Kommisjonens gjennomføringsforordning (EU) 2026/1821 av 27. juli 2026 om endring av gjennomføringsforordning (EU) 2015/1018 om utarbeiding av en liste med klassifisering av tilfeller innen sivil luftfart som omfattes av obligatorisk rapportering, med hensyn til ubemannede luftfartøysystemer (UAS), hendelser i U-space, hendelser i part-IS, og fjerning av visse hendelser knyttet til luftfartssikkerhet fra obligatoriske rapporteringskrav
Etterforsking og forebygging av flyulykker: rapportering knyttet til ubemannede luftfartøysystemer
Kommisjonsforordning publisert i EU-tidende 28.7.2026
Tidligere
- Utkast til forordning lagt fram av Kommisjonen 4.5.2026 med tilbakemeldingsfrist 1.6.2026
Bakgrunn
(fra kommisjonsforordningen)
(1) According to the first subparagraph of Article 4(5) of Regulation (EU) No 376/2014, the Commission is required to adopt a list classifying occurrences to be referred to when reporting occurrences, under mandatory reporting systems set out in that Regulation, and which fall within the categories of Article 4(1) of that Regulation.
(2) Commission Implementing Regulation (EU) 2015/1018 (2) lays down a list classifying occurrences in civil aviation that require mandatory reporting under Regulation (EU) No 376/2014.
(3) The evaluation of Regulation (EU) No 376/2014 (3) carried out by the Commission in 2020 concluded that while occurrences involving unmanned aircraft systems (‘UAS’) fall within the scope of that Regulation clarity is needed as regards what constitutes mandatorily reportable occurrences.
(4) There is currently sufficient operational experience with UAS occurrences to facilitate the identification of potential significant risks to aviation safety and to determine the appropriate reporting requirements.
(5) Given the technological and operational differences between UAS and manned aircraft, a separate Annex for UAS to encompass specific occurrences pertinent to UAS operations should be included to distinguish occurrences unique to UAS while maintaining the integrity of existing classifications for manned aircraft.
(6) The mandatory reporting of occurrences related to the operation of UAS should be limited to those UAS operations that present a significant risk to aviation safety, in line with the risk-based approach established under Regulation (EU) 2018/1139 of the European Parliament and of the Council (4). Pursuant to Article 56(1) and (5) of that Regulation, UAS operations requiring either a certificate or a declaration for design have an inherently higher risk profile due to complex operational environments, higher-performance aircraft, or interactions with manned aviation. Such UAS operations require safety-related occurrences to be mandatorily reported, to ensure identification and mitigation of risks.
(7) In contrast, UAS operations that do not require a certificate or declaration are excluded from reporting the list of occurrences. This targeted approach ensures that reporting obligations remain proportionate to the level of risk while maintaining alignment with the existing Union aviation safety framework.
(8) It is important to also consider the risks in new scenarios, such as the operations of UAS in the U-space airspace (5). Given the risk nature of U-space operations, particularly in urban and densely populated environments, occurrences such a collision or a loss of control might pose a significant threat to the safety of persons and property on the ground, as well as to other airspace users. The expected increase in UAS operations within U-space compounds these risks, making reporting as set out by Regulation (EU) No 376/2014, essential for timely hazard identification, risk mitigation, and the prevention of accidents and incidents.
(9) Regulation (EU) No 376/2014 explicitly requires reporting of some security-related aviation occurrences which may affect safety of the operations. As such, Implementing Regulation (EU) 2015/1018 include security-related occurrences under its Annexes. Commission Regulation (EU) 2026/247 (6) has established the mechanism and process for the reporting, classification, processing, storage, protection, analysis and aggregation of information on aviation security incidents, in particular regarding acts of unlawful interference, at EU level. In the light of this EU security occurrence reporting system, consideration has been given to remove some aviation security related occurrences that are better addressed by security authorities.
(10) Some security occurrences (e.g., fires, laser interference) have dual safety and security implications, and there should be reported to both safety and security authorities under the respective legislative frameworks. This double reporting is deemed necessary, as being reported on safety only could prevent this information to be used for security purposes, which needs it to be available as soon as possible on the security side. Furthermore, Article 15(2) of Regulation (EU) No 376/2014 restricts the use of reported occurrence data solely to safety improvements, prohibiting sharing with other persons, including security authorities.
(11) The reporting on bomb threats or hijackings, aerodrome security related occurrences and non-compliance with rules concerning baggage or passenger reconciliation under Implementing Regulation (EU) 2015/1018 should be maintained until the provisions on the reporting of aviation security occurrences set out in point 19 of the Annex to Regulation (EU) 2026/247 begin to apply on 1 January 2028.
(12) As information security incidents may affect the normal and safe functioning of systems, equipment, and digital infrastructure, generic information security occurrences have been added in the list of occurrences to be reported.
(13) To ensure the continued safe and reliable operation of systems, equipment, and digital infrastructure, certain information security occurrences must be reported under the safety occurrence reporting framework. While not all information security events (e.g., deliberate attacks against critical systems and data) fall within this scope, accidental or unintentional incidents (such as malware infections, compromised information or data, or system disruptions caused by security failures) may pose safety risks and warrant investigation to prevent recurrence. Therefore, a broad and generic reference has been included to capture such occurrences without prescriptive detail.
(14) The measures provided for in this Regulation are in accordance with the opinion of the Committee established by Article 127 of Regulation (EU) 2018/1139,