Aviation is extraordinarily safe, but that safety is not accidental. It is the result of decades of investment in technology, procedures, training, staffing and redundancy, as well as lessons learned, unfortunately sometimes only after people have been killed.
That creates an uncomfortable question:
Why does aviation sometimes wait for an accident before investing in a safety measure whose value was already understood?
A recent accident at New York LaGuardia Airport provides one example.
On 22 March 2026, an Air Canada Express CRJ900 collided with an airport fire truck while landing on Runway 4. Both pilots were killed and 39 people were taken to hospital, six with serious injuries.
The US National Transportation Safety Board (NTSB) investigation is still ongoing. No final cause has been established, and the accident should not be reduced to one failure, one missing piece of equipment or one individual decision.
But one detail is worth examining.
A Safety Barrier That Wasn’t There
The fire truck involved in the LaGuardia collision was not equipped with a transponder.
LaGuardia has sophisticated surface surveillance, and non-cooperative vehicles can still be detected by surface radar. The vehicle was therefore not simply “invisible”. But there is an important difference between detecting a primary radar return and continuously tracking an individually identified cooperative vehicle.
During the accident sequence, vehicles travelling close together were reportedly merging and unmerging on the surveillance display, making reliable individual tracking difficult. The system did not generate an automatic conflict alert.
A transponder would not, by itself, have prevented the accident. A cooperative track could have provided the surveillance system with better information and potentially enabled an alert, but whether that would have provided sufficient time to prevent the collision is a different question.
That distinction is important. Safety barriers do not need to guarantee that an accident will be prevented in order to be valuable. Their purpose is to add another opportunity to detect an error, identify a conflict or break an accident chain.
Vehicle transponders are one such barrier. Compared with the cost of airport infrastructure or an airport fire truck itself, they are relatively inexpensive.
So the broader question is not whether one transponder would definitely have prevented one accident. It is this:
If an additional safety barrier is available, technically mature and proportionate to the risk, why does it sometimes take an accident before the investment becomes urgent?
Luxembourg Learned a Similar Lesson
Luxembourg has its own history with this type of risk.
Today, Luxembourg Airport operates an Advanced Surface Movement Guidance and Control System (A-SMGCS), providing controllers with surveillance and identification of aircraft and appropriately equipped vehicles on the manoeuvring area.
That safety barrier was not available in 2010.
On 21 January 2010, Cargolux flight CLX793, a Boeing 747-400F, was approaching Runway 24 at Luxembourg Airport in very low visibility. The aircraft was conducting a CAT IIIb autoland approach with an RVR of approximately 350 metres.
A maintenance van was still on the runway when the Boeing 747 was cleared to land.
Shortly before touchdown, the pilot flying briefly saw what he believed to be a vehicle in the touchdown zone. By then, however, there was essentially no time left to react. The aircraft’s right body landing gear struck the roof of the van.
The aircraft continued its landing, vacated the runway and taxied to the apron. At that stage, the flight crew was apparently not aware that the aircraft had actually collided with the vehicle.
Despite the potentially catastrophic circumstances, nobody was killed or seriously injured.
The official Luxembourg investigation identified several failed or absent safety barriers. One was particularly significant: Luxembourg Airport had no Surface Movement Radar / A-SMGCS.
The investigation recommended improving the surveillance and control of ground traffic through the introduction of an A-SMGCS Level 2 system.
What makes this particularly relevant to the discussion about safety investment is that the technology was not unknown. The official report records that ANA had already launched a tender procedure for A-SMGCS Level 2 in 2010. The contract was ultimately not awarded for procedural reasons and implementation was put on hold.
The system was therefore not operational when the Boeing 747 struck the van. Today, Luxembourg Airport has A-SMGCS.
The lesson is not that somebody deliberately ignored a known danger. Safety investment is rarely that simple. The lesson is that the value of a safety barrier can look very different before and after an accident.
Safety Is Also About People
Technology is only part of the equation.
A safe system requires both appropriate equipment and enough qualified people to operate it safely.
For air traffic control, that means having sufficient controllers not simply to fill positions, but to allow the operation to function safely during traffic peaks, abnormal situations, emergencies, training, sickness and necessary breaks.
Air traffic control requires sustained concentration and situational awareness. Controllers continuously build and update a mental picture of traffic while communicating with pilots and other controllers, monitoring aircraft and vehicles, anticipating conflicts and reacting to unexpected events.
Most situations are routine. The safety challenge is recognising the one that suddenly isn’t.
That is why adequate staffing, sensible rostering, working-time limitations and proper breaks are not simply employment conditions.
They are safety barriers.
Fatigue Is Not Just an Employee Issue
Aviation has known about the effects of fatigue for decades.
A particularly relevant ATC example occurred on 27 August 2006, when Comair Flight 5191 attempted to take off from the wrong runway at Lexington, Kentucky. The aircraft crashed, killing 49 of the 50 people on board.
Only one controller was working in the tower, although FAA guidance called for two controllers during the midnight shift. The controller reported obtaining only around two hours of sleep in the preceding 24 hours.
Importantly, the NTSB did not conclude that the absence of a second controller caused the accident or that another controller would necessarily have prevented it. The investigation did, however, raise significant concerns about controller fatigue and scheduling.
Eighteen years later, in 2024, the FAA announced that controllers would receive at least 10 hours off between shifts and 12 hours before a midnight shift.
NTSB Chair Jennifer Homendy said:
“The safety of our skies depends on air traffic controllers who are well-trained and well-rested.”
She also made a particularly relevant observation about how long the issue had been known:
“We have been calling for action on controller fatigue for more than 18 years.”
That is precisely the issue. The risk was known and the safety argument existed, but meaningful change took years.
Europe Already Recognises Fatigue as a Safety Risk
In Europe, fatigue management is not simply a question of working conditions. Under Regulation (EU) 2017/373, ATC service providers are required to manage controller fatigue and implement rostering systems addressing issues including duty periods, breaks, minimum rest and night work.
EASA’s rules for ATM/ANS providers therefore treat fatigue management as an organisational safety responsibility. ICAO’s Fatigue Management guidance follows the same principle: fatigue can degrade human performance and must be actively managed as a safety risk.
We discuss this aspect of ATC in more detail here:
Human Factors in Air Traffic Control: Fatigue, Mental Health & Safety
The principle is straightforward: controllers are one of aviation’s final safety barriers.
If proper breaks require additional controllers, those controllers are part of the cost of providing a safe air navigation service. If better surveillance requires new technology, that technology is part of the cost of safety. And if a system requires redundancy so that one technical failure does not remove a critical capability, that redundancy is part of the cost of safety.
The Problem With Safety Investment
There is a fundamental difficulty when deciding how much to invest in aviation safety:
The better the safety system works, the less visible its value becomes.
A controller may catch an error before it develops into an incident. A warning system may generate an alert, or a second technical system may take over when the first one fails. Adequate staffing can allow a controller to take a proper break and return rested. A transponder can allow a vehicle to be positively identified, while a runway incursion alert may cause somebody to react several seconds earlier.
When these safety barriers work, nothing happens. There is no accident, no headline and no investigation.
And precisely because nothing happens, it can become difficult to demonstrate what the investment actually prevented.
That creates a difficult economic paradox: a safety measure that successfully prevents accidents can eventually begin to look unnecessary precisely because the accidents are not happening.
When budgets become tighter, a replacement may be postponed, additional staffing may begin to look expensive, redundancy can appear excessive and a technical upgrade may be delayed for another year. Most of the time, the system continues to work.
Until one day it doesn’t.
New Technology Is Not Automatically Safer Technology
This argument should not be misunderstood as saying that every new system should be purchased or that more staff automatically means more safety. Safety measures must be proportionate to the risk and supported by proper safety assessment.
New technology is not automatically safer technology.
A virtual or remote tower, for example, may offer operational or financial advantages. But it should only be considered a safety improvement if that can be demonstrated for the specific operational environment in which it will be used.
The same principle applies to automation, surveillance systems, artificial intelligence and other new technologies. Technology should solve an identified operational or safety problem, not be introduced simply because it is newer or cheaper.
The opposite is equally important. A proven safety system should not be rejected simply because the risk it mitigates is rare or because its benefit is difficult to express on a balance sheet.
One Mistake Should Not Become an Accident
Modern aviation safety is built on layers: procedures, training, staffing, rest, communication, surveillance, transponders, runway lighting, conflict alerts, redundancy and human situational awareness.
Those layers exist because neither people nor technical systems are perfect. A controller can make a mistake, a pilot can make a mistake, a vehicle driver can misunderstand a clearance, a technician can make an error, equipment can fail, and a procedure can prove inadequate in a situation nobody anticipated.
The objective is not to create an aviation system in which nobody ever makes a mistake. Such a system does not exist.
The objective is to build enough independent barriers around those mistakes that one mistake does not become an accident.
That is the essence of a mature safety system.
Safety Costs Money Before an Accident
This brings us back to the uncomfortable part.
Before an accident, another controller costs money. A new surveillance system costs money. Better fatigue management may require additional staffing. Vehicle transponders, technical redundancy, training, replacement of ageing equipment and maintaining systems that may rarely be needed all cost money.
The benefits, meanwhile, are often invisible.
Then an accident happens, and suddenly the calculation changes. Equipment that previously looked expensive can appear inexpensive by comparison. Additional staffing that seemed unnecessary may become obviously valuable, while redundancy that once looked excessive can suddenly seem essential. An upgrade that could wait another year may become urgent.
Luxembourg experienced this with surface surveillance, and aviation history contains many similar examples.
This does not mean that every accident could have been prevented simply by spending more money. It means that safety investment should be judged by the risk it reduces, not by how recently that risk produced an accident.
The Question We Should Ask Before the Next Accident
Luxembourg today has safety barriers that did not exist when the Cargolux Boeing 747 struck a maintenance van in 2010. That is progress.
But the most useful lesson from 2010 is not simply that we installed A-SMGCS afterwards. It is to ask what the equivalent question is today.
Are there areas where we already know that an additional safety barrier would reduce risk? Does a staffing solution exist but appear too expensive? Is ageing equipment still considered acceptable because it has not yet failed at the wrong moment? Could additional redundancy prevent one failure from becoming a serious incident? Are operational staff repeatedly identifying a weakness that is easy to tolerate because nothing serious has happened yet?
Those questions do not automatically justify spending money. But they justify being taken seriously.
Because waiting for an accident provides very convincing evidence that an investment was necessary.
It is also the worst possible way to obtain that evidence.
Safety equipment costs money. Adequate staffing costs money. Fatigue management costs money. Training costs money. Redundancy costs money.
Accidents cost considerably more.
The objective of aviation safety should not simply be to learn from accidents.
It should be to recognise the next missing safety barrier before an accident demonstrates why we needed it.
Sources and Further Reading
- NTSB — Air Canada Express Flight 8646 collision at LaGuardia
- Luxembourg AET — Cargolux Boeing 747 / maintenance van accident report
- NTSB — Comair Flight 5191 accident report
- NTSB — Air Traffic Controller Fatigue and FAA Rest Requirements
- EASA — Easy Access Rules for ATM/ANS
- ICAO — Fatigue Management
- ATC.lu — Human Factors in Air Traffic Control: Fatigue, Mental Health & Safety

