Tuesday, 6 October 2026

THE MALICIOUS INSIDER IN THE FLIGHT DECK

 Lessons from flydubai FZ1073 and Earlier Cases of Deliberate or Suspected Crew Action

A Low-Probability, Catastrophic-Risk Threat

The 30 September 2026 incident aboard flydubai flight FZ1073 from Dubai to Tel Aviv has reopened one of commercial aviation's most uncomfortable security questions: what happens when the threat is not outside the cockpit, but is a trained, credentialed and trusted person already inside it? UAE authorities have stated that the co-pilot attacked the captain with a crash axe and attempted to seize the flight controls, describing the act as an attempted terrorist attack. The aircraft was eventually brought under control and safely diverted to Tabuk, Saudi Arabia. The investigation into motive, prior planning, possible associates and failures in personnel vetting remains open.

The event should not be used to stigmatised professional pilots. Deliberate hostile acts by flight crew remain extraordinarily rare. However, their potential consequences are catastrophic, and they expose a vulnerability that ordinary hijack-prevention measures cannot address. Reinforced cockpit doors, access codes and passenger screening are designed primarily to keep an unauthorised attacker out. They offer little protection when the attacker already has legitimate flight-deck access.

The Historical Record: Not One Phenomenon, but Several

FZ1073 is not without precedent, although earlier events fall into different evidential and motivational categories. FedEx Flight 705 in 1994 remains one of the clearest insider-threat cases. An off-duty FedEx flight engineer, travelling in the cockpit jump seat, attacked the operating crew to seize the DC-10. Despite severe injuries, the crew fought back and landed safely. The significance is fundamental: the attacker was not an outsider breaching aviation security. He was an authorised employee with technical knowledge and trusted access.

EgyptAir Flight 990, a Boeing 767 that crashed into the Atlantic in 1999, falls into a more complex category. The NTSB concluded that the aircraft's departure from normal cruise and impact resulted from the relief first officer's flight-control inputs, while explicitly stating that the reason for those actions could not be determined. The CVR included repeated religious expressions, but those words cannot be responsibly treated as proof of religious motivation or terrorism. The case demonstrates the need to separate three questions: who manipulated the aircraft, whether the manipulation was deliberate, and why it occurred.

SilkAir Flight 185 is similarly disputed. The Indonesian investigation did not determine a cause, whereas the US NTSB concluded that the evidence was most consistent with deliberate control inputs. It is therefore relevant as a suspected case, but not as an established example of pilot suicide.

LAM Mozambique Flight 470 and Germanwings Flight 9525 are far less ambiguous. Investigators concluded in both cases that a pilot deliberately caused the aircraft to descend while alone in effective control of the flight deck. Germanwings prompted major changes in European policy on pilot psychological assessment, support programmes and substance testing.

Malaysia Airlines MH370 again belongs in a separate evidential category. The loss of normal communications, major route deviation and continued flight for many hours inevitably generated hypotheses involving deliberate human action. Yet the main wreckage, CVR and FDR have not been recovered, and the official investigation could not determine the cause. MH370 therefore illustrates the consequences of the loss of assured control, tracking and communications, but should not be presented as a proven pilot-suicide event.

The Common Vulnerability: Trusted Access

These cases differ in motive and certainty, yet they expose a common structural weakness: aviation systems are built on the assumption that authorised personnel will support the safe completion of the flight. A pilot, engineer, instructor, check pilot or other authorised crewmember can bypass layers of security precisely because the system is designed to trust that individual.

This is why the term “rogue pilot” is too narrow. The more useful concept is the malicious insider threat to the flight deck. It includes operating pilots, deadheading crew, engineers and other employees with privileged access. The risk may arise from terrorism, personal grievance, deliberate self-destruction, coercion or acute behavioural breakdown. These pathways are not interchangeable, nor are their countermeasures.

FZ1073 also raises a specific concern about cross-border personnel information. Modern pilots may train in one country, hold a licence issued by another, and work successively for several international operators. If one State or employer has imposed a serious security-related restriction, that information must not simply disappear when the individual crosses a jurisdictional boundary.

Where Current Defences Remain Weak

ICAO's Insider Threat Toolkit already recognises that background checks should be recurrent and that continuous vetting should be encouraged, including cooperation with authorities in other States. Importantly, ICAO notes that some insiders develop malicious intent only after employment. Pre-employment screening is therefore necessary but insufficient.

The United States Pilot Records Database offers another useful model. It requires covered operators to review available training, qualification, disciplinary and separation records before employing a pilot. It is not a global security database, but it shows that structured, regulated sharing of employment history can be achieved without compromising due process.

The post-Germanwings European response introduced psychological assessment before line flying, pilot support programmes and enhanced drug and alcohol testing. These are valuable aeromedical barriers, but psychological screening must not be confused with security vetting. A terrorist insider, a suicidal pilot and a pilot with a treatable mental-health condition are distinct problems. Treating them as one can both miss genuine threats and discourage pilots from seeking medical help.

A Layered Preventive Strategy

The priority should be an internationally compatible system for recurrent personnel security vetting. National authorities should be able to flag serious aviation security restrictions to one another via secure regulator-to-regulator channels. Airlines need not receive intelligence details; they do need to know when an applicant or serving crew member requires further security review before granting unrestricted cockpit access.

Second, airlines must verify previous employment directly rather than infer it from a CV. Relevant records should include serious disciplinary action, separation from employment, unresolved security restrictions and documented safety-significant behaviour. A non-response from a previous employer should trigger further review, not automatic clearance.

Third, airlines need robust, confidential reporting and peer-support systems. Colleagues often notice significant behavioural changes before management does. Reporting mechanisms should enable instructors, pilots and cabin crew to raise genuine concerns while protecting employees from arbitrary accusations based on nationality, religion, political opinion or routine mental-health treatment. Security assessments must be intelligence-led and behaviour-based, not discriminatory.

Fourth, operators should review cockpit procedures to address malicious interference. CRM traditionally assumes that both pilots ultimately share the objective of safe flight. A hostile crew member violates that premise. Training should therefore address deliberate interference with controls, assault or incapacitation of one pilot, rapid cabin-crew intervention, emergency cockpit access, and communication with ATC. This is not an argument for turning pilots into security officers; it is an argument for recognising an extreme but credible contingency.

Fifth, FZ1073 justifies a technical review of emergency equipment, such as the crash axe. Removing it automatically may create a new hazard, as crews may need it during a fire, structural damage or evacuation. However, its location, retention, accessibility and tamper indication should be assessed against the insider-threat scenario.

Finally, insider threat belongs at the intersection of the airline's Safety Management System (SMS) and Security Management System (SeMS). Safety departments traditionally analyse errors, equipment failures and procedural breakdowns, while security departments focus on hostile acts. FZ1073 shows why these domains must intersect. A malicious insider may exploit normal operational authority to create a safety catastrophe in seconds.

Conclusion

Aviation has spent the past quarter-century making the cockpit extraordinarily difficult for an outsider to penetrate. The next challenge is to ensure that trusted access does not itself become the vulnerability. FedEx 705, EgyptAir 990, SilkAir 185, LAM 470, Germanwings 9525, the unresolved disappearance of MH370, and now FZ1073 show that the issue cannot be reduced to a single motive or medical diagnosis.

The probability of deliberate hostile action by authorised aviation personnel remains very low. However, the consequences could be catastrophic. The correct response is neither suspicion of the pilot profession nor intrusive surveillance of every crew member. It is a layered security architecture: verified international employment histories, recurrent and continuous vetting, regulator-to-regulator information sharing, effective peer-support systems, carefully governed reporting, route-sensitive risk assessment, and explicit insider-threat planning within both SMS and SeMS.

The most important question arising from FZ1073 may therefore be broader than the alleged act itself: if relevant warning information existed before the flight, why did the aviation system fail to turn that information into an effective barrier? The answer will determine whether FZ1073 becomes merely another extraordinary incident - or the catalyst for a more mature global approach to flight-deck insider risk.


Author: GR Mohan

Friday, 18 September 2026

Miami Runway Excursion: A Failure of Barriers Before the Runway End

 The 21 Air Boeing 767 accident in Miami on 6 September 2026 is disturbing not merely because an aircraft overran a runway with fatal consequences. It is disturbing because preliminary evidence suggests that several established safety barriers may have been progressively breached before the aircraft even left the paved surface.

The NTSB investigation remains ongoing, and it has not yet determined a probable cause. Yet within three days of the accident, the Board released verified information from the Cockpit Voice Recorder and Flight Data Recorder. That preliminary sequence already raises serious questions about stabilised-approach discipline, Crew Resource Management, cockpit authority gradient, training and organisational safety culture.

The emerging picture is stark.

Configuration for landing was delayed. Flaps 5 was called less than three minutes before the end of the CVR recording, followed by landing gear, Flaps 15 and Flaps 20. When Flaps 20 was called, the other pilot cautioned that the aircraft was too fast. The NTSB states that this pilot made further comments about excessive speed throughout the remainder of the recording, and the pilot flying did not consistently respond.

The autopilot was subsequently disengaged. The automated 1,000-foot call was followed by a “sink rate” warning. Another “sink rate” warning occurred below 500 feet. Around minimums, repeated “too low terrain” alerts were issued. Flaps 30 were not called until approximately 41 seconds before the recording ended, immediately before the final radio-altitude callouts and touchdown.

This is precisely the type of sequence that the stabilised-approach criteria are designed to prevent.

A stabilised approach is not an aspirational description of a good approach. It is a procedural safety barrier against continuation bias, deteriorating energy states, and last-minute improvisation.

At the designated stabilisation gate, the aircraft should be on the correct flightpath, properly configured, within prescribed speed and descent-rate limits, and the crew should be ready to land. If those criteria are not met, the required response should be unequivocal:

GO AROUND.

The precise company criteria applicable to this flight must be established by the investigation. However, irrespective of the individual numerical limits, the sequence raises a fundamental question:

Why did accumulating deviations and repeated warnings not produce decisive intervention?

CRM is intervention—not commentary

That question extends well beyond the pilot flying.

a) The pilot monitoring is not a spectator.

b) There is an important difference between:

“Too fast.”

and

“UNSTABLE—GO AROUND.”

The first describes a condition.

The second triggers a safety defence. Effective CRM requires monitoring, challenging, responding and, where necessary, escalation. If the aircraft continues through a mandatory stability gate outside limits, repeatedly describing the deviation cannot, by itself, constitute an effective defence.

The investigation therefore needs to establish whether stabilised-approach calls were clearly defined, whether a go-around became mandatory once specified criteria were exceeded, and whether the pilot monitoring was explicitly authorised to insist on it.

But another important human-factors question should also be examined:

Was there a cockpit authority gradient?

A steep cockpit gradient can significantly reduce the monitoring pilot's effectiveness.

If one pilot is substantially more senior, more experienced, holds a training or checking position, or otherwise has greater organisational authority, the other pilot may be reluctant to challenge decisions forcefully. The PM may recognise that an approach is deteriorating and may even repeatedly verbalise concern, yet stop short of the decisive intervention that CRM requires.

Nothing currently released by the NTSB establishes that such a gradient existed on Flight 7598. It would therefore be incorrect to assert that it did.

But the recorder’s summary makes the question legitimate.

One pilot repeatedly expressed concern about excessive speed. The approach nevertheless continued, and the NTSB specifically notes the lack of a consistent verbal response.

Investigators should therefore examine the pilots' respective qualifications, seniority, flying experience, company roles, and previous professional relationship.

a) Was the PM hesitant to challenge the PF?

b) Was an excessive authority gradient present?

c) Was there deference arising from rank, experience or training status?

d) Did the airline's CRM programme specifically teach pilots how to handle such gradients?

e) Most importantly, were pilots trained that once a defined safety limit had been crossed, procedural authority superseded cockpit hierarchy?

In a mature CRM environment, rank should become irrelevant if a mandatory safety criterion is violated.

The correct call from the more junior pilot must carry exactly the same operational weight as one from the captain.

From an approach problem to a runway emergency

The touchdown sequence shows how quickly options disappeared.

The FDR recorded the nose and right main gear touching down at 158 knots. Braking began around 146 knots, and the left main gear did not register touchdown until approximately 134 knots. These values cannot be conclusively interpreted without weight, VREF, wind, touchdown position and runway conditions, but the sequence clearly warrants detailed examination.

What happened next is particularly significant.

At approximately 120 knots, the brakes were released, and the thrust was increased to a value consistent with go-around thrust. The CVR also recorded a go-around call.

Four seconds later, the throttles were returned to idle, and the brakes were reapplied at approximately 117 knots. The aircraft subsequently departed the paved surface. The FDR also showed no indication that either speed brakes or thrust reversers had been deployed before recording ended.

The investigation must establish why the go-around was initiated after touchdown and then abandoned, and why the principal additional deceleration systems were apparently not deployed.

But operationally, the broader lesson is clear.

A relatively straightforward decision available hundreds of feet earlier had become far more difficult:

Continue stopping—or attempt to fly again?

That is exactly the predicament that stabilised-approach gates are intended to prevent.

The investigation must move beyond the cockpit

Nevertheless, it would be inadequate to treat Miami as simply an error by two pilots.

The more important investigation may lie upstream.

What was the operational culture at 21 Air?

How rigorously were the stabilised-approach and mandatory go-around policies enforced?

Were pilots genuinely encouraged to go around without concern for schedule disruption, additional fuel consumption or criticism?

Did recurrent simulator training realistically expose crews to continuation bias, high-energy approaches, late configuration, rejected landings and assertive PM intervention?

Did CRM scenarios deliberately place junior pilots opposite dominant or highly experienced captains and require them to escalate from advisory language to a mandatory go-around call?

That last point matters greatly.

CRM training is incomplete if crews practise cooperation only when both pilots agree. Its true test is whether the less authoritative cockpit member can intervene effectively when the more authoritative one persists with an unsafe course of action.

The investigation should also examine line checks, recurrent simulator reports, Flight Data Monitoring, and internal safety reports.

a) Were there any previous high-energy or unstable approaches?

b) Was late configuration occurring during the operation?

c) Were crews continuing below stabilisation gates?

d) Had FDM identified such trends?

e) If so, what corrective action was taken?

A mature Safety Management System should identify these precursors before they culminate in an accident.

Safety culture is therefore not demonstrated merely by having a stabilised-approach policy in the operations manual.

It is demonstrated when a junior first officer believes, without hesitation, that calling “GO AROUND” to a senior captain will be supported by the organisation.

Transparency is another safety barrier

Miami also offers a second important lesson.

The NTSB did not wait for the final report before communicating established facts. It held public briefings and released preliminary recorder data, while clearly stating that the data were preliminary and subject to change. The investigation remains ongoing.

That distinction is crucial.

Transparency is not premature judgement.

Verified facts can be disclosed without assigning blame or stating probable cause.

The contrast with recent Indian investigations inevitably raises questions about whether more frequent disclosure of established safety-relevant facts could reduce the information vacuum between formal reports.

Information vacuums do not eliminate speculation. They often fuel it.

Responsible disclosure strengthens confidence, allows operators to review their own procedures, and enables safety lessons to circulate before a final report is completed.

The wider lesson

The central question arising from Miami may ultimately not be simply:

Why did the pilot flying continue?

It may be:

Why did the system surrounding that pilot fail to stop the continuation?

That encompasses the PF, the PM, possible cockpit gradient, SOPs, recurrent training, checking, FDM, SMS and management culture.

What is concerning is a mechanism by which a PM can recognise the hazard and repeatedly voice concern yet still fail to escalate to an effective intervention.

Accidents rarely result from a single defence failing. They occur when successive barriers fail, are bypassed, or become ineffective.

Miami offers an opportunity to examine precisely such a progression.

The NTSB is also demonstrating another principle equally important to aviation safety:

An investigation can be rigorous without being silent and transparent without being premature.


Author: GR Mohan

Thursday, 10 September 2026

Potomac Mid-Air Collision: A Failure to Convert Warning Signs into Safety Action

 The most important lesson from the January 2025 mid-air collision near Washington National Airport is not that a single crew or controller made an isolated mistake. Rather, multiple agencies had warning signs of an emerging collision risk, yet the system failed to translate those warnings into effective preventive action.

The NTSB investigation found that the hazard was neither unknown nor unforeseeable. The airspace around DCA had a documented history of close encounters between helicopters and commercial aircraft. Pilots and controllers had raised concerns. Safety databases recorded relevant events. Local working groups had discussed the geometry of Helicopter Route 4 and its proximity to the Runway 33 approach.

Over the three years preceding the accident, FAA/ASIAS analysis identified 15,214 encounters between commercial aeroplanes and helicopters in which lateral separation was less than 1 nautical mile and vertical separation was less than 400 ft. This averages roughly 390 proximity events per month. On the northern segment of Route 4—the accident area—analysis of the preceding 12 months showed that 49% of helicopter flights exceeded the published route altitude at least once, and 17% of all recorded track points on that segment were above the altitude limit.

Yet meaningful mitigation did not occur before the fatal accident. This was fundamentally a failure of the Safety Management System across organisational boundaries.

A Known Hazard

Helicopter Route 4 passed close beneath the Runway 33 approach path. Under certain conditions, the theoretical vertical separation between a helicopter operating at the published route altitude and an arriving airliner could be as little as 75 ft.

Such a margin depended heavily on precise altitude compliance, correct altimeter indications, controller situational awareness, successful visual acquisition, and timely intervention.

This was therefore not a robustly separated traffic system. It relied on several safety barriers functioning correctly every time.

Repeated close-proximity events should have prompted progressively stronger risk assessment. Instead, individual occurrences appear to have been treated largely as separate incidents rather than as evidence of a recurring systemic hazard.

Data Existed, but Risk Was Not Integrated

The FAA, controllers, airline crews and military helicopter operators each possessed parts of the safety picture.

Pilot and controller reporting systems recorded reports. Surveillance and proximity data were available. TCAS events had occurred. Operational concerns had been raised locally.

But an SMS is not effective merely because data are collected. Its purpose is to connect the sequence:

hazard identification → risk assessment → mitigation → safety assurance.

At DCA, that loop was not closed effectively.

The problem was fragmentation. FAA route planners saw one aspect of the risk. Controllers saw another. Airlines and their crews experienced yet another. The Army held its own operational and training information. No single organisation appears to have assembled these inputs into a shared conclusion that the collision risk had become unacceptable.

That is a major systemic failure.

FAA and ATC Failures

The FAA bears significant responsibility because it controlled both the airspace design and the wider safety framework.

The NTSB found that helicopter routes were not reviewed and reassessed with sufficient rigour, despite accumulating safety information and prior recommendations. The Route 4 geometry should have prompted reconsideration well before the accident.

At tower level, high workload and combined controller positions further reduced resilience. The controller had to manage helicopter and fixed-wing traffic in a complex night-time environment. This affected situational awareness, traffic advisories and the ability to recognise the developing conflict.

The deeper issue is not simply a controller error. It is whether ATC management had allowed a demanding operating configuration to become routine without a sufficiently robust real-time risk-assessment process.

When controllers are repeatedly required to “make the system work” under high workload and tight margins, that is itself a safety warning.

Overreliance on Visual Separation

The system also relied heavily on pilot-applied visual separation.

That is particularly vulnerable at night, when distance, closure rate and aircraft identity are harder to judge. Night-vision goggles restrict the field of view and can complicate visual acquisition.

In such circumstances, “traffic in sight” should not serve as the primary defence against inadequate route separation.

Visual separation should supplement safe airspace design, not compensate for poor geometry.

Army Safety-Management Failures

The Army also had significant responsibilities.

Helicopter altitude compliance was critical because even small deviations could materially reduce the already limited vertical separation.

The investigation identified shortcomings in understanding altimeter tolerances and in the Army’s broader safety-management processes. A stronger SMS, supported by flight-data monitoring and systematic analysis of altitude exceedances, should have determined whether Route 4 operations were routinely eroding the intended safety margin.

Without that feedback mechanism, potentially important trends were not translated into operational change.

Technology Was an Incomplete Defence

Collision-avoidance technology could not be relied on as a final safeguard.

TCAS protection is limited close to the ground, and helicopter surveillance and ADS-B capabilities were not always equivalent to those of commercial aircraft.

This reinforces a basic principle: collision-avoidance systems should be the last line of defence, not the primary solution to poor traffic geometry.

The system should have prevented the aircraft from coming so close in the first place.

A Failure Across Agencies

The strongest conclusion is that responsibility was shared.

The FAA was responsible for airspace design, route review and ATC safety oversight.

a) ATC management was responsible for staffing, workload, position combining and operational risk controls.

b) The Army was responsible for helicopter operations, altitude discipline, training and its own SMS.

c) Airline and controller reports provided further warning data.

d) Yet the overall system failed to integrate these inputs into a unified risk picture.

This is precisely where inter-agency safety management becomes critical. When several organisations share the same airspace, no agency can assess safety solely within its own organisational boundaries. The risk belongs to the system as a whole.

The NTSB’s Recommendations

The NTSB consequently recommended wide-ranging measures, including:

1) redesign and regular review of helicopter routes;

2) stronger vertical and lateral separation criteria;

3) improved analysis and sharing of close-proximity data;

4) better ATC workload and position-combining controls;

5) improved real-time operational risk assessment;

6) stronger controller training in visual separation and threat management;

7) improvements to conflict-alert systems and frequency management;

8) broader ADS-B In and collision-avoidance capability; and

9) stronger Army SMS, flight-data monitoring and altitude-awareness training.

These recommendations are important because they address the system that allowed the risk to persist, not merely the actions of those operating when the final barriers failed.

The Larger Lesson

The Potomac collision should therefore be seen as a classic example of the difference between having safety-management processes and operating an effective SMS.

a) Reports existed.

b) Close calls occurred.

c) Data were available.

d) Concerns had been raised.

e) Yet the risk remained substantially unmitigated.

A near miss is not evidence that the system worked. It is evidence that some barriers failed, while others narrowly prevented an accident. Repeated near misses are even more serious. They indicate that the system may be repeatedly approaching its safety boundary.

The tragedy at DCA was therefore not simply the result of one night's errors. It was the culmination of known hazards, recurring precursor events, fragmented safety information, weak inter-agency risk management, inadequate route design, excessive reliance on visual separation, and delayed corrective action.

The central safety lesson is hard to ignore:

When multiple agencies possess warning signs of a foreseeable hazard but fail to integrate and act on them, the failure is systemic long before the accident occurs.


Author: GR Mohan

Wednesday, 9 September 2026

AI2379 AND AI171: INVESTIGATIVE INDEPENDENCE CANNOT BECOME INSTITUTIONAL SILENCE

 A preliminary accident report is not expected to determine causation, provide an exhaustive analysis, or pronounce definitive conclusions. But that limitation cannot serve as a convenient justification for withholding pertinent facts already established. Investigative independence and transparency are not competing principles. A credible investigation requires both.

The Aircraft Accident Investigation Bureau (AAIB) therefore needs to confront a fundamental question: why does important factual information repeatedly surface in the public domain through unnamed “civil aviation sources”, leaked documents and media reports before the investigating authority acknowledges it?

For a major aviation occurrence, periodic factual briefings should be integral to the investigative process. They need not speculate on causation. They need only inform the public of what has been established, what remains under examination, what evidence is being analysed, and whether any immediate safety concern has been identified.

Silence does not suppress speculation. It creates the conditions for speculation to flourish.

AI2379: A Narrative That Changed Outside AAIB

The handling of AI2379 illustrates the problem.

The initial public narrative was turbulence. As late as 6 August, Civil Aviation Minister K. Rammohan Naidu was still discussing the occurrence principally in those terms. No official public reference mentioned the extraordinary transient loss of hydraulic pressure later identified in all three hydraulic systems.

Yet a substantially different story was already emerging elsewhere.

The Aviation Herald published a more technically detailed account on 5 August. Media organisations subsequently reported hydraulic-system problems, in some cases attributing their information to civil-aviation or investigative sources. By 10 August, reports were openly referring to a transient triple-hydraulic-system failure. A copy of the aircraft's post-flight technical report, apparently downloaded on 4 August and showing the relevant failure messages, surfaced publicly on 13 August.

Eventually, Airbus DFDR analysis and the AAIB preliminary report established the essential fact: the aircraft had experienced an extraordinary, rapid sequence of events involving loss of hydraulic pressure across all three systems, accompanied by significant degradation of flight-control capability.

The early reporting was therefore not simply wild media speculation. Its central technical assertion was subsequently substantially validated.

That raises an uncomfortable question. If such information was sufficiently credible to circulate among aviation sources and journalists, why was the investigating authority not the authoritative source explaining what was known and, equally importantly, what was not known?

The Captain's Condition: An Unanswered Human-Factors Question

Another issue requires clarification.

Media reports citing unnamed sources claimed that one pilot fell in the cockpit and required assistance from the cabin crew. Subsequent accounts went further, alleging that the PIC appeared unsteady after landing, required assistance to sit, and was physically supported while providing the post-flight urine sample (India Today). These reports remain unverified allegations unless the AAIB confirms them. They should not be presented as established fact.

But they cannot simply be ignored.

The relevant investigative question is clear:

What was the PIC’s physical and functional condition immediately before, during and after the occurrence, and why was he reportedly assisted?

The preliminary report states that, after recovering from the upset, the captain assumed control of the aircraft. If reports that he had fallen, was unsteady, or required assistance are accurate, an obvious operational question follows: why was control transferred to him?

Conversely, if the captain was fully fit and functioning normally, the AAIB could dismiss this speculation with a factual statement.

Both versions cannot comfortably coexist without an explanation.

Why Continue for Another 98 Minutes?


The operational decision following the hydraulic event raises an even more pressing question.

The aircraft had just experienced an apparently unprecedented transient loss of hydraulic pressure affecting all three systems, together with temporary degradation of key flight-control functions. The systems recovered, but the initiating mechanism remained unknown.

The crew nevertheless continued to their destination for about another 98 minutes rather than diverting to the nearest suitable airport.

That decision warrants rigorous examination.

What ECAM warnings and system indications were available to the crew? What did they understand about the sequence of hydraulic losses and subsequent recovery? Were the systems indicating normal operation afterwards? Did the crew appreciate that three hydraulic systems had apparently been affected within seconds of one another? What technical, operational or dispatch considerations supported continuation?

The issue is not whether hindsight can produce a better decision. The issue is whether continuation was consistent with the information actually available to the crew at the time.

That is precisely the sort of factual context an investigating authority can explain without determining whether probable cause exists.

An Aircraft-Specific Failure—or a Fleet Safety Issue?

The technical implications are equally significant.

VT-EXO's maintenance history is available to investigators. Airbus participated in the technical examination. DFDR data were recovered. Components and hydraulic fluid samples were reportedly subjected to further examination.

Yet the central technical question remains publicly unresolved:

Was this an aircraft-specific anomaly, or was there any possibility of a failure mechanism relevant to the wider A320neo fleet?

The distinction is critical.

The fleet was not grounded. No fleet-wide Airworthiness Directive was issued. No publicly known urgent service bulletin was issued. No comparable warning to operators emerged. This may ultimately indicate that investigators and Airbus found no evidence requiring immediate fleet action.

But the absence of regulatory action is not, by itself, an explanation.

If the analysis demonstrated that continued operation of the fleet posed no immediate safety concern, stating this would strengthen public confidence rather than compromise the investigation.

More troublingly, technical material reportedly linked to Airbus's early analysis was published publicly and later withdrawn on confidentiality grounds. Whether that material was authentic, preliminary or incomplete is precisely why authoritative communication matters. When official information is absent, leaked technical material inevitably acquires an authority it may not deserve.

What Is Known—and What Is Not

AI2379 is not an investigation starved of evidence.

The DFDR and CVR were available. The flight and cabin crew could be interviewed. Maintenance records were available. The post-flight technical report was available. Airbus and BEA participated in the technical investigation. The sequence of aircraft behaviour could therefore be reconstructed with considerable precision.

The immediate aircraft response—the altitude excursion, flight-control degradation, hydraulic-pressure losses and subsequent recovery—is well known.

What remains publicly unresolved is the most important technical question: what initiated the extraordinary hydraulic event?

That uncertainty is entirely legitimate. Complex technical investigations take time.

What is harder to defend is withholding established factual information merely because the ultimate causal mechanism is unknown.

AI171 Shows the Same Institutional Problem

The concern is not limited to AI2379.

The Supreme Court proceedings on AI171 revealed a similar communication deficit. Despite notices issued in September 2025, the Court was informed in January 2026 that the Centre and AAIB had still not filed their responses, and the investigating side was reportedly unrepresented when the matter was taken up. At a further hearing scheduled for May, counsel for AAIB was reportedly absent.

AAIB subsequently filed its substantive response opposing a court-monitored investigation and appeared before the Court to defend its investigative process.

Whatever the petition's legal merits, the optics are damaging.

An accident-investigation authority handling one of India's most consequential aviation disasters should not have to be repeatedly pressed—by courts, families, professional organisations or the media—to explain its procedures.

Transparency Is Not Premature Causation


There is a tendency to frame demands for information as demands for premature conclusions, but that is a false choice.

Nobody should expect AAIB to announce a probable cause before the evidence supports it. Nobody should expect protected CVR material, sensitive personal information or speculative technical hypotheses to be released merely to satisfy public curiosity.

But verified factual information is different from investigative speculation.

AAIB can say what the recorders show without explaining why it happened. It can describe components under examination without predicting what those examinations will establish. It can state whether an immediate fleet-safety concern has been identified without prejudging final causation. It can clarify demonstrably false narratives without compromising investigative independence.

That is what mature accident-investigation authorities do.

The present approach risks producing precisely the opposite outcome. Official silence leaves journalists reliant on anonymous sources. Technical documents leak. Partial information is amplified. Competing narratives become entrenched. Investigators then cite confidentiality to avoid discussing information already in the public domain.

Confidentiality cannot replace communication.

AAIB's responsibility is not merely to produce a technically defensible final report months or years after an occurrence. It must also preserve confidence in the investigative process during the investigation.

AI2379 demonstrates why this matters. The public was initially told about turbulence. Hydraulic-system information emerged elsewhere. Technical documents surfaced, and Airbus analysis was reported. Questions arose about the captain's physical condition. The decision to continue for another 98 minutes remained unexplained. Eventually, the preliminary report confirmed much of the underlying technical sequence.

The problem is therefore no longer simply a matter of insufficient information.

It is a problem of who provides that information, when it is provided, and whether the investigating authority remains the most credible source of facts about its own investigation.

On that measure, AAIB has serious grounds for recovery.

Investigative independence deserves protection, but institutional silence does not.

Note: The Final report on AI171 is expected on 13 Oct 2026. Hope it puts some of the ongoing speculations to rest.


Author: GR Mohan

Sunday, 6 September 2026

AI2379: Transparency Must Not Be Lost in the Investigation

 The preliminary report on Air India flight AI2379 raises more questions than it answers. That is not, by itself, a criticism of an accident investigation. Preliminary reports are not intended to establish causation or apportion blame. But when an aircraft loses all three hydraulic systems in rapid succession, loses autopilot and flight-control capability, triggers a stall warning, and undergoes a significant altitude excursion, the aviation community is entitled to expect a clear account of the established facts and any immediate safety implications.

AI2379, an Airbus A320-251N, was operating from Phuket to Delhi on 4 August 2026 with 145 people on board. The aircraft was cruising at FL360 when, according to the Aircraft Accident Investigation Bureau (AAIB), the flight-control system detected a loss of Green hydraulic pressure at 04:02:43 UTC. Four seconds later, Blue and Yellow hydraulic pressures were also reported as lost. At 04:02:48, the autopilot disconnected, and a continuous, repetitive chime sounded. Three seconds later, a stall warning was triggered.

The aircraft initially climbed 372 feet above its assigned level, then descended 292 feet. The First Officer, who was Pilot Flying, attempted to control the aircraft before the Pilot-in-Command took over. (Unofficial reports indicate that the pilot was standing behind the copilot, fell during the incident, and was helped into the seat by the cabin crew. After landing, the crew assisted him off the aircraft because he could not move on his own.) Remarkably, the Blue hydraulic system recovered almost immediately, followed within seconds by Yellow and Green, with the flight-control surfaces recovering and normal aircraft operation restored. The central technical question is therefore clear: why did three normally independent hydraulic systems apparently lose pressure almost simultaneously, and why did they recover within seconds?

The preliminary report does not answer that question. Nor should it be expected to at this stage. What is harder to understand is why the report offers so little indication of what the investigation team has established about this extraordinary sequence, despite already having access to the principal sources of evidence.

The AAIB states that it recovered, downloaded, and made both the CVR and DFDR available to the investigation team. The AAIB also conducted in-person interviews with the pilots and cabin crew. It further notes that Airbus technical experts, assigned through France’s BEA, inspected the aircraft between 13 and 15 August. Investigators then removed hydraulic components and collected fluid samples for further analysis, and collected maintenance and operational records, fuel and oil samples, and ATC data.

In other words, this is not an investigation awaiting evidence. Considerable evidence was already in hand, making the lack of a meaningful technical safety assessment particularly striking. Classifying it as an accident should not be a reason to withhold established safety-relevant facts. A legitimate distinction exists between releasing factual information and prematurely declaring a probable cause. The former can support safety; the latter can prejudice an investigation.

AAIB need not—and should not—speculate publicly about the root cause while evidence is still being analysed. But it could have stated clearly what is already known. That would neither compromise the investigation nor assign blame.

Another issue that cannot be overlooked concerns what happened after the hydraulic systems recovered.

The report records that the cabin supervisor informed the cockpit of the injuries. The aircraft experienced a triple hydraulic failure, a temporary loss and recovery of flight controls, and an altitude upset. Yet the crew elected to continue to Delhi for approximately 1 hour 28 minutes rather than divert. The preliminary report records that decision but does not analyse it. This decision warrants careful professional scrutiny.

The investigation must establish precisely what the crew saw on the ECAM, which hydraulic indications remained after recovery, and what the CVR and crew interviews reveal about the crew’s assessment and decision-making.

There have also been reports of speculation about “human intervention”. The published chronology, by itself, does not establish that humans deliberately initiated the hydraulic failures. Any conclusion about crew input must be based on the correlation of control inputs, system parameters, ECAM events, warnings, and CVR evidence—not on selective leaks or anonymous briefings.

The preliminary report does not establish that the toxicology result caused, contributed to, or was related to the hydraulic failure or altitude excursion. The technical sequence remains unexplained.

What Airbus knows matters

Perhaps the most uncomfortable aspect is the apparent discrepancy between what has emerged publicly from technical sources and what has appeared in the official preliminary report. The AAIB has already confirmed Airbus's technical involvement. Yet the preliminary report makes no technical safety recommendations to Airbus or the operator regarding the apparent simultaneous loss of all three hydraulic systems.

That is not necessarily evidence of an investigative failure. A safety recommendation should be based on a sufficiently validated safety issue. If the investigation has not yet established the mechanism, an immediate fleet-wide technical recommendation may not be justified.

But this raises an important question: has the investigation established that the event was confined to VT-EXO, or has it carried out an interim fleet-risk assessment?

If the answer is yes, the aviation community should be told why no precautionary action is considered necessary. If the answer is no, that too warrants explanation.

Ultimately, a safety investigation is about learning from the last event before the next—not merely explaining it.

Transparency is itself a safety tool

At present, there is insufficient evidence to accuse AAIB of a deliberate cover-up. Such an allegation would be premature and unfair. However, the current communication strategy creates an avoidable perception of selective disclosure.

When official silence is accompanied by fragmented technical information emerging through other channels, speculation inevitably fills the vacuum. That is particularly dangerous when the event involves a modern transport aircraft apparently losing all three hydraulic systems simultaneously. AAIB’s own report states that its sole objective is to prevent future accidents and incidents, not to apportion blame or liability. That principle should extend to its communication with the aviation community. Its only substantive public statement says it is collecting evidence and that no conclusions should be drawn from isolated information. Meanwhile, detailed engineering information has emerged through the media. The consequence is perverse: the official investigator supplies less factual information than leaked Airbus and maintenance documents, leaving unofficial sources to define the public narrative.

And that creates exactly the problem we discussed previously with AI 171: confidentiality is being interpreted as silence rather than as disciplined transparency.

AI2379 presents an extraordinary technical event, a significant crew decision, and a potentially important systemic safety issue. The final cause may take months to determine. Selective leaks to the media have clouded the investigation and shaped the public narrative. There is no justification for allowing uncertainty about the cause to become uncertainty about the facts.

The aviation community does not need premature conclusions.

It needs the truth about what is already known.

Author: GR Mohan


THE MALICIOUS INSIDER IN THE FLIGHT DECK

  Lessons from flydubai FZ1073 and Earlier Cases of Deliberate or Suspected Crew Action A Low-Probability, Catastrophic-Risk Threat The 30 S...