Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal

Assurance Framework for Safe and Trustworthy AI in Railway Systems

Manuel Müllera, Stefan Brunnerb, Leticia Fernandez Moguelc and Monika Reifd

Safety-Critical Systems Research Lab, Zurich University of Applied Sciences ZHAW, Switzerland.

amanuel.mueller@zhaw.ch

bstefan.brunner@zhaw.ch

cleticia.fernandezmoguel@zhaw.ch

dmonika.reif@zhaw.ch

Jiwon Shin

Stadler Signalling, Switzerland.

jiwon.shin@stadlerrail.com

ABSTRACT

Safety assurance for railway software is traditionally based on defined objectives supported by structured processes and documentation. These processes provide confidence in the correctness and reliability of deterministic, rulebased applications. With the introduction of artificial-intelligence-based perception and automation functions, this approach must be extended. The behavior of data-driven models cannot be fully demonstrated through conventional verification alone, and additional documentation, processes, and technical evidence are required to capture their development, validation, and operational control. Concurrently, new regulatory frameworks such as the EU Artificial Intelligence Act and emerging standards from CEN-CENELEC JTC 21 and ISO/IEC JTC 1/SC 42 introduce explicit requirements for fairness, robustness, transparency, traceability, and human oversight in high-risk AI systems. These provisions complement existing railway safety obligations but demand new methodological means of demonstrating compliance. To address these combined needs, this paper introduces a conceptual assurance framework for AI-enabled automated railway systems that extends process- and documentation-based assurance with technical and methodological measures. These are organized into coordinated pipelines covering the life-cycle of AIenabled components: a data pipeline ensuring dataset quality and governance; a training pipeline managing model configuration and reproducibility; a verification and validation workflow combining scenario-based testing with complementary methods such as stress and sensitivity analysis, adversarial attacks, and uncertainty quantification to evaluate model behavior and robustness; and a monitoring pipeline enabling continuous assessment of performance and degradation in operation. Together, these pipelines address essential AI properties such as fairness, robustness, and transparency, translating regulation into traceable, auditable activities. The framework provides a consistent basis for aligning AI-specific compliance requirements with established railway assurance processes and generating evidence to support structured, transparent safety argumentation for future railway systems.

Keywords: Railway safety, AI assurance, Verification and validation, Regulatory compliance, Trustworthy AI.



Download PDF