Kairos Power: Licensing a First-of-a-Kind Fluoride Salt Reactor
How an advanced fission company is building the systems engineering foundation to put a novel reactor design through NRC licensing — without a regulatory playbook to follow
Nuclear licensing has always been a systems engineering problem first and a physics problem second. The NRC does not license reactor physics. It licenses documented, traceable arguments that a specific design will maintain safety functions under defined conditions — and that the organization building it understands what it has designed well enough to operate it safely.
For conventional light water reactors, that documentation burden is severe but manageable. Decades of operating experience, established regulatory guidance, and a body of accepted analysis codes give applicants a known path. For Kairos Power and its fluoride salt-cooled high temperature reactor, no such path exists. The KP-FHR uses a pebble bed fuel form, a flibe (lithium-fluoride beryllium-fluoride) coolant, and operates at temperatures and pressure conditions that share almost nothing in common with the PWR and BWR designs that NRC staff know best. Every element of the licensing basis — safety classification, design basis events, acceptance criteria, analysis methodology — has to be constructed from scratch, argued with the regulator, and kept internally consistent across a requirements hierarchy that is itself still being developed.
That is not a complaint about Kairos Power’s situation. It is a description of the systems engineering challenge they have chosen to take on, and the way they are taking it on is worth examining carefully.
What the KP-FHR Actually Is
Before addressing the licensing and systems engineering dimensions, it helps to be precise about the technology, because the technical properties of the design drive most of the regulatory difficulty.
The KP-FHR uses pebble fuel — spherical graphite-matrix fuel elements about the size of a billiard ball, each containing thousands of TRISO (tristructural isotropic) fuel particles. TRISO particles have a strong independent safety case: each particle has its own multi-layer ceramic containment, and the particles have been demonstrated to retain fission products at high temperatures without relying on active cooling. That property is central to the KP-FHR’s safety architecture.
The coolant is flibe, a molten salt operating at roughly 600–700°C and near-atmospheric pressure. Compared to water-cooled reactors, this means no high-pressure primary system — which eliminates an entire class of loss-of-coolant accidents. Flibe is also chemically stable, optically transparent, and has a high volumetric heat capacity. It does not flash to steam. It does not react violently with air or water. These properties simplify some safety arguments considerably.
The combination — high-temperature capable fuel with inherent retention characteristics, a chemically benign low-pressure coolant — is intended to produce a reactor with what Kairos describes as a “robust safety basis”: one where the fundamental safety case does not depend on active systems or operator action for design basis events. The reactor should be able to sit, lose cooling, lose power, and not produce a radiological release that exceeds off-site dose limits.
That safety logic is compelling and, if validated, would genuinely simplify siting and emergency planning. But compelling logic is not the same as a licensed design. The NRC needs traceable, verified arguments at every level.
Building a Licensing Basis Without Precedent
The core systems engineering challenge at Kairos is that they cannot simply point to existing regulatory guidance and say “we comply.” NRC regulatory guides, standard review plans, and accepted analysis codes were developed for light water reactors. Many of them do not apply to a molten salt system in any straightforward way.
This means Kairos has to do something unusual: they must develop the technical basis for their own regulatory framework in parallel with developing the design. The NRC’s Part 53 rulemaking — a new, technology-inclusive licensing framework intended to replace the more prescriptive Part 50 pathway for non-LWR designs — is still being finalized. Kairos has been active in that process, because the framework that eventually governs their commercial plant is partly being written in real time.
For the Hermes demonstration reactor, Kairos used 10 CFR Part 50 — the existing framework — with extensive engagement with NRC staff to establish what specific guidance applies and what requires alternative arguments. This is a legitimate approach, but it requires extensive pre-application interaction, detailed white papers for novel technical areas, and a tolerance for regulatory uncertainty that most large organizations are not structured to absorb.
The design basis itself — the set of postulated events and conditions the design must withstand without exceeding safety limits — had to be constructed by analogy and first-principles argument. For a PWR, the design basis event list is well-established. For a KP-FHR, Kairos had to systematically identify what initiating events are credible given the specific technology, argue that the set is complete, and then demonstrate that each event is bounded by analysis.
That argument structure — initiating events, safety functions, systems credited in the response, acceptance criteria, analysis methodology — is a requirements hierarchy, even when it is not described in those terms. Every element has to be internally consistent and traceable to the licensing basis. A change to a system or component anywhere in that chain has the potential to invalidate analyses downstream.
Safety Classification as a Requirements Discipline
One of the most consequential decisions in nuclear systems engineering is the safety classification system. For light water reactors, the classification hierarchy — safety-related, augmented quality, non-safety — determines procurement standards, testing requirements, documentation requirements, and design change control. It is, in effect, a requirements management system built into the regulatory framework.
For non-light-water reactors, the inherited classification language often does not map cleanly. Kairos has had to develop a classification scheme that preserves the underlying logic — structures, systems, and components important to safety require more rigorous treatment — while connecting it to the specific safety functions their design relies on.
The KP-FHR’s safety functions are different from an LWR’s. Because the fuel is capable of retaining fission products independently and the coolant is low-pressure, the primary containment function works differently. The passive decay heat removal approach works differently. The approach to accident source term estimation is different. Each of these differences requires the safety classification system to be grounded in the actual safety analysis rather than inherited from precedent.
Getting this right matters enormously. Misclassify a system as non-safety-related when the licensing basis actually relies on it, and the entire safety case is compromised. Over-classify everything as safety-related and you’ve imposed qualification costs that are unnecessary and that undermine the economic case for the technology. The right answer requires a tight coupling between the requirements hierarchy and the safety analysis — and that coupling has to be maintained as both evolve.
Hermes as a Systems Engineering Instrument
The Hermes demonstration reactor — a non-power test reactor sited at the East Tennessee Technology Park in Oak Ridge — is frequently described in press coverage as a “stepping stone” to the commercial KP-X plant. That is accurate but understates its systems engineering function.
Hermes is, among other things, a risk-reduction mechanism designed to resolve key technical uncertainties before Kairos commits to the design decisions that will be locked into a commercial licensing basis. Some of those uncertainties are operational: How does pebble fuel behave in a circulating fluoride salt system over extended operation? What are the actual tritium production and management characteristics of flibe at operating temperature? How do instrumentation and control systems perform in the thermal and chemical environment of the primary circuit?
These are not questions that can be fully answered by analysis alone. Kairos’s engineering culture explicitly recognizes this. The company has been public about its belief that hardware testing produces knowledge that modeling and simulation cannot fully substitute for, and that iterating on physical hardware — even at significant cost — is more reliable than attempting to analytically bound every uncertainty before building anything.
That posture is unusual in nuclear development, which has historically leaned heavily on analysis-first approaches, partly because hardware testing at reactor scale is extraordinarily expensive and time-consuming. Kairos is attempting to compress the learning cycle by building Hermes at a scale and cost that is meaningful for learning but not prohibitive — and by being disciplined about what Hermes specifically needs to teach.
The systems engineering challenge this creates is managing the interface between test-driven learning and formal requirements discipline. When a test reveals something unexpected — about pebble behavior, about coolant chemistry, about a component’s performance — the organization needs processes to evaluate whether that finding requires a change to the design basis, a revision to a safety analysis, or a change to a classified system. That evaluation loop has to be fast enough to preserve the learning value of the test program, but rigorous enough that changes don’t propagate through the requirements hierarchy in ways that aren’t tracked.
The Tension Between Iteration and Locked Requirements
This is the deepest systems engineering tension in Kairos’s situation, and it is worth being direct about it.
NRC licensing inherently rewards stability. A design that changes frequently imposes review burden on the regulator, introduces the risk of internal inconsistencies in the licensing basis, and raises questions about whether the applicant understands their own design well enough to license it. The incentive structure pushes toward locking requirements and design decisions as early as possible.
An iterative, hardware-testing engineering culture pulls in the opposite direction. The whole point of testing is to learn things that change what you do. If Hermes reveals that a particular component design needs modification, the right engineering response is to modify it — not to suppress the finding because the requirements document already says something different.
Kairos has to operate in both of those worlds simultaneously, and the way they manage the interface says a great deal about their organizational maturity.
The approach, from what is visible in their public filings and technical program descriptions, involves a staged commitment to design decisions — using the Hermes program to resolve key uncertainties before those decisions have to be locked for a commercial licensing application, rather than after. This is the right strategy, but it requires extraordinary discipline in sequencing: knowing which decisions can remain open during Hermes operation, which must be made before Hermes starts up, and which can be informed by Hermes results before being committed to in a construction permit application for KP-X.
What Kairos Is Actually Attempting
Kairos Power is not just trying to build a reactor. They are attempting to demonstrate that a novel reactor technology can be licensed in the United States through a rigorous, credible process — and that the licensing process itself can be completed in a timeframe that is relevant to current energy needs.
That second goal is as important as the first. If the KP-FHR takes as long to license as some Generation IV concepts have taken to develop, the technology arrives too late to influence the near-term energy transition. Kairos has been explicit that speed matters, and their incremental strategy — Hermes first, then KP-X — is partly designed to demonstrate to the NRC, the industry, and potential customers that the licensing process is tractable.
The systems engineering discipline required to support that strategy is substantial. The requirements hierarchy has to be rigorous enough to satisfy NRC review, flexible enough to accommodate ongoing learning, and maintained with enough consistency that changes in one part of the basis don’t silently invalidate arguments in another. The safety classification system has to be novel enough to fit the technology and conservative enough to be credible to a regulator unfamiliar with fluoride salt systems. The design basis has to be complete, the analysis methodology accepted, and all of it documented in a form that NRC staff can review.
None of that is a software problem or a process problem in isolation. It is a systems engineering problem that requires the organization to know, at any given moment, what they have decided, why they decided it, what evidence supports it, and what would cause them to revisit it.
Whether Kairos Power can sustain that discipline through the full licensing cycle — and what the nuclear industry learns from the attempt regardless of outcome — is one of the more consequential engineering stories in energy right now.