not determine international responsibility, civil or criminal liability, or attribution of software conduct. Its treatment of responsibility is primarily operational: under what conditions can a human remain genuinely responsible when control actions are divided among onboard personnel, remote operators, software agents, communications infrastructure and companies? This requires distinguishing the master’s operational responsibility from the accountability and traceability of those who design, deploy or operate software, and from legal responsibility or liability, which the Code does not resolve.
Adopted by resolution MSC.595(111), the non-mandatory Code came into effect on 1 July 2026. It applies to cargo ships under SOLAS Chapter I, including associated ROCs, where an Administration considers existing instruments impracticable or insufficient for the relevant autonomous or remote functions (I/2.1). It is technology-neutral and supplementary to other IMO instruments. Because it is non-mandatory, its legal significance will depend largely on how Administrations incorporate it into approval, certification and safety-management practice; it does not itself create liability rules. Even so, that practice may shape what Administrations and industry treat as reasonable while the mandatory regime is developed. Significantly, its preamble requires both the Code and the use of MASS to conform to the relevant rules of international law, including UNCLOS, and to generally accepted international regulations, procedures and practices developed by IMO.
The model preserves human responsibility. Yet responsibility cannot be secured by identifying a person alone. It depends on whether the surrounding architecture gives that person the information, authority and practical capacity required to act.
A Human Master Outside the Bridge
The Code states that there should be a human master responsible for a MASS, regardless of its mode of operation, with means to intervene when necessary (II/8.7.3). The master remains responsible for safe operation at all times and may be located on board or at a ROC. Where crew or other persons are on board, however, the master should be physically present there (II/14.2.1.10-12).
Several masters may be operationally responsible during one voyage, although only one should hold responsibility at any given time. A transfer of command to, within or between ROCs should provide sufficient time, resources and procedures for the incoming master to establish situational awareness and become familiar with the ship and the relevant ROC (II/14.2.1.13-15).
The Safety Management System should also preserve the master’s overriding authority (II/11.2.3.5). The Code therefore does more than retain a familiar title. It links command to conditions of competence, information, continuity and intervention, even when physical presence on the bridge is absent.
Flag-State Control at a Distance
Remote command is therefore not only a question of how SOLAS requirements are adapted. Article 94 of UNCLOS requires every State to “effectively exercise its jurisdiction and control” over ships flying its flag. That obligation extends to administrative, technical and social matters and is reinforced by the flag State’s jurisdiction over the ship and its master, officers and crew (art 94(2)(b)). Article 94(3)-(4) further requires measures necessary to ensure safety at sea, including that each ship be in the charge of a master and officers possessing appropriate qualifications. The Convention was drafted around conventional shipping, but it does not make the bridge the legal source of command. Its concern is whether the flag-State arrangement produces qualified and effective control.
These provisions give the Code a broader significance. Its rules on approval, manning, task allocation, connectivity, command transfer and override describe the conditions through which an Administration may demonstrate that moving the master ashore has not hollowed out the control required by Article 94. The relationship should not be overstated. Because the Code is non-mandatory, it cannot simply be equated with the “generally accepted international regulations, procedures and practices” referenced in Article 94(5). Its immediate significance is more modest: it provides a common framework against which Administrations can assess whether remote command preserves the substance of existing obligations while practice develops around a future mandatory instrument.
Article 98 of UNCLOS sharpens the point. It requires each State to require the master of a ship flying its flag to render assistance to persons in danger at sea and, when informed of distress, to proceed with all possible speed where this may reasonably be expected. Chapter 21 of the MASS Code correspondingly requires the master to comply with SOLAS and applicable international law and requires ship-specific plans and procedures enabling assistance, including rescue equipment usable independently of crew presence (III/21.2). A remote master must therefore be capable not only of directing the ship, but of causing it to perform the acts that international law assigns to the office. In this context, a capability gap can become a law-of-the-sea problem: a formal appointment cannot secure compliance if the ship and ROC are not designed to make assistance operationally possible.
Human Oversight as a Regulatory Capacity
The Code’s most consequential provisions concern the content of human oversight. Onboard crew and remote operators responsible for MASS operations should be able to understand system outputs, supervise the system, verify system-initiated decisions and intervene or override where required (II/8.7.1). They should receive ample time and sufficient information to establish situational awareness, assume responsibility and exercise direct or supervisory control (II/8.7.4).
The software principles reinforce these requirements. Software should be transparent and explainable throughout its operational life. Relevant personnel should understand the technology and its operational methods, supported by auditable methodologies, data sources and documentation (II/10.4). Software should be auditable and traceable to the entities developing, deploying or operating it, with mechanisms for oversight, impact assessment, audit and due diligence (II/10.5). Controllability requires accurate and timely information, verification of system behaviour, and the ability to take over or override within a timeframe that minimises risk (II/10.7).
The problem resembles a concern explored in The Age of AI: institutions may rely on useful outputs that the responsible human cannot fully reconstruct. At sea, however, the issue is regulatory rather than metaphysical. Human oversight cannot mean the presence of a person who merely receives or confirms a system output. It requires conditions under which that person can evaluate the output, understand its limits and act against it when necessary.
The Architecture Behind Command
The master may be identifiable, but the capacity to command depends on a distributed institutional and technological architecture. Under the Code, the ISM Company should develop and maintain the Safety Management System. ROCs organise remote operations. Software design shapes how information is processed and control actions are initiated. Sensors determine what the system can perceive; interfaces affect what operators can understand; connectivity determines whether information and commands arrive accurately and in time. Administrations approve and survey the arrangement.
The Code recognises these dependencies. The Concept of Operations should identify which functions are autonomous or remotely operated, how they are allocated between human and software agents, how they are supervised, where the agents are located and which other systems or personnel participate in the control action (II/8.6.2). The Company should document the division of tasks and the relationship among the Company, MASS and associated ROCs, while ROC operations are included in safety-management verification and certification (II/5.7). Connectivity should be adequate for the operational context, taking account of bandwidth, data integrity, reliability, resilience and latency (III/17.2).
The master’s authority is therefore not produced by a single rule. It emerges from the interaction of legal provisions, administrative approval, corporate procedures, technical standards and system design. The more precise risk is not necessarily a responsibility gap, but a capability gap: operational responsibility may be assigned without commensurate access to the information, time, authority and means of intervention required to discharge it.
Making Human Control Operational
Four dimensions are particularly relevant. The first is epistemic: the master must receive accurate, timely and intelligible information about the ship, its environment and the basis on which a system proposes or initiates action. On a functional reading, explainability need not require reconstruction of every computational step, provided that it permits an informed assessment of whether an output is reliable within the relevant Operational Design Domain.
The second is temporal. Information and authority have limited value if latency, interface design or the speed of automated action leaves no meaningful opportunity to intervene. The Code therefore links control to sufficient time for situational awareness and provides that autonomous or remote navigation systems should be capable of override from locations where navigational control is exercised. The override should be simple, independent of the controlled system and immediately available (III/16.5).
A third dimension is organisational. Clear lines of authority must connect the master, remote operators, onboard personnel, the Company and the ROC. This becomes more difficult where a ROC serves several ships: the Code contemplates separate safe-manning documentation and alert arrangements capable of organising and delegating alerts by MASS (II/5.9.4; II/13.4.2).
The fourth is evidentiary: the exercise of control must be reconstructable after an incident. Systems should log performance, failures and incidents; preserve data for at least 30 days; and retain sufficient detail to restore a complete record of remote operations and automated decisions. The information should be available to Administrations and marine investigation authorities (II/9.10). Responsibility requires not only the capacity to act, but also the ability to determine what happened and whether intervention was realistically possible.
These dimensions are a functional reading of the Code, not a new test for international attribution or ship nationality. They ask whether the person designated as operationally responsible has the practical means to discharge that role and, correspondingly, whether the flag State’s exercise of jurisdiction and control can be effective rather than merely formal.
What the Experience-Building Phase Should Test
The planned Experience-Building Phase should test this architecture rather than merely count voyages completed without casualties. Relevant scenarios include transfers of command between ROCs, degraded connectivity, competing alerts affecting several ships, software updates that alter task allocation, and attempted overrides under time pressure. Near misses and unsuccessful interventions may be more informative than routine operation because they expose the point at which nominal authority ceases to be usable. Search-and-rescue scenarios are equally important, particularly where recovery equipment must be used and persons in distress accommodated without onboard crew.
The framework for the Experience-Building Phase is scheduled for development at MSC 112 in December 2026. The IMO roadmap then envisages work on a mandatory Code from 2028, with adoption expected by July 2030 and entry into force in January 2032. The non-mandatory period is therefore a critical opportunity to determine whether the model works in practice.
Preserving a human master is an important regulatory choice. But responsibility cannot be maintained by designation alone. It requires an environment in which the person designated as responsible can understand, supervise, challenge and, where necessary, override the systems through which the ship is operated. The MASS Code begins to define those conditions. For the law of the sea, the Experience-Building Phase should determine whether they allow flag States to exercise effective control under Article 94 and masters to discharge the duty of assistance under Article 98. The task is not to preserve human responsibility rhetorically, but to make command operationally real.
About the author
Gustavo Leite Neves da Luz is a Postdoctoral Fellow in Law and Policy at the Marine & Environmental Law Institute, Schulich School of Law, Dalhousie University. He holds a PhD in International Law from the University of Hamburg and an LLM from the Federal University of Minas Gerais. His research focuses on the law of the sea, international environmental law, emerging ocean technologies and the history of international law.