The Orbital Flash Crash
What Happens When Thousands of Satellites React at Once?
At 09:42 UTC, a satellite receives a collision warning.
Its software predicts that another object will pass too close. It calculates a safer trajectory and fires its thrusters.
The spacecraft has behaved exactly as designed.
But its new trajectory creates possible encounters with several neighbouring satellites. Their systems recalculate. Two manoeuvre. One waits for ground approval. Another operator is still working from an older orbital prediction.
More alerts appear.
Within minutes, several constellations begin changing course. Some satellites act autonomously. Others follow fleet-level commands. A military spacecraft publishes no precise manoeuvre plan. A geomagnetic storm is also increasing atmospheric drag, making every forecast less reliable.
Nothing has become sentient. No machine has deliberately attacked anything.
Every operator is trying to protect its own assets.
Collectively, however, they are making low Earth orbit less predictable.
This is an orbital flash crash: a hypothetical cascade in which individually reasonable spacecraft decisions interact faster than operators can coordinate them, transferring risk across an increasingly congested orbital environment.
The danger is not AI alone. It is the combination of congestion, uncertain data, automation and fragmented governance.
LEO is large, but its useful regions are crowded
Spacecraft are not distributed evenly throughout space. They cluster in orbital bands that offer useful combinations of coverage, latency, atmospheric lifetime and launch accessibility.
ESA reports that the scale of commercial constellations continues to increase and that, in some heavily populated altitude bands, active spacecraft are now present in the same order of magnitude as debris. It describes Earth orbit as a finite resource whose condition continues to deteriorate. [1]
The practical problem is therefore not that satellites are “using up space” in a simple volumetric sense. It is that thousands of fast-moving objects repeatedly cross a limited number of useful orbital shells.
The challenge becomes particularly difficult during:
orbit raising after launch;
movement between operational planes;
collision-avoidance manoeuvres;
end-of-life descent;
spacecraft failure;
and periods of elevated atmospheric drag.
A constellation shell is not legally owned by its operator. It is an operational architecture, not a private road. Other satellites may cross it, operate near it or establish overlapping systems.
That means safety depends less on ownership and more on predictable behaviour.
Why the comparison with a financial flash crash works
A financial flash crash occurs when automated trading systems respond to market signals and to one another. Each algorithm may follow a rational rule, yet their combined actions create feedback loops that rapidly destabilise the market.
Orbit could develop a similar problem.
One manoeuvre changes the environment faced by other spacecraft. Their responses create further trajectory changes. Those changes produce new conjunction assessments and potentially more manoeuvres.
The underlying question changes from:
Can one satellite avoid one collision?
to:
Can thousands of independently designed systems remain stable while all are changing one another’s operating environment?
A manoeuvre may be locally safe but systemically harmful.
Satellites operate from predictions, not perfect knowledge
Collision assessment relies on forecasts of where objects will be in the future.
Those predictions depend on:
tracking measurements;
atmospheric-density models;
spacecraft mass and orientation;
propulsion performance;
planned manoeuvres;
and estimates of positional uncertainty.
A conjunction alert does not prove that two objects will collide. It indicates that their predicted positions and uncertainty regions overlap enough to justify concern.
Different operators may evaluate the same encounter using different tracking networks, models, risk thresholds and manoeuvre assumptions. Two systems can therefore process the available information correctly and still reach opposite conclusions.
One decides to move.
The other decides to remain still.
Neither necessarily knows what the other has decided.
NASA’s conjunction-assessment guidance emphasises high-quality trajectory data, realistic uncertainty, operator coordination and the exchange of planned manoeuvre information for precisely this reason. [2]
The central gap is data governance
An autonomous system cannot coordinate around information it does not possess.
For safe interaction, another operator may need to know:
the spacecraft’s predicted trajectory;
the uncertainty around that prediction;
whether it can manoeuvre;
whether it remains under control;
whether a manoeuvre is planned;
when the manoeuvre will occur;
and where the spacecraft is expected to be afterwards.
Today, these details may be spread across government catalogues, commercial tracking services, operator-generated ephemerides and direct bilateral communications.
The UN Long-term Sustainability Guidelines encourage operators and states to maintain contact details, share information about space objects and orbital events, and perform conjunction assessment during all phases of controlled flight. They are important, but voluntary. [3]
Some regulators and operators have gone further. The FCC has required Kuiper to share ephemeris data and coordinate physical operations with operators using similar orbits. Other authorisations include comparable operator-specific obligations. [4]
SpaceX also states that it shares space-safety and situational-awareness information with operators, while ESA’s CREAM programme is developing automated risk assessment and operator coordination. [5]
But there is still no universally binding global requirement that every civil, commercial and military spacecraft continuously publish accurate future trajectories through one trusted system.
Why operators may refuse to share
For commercial companies, detailed trajectory information may reveal operational methods, manoeuvring capability, fuel strategy or constellation performance.
For governments, the concern is greater.
Frequent high-precision updates could reveal:
where a surveillance satellite will pass;
when it is repositioning;
how quickly it responds;
whether it is degraded;
and how much manoeuvring capability it retains.
The information required for collision avoidance may also help another state monitor or counter the asset.
This creates a genuine conflict between orbital safety and national security.
A military operator may disclose less information, disclose it late or share it only through trusted channels. That may be strategically rational while still increasing collision and misinterpretation risk.
An AI system can observe motion.
It cannot reliably infer whether that movement represents station-keeping, collision avoidance, inspection, intelligence collection or preparation for interference.
Five ways an orbital flash crash could begin
1. Incompatible autonomous decisions
Two manoeuvrable satellites predict an encounter.
Both decide to move in the same direction. The risk remains. Both recalculate and move again.
The problem is not necessarily bad software. The systems may use different right-of-way assumptions, decision times or optimisation goals.
One system may minimise collision probability. Another may minimise fuel use. A fleet manager may optimise constellation coverage while an onboard controller prioritises immediate local safety.
Without shared rules, “optimal” has no universal meaning.
2. Missing, delayed or corrupted information
One operator manoeuvres but does not distribute its updated ephemeris quickly enough.
Other systems continue calculating against the old trajectory. When the change is finally detected, several satellites respond late and simultaneously.
A cyberattack could create an even worse version by altering trajectory messages, delaying updates or injecting false conjunction data. The attacker would not need to control a satellite directly. It could manipulate the information upon which autonomous systems depend.
3. A constellation-wide common failure
A fleet of 10,000 satellites cannot be operated as 10,000 independent missions. It requires onboard autonomy, orbital-plane control, constellation-level planning, ground infrastructure and fault detection, isolation and recovery, or FDIR.
That scale improves coordination inside the fleet but creates common-mode risk.
A faulty update, incorrect drag model, shared navigation bias or bad decision threshold could affect thousands of spacecraft at once.
A particularly dangerous conflict could arise between control layers:
the fleet system commands one manoeuvre;
onboard collision avoidance selects another;
safe-mode logic restricts both;
and ground control is temporarily unavailable.
The system must know which authority wins before the emergency begins.
4. A space-weather disturbance
Space weather is one of the strongest possible common triggers because it can affect many operators simultaneously.
Geomagnetic storms heat and expand the upper atmosphere, increasing drag on low-orbiting objects. The response varies with altitude, spacecraft shape, attitude and mass, so satellites do not all drift identically.
At the same time, space weather can degrade communications and navigation and cause spacecraft anomalies. NOAA lists radio disruption, GPS degradation and satellite effects among the principal impacts. [6]
In February 2022, enhanced atmospheric drag following a geomagnetic disturbance contributed to the loss of 38 of 49 newly deployed Starlink satellites. [7]
At mega-constellation scale, the concern is broader than losing individual satellites. A storm could simultaneously cause:
orbit predictions to age rapidly;
conjunction warnings to multiply;
satellites to drift out of formation;
communications to become intermittent;
multiple spacecraft to enter safe mode;
and fleet managers to command widespread corrective manoeuvres.
The physical disturbance comes from the Sun. Automation determines whether the response remains controlled.
5. Strategic misinterpretation
Several foreign satellites manoeuvre near a national-security spacecraft.
Their actions may be unrelated collision responses. But without shared intent data, they could resemble coordinated proximity operations.
The state operating the sensitive satellite may not know whether it is observing:
safety manoeuvres;
inspection;
intelligence collection;
electronic interference;
or preparation for physical action.
The machines see trajectories.
Governments see potential intent.
A technical cascade could therefore become a political crisis before operators have time to explain it.
Why debris makes coordination incomplete
Not every conjunction involves two functioning satellites.
Debris cannot publish an ephemeris, negotiate right of way or fire a thruster. A failed satellite may also be unable to communicate even when its operator knows where it is.
Automated coordination can therefore reduce active-versus-active risk but cannot remove the wider debris problem.
A physical collision could produce fragments across related trajectories, converting a short-lived coordination failure into a hazard lasting years. ESA warns that debris growth and fragmentation continue to threaten the long-term usability of important orbital regions. [1]
The orbital flash crash and Kessler syndrome are not the same:
the first is a rapid information and manoeuvre cascade;
the second is a physical collision and debris cascade.
But the first could increase the probability of the second.
What would reduce the risk?
A single global controller for every spacecraft is politically unlikely and technically dangerous. It would create difficult questions over authority, classified data, cybersecurity and liability.
A more practical model is a federated orbital safety layer connecting national, commercial and civil systems.
It would require five foundations.
A minimum safety dataset
Operators should exchange authenticated information covering trajectory, uncertainty, manoeuvrability, control status and planned manoeuvres.
Sensitive operators could provide greater precision only to accredited coordination services rather than publishing everything openly.
Machine-readable intent
A spacecraft should be able to communicate a limited set of unambiguous states:
manoeuvre planned;
manoeuvre completed;
remaining passive;
unable to manoeuvre;
trajectory uncertain;
or human coordination required.
Shared rules of interaction
Autonomous systems need prior rules governing active-versus-active encounters, crewed-spacecraft priority, transit through constellation shells and conflicts between local and fleet-level controllers.
ESA’s CREAM work is already exploring automated coordination and a form of “rules of the road” between active satellites. [8]
Constellation-scale safety testing
Regulators should test more than one representative spacecraft.
Operators should demonstrate fleet stability during:
simultaneous conjunctions;
fleet-wide software changes;
communication loss;
navigation bias;
solar storms;
mass safe-mode events;
and interaction with another autonomous constellation.
Digital twins and adversarial simulations should test whether individually safe responses create emergent fleet-level hazards.
Decision records and emergency coordination
Autonomous manoeuvres should leave tamper-resistant records of the data received, risk calculated, software version used and action selected.
Governments and operators also need a rapid incident channel through which an unexplained manoeuvre near a sensitive asset can be identified as a safety response before it is interpreted as hostile.
AI is not the villain, but it raises the stakes
Most present collision-avoidance systems are not independent artificial intelligences. They rely heavily on orbital mechanics, probabilistic assessment, optimisation and operator-defined procedures.
AI and machine learning may increasingly help classify alerts, predict behaviour, optimise manoeuvres and manage fleets. ESA is already developing more automated collision-risk assessment to reduce false alerts, operator workload and response time. [5]
Automation is necessary because humans cannot manually coordinate every interaction among tens of thousands of spacecraft and far more debris objects.
The answer is therefore not to remove autonomy.
It is to prevent uncoordinated autonomy.
Earth now has emerging AI laws, including the EU AI Act, but these do not create an international operational code for autonomous spacecraft. Existing space law assigns responsibility to states for national space activities, while voluntary and national rules encourage safer behaviour. None yet provides a complete machine-to-machine traffic regime for orbit.
The missing layer is not another general declaration that space should be used responsibly.
It is an engineering governance system that tells machines what information they must exchange, how they should interpret it and which one must act when their plans conflict.
The real warning
The first orbital flash crash may not involve an explosion.
It may appear as a sudden flood of warnings, unnecessary manoeuvres, conflicting trajectories, service interruptions and emergency coordination calls.
It could begin with a software update, an unannounced national asset or a geomagnetic storm.
The dangerous sequence is straightforward:
LEO congestion provides the exposure. Incomplete data provides the uncertainty. Automation provides the speed. Common systems provide the correlation. Fragmented governance provides the gap.
The greatest risk is not that one satellite makes an obviously foolish decision.
It is that thousands make individually defensible decisions using different models, different rules and incomplete versions of reality.
Every spacecraft protects itself.
The orbital system still fails.
The danger is not one bad decision.
It is a system in which thousands of reasonable decisions combine into one catastrophic outcome.
References
[1] European Space Agency, ESA Space Environment Report 2025 and subsequent environment reporting.
[2] NASA, Spacecraft Conjunction Assessment and Collision Avoidance Best Practices Handbook.
[3] United Nations Office for Outer Space Affairs, Guidelines for the Long-term Sustainability of Outer Space Activities.
[4] Federal Communications Commission, Kuiper authorisation conditions concerning ephemeris sharing and physical coordination, 2024; FCC orbital-debris rulemaking record, 2025.
[5] European Space Agency, CREAM: Avoiding Collisions in Space Through Automation; SpaceX, space-safety information and operator-coordination materials.
[6] NOAA, Space Weather Impacts and NOAA Space Weather Scales.
[7] European Space Agency and peer-reviewed research concerning the February 2022 Starlink geomagnetic-storm losses.
[8] ESA CREAM In-Orbit Demonstration materials concerning onboard collision avoidance and active-satellite coordination.


