The software fault behind the UK’s September 8 air-traffic disruption has been identified, but the investigation is not finished. NATS published a preliminary account on September 18 describing how a fleeting processing error developed into restrictions that disrupted journeys across the country and beyond.
The distinction matters for passengers and airlines seeking answers. Identifying a faulty piece of software is one task; establishing why it remained undetected, how the response worked and what should change across the system requires further examination.
Reuters reported that the incident led to around 2,000 flight cancellations. Transport Secretary Heidi Alexander called the disruption unacceptable and sought an independent review. NATS says its response maintained safety, even as the available capacity fell sharply.
How a small error spread
In its published explanation, NATS says a manual request for an aircraft identification code was paused while the system dealt with a higher-priority activity. When the original process resumed, a software defect caused corrupted output that affected later flight-data updates.
These identification codes help air-traffic systems associate an aircraft with its flight information. With less usable information available, controllers had to operate under restrictions. NATS says the affected operation was London Area Control, but restarting the National Airspace System required measures across the UK.
This explains why the geographic reach of the disruption was wider than the immediate fault. A problem in one connected part of an air-traffic system can affect the amount of traffic other parts are able to accept.
The timeline shows why recovery took hours
The preliminary investigation document, dated September 16, sets out the following sequence for September 8. It cautions that reported times remain subject to the fuller investigation.
- 10:02: a link failure was reported, followed by an apparent automatic recovery.
- 12:32: repeated losses of the connection marked the start of the major incident.
- 12:45: restrictions began limiting traffic in affected sectors.
- 15:17–16:09: engineers restarted the system and loaded flight data.
- 18:50: reconciliation of data across systems was complete.
- 19:30: all airspace restrictions had been lifted.
Restarting the system was therefore not the end of the repair. Engineers also had to reconcile information that had become inconsistent while systems were disconnected. Restoring a common, dependable picture of flight data was part of restoring operations.
Safety and reliability are different questions
NATS chief executive Martin Rolfe says safety was maintained. The company also says the passenger disruption took more than two days to clear, although its own operations returned to normal that evening.
Both statements can be true. Restricting flights can protect safe operation while leaving passengers stranded and schedules badly disrupted. A finding that aircraft remained safely separated would not, on its own, answer questions about whether the underlying failure should have been prevented.
Associated Press reported that Alexander asked the Civil Aviation Authority to check NATS’s findings and examine its investment plans and regulatory compliance. That scrutiny extends beyond accepting the operator’s explanation of the immediate defect.
ITV reported Rolfe’s statement that incorrect actions by military or civilian operators had not caused the fault. He also distinguished it from the outages in 2023 and 2025. Similar disruption for travellers does not necessarily mean an identical technical failure has happened again.
What remains unresolved
NATS says mitigation measures are in place while a permanent fix is tested. That wording should not be confused with a statement that every corrective measure has already been deployed and independently assessed.
The Guardian’s account of the response reports airline demands for compensation and a credible plan to improve resilience. It also records ministers’ question about why the issue was not found and fixed before it caused widespread disruption.
The immediate technical cause and the wider accountability questions need to be followed separately. The next useful evidence will be the fuller investigation, the regulator’s assessment and confirmation of completed corrective work. None of those outcomes should be assumed from a preliminary report alone.