This week, thousands of passengers across the UK found themselves looking at departure boards filled with delays and cancellations.
The cause wasn’t weather, industrial action or an airport closure. It was a technical problem within the system used by NATS, the organisation responsible for managing much of the UK’s air traffic.
NATS reported a problem with its flight processing system on Tuesday afternoon, affecting departures from airports across the country. A fix was eventually implemented, and the system recovered, but by then the disruption had spread throughout the network. More than 1,000 flights were cancelled, with Heathrow, Gatwick, Manchester and other major airports affected.
Flights are operating again, but the effects haven’t disappeared with the technical problem. Aircraft and crews have ended up in the wrong places, schedules have been disrupted and airlines are now working through the knock-on effects. Further cancellations and delays have continued into Wednesday as the network recovers.
For passengers, it’s understandably frustrating.
But from a flight training perspective, there’s another side to the story that’s worth looking at.
What actually happens when the air traffic control system can’t operate normally?
The first thing to understand is that air traffic control doesn’t simply disappear.
The UK’s airspace normally handles a huge volume of traffic, and doing that safely depends on controllers having the information and systems they need to build an accurate picture of where aircraft are, where they’re going and how traffic can be safely sequenced.
When part of that infrastructure becomes degraded, the answer isn’t to continue handling the same volume of traffic and hope for the best.
Capacity is reduced.
That can mean aircraft being held on the ground, departures being delayed, restrictions being introduced and traffic flows being regulated. From the passenger’s perspective, that looks like the system has stopped working. Operationally, however, reducing the amount of traffic is one of the ways safety margins can be protected when the normal level of service isn’t available.
We’ve seen this principle before.
During the major NATS flight-planning failure in August 2023, NATS said it deliberately reduced the number of aircraft in UK airspace while dealing with the technical problem because maintaining safety was its overriding legal duty. Despite the disruption, thousands of flights continued to be handled during the incident.
It’s an important distinction.
Disruption doesn’t necessarily mean a loss of safety. Sometimes disruption is the consequence of protecting it.
And that’s where an event like this becomes particularly relevant to pilots.
An ATC restriction might begin as a technical problem hundreds of miles away, but its effects can quickly reach the flight deck.
A departure slot changes. A delay increases. Fuel planning may need to be reconsidered. The weather at the destination or alternate may be changing while the aircraft waits. Crew duty time continues to run. Passengers are waiting. Connections are being missed. And once airborne, further restrictions or rerouting may still be possible.
Suddenly, something that began as an ATC technical failure has created a completely different operational environment for the crew.
This is where Threat and Error Management becomes particularly relevant.
In TEM, a threat is something outside the pilot’s direct control that increases the complexity of the operation. An ATC system failure is a good example. The crew didn’t create it and can’t fix it, but they still have to manage its consequences.
The threat itself doesn’t necessarily make the flight unsafe.
What matters is what happens around it.
If a departure is delayed significantly, does the original fuel plan still provide the margins the crew wants? If the expected arrival time changes, has the weather picture changed too? If the crew is given a different routing, what needs to be checked? And as workload increases, are decisions still being made with the same margin that existed when the flight was originally planned?
It’s a useful example of why TEM isn’t simply an exam concept.
The situation around an aircraft is constantly changing, and good threat management is partly about recognising when the original plan needs to change with it.
There’s another interesting aspect to yesterday’s disruption.
Aviation safety is built around the assumption that individual components can fail.
That principle appears everywhere, from duplicated aircraft systems to operational procedures and contingency planning. The aim isn’t to create a world in which nothing ever goes wrong. It’s to make sure that when something does, there are other layers available to prevent that failure from becoming something more serious.
It’s the same thinking behind the Swiss Cheese model that we teach in Human Performance.
Normally, several layers sit between a problem and an accident: technology, procedures, regulation, training and human intervention among them. Individual layers can have weaknesses, but safety comes from preventing those weaknesses from aligning.
In this case, we don’t yet know precisely what caused the NATS technical failure, so it’s too early to make judgements about the resilience of the system itself. That will require a proper technical investigation.
But the operational response demonstrates the principle particularly well.
If the technology needed to manage the normal traffic volume isn’t available, another layer comes into play: reduce the traffic volume to something that can be managed safely.
It may create enormous disruption.
But that’s preferable to allowing commercial or operational pressure to erode the safety margin.
There is also a wider question here.
This isn’t the first significant technical disruption involving NATS in recent years. In August 2023, an unusual flight-plan processing problem resulted in restrictions to UK airspace and widespread cancellations. A further technical issue affected UK air traffic in July 2025, and now another failure has caused substantial disruption in September 2026. The latest incident has inevitably renewed questions within the industry about the resilience of such critical infrastructure.
Those questions are legitimate, but they’re separate from the question of whether the system remained safe.
And that’s perhaps the most interesting lesson for anyone currently studying towards their ATPLs.
We spend a lot of time learning how aviation works when everything is operating normally: airspace, clearances, separation, flight planning, fuel, communications and procedures.
But aviation safety is arguably revealed most clearly when something isn’t operating normally.
Yesterday’s disruption shows how quickly a failure in one part of the aviation system can affect everything around it. It also demonstrates why contingency procedures, capacity restrictions and conservative decision-making exist.
There is still plenty we don’t know about what caused this particular failure, and the investigation will be important in establishing what happened and whether further changes are needed.
But from a training perspective, there’s already something worth taking from it.
When part of the aviation system becomes degraded, the objective isn’t necessarily to keep everything running normally.
Sometimes the safest response is to accept that you can’t.
And in aviation, knowing when to reduce capacity, increase the margin and change the plan is a principle that applies just as much in the flight deck as it does in an air traffic control centre.






