/

When Separation Fails: The Iberia–Air Europa Warning

14 mins read
Iberia A321 and Air Europa Boeing 787

The human condition today is better than it’s ever been, and technology is one of the reasons for that. — Tom Clancy

The Issue

The near collision involving an Iberia Airbus A321 and an Air Europa Boeing 787-9 over the Atlantic Ocean on 10 July 2026 presents aviation law with a particularly instructive circumstance in which technology, human responsibility, air traffic management and international regulation converge. The occurrence is significant not merely because two commercial aircraft found themselves on the same airway and at the same level of flight while proceeding in opposite directions, but because the event demonstrates, with unusual clarity, the manner in which the international civil aviation system is constructed around layers of safety. One layer may fail, another may compensate, and a final layer may prevent an occurrence from becoming an accident. In this instance, the final airborne defence, the Traffic Collision Avoidance System, or TCAS, appears to have performed precisely the function for which it was designed. Yet the fact that TCAS had to intervene raises a question of greater juridical and regulatory significance: why did the preceding layers of the air navigation system permit the two aircraft to reach a position in which collision avoidance became necessary?

The Facts

The facts presently available must be approached with a measure of legal prudence. According to information attributed to Spain’s Civil Aviation Accident and Incident Investigation Commission, known as CIAIAC, the event occurred at approximately 01:23 UTC on 10 July 2026 in the oceanic sector of the Canary Islands Flight Information Region and Upper Information Region. The Iberia Airbus A321, registration EC-OLE and call sign IBE0140, was operating on airway N857 at flight level 360, travelling northeast between the reporting points ETIBA and BIPET. At the same level and on the same airway, a Boeing 787-9 identified in the investigative information as EC-NBM, call sign AEA05, was proceeding in the opposite direction. The TCAS system aboard the Iberia aircraft first generated a traffic advisory and subsequently a resolution advisory instructing the aircraft to descend. The Boeing received a complementary climb advisory. The Airbus descended approximately 500 feet and the Boeing climbed approximately 400 feet, after which the systems indicated that the conflict had been resolved. Both aircraft continued their respective flights without injury or damage.

There has been some inconsistency in secondary reporting concerning the registration and flight identification of the Air Europa aircraft. Some reports have referred to EC-ODH and flight UX57, whereas the information attributed to the Spanish investigation identifies EC-NBM and AEA05. That discrepancy illustrates an important principle of aviation investigation: facts must be distinguished from reportage, and preliminary information must be distinguished from established findings. The juridical temptation to identify a culprit immediately must yield to the investigative discipline of determining what actually occurred, why it occurred and whether the occurrence was the product of an individual error, an organizational deficiency, a procedural weakness, a technological failure, or a combination of several latent conditions. Aviation safety regulation is founded upon precisely this philosophy of learning rather than premature attribution of blame.

The Chicago Convention

The event must consequently be placed within the broader architecture created by the Convention on International Civil Aviation, signed at Chicago on 7 December 1944. The Chicago Convention did not merely create the International Civil Aviation Organization; it established a normative framework within which international civil aviation could develop in an orderly and safe manner. Article 28 is particularly relevant because it recognizes the responsibility of Contracting States, so far as they may find practicable, to provide airports, radio services, meteorological services and other air navigation facilities in accordance with standards and practices internationally established or recommended by ICAO. The provision is important because it places air navigation within the sphere of public responsibility. Airspace is not simply a commercial highway. It is an infrastructure of public safety administered through national authority but increasingly governed by international harmonisation.

Article 37 of the Convention gives this principle an institutional dimension by requiring States to collaborate in securing the highest practicable degree of uniformity in regulations, standards, procedures and organisation in circumstances where such uniformity facilitates and improves air navigation. It is here that the ICAO Annexes acquire their importance. They represent an extraordinary exercise in international regulatory harmonisation because the safety of an aircraft crossing national boundaries cannot sensibly depend upon an entirely different philosophy of navigation every time the aircraft enters another jurisdiction. Article 38, moreover, recognises the possibility of national differences while imposing an obligation of notification. The underlying philosophy is therefore one of sovereignty tempered by transparency and international responsibility.

It is sometimes said that there is an ICAO “Annex on Air Traffic Management”. Strictly speaking, that description is imprecise. The regulatory architecture of air traffic management is distributed principally among Annex 2, dealing with Rules of the Air, Annex 11, dealing with Air Traffic Services, and the Procedures for Air Navigation Services — Air Traffic Management, known as PANS-ATM or Doc 4444. ICAO itself identifies Annex 2, Annex 11 and PANS-ATM as central components of its air traffic management framework. This distinction is not merely academic. Annexes establish Standards and Recommended Practices, while PANS-ATM provides detailed procedures through which the broad regulatory principles are translated into operational practice.

Legal Issues

The legal significance of this framework becomes apparent when the circumstances of the Iberia–Air Europa occurrence are considered. Air traffic management is fundamentally a system of separation. Its purpose is not merely to tell aircraft where they may fly but to organise the movement of aircraft in such a manner that the possibility of collision is reduced to an acceptable level. The system depends upon accurate flight information, appropriate clearances, communication, coordination, surveillance and adherence to established procedures. Where two aircraft travelling in opposite directions appear to have occupied the same airway and the same flight level, the appropriate legal question is therefore not immediately whether a particular controller was negligent. The more sophisticated question is whether the air traffic management system, considered as a whole, functioned in accordance with the applicable regulatory framework.

TCAS and surveillance

This is where the distinction between an individual error and a systemic failure becomes essential. Modern aviation safety regulation increasingly recognises that an accident or serious incident rarely arises from one isolated act. Human beings operate within systems, and those systems contain procedures, technologies, organizational structures, workload pressures, communication arrangements and assumptions. A person may make an error, but the central safety question is whether another layer of the system should have detected and corrected that error before it became operationally consequential. The Iberia–Air Europa event is therefore valuable precisely because it allows the concept of layered defence to be examined in an actual operational setting.

The role played by TCAS is particularly instructive. TCAS is sometimes loosely described as artificial intelligence, but such a description is misleading. TCAS is principally an automated airborne collision-avoidance system operating according to defined logic and internationally established performance requirements. ICAO Annex 10, Volume IV, specifically contains Standards and Recommended Practices concerning secondary surveillance radar and airborne collision avoidance systems, including the technical characteristics of ACAS. It is therefore more accurate to speak of TCAS as advanced aviation automation rather than simply artificial intelligence.

The distinction nevertheless becomes increasingly important as aviation moves towards systems incorporating more sophisticated computational decision-making. The legal system must confront the possibility that machines will increasingly assist, advise or, within carefully prescribed parameters, make decisions that have immediate consequences for aviation safety. Yet technology does not possess legal responsibility merely because it possesses operational capability. A machine cannot be summoned before a court, cannot hold an air operator certificate and cannot be subjected to regulatory oversight in the manner of an airline or air navigation service provider. Responsibility continues to reside within the human and institutional architecture surrounding the technology.

TCAS should therefore be understood as a safety net rather than a substitute for air traffic control. Its existence does not absolve the air navigation service provider from the responsibility to provide appropriate separation, nor does it transfer the responsibility for the safe conduct of a flight from the pilot to the machine. Rather, TCAS introduces an additional protective barrier. When the primary system of separation becomes compromised, the airborne collision-avoidance system may provide the warning necessary to prevent the situation from escalating into catastrophe. In this sense, the Iberia–Air Europa occurrence demonstrates the resilience of the aviation safety system. At the same time, it demonstrates that resilience should never become an excuse for complacency.

Indeed, the most important safety question arising from the occurrence is not simply why TCAS worked. It is why TCAS was required to work. The fact that a collision was avoided is reassuring, but from a regulatory perspective it is also an invitation to investigate the conditions that preceded the resolution advisory. If two aircraft are placed in a conflict situation, the investigation must consider the entire chain of events. Were the flight plans correctly processed? Were the aircraft properly identified? Were clearances correctly issued? Was coordination between sectors effective? Were the applicable separation procedures correctly followed? Was there a communication difficulty? Did automation display information in a manner conducive to misunderstanding? Were there workload or human-factors considerations? Were there previous occurrences that might have indicated a latent hazard?

Safety Management

This philosophy corresponds closely with the evolution of ICAO’s safety-management regime. Annex 19, Safety Management, provides overarching provisions relating to safety management functions associated with the safe operation of aircraft and emphasizes the importance of safety management at State level. The current ICAO framework also places considerable emphasis upon the collection, analysis, exchange and protection of safety information. The significance of this approach is profound. Aviation regulation is progressively moving from a philosophy of reacting to accidents towards a philosophy of identifying hazards before they mature into accidents.

The near collision therefore constitutes safety intelligence. Its value lies in the information it provides concerning the functioning of the system. A mature safety culture does not ask only, “Who made the mistake?” It asks, “What conditions made the mistake possible, and why did the system not detect it earlier?” This is the essence of a proactive State Safety Programme and of the Safety Management System required of relevant aviation service providers. ICAO’s Safety Management Manual emphasizes that safety management should be tailored to the environment in which an organization operates and should focus upon identifying and controlling safety risks.

The legal significance of this approach should not be underestimated. Traditional notions of liability are often retrospective. They ask who did what and whether that conduct constituted a breach of a legal obligation. Safety management is prospective. It asks what may go wrong tomorrow and what can be done today to prevent it. The two approaches are not mutually exclusive, but aviation safety is particularly dependent upon the latter. If every reported occurrence immediately becomes an exercise in individual blame, personnel may become reluctant to report hazards, and the regulatory system may lose the very information it needs to improve safety.

The European regulatory framework reinforces this systemic approach. Air traffic management and air navigation service providers within the European aviation system operate within a detailed regulatory environment that imposes requirements concerning safety management, oversight and organizational competence. The European framework therefore complements the Chicago Convention architecture rather than replacing it. International Standards provide the global foundation, while regional and national law gives those principles operational effect.

The occurrence also invites consideration of cybersecurity, although there is presently no evidence that a cyberattack caused the Iberia–Air Europa event. It would therefore be legally and factually inappropriate to imply that cyber interference was involved. Nevertheless, cybersecurity has become inseparable from aviation safety because contemporary air navigation increasingly depends upon interconnected digital systems. The modern aircraft is not an isolated machine, and the modern air traffic management system is not an isolated collection of radar screens and radio communications. It is an information environment.

Cyber Security and Safety

This development introduces a new category of vulnerability. If the integrity of aviation information were compromised, the consequences could extend beyond the cyber domain and directly into flight safety. An incorrect aircraft identity, inaccurate position information, corrupted flight data or compromised communication could potentially create circumstances in which the human decision-maker and the automated system were both acting upon information that could not be trusted. Cybersecurity is therefore not merely a question of protecting computers. It is a question of protecting the integrity of the information upon which aviation decisions depend.

ICAO has recognised that digital transformation and increasing interconnectivity create new vulnerabilities within civil aviation. Recent ICAO work expressly links cybersecurity with the growing digital dependency and systemic complexity of aviation. The regulatory challenge is consequently one of ensuring that safety, security, capacity and efficiency are not treated as isolated silos. A cyber incident affecting an air traffic management system can become a safety incident; a safety vulnerability in a digital system can become a security concern. The boundaries between these disciplines are becoming increasingly porous.

This consideration becomes even more important when artificial intelligence is introduced into the aviation ecosystem. AI may eventually assist in predicting traffic conflicts, optimising routes, identifying anomalies and supporting controllers and flight crews. Its promise is substantial, but so too is its regulatory challenge. An AI-enabled system may produce a recommendation based upon data that is incomplete, inaccurate or compromised. The issue is therefore not simply whether the algorithm is intelligent. The issue is whether the data is trustworthy, whether the system is explainable to the human decision-maker, whether its performance can be validated and certified, and whether there remains an appropriate allocation of responsibility when its recommendation is wrong.

Interdependence

The Iberia–Air Europa occurrence provides a useful conceptual framework for answering these questions. The TCAS system did not replace the pilots; it complemented them. The pilots did not replace air traffic management; they operated within it. Air traffic management did not operate independently of the State; it functioned within a regulatory architecture established through national, regional and international law. The safety of the flight was therefore the product of interdependence.

That interdependence is perhaps the central jurisprudential lesson of the event. Aviation safety is not the product of a single legal obligation. It is an ecosystem of obligations, standards, procedures, technological safeguards, professional responsibilities and institutional oversight. The Chicago Convention provides the constitutional framework. The ICAO Annexes establish the internationally harmonised regulatory structure. PANS-ATM provides operational detail. Safety management identifies and controls risk. TCAS provides an airborne defence. Cybersecurity protects the information environment upon which increasingly automated aviation depends.

Challenges

The event also demonstrates why technological optimism must be approached with caution. It would be easy to conclude that because TCAS prevented the aircraft from colliding, technology has solved the problem. Such a conclusion would represent technological determinism and would misunderstand the nature of aviation safety. Technology does not eliminate risk; it changes the character of risk. A new automated system may eliminate one category of human error while introducing another category of dependency. A digital network may increase efficiency while creating a new avenue for systemic disruption. Artificial intelligence may identify patterns that humans cannot readily perceive while simultaneously generating decisions whose reasoning is difficult to understand.

The regulatory response must consequently remain grounded in the principle of human responsibility. The human being remains at the centre of the aviation system, not because human beings are infallible, but because aviation safety requires judgment, accountability and the capacity to intervene when automated systems encounter circumstances outside their assumptions. The objective should not be to construct a system in which humans are removed from responsibility, but one in which humans and machines are appropriately integrated.

There is also a broader public-interest dimension. The travelling public places an extraordinary degree of trust in the aviation system. A passenger boarding an aircraft has no realistic means of examining the separation standards applicable to the flight, the controller’s workload, the integrity of surveillance information or the functioning of the aircraft’s collision-avoidance system. That passenger relies upon a chain of professional and institutional responsibilities that extends from the pilot and airline to the air navigation service provider, regulator, manufacturer and ultimately the State.

It follows that the public interest requires transparency without compromising the integrity of safety investigations. The aviation community must communicate occurrences honestly, but it must also resist sensationalism. A near collision should neither be trivialised nor exaggerated. It should be understood as a warning signal. The absence of casualties does not mean that there was no safety significance; equally, the activation of TCAS does not by itself establish that a catastrophe was imminent. The facts, rather than the rhetoric surrounding them, must guide the regulatory response.

The Iberia–Air Europa occurrence is therefore best understood as a reminder of the continuing evolution of international aviation law. The Chicago Convention system was conceived in an era in which the principal challenges concerned aircraft navigation, communications, sovereignty and the orderly development of international air transport. Eight decades later, the same legal architecture must accommodate digital networks, automated decision-making, artificial intelligence, cyber threats and increasingly complex air traffic management systems.

The enduring strength of the Chicago Convention lies precisely in its capacity for such evolution. Its philosophy is based upon international cooperation, harmonisation and the recognition that aviation safety is a common interest transcending national boundaries. The Annexes provide the means through which that philosophy is continuously translated into contemporary Standards and Recommended Practices.

The final lesson of the 10 July 2026 event is therefore not that TCAS saved two aircraft. That is the immediate operational conclusion. The deeper regulatory conclusion is that the aviation safety system succeeded because several layers of defence remained available when one or more earlier layers did not prevent the conflict from developing. The obligation of the aviation community now is to learn from the event so that the last line of defence is not routinely required to compensate for weaknesses elsewhere in the system.

Aviation safety is ultimately a matter of confidence in an interconnected system. The passenger must be able to trust the pilot; the pilot must be able to trust the instruments; the controller must be able to trust the information available to the air traffic management system; the regulator must be able to trust the safety-management processes of the organizations it oversees; and the entire system must increasingly be able to trust the integrity of its digital environment.

The Iberia–Air Europa occurrence thus provides an unusually rich case study in the contemporary relationship between law and technology. It illustrates the continuing relevance of the Chicago Convention, the regulatory importance of Annexes 2, 10, 11, 13, 17 and 19, the complementary character of PANS-ATM, the indispensable role of TCAS, the emerging regulatory questions surrounding artificial intelligence and the necessity of treating cybersecurity as an integral component of aviation safety.

The most appropriate response is therefore neither alarm nor complacency. It is disciplined inquiry. The aviation system should ask what happened, why it happened, what barriers prevented a worse outcome, what barriers failed to perform as expected, and what changes are necessary to prevent recurrence. In that process lies the true meaning of safety regulation. The objective is not merely to ensure that aircraft do not collide. It is to create a system so resilient, transparent, accountable and continuously learning that when an unexpected threat emerges, there are sufficient layers of protection to ensure that human error, technological limitation or organizational imperfection does not become a tragedy.

In this sense, the near collision over the Atlantic is not simply an incident involving two aircraft. It is a manifestation of the modern aviation system itself: human, technological, international, interconnected and dependent upon a continuing process of regulatory vigilance. The warning issued by TCAS was heard, the pilots responded, the aircraft separated and the flights continued. The responsibility now belongs to the wider aviation community to hear the regulatory warning contained within the event and to convert it into safety knowledge.

My Take

The Iberia–Air Europa near miss is a salutary reminder that the safety of international air navigation cannot ultimately depend upon the successful intervention of the last line of defence. That TCAS intervened and the two aircraft responded appropriately is a testament to technological resilience; but it should not become a regulatory alibi. The more profound question for ICAO and national regulators is why the architecture of air traffic management permitted two large commercial aircraft to approach each other on the same airway and at the same flight level in the first place. The incident therefore belongs not merely to the domain of operational error, but to the larger jurisprudence of safety management, air navigation services and State responsibility.

The legal profession should resist the temptation to identify a single culpable actor before the safety system has been examined in its entirety. Air navigation is a socio-technical construct in which pilots, controllers, procedures, surveillance systems, communications, navigation infrastructure and regulatory oversight are interdependent. ICAO’s conception of safety management requires precisely this systemic approach: hazards must be identified and risks continuously managed rather than merely investigated after an occurrence. States, consequently, have a responsibility under the international regulatory framework to ensure that air navigation services meet the requisite standards of safety, regularity and efficiency, supported by effective safety management programmes.

My principal lesson is therefore that ICAO and State regulators should treat near misses as regulatory intelligence, not simply as fortunate escapes. Every loss of separation should prompt examination of surveillance coverage, controller workload, route design, flight-level allocation, communications, human factors, TCAS performance and the adequacy of existing Standards and Recommended Practices. The objective should not be to construct a culture of blame, but a culture in which the law learns from the proximity of catastrophe. The future of air navigation will increasingly depend upon integrated CNS/ATM, automation and artificial intelligence; yet the legal responsibility for their safe deployment will remain human and institutional. A near collision is consequently not an absence of an accident. It is an accident that has been given, by technology and human judgment, another opportunity to teach us.

Ruwantissa Abeyratne

Dr. Abeyratne teaches aerospace law at McGill University. Among the numerous books he has published are Air Navigation Law (2012) and Aviation Safety Law and Regulation (to be published in 2023). He is a former Senior Legal Counsel at the International Civil Aviation Organization.

Leave a Reply

Your email address will not be published.

Latest from Blog