Who Bears Liability for the American Airlines IT Outage?
The July 28, 2026 American Airlines systemwide IT outage caused over 1,100 delays and 221 cancellations, raising critical questions about vendor liability. This article analyzes whether American can recover losses from DXC Technology under the legal theories that allowed Delta's $550M claim against CrowdStrike to proceed, and whether passengers have viable claims.
- Jurisdiction
- United States
- Court
- Fulton County Superior Court
- AI tool named
- CrowdStrike
- Ruling date
- May 19, 2025
- Source document
- View primary court order ↗
- Last verified
- Jul 29, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
The legal investigation into American Airlines’ 2026 IT outage starts with a fork, not a culprit. On July 28, American suffered a systemwide IT outage that led to more than 1,100 delays, 221 cancellations, and a 48-minute FAA nationwide ground stop, according to Reuters; CNN likewise reported a nationwide halt tied to an IT outage affecting the carrier’s operations.[1][2] Some local reports have pointed to a network hardware issue involving a platform using DXC Technology, but that vendor link has not been confirmed by American in the available official statements, and Reuters and CNN did not name DXC in their initial operational accounts. That distinction matters. A vendor name is not a legal theory, and an outage narrative is not yet proof of causation.
The immediate legal allocation is therefore split into three relationships: American to passengers, American to any responsible vendor, and regulators to the airline. Those relationships do not produce the same remedies. American remains the passenger-facing carrier for cancellations, refunds, and controllable-delay commitments. If DXC is confirmed as the technical root cause, American may have a separate commercial recovery path against DXC. Passengers, by contrast, likely face a narrower route than the scale of the disruption suggests.

The Vendor Question Is Plausible, Not Proved
DXC is not a random name in this fact pattern. American previously said a Christmas Eve 2024 operational disruption was caused by a vendor technology issue, and reporting on that incident identified DXC as the technology provider involved.[3] That earlier confirmed relationship makes the July 2026 DXC reporting worth tracking. It does not, by itself, make DXC legally responsible for the July 28 outage.
The practical legal work in the first 24 to 48 hours is less dramatic than a public blame cycle. Counsel would want preservation notices, incident timelines, change logs, service-level records, escalation tickets, contracts, insurance notices, and any communications with the FAA and DOT. The question is not simply whether a system failed. It is whether a party owed a duty, breached a contract or independent legal obligation, caused losses that can be proved, and failed to disclaim or limit the relevant exposure.
That is why the Delta v. CrowdStrike litigation is the useful comparison. It does not answer whether DXC caused American’s outage. It does show how an airline can try to move outage losses upstream when a technology provider’s alleged conduct is tied to mass cancellations.
Why Delta v. CrowdStrike Matters More Than the Airport Delay Count
In May 2025, a Fulton County Superior Court judge allowed Delta Air Lines to proceed with claims against CrowdStrike arising from the July 2024 global technology outage. Delta alleged more than $550 million in losses and tied those losses to roughly 7,000 canceled flights. The court allowed claims including gross negligence, computer trespass, and conversion to survive CrowdStrike’s motion to dismiss.[4]
Survival at the motion-to-dismiss stage is not a win on liability. It means Delta pleaded enough for those claims to continue into litigation. CrowdStrike can still contest causation, damages, contractual limitations, comparative fault, technical responsibility, and the scope of any duty. But procedurally, the ruling matters because it kept alive claims that sound more forceful than a standard contract dispute.

The gross-negligence piece is the obvious commercial lever. Ordinary negligence and breach-of-contract theories often run into limitation-of-liability clauses, warranty disclaimers, exclusive-remedy provisions, and damages caps. Gross negligence, depending on governing law and contract language, may be harder to waive or cap. That is why plaintiffs try to plead the failure as something worse than a bad patch, a defective update, or an operational mistake. The claim has to fit the facts, but the pleading objective is clear: escape the narrowest remedial box.
Computer trespass and conversion do different work. They attempt to characterize the technology event as an interference with systems or property interests, not merely poor performance under a services agreement. Whether those theories fit a network hardware issue would depend on the actual architecture, access rights, contract permissions, and mechanism of failure. A vendor whose authorized platform malfunctions is not automatically a trespasser. But the Delta ruling shows that a court may allow those theories to be tested where the pleaded interference with airline systems is concrete enough.
For American, the roadmap would be conditional. If DXC is confirmed as the root cause, American could evaluate whether the incident record supports contract claims, indemnity demands, negligence theories, or more aggressive tort-style claims modeled on Delta’s surviving theories. The strength of that path would turn on documents that public reporting does not yet provide: the master services agreement, service-level commitments, exclusions, cyber or technology E&O coverage, notice requirements, governing law, and any incident-specific admissions.
| Legal relationship | Likely question | Practical remedy path |
|---|---|---|
| Passenger vs. American | Did the cancellation or delay trigger refund and service commitments? | DOT refund rights, amenities for controllable disruptions, contract-of-carriage remedies |
| American vs. vendor | Did a vendor breach contractual or independent duties and cause provable operational losses? | Contract damages, indemnity, insurance recovery, possible tort-style claims if facts support them |
| Passenger vs. vendor | Can state-law claims avoid airline deregulation preemption? | Difficult class-action path after the CrowdStrike passenger dismissal |
| Regulator vs. American | Did the carrier comply with refund, delay, cancellation, and consumer-protection obligations? | DOT oversight and potential enforcement exposure |
American Still Owns the Passenger-Facing Problem
Even if a vendor caused the outage, passengers did not buy transportation from the vendor. They bought it from American. That makes American the first legal and regulatory counterparty for canceled flights, refunds, rebooking, and commitments listed on the DOT Airline Customer Service Dashboard.
The DOT treated airline disruptions related to the 2024 CrowdStrike outage as controllable for dashboard purposes, a classification that matters because controllable cancellations and delays trigger the commitments carriers have made for meals, hotels, ground transportation, and rebooking assistance.[5][6] That does not mean every affected passenger receives damages. It means the event is not treated like weather for customer-service purposes.
Refund rights sit on a separate track. DOT materials state that passengers are entitled to a refund when an airline cancels a flight and the passenger does not accept alternative transportation or travel credits; DOT’s automatic refund rule requires prompt refunds, including within seven business days for credit card purchases and within 20 days for cash or check purchases.[7] Available materials note that DOT paused enforcement of certain refund-rule provisions through June 30, 2026, but the basic refund obligation for canceled flights remains the important floor.
That floor is often less than passengers expect. U.S. law does not provide an EC 261-style fixed cash compensation regime for domestic airline disruption. A passenger whose itinerary was ruined may have a refund right, meal or hotel assistance depending on circumstances and carrier commitments, and customer-service remedies. That is not the same as a broad damages claim for missed meetings, lost vacation time, emotional distress, or consequential losses.
Why Passenger Class Claims Face the Hardest Road
The strongest warning for passengers is not the Delta case. It is the separate CrowdStrike passenger class-action dismissal. In June 2025, the Western District of Texas dismissed state-law passenger claims arising from the 2024 CrowdStrike outage, holding that the Airline Deregulation Act’s preemption provision, 49 U.S.C. § 41713, barred claims against a third-party vendor whose actions affected airline services.[8]
That ruling is not nationally binding in every court. Preemption outcomes can vary by circuit and by the way claims are pleaded. But the logic is a serious barrier: if a passenger claim depends on the timing, routing, cancellation, or provision of airline service, the ADA may preempt state-law attempts to turn the disruption into a damages class action. Suing the technology vendor instead of the airline does not necessarily avoid that problem if the claimed injury is still the disruption of air service.
American’s contract of carriage adds another obstacle because it contains a class-action waiver. That does not erase statutory refund rights or DOT oversight, but it narrows the procedural vehicle passengers might prefer after a mass event. A passenger may still pursue individualized remedies where available. The harder proposition is aggregating disruption damages into a class case that survives both federal preemption and contractual waiver arguments.
This is the point at which public frustration and legal recoverability diverge. A systemwide outage can strand thousands of people and still produce limited passenger damages. The law is more receptive to the airline’s own upstream loss claim because the airline can point to operational expenses, cancellation costs, crew and aircraft displacement, reimbursement outlays, and lost revenue. Passengers mostly meet a framework built around refunds, rebooking, and service commitments.
Regulatory Exposure Is Separate From Private Recovery
A DOT review, if one follows, would not need to resolve every vendor-causation issue before asking whether American handled customers properly. Regulators care about refund timing, communications, tarmac-delay compliance, disability accommodations, and whether the carrier met the commitments it publicly made. Vendor fault may explain an operational failure, but it does not automatically excuse the carrier’s consumer-protection obligations.
American also does not enter the regulatory conversation with a blank history. The airline previously faced a $4.1 million fine for tarmac-delay violations, and an April 2026 aviation regulatory update described a pending $255,000 FAA proposed penalty involving alleged drug-and-alcohol testing program violations.[9] Those are not findings about the July 28 outage. They matter only as a reminder that airline disruption events can quickly migrate from operations desks to enforcement files.
What Would Make DXC Exposure Commercially Real
If DXC is confirmed, American’s recovery analysis would likely begin with the contract and then test whether the facts justify claims outside the contract’s lowest-liability channel. The most important documents would be the services agreement, service descriptions, incident-response obligations, maintenance windows, change-management rules, limitation-of-liability provisions, indemnity clauses, cyber and technology E&O insurance requirements, and any clauses addressing consequential damages from operational interruption.
- Root cause: whether the failure actually originated in DXC-controlled hardware, software, configuration, access, or managed service operations.
- Control: whether DXC had the authority and practical ability to prevent, detect, or remediate the condition that halted operations.
- Notice: whether American and DXC complied with incident, indemnity, insurance, and escalation deadlines.
- Loss measurement: whether American can segregate outage losses from ordinary disruption costs and prove causation flight by flight or category by category.
- Liability limits: whether contractual caps or exclusions apply, and whether gross negligence or similar theories can avoid them under the governing law.
The Delta ruling helps most on the last point. It gives American a litigation template for arguing that a major airline technology outage may support gross negligence and computer-system interference theories, at least at the pleading stage, when losses are large and the alleged vendor conduct is sufficiently connected to operational collapse. It does not guarantee that a court would treat a network hardware issue the same way it treated Delta’s allegations against CrowdStrike.
Insurance will sit behind this analysis. American may have business-interruption, cyber, aviation, or contingent technology coverage questions. DXC may have technology errors-and-omissions or cyber coverage. Insurers will care about the same facts courts will: cause, timing, exclusions, waiting periods, dependent-system language, contractual liability exclusions, and whether a claim sounds in negligence, contract, computer trespass, or conversion.
The Conditional Answer
American bears the immediate passenger-facing obligations from the July 28 outage. That includes refunds where required, rebooking, and controllable-disruption amenities tied to DOT-facing commitments. A vendor’s involvement would not move those duties to DXC in the passenger’s hands.
If DXC is officially confirmed as the root cause, American has the more commercially meaningful legal path. Delta v. CrowdStrike makes that path more credible because it shows a court allowing an airline’s high-value outage claims to proceed under gross negligence, computer trespass, and conversion theories. The useful word is proceed. Delta has not yet recovered $550 million, and American would still need proof, contract language, causation, and damages.
Passengers likely have the narrowest damages path. The CrowdStrike passenger dismissal strengthens the ADA-preemption defense for both airlines and vendors when state-law claims are built on disrupted air service, and American’s class-action waiver further reduces the likelihood of a broad passenger class recovery. The next legally important fact is not another delay total. It is official root-cause confirmation.
References
- FAA issues American Airlines nationwide ground stop over IT outage, Reuters, July 28, 2026.
- American Airlines flights halted, CNN, July 28, 2026.
- American Air Says Christmas Eve Delays Caused by Tech Glitch, SupplyChainBrain, December 2024.
- Delta can sue CrowdStrike over computer outage that caused 7,000 canceled flights, Reuters, May 19, 2025.
- Airline delay or canceled flight? What you’re entitled to, Business Insider, July 2024.
- Airline Cancellation and Delay Dashboard, U.S. Department of Transportation.
- Fly Rights, U.S. Department of Transportation.
- CrowdStrike Customer Class Action 2024 Outage, Expert Institute, June 2025.
- Aviation Regulatory Update April 2026, Eckert Seamans, April 2026.
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →