Airbus Fly-By-Wire, Flight Envelope Protection, and the Control Laws That Decide How Much the Computer Will Let You Do

Radio Hangar explores Airbus Fly-By-Wire, Flight Envelope Protection, and the Control Laws That Decide How Much the Computer Will Let You Do.

Aviation Technology Analyst

SUMMARY: How Airbus fly-by-wire and flight envelope protection use control laws to limit what pilots can command - and why the handoff matters.

Fly-by-wire replaces the mechanical cables between a pilot’s controls and the flight surfaces with sensors and computers, so the sidestick commands a result - a pitch rate or G-load - rather than a control surface position. In a normally functioning Airbus, those computers enforce flight envelope protection: hard limits that prevent the airplane from stalling, overspeeding, over-stressing the wings, or rolling past a safe bank angle. The catch is that this protection depends on trustworthy sensor data, and when that data fails, the computer hands the airplane - and its full ability to stall - back to a pilot who may no longer expect it.

What Is Fly-By-Wire and How Does It Work?

In the airplane most pilots learned in, like a Cessna 172, pulling back on the yoke physically pulls a steel cable. That cable runs over pulleys to the tail and moves the elevator directly. There is an unbroken mechanical chain from your hand to the control surface. If you pull hard enough to stall, it stalls - the airplane has no opinion.

Fly-by-wire cuts that cable. The sidestick connects only to a set of sensors. When you move it, you send a number to a bank of flight control computers. Those computers read what you asked for, read what the airplane is currently doing, and decide how to move the control surfaces to deliver it.

The key distinction: in a fly-by-wire Airbus, the sidestick doesn’t command a control surface position. It commands an outcome. Pull back a set amount and you’re asking for a specific G-load and pitch rate - not “elevator up fifteen degrees.” The computer calculates the deflection needed and adjusts it constantly as speed and load change.

Why Did Manufacturers Switch to Fly-By-Wire?

The obvious answer is weight. Cables, pulleys, pushrods, and hydraulic runs are heavy and span the entire airframe. Replacing them with wires and computers saves hundreds of pounds - and on an airliner flying tens of thousands of hours over a 30-year life, that weight is money on every leg.

But weight was never the real prize. The real prize was this: once a computer sits between the pilot and the flight controls, the computer can say no. That capability is flight envelope protection.

What Is Flight Envelope Protection?

Every airplane has an envelope - the range of speeds, load factors, and angles where it flies safely. Too slow and you stall. Too fast and you risk structural or control problems. Pull too hard and you overstress the airframe. Roll too far and you’re inverted and losing altitude. The edges of that envelope are where airplanes break and people get hurt.

In a traditional airplane, nothing stops you from flying off that edge. Your only protection is training, attention, and the cues the airframe gives you: the pre-stall buffet, rising control forces, the scream of an overspeed. Warnings, but no hard stops.

Starting with the A320 in the late 1980s, Airbus built the hard stops in. In a normally functioning Airbus, there are walls at the edges of the envelope, and the airplane will not let you push through them:

  • High angle-of-attack protection. Pull fully aft and the airplane flies right up to the edge of the stall, sits at maximum lift, and holds it. You physically cannot stall it with the stick in that mode. Full aft stick gives you the best climb the wing can produce, and then guards that line.
  • High-speed protection. Dive toward the never-exceed speed and the airplane gently pitches itself back up to resist the overspeed.
  • Load factor limit. In the clean configuration, the Airbus won’t let you pull more than 2.5 G or push below −1 G. Yank as hard as you want; you get exactly the structural limit and no more.
  • Bank angle protection. Roll toward the vertical and the airplane resists. Release the stick and it rolls itself back toward a normal attitude.

Put together, this is an airplane that is extraordinarily hard to break in its normal state. A startled pilot who hauls back in a panic gets maximum performance instead of a stall and spin. Since a large share of fatal accidents come down to someone, for a few seconds, asking the airplane to do something it couldn’t survive, envelope protection is the engineer’s answer: let the human ask, let the computer refuse.

What Are Airbus Control Laws: Normal, Alternate, and Direct?

All of that protection only exists when the computers have good data and are working normally. Airbus calls that state Normal Law - every sensor trusted, every system talking.

The computers depend on air data: airspeed from the pitot tubes, angle of attack from vanes on the nose, altitude from static ports. If that data goes bad - sensors disagree, freeze, or lie - the computers can’t safely protect an envelope they can no longer measure. Protection built on a bad airspeed reading isn’t protection; it’s a hazard.

So Airbus built in a fallback. When the computers lose trust in their data or lose enough redundancy, they downgrade into Alternate Law. Most protections go away. The airplane still flies and responds, but stall protection is reduced or gone, the hard walls come down, and the airplane now behaves in a way that feels almost the same but isn’t.

Below that is Direct Law, where the sidestick more or less directly commands the control surfaces like a conventional airplane, with no protections at all. That’s the bottom of the ladder, usually seen near landing or after significant failures.

The Danger: What Happens When the Protections Disappear?

Here is the central criticism of the whole philosophy. A pilot who has spent thousands of hours in an airplane that cannot stall may, on some level, stop believing it can stall. Then one night the data goes bad, the airplane quietly hands the protections back, and the human is holding an airplane that will absolutely stall - that is in fact stalling - while part of the brain still trusts a wall that is no longer there.

This points directly at one accident: a widebody Airbus lost over the Atlantic at night in 2009. In cruise, it flew into a zone of ice crystals that blocked the pitot tubes, and the airspeed readings became unreliable. The computers did exactly what they were designed to do - they dropped out of Normal Law, handed the protections back, and told the crew. In the confusion that followed, a pilot held the nose up into a full aerodynamic stall and held it there for over three minutes, all the way down to the ocean. The airplane was mechanically fine the entire time. The stall protection that would have stopped that input in Normal Law was gone because the data feeding it was gone.

That accident rewrote how airlines train, forcing a hard look at manual flying skills, at how crews recognize which law they’re in, and at what happens to a human when years of automation suddenly steps back. The lesson wasn’t that fly-by-wire is bad. The lesson was that the handoff is the dangerous part. The airplane is safest when the computer is fully in charge, and safest when the human is fully in charge. The trouble lives in the seam between the two.

How Does Boeing’s Approach Differ From Airbus?

Boeing went fly-by-wire too, starting with the 777 in the 1990s, but made a deliberately different choice about the walls. A Boeing fly-by-wire airplane has envelope protection as well, but it’s built as soft protection. As you approach the stall, the controls get heavy and the airplane resists and fights you. But if the pilot in command decides this is the moment to pull past that limit, the airplane will let them. Final authority stays with the human.

Airbus draws the line and says the computer holds it. Boeing draws the line and says the human can cross it if they truly mean to.

Neither is obviously right. The Airbus philosophy saves the pilot who panics and yanks. The Boeing philosophy saves the pilot who needs, in some once-in-a-career emergency, to do something the designers never imagined. Both have saved airplanes; both have been second-guessed after accidents. It’s one of the genuine debates in aircraft engineering, and it has no tidy answer.

Is Envelope Protection Coming to Smaller Aircraft?

It already has. Fly-by-wire has marched steadily down into smaller airplanes. Business jets have had it for years - Embraer jets, Gulfstreams, Dassault’s Falcons, and the newer Cessna Citations all fly with flight computers and their own flavors of envelope protection.

It’s also reaching general aviation in a softer form. You don’t need full fly-by-wire to get some of the benefit. Modern autopilots from Garmin and others include what’s usually called envelope protection or electronic stability protection. In a conventional airplane with steel cables still connecting the yoke to the surfaces, the autopilot servos watch what you’re doing - bank too steeply, get too slow, or pitch too far, and the servos nudge you back toward safe flight, even with the autopilot switched off. It’s not the hard wall of an Airbus; it’s a firm hand on your shoulder, scaled down to airplanes a private owner can afford.

Looking further out, this only accelerates. Every electric airplane, eVTOL, and autonomous flight system being built now is fly-by-wire from the first line of code - there is no cable option. A machine with a dozen electric motors and no traditional controls is envelope protection all the way down; it literally cannot be flown any other way. The questions Airbus first wrestled with in the 1980s - how much authority the computer gets, what happens when the data goes bad, how the human knows which mode they’re in - are the design meetings happening at advanced air mobility startups today.

What This Means for Pilots

Envelope protection is one of the great safety ideas in aviation, and it has quietly prevented an enormous number of accidents that never made the news - because the accident that doesn’t happen never gets a report.

But it changes the job rather than removing the pilot. In an airplane with protections, your task is no longer just to fly the wing. It’s to know, at every moment, what the airplane will and won’t do for you right now - in this mode, with the data it currently trusts. The wall is a gift, right up until the wall isn’t there, and the whole game is knowing which of those two worlds you’re in.

Key Takeaways

  • Fly-by-wire replaces mechanical cables with sensors and computers; the Airbus sidestick commands an outcome (G-load, pitch rate), not a control surface position.
  • In Normal Law, an Airbus enforces hard limits - no stall, no overspeed, a 2.5 G / −1 G load ceiling in clean configuration, and bank angle protection.
  • Protection depends on good air data. When sensors fail, the airplane downgrades to Alternate Law or Direct Law, where most protections disappear.
  • The fatal 2009 Atlantic accident showed the core risk: blocked pitot tubes dropped the airplane out of Normal Law, and a pilot stalled it for over three minutes with the protections gone.
  • Boeing’s 777-era approach uses soft protection that resists but ultimately lets the pilot override, framing aviation’s enduring debate over how much authority the computer should hold.

Radio Hangar. Aviation talk, built by pilots. Listen live | More articles