September 3, 2026

Beyond the Flight Deck

Why Aviation’s Next Safety Breakthrough Must Begin with Leadership

Aviation’s next safety breakthrough cannot come from the flight deck alone. It must come from leaders who recognize and address the systemic warning signals, normalized risks, and organizational decisions that create significant risks. As recent aviation tragedies show, preventing serious events requires safety leadership that proactively addresses the cognitive and organizational systems that shape how safety is actually created.

On the evening of December 28, 1978, United Airlines Flight 173 was on approach to Portland International Airport with 189 people aboard. The crew was experienced. The aircraft was airworthy. The weather was clear. And yet the DC-8 ran out of fuel six miles from the runway and crashed into a suburban neighborhood, killing ten of those aboard.

The NTSB found that the captain, absorbed in a landing gear indicator problem, had not processed the urgency of the low fuel warnings from his first officer and flight engineer — who, in turn, had not pushed hard enough against his authority. Everyone had the information necessary to prevent the accident, but the crew’s system of communication and shared situational awareness — the mechanism designed to surface critical information across the cockpit hierarchy — had failed.

From that investigation came a revolution. NASA’s human factors research into crew dynamics and decision-making gave rise to what was then called Cockpit Resource Management (CRM). United Airlines implemented the industry’s first CRM training program in 1981. Within a decade, virtually every commercial carrier in the world had adopted it. CRM did not simply change pilot training; it changed the industry’s theory of the human being in the cockpit — not as a source of error to be controlled through procedures alone, but as a cognitive system that had to be understood and designed around. I came into the industry in 1986, a beneficiary of that revolution before I fully understood it. It took years of experience – and the cumulative weight of investigations, near misses, and hard conversations with crews and leaders – to appreciate what CRM had accomplished, and what it had left unfinished.

I believe aviation is standing at a moment analogous to the birth of CRM. The next safety revolution will not occur primarily in the cockpit. It will occur in how leaders understand cognition, organizational decision-making, and the systems that shape frontline performance.

Aviation Safety: Airplane landing at sunset

Three recent events have brought this conviction into sharp focus:

  • The Potomac River collision at Reagan National Airport in January 2025
  • The Runway collision at LaGuardia in March 2026
  • The engine separation and crash of UPS Flight 2976 at Louisville in November 2025

Each has its own technical narrative and investigative record. Taken together, they point to a common question: how do experienced people, working inside systems designed by skilled and well-intentioned professionals, miss or normalize signals that later prove to be catastrophic.

In Thinking, Fast and Slow, Nobel laureate Daniel Kahneman describes two modes of cognition: System 1 — fast, intuitive, automatic, and System 2 — deliberate, analytical, effortful. Aviation has built much of its safety architecture around System 2: checklists, procedures, regulations, investigations, and formal risk assessments. The implicit assumption is that these mechanisms will engage deliberate reasoning when it is needed most. However, they may not under stress, high workload, competing priorities, or the familiar pull of established routine. The fast brain is efficient, but it is also vulnerable to habit-driven error, normalization of familiar risks, and the tendency to miss a known threat when attention is fully occupied elsewhere.

The NTSB’s findings on the Potomac collision illustrate what happens when routine masks risk across an entire system. The Army helicopter crew had flown that route many times — the risk felt familiar, the habits deeply ingrained.

On that evening, they were also flying with AN/AVS-6 night vision goggles, which limit the crew’s field of view and reduce depth perception relative to unaided sight, compounding the effect of that familiarity. Flight crews across both military and commercial aviation had long accepted the coexistence of their traffic in that airspace as a normal operating condition at Reagan National. Air traffic controllers were managing a high-tempo environment with limited cognitive bandwidth for anything beyond traffic flow.

Everyone was operating within what the system had made normal. No one was acting outside the standards of a typical night. Yet sixty-seven people died.

The NTSB also found that Traffic Collision Avoidance System (TCAS) advisories had been triggered near Reagan National at least monthly since 2011. The system had heard its own warning for fourteen years and learned to live with it.

The route design itself became part of the story. Helicopter routes published carried altitude guidance on the FAA’s Baltimore-Washington Helicopter Route Chart that the NTSB found unclear and inconsistently interpreted, bringing military and commercial traffic into closer proximity than the chart implied.

The hazard was not hidden. It was normalized — absorbed into the daily rhythm of operations until it no longer registered as a signal requiring action. Normalization does not eliminate risk; it eliminates the perception of risk.

The LaGuardia runway collision — documented in a preliminary NTSB report and subject to revision as the investigation continues — offers a different but equally revealing example of how fast-brain decisions, made independently by multiple actors, can cascade toward catastrophe.

Port Authority emergency vehicles were responding to an incident on the far side of the airfield. To reach it, they needed to cross an active runway. In low visibility conditions, the local controller issued a clearance to cross. The crew accepted it. What they did not do — or perhaps did not allow themselves to do — was question it.

The runway entrance lights (RELs) were signaling stop. Those lights — red in-pavement signals that activate automatically when an aircraft is on approach — exist precisely for this situation: an independent warning system designed to catch exactly the kind of error that was unfolding. The aircraft rescue and firefighting (ARFF) crew saw them. They crossed anyway — directly into the path of Air Canada Express Flight 8646, a CRJ-900 on final approach to the same runway. The aircraft collided with the ARFF vehicle, killing both pilots and injuring 39 others, with six serious injuries.

The tower context matters. The cab was staffed by just two controllers. The ground controller – also the controller-in-charge – was consumed by an aircraft that had performed two rejected takeoffs and declared a ground emergency — the same event that had dispatched the ARFF vehicles. With the ground controller managing that escalating situation, the local controller took over both frequencies. That same local controller – the one who had cleared the Air Canada flight to land minutes earlier – issued the runway crossing clearance to the ARFF vehicles.

The controller was not indifferent to risk; he was managing simultaneous demands with virtually no cognitive reserve. The clearance was not simply a careless act. It was the output of a system operating at the edge of its human capacity. When multiple safeguards fail in sequence, the pattern often points to a shared cognitive root: each layer of protection quietly deactivated by the same fast-brain logic that made each individual decision feel, in the moment, reasonable.

On November 4, 2025, UPS Flight 2976 — a McDonnell Douglas MD-11 with 34 years of service — experienced left engine and pylon separation during takeoff and crashed near Louisville Muhammad Ali International Airport. Fifteen people died.

The NTSB identified fatigue cracking in the left pylon support structure; Boeing’s 2011 service letter had cited four previously reported bearing-race failures involving three airplanes and recommended periodic visual inspections, while not treating the issue as safety-of-flight critical. The warning may not have been dramatic in isolation — a service letter from 2011, a maintenance inspection, a reported bearing failure — but it was exactly the kind of signal that precedes a serious event: a known failure mode, documented and distributed, that an effective organizational system should have elevated to the people with the authority to act.

That is fast-brain normalization at the institutional level. Warning signals, repeated without catastrophe, stop feeling like warnings. The signal becomes the background. What should have triggered inquiry becomes part of the accepted operating picture.

Safety does not emerge from procedures alone. It emerges from thousands of interconnected decisions about staffing, resources, priorities, schedules, equipment, incentives, and operational tradeoffs. By the time a crew confronts a hazard, much of the risk landscape has already been designed for them.

Kahneman helps explain what happens in the brains of people near the point of consequence. The work of Tom Krause, Kristen Bell, and Laura Harrison helps explain why the conditions for failure so often exist before anyone enters a tower cab, flight deck, maintenance hangar, or boardroom.

In 7 Insights into Safety Leadership, Tom and Kristen challenge one of the most persistent assumptions in safety management: that reducing minor injuries will, by extension, reduce serious ones. Their research found the opposite pattern in many organizations: recordable injuries trending downward while serious injuries and fatalities held flat. The traditional Safety Triangle — the century-old model built on the premise that reducing minor incidents at the base of the pyramid will, by extension, reduce serious events at the apex — does not reliably predict catastrophic risk. Serious injuries and fatalities have their own precursors, their own causes, and they require their own leadership attention.

In a recently published article in Professional Safety, Tom and Laura offer a complementary answer to why those precursors so often go unseen. Drawing from analysis of 365 serious injury and fatality events across industries over a decade, they argue that many of the most dangerous exposures are embedded in decisions leaders make long before anyone is placed in harm’s way.

They call it systemic exposure. Strategic decisions – acquiring aging assets, reducing headcount, expanding capacity, standardizing systems across operations with different risk profiles – may each make business sense at the senior leadership level, but they cascade through the organization, creating operational constraints that frontline workers must navigate. When those constraints go unaddressed, workarounds are normalized. Deviation becomes routine. The gap between how work is imagined and how it is actually performed grows silently, until a trigger event closes it in the worst possible way.

This is exactly the function a properly deployed Safety Management System (SMS) is designed to serve — not as a reporting database or compliance function, but as a decision framework that surfaces systemic risk signals and gives leaders the visibility to act before exposure becomes an event. The three accidents examined here raise a direct question about each relevant organization’s SMS or safety assurance process: the precursor signals were in the system – did they reach the people with the authority to act on them?

“If we fail to understand and anticipate how decision networks influence frontline behavior, we leave workers to manage contradictions they cannot safely resolve.”

— Dr. Tom Krause & Laura Harrison, Professional Safety, 2026

Seen through this lens, the Louisville crash becomes even more instructive. Keeping a 34-year-old aircraft in service while documented component concerns accumulated over time is an example of systemic exposure: warning signals embedded in the system and progressively normalized, with workers and maintenance teams managing contradictions inherited from upstream decisions.

The same pattern runs through Reagan National and LaGuardia. The FAA’s failure to redesign helicopter routes despite years of recurring collision advisories was a system-shaping decision deferred at the institutional level. The staffing configuration that placed two controllers in a LaGuardia tower cab – managing an active runway, approaching traffic, and a ground emergency simultaneously – was not their decision that night. It was inherited, and it left no margin.

That configuration was not unique to LaGuardia that night. Recent congressional and industry testimony has identified ATC staffing, modernization, and surveillance limitations as active national safety concerns. The operational constraint the crew inherited was a systemic condition, not merely a local anomaly.

Tom and Laura’s central prescription is direct: organizations must design decision systems that make the safe choice the easy choice. Leaders must trace how their decisions cascade to the frontline, treat workarounds as system signals rather than individual failures, and share accountability for risk across every level of the organization that created the conditions for it.

In these three accidents, the precursors were not hypothetical, they were documented: recurring collision alerts at Reagan National, documented pylon concerns on the MD-11, including a Boeing service letter dating to 2011, and runway entrance lights that were activated and visible as the ARFF crew crossed the runway at LaGuardia. None were hidden. Each was knowable. What was missing was an organizational system that treated the signals as warnings — and the will of leadership to act before a catastrophic event forced the question.

During my years as a chief pilot, director of operations, and chief safety officer, I became increasingly convinced that serious events are rarely born in the moment they occur. More often, they are the visible endpoint of decisions, adaptations, and normalized compromises that accumulated quietly over time.

What CRM did for crews, aviation now needs for its leaders. CRM succeeded because it changed how pilots understood human performance. That model — which began as Cockpit Resource Management and evolved into Crew Resource Management as it spread beyond the flight deck — extended from cockpits to cabin crews, dispatchers, maintenance teams, and other high-consequence industries. The next paradigm shift requires doing the same thing at the organizational level: for airlines, regulators, manufacturers, Maintenance, Repair, and Overhaul (MRO) providers, and every institution whose decisions shape the operating environment.

Leaders must learn to recognize precursor signals, understand how their decisions cascade through complex systems, and appreciate that serious events often begin long before anyone touches a control column or steps onto a ramp.

The Senate’s June 2026 hearing on close calls shows the industry is already debating technology, surveillance, tracking mandates, runway-safety systems, and modernization. Those are necessary conversations. They are not sufficient. The accidents at the center of this article point to something underneath: the cognitive habits and leadership decisions that determine whether the visible architecture of safety — including the SMS — functions as designed or gets quietly worked around.

The question facing aviation is not whether we can build safer aircraft or write better regulations. We will continue to do both. The harder question is whether we are prepared to examine the cognitive and organizational systems that shape how safety is actually created. That answer will not only define the next generation of aviation safety, but safety for other high-hazard industries.

Neil Schnaak is an Executive Consultant with the Krause Bell Group and an Airline Transport Pilot with 8,100 flight hours. His four-decade professional aviation career includes service as Chief Safety Officer for Hawaiian Airlines, his most recent airline post, and prior FAA Part 119 management roles with other Part 121 carriers, including Director of Safety, Director of Operations, and Chief Pilot. He has chaired the Airlines for America Safety Council, led and supported Part 121 air carrier certification efforts, and contributed to the FAA’s System Approach to Safety Oversight. He advises aviation and other high-consequence organizations on safety leadership, organizational learning, and serious-event prevention.