How a Millisecond Software Error Grounded Thousands Across the UK

A software defect that corrupted flight data in a millisecond caused mass cancellations and delays across the United Kingdom on Tuesday 8 September 2026, National Air Traffic Services said. The Guardian
The failure disrupted travel for hundreds of thousands of passengers. NATS imposed restrictions across UK airspace for six hours to allow the system to be restarted. It took more than two days to clear the backlog.
The disruption began with departures in the London area. By the evening it had spread across the UK and beyond. Early reporting during the outage put cancellations at 2,000 flights. USA Today
In its preliminary report, NATS traced the failure to a software defect in part of the National Airspace System, the subsystem that allocates codes to individual aircraft to identify flights on radar. Think of those codes like licence plates that let controllers tell planes apart. While one manual aircraft code request was being processed, another request paused it. When processing resumed, the defect produced corrupted output. That corruption then affected subsequent flight data updates.
NATS chief executive Martin Rolfe said "the issue has been identified and mitigation is in place while a permanent fix is safety tested and deployed." He said the September 2026 incident was unrelated to previous failures and dismissed speculation that military intervention had caused it. He also said "at no point during the September 2026 outage was safety in question."
The government initially gave NATS one week to investigate the systems failure that halted flights. Reuters Transport Secretary Heidi Alexander has since tasked the Civil Aviation Authority with conducting an independent review. The review will check NATS findings and investigate investment plans for resilience. Publication is expected within six months.
Airlines called for Rolfe's dismissal after the incident. It was the third major UK air traffic control failure since summer 2023, according to airline critics cited in the reporting.
The broader context here is the concentration of risk in en route data processing. A fault measured in milliseconds required hours of flow restrictions and days of schedule recovery. Downstream flight data updates depend on consistent aircraft identification, so when surveillance codes were corrupted the precautionary response was to constrain traffic, restart and validate. That protects separation standards but creates network-wide delay that airlines and airports cannot absorb without cancellations.
In my view, the credibility test will be less about the millisecond trigger than about assurance and investment. NATS points to mitigation already in place and a permanent fix under safety testing. The CAA review will test that claim independently and examine resilience spending. Airline pressure for leadership change adds a political dimension, but the structural questions concern redundancy, manual fallback procedures for code allocation, and how quickly corrupted data can be isolated. Those findings, due within six months, will shape the next negotiation over funding, accountability and contingency planning for UK controlled airspace.
Looking ahead, watch three outputs. First, the CAA terms of reference and whether they extend beyond validation of NATS findings to system architecture and procurement. Second, the safety case for the permanent fix and any interim operating constraints. Third, airline and airport recovery protocols after extended flow control, since the two-day backlog shows that restart of the technical system does not equal restoration of the schedule.


