An Ethical Functionality without Agency (EFA) Autopsy of the Boeing MCAS Failure
Summary of the events: Two Boeing 737 MAX aircraft were lost (Lion Air Flight 610 (JT610) and Ethiopian Airlines Flight 302 (ET302))…
An Ethical Functionality without Agency (EFA) Autopsy of the Boeing MCAS Failure

Image: Bloomberg.com
Summary of the events: Two Boeing 737 MAX aircraft were lost (Lion Air Flight 610 (JT610) and Ethiopian Airlines Flight 302 (ET302)), claiming 346 lives. DoJ wrote that “Boeing’s employees chose the path of profit over candor by concealing material information from the FAA concerning the operation of its 737 Max airplane and engaging in an effort to cover up their deception.”
The MCAS disaster was not a single failure, but a cascading collapse across the entire E7 Reference Architecture stack, proving the necessity of the EFA framework from the hardware up to the moral layer.
From a policy/architecture viewpoint, this analysis shows how EFA would keep humans in control. In MCAS, EFA recommendations are proactive, not reactive. Any actions already taken that are echoed in this article are coincidental; the FAA RTS report was written in 2020.
Structure of article: E7 Layer/MCAS Failure Analysis/How EFA Would Have Prevented It
L7: Human Sovereignty
FAILURE: Pilots were unaware of MCAS’s existence and authority. The system asserted control over the aircraft against the explicit, repeated commands of the trained human operators. They were actively fighting the system (repeated manual trim inputs) while lacking knowledge of why it was opposing them. This is the ultimate violation of human sovereignty.
EFA MANDATE: The system would be classified as a Class H (High-Stakes) tool. The EFA playbook mandates that human operators must have ultimate authority and be fully aware of any automated system’s operational envelope. The “Latency Kill Zone” concept would have been invoked, guaranteeing a procedural and technical means for the pilot to permanently disable MCAS.
L6: System Orchestration
FAILURE: MCAS was a lone, dominant agent. There was no “panel of experts.” It relied on a single, uncorroborated input source.
EFA MANDATE: A “Ring of Fire” architecture would be mandatory. RoF applies analogously to any decision logic. The system would ingest data from multiple Angle of Attack (AoA) sensors. Disagreement between sensors would not result in action; it would immediately void the automated recommendation and escalate to the human pilot for a final decision.
L5: Runtime Enforcement Layer (REL)
FAILURE: There was no independent overseer. Once triggered, MCAS could re-trigger itself repeatedly, creating a deadly feedback loop. The system had no self-awareness of its own dangerous, repetitive behavior.
EFA MANDATE: A Runtime Enforcement Layer is the core technical control for this. The REL would monitor MCAS’s commands. It would have simple, hard-coded rules like: “IF MCAS attempts to trim nose-down > X times in Y seconds, OR IF pilot input is consistently contrary, THEN kill the MCAS process and flag for human-only control.”
L4: Model/Logic
FAILURE: The model was designed to be overly aggressive and could be activated by a single sensor’s input tipping past a threshold. The logic did not account for a faulty sensor providing erroneous but “valid” data.
EFA MANDATE: The model’s logic would be subject to the R/M/H classification. For a Class H system, logic that can be triggered by a single point of failure would be explicitly forbidden. The “Evidence Pack” would require documentation proving robustness against sensor failure.
L3: Data & Representation
FAILURE: The system’s entire world-view was built upon a single AoA sensor. When this sensor failed, the system’s “reality” was fatally flawed, but it acted with complete certainty.
EFA MANDATE: The framework’s emphasis on “Information Attrition” is key. Relying on one sensor is the ultimate form of information attrition. EFA would mandate data redundancy as a baseline requirement for any system above Class R (Routine).
L1/L2: Hardware/Infra
FAILURE: The second AoA sensor was available, but the software to use it as a cross-check was sold as an optional extra. The hardware was not configured for resilience by default.
EFA MANDATE: For a Class H system, the full suite of available hardware sensors would be non-negotiable. The configuration would be dictated by the safety requirements defined at the upper layers, not by commercial incentives.
The Human Element: The Missing HEAR
Most importantly, the MCAS saga reveals a catastrophic diffusion of moral responsibility. Who was the Human Ethical Agent of Record (HEAR)? Who was the single, named individual accountable for the decision to hide the system from pilots, to rely on one sensor, to make the safety feature optional? The answer is no one, and everyone.
EFA framework makes this impossible. It forces an organization to name the HEAR, who must sign off on the Moral Chain of Custody and the Evidence Pack, especially for a Class H system.
References
EFA 4.1 Reference Edition: **https://zenodo.org/records/18368267**
EFA E7 Reference Architecture: **https://zenodo.org/records/18304066**
EFA 1.2 Playbook: **https://zenodo.org/records/18390725**
**https://www.faa.gov/sites/faa.gov/files/2022-08/737_RTS_Summary.pdf**
**https://humanfactors.arc.nasa.gov/publications/Analyses_Boeing_737MAX.pdf**
메타데이터
- post_id
- dfaa9eaf0370
- slug
- an-ethical-functionality-without-agency-efa-autopsy-of-the-boeing-mcas-failure-dfaa9eaf0370
- url
- https://medium.com/@rupp.charles/an-ethical-functionality-without-agency-efa-autopsy-of-the-boeing-mcas-failure-dfaa9eaf0370
- canonical_url
- https://medium.com/@rupp.charles/an-ethical-functionality-without-agency-efa-autopsy-of-the-boeing-mcas-failure-dfaa9eaf0370
- author_url
- https://medium.com/@rupp.charles
- status
- ok
- fetched_at
- 2026-06-20 20:29:01