
The Last Mile Revolution: How AI is Transforming Logistics and Shipping
How logistics teams can use AI for forecasting, routing, traceability, resilience, and last-mile promises while respecting workers, customs, and emissions.
Read MoreZharfAI Team

Maritime autonomy is not one switch that turns a crewed ship into a “ghost fleet.” Navigation, lookout, machinery, cargo, mooring, communications, emergency response, maintenance, and security can each be conventional, automated, remotely controlled, or autonomous in different operating modes. The safe design problem is to allocate every function and responsibility across ship systems, onboard people, a remote operations center, the company, and public authorities.
The boundary is non-negotiable: autonomy does not remove the master, operator, company, flag-state, coastal-state, port, or legal obligations that apply. AI can support perception, route comparison, or machinery diagnosis. It cannot manufacture right of way, excuse an inadequate lookout, erase the master’s authority, or turn an unapproved operating mode into lawful navigation.
Create a function inventory for voyage planning, situational awareness, collision avoidance, position fixing, speed and heading control, propulsion, power, communications, cargo, stability, fire safety, search and rescue, security, pollution prevention, anchoring, towing, and mooring. For each mode, state whether the function is performed onboard, remotely, autonomously, or jointly.
ISO/TS 23860:2022 is a published technical specification for terminology related to autonomous ship systems. Its ISO page shows the edition under review for revision, so teams should verify the current terminology rather than treating the 2022 vocabulary as permanent law. Consistent words help engineering; they do not determine regulatory approval.
The IMO’s autonomous-shipping FAQ and MASS Code status records that resolution MSC.595(111) adopted the non-mandatory MASS Code in May 2026 and that it took effect on July 1, 2026. The Code is goal-based, applies within its stated scope, and supplements existing instruments. It is not yet the future mandatory SOLAS code.
The same IMO source says the master retains overall responsibility at all times, including when not onboard, and describes remote operations centers within a robust safety-management system. The roadmap envisages experience-building work beginning at MSC 112 in December 2026, mandatory-code development in 2028, expected adoption by July 1, 2030, and expected entry into force on January 1, 2032. Those are roadmap milestones, not current mandatory dates.
Name the master, company, designated person, remote operators, onboard crew if any, maintenance provider, communications provider, port agent, and emergency contacts for every voyage and mode. Define who has command, who may change mode, who acknowledges alarms, and who communicates with authorities and other vessels. Avoid a design where two people each believe the other has control.
The IMO’s International Safety Management Code overview describes a mandatory safety-management framework under SOLAS Chapter IX, including assessment of identified risks and safeguards. Map autonomous-system hazards, remote-center duties, software change, cybersecurity, and degraded operation into the company safety-management system rather than leaving them in a vendor manual.
For each mode, specify geographic area, chart quality, water depth, traffic density, vessel types, speed range, weather, wind, sea state, visibility, ice, day or night, communications coverage, positioning integrity, sensor health, tug and pilot requirements, and port permission. State the conditions that trigger a restricted mode, remote takeover, onboard control, safe stop, anchoring, or return.
Monitor the domain continuously. “Inside the route polygon” is insufficient when visibility, traffic, connectivity, or machinery state has changed. The system must identify when it is approaching a limit early enough for the assigned human or fallback to act. Unknown domain status is a failure condition, not permission to continue.
Fuse radar, AIS, electro-optical and infrared cameras, GNSS and other position sources, gyro, speed log, depth, weather, charts, machinery, and vessel-specific sensors. Keep source time, coordinate frame, calibration, health, uncertainty, and association history. AIS is cooperative information and can be missing, delayed, wrong, or spoofed; it is not a substitute for independent lookout.
Track objects through occlusion, clutter, glare, rain, fog, sea return, small craft, fishing gear, floating debris, and sensor failure. Display raw evidence and confidence to the responsible operator. A perception model should be able to abstain and request assistance rather than convert an uncertain target into a confident maneuver.
The IMO’s COLREG overview summarizes responsibilities, proper lookout, safe speed, risk of collision, avoiding action, traffic separation, conduct in sight, and restricted visibility. The Convention applies through legal rules and maritime practice; a software decision tree cannot reduce every encounter to vessel labels and closest-point calculations.
Represent visibility, geometry, maneuverability, constraints, intentions, uncertainty, and developing risk over time. Test multi-vessel encounters, ambiguous behavior, non-compliant vessels, narrow channels, traffic schemes, fishing activity, and loss of communications. Keep the master or authorized operator able to intervene, and record the evidence and rationale for every material course or speed change.
Define staffing, competence, watch schedules, fatigue controls, workload, vessel-to-operator ratio, supervision, language, handover, and authority. One operator monitoring several quiet voyages can become overloaded when simultaneous alarms, weather, traffic, or connectivity failures occur. Capacity rules should reduce assigned vessels before the queue becomes unsafe.
Provide independent communications where proportionate, authenticated control, latency and loss monitoring, synchronized displays, voyage and machinery context, and an unambiguous control token. A remote operator needs a common operating picture and time to understand it; transferring a control bit is not a safe handover. Exercise loss of the center, regional network outage, evacuation, and transfer to another approved location.
Every transition should define initiator, prerequisites, confirmation, control authority, state synchronization, timeout, and failure response. Prevent silent mode changes. Use distinct indicators for “monitoring,” “advising,” “remote control,” and “autonomous control.” Record who had control and which software configuration was active.
Minimum-risk behavior is context-specific. Slowing or stopping in a traffic lane, narrow channel, heavy weather, or close-quarters situation can create danger. Pre-engineer options by location and vessel condition and validate them with nautical experts. If communications fail, the ship should not improvise beyond its approved mode and domain.
Automation can reduce routine workload and simultaneously erode skill, attention, and shared understanding. Design for calibrated trust: show limits, uncertainty, and reasons; avoid alarm floods; provide rehearsal; and keep manual skills current. Staff must be able to challenge a route or maneuver without fighting the interface.
Human-approval design for AI applies directly to remote command. Intervention needs time, authority, independent sensor views, and practiced procedures. Review staffing and competency with seafarers and human-factors specialists. Moving a role ashore changes fatigue and teamwork; it does not make the human element disappear.
Autonomy must coexist with propulsion loss, steering fault, blackout, fire, flooding, cargo shift, pollution, medical emergency, grounding, collision, and search and rescue. Specify what can be detected, isolated, repaired, or reset without people onboard. Some faults require physical intervention and make a fully uncrewed concept unsuitable for the route.
The IMO SOLAS overview describes mandatory safety domains including navigation, radiocommunications, construction, fire protection, lifesaving, safety management, and security. The MASS Code supplements applicable instruments; it does not waive them. The flag administration, recognized organization where used, port state, and other authorities determine approvals in their domains.
Threat-model sensors, positioning, AIS, charts, bridge systems, controllers, satellite and terrestrial links, the remote center, vendor access, update servers, models, and logs. Segment safety-critical functions, authenticate commands, sign software and models, secure boot, protect keys, constrain remote maintenance, and maintain clean recovery images.
Test spoofing, jamming, delayed or replayed commands, compromised sensors, prompt injection through messages or documents, supply-chain malware, denial of service, and insider misuse. A cybersecurity response must consider navigational and machinery consequences before isolation. Critical-infrastructure risk management provides a broader service-continuity model.
Autonomous and conventional vessels will share waterways for years. Design communications and behavior that other mariners can understand. Confirm procedures with vessel traffic services, pilots, tugs, terminals, coast guards, and port authorities. Do not assume every participant consumes a machine-readable intent message.
The IALA MASS technical work overview describes ongoing work on navigation services, VTS, connectivity, positioning, risk, and testbeds. It is an evolving technical program, not a completed global rulebook. Record which local VTS and aids-to-navigation requirements apply and how a remote center will make and acknowledge voice communications.
AI can compare routes and speeds using weather, currents, arrival windows, fuel curves, emissions, charter terms, berth availability, and maintenance constraints. The optimizer should produce options with assumptions and confidence, while the approved voyage plan and navigation watch preserve safety margins and legal duties.
Never let an efficiency objective override safe speed, weather limits, under-keel clearance, traffic, fatigue, or emergency obligations. Recalculate when forecasts, port windows, or machinery change, and record why the plan changed. For cargo and port dependencies, see AI in maritime shipping and supply chains.
Store hardware, sensor, calibration, chart, model, rule, software, firmware, cybersecurity, and operating-domain configurations as an approved vessel baseline. Use management of change for replacements, thresholds, retraining, and remote-center procedures. A camera move or radar-software update can invalidate perception evidence.
Preserve voyage data, sensor health, mode, control authority, alerts, operator actions, model outputs, communications, and software identity for investigation under the applicable retention rules. Logs must be time-synchronized and tamper-evident. They support reconstruction but do not replace required voyage-data recording or official reporting.
Build requirements traceability from hazard and regulation to test. Use component tests, software and hardware in the loop, bridge simulators, remote-center exercises, controlled water trials, and progressively representative voyages. Keep simulation assumptions and domain coverage explicit; a digital ocean cannot represent every mariner or sensor failure.
Test ordinary navigation and rare combinations: two sensor losses in fog, ambiguous fishing traffic with high latency, fire during remote-center failover, or cyber compromise during a machinery fault. Include conventional vessels and external responders. Independent nautical, engineering, cyber, human-factor, and regulatory review should challenge the safety argument.
Track:
Absence of collision in a small trial is not statistical proof of safety. Use leading indicators and structured scenario coverage alongside operational experience.
Phase one improves data quality, voyage comparison, machinery monitoring, and port coordination on a conventionally operated vessel. Phase two runs perception and maneuver recommendations in shadow mode. Phase three pilots bounded automation with crew onboard and immediate intervention. Later phases add approved remote operation or uncrewed modes only inside a certified domain with demonstrated emergency support.
AI in logistics and shipping can capture value before removing onboard roles. Each autonomy gate needs flag-state and other required approvals, a safety case, cybersecurity evidence, crew and remote-center competence, insurance and contract review, incident exercises, rollback, and a decision to continue or stop. Technology readiness never supplies legal authority by itself.
Sources were reviewed on July 30, 2026. IMO resolution MSC.595(111)’s MASS Code had taken effect on July 1, 2026 but remained non-mandatory; the later mandatory-code dates are expected roadmap milestones. SOLAS, COLREG, the ISM Code, national law, flag-state requirements, coastal and port rules, class requirements, and contracts can apply in parallel. ISO/TS 23860:2022 was published but shown under review for revision. IALA’s MASS material describes ongoing technical work. Owners should obtain current determinations from the relevant administration, recognized organization, port and coastal authorities, insurers, and qualified maritime counsel.

How logistics teams can use AI for forecasting, routing, traceability, resilience, and last-mile promises while respecting workers, customs, and emissions.
Read More
A safety-led guide to AI for vessel routing, maintenance, port ETA, digital trade documents, resilience, and decarbonization under human command.
Read More
A practical guide to using AI for budgets, vendors, accessibility, guest communication, schedules, and safety while keeping planners accountable.
Read MoreGet in touch with our team to discuss how we can help your business.