Let me describe something to you and you tell me whether you would sign up:
I want you to climb into a metal tube. The tube weighs about as much as a small office building. It travels at roughly 500 miles an hour, seven miles above the ground, in air too thin to keep you conscious and freezing cold. You will be seated for this. There will be a beverage service. Someone two rows back will recline into your knees.
And it is the safest way human beings have ever figured out how to travel. Roughly 1,200 times safer per passenger mile than the car you took to the airport. đł
And, ICYMI⊠đ (Trigger warning: donât read if you are afraid of flying)
Things Go Wrong on Pretty Much Every Flight
There is a program called Line Operations Safety Audits where trained observers ride in the jump seat on ordinary scheduled flights. Not accident flights. Not incidents. Regular, weekday, get-me-to-Cleveland flights.
Here is what normal looks like in the cockpit:
An average of 4.2 threats per flight, meaning stuff the crew didnât cause and has to handle anyway. Errors on about 80% of flights. An average of roughly three errors per flight. About 35% of flights drifting into an undesired aircraft state at some point. Between 85 and 95% of those threats managed successfully. And about a quarter of the errors were handled badly.
Read that again. Three errors. Every flight. Yours included. The one you took last month with the good pretzels.
MeanwhileâŠ38.7 million flights in 2025 with a five-year rate of roughly one fatal accident per 5.6 million flights.
So the safest thing we have ever built is riddled with mistakes. And it is still the safest thing we have ever built. How?
A System of Fine Tuned Safety
Over decades, we built the machinery that keeps a high-stakes operation, in the sky, at 500 miles an hour, to about three errors a flight and then catches nine out of ten of the threats swirling around them.
Hate to say it, but building that safety machinery wasnât cheap. It took about a hundred years and a series of fatal blunders.
Like the price of being nice (yes, nice can have a costâŠ). United 173 was circling Portland in December 1978, waiting to land. The captain starts fiddling with a landing gear light. The first officer notices the fuel getting low. The flight engineer says out loud (but maybe a little too nicely) that fifteen minutes is going to run the fuel really low. Neither one pushes. The captain keeps worrying about the landing gear. The airplane runs its tanks dry and comes down six miles from the runway. Ten people die. đ±
If you read the NTSB report, youâll see the contributing factor was the crewâs failure to successfully communicate their concern to the captain. The first officer had raised it, in their words, in subtle comments rather than in a positive or direct tone. They were being too nice.
The fix they recommended was training. Specifically, in what they called âparticipative management for captainsâ and âassertiveness training for other cockpit crewmembers.â
A federal accident report. Prescribing assertiveness training. Because ten people died of politeness.
Maybe they coulda just called it âHow to NOT be polite in an emergency.â But, on the other hand, having grown up with a healthy dose of âMinnesota Nice, I kind of get it. â
NASA ran a workshop the next year. United built the first program in 1981 and the pilots called it charm school. It now lives in the Code of Federal Regulations, and no US carrier can put you in a flight crew seat without it.
What This Means in the Age of AI
Last Thursday I was on office hours with the cohort and told the Otis elevator story, recently detailed by Jason Averbook. Elisha Otis, 1850s, standing on a platform in front of a crowd while a guy chops the hoist rope with an axe, just to prove the safety brake works. He kept doing it because nobody would get in the box otherwise.
One of the attendees at office hours took that somewhere that surprised me. She said her brain went straight to the andon cord, and asked âwhen the andon cord went in, how did you get people to trust pulling it instead of fearing theyâd be fired for pulling it?â
Otis elevators needed trust. The Andon cord needed trust. Aviation needed trust. AI also needs trust.
Each of those handled trust differently. Otis put his life on the line to build trust around the safety brake. The Andon cord celebrated those who pulled it. Aviation gave their confidential safety reporting system to a trusted agency (NASA) to be an honest broker for information to the FAA.
In the age of AI, I want to ask: who runs the trust channel at your company? What does it cost someone to report an issue with AI? When your last agent did something it absolutely should not have done, how did you find out, and who told you?
We Need Integrated, Human-Machine Systems that Monitor, Maintain, and Report
Here is where I get twitchy.
Practically all the enterprise energy I see is pointed at the machine. Which model, which benchmark, which vendor, which context window, which demo made the CFO nod. Fine. Real work. Also the work a supplier will happily do for you.
The other work is going backwards. One survey of 800 IT leaders this summer found the share of organizations requiring human review before a high-risk AI action dropped from 40% to 25% in six months, while full autonomy with no human review more than doubled. Over that same stretch, those same people marked their own AI maturity down from 40% to 23%.
Aviation gained its safety record through tragedy after tragedy. Fatal learning loops that improved the system. Today, we have machines that check the humans and humans that check the machines. Weâve developed the systems that, together, create a high degree of safety in a metal tube, hurtling through freezing air, with a bunch of human lives at stake.
With AI, we continue to hand over more authority while feeling less able to supervise it. We lack the systems to monitor, escalate, and even babysit the systems we are building (see my article We Gave Toddlers the Keys to the Car and then Had a Security Conference About the Car about the Hugging Face incident at OpenAI)
You can see why I get twitchy. Do you have named channels for catching your AI errors? Who says what an agent can do without asking permission? Who reviews the ones that go sideways?
The Wide Gap Between Perfect and Dangerous
We keep asking whether these systems are good enough yet. Good enough to do what? Aviation asks a better question, how do we build a system that makes an imperfect flight trustworthy? In aviation, it took a century of NTSB investigations, standards, mandates, reporting regimes, and named people with named jobs. And the system was primarily built from tragedy.
We have an opportunity, with AI, to be more proactive. To take the skeptics, the safety-minded, those who deeply understand the technology and the process, and ask them to help us see the blind spots. I see so many organizations rushing to build, they arenât seeing their houses are made of straw.
The good news is a lot of these people are already on your payroll. They are often the ones hanging back, waiting. Waiting to be asked: where could this go wrong?
Get the Rest of This Series in Your Inbox
This is the first of a few pieces on how trust actually gets built around a technology, and what we can steal from the systems we already trust without ever thinking about them. Subscribe free at intel.hyperadaptive.solutions.
Needing to Build the System?
If you see the gaps in your organization, whether they are around AI activation, governance, safety, or leadership, and want to give them a better chance of success, consider joining Running Hyperadaptive Organizations. We take the moves you are trying to make, pressure test them in our learning arena, and create a narrative that can be heard in your organization. October cohort is open: http://hyperadaptive.solutions/class



