Mode Confusion, Air France Four Forty-Seven, and the Human Factors Problem That Modern Automation Has Not Solved

Mode confusion - the dangerous gap between what automation is doing and what pilots believe it's doing - remains an unsolved root cause in major aviation accidents.

Aviation Technology Analyst

Mode confusion - the dangerous gap between what an aircraft’s automation is doing and what the pilots believe it’s doing - has been a documented human factors problem in aviation for more than three decades. Despite extensive research, revised training programs, and incremental design improvements from major manufacturers, it continues to appear as a causal or contributing factor in accident reports. The engineering task of matching autoflight system complexity to human cognitive limits remains unfinished.

What Happened on Air France Flight 447

On June 1, 2009, Air France Flight 447 was cruising over the South Atlantic at high altitude, approximately three and a half hours out of Rio de Janeiro. The crew was experienced. The Airbus A330 they were flying is one of the most capable commercial jets ever built, loaded with redundant systems and flight envelope protections representing decades of engineering.

Then the pitot tubes iced over.

In the following 212 seconds, the automation did exactly what it was designed to do. It detected inconsistent airspeed data, transitioned to a degraded protection mode, disconnected the autopilot, and adjusted the autothrust. Every system action was logical, traceable, and by the book.

The airplane hit the ocean. 228 people were killed.

The Bureau d’Enquêtes et d’Analyses (BEA) final report - more than 200 pages - traced the causal chain. The transition from Normal Law (full envelope protection) into Alternate Law (significantly reduced protections) was not fully recognized by the crew. Flight control characteristics changed in ways that weren’t correctly processed in the moment. Multiple simultaneous alerts, turbulence, darkness, the absence of the captain, and the rapid unloading of the autoflight system created conditions where the crew’s mental model of what the aircraft was doing diverged from reality.

The aircraft pitched up. Angle of attack climbed. The stall warning activated, loud and repetitive. The nose continued to rise above 20 degrees angle of attack - and then the stall warning stopped. Not because the stall resolved. At extreme angles of attack, the sensors are considered unreliable and the warning ceases. The silence was not a recovery signal. The crew held back pressure when they needed to push forward.

How Automation Complexity Created the Problem

Early autopilots operated with a limited, transparent mode set: wing leveler, altitude hold, heading mode. The mental model required to operate a 1950s autopilot fit comfortably inside working memory. If something unexpected happened, the list of possible causes was short.

The flight management system (FMS), introduced in the late 1970s, changed everything. Manufacturers began integrating navigation computers directly into the autoflight architecture, enabling aircraft to fly entire routes - departure through approach - following a programmed three-dimensional path. The benefits were immediate and real: improved fuel efficiency, dramatically better precision, reduced cruise workload on long-haul flights.

But complexity exploded. Modern autoflight systems operate with dozens of modes: LNAV, VNAV, Altitude Capture, Altitude Hold, Vertical Speed, Flight Level Change, speed modes, path modes, and sub-modes within each. Every mode carries different authority over the aircraft. Every mode has specific conditions under which it engages, disengages, and automatically hands off to another mode. Some of those handoffs happen without any direct crew input.

The Flight Mode Annunciator (FMA) is the crew’s window into that complexity. On the Airbus, it sits at the top of the Primary Flight Display in small text. On the Boeing, similar real estate, similar design concept. The premise was straightforward: if pilots can always see what mode the system is currently in, they’ll always know what the aircraft is doing. The research eventually showed that premise was incomplete.

What Researchers Found About Out-of-the-Loop Syndrome

In the late 1980s and through the 1990s, researchers at NASA Ames Research Center began investigating what they initially called the automation complacency problem. The deeper they dug, the more they found complacency wasn’t the right word.

When automation is handling the aircraft, pilots naturally shift into a monitoring role. Active flying decreases. Cognitive resources move toward other tasks - evaluating weather, running fuel calculations, communicating, coordinating. This is rational behavior; the automation is doing its job.

The problem is what researchers named out-of-the-loop syndrome. The longer a pilot spends passively watching a system rather than actively operating it, the more their situational awareness of that system’s current state degrades. The mental model of what mode is active, what the aircraft will do next, and how the system will respond if conditions change gradually goes stale.

Then something unexpected happens. The automation transitions to a different mode. The FMA updates. The pilot missed it. Their mental model is now wrong.

Human factors researchers call what follows plan continuation error: acting based on a stale mental model, and interpreting instrument readings in the direction of expectation rather than correctly reading them as evidence that something has changed.

NASA simulator studies in the 1990s - led notably by researchers Everett Palmer and Asaf Degani - put experienced airline captains with decades of type experience into scenarios testing their understanding of their own autoflight systems. A significant number demonstrated incorrect or incomplete mental models of what their automation was doing under test conditions. The industry treated the finding largely as a training problem. It wasn’t only a training problem.

How Mode Confusion Contributed to Asiana Flight 214

Asiana Airlines Flight 214 in 2013 is a different accident with a similar thread.

A Boeing 777 was on a visual approach to San Francisco International Airport. The crew intended to fly a stabilized approach with the autothrottle maintaining target airspeed. They selected Autothrottle Speed mode. Through a sequence of mode interactions during approach setup, the autothrottle transitioned into a different mode - one that does not protect airspeed the same way. The transition was annunciated on the FMA. The crew did not register it. They believed the system was actively protecting their speed. It was not.

Airspeed bled off over the final miles. The aircraft crossed the threshold 17 knots below target and struck the seawall short of Runway 28 Left. Three passengers died.

The National Transportation Safety Board (NTSB) investigation explicitly identified mode confusion as a causal factor. The crew’s understanding of the autothrottle mode was incorrect at a critical moment.

Two accidents. Two manufacturers. Two different aircraft types, different airports, different flight phases. The same core failure.

What Manufacturers Have Done in Response

Airbus has revised the FMA standard multiple times since the original fly-by-wire fleet was certified. Mode transitions are more visually prominent. Certain critical transitions now include aural callouts in addition to visual annunciation. On modern Airbus variants, the autopilot disconnect generates a synthetic voice announcement - “autopilot off” - an addition made specifically in response to incidents where crews failed to register the visual-only indication under high workload.

Following Asiana, Boeing issued revised operational guidance for 777 autothrottle modes. Flight Crew Operations Manuals were updated to more explicitly describe autothrottle behavior during visual approaches. Training programs expanded their coverage of low-altitude mode management.

These are real responses. They are also primarily documentation and training responses to what is fundamentally a design problem.

Garmin approached the problem differently when engineering their modern integrated platforms. The G3000 and G5000 systems, found in aircraft like the HondaJet and the Piper M600, were built around a design philosophy that minimizes the number of simultaneously active modes a pilot needs to track and makes current mode state obvious from the primary display without requiring reference to a separate secondary annunciator.

The GFC 500 autopilot, certified for retrofit in aircraft including the Cessna 172 and Piper Archer, was developed with explicit attention to mode awareness: one clear annunciator line, plain language descriptions, and prominent visual transition alerts. Garmin’s published installation data cites meaningful reductions in loss-of-control accidents in equipped aircraft. That represents real engineering progress at the general aviation level.

Why General Aviation Is Not Immune

Mode confusion is not exclusive to airliners. The Garmin G1000 glass cockpit transformed light GA when it arrived in the early 2000s - a massive leap forward from six-pack steam gauges. It also introduced a new category of pilot errors that hadn’t existed before. Pilots programmed wrong waypoints and followed them with precision. Pilots activated approaches in the wrong sequence and were confused when guidance didn’t behave as expected. Pilots engaged VNAV without understanding why the aircraft was descending when they expected level flight.

The training community has spent two decades catching up to the avionics. The Airmen Certification Standards now require demonstrated understanding of automated flight systems. The FAA has published advisory circulars specifically on automation dependence. Most flight schools teach glass cockpit transition as a defined curriculum area.

But a structural problem persists: automation advances faster than training follows. When a new system gets certified, it enters service before training programs have fully matured. The G1000 is being superseded by touchscreen G3000 systems with different interfaces. The gap doesn’t close - it just moves forward in time.

What the Next Generation of Solutions Looks Like

At the commercial level, the mode space isn’t going to shrink. The FMS is deeply embedded in airline operations, air traffic control procedures, and aircraft certification. VNAV Path mode and VNAV Speed mode exist and behave differently because the aircraft genuinely needs to behave differently in those two situations. Simplifying away complexity costs capability.

What can change is how transitions are communicated. The current paradigm is reactive: the FMA tells pilots what mode they’re in now. Several human factors research programs are pursuing what they call predictive annunciation - giving crews advance notice that a mode transition is approaching rather than simply logging that it happened. A callout indicating that altitude capture will activate in the next 20 seconds, and describing the aircraft behaviors to expect, is a fundamentally different approach.

There is also active research into flight intent monitoring - the concept that automation should infer what the pilot intended when configuring a particular mode setup and flag divergence between what the system is actually doing and that inferred intent. Collins Aerospace and Honeywell both have active human factors integration programs working in this direction. The theoretical framework is developing. Translation into certified avionics takes years.

Why This Matters for Every Pilot Flying Automation

Mode confusion is not a training failure that pilots are collectively failing to solve. It is a design mismatch between the complexity of modern autoflight systems and the cognitive architecture of the human beings who operate them.

Both sides of that mismatch are real. The systems are complex because operational requirements are genuinely complex. Human attention and working memory have real, well-documented limits under high workload. The engineering task - and it is primarily an engineering task - is to build systems that account for those limits rather than assuming perfect vigilance.

The accident record says the problem isn’t fully solved. The research record says it’s better understood than ever. Holding both of those facts simultaneously is the right mental posture for any pilot sitting down in front of an FMA and programming a route.


Key Takeaways

  • Mode confusion - the gap between what automation is doing and what pilots believe it’s doing - is a documented causal factor in both Air France 447 (2009) and Asiana 214 (2013), among other accidents
  • Out-of-the-loop syndrome degrades pilot situational awareness during passive monitoring, making it harder to correctly interpret a sudden mode transition under high workload
  • Manufacturer responses have focused primarily on improved visual/aural annunciation and updated training - real progress, but largely a documentation response to a design-layer problem
  • General aviation pilots face the same risk; the arrival of glass cockpits introduced mode-confusion accident types that hadn’t existed in the steam-gauge era
  • The most promising research directions - predictive annunciation and flight intent monitoring - aim to shift the system’s role from passive logger to active participant in crew mode awareness

Radio Hangar. Aviation talk, built by pilots. Listen live | More articles