/

Air India Flight Ai 171 – A New Theory Emerges

The crash of AI 171—if rooted in a miscommunication between a WOW sensor and FADEC logic—could signify more than a tragedy.

6 mins read
A 15-page report from India’s Aircraft Accident Investigation Bureau, part of the ongoing Boeing 787-8 Dreamliner crash probe, found that fuel control switches were set to “cut-off” during takeoff.

Artificial intelligence is the future, but we must ensure it is the future that we want. ~ Tim Cook

On the twelfth day of June 2025, Air India Flight AI 171, a Boeing 787-8 Dreamliner registered as VT-ANO, departed from Ahmedabad with 241 souls aboard, bound for London. Barely a minute into the flight, both engines experienced a sudden, catastrophic loss of thrust. Within seconds, the aircraft descended uncontrollably and impacted a densely populated college campus. The tragedy—which claimed all but one life aboard, and 19 lives on the ground—sent shockwaves through the aviation community. It also raised deeply troubling questions about automation, system logic, and the human-machine interface in modern civil aviation. Central to these emerging discussions is a new theory (only a theory ascribed to the crash at this point) suggesting a malfunction in the Weight-on-Wheels (WOW) system, which may have prevented Full Authority Digital Engine Control (FADEC) from transitioning into flight mode, thereby contributing to fuel starvation.

The following discussion examines this theory from a legal-technical perspective, aiming to assess not only its epistemic legitimacy but also its implications for civil liability, manufacturer responsibility, and international aviation law obligations under treaties such as the Chicago Convention of 1944 and the Montreal Convention of 1999.

The Anatomy of the WOW and FADEC Interface

Modern aircraft are driven as much by software logic as they are by aerodynamic principles. The Weight-on-Wheels (WOW) system consists of pressure-sensitive or mechanical squat switches located on the aircraft’s landing gear, whose primary function is to inform downstream systems whether the aircraft is on the ground or airborne. This signal, though seemingly binary, underpins a panoply of critical functions, including thrust reverser inhibition, braking logic, spoiler deployment, and stall warning configuration.

FADEC—a microprocessor-driven engine control system—is designed to automate thrust control by interpreting various sensor inputs, including the WOW signal, and regulating fuel flow, ignition, and engine power accordingly. While FADEC is lauded for improving engine efficiency and safety, its full authority nature—where the pilot cannot override certain commands—has also been a focal point of regulatory and jurisprudential scrutiny.

In the case of AI 171, emerging evidence and leaked FAA advisories seemingly suggest that an erroneous WOW signal may have resulted in FADEC logic concluding that the aircraft was still on the ground, despite being in the takeoff climb. This failure to transition from ground to flight mode may have triggered a “fuel cut-off” scenario or a refusal to sustain commanded thrust levels.

Epistemic Triggers and Teleological Failure

The crux of the theory lies in the epistemic logic of the aircraft’s system. FADEC, receiving a false WOW input indicating “on ground,” would proceed to inhibit certain airborne engine modes or override pilot throttle commands. Teleologically, this is a failure of the safety system to discern context, a critical distinction between information and understanding. The pilot, unaware of the miscommunication between subsystems, may have been thrust into a scenario where manual intervention was rendered futile.

The Montreal Convention of 1999, particularly Article 17, speaks to “accidents” arising from the operation of an aircraft. Here, the term “accident” has been judicially construed to mean an “unexpected or unusual event or happening that is external to the passenger.” In this instance, if FADEC denied flight thrust because of a WOW error, we are potentially looking at an “accident” within the meaning of Article 17.

Further, the concept of “defect” in civil aviation law, particularly under product liability, must be examined. In the United States, the Restatement (Third) of Torts defines a product defect not only in terms of manufacturing or design error but also in its inadequate instructions or warnings. If Boeing or General Electric (assuming GE engines) failed to provide clear redundancy protocols or override options for FADEC-WOW miscommunication, liability could be triggered under both product liability law and Article 21 of the Montreal Convention, which sets compensatory limits for damage under Article 17..

Juridical Implications of Systemic Autonomy

Autonomous systems in aircraft do not operate in vacuo; they are the product of engineering design, logic trees, and regulatory oversight. The FAA’s prior advisories in 2018 and 2022 regarding Boeing software anomalies tied to WOW signals point to foreseeability. Under a line of jurisprudence, foreseeability of harm is a cornerstone of carrier liability. If an operator or manufacturer could foresee that a WOW malfunction might lead to erroneous fuel cut-off via FADEC and failed to implement mitigation, a legal duty arises.

This situation also engages strict liability under Article 21 of the Montreal Convention, where the carrier is liable for damage arising under Article 17 unless it proves that it took all measures reasonably required to avoid the damage. Given the complexity of software logic and human-system interaction, the burden shifts onto the carrier and, by extension, the manufacturer or maintenance contractor, to demonstrate adherence to airworthiness directives and redundant system checks.

In such a scenario, even if the final AAIB report reveals no intentional crew input leading to the fuel cutoff, the automation system’s unilateral logic path—conditioned by a WOW malfunction—may be seen as the proximate cause of the crash.

Regulatory and State Responsibility Under International Law

The matter also implies state responsibility under the Chicago Convention, particularly Articles 33 (Recognition of Certificates) and 37 (Adoption of International Standards). If the State of Design (United States), through the FAA, failed to impose mandatory modifications to the FADEC-WOW interface despite known risks, and the State of Registry (India) accepted the aircraft’s continued operation under such conditions, both could be implicated in a failure to uphold due diligence obligations.

This assumes added importance in light of Annex 8 to the Chicago Convention, which sets forth airworthiness requirements. Paragraph 3.1.2 specifically requires that an aircraft continue to operate safely in foreseeable operational conditions. If a WOW sensor, known to be vulnerable to transient moisture or failure under certain landing gear loads, triggered catastrophic FADEC behavior, then the aircraft arguably did not meet this standard.

The ICAO Council, acting under Article 54(j),  which empowers ICAO’s Council to consider any matter related to the Convention when referred by a Contracting State, may thus be compelled to investigate whether systemic failures in software certification contributed to the accident, and whether international safety oversight mechanisms need recalibration in the era of algorithmic flight control. This provision, which is a mandatory function of the Council, serves as an inclusive mechanism for addressing State concerns without resorting to formal dispute resolution. This provision also reinforces the Council’s role as a deliberative body, ensuring cooperative oversight of international civil aviation. The Council

Revisiting Manufacturer and Operator Liability in the Age of Algorithmic Determinism

The AI 171 incident, if proven to have involved a WOW-induced FADEC malfunction, opens an entirely new chapter in aviation jurisprudence. It raises the question: can a manufacturer be held liable for logic-induced malfunction, even when the hardware operates within designed tolerances? The answer lies in design foreseeability and failure mode analysis.

In Sikkelee v. Precision Airmotive Corp (14-4193 (3d Cir. 2016), the U.S. Court of Appeals for the Third Circuit held that state tort claims involving aircraft design defects are not necessarily pre-empted by federal law. This reinforces the principle that the existence of an approved type certificate does not exonerate a manufacturer from civil liability. Thus, even if Boeing’s FADEC logic was FAA-certified, that does not immunize it from tort claims where software architecture fails in predictable yet unaccounted-for conditions.

Furthermore, the failure to warn operators of the interplay between FADEC and WOW systems in critical flight regimes may constitute negligence per se. This is particularly relevant if Boeing, GE, or the operators were aware of previous non-fatal incidents involving similar logic faults but did not issue mandatory Service Bulletins or simulator retraining.

Duty to Inform and the Montreal Convention

Beyond design and regulatory liability, the Montreal Convention also embeds a moral duty into its legal fabric: the duty to inform and the right of passengers to rely on the assumption of safety. In the case of AI 171, if the theory holds, passengers placed their trust not only in the mechanical and human competence aboard the aircraft but also in the unseen algorithms mediating the aircraft’s behavior. When those algorithms become the instrument of harm, the legal obligation to account becomes unavoidable.

Moreover, the Convention allows for aggregation of claims under Article 21(2), but does not restrict actions against third parties, such as manufacturers, under national law. This enables the possibility of multi-party litigation, encompassing Air India, Boeing, GE, and potentially state regulators, under both private and public international law frameworks.

My Take

If this emerging theory regarding WOW-induced FADEC malfunction is validated by final accident investigation reports, it may well necessitate a wholesale re-evaluation of existing legal doctrines concerning aircraft automation. The balance between human authority and system autonomy is at the crux of this inquiry. The law must keep pace with the evolving realities of civil aviation, where decisions that determine life or death are made not by pilots alone, but by lines of code reacting to sensor inputs.

As jurisprudence moves into this realm of “machine culpability,” existing instruments such as the Montreal Convention must be interpreted with an awareness of systems theory and engineering epistemology. The principle of res ipsa loquitur—that the thing speaks for itself—may no longer suffice when the “thing” is a silent algorithm making decisions faster than any human can comprehend.

In closing, the crash of AI 171—if rooted in a miscommunication between a WOW sensor and FADEC logic—could signify more than a tragedy. It could be the clarion call for a new paradigm of accountability, one that integrates the language of law with the logic of machines. The journey ahead must be one of informed adaptation, where international air law becomes conversant in the dialect of digital determinism, lest it be rendered obsolete in the skies it seeks to govern.

Ruwantissa Abeyratne

Dr. Abeyratne teaches aerospace law at McGill University. Among the numerous books he has published are Air Navigation Law (2012) and Aviation Safety Law and Regulation (to be published in 2023). He is a former Senior Legal Counsel at the International Civil Aviation Organization.

Latest from Blog