/

Integrity of Security at Airports  — The Recent Controversy in Sri Lanka

The resignation that followed is emblematic of a deeper and more troubling phenomenon: the politicization of technical security functions.

13 mins read
Bandaranaike International Airport, Katunayake, Sri Lanka.

All human life can be found in an airport. ~ David Walliams

Air Chief Marshal Harsha Abeywickrama, who served concurrently as Chairman of Airport and Aviation Services (Sri Lanka) Limited and as a former Commander of the Sri Lanka Air Force, has reportedly laid down his office in circumstances that transcend the ordinary vocabulary of administrative resignation and enter the more exacting realm of principle. His departure, as understood from those conversant with the matter, was precipitated by a fundamental disagreement over the integrity of aviation security, arising from a ministerial request that sought to extend high-level security clearance to certain members of the clergy for access to sterile areas of airports—zones situated beyond immigration control and governed by the most exacting international security standards. To Abeywickrama, whose professional life has been forged in the disciplines of command, risk, and accountability, such a request was irreconcilable with the normative rigidity demanded by international aviation security obligations, and it was this irreconcilability that ultimately rendered his continued tenure untenable.

The resignation is not merely an administrative episode or an internal bureaucratic disagreement; it is a juridical and ethical moment that exposes a profound fault line between executive authority and the sacrosanct autonomy of aviation security. It is a moment that compels a re-examination of the relationship between political power and technical expertise within the international civil aviation system, a system that was deliberately constructed, in the aftermath of war and insecurity, to insulate safety and security from transient political expediency. At its core, this episode illustrates the dangers inherent when executive direction seeks to intrude upon security regimes that are normatively governed not by discretion, privilege, or symbolism, but by risk assessment, threat mitigation, and uniform application of international standards.

The ICAO Position

International civil aviation security rests upon a foundational premise: that threats to aviation are indifferent to rank, vocation, faith, or political symbolism. Annex 17 (Aviation Security) to the Convention on International Civil Aviation embodies this premise with unmistakable clarity. It imposes upon Contracting States the obligation to establish, implement, and maintain a national civil aviation security program that ensures the protection of civil aviation against acts of unlawful interference. The language of Annex 17 is not aspirational; it is imperative. It speaks in the grammar of duty rather than discretion, placing the responsibility squarely upon States to ensure that access to security-restricted areas, including sterile areas beyond immigration and passenger screening points, is strictly controlled, continuously monitored, and granted only on the basis of operational necessity and verified trustworthiness.

Within this normative architecture, sterile areas are not symbolic spaces but juridical zones of heightened vulnerability. They are spaces where the convergence of aircraft, passengers, crew, and critical infrastructure creates the conditions under which a single security lapse can cascade into catastrophe. For this reason, Annex 17, read together with the ICAO Aviation Security Manual, insists upon a layered security approach in which access control is not a courtesy extended by authority but a privilege earned through exhaustive vetting, background checks, and demonstrated operational need. The Manual makes explicit that access authorization must be predicated on the principle of “need to access,” and that exemptions, however well-intentioned, introduce asymmetries that adversaries are adept at exploiting.

It is against this normative and operational background that the reported ministerial request to grant high-security clearance to certain religious figures must be examined. The issue is not one of faith, respect, or cultural accommodation; it is one of structural integrity. Aviation security regimes do not distinguish between individuals on the basis of moral standing or social reverence. They distinguish only between those whose access is essential to aviation operations and those for whom access constitutes an avoidable risk. The moment such distinctions are blurred by executive direction, the entire security edifice begins to erode, not dramatically, but insidiously, through precedent.

The ICAO Aviation Security Manual warns, in measured but unmistakable terms, of the dangers of ad hoc exemptions. It underscores that insider threats represent one of the most pernicious and difficult risks to mitigate precisely because they exploit trust, familiarity, and perceived legitimacy. When access is granted on grounds external to security assessment, the integrity of access control systems is compromised, and the concept of security clearance itself is devalued. The Manual further emphasizes that senior officials and politically exposed persons must not be exempted from standard security procedures, as such exemptions create vulnerabilities that can be exploited directly or indirectly.

Air Chief Marshal Abeywickrama’s reported objection to the ministerial request must therefore be understood not as institutional obstinacy, but as fidelity to an international legal obligation and to the ethical demands of professional responsibility. As a former Commander of the Sri Lanka Air Force and a custodian of national aviation infrastructure, his duty was not to accommodate power but to resist its misapplication where security was concerned. In aviation security, professional judgment is not subordinate to political convenience; it is the very mechanism by which States discharge their obligations under the Chicago Convention.

The resignation that followed is emblematic of a deeper and more troubling phenomenon: the politicization of technical security functions. Annex 17 envisages a clear demarcation between policy formulation, which may legitimately fall within the political domain, and security implementation, which must remain insulated from interference. This demarcation is not merely functional; it is epistemic. Aviation security is a discipline governed by threat intelligence, risk matrices, and constantly evolving methodologies. Executive interference that bypasses these epistemic foundations replaces evidence with authority, and assessment with assertion.

The Danger

Such authoritative use of arbitrary power perforce brings inherent dangers which  extend beyond the immediate security risk. They implicate the international standing of the State itself. Under ICAO’s  Universal Security Audit Programme, States are subject to regular ICAO audits assessing compliance with Annex 17 Standards and Recommended Practices. Any indication that access controls are subject to political override exposes the State to adverse audit findings, corrective action plans, and, in extreme cases, enhanced scrutiny by other States. In an interconnected aviation system, reputational damage is not abstract; it translates into increased inspections, operational delays, and erosion of trust by foreign carriers and regulators.

Moreover, executive intrusion into security decisions risks normalizing a culture of exception. Once a precedent is established that security clearances can be granted by ministerial fiat, the rationale for refusal becomes progressively weaker. What begins as an isolated request, framed perhaps as benign or exceptional, becomes an implicit doctrine of privilege. The ICAO Security Manual cautions against precisely this phenomenon, noting that the gradual dilution of access control standards often precedes major security failures, not because the threat environment worsened, but because vigilance eroded.

There is also a constitutional dimension to this episode that cannot be ignored. Critical national infrastructure such as airports occupies a unique legal and moral space. It is infrastructure whose failure carries transboundary consequences, implicating not only domestic law but international responsibility. Those entrusted with its security are therefore bound by a higher standard of independence and integrity. When executive authority encroaches upon this space, it risks converting technical custodians into mere functionaries, thereby undermining the very rationale for appointing professionals of experience and distinction.

Misconceptions of State Sovereignty

The silence of the Ministry of Aviation following the resignation further compounds the concern. Transparency is not antithetical to security; indeed, Annex 17 encourages States to foster a security culture grounded in accountability and clarity of roles. The absence of an official explanation invites speculation and erodes public confidence, not only in the aviation security apparatus but in the governance structures that oversee it. In a field where confidence is itself a security asset, opacity becomes a liability.

What this episode ultimately reveals is a misunderstanding of sovereignty in the context of international aviation. Sovereignty, under the Chicago Convention, is not a license to disregard international norms; it is a responsibility to uphold them. States retain complete and exclusive sovereignty over their airspace, but that sovereignty is exercised within a framework of reciprocal obligations. Annex 17 represents a collective determination that aviation security must be shielded from parochial pressures precisely because the consequences of failure are global.

The resignation of a senior security professional in defense of these principles should not be viewed as an act of defiance, but as an act of institutional conscience. It is a reminder that the effectiveness of aviation security depends not only on technology and procedure, but on the moral courage of those who are willing to say no when no is required. When executives interfere with security decisions, they do not merely override a professional judgment; they assume responsibility for risks they may neither fully comprehend nor be equipped to manage.

Deontology and the Airport Manger – The AI Role

The airport manager in the contemporary aviation ecosystem stands not merely as an administrator of infrastructure, but as a fiduciary of international trust. Airports are no longer purely national assets; they are nodal points in a global system whose safety and security depend upon uniformity, predictability, and insulation from parochial influence. Nowhere is this more evident than in the domain of aviation security, where Annex 17 to the Convention on International Civil Aviation and the ICAO Aviation Security Manual impose upon States, and by extension upon airport managers, obligations that are legal, operational, and ethical in equal measure. The increasing tendency of executive authorities to intrude upon security-sensitive decisions therefore raises a question of systemic importance: how may airport managers lawfully and effectively circumvent political interference without undermining constitutional authority, while preserving the integrity of aviation security in an era of complex threats?

Annex 17 is founded upon a deceptively simple premise: that aviation security must be governed by rules rather than personalities. Its standards require States to establish a national civil aviation security programme that clearly allocates responsibilities, enforces access control to security-restricted areas, and ensures that no person is granted access unless their trustworthiness has been verified and their operational need established. The ICAO Aviation Security Manual reinforces this by emphasizing that exemptions, informal authorizations, and ad hoc clearances constitute systemic vulnerabilities. These instruments collectively envisage an aviation security regime that is deliberately resistant to discretion exercised outside structured processes, precisely because discretion is the conduit through which political pressure most easily flows.

The first and most effective mechanism available to airport managers in circumventing political intrusion lies in the juridification of security decision-making. When access authorizations, clearances, and exemptions are governed by codified procedures embedded within the national civil aviation security program, the airport manager ceases to function as an individual decision-maker and becomes instead the executor of a legal framework. Political requests, however forcefully articulated, are thereby transformed into questions of compliance rather than matters of accommodation. In this sense, the airport manager does not refuse authority; he or she defers to a higher norm, grounded in international obligation and incorporated into domestic law.

This transformation of discretion into procedure has a profound defensive effect. Political intrusion thrives in informality, in unwritten understandings and exceptional gestures. It falters in environments where every decision must be documented, justified, and traceable to an established standard. Annex 17 implicitly recognizes this dynamic by requiring States to ensure that aviation security measures are subject to quality control, internal audits, and oversight. An airport manager who insists upon written requests, documented risk assessments, and recorded determinations does not provoke confrontation; rather, such a manager neutralizes intrusion by exposing it to institutional scrutiny.

Closely allied to proceduralization is the concept of institutional pluralism. The ICAO security framework does not envisage aviation security as the province of a single individual or office. Instead, it mandates coordination among airport authorities, aviation regulators, law enforcement agencies, intelligence services, and security providers. Where access decisions are made collectively by security committees or joint assessment panels, the capacity for unilateral political influence is significantly reduced. Executive authority, which may exert pressure upon a single office-holder, finds itself diluted when confronted with an interlocking network of professional judgments. In such circumstances, responsibility is diffused, but accountability is strengthened.

This diffusion is not a bureaucratic artifice; it is a deliberate safeguard against capture. Aviation security is uniquely vulnerable to the personalization of power because its failures are often invisible until catastrophe occurs. Annex 17 therefore seeks to institutionalize skepticism by ensuring that no single actor controls both the decision and its justification. Airport managers who actively cultivate this culture of collective assessment are not evading authority; they are fulfilling the spirit of international aviation law, which treats security as a systemic rather than hierarchical function.

Yet even the most robust procedural and institutional safeguards remain vulnerable in political environments where executive authority is accustomed to overriding norms through informal channels. It is in this context that artificial intelligence assumes a new and potentially transformative role. Properly understood, AI is not merely a technological enhancement; it is an epistemic intervention that can alter the balance between discretion and rule-based governance. When deployed within the aviation security framework envisaged by Annex 17, AI can function as an institutional buffer between political impulse and operational execution.

One of the most immediate contributions of AI lies in risk-based access control. The ICAO Aviation Security Manual underscores that access to security-restricted and sterile areas must be predicated on verified trustworthiness and operational necessity, and that such trustworthiness must be subject to continuous reassessment. AI systems are uniquely suited to this task. By integrating data from background checks, access histories, behavioral indicators, and threat intelligence, AI can generate dynamic risk profiles that are continuously updated and uniformly applied. In such a system, access decisions are no longer anchored in personal discretion, but in algorithmic assessment grounded in predefined criteria.

The normative significance of this development is considerable. When access decisions are driven by AI-generated risk assessments, political intrusion encounters a structural barrier. A directive seeking preferential access must confront not an individual manager’s judgment, but a system whose outputs are consistent, documented, and auditable. To override such a system is no longer a quiet administrative act; it is a visible deviation from established security logic, one that demands justification and invites scrutiny. In this way, AI does not replace human judgment; it constrains it within a framework that privileges evidence over influence.

AI also reinforces one of the most fundamental principles of Annex 17: the equal application of security measures. One of the gravest dangers of political interference is the normalization of exemption. Once certain individuals or groups are perceived as entitled to special treatment, the universality of security collapses. AI systems, by their design, resist exemption unless explicitly programmed to allow it. This resistance can serve as a powerful shield for airport managers, who may legitimately assert that deviations are technically impossible without systemic alteration. The burden of responsibility is thereby shifted away from the individual manager and onto the governance structure itself.

Another critical area where AI aligns with ICAO guidance is insider threat detection. The Aviation Security Manual repeatedly identifies insiders as one of the most significant risks to aviation security, precisely because they operate within trusted environments. AI systems capable of detecting anomalous patterns of movement, access frequency, or behavior within sterile areas offer a level of vigilance that is both continuous and impartial. Such systems do not discriminate on the basis of rank, office, or social standing; they detect deviations from norm. This epistemic neutrality mirrors the legal neutrality demanded by Annex 17, which is indifferent to status and attentive only to risk.

However, the use of AI as a safeguard against political intrusion is not without its own dangers. An AI system that is opaque, proprietary, or subject to executive manipulation risks becoming an instrument of power rather than a check upon it. For AI to serve the integrity of aviation security, its governance must be transparent, its criteria subject to audit, and its outputs explainable. Airport managers must retain ultimate responsibility for decisions, but any deviation from AI-generated assessments should require written justification and trigger review mechanisms. In this manner, AI becomes a discipline rather than a disguise.

There is also a deeper philosophical caution embedded within Annex 17 that remains salient in the age of artificial intelligence. Security, at its core, is a human responsibility. Technology may assist, inform, and constrain, but it cannot absolve decision-makers of ethical accountability. The airport manager who relies on AI must therefore do so not as a means of abdication, but as a means of reinforcement. The danger lies not in algorithmic governance, but in allowing algorithms to become convenient alibis for moral failure.

Perhaps the most understated but consequential contribution of AI lies in documentation and traceability. Political intrusion often operates through informal communications, verbal directives, and unwritten expectations. AI-driven systems that log access requests, risk scores, approvals, overrides, and justifications create an evidentiary trail that deters interference by increasing the likelihood of exposure. In a system subject to ICAO audits and international scrutiny, such traceability is itself a form of protection. Transparency, far from undermining security, becomes one of its most potent allies.

Ultimately, the circumvention of political intrusion by airport managers is not an act of resistance against the State, but an act of fidelity to its highest obligations. Annex 17 does not merely prescribe technical measures; it articulates a philosophy of governance in which aviation security is insulated from whim and anchored in reason. Artificial intelligence, cautiously and ethically deployed, can reinforce this insulation by embedding objectivity, consistency, and accountability into systems that are otherwise vulnerable to human pressure.

Yet no legal framework or technological system can substitute for institutional courage. The airport manager who stands firm against improper interference does so not in opposition to authority, but in service of the public interest and international trust. In an era where threats to aviation are increasingly asymmetric and subtle, the most dangerous vulnerability may no longer be technological or operational, but political. To guard against that vulnerability is to understand that aviation security, once compromised by power, cannot be restored by explanation or apology. It can only be preserved by structures—legal, institutional, and technological—that make compromise not merely difficult, but impossible.

My Take

In the final analysis, the dangers of executive interference in aviation security are not hypothetical. They are well-documented in the annals of aviation history, where lapses have often been traced not to ignorance of standards, but to their deliberate circumvention. Annex 17 and the ICAO Aviation Security Manual were crafted precisely to prevent such circumvention by embedding security within a rules-based system resistant to arbitrary influence. To depart from this system is to invite not flexibility, but fragility.

The episode surrounding Air Chief Marshal Abeywickrama’s resignation should therefore serve as a cautionary tale, not only for Sri Lanka but for all States navigating the delicate balance between authority and expertise. Aviation security is not an arena for accommodation or symbolism; it is a domain governed by necessity, uniformity, and restraint. When these principles are compromised, the risk is not borne by the decision-maker alone, but by every passenger who entrusts their life to the integrity of the system.

The most essential approach an airport manager can adopt in ensuring airport security in the age of artificial intelligence is to treat AI not as a substitute for human judgment, but as an epistemic discipline that constrains discretion and reinforces fidelity to international obligation. Properly integrated, AI should function as a rule-based architecture that embeds Annex 17 compliance into everyday decision-making by translating risk assessment, access control, and anomaly detection into objective, auditable processes applied uniformly and without exception. In doing so, AI insulates security determinations from transient influence, personal persuasion, and political intrusion, while preserving human accountability at the point of decision. The airport manager’s task, therefore, is not to delegate responsibility to machines, but to harness AI as a guardian of consistency, transparency, and institutional integrity within the aviation security system.

Ruwantissa Abeyratne

Dr. Abeyratne teaches aerospace law at McGill University. Among the numerous books he has published are Air Navigation Law (2012) and Aviation Safety Law and Regulation (to be published in 2023). He is a former Senior Legal Counsel at the International Civil Aviation Organization.

Leave a Reply

Your email address will not be published.

Latest from Blog