Executive Summary
ZeroUSV's launch of a Teledyne Slocum glider from an uncrewed Oceanus12 USV under the Royal Navy's Atlantic Bastion programme is a genuine first, but it demonstrates the easy half of the problem. For survey and metocean buyers, recovery in a seaway, not launch, sets the reliability threshold. We set out how to define the metocean operability envelope, the command-and-control failure modes, and the acceptance criteria that should govern any host-USV procurement before crewed vessel days are designed out of a campaign.
What ZeroUSV Actually Demonstrated
ZeroUSV launched a Teledyne Slocum glider from an uncrewed Oceanus12 surface vessel – by the companies’ account, the first time an ocean glider has been deployed from an autonomous USV. The work supported the Royal Navy’s Atlantic Bastion programme, part of a UK Ministry of Defence effort examining how autonomous systems can support maritime security, subsea monitoring and the protection of critical undersea infrastructure. Two Oceanus12 USVs took part in the wider trial. Teledyne Marine supplied the glider, and the demonstration sits alongside a recently announced strategic partnership between Teledyne Marine and MSubs aimed at integrating surface vessels, underwater vehicles and sensing for naval programmes.
Matthew Ratsey, managing director and co-founder of ZeroUSV, described the event as the first time the world had seen “the launching and operating of an ocean glider from an uncrewed vessel.” Arnar Steingrimsson of Teledyne Marine framed it as a capability enhancement for time-sensitive defence work – anti-submarine warfare, intelligence/surveillance/reconnaissance and rapid environmental assessment (REA) – with explicit read-across to commercial and scientific oceanography.
That read-across is the part worth examining carefully. The defence framing is clear enough. The question we think survey managers, positioning engineers and metocean buyers should be asking is narrower and harder: what does a single successful launch tell us about whether a host USV can be relied upon to carry a survey or monitoring campaign, and what does it not tell us at all.
Why a Launch Milestone Moves the Survey Cost Stack
The commercial logic of a host USV is straightforward. A small uncrewed surface vessel that can deploy, tend and recover a long-endurance asset removes the need to keep a crewed mother ship loitering on station while a glider or AUV does weeks of work. For persistent metocean monitoring, geophysical reconnaissance and environmental baseline collection, the cost that dominates is vessel time, not sensor time. Displace the crewed platform and the economics of long-duration data collection change materially.
This is why the demonstration matters beyond defence. A buoyancy-driven glider already delivers persistent, low-power observation over weeks to months. Pair it with an autonomous host that can put it in the water and bring it back, and the result is a distributed observation model that does not require a manned deck at either end of the deployment. For operators running repeat metocean lines or monitoring fixed infrastructure, that is the prize.
The prize is only real if the autonomous launch and recovery system (LARS) works across the weather window the campaign actually operates in. A milestone achieved once, in conditions chosen for the demonstration, establishes feasibility. It does not establish availability. And availability – the proportion of the planned window in which the system can be relied upon to perform – is the number that decides whether crewed days can be designed out of a campaign or whether a standby vessel has to stay in the budget anyway, which erases most of the saving.
Launch Is the Easy Half of the Problem
The binding engineering constraint is recovery, not launch. Releasing a glider is comparatively benign: the vehicle is unpowered at the surface, the host lets it go, and the glider flies itself away from the platform. Recovery inverts every favourable condition. The host is capturing a slender, low-freeboard vehicle at the surface, in a seaway, from a platform with no crew on deck to take a line, fend off, or manage a snagged recovery. Relative heave between host and glider, snap loads on the capture mechanism, and the geometry of a successful latch all degrade as sea state rises.
So a launch demonstration is necessary but a long way from sufficient. The reliability threshold for survey use is set by the recovery envelope, and that envelope sits well below the survival and transit limits of the vessel.
The metocean operating envelope is the first thing to nail down. Operability for recovery should be defined in terms of significant wave height (Hs), wave period (Tz or Tp), wind, and surface current, because each drives a different failure path. Hs and period govern relative motion at the capture point; current governs the host’s ability to hold a heading and position long enough to attempt the grab; wind drives leeway on both bodies. A USV of this class has limited freeboard and limited station-keeping authority, so the probability of a missed or aborted capture climbs steeply once Hs passes the point where relative heave exceeds the capture window of the mechanism.
Station-keeping is not a survey-line problem. Holding a heading along a planned line is one thing. Holding position to within a capture tolerance in a tideway, while a glider drifts at the surface, is another. Small USVs may not carry the propulsion redundancy or control authority that a DP-class vessel brings to that task, and the relevant figure of merit is positional excursion under the design current and sea state, not nominal track-keeping in calm water.
The command-and-control link defines the integrity loop. Over-the-horizon supervision runs over satellite, with the bandwidth and latency that implies. A recovery decision – attempt now, wait, or abort to a safe state – must either be made within that latency budget or delegated to onboard autonomy with a defined and logged decision rule. What the vehicle does on loss of link is a design question, not an operational afterthought: hold, loiter, return to a rendezvous, or abandon the attempt. Every one of those branches needs an audit trail that a class surveyor or an incident investigator can reconstruct.
Energy and reliability sit underneath all of it. Station-keeping in current burns power that transit does not, so the host’s energy budget has to be assessed against the recovery scenario, not the cruise scenario. And the LARS mechanism itself is the part most likely to introduce a single point of failure. The questions are familiar from any reliability case: mean time between failures, the proportion of recovery cycles completed without manual intervention, and the consequence of the worst-case failure – which, for an unattended deployment, can mean a stranded asset.
Data still has to meet the survey standard. Hosting a sensor from a USV changes the platform, not the acceptance criteria. Bathymetric and positioning deliverables remain bound by IHO S-44 Edition 6 total horizontal and vertical uncertainty for the relevant order, and positioning integrity should be demonstrated against IOGP guidance regardless of whether a human is on board. An autonomous host that cannot hold its positioning solution through the deployment is not a survey platform, however elegant the launch.
Where the Procurement Logic Goes Wrong
1. Reading a Launch Demonstration as a Recovery Capability
The single most common error is treating “first launch” as “proven LARS.” They are different milestones separated by the far harder part of the engineering. A buyer who specifies against the launch demonstration is buying the easy half and assuming the rest. Insist on recovery evidence, in representative conditions, before the capability goes anywhere near a campaign plan.
2. Procuring Against a Vessel, Not an Operability Envelope
Procurement that names a platform without stating the Hs, period and current limits for launch and recovery has not specified the thing that matters. Two USVs of the same class with different LARS mechanisms can have very different recovery envelopes. The envelope, demonstrated and contracted, is the deliverable. The hull is just the carrier.
3. Under-Specifying the Link and Its Failure Modes
Operators frequently scope the comms link for telemetry and forget that it is also the integrity path for a recovery decision. If the supervisory loop cannot close inside the latency budget, the decision must be made onboard, and the onboard rule must be specified, tested and logged. A loss-of-link event during a recovery attempt is a foreseeable condition, not an edge case.
4. Treating the Regulatory and Class Pathway as an Afterthought
An uncrewed surface vessel operating beyond visual range engages flag-state acceptance, COLREGs compliance for collision avoidance, and class guidance for autonomous and remotely operated ships. The IMO MASS Code is still in development, and national frameworks such as the UK industry code of practice for maritime autonomous surface ships fill the gap in the meantime. Class guidance – for example DNV-CG-0264 and the Lloyd’s Register ShipRight procedures for autonomous systems – sets out what an assurance case has to contain. Discovering the regulatory pathway after award turns a survey contract into a compliance project.
5. Confusing Endurance with Availability
A glider’s endurance is measured in weeks. The host USV’s availability for launch and recovery is measured against the weather. These are not the same property, and a long-endurance payload tied to a low-availability recovery window yields a vehicle the operator can deploy but cannot reliably retrieve when the data is in. Endurance is a payload spec; availability is a system spec, and the campaign plan depends on the second.
The linkage is worth making concrete, because availability is a function of the recovery envelope and the local wave climate, not of the payload. Take an illustrative recovery ceiling of Hs 1.5 m. In a benign window – a sheltered shelf area or a settled summer season – Hs sits below 1.5 m for a large share of the time, so a recovery opportunity is rarely far away and the host can wait out the occasional exceedance without disturbing the campaign. The same 1.5 m ceiling reads very differently in a North Sea-type winter, where Hs commonly exceeds 1.5 m for a substantial part of the month: the recovery system is then weather-limited for long stretches, the asset cannot be retrieved on demand, and a standby vessel creeps back into the plan to cover the gap. The figures are area- and season-specific and must be read off a hindcast or measured wave-climate distribution for the actual site and window – the point is the shape of the relationship, not these illustrative values. Two campaigns with identical hardware and identical glider endurance can therefore have completely different availability, purely because one operates against a kinder exceedance curve than the other. That is why the recovery envelope has to be specified against the site’s wave climate, not against the vessel’s survival limit.
How to Qualify a Host USV Before You Commit
Specify launch and recovery operability as contracted limits, then make the vendor demonstrate the recovery limit. State the Hs, period and surface-current ceilings for recovery in the contract, and require repeated successful autonomous recoveries at or near those limits – not one launch in a chosen weather window. A defensible starting point for a small USV recovering a glider is a modest envelope, for example Hs in the region of 1.5 m, with the actual figure set by the demonstrated capture performance rather than the brochure.
The brackets below are anchors for an invitation to tender, not specifications. None of them is a generic figure to be lifted into a contract unverified; each must be ratified or replaced by what the vendor can actually demonstrate. They exist so a buyer can frame an ITT and recognise an unserious number when one is offered.
- Recovery Hs ceiling: order of 1.0–2.0 m for a small low-freeboard host capturing a slender glider, with the binding figure derived from demonstrated capture performance rather than asserted. Treat anything claimed above this band without staged-trial evidence as unproven.
- Wave period: pair the Hs ceiling with a period qualifier (for example Tz roughly 5–8 s), because relative heave at the capture point is driven by period as much as height; an Hs limit quoted with no associated period is incomplete.
- Surface-current limit for station-keeping: typically a fraction of a knot to around 1 knot for a small USV holding a capture position, set by demonstrated positional excursion under load, not by the propulsion rating.
- Latency ceiling for the supervisory decision loop: seconds for a human-in-the-loop attempt-or-abort decision over satellite; anything longer forces the decision onboard and makes the autonomous decision rule, not the link, the deliverable.
- MTBF for the LARS mechanism, abort-rate ceiling, and minimum consecutive successful recoveries: no defensible generic figure exists for these – they must be derived from the vendor’s demonstrated capture record across the contracted envelope. Require the underlying trial data and set the acceptance numbers from it; a target offered with no trial population behind it is an adjective.
Set an availability target and an abort-rate ceiling, and tie acceptance to them. Define the minimum number of consecutive successful autonomous recovery cycles required for acceptance, a target mean time between LARS failures, and a maximum acceptable mission-abort rate across the design metocean envelope. Without these numbers, “reliable” is an adjective, not an acceptance criterion.
Contract the link budget and the loss-of-link behaviour. Specify a latency ceiling for the supervisory decision loop, the mandated safe-state behaviour on loss of link during and outside a recovery attempt, and the logging that allows any abort decision to be reconstructed after the fact. The decision rule is part of the deliverable.
Engage the regulatory and class pathway before award, not after. Confirm flag-state position, COLREGs collision-avoidance evidence, and the applicable class guidance early, and require the vendor to bring a written assurance case structured to it. Treat the autonomous LARS proving like DP and FMEA proving on a conventional vessel – staged trials across the envelope, with documented failure-mode response – and run acceptance trials in that spirit, drawing on IMCA’s approach to demonstrating system behaviour under fault conditions.
Hold the survey deliverable to the same standard as a crewed platform. Acceptance of bathymetric and positioning data should be against IHO S-44 Edition 6 for the contracted order, with positioning integrity demonstrated to IOGP guidance. The host being uncrewed changes nothing about the uncertainty budget the client signs off.
Define the asset-loss contingency before deployment. A stranded or non-recovered glider is a foreseeable outcome of an autonomous recovery that fails outside the envelope. Agree the recovery contingency, the responsible party, and the insurance position in advance, so a missed capture is a planned procedure rather than an incident.
The ZeroUSV demonstration is a real step, and the host-and-deploy model it points towards is the right direction for persistent, distributed ocean data collection. For a survey buyer, the discipline is to separate the milestone from the capability. Launch was demonstrated. Recovery, across the weather a campaign actually works in, is the threshold that decides whether the crewed vessel can come out of the plan – and that is the number to write into the contract.
Based on: ZeroUSV autonomously deploys ocean glider at Atlantic Bastion exercise
Published by
Unmanned Systems Review Board
ROV, AUV & Autonomous Subsea Systems
A technical review board evaluating ROV and AUV capabilities, autonomous inspection methodologies, and unmanned subsea system integration for survey and construction support.