Five Design Principles I Learned from Autonomous Systems
· 7 min read
Fifteen years designing interfaces for some of the most complex systems humans have built has sharpened a few principles I now apply to every design problem, autonomous or otherwise.
Fifteen years designing interfaces for some of the most complex systems humans have built autonomous vehicles, military AI, remotely piloted aircraft has sharpened a few principles I now apply to every design problem, regardless of domain. Here are the five that have proved most durable.
1. The failure state is the product
In most digital product design, the failure state is an afterthought. In safety-critical design, it is the primary design surface. When the system fails, the interface's job isn't just to show an error; it's to get the user back to solid ground as quickly as possible. What do they need to understand? What action should they take next? The interface has to make the path back to normal obvious, even under stress. I now apply this principle everywhere: the quality of a design is measured as much by how gracefully it recovers as by how well it works when everything goes right.
2. Transparency without structure is just noise
Early in autonomous vehicle development, the temptation was to give users everything: every sensor reading, every system state, every decision flag, in the name of transparency. It didn't build trust; it created overload. Users couldn't parse what was actually happening because there was too much signal and no hierarchy. The lesson was hard-won: raw data exposed without structure doesn't inform, it overwhelms. Transparency only earns trust when it's curated: when the interface surfaces what matters at the moment it matters, and lets everything else recede.
3. Mental models and interfaces are equally important
An interface is only as good as the mental model it helps the user build, and a mental model is only useful if the interface reinforces it accurately. In autonomous systems, the operator's mental model of the system's state and intentions is the safety-critical resource. If the interface creates a wrong mental model, if the operator believes the vehicle is doing one thing when it's doing another, the interface has failed regardless of how clean it looks. I now spend as much time on what users believe to be true as on what they see on screen. Neither can succeed without the other.
4. Workload is the real design constraint
Most design is constrained by screen size, data availability, or technical feasibility. In high-stakes environments, the dominant constraint is human cognitive workload. An operator managing a fleet of autonomous vehicles, or a remote pilot supervising an aircraft, has a finite cognitive budget. Every element on screen is a withdrawal from that budget. This forces a rigour in information hierarchy that general-purpose product design rarely demands and it's made me a better designer for every context since.
5. The best design is the one that disappears
In aviation, the best cockpit design is one the pilot doesn't think about. They read the instruments without reading them, it's automatic, practiced, invisible. This is the aspiration for all safety-critical interface design: an interface so well structured, so consistent, so responsive to context, that the user's conscious attention is freed entirely for the task at hand. The interface becomes a layer they operate through rather than something they operate. That invisibility is the highest form of craft.
These principles travel
None of these principles are unique to autonomous systems. They apply to any interface that matters to any product where the user's success has real consequences. The reason I learned them in autonomous systems is that the stakes forced clarity: when an interface failure can stop a vehicle on a busy road or cause a pilot to misread their altitude, the feedback is unambiguous. Most design environments don't offer that clarity. But the principles it produces are universal.