Showing posts with label communications. Show all posts
Showing posts with label communications. Show all posts

Sunday, 6 September 2026

AI2379: Transparency Must Not Be Lost in the Investigation

 The preliminary report on Air India flight AI2379 raises more questions than it answers. That is not, by itself, a criticism of an accident investigation. Preliminary reports are not intended to establish causation or apportion blame. But when an aircraft loses all three hydraulic systems in rapid succession, loses autopilot and flight-control capability, triggers a stall warning, and undergoes a significant altitude excursion, the aviation community is entitled to expect a clear account of the established facts and any immediate safety implications.

AI2379, an Airbus A320-251N, was operating from Phuket to Delhi on 4 August 2026 with 145 people on board. The aircraft was cruising at FL360 when, according to the Aircraft Accident Investigation Bureau (AAIB), the flight-control system detected a loss of Green hydraulic pressure at 04:02:43 UTC. Four seconds later, Blue and Yellow hydraulic pressures were also reported as lost. At 04:02:48, the autopilot disconnected, and a continuous, repetitive chime sounded. Three seconds later, a stall warning was triggered.

The aircraft initially climbed 372 feet above its assigned level, then descended 292 feet. The First Officer, who was Pilot Flying, attempted to control the aircraft before the Pilot-in-Command took over. (Unofficial reports indicate that the pilot was standing behind the copilot, fell during the incident, and was helped into the seat by the cabin crew. After landing, the crew assisted him off the aircraft because he could not move on his own.) Remarkably, the Blue hydraulic system recovered almost immediately, followed within seconds by Yellow and Green, with the flight-control surfaces recovering and normal aircraft operation restored. The central technical question is therefore clear: why did three normally independent hydraulic systems apparently lose pressure almost simultaneously, and why did they recover within seconds?

The preliminary report does not answer that question. Nor should it be expected to at this stage. What is harder to understand is why the report offers so little indication of what the investigation team has established about this extraordinary sequence, despite already having access to the principal sources of evidence.

The AAIB states that it recovered, downloaded, and made both the CVR and DFDR available to the investigation team. The AAIB also conducted in-person interviews with the pilots and cabin crew. It further notes that Airbus technical experts, assigned through France’s BEA, inspected the aircraft between 13 and 15 August. Investigators then removed hydraulic components and collected fluid samples for further analysis, and collected maintenance and operational records, fuel and oil samples, and ATC data.

In other words, this is not an investigation awaiting evidence. Considerable evidence was already in hand, making the lack of a meaningful technical safety assessment particularly striking. Classifying it as an accident should not be a reason to withhold established safety-relevant facts. A legitimate distinction exists between releasing factual information and prematurely declaring a probable cause. The former can support safety; the latter can prejudice an investigation.

AAIB need not—and should not—speculate publicly about the root cause while evidence is still being analysed. But it could have stated clearly what is already known. That would neither compromise the investigation nor assign blame.

Another issue that cannot be overlooked concerns what happened after the hydraulic systems recovered.

The report records that the cabin supervisor informed the cockpit of the injuries. The aircraft experienced a triple hydraulic failure, a temporary loss and recovery of flight controls, and an altitude upset. Yet the crew elected to continue to Delhi for approximately 1 hour 28 minutes rather than divert. The preliminary report records that decision but does not analyse it. This decision warrants careful professional scrutiny.

The investigation must establish precisely what the crew saw on the ECAM, which hydraulic indications remained after recovery, and what the CVR and crew interviews reveal about the crew’s assessment and decision-making.

There have also been reports of speculation about “human intervention”. The published chronology, by itself, does not establish that humans deliberately initiated the hydraulic failures. Any conclusion about crew input must be based on the correlation of control inputs, system parameters, ECAM events, warnings, and CVR evidence—not on selective leaks or anonymous briefings.

The preliminary report does not establish that the toxicology result caused, contributed to, or was related to the hydraulic failure or altitude excursion. The technical sequence remains unexplained.

What Airbus knows matters

Perhaps the most uncomfortable aspect is the apparent discrepancy between what has emerged publicly from technical sources and what has appeared in the official preliminary report. The AAIB has already confirmed Airbus's technical involvement. Yet the preliminary report makes no technical safety recommendations to Airbus or the operator regarding the apparent simultaneous loss of all three hydraulic systems.

That is not necessarily evidence of an investigative failure. A safety recommendation should be based on a sufficiently validated safety issue. If the investigation has not yet established the mechanism, an immediate fleet-wide technical recommendation may not be justified.

But this raises an important question: has the investigation established that the event was confined to VT-EXO, or has it carried out an interim fleet-risk assessment?

If the answer is yes, the aviation community should be told why no precautionary action is considered necessary. If the answer is no, that too warrants explanation.

Ultimately, a safety investigation is about learning from the last event before the next—not merely explaining it.

Transparency is itself a safety tool

At present, there is insufficient evidence to accuse AAIB of a deliberate cover-up. Such an allegation would be premature and unfair. However, the current communication strategy creates an avoidable perception of selective disclosure.

When official silence is accompanied by fragmented technical information emerging through other channels, speculation inevitably fills the vacuum. That is particularly dangerous when the event involves a modern transport aircraft apparently losing all three hydraulic systems simultaneously. AAIB’s own report states that its sole objective is to prevent future accidents and incidents, not to apportion blame or liability. That principle should extend to its communication with the aviation community. Its only substantive public statement says it is collecting evidence and that no conclusions should be drawn from isolated information. Meanwhile, detailed engineering information has emerged through the media. The consequence is perverse: the official investigator supplies less factual information than leaked Airbus and maintenance documents, leaving unofficial sources to define the public narrative.

And that creates exactly the problem we discussed previously with AI 171: confidentiality is being interpreted as silence rather than as disciplined transparency.

AI2379 presents an extraordinary technical event, a significant crew decision, and a potentially important systemic safety issue. The final cause may take months to determine. Selective leaks to the media have clouded the investigation and shaped the public narrative. There is no justification for allowing uncertainty about the cause to become uncertainty about the facts.

The aviation community does not need premature conclusions.

It needs the truth about what is already known.

Author: GR Mohan


Saturday, 8 August 2026

AI-171: Transparency, Secrecy and the Purpose of Accident Investigation

 More than a year after the loss of Air India Flight AI-171, the central issue is no longer simply whether the Aircraft Accident Investigation Bureau is continuing its work. The more pressing question is whether the investigation will ultimately yield a technically convincing and publicly accessible explanation of what happened.

The Ministry of Civil Aviation has stated that the investigation is being conducted in accordance with the Aircraft (Investigation of Accidents and Incidents) Rules and with applicable ICAO Standards and Recommended Practices. It has also said that the AAIB has undertaken an extensive examination of the technical, operational, organisational and human factors associated with the accident, and that significant progress has been made in analysing aircraft systems, flight-recorder data and other evidence.

The AAIB, for its part, has reiterated its commitment to professionalism, transparency and investigative rigour.

Those assurances are welcome, but they also invite an obvious question: where is the transparency?

The preliminary report issued in July of last year was necessarily limited in scope and largely factual. This is entirely normal. Preliminary reports are not intended to establish probable cause or provide a complete analysis.

What is more difficult to understand is why, after such an extended period of investigation, so little substantive information has emerged regarding the direction of the technical inquiry.

We are told that aircraft systems have been examined, flight-recorder data analysed and forensic work undertaken. Yet fundamental questions remain unanswered.

Which components were subjected to detailed examination? Which systems were considered potentially relevant? Were any parts sent overseas for specialist analysis? Have those examinations been completed? Has the AAIB received the findings? Have investigators identified any mechanical, electrical, software or system anomalies? More importantly, have significant technical failure modes been conclusively ruled out?

These questions are not speculative distractions. They go directly to the purpose of an aircraft accident investigation.

At the heart of the AI-171 investigation lies a critical, still unresolved issue: how and why did both fuel-control switches move from RUN to CUTOFF shortly after take-off?

Everything else is secondary to that question.

The loss of thrust occurred during one of the most vulnerable phases of flight. If the switches changed state because of a technical or electrical malfunction, investigators must establish and explain the mechanism. If the possibility of a technical malfunction has been excluded, the basis for that exclusion must be demonstrated.

If human action is involved, the conclusion must rest on evidence rather than assumption.

And if the evidence does not allow investigators to determine with certainty how the switches moved, the final report should state this plainly.

There is nothing professionally unacceptable about an inconclusive finding when the evidence genuinely does not permit a definitive conclusion. What would be unacceptable is leaving the central causal question unanswered while relying on confidentiality provisions to avoid discussing the evidence.

This is where the issue of the Cockpit Voice Recorder is particularly important.

There is a sound and well-established reason for protecting raw CVR recordings. Cockpit recordings may contain private conversations, incidental remarks and information entirely unrelated to the accident. Unrestricted publication would serve little safety purpose and could seriously undermine the principles on which protected safety information is collected.

The aviation community should therefore resist simplistic demands that the complete CVR recording be released publicly.

But that is not the real issue.

The crucial distinction is between protecting a raw cockpit recording and withholding information about the safety significance of what that recording reveals.

ICAO provisions protecting CVR material were never intended to prevent investigators from explaining relevant cockpit events in a final accident report. On the contrary, if a statement, action or exchange recorded on the CVR materially assists in understanding the accident sequence, that information forms part of the evidential basis of the investigation.

The public does not need to hear every second of cockpit conversation. But the aviation community needs to understand what the recorder evidence establishes about the accident.

CVR confidentiality must therefore not become a convenient shield behind which critical causal evidence is concealed.

The same principle applies to the Flight Data Recorder and to any forensic examinations of aircraft components or systems.

A professional accident report should not merely state that no technical defect was identified. It should explain how investigators reached that conclusion.

What failure modes were considered? What tests were conducted? What physical evidence was recovered? Which electrical or electronic pathways were examined? Which system logic was assessed? Were switch mechanisms physically inspected? Were wiring, control systems, software functions, or associated components tested? Did the recorder data support or contradict any technical hypotheses?

The credibility of the investigation depends on the ability of technically qualified readers to understand the reasoning.

This is particularly important when a conclusion may point away from mechanical failure and towards human action.

Such conclusions carry significant consequences. They affect the reputation of crew members who cannot speak for themselves. They may influence litigation, manufacturer liability, airline accountability and public perception.

That makes evidential transparency even more important, not less so.

If human action is implicated, the report must establish the sequence convincingly. It should examine not only what appears to have happened but also the circumstances in which it happened: workload, cockpit interaction, procedural design, system ergonomics, possible inadvertent action, startle, cognitive factors, and any relevant organisational influences.

Accident investigation is not strengthened by prematurely reducing a complex event to a single cockpit action.

Nor is it strengthened by excluding technical explanations without demonstrating how they were eliminated.

The recent reports that a copy of the AAIB report may be submitted to the Supreme Court in a sealed cover add another dimension to the debate.

There may be perfectly legitimate reasons for a court to receive certain material confidentially. Judicial proceedings often require sensitive information to be protected, particularly where statutory restrictions apply to recordings, personal information or other investigative material.

But a confidential submission to the Supreme Court and a public aviation accident report serve very different purposes.

a) One serves a judicial process.

b) The other serves aviation safety.

c) A sealed report does not, in itself, prevent a recurrence.

d) It does not inform flight crews.

e) It does not change operating procedures.

f) It does not alert engineers to a system vulnerability.

g) It does not lead manufacturers to modify a design.

h) It does not enable regulators to improve oversight.

And it does not provide the wider aviation community with the lessons that accident investigation is intended to yield.

For that reason, a sealed submission can never be regarded as a substitute for a comprehensive public report.

The primary objective of a safety investigation is not to determine guilt behind closed doors. Its purpose is to reconstruct the sequence of events, identify causal and contributory factors, and recommend measures to reduce the likelihood of recurrence.

That purpose can only be fully achieved when the findings become accessible to those who must act upon them.

a) This is also why prolonged opacity is dangerous.

b) It inevitably creates suspicion.

If no technical defect has been identified, people will naturally ask what the remaining evidence indicates. If investigators have access to the CVR, FDR, physical evidence and forensic results, but the public continues to receive little more than assurances of progress, speculation will fill the vacuum.

Questions will arise about whether the crew, the manufacturer, the airline, the regulator or Government itself has an interest in limiting disclosure.

At present, there is no verified evidence that any of these parties is being protected.

That must be stated clearly.

Criticism of secrecy is justified. An allegation of a deliberate cover-up requires evidence.

But investigative authorities must also recognise that secrecy carries its own consequences. The longer crucial questions go unanswered, the more public confidence erodes.

Trust cannot be sustained indefinitely by statements about professionalism and rigour.

It has to be earned through evidence.

The final report must therefore do far more than announce a conclusion.

a) It must show its work.

b) If a technical failure was considered and rejected, the report should explain the basis for rejection.

c) If an electrical malfunction was investigated, the relevant findings should be presented.

d) If the fuel-control switch design or operation was examined, the results should be discussed.

e) If overseas forensic examinations were commissioned, their significance should be explained.

f) If recorder information establishes a particular sequence, the relevant parameters should be presented clearly enough for informed readers to follow it.

g) If human factors were involved, the analysis should be proportionate, detailed and evidence-based.

h) If organisational, training, regulatory or procedural weaknesses contributed, they should not be obscured by an excessive focus on the final seconds in the cockpit.

i) And if investigators remain unable to determine exactly why the decisive event occurred, the report should say so.

j) There is no need to manufacture certainty simply to produce a neat conclusion.

In aviation safety, an honest admission of limitation is far more valuable than an unsupported assertion.

Transparency should not be confused with indiscriminate disclosure. There is no need to publish irrelevant cockpit conversations or to invade personal privacy. Nor should incomplete or unverified evidence be released prematurely.

But once an investigation reaches its final stage, the evidence required to understand the accident must be disclosed in sufficient detail to withstand technical scrutiny. That is the standard by which the AI-171 investigation should ultimately be judged.

a) The families of those who died deserve meaningful answers.

b) Pilots need to know whether there is an operational lesson.

c) Engineers need to know whether there is a technical vulnerability.

d) Airlines need to know whether procedures require modification.

e) Manufacturers need to know whether design or system changes are necessary.

f) Regulators need to know whether certification, training or oversight require reform.

g) Passengers have a legitimate expectation that a catastrophic accident will result in a clear explanation and tangible safety improvement.

h) These interests are not secondary to the investigation.

i) They are the reason the investigation exists.

j) The public does not need the raw CVR.

k) It does not need speculation dressed up as fact.

l) It does not need premature accusations.

What it needs is a technically complete and intellectually honest account of the accident.

a) If a technical failure has been ruled out, show how.

b) If a system malfunction remains possible, explain why.

c) If human action is implicated, establish this rigorously.

d) If forensic analysis has produced important findings, disclose their safety significance.

e) And if uncertainty remains, acknowledge it.

The AAIB has repeatedly emphasised transparency, professionalism and investigative rigour.

The final report will offer an opportunity to demonstrate all three.

A sealed report may satisfy a procedural or judicial requirement.

But aviation safety is not advanced by sealing away evidence. It advances when evidence is examined rigorously, conclusions are explained convincingly, and lessons are shared openly.

The real test of the AI-171 investigation will therefore not be whether the AAIB says it conducted a thorough investigation. It will be whether the final report shows the aviation community that it did.

a) The investigation must answer the central questions.

b) It must subject its reasoning to professional scrutiny.

c) And above all, it must explain the accident — not bury it.


Author: GR Mohan

Friday, 5 June 2026

Air India AI171 Accident: An Evidence-Based Assessment of Current Facts, Technical Issues, and Competing Theories

 The crash of Air India Flight AI171 has sparked extensive debate across traditional media, aviation forums, and social media platforms. Numerous theories have emerged, ranging from deliberate pilot action to a catastrophic electrical failure of the Boeing 787. Many of these assertions have been presented with a degree of certainty that is not supported by the available evidence.

This article aims to distinguish between facts, inferences, possibilities, and speculation currently circulating among a biased group seeking to interfere with and hijack a coherent, non-partisan analysis.

A review of the preliminary investigation findings, the known Boeing 787 system architecture, historical service experience, and publicly available technical information indicates that the immediate cause of the loss of thrust is known, but the root cause remains under investigation.

The currently available evidence establishes that both engines lost fuel supply shortly after take-off, following the transition of both fuel control switches from RUN to CUTOFF. What remains unknown is why those switches changed state.

At present, no publicly available evidence conclusively supports either a pilot-action scenario or a mechanical, electrical, or software malfunction.

What Is Established

The preliminary investigation has established the following sequence:

1. The aircraft departed normally.

2. Shortly after liftoff, both fuel control switches transitioned from RUN to CUTOFF.

3. Fuel supply to both engines was interrupted.

4. Both engines began shutting down.

5. The switches subsequently returned to RUN.

6. Engine relight sequences commenced.

7. Some engine recovery occurred, but insufficient thrust was available to prevent impact.

8. The Ram Air Turbine (RAT) was deployed during the event.

9. Cockpit voice recordings captured an exchange in which one pilot questioned the other regarding the fuel cutoff action, while the other denied having done so.

These facts are derived from recorded flight data and cockpit voice recorder information and therefore constitute the most reliable evidence currently available. However, a more detailed and authentic sequence of events may be compiled from EAFR data and AAIB's ancillary investigations.

What Is Not Yet Established

The investigation has not yet determined:

1) Why did the fuel control switches transition to CUTOFF?

2) Whether the switch movement resulted from human action.

3) Whether the switch movement resulted from a mechanical failure.

4) Whether an electrical malfunction contributed to the event.

5) Whether a software or avionics malfunction contributed to the event.

6) Whether any prior maintenance discrepancies played a role.

7) Whether any design vulnerability exists within the fuel control system.

8) Which pilot made which statement on the cockpit voice recording?

Consequently, any claim that the accident has already been solved is premature.

Understanding the Fuel Control Switches: 

a) The Boeing 787 fuel control switches are critical cockpit controls used to start and shut down the engines.

b) Moving a switch from RUN to CUTOFF commands fuel flow to cease, resulting in engine shutdown.

c) The significance of the preliminary findings cannot be overstated:

d) The accident sequence was not initiated by a spontaneous engine flameout, compressor stall, bird strike, or fuel exhaustion. The available data indicate that fuel supply was interrupted following the switch transition.

The central investigative question, therefore, becomes:

Why did the switches transition from RUN to CUTOFF?

The Boeing 787 and Historical Electrical Issues

The Boeing 787 has experienced several well-documented electrical-system issues throughout its service life.

These include:

a) Lithium-ion battery failures.

b) Battery thermal runaway events.

c) Electrical power panel issues.

d) Generator control problems.

e) Electrical distribution faults.

f) Software-related system anomalies.

These issues are part of the aircraft's documented service history and should not be ignored. However, an important distinction must be maintained. The presence of historical electrical problems does not automatically establish a link to AI171.

Accident investigation requires a demonstrable causal chain. At present, no publicly released evidence shows that any known Boeing 787 electrical failure mode can independently move both fuel control switches from RUN to CUTOFF.

The historical record, therefore, establishes only that electrical problems have occurred. on the 787—not that they caused this accident.

Could an Electrical Failure Have Caused the Event?

The possibility cannot be ruled out at present.

Modern transport aircraft rely extensively on electrical signalling, digital control systems, and electronic engine management. A hypothetical common-mode electrical failure affecting multiple systems is therefore technically conceivable.

However, no evidence has yet been released demonstrating:

a) Simultaneous failure of both engine control systems.

b) Electrical commands that could independently reposition both fuel switches.

c) Wiring failures affecting both engines in a manner consistent with the recorded sequence.

d) Avionics failures producing the observed switch transitions.

For such a theory to become credible, investigators would need to identify physical evidence from recovered components, wiring, electronic modules, maintenance records, or system fault logs.

No such evidence has been made public. Accordingly, an electrical-failure explanation remains a hypothesis rather than a conclusion.

The FADEC Theory

A widely circulated claim holds that an electrical fault caused the Full Authority Digital Engine Control (FADEC) system to shut down both engines. This explanation faces significant technical challenges. The FADEC controls engine operation, fuel metering, and engine protection functions. It can command an engine shutdown under specific circumstances.

However, there is currently no publicly documented Boeing 787 architecture showing the FADEC physically moving the cockpit fuel control switches from RUN to CUTOFF. The available evidence indicates that the switches themselves changed state.

Therefore, investigators must determine whether:

a) The switches were moved manually.

b) The switches suffered a mechanical malfunction.

c) The switch position was incorrectly recorded.

d) An unidentified system anomaly occurred.

At present, the FADEC theory remains unsupported by publicly available evidence.

The 2018 Fuel Switch Advisory

Considerable attention has focused on a 2018 FAA advisory concerning fuel control switch locking mechanisms. The advisory raised concerns about switch-locking features and inspection practices. It is relevant because it shows that fuel switch reliability had previously attracted regulatory attention.

However, several important facts must be noted:

a) The advisory did not result in an Airworthiness Directive requiring immediate fleet-wide action.

b) The condition was not formally classified as an unsafe condition requiring a mandatory modification.

c) The AI171 preliminary report does not conclude that this issue caused the accident.

The existence of the advisory, therefore, justifies further investigation but does not establish causation.

Recent Fuel Switch Events

Reports have emerged of fuel control switch anomalies on other aircraft, including incidents involving Air India aircraft. These reports demonstrate that switch-related abnormalities are not purely theoretical. However, accident investigation requires more than similarity. The existence of another switch-related event does not prove that the same mechanism occurred on AI171. Investigators will need to establish a direct evidentiary link before any such conclusion can be drawn.

The Cockpit Voice Recorder Evidence

The CVR excerpt has sparked extensive speculation. The reported exchange indicates that one pilot questioned the other about the fuel cutoff action and was denied. This information establishes only one thing with certainty: at least one pilot appeared surprised or confused by the fuel cutoff event.

The exchange does not establish:

a) Intentional action.

b) Accidental action.

c) Mechanical failure.

d) Electrical failure.

e) Sabotage.

f) Suicide.

Without the complete CVR transcript, cockpit context, crew actions, and synchronised flight data, the exchange cannot support definitive conclusions.

The Claim That the Captain Was Found Holding the Controls

A frequently repeated claim is that the captain's body was recovered with both hands on the controls, supposedly proving that he was attempting to save the aircraft. No official investigative document currently available supports this assertion. Even if such information were eventually verified, it would not establish causation. Pilots confronted with an emergency would be expected to attempt recovery regardless of how the emergency originated. Accordingly, this claim has little investigative value and should not be relied upon.

RAT Deployment and Its Significance

The deployment of the Ram Air Turbine is an important factual point. The RAT provides emergency power when normal electrical generation is unavailable.

What remains uncertain is the precise timing relationship among:

a) RAT deployment,

b) Engine power loss,

c) Fuel switch transitions,

d) Electrical system status.

Numerous commentators have attempted to construct alternative timelines from CCTV footage and other observations. Such reconstructions remain speculative until validated against synchronised flight-recorder data. Consequently, RAT deployment should currently be regarded as an important investigative clue rather than as evidence supporting any particular theory.

Common Errors in Public Commentary

Several recurring analytical errors are evident in public discourse:

Error 1: Assuming Possibility Equals Proof

An electrical fault could theoretically cause unusual system behaviour.

That does not mean it did.

Error 2: Assuming Historical Problems Explain Current Events

The existence of previous 787 electrical issues does not establish a link to AI171.

Each accident requires independent proof.

Error 3: Treating Absence of Evidence as Evidence

The lack of evidence for one theory does not automatically validate another.

Error 4: Interpreting Partial Information as Complete Information

The public has access only to selected excerpts from a much larger body of evidence.

Investigators possess substantially more information than has been released.

Current Assessment

Based on all publicly available evidence, the following conclusions are justified:

Supported by Evidence

1) Fuel supply to both engines was interrupted.

2) Both fuel control switches moved from RUN to CUTOFF.

3) The switches later returned to RUN.

4) Engine relight attempts were made.

5) The RAT was deployed.

6) The crew attempted to recover the aircraft.

7) The root cause of the switch transition remains unknown.

Not Supported by Evidence

1) Deliberate pilot action has been proven.

2) Pilot suicide has been proven.

3) Boeing 787 electrical faults caused the accident.

4) FADEC autonomously moved the switches.

5) The 2018 FAA advisory caused the accident.

6) Mechanical switch failure caused the accident.

7) The CVR exonerates the crew.

8) The CVR incriminates the crew.

Conclusion

The preliminary investigation has identified the immediate cause of the loss of thrust: interruption of the fuel supply following the transition of both fuel control switches from RUN to CUTOFF.

The most important question—why those switches changed state—remains unanswered.

At present, neither the pilot-action hypothesis nor the mechanical, electrical, or software-failure hypotheses has been substantiated by publicly available evidence.

A disciplined investigative approach requires resisting the temptation to fill evidentiary gaps with speculation. Until the component examinations, system analyses, maintenance reviews, and the final accident report are complete, the cause of the switch transition must remain undetermined.

The available evidence supports caution rather than certainty.

Author: GR Mohan

Monday, 26 January 2026

The 2025 IndiGo Flight Disruption Crisis

 Regulatory Non-Compliance, Systemic Failures, and the Case for Smarter Fatigue Risk Management

In December 2025, India’s aviation system went through one of its most disruptive operational episodes in recent memory. IndiGo Airlines—by far the country’s largest carrier, with roughly 60 per cent of the domestic market—was forced to cancel thousands of flights over a matter of days. What initially appeared to be a mix of weather issues, congestion, and technical glitches soon revealed a more fundamental problem: the airline was unable to operate its published schedule while complying with the revised Flight Duty Time Limitation (FDTL) regulations issued by the Directorate General of Civil Aviation (DGCA).

These revised FDTL norms were introduced specifically to address long-standing concerns around pilot fatigue, a recognised safety risk globally. The rules were rolled out in two phases during 2025, with the second and more restrictive phase coming into effect on 1 November 2025. Within weeks, the cracks began to show. By early December—right in the middle of peak winter travel and the wedding season—IndiGo’s operation started to unravel, leaving passengers stranded and triggering intense scrutiny of airline management decisions as well as regulatory preparedness.

This article looks beyond the headlines to examine what really went wrong. It analyses IndiGo’s internal planning and execution failures, evaluates the DGCA’s regulatory framework and oversight approach, and explores whether India now needs to move beyond purely prescriptive duty limits toward a more mature Fatigue Risk Management System (FRMS). Drawing on DGCA circulars, audit findings, and industry commentary, the discussion asks a central question: was this crisis caused by rigid regulation—or by inadequate preparation and execution at the airline level?

Background: DGCA’s Revised FDTL Framework

The DGCA formally notified revised FDTL requirements in January 2024 through an updated Civil Aviation Requirement (CAR). The intent was clear: bring India’s fatigue regulations closer to international best practices and address chronic concerns around extended duty periods, night operations, and cumulative fatigue.

To allow airlines time to adjust, implementation was deliberately phased:

a) Phase 1 (effective 1 July 2025):
Weekly rest requirements increased from 36 hours to 48 hours.

b) Phase 2 (effective 1 November 2025):
Tighter controls on night operations, a sharp reduction in permitted night landings (from six to two per week), and more restrictive duty-hour limits.

The framework set clear, prescriptive limits for Flight Duty Period (FDP), Flight Time (FT), and minimum rest, with additional provisions covering acclimatisation, split duty, standby, and unforeseen operational disruptions. Airlines were required to submit revised FDTL compliance schemes for DGCA approval. While initial compliance deadlines were set for 2024, extensions pushed full implementation into 2025.

There was little ambiguity in regulatory intent. The changes were known more than a year in advance, giving operators time to adjust hiring plans, training pipelines, and rostering models. That said, IndiGo’s high-frequency, tightly optimised network meant that even small planning errors carried outsized operational consequences.

Operational Timeline and Impact

Once Phase 2 came into force, the situation deteriorated quickly:

Period

Flight Cancellations

On-Time Performance

November 2025

1,232

67.7%

1–2 December

Escalating

49.5%, 35%

3–4 December

200–550 per day

19.7%, 8.5%

5 December

~1,600 (peak)

Severely degraded

Mid-December (cumulative)

~4,500

—

The knock-on effects were significant. Passenger disruption was widespread, refund liabilities were estimated at over ₹5 billion (around USD 59 million), and airfares on competing airlines surged. IndiGo’s market capitalisation reportedly dropped by nearly ₹400 billion (USD 4.7 billion). Indian Railways even had to add extra services to accommodate displaced travellers—an unusual but telling indicator of the system's overall impact.

What Went Wrong: A Closer Look

1. Planning and Manpower Management Failures

IndiGo initially pointed to weather, congestion, and technology issues. While these factors always play a role, they did not explain the scale or persistence of the disruption. Subsequent audits and industry analysis pointed to more basic problems: inadequate anticipation of the operational impact of Phase 2 FDTL rules, despite ample advance notice.

Fleet growth continued aggressively, but pilot recruitment, training, and rostering did not keep pace with the more restrictive duty and rest limits. Industry observers highlighted lean manpower assumptions, delayed hiring cycles, and heavy reliance on maximising crew productivity. Informal non-poaching practices were also cited as limiting short-term workforce flexibility.

DGCA audits found that IndiGo’s overall pilot numbers were not dramatically out of line with global benchmarks. The real weakness lay in rostering and utilisation. Poor scheduling decisions led crews to violate FDTL, triggering cancellations. IndiGo later acknowledged that it had underestimated the operational impact of Phase 2 implementation.

2. Lack of Contingency and Risk Mitigation Planning

Equally damaging was the absence of proactive mitigation. IndiGo did not meaningfully flag compliance risks to the regulator in advance, nor did it sufficiently trim schedules before enforcement began. Other Indian carriers, facing the same regulatory environment, made targeted capacity reductions and adjusted rosters early, avoiding widespread disruption.

Reports from pilots suggested that available crews were not always deployed effectively, pointing to coordination and planning issues rather than absolute shortages. In a high-utilisation, point-to-point network like IndiGo’s, even small inefficiencies cascaded rapidly into system-wide failure.

3. Regulatory Oversight Constraints

The DGCA was not immune from criticism. Questions were raised about the timing of enforcement actions and the effectiveness of oversight, particularly after the removal of four inspectors during the period. However, the regulator maintained that airlines had sufficient notice and flexibility, and that responsibility for implementation lay squarely with operators.

Regulatory Response

As the crisis peaked, the DGCA stepped in with a temporary, conditional exemption from certain FDTL provisions, valid until 10 February 2026. The relief was tied to periodic reviews and a structured compliance roadmap.

Enforcement actions included:

a) A record penalty of ₹22.2 crore (approximately USD 2.6 million) for 68 days of non-compliance

b) A requirement for financial guarantees

c) A mandated 10 per cent reduction in scheduled capacity

IndiGo is committed to restoring full operations by the end of the exemption period, citing improved pilot availability and revised rostering practices.

Why FRMS Now Matters

The disruption highlighted a long-standing issue: purely prescriptive duty-time rules, while essential, have limits—especially for large, complex airline operations. Recognising this, the DGCA released draft Fatigue Risk Management System (FRMS) guidelines in September 2025.

FRMS shifts fatigue management from fixed limits alone to a data-driven, performance-based approach. Core elements include:

a) Systematic identification of fatigue hazards

b) Continuous monitoring using operational and physiological data

c) Evidence-based mitigation strategies

d) Integration with existing Safety Management Systems (SMS)

Done properly, FRMS can offer flexibility without compromising safety. But it is not a shortcut. It requires strong data capability, scientific validation, regulatory maturity, and genuine organisational commitment. Pilot unions have rightly cautioned against FRMS being used as a backdoor to longer duties without safeguards, underscoring the need for transparency and independent oversight. 

Way Forward

The 2025 IndiGo disruption was not caused by unrealistic regulation. It was largely the result of management-level failures in planning, risk assessment, and execution. The DGCA provided sufficient lead time, and other airlines demonstrated that compliance was achievable with disciplined preparation.

That said, the episode offers clear lessons. Airlines must treat regulatory transitions as major operational risks, not administrative exercises. Regulators must strengthen oversight and enforcement consistency. And the industry as a whole must move toward more mature, evidence-based fatigue management through carefully implemented FRMS.

If Indian aviation is to grow sustainably without repeating crises of this scale, fatigue management must evolve from box-ticking compliance to a genuine safety culture—one built on data, transparency, and collaboration between regulators, operators, and pilots alike.

 

Disclaimer: The views expressed by the author are his personal interpretation of the events.

Author: GR Mohan

Miami Runway Excursion: A Failure of Barriers Before the Runway End

  The 21 Air Boeing 767 accident in Miami on 6 September 2026 is disturbing not merely because an aircraft overran a runway with fatal cons...