Skip to content

Regulation

Why three American outages produced no FAA IT mandate

By Editorial TeamUpdated Aug 2, 2026
Authority
U.S. Department of Transportation
Rule type
regulation
Jurisdiction scope
US federal
Effective date
Jul 1, 2024
Source text
Read primary rule text ↗

Airlines must provide automatic refunds for canceled or significantly changed flights; no preemptive airline-IT resilience mandate exists.

The July 28, 2026 American Airlines ground stop is already easy to misread. The event was only days old as of this writing, American had not disclosed a root cause or remediation plan, and no DOT investigation had been announced as of the July 29 analysis reflected in the available record. What is known is narrower: the FAA ground stop ran for roughly 48 minutes, from about 6:30 p.m. to 7:18 p.m. ET; American described a “technology issue that briefly impacted connectivity”; and contemporaneous flight-tracking figures showed about 1,100 delayed flights and 221 cancellations, subject to later revision.[3][4]

That matters because the useful frame is not “a third FAA ground stop.” The record supports three American Airlines connectivity-layer failures in less than two years: two full FAA ground stops and one major non-ground-stop outage. The difference is not cosmetic. A ground stop tells us who had authority to hold aircraft on the day the carrier could not safely or practically run its operation. It does not, by itself, tell us that any federal agency had authority to require a different airline IT architecture before the next failure.

DateWhat failed or was disclosedOperational impactRegulatory posture shown in the record
Dec. 24, 2024American attributed the Christmas Eve disruption to DXC Technology network hardware affecting its Flight Operations System.An approximately one-hour nationwide ground stop. Cirium data cited in contemporaneous reporting showed 3,901 scheduled flights, 19 cancellations, and only 37% on-time performance.FAA operational ground stop; no forward-looking federal airline-IT resilience mandate identified in the available record.
June 27, 2025American described a widespread “technology issue affecting connectivity” across booking, check-in, ticketing, baggage, and maintenance functions.FlightAware figures cited in contemporaneous reporting showed more than 40% of flights delayed and 7% canceled. No full FAA ground stop was reported.Major operational disruption; no full ground stop and no new binding federal IT-resilience obligation identified.
July 28, 2026American disclosed only a “technology issue that briefly impacted connectivity” and named no vendor.FAA ground stop of about 48 minutes. FlightAware figures cited in contemporaneous reporting showed about 1,100 delays, or 30%, and 221 cancellations, or 6%.FAA operational ground stop. As of the July 29 analysis, no DOT investigation had been announced.

The Christmas Eve disruption is the cleanest example of the difference between a visible aviation event and a regulatory mandate. Reuters reported an approximately one-hour nationwide ground stop after American attributed the problem to DXC Technology network hardware affecting the Flight Operations System; the same report cited Cirium figures showing 3,901 scheduled flights, 19 cancellations, and 37% on-time performance that day.[1] That is an operationally serious record. It is not, standing alone, evidence that the FAA acquired direct authority over the airline’s network hardware or vendor design.

The June 27, 2025 incident widened the operational picture without changing the legal one. CNN reported that American had a technology issue affecting connectivity across booking, check-in, ticketing, baggage, and maintenance, with FlightAware showing more than 40% of flights delayed and 7% canceled; no full ground stop was reported.[2] The July 2026 event then returned to the ground-stop pattern, but with less public technical detail from the carrier.[3][4]

Timeline of three American Airlines outage nodes with two ground-stop symbols and one warning symbol

What the FAA stop did — and did not — decide

In these incidents, the FAA’s most visible role was immediate air-traffic control: hold departures while the carrier’s systems could not support ordinary operations. That is a real exercise of public authority. It protects the national airspace system from an airline dispatch and connectivity failure spilling into unsafe movement.

But the stop order is a poor proxy for software-resilience jurisdiction. The agency can stop aircraft from departing when the carrier cannot operate normally. The harder question is whether any regulator can require the carrier, in advance, to build, test, segment, contract for, or audit its internal IT stack in a prescribed way. The American incidents show the former authority. They do not show the latter.

That is where the Government Accountability Office’s 2019 airline IT outage report does more work than any single holiday outage account. GAO reviewed airline IT outages from 2015 through 2017 and found 34 outages across 11 of 12 selected airlines; about 85% caused flight delays or cancellations.[5] Those figures show that American’s recent sequence is not an entirely novel class of operational risk. They also show why recurrence has not automatically become rulemaking.

The structural gap GAO found

GAO’s central finding was not simply that airline IT outages happen. It was that the federal oversight record was not built to see them cleanly. The report said federal data could not be used to identify airline IT outages, even when those outages produced delays or cancellations.[5] If the dataset cannot reliably distinguish a carrier software failure from other operational causes, then a regulator trying to build a targeted rule starts with a bad evidentiary map.

The same report drew the jurisdictional line plainly: FAA does not directly oversee airline IT systems.[5] That sentence is easy to skate past because the FAA is the agency the public sees when aircraft stop moving. But authority to manage the airspace during a disruption is not the same as authority to prescribe the resilience requirements for the airline connectivity layer that failed upstream.

Diagram showing airline IT cloud separated from legal, aviation, and aircraft regulatory boxes

DOT’s consumer-protection tools were also narrower than the outage problem. GAO found that DOT consumer protections did not specifically address IT outages, and that no airline contract of carriage reviewed by GAO contained provisions specifically addressing IT outages.[5] That last point is where public law and private contracting leave the passenger-facing worker exposed. The gate agent has to rebook, explain, refund, and absorb anger; the contract text may still say little about the particular technology failure that created the line.

The result is not a total absence of legal consequence. It is a mismatch between consequence and prevention. Regulators can police refunds, disclosures, unfair practices, and airspace operations. GAO’s report does not show a mature federal regime that sets prospective reliability requirements for airline IT systems as such.

Refund enforcement is the binding lever DOT actually has used

DOT’s April 2024 automatic refund rule is the binding instrument that fits this record most closely: when a flight is canceled or significantly changed, the passenger-refund obligation can attach without waiting for the agency to regulate the failed technology itself.[6] That is a consumer-remedy mechanism, not an engineering code for airline reservation, crew, baggage, maintenance, or dispatch systems.

The Southwest enforcement matter shows how expensive travel-disruption enforcement can become when the agency finds violations within its consumer-protection lane. DOT announced a $140 million civil penalty after Southwest’s holiday 2022 disruption, which involved 16,900 cancellations; DOT described the penalty as its largest ever for a travel disruption.[7] That case is important because it defeats the easy claim that DOT is powerless when airline technology and operations collapse. It is equally important because it does not prove that DOT has imposed a general preemptive IT-resilience mandate.

The Delta/CrowdStrike disruption is the closer comparison for vendor-caused IT failure. The July 2024 disruption involved more than 7,000 cancellations and affected about 1.3 million passengers; DOT opened an investigation on July 23, 2024, and the disruption was treated as a controllable event.[8][9] The probe closed in June 2026 with no penalties, with reporting citing prompt refunds and the administration’s enforcement policy.[8] That closure should not be turned into a permanent immunity rule. It is an enforcement outcome under a particular posture, and a later administration could treat similar facts differently.

Still, the Delta closure is the relevant boundary marker. DOT had a high-profile vendor IT disruption, passenger harm at scale, and an open investigation. The closing record, as reported, produced no new software-reliability obligation applicable across carriers. The enforceable center remained refunds and consumer treatment after the disruption, not federal certification of the software layer before it failed.

When the failed system belonged to FAA, the response looked different

The FAA’s January 2023 NOTAM failure is the useful contrast, not a precedent for airline IT oversight. That failure produced the first nationwide ground stop since 9/11 after a contractor’s unintended file deletion affected the NOTAM system.[10] Because the failed system was the FAA’s own, the agency could speak in the language of internal remediation: synchronization delay, a two-person protocol for database maintenance, and NOTAM modernization.[10]

Acting FAA Administrator Billy Nolen’s Feb. 15, 2023 Senate testimony similarly belonged to the agency-system side of the ledger.[11] It showed what remediation looks like when the public agency owns the system, controls the modernization program, and can change maintenance procedures directly. That does not answer the American Airlines question, where the failed connectivity layer sits inside the carrier and its vendor relationships.

FAA’s safety-management-system architecture is adjacent but not dispositive. The FAA’s 2015 SMS final rule established a safety-management framework for certain aviation organizations.[12] The available record here does not connect that framework to direct FAA oversight of airline IT outages, so it should not be treated as the missing mandate under another name.

Litigation is not filling the gap either

Passenger litigation has not become the substitute regulator in this record. The available record does not identify a verified passenger class action over the American Airlines IT outages themselves. Unrelated American Airlines litigation — including AAdvantage or price-fixing matters — should not be folded into this outage story just because the defendant name is the same.

Del Rio v. CrowdStrike is worth noting only at the edge. A federal district court in the Western District of Texas dismissed passenger claims on Airline Deregulation Act preemption grounds in June 2025, and the case was pending before the Fifth Circuit after March 30, 2026 argument, with the panel reportedly skeptical.[9] That appellate status must be re-verified before anyone relies on it. Even if the case changes on appeal, it would still be a litigation path, not a federal IT-resilience rule.

The aviation record does not prove what bar regulators or courts will do with legal AI. The comparison is narrower: when a professional service depends on private software infrastructure, public actors may have clear authority over downstream duties while lacking a general statutory baseline for upstream reliability.

For legal-AI tools in the United States, the reliability duties that matter today usually enter through professional responsibility rules, ethics opinions, procurement terms, court orders, and verification workflows. ABA Formal Opinion 512, for example, addresses generative AI through lawyers’ existing duties of competence, confidentiality, communication, supervision, fees, and candor; it does not create a federal software-reliability statute.[13]

That distinction is exactly what law-firm KM and risk teams feel in practice. A partner may ask whether an AI research tool is “approved.” The answer usually is not a simple public-law yes. It is a stack of narrower controls: what the vendor promised, what data the contract permits, whether the tool can be used on client confidential information, whether outputs must be checked against primary law, whether a court order restricts AI-assisted filings, and who keeps the audit trail.

State-level moves can harden that stack, but they still have to be read source by source. Proposed or adopted ethics rules may move a lawyer-facing obligation from guidance toward a disciplinary “must,” while vendor contracts may allocate warranties, incident notice, audit rights, indemnity, and data-handling commitments. Those are important controls. They are not the same thing as Congress imposing a general reliability standard on legal-AI vendors.

The EU AI Act supplies the obvious contrast because it does create a statutory AI governance framework with risk-based obligations.[14] It may matter to US legal organizations when their activities, clients, vendors, or deployments fall within its scope. But it is an external statutory scheme, not evidence that US federal law has already supplied the same baseline for domestic legal-AI reliability.

This is the synthesis judgment the aviation record supports: US legal-AI reliability duties currently resemble the airline-IT gap more than they resemble a mature statutory regime. The duty to verify is real. The duty to supervise tools is real. Contracting discipline is real. But those duties live in professional and private-law channels unless Congress, a court, or an applicable external statute changes the baseline.

Readers tracking the binding-versus-advisory line can compare this pattern with the state-bar rulemaking issues covered in California State Bar AI ethics proposed rule amendments, the ethics-layer analysis in Defense Attorney AI Court Filings Ethics, and the operational verification approach in the Prompt→Verify→Audit legal ethics risk framework. The same authority question also appears in aviation-liability form in Delta Close Call: FAA Probe Highlights Five Liability Layers.

References

  1. Reuters report on American Airlines Christmas Eve nationwide ground stop — Reuters, Dec. 24, 2024
  2. CNN report on American Airlines June 27, 2025 technology issue — CNN, June 27, 2025
  3. Reuters report on American Airlines July 28, 2026 FAA ground stop — Reuters, July 28, 2026
  4. CNN report on American Airlines July 28, 2026 technology issue — CNN, July 28, 2026
  5. Airline Information Technology Outages: Causes, Impacts, and Associated Trends — U.S. Government Accountability Office, June 2019
  6. DOT automatic refund rule — U.S. Department of Transportation, April 2024
  7. DOT announcement of $140 million Southwest Airlines civil penalty — U.S. Department of Transportation
  8. Travel Weekly report on DOT closure of Delta/CrowdStrike probe — Travel Weekly, June 16, 2026
  9. 2024 Delta Air Lines disruption — Wikipedia
  10. FAA statement on NOTAM outage — Federal Aviation Administration, Jan. 19, 2023
  11. Senate testimony of Acting FAA Administrator Billy Nolen — U.S. Department of Transportation, Feb. 15, 2023
  12. Safety Management Systems for Domestic, Flag, and Supplemental Operations Certificate Holders — Federal Aviation Administration, 2015
  13. Formal Opinion 512: Generative Artificial Intelligence Tools — American Bar Association
  14. Artificial Intelligence Act — European Union

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory