The argument for Continuous Deployment is that you _always_ see problems in production, and that all you are injecting from moving from a staged-release cycle to CD is that you are now seeing 10-15% more issues (Let's say 60 P2 or greater Issues instead of 50 P2 or greater Issues), but the cost of fixing everything has dropped significantly, fixes occur much, much more quickly (sometimes same day instead of multiple months), and you are able to enjoy the productivity advantages of your software that is finely tuned to the users needs much, much more quickly. CD can (and usually does) result in less downtime than stages releases - mostly because of the rapid cycle from coding -> error detection -> problem resolution.
The _only_ problem as I see it, is that you don't have as much control over the probability of a P1 issue hitting your system. That's fine in the case of something like Amazon.com, where a P1 issue might cost the organization $10 million dollars, but they've received $50 million dollars in value from using CD. It's not the case where a P1 issue might result in a catastrophic loss measured in 10s of Billions of dollars (Power Grid, Shuttle Launch, Nuclear Systems) - for those, you need to stage ensure 100% coverage/regression/code review. In fact, you need 100% coverage/review of your _development techniques_, not just the code produced.
The capability to monitor, deploy, and rollback new features/fixes on short notice would seem to be a part of that, even if actually used infrequently. I would think that you would need to be able to respond to a change in the environment the system is operating in as much ensure that a new release doesn't contain bugs that would manifest in your current understanding of the operating environment.
I am suggesting that much if not all of the infrastructure needed to reliably patch/rollback critical systems can also be used for continuous deployment at the option of the development team and/or the customer.
So in the event that a P1 hit a continuously operating network application (e.g. power grid) the ability to deploy and rollback new features rapidly in response might be a valuable option to have. It's an approach that increases resilience. This does not mean you have to do this all of the time.
Perhaps the closest example I can think of with regards to continuous deployment in mission critical situations are the martian rovers - I think they had some real-time deployment of new code. But, the implications of a problem with them were relatively minor - a few hundred million dollars, and no lives lost.
Are there any examples of continuous deployment in a scenario in which hundreds of lives and/or billions of dollars are at stake?