Most editions of The Safety Layer begin with a chain of failures. This one begins with a system that worked exactly as designed — and a collision that happened anyway.
That gap, between a safeguard functioning and a safeguard preventing harm, is where this edition lives.
The purpose of accident investigation is prevention, not blame — a principle written into international aviation law and repeated at the top of nearly every official report.
That distinction matters here more than usual.
Scenario
A Runway, Two Aircraft, One Alert
A wide-body airliner was cleared to land on an active runway at a major international airport, at night. A smaller aircraft was on that same runway — stopped, not moving, not supposed to be there.
The smaller aircraft's crew believed they had clearance to enter. Air traffic control had cleared them only to a holding point short of the runway. One crew member correctly read back the hold-short instruction. The aircraft proceeded onto the runway anyway.
The airport's ground-monitoring system did its job. It detected the unauthorized entry and displayed a warning to the control position responsible for that runway.
No controller action followed.
Roughly forty seconds later, the landing aircraft touched down and collided with the stationary aircraft. Both were destroyed. Everyone aboard the landing aircraft survived, evacuating through smoke after the aircraft's public address system failed and cabin crew fell back on portable megaphones. Five of the six crew aboard the smaller aircraft did not survive.
Investigators are still working through why an alert that fired correctly produced no response at all.
Human Factors Lens
When the Alert Isn't the Barrier — the Response to It Is
It's tempting to treat an automated warning system as a barrier in itself. It isn't. The barrier is the trained, rehearsed human response to that warning. A system can be engineered flawlessly and still fail completely if nobody built — or practiced — the procedure for what happens the moment it activates.
That's the layer investigators are focused on now: not whether the alert worked, but whether anyone had ever been shown what to do when it did.
A second, quieter human factors thread runs alongside it. The entering aircraft's crew read back the correct instruction and then acted against it — beginning a checklist that, by procedure, belongs only after runway-entry clearance is granted. Investigators are examining whether fatigue, duty-time management, and limited recent experience on that aircraft type played a role. None of that has been confirmed. All of it remains open.
Cockpit discipline procedures that restrict non-essential conversation during critical phases of flight — standard practice at many operators — were not in place at the entering aircraft's base. Its absence doesn't explain the error. It removes one more layer that might have caught it before the runway did.
Safety Legacy
A Pattern the Investigators Named Themselves
Investigators drew their own parallel — to a separate accident more than two decades earlier, involving a different aircraft and a different alerting system, where a similar gap was identified: an alert triggered correctly, and no established procedure existed for how controllers should respond to it.
That earlier finding was supposed to close this gap industry-wide. The fact that a structurally similar gap appears again, in a different system, at a different airport, is the kind of pattern safety investigators exist to notice — not proof of a repeated cause, but a signal that "install the alert" and "solve the problem" are not the same sentence.
Practical Takeaways
What This Case Is Already Teaching, Before It's Finished
An alert is not a control. A warning that fires into a vacuum — no assigned response, no rehearsed action — is instrumentation, not a defense.
Read-back correctness isn't the same as read-back compliance. A crew member can say the right words and the aircraft can still do the wrong thing seconds later. Verification of understanding has to outlast the radio call.
Visibility assumptions deserve verification testing, not intuition. Investigators are running night trials with matched aircraft, matched lighting, and matched runway geometry — because "the crew should have seen it" is a hypothesis, not a finding, until it's tested.
Damage mitigation and cause are separate investigations. The fact that everyone aboard the landing aircraft survived, and the fact that the collision happened at all, are being treated — correctly — as two different engineering questions.
A Question for Your Organization
If your facility has an automated alert for a low-probability, high-consequence event, does every person who might see it fire know — from training, not assumption — exactly what to do in the next ten seconds?
Would a false alarm be treated as evidence the system is too sensitive, or as a free rehearsal you didn't have to pay for with an accident?
Is there a documented procedure for every alert in your environment, or does the alert's existence quietly substitute for one?
Suggested Reading
Japan Transport Safety Board, Second Interim Report (December 2025) — the primary source for this edition: https://jtsb.mlit.go.jp/eng-air_report/interim20251225-JA722A_JA13XJ.pdf
ICAO Annex 13 to the Convention on International Civil Aviation — the framework governing this and nearly every civil aviation investigation worldwide
No probable cause has been issued in this case. The items above marked as "under analysis" remain genuinely open, and this account will be revised if a final report changes them.
An alert that no one acts on teaches the same lesson as no alert at all — except it costs more to build, and it's harder to notice the gap until afterward.
The system worked. That's what makes this one worth reading closely.
If you're reading a forwarded copy of The Safety Layer, consider subscribing to receive a new edition every Sunday at 1000 UTC. Every issue explores one event, one systems lesson, and one idea that reaches beyond aviation.

