The ILS wasn't working, but the GPS was. All major and most minor airports have approach plates/terminal procedures. Calculate the desired glide path to touchdown on the runway. Display on a MFD (multi function display) plane, glide path, runway. Proper glide path? Green backlight. Outside of margin glidepath? Yellow backlight. Fall within dangerous limits near the ground? Red backlight, engage autopilot (to go to hold position indicated by approach plates), go to full power, and disable pilot input until above safe altitude (props if you notify control via ADS-B of go-around due to human error).
http://en.wikipedia.org/wiki/Approach_plate
"Approach plates are essential for an airplane to make a safe landing during instrument meteorological conditions (IMC), such as low ceilings or reduced visibility due to fog, rain, or blowing snow. They provide specific waypoints and altitudes necessary to line an aircraft up with a designated runway for landing, as well as important navigational information, such as radio frequencies of navigational aids and required course headings, and the prescribed minimum visibility requirements to execute the approach."
http://flightaware.com/resources/airport/KSFO/procedures
Runway 28L approach plate:
http://flightaware.com/resources/airport/KSFO/IAP/ILS+RWY+28...
In this case, it clearly appears that a computer could easily have looked at the altitude, attitude, air speed, and thrust and decided with enough time to recover that the meat module was malfunctioning, and could have initiated a go around.
Also, it's pretty clear that the automation could have started yelling LOLWUT or whatever the industry jargon is for exceptionally inconsistent inputs, such as flight level change mode on final.
Plenty of aviation accidents boil down to conflicts between different automated systems, or between automated systems and pilot's senses, and there is no universal criterion for deciding which one should win.
- 0. Less control over the machine's behavior atrophies pilot's situational awareness. Boeing requires a deeper understanding of how the machine behaves and hence what's permissible.
- 1. Reduces an experienced pilot's potential recovery options.
In this case, three clowns stalled a perfectly working multimillion-dollar craft into the ground and killed a few people (it could have been significantly worse). I wouldn't let these jokers fly Flight Simulator, they're liabilities.
The computer should be able to differentiate between situations where some plausible sequence of pilot actions will result in success, and one where no such success is possible.
"Autoland systems were designed to make landing possible in visibility too poor to permit any form of visual landing, although they can be used at any level of visibility. They are usually used when visibility is less than 600 meters RVR and/or in adverse weather conditions, although limitations do apply for most aircraft—for example, for a Boeing 747-400 the limitations are a maximum headwind of 25 kts, a maximum tailwind of 10 kts, a maximum crosswind component of 25 kts, and a maximum crosswind with one engine inoperative of five knots. They may also include automatic braking to a full stop once the aircraft is on the ground, in conjunction with the autobrake system, and sometimes auto deployment of spoilers and thrust reversers."
"Autoland requires the use of a radar altimeter to determine the aircraft's height above the ground very precisely so as to initiate the landing flare at the correct height (usually about 50 feet (15 m)). The localizer signal of the ILS may be used for lateral control even after touchdown until the pilot disengages the autopilot. For safety reasons, once autoland is engaged and the ILS signals have been acquired by the autoland system, it will proceed to landing without further intervention, and can be disengaged only by completely disconnecting the autopilot (this prevents accidental disengagement of the autoland system at a critical moment). At least two and often three independent autopilot systems work in concert to carry out autoland, thus providing redundant protection against failures. Most autoland systems can operate with a single autopilot in an emergency, but they are only certified when multiple autopilots are available."
"Autoland is highly accurate. In his 1959 paper [2] John Charnley, then Superintendent of the UK Royal Aircraft Establishment's Blind Landing Experimental Unit (BLEU), concluded a discussion of statistical results by saying that "It is fair to claim, therefore, that not only will the automatic system land the aircraft when the weather prevents the human pilot, it also performs the operation much more precisely"."
I think it's less about "how much do we take away", and more about "if we automate this, will we train dangerous habits into pilots who use it?"
You don't tech you junior sysadmins to use "rm -rf /" to delete user data "because Unix prevents you from deleting files not owned by you, so it's perfectly safe!" _one day_ that sysadmin is going to be logged in as root.
I have no idea whether the pilot here was trained to let an Airbus override dangerous actions on his part or not - but if he _was_ – _that's_ something that ought to be considered for changing.
We wouldn't let a car manufacturer sell a car with the brake pedal on the right and the accelerator on the left - because no matter how diligently you tell buyers, or how prominently you point it out in the owners manual, somebody is going to mash that accelerator pedal in an emergency expecting the car to stop.
http://en.wikipedia.org/wiki/Northrop_Grumman_X-47B
The X-47B receives commands from the flight deck, but is not directly piloted. It not only can be catapulted from an aircraft carrier, fly its mission, and return with no human input, it can also autonomously on-air refuel from a tanker with no human pilot on the ground.