Home / Library / Human Factors

Flight Deck Automation

Human FactorsCPL · IR · ATPL8 min readUpdated Sep 2026
Definition

Flight deck automation is the set of systems, such as the autopilot, flight director, autothrottle and flight management system, that perform tasks the pilot would otherwise do by hand. Its human factors cover choosing the right level of automation, monitoring it, understanding its modes and keeping the skills to fly without it.

Flight deck automation is the set of systems that carry out tasks the pilot would otherwise do by hand: the autopilot and flight director, the autothrottle or autothrust, the flight management system (FMS), and the envelope protections of fly-by-wire aircraft. It flies more precisely than a person can, spreads the workload, and frees capacity for planning, monitoring and communication.

It also changes the pilot's job. Automation does not remove workload so much as change its nature, replacing active control with passive monitoring, which is the task humans perform worst. Much of what goes wrong on modern flight decks happens at this boundary: a mode the crew did not expect, a speed nobody was watching, a disconnection that hands a confusing situation back to a pilot who has not flown by hand for weeks. Automation is part of CRM training under EASA's ORO.FC rules, and automation management is one of the components of the FAA's single-pilot resource management.

On this page
  1. The role of automation
  2. Levels of automation
  3. Managing automation
  4. Automation complacency and dependency
  5. Mode confusion and automation surprise
  6. The out-of-the-loop problem
  7. Maintaining hand-flying skills
  8. Frequently asked questions

The role of automation

About 70 % of aviation accidents are attributed to human error, and that figure has driven the spread of automation, as the industry looks for ways to remove the human element where it is safe to do so. The benefits are real. An autopilot engaged early in a busy arrival releases mental capacity for briefing, checklists and threat assessment, and an autopilot holds a flight path more precisely than hand flying, especially in IMC.

Human performance texts list the disadvantages that come with it:

Levels of automation

Automation is not simply on or off. It is used at different levels:

Level Who flies Where the targets come from
Manual, raw data The pilot, without flight director The pilot's own scan of the instruments
Manual with flight director The pilot, following the command bars Modes selected by the crew or the FMS
Autopilot and autothrust, selected guidance The autopilot Values the crew dials on the glareshield panel
Autopilot and autothrust, managed guidance The autopilot The FMS flight plan and its constraints

On the Airbus flight control unit, pulling a knob engages selected guidance with the value in the window as the target, and pushing it engages or arms managed guidance from the flight plan. Boeing's mode control panel offers equivalent choices between modes such as heading select and LNAV.

No level is best in itself. Airbus puts the principle into its golden rules: the crew must use the appropriate level of automation at all times, which can include manual flight, and must understand the operational effect of the level selected. A decision to fly manually is agreed between both pilots and based on the aircraft's status, pilot fatigue, the weather, the traffic and familiarity with the area. When the aircraft does not follow the desired path, the pilot flying changes level, from managed to selected guidance or from selected guidance to manual flying, while the pilot monitoring communicates, challenges and takes over if necessary.

Managing automation

The flight mode annunciator (FMA) is the primary place where the aircraft shows which modes are actually engaged and armed for thrust, pitch and roll. A knob push or pull is a request; the FMA is the answer. Airbus's rule is to monitor, announce, confirm and understand the FMA at all times, and SOPs have every mode change called out and checked by both pilots against what was intended.

The A320 flight mode annunciator: engaged modes in green, armed modes in blue, a white box around each change for ten seconds, and the difference between managed and selected guidance. v1prep schematic.
The A320 flight mode annunciator: engaged modes in green, armed modes in blue, a white box around each change for ten seconds, and the difference between managed and selected guidance. v1prep schematic.Illustration © v1prep

Good automation management rests on a few habits:

Automation complacency and dependency

Automation complacency is over-reliance on automation. Its classic symptom is passive monitoring: leaving it to the computer, in the belief that the automation is more capable, until the pilot regards the aircraft as infallible. Sustained monitoring of a system that is usually right is a task humans do badly. Trust grows, the sampling of mode annunciations slows, and the pilot ends up discovering a problem from the flight path instead of from the annunciator.

Automation dependency is reliance on automation to the point where the pilot can no longer fly confidently without it. The FAA's SAFO 13002 notes that continuous use of autoflight can degrade a pilot's ability to recover quickly from an undesired aircraft state. The NTSB found that Asiana's automation policy emphasised full use of automation and did not encourage manual flying, and that more manual practice would likely have helped the pilot flying notice the decaying speed and add power.

Mode confusion and automation surprise

A mode error, or mode confusion, occurs when the pilot believes the automation is in one mode while it is actually in another. An automation surprise follows when the aircraft then does something the crew did not expect. Keeping the modes in the central scan is the defence.

Asiana Airlines flight 214 is the standard case. On 6 July 2013 a Boeing 777 was on a visual approach to San Francisco, high on the profile. The pilot flying selected flight level change mode while below the selected altitude, so the autopilot began to climb and the autothrottle advanced the thrust. He disconnected the autopilot and pulled the thrust levers to idle, and the autothrottle changed to HOLD, a mode in which it does not control speed. None of the three pilots later recalled seeing the change on the FMA. The NTSB found the autothrottle logic complex and not intuitive; interviews showed that other pilots at the airline, including some instructors, held similarly inaccurate mental models of it. It found the crew's monitoring of airspeed insufficient because of expectancy, workload, fatigue and reliance on automation. The aircraft struck the seawall; three passengers died (see stabilised approach).

On Turkish Airlines TK1951 at Amsterdam in 2009, a faulty left radio altimeter reading of -8 ft put the Boeing 737's autothrottle into its RETARD flare mode, closing the thrust levers on the approach. The autopilot kept following the glideslope by raising the nose as the speed decayed, and the crew did not notice the lack of thrust until the aircraft neared the stall; nine of the 135 occupants died (see radio altimeter). The lesson common to both: read the FMA after every change, and keep speed and thrust in the scan on every coupled approach.

The out-of-the-loop problem

A pilot who is only monitoring is out of the loop: no longer controlling the aircraft, less aware of its state, and often not mentally prepared to take over when the automation fails or disconnects. The handover then comes at the worst moment, with an abnormal situation and an alarm. Startle is the involuntary reflex to a sudden intense stimulus; surprise is the slower cognitive response to an event that violates expectation, and the mental effort of rebuilding a picture that has just been shown to be wrong. The first response to either should be to stabilise the flight path and buy time, not to act on the first explanation that comes to mind.

Air France flight 447 showed the cost. On 1 June 2009 an Airbus A330 cruising at FL350 lost consistent airspeed indications, most likely because ice crystals obstructed the pitot probes. The autopilot and autothrust disconnected and the flight controls reverted to alternate law. The pilot flying's nose-up inputs took the aircraft to about 38,000 ft and into a stall that the crew never identified, and all 228 people on board died. The BEA listed among the factors the absence of training at high altitude in manual handling and in the unreliable airspeed procedure, and task-sharing weakened by incomprehension of the situation and poor management of the startle effect (see unreliable airspeed).

Maintaining hand-flying skills

Manual flying skills decay when they are not used, and they are needed most when the automation has just failed, disconnected or been set up wrongly, often while the pilot is also surprised and troubleshooting. The FAA's SAFO 13002 and SAFO 17007 encourage operators to give pilots opportunities for manual flight when conditions permit, and a balanced practice of hand-flying departures and approaches keeps the skill available.

The timing matters. A clear day, light traffic, a familiar airfield and a rested crew make a good opportunity; a complex arrival with frequent ATC changes does not. After AF447 the BEA recommended regular training in manual handling of the approach to stall and stall recovery, including at high altitude, and in handling surprise. Regulators have since made upset prevention and recovery training mandatory for airline pilots.

Hand-flying also counters underload. On a long, quiet automated sector arousal falls, attention wanders and vigilance for rare events decays; periods of manual flying, alongside a disciplined scan and regular systems checks, bring arousal back towards the middle of the performance curve. For the single pilot flying IFR, the autopilot remains a workload tool rather than a substitute pilot: it should be engaged early in a busy phase while the pilot stays actively in the loop, and it never replaces instrument currency.

Exam tip: complacency shows as passive monitoring; mode error is believing the automation is in one mode when it is in another; the response to automation surprise is to reduce the level of automation and fly; and the appropriate level of automation can include manual flight.

Frequently asked questions

What does "use the appropriate level of automation" mean?

It means choosing, at every moment, the combination of autopilot, flight director, autothrust and flight management guidance that best suits the task, the workload and the situation, and understanding what that level will do. The appropriate level can be manual flight. Airbus makes it one of its four golden rules, and if the aircraft does not follow the desired path the pilot flying steps down, from managed to selected guidance or from selected guidance to manual flying.

What is automation complacency?

Automation complacency is over-reliance on automated systems. Its classic symptom is passive monitoring, leaving it up to the computer in the belief that the automation is more capable than the crew. Humans are poor at sustained monitoring of a system that is usually right, so mode changes and deviations are noticed late. The defences are active monitoring of the flight mode annunciator, verbalising every mode change, cross-checking raw data and keeping manual skills current.

What is automation surprise and how should a crew respond?

Automation surprise is the automation doing something the crew did not expect, usually because of a mode they did not select or understand, the moment summed up by asking what it is doing now. The recommended response is not to reprogram but to reduce the level of automation, disconnecting the autopilot or autothrottle if needed, fly the aircraft on the desired path, and re-engage the automation only once the mode logic is understood.

What went wrong with the automation on Asiana 214?

On a visual approach to San Francisco in 2013, the pilot flying selected flight level change mode below the selected altitude, so the autopilot began to climb. He disconnected the autopilot and pulled the thrust levers to idle, and the autothrottle went to HOLD, a mode in which it does not control airspeed. None of the three pilots later recalled seeing the change on the flight mode annunciator; the speed decayed, and the Boeing 777 struck the seawall.

Why do airline pilots still need hand-flying skills?

Automation can fail, disconnect, or be programmed wrongly, and the pilot must then fly the aircraft precisely by hand, often while surprised and troubleshooting. The FAA's SAFO 13002 notes that continuous use of autoflight can degrade the ability to recover quickly from an undesired state, and it and SAFO 17007 encourage operators to give pilots opportunities for manual flight when conditions permit. Investigators have cited limited manual handling practice in several accidents.

Test yourself on Flight Deck Automation

The v1prep banks cover this topic in Human Performance and Limitations (040), with a worked explanation for every answer. EASA ATPL, PPL, IR and CPL, the FAA written tests and A320/B737 type ratings.

Start practising →
16,000+ questions · EASA & FAA · Free to start

Sources and further reading

  1. NTSB AAR-14/01, Descent Below Visual Glidepath and Impact With Seawall, Asiana Airlines Flight 214, Boeing 777-200ER, San Francisco, 6 July 2013
  2. BEA, Final Report on the accident on 1st June 2009 to the Airbus A330-203 F-GZCP, Air France flight AF 447 Rio de Janeiro to Paris
  3. Dutch Safety Board, Turkish Airlines, crashed during approach, Boeing 737-800, Amsterdam Schiphol Airport
  4. FAA AC 120-71B, Standard Operating Procedures and Pilot Monitoring Duties
  5. EASA Easy Access Rules for Air Operations (ORO.FC.115 and AMC, CRM training)
  6. ICAO Doc 9683, Human Factors Training Manual

Library articles are written for study and exam preparation. They do not replace your aircraft's approved documentation, your operator's procedures or the regulations themselves.