Ural 178: when safety and success diverge
Most aviation incidents involve flying—whether well or badly. This extraordinary edge case exposes a breakdown in the very concept of what “safety” means. Its lessons about recognition are universal.
I have a quiet hobby which amuses me at bedtime, even if bedtime is perhaps not the most appropriate setting for such grim material. I like learning about air crashes and their investigations. They are extraordinary microcosms of technological ambition, human competence and failure, institutional learning, plus the occasional whim of nature. The immediate protagonists are usually less of interest than the “systems of systems” interacting in unusual ways.
They are also fascinatingly diverse and informative in a way that, say, automobile accidents generally are not. Aviation takes a commonplace human activity—getting from one place to another—and attaches to it unusual technological complexity and, in extremis, enormous peril. When things go badly wrong, ordinary assumptions are compressed into seconds and subjected to tests for which nobody would willingly design the experiment.
The result is an unusually rich laboratory for discovering what “safety” and “success” actually mean.
⁂
There are many (in)famous examples of “flights gone wrong” that ended in noteworthy successes or failures.
The “Gimli Glider” was an Air Canada Boeing 767 that ran out of fuel in 1983, yet landed safely at a former air force base in Manitoba—under the command of a pilot who happened to have experience flying gliders. It was still “flying”; the category of machine had changed mid-flight.
The powered airliner had become a glider, but the governing activity remained recognisably the same: manage its remaining energy and fly it to a suitable surface.
BA38, a Boeing 777 arriving at Heathrow from Beijing in 2008, suffered a severe loss of thrust from both engines on final approach. With the aircraft no longer able to reach the intended touchdown point, the captain reduced the flap setting, trading some low-speed lift for reduced drag and precious additional range. The aircraft came down just inside the airport boundary, short of the runway, and was written off. Everyone survived.
It was still “flying”; what had changed was the minimum acceptable outcome. Reaching the intended touchdown point had ceased to matter; preserving enough trajectory to clear the obstacles and reach survivable terrain did.
QF32, a Qantas Airbus A380, suffered an uncontained engine failure shortly after departing Singapore in 2010, causing extensive and bewilderingly interconnected systems damage. The crew spent the following period working out what capabilities the aircraft they now possessed actually retained, rather than assuming that the certified A380 they had departed in still described their machine. They eventually returned safely to Singapore.
It was still “flying”; what had changed was the category of machine capability. The central problem was reconstruction of a viable model of what aircraft remained.
⁂
Then there is the most celebrated example: Captain Chesley “Sully” Sullenberger and US Airways Flight 1549. A bird strike shortly after departure from LaGuardia caused a near-total loss of usable thrust from both engines at very low altitude. There was insufficient energy, allowing for the realities of diagnosis and decision time, to reach a runway with acceptable confidence. Sullenberger chose the Hudson.
It was still “flying”; what had changed was the category of terminus. A runway was no longer constitutive of a successful landing. The river would do.
These cases look radically different, but they retain something important in common. In each, however badly the original plan had failed, the crew could still recognise what kind of activity they were engaged in:
The machine might become a glider.
Its capabilities might have to be reconstructed from scratch.
The intended runway might become merely airport grass.
Or a river might replace the airport altogether.
But the governing problem remained intelligible:
fly the thing you actually have, using the energy and control remaining, towards the best survivable termination available.
And then there is Ural Airlines Flight 178.
⁂
Ural is different.
Because for a few extraordinary seconds, the uncertainty was not merely about how to fly the aircraft, what capabilities remained, or where to put it.
The uncertainty was whether continued flight was still the safe objective at all.
Was this still an aeroplane to be saved, or had it become a survival capsule to be stopped?
This exposes category boundaries that are rarely visible. The “aha!” is the same one I have been exploring in recent articles: once we recognise a situation as category A rather than category B, we have already imported a framing assumption that determines which objectives—and therefore which actions—appear rational.
Reasoning happens downstream of recognition.
There is a hidden arrow that usually disappears.
That makes recognition errors particularly treacherous. You can reason impeccably from the wrong category and obtain a faultlessly logical wrong answer. Worse, because everything downstream of the recognition choice is internally coherent, the resulting failure is easily misdiagnosed. Accusations can fly of lax thinking, poor execution, or non-compliance—rather than the core issue being to recognise what kind of problem you are actually in.
Ural 178 may be an unusually pure example because the category boundary itself was unstable and, in real time, undecidable.
⁂
And, remarkably, the aviation-safety response to the accident appears largely to have remained downstream of that boundary.
It has analysed
what the crew did within the continuation frame
without squarely asking
whether continued flight was still the correct frame in the first place.
It is here that three tools I have been developing—General Prolegomena, Geometry–Topology–Field–Observability (GTFO), and Recognition–Reconstruction–Reality (R-R-R)—become unexpectedly useful. Together they provide an epistemic toolkit for diagnosing the deeper structural problem exposed by Ural 178.
Hence my writing up this incident. Not to drag you into my macabre midnight hobby, but to demonstrate something much more general: how we can get underneath a problem in ways that even deep subject-matter expertise does not necessarily equip us to see.
Expertise is extraordinarily powerful downstream of recognition. But that is precisely the problem.
If the initial recognition is wrong—or the category boundary itself is unstable—ever greater expertise can produce ever more sophisticated reasoning inside the wrong frame.
In that context, these AI tools ask three different but complementary questions.
General Prolegomena: Before reasoning within a category, what entitles us to believe that we have recognised the right category?
R-R-R: What actually happened; what was available to be recognised in real time; and how much of what we subsequently “know” is retrospective reconstruction?
GTFO: Which observable features belong to the visible geometry of successful aviation, and which deeper invariant is that geometry ultimately supposed to preserve?
Ural is remarkable because all three questions converge on the same fault line.
⁂
To understand the situation, let us first run through it from an orthodox aviation-safety perspective.
Ural Airlines Flight 178 was an Airbus A321 carrying 233 people: 226 passengers and seven crew. It departed Moscow’s Zhukovsky International Airport on 15 August 2019. The airport already had a serious bird-hazard problem, exacerbated by nearby waste sites and inadequate bird-control measures—failures that would later feature prominently in the investigation.
Seconds after take-off, the nightmare every airline pilot rehearses in a simulator arrived in a particularly unpleasant form: the aircraft encountered a flock of gulls and birds entered its engines.
Both engines were damaged.
The left was reduced to roughly idle thrust; the right retained substantially more, but still suffered a significant loss. Total available thrust was less than that normally available from a single engine at the take-off setting. There was severe vibration, multiple warnings, extreme workload, and very little altitude in which to make sense of any of it.
The investigation subsequently concluded that the combination lay outside the expected operating conditions assumed in certification.
At first, however, there was no decision to make about whether to take off: they already had. The aircraft was only hundreds of feet above the ground. The runway was behind them. Stopping the take-off was no longer an option.
The orthodox task was therefore brutally familiar: fly the aeroplane.
Clean it up. Retract the landing gear and remove its enormous drag. Control pitch and airspeed. Establish whatever climb performance remains. Stabilise the situation. Diagnose the failures. Run the appropriate procedures. Then work out where and how to land.
That is not what happened.
⁂
The landing gear remained extended. The crew became severely disorganised under the extraordinary psycho-emotional load. The first officer’s performance deteriorated badly. Pitch and speed were not managed as the continuation procedure required. With the gear still producing substantial drag, the aircraft could not establish the performance it needed.
The final investigation would describe the crew’s actions in striking terms: showing “clear signs of disorganisation, inconsistency and chaos.”
Eventually the gear was retracted. But by then the aircraft was descending towards the terrain.
Moments later, the A321 touched down gear-up in an enormous cornfield beyond the airport.
The aircraft was written off.
All 233 people aboard survived.
Twenty-eight people were injured, three seriously.
The immediate public story almost wrote itself.
Captain Damir Yusupov became a national hero, inevitably compared with Chesley Sullenberger after the Hudson ditching. Decorations followed before the much slower machinery of technical investigation had answered the awkward question: had this really been brilliant airmanship?
The final report was dated in 2022, but was not officially published by the Interstate Aviation Committee until November 2025. When the full technical findings became publicly available, the picture was considerably less comfortable.
Its modelling indicated that, had the crew promptly retracted the gear and correctly managed pitch and speed, continued flight might have been possible.
Yet the report also acknowledged something crucial: maintaining even the residual thrust upon which that counterfactual depended was not guaranteed.
The harsh reading is therefore tempting:
The pilots failed to execute several of the familiar initial post-V1 priorities correctly. They left the gear down, mishandled the aircraft’s energy, became overwhelmed, missed an available opportunity to climb away, and destroyed an expensive airliner in a field. By extraordinary good fortune, the field was forgiving and everybody lived.
In that reading, 233 survivors are evidence of luck rather than good airmanship.
That is the interpretation I want to challenge.
⁂
Not because the investigation’s aerodynamic reconstruction is necessarily wrong. Nor because procedural errors somehow become good decisions when everybody survives. And certainly not because 233 survivors prove that the course actually taken was optimal.
The problem lies one level upstream:
The investigation could reconstruct that continued flight might have been physically possible.
It could not establish that the damaged engines would continue providing the residual capability upon which that possibility depended.
The unchosen branch therefore had an uncertain destination.
And that exposes a question more fundamental than whether the crew correctly executed the procedure for continuing flight:
Was continued flight still the correct safety objective in the first place?
The very nature of “success” changes with the recognition category engaged.
⁂
Let us, for a moment, return to the most fundamental truths of flying in any powered aircraft:
There is fuel, which is converted into kinetic and potential energy.
The hull rises above the ground.
There is a finite capacity to keep it above the ground.
That capability may degrade in flight.
At some point, there is a return to a ground energy state: level with the terrain, and no longer moving in relation to it.
In normal operation, the pilot’s job is to optimise this cycle for fuel economy, wear on the machine, passenger comfort and on-time arrival. The conventional terminus for each flight is a prepared surface that permits the aircraft to be used again. Standard procedures recognise many failure modes and degraded outcomes, extending all the way to ditching in water.
Stripped to its bare essentials, “safe and successful” is X fragile bodies entering a temporary state of energisation, and X fragile bodies emerging following de-energisation.
Arrival at the intended destination is a helpful side-effect. But it is only a secondary property of the primary outcome. Obviously transportation is the commercial purpose of aviation, so destination isn’t literally incidental. But within the safety ontology we are constructing, it is subordinate: destination is valuable conditional on conserving the bodies.
That is the governing invariant.
Not reaching the original destination.
Not landing on a conventional runway.
Not having an aircraft that flies another day.
Those are all proxies for the desired outcome, and strongly correlated with it.
But they are not synonymous with it.
And with Ural 178, they arguably diverge. That is what gives the incident its unusual diagnostic character.
⁂
Now we can begin to see how “safe airmanship” and “suicidal heroic adventurism” can approach one another, merge, and perhaps even cross over. Read the same facts from inside the runtime—without hindsight, mathematical modelling, engine examination or leisurely reconstruction—and reality looks very different.
The machine had very little energy margin at very low altitude. The damaged engines still had enough residual thrust, in principle, to add energy, producing greater altitude and therefore more options.
But its condition was uncertain:
The effective thrust available in the moment was not precisely known.
Its direction of change was not known.
How the damaged engines might evolve was not known.
The effect of asymmetric thrust on performance was not known.
The risk of adding more energy was not known.
The consequences of attempting to climb, turn and return were not known.
What was known was that an extraordinary “energy cushion”—a mature cornfield ripe for harvest—lay directly ahead.
Return now to our governing invariant:
get the fragile bodies back to earth and dissipate the aircraft’s flight energy without losing any of them.
Preservation of the aircraft was now subordinate to that singular requirement. Attempting recovery offered the possibility of altitude, more options, a runway landing and perhaps an aircraft that could fly another day.
But acquiring those things required continued dependence upon damaged machinery whose future behaviour was uncertain, while surrendering an unusually benign termination opportunity immediately ahead.
In other words, following the continuation procedure did not simply represent “the safe option”.
It exchanged…
…an immediate and bounded hazard
…for continued exposure to a poorly characterised ruin risk
…in return for the possibility of recovering something resembling a normal flight.
Immediate termination offered the inverse exchange:
Putting the aircraft into vegetation, with no buildings or substantial obstacles immediately ahead, was certainly dangerous.
But it transformed an uncertain and evolving airborne problem into a bounded problem of attitude, impact, deceleration and evacuation.
It exchanged uncertain safety with potentially unlimited unsafety for certain, limited unsafety.
And under sufficiently extreme uncertainty, that may be the rational exchange.
The job wasn’t to fly well.
It was to crash well.
There are details whose meaning flips when we change the root recognition from “aviate” [directing energy] to “dissipate” [removing flight energy].
Keeping the gear down initially added enormous drag and impaired climb performance:
Under the continuation recognition, that is simply an error.
Under the termination recognition, however, the same drag shortened the realised trajectory and may thereby have helped keep the aircraft within the extraordinary soft-landing zone immediately ahead.
The apparent “freeze” of the first officer undergoes a similar inversion:
Under the continuation recognition, his failure to perform expected actions is a serious Crew Resource Management and procedural failure.
Under the termination recognition, the same inaction can at least be read differently: whatever its psychological cause, it did not inject additional actions, distractions or competing objectives into the few seconds available to the captain.
Even the absence of rote adherence to procedure changes meaning:
Under the continuation recognition, essential tasks were omitted.
Under the termination recognition, almost the entire problem had collapsed to a tiny number of remaining degrees of freedom: keep the aircraft controllable, configure it for the impending contact with terrain, and manage the transition from flight energy into vegetation, structure, soil and friction.
The observations have not changed. The recognition has.
And with it, their meaning changes.
That is the whole point.
⁂
There is one fact in this tale that is overwhelming: nobody died.
There is no “what if” to analyse for improved mortality. No loss of life to explain, however limited. No grieving relative demanding accountability. Indeed, some passengers have returned to the cornfield on anniversaries and met Captain Yusupov there.
This poses a deep structural conundrum for aviation safety itself—and for its self-concept.
In normal operation, every flight is effectively another sample against a vast accumulated body of experience. Procedure encodes that experience, including known failure modes, and improves survival probabilities on the presumption that the circumstances encountered can be recognised as belonging to categories informed by previous failure and learning.
That system works extraordinarily well.
But Ural 178 exposes its foundational dependency:
the procedure can only be as appropriate as the recognition that selects it.
There is no alternative path through the enormous state space that can improve upon the realised mortality outcome of Ural 178. Every counterfactual—gear up immediately, establish climb, continue flight, turn back, land normally—faces the same awkward empirical rebuke:
Nobody died.
That does not prove that the path actually taken was optimal. A good outcome can follow a bad decision, just as a catastrophe can follow a good one. But it places a hard ceiling on what any counterfactual can improve in the mortality outcome, while leaving open a downside extending all the way to mass fatality.
⁂
This raises the uncomfortable possibility that a safety regime can, in sufficiently unusual circumstances, impose a false recognition on reality—and thereby recommend actions that increase rather than decrease the very ruin risk the regime exists to control.
Worse, there is a potential sampling and invisibility problem.
A crew can follow procedure, continue flight, land normally and disappear into the enormous population of successful operations. We observe the successful outcome, but never observe the alternative branch, nor discover whether the decision exposed everyone aboard to an unnecessary tail risk that simply failed to materialise.
Ural produces the opposite visibility.
Procedure was imperfectly executed, the aircraft ended up in a cornfield, and an investigation necessarily followed. Yet everybody walked away alive. The anomalous branch therefore receives intense scrutiny precisely because it generated the visible event, while conventionally successful branches (that may sometimes carry hidden counterfactual risk) leave no accident to investigate.
This is not evidence that aviation procedure is generally unsafe. Quite the opposite: its extraordinary empirical success is beyond serious dispute.
It is evidence of an epistemic asymmetry in how aviation gets to learn what “safe” means at the boundary of its experience.
⁂
My sense is that the behaviour of both the captain and his relatively junior first officer amounted, whether consciously or otherwise, to a remarkably “reality-first” response:
They did not successfully instantiate the recognition offered by standard procedure: that they possessed a degraded aircraft whose continued function as an aircraft should be preserved.
Their behaviour instead became consistent with a radically different recognition: that the sole remaining function of the asset might be to absorb and dissipate the energy already added to it while protecting its occupants.
We should be extremely humble about reconstructing what happened cognitively in that cockpit.
No later reconstruction can reproduce its environment:
The flight-data recorder can tell us what the machine did.
The cockpit voice recorder can tell us something about what was said.
Engineering analysis can tell us what the aircraft might physically have been capable of.
None can reproduce the visceral experience of being a few hundred feet above the ground in a violently vibrating machine, with two bird-damaged engines, ambiguous capability, multiple warnings, seconds to act, and 233 lives attached to the answer.
The alternative “success modes”—climb away, diagnose, return and land conventionally—therefore remain counterfactuals. They matter for understanding aircraft performance and improving training, but they cannot overturn the one invariant that reality actually instantiated:
everyone lived as the aircraft’s flight-energy state returned to baseline.
Achieving that outcome involved abandoning almost every conventional proxy for success. Some were geometric: configuration, pitch, altitude, trajectory, the runway itself. Others were topological: the expected continuities of powered flight—climb, stabilise, diagnose, return, land—were simply not traversed.
Seen through the tools developed earlier, this begins to look like a prolegomenal problem. The question logically prior to “How do we fly the plane?” was:
Are the preconditions for “fly the plane” still sufficiently satisfied?
The answer available in real time was not obviously yes.
They occupied something that remained aerodynamically an aeroplane, and which later reconstruction suggests retained some potential for continued powered flight, but whose ability to sustain that role was uncertain.
It was an aircraft physically.
Whether “aircraft” remained the correct operational recognition was the unresolved question.
⁂
There was no possibility of the Gimli Glider being refuelled in mid-air and becoming a powered 767 again.
There was no possibility of BA38 suddenly clearing the ice restriction in its fuel system and performing a go-around.
There was no possibility of QF32’s exploded engine reassembling itself, or of the systems severed by its debris healing themselves.
There was no possibility of a better landing surface suddenly appearing within Captain Sullenberger’s remaining energy envelope than the Hudson.
In each case there was enormous uncertainty about what to do, but comparatively little uncertainty about what kind of problem the crew was now solving. The operational mode had been imposed by physical reality.
Ural 178 was different. It kept open an alternative hypothetical path.
The aircraft had not cleanly become a glider. Nor had it cleanly remained a viable powered aircraft. Enough capability apparently remained that later reconstruction could show a possible continuation path, but not enough certainty existed in real time to establish that continued flight would remain viable.
This pushed the problem upstream.
The uncertainty was no longer merely within the mode of operation.
There was uncertainty about which mode of operation was actually engaged.
QF32 provides the useful contrast. Its crew possessed an extraordinarily damaged machine, but one with substantial residual capability, altitude and time. They could continue flying while reconstructing what aircraft they now had. Ural had almost none of that luxury. It had very little altitude, very little time, uncertain residual propulsion—and an enormous cornfield immediately ahead.
The crew therefore faced a meta-decision before the ordinary decisions of airmanship could even be made:
Is this still an aircraft to continue to be flown, or has it become an energy system to be terminated?
That is what makes Ural 178 unusually instructive.
And the same meta-decision—the act of recognition that necessarily precedes reasoning or reconstruction—appears across remarkably different domains. Law, governance, science, journalism and regulation all depend upon deciding what kind of thing is before us before their sophisticated machinery for dealing with that thing can begin.
Get the recognition wrong, and expertise does not necessarily rescue you.
It may simply reason more expertly inside the wrong reality.
I went through my “Ghost Court” saga at the High Court, and found that “lexworthiness” challenges are not recognised. In that litigation, I also encountered a related problem: the constitutive path for the claimed tribunal could not be reconstructed from the record.
My conclusion is that the problem explored here is larger than any particular application domain. We are looking at civilisation-grade questions about how complex systems scale knowledge, classify reality, and manage failure.
The recurring pattern is that individual domains are extraordinarily good at reasoning after the object before them has been recognised. They are much less well equipped to question the recogniser itself, particularly where doing so threatens foundational categories of identity: What court is this? What aircraft do we actually have? What kind of operation is presently taking place?
The Russian investigation of Ural 178 is a good example precisely because it is neither stupid nor obviously unreasonable. It is technically sophisticated within its frame, and carefully hedges the suggestion that continued flight would necessarily have ended safely.
The deeper difficulty lies upstream of that analysis: category integrity under high-order uncertainty, including uncertainty about which operational mode is presently engaged.
Civilian institutions rarely have to reason explicitly at this level. Military affairs comes closer, because catastrophic degradation, incomplete information, adversarial deception and the possibility that your own representation of reality has failed are native assumptions rather than exotic exceptions.
⁂
Ural 178 is therefore an almost perfect teaching instrument. Its extraordinary terminal fact—everyone lived—forces us to examine recognition and reconstruction problems that would otherwise remain invisible. It exposes the hidden step in which a recogniser is selected before the reasoning begins.
Consider the uncomfortable counterfactual.
In principle, the crew could have cleaned up the aircraft, continued the climb and attempted a conventional recovery. The investigation suggests such continuation was physically possible under favourable assumptions. But its safe completion was not guaranteed.
Suppose they had done everything “right”.
Suppose they had followed procedure.
Suppose they had climbed away from the cornfield.
And suppose the remaining damaged propulsion had then deteriorated, leaving them without sufficient energy or a comparably benign place to terminate.
Everyone might have died.
The crew could nevertheless have been judged to have performed heroically. They had followed their training. They had executed the prescribed response. They had done everything reasonably expected of professional aviators confronted with an appalling emergency.
They could have been beyond reproach.
They pursued orthodox safety and success.
And everyone could still have been dead.
That is exactly the problem.
A governance system can produce behaviour that is procedurally correct, professionally defensible and institutionally legible—and still fail the invariant the entire system exists to preserve.
That isn’t safety.
And it isn’t success.


