Autonomy that only works on a perfect network is not field autonomy. In remote Australian environments, links drop, bandwidth collapses and latency becomes unpredictable. Systems must continue to behave safely and usefully when the operator picture is incomplete.
Design for interruption
Degraded-communications design starts with clear assumptions: what the platform may do alone, what requires operator confirmation, and what must enter a safe state. Operating plans should include contingencies, not only ideal routes.
Local authority with limits
Edge behaviour can continue navigation, sensing, buffering and health monitoring while awaiting acknowledgement. Consequential actions — entering restricted zones, interacting with people, or changing operating intent — should remain bounded by policy and human oversight.
Make uncertainty visible
Operators need to know when telemetry is stale, which commands were acknowledged, and which assets are operating on last-known intent. Honest status presentation is part of safety, not a cosmetic dashboard detail.
Test the ugly cases
Validation should include link loss, partial sensor failure and delayed command delivery. Demonstration success under ideal conditions is not evidence of field reliability.
