NATS published its preliminary investigation report into the September 8, 2026 failure that shut down most UK departures, and it names a cause that is almost absurdly small. A request to allocate a squawk code to an ordinary flight plan landed inside a roughly one millisecond window in which a legacy software defect could corrupt the answer.
The report is dated September 16 and was released on September 18. NATS expected to handle around 8,000 flights that Tuesday. EUROCONTROL records show it handled 6,094.
AeroCorner covered the failure on the day it happened, when the cause was still unknown. This is the first technical account of it.
What the one millisecond actually refers to
The defect sat in a module of the National Airspace System, the core flight data platform that holds flight plans, matches them to radar tracks, and allocates the squawk codes aircraft transmit so controllers can tell one target from another.
At 10:00 on September 8 a valid manual request for a squawk code was made correctly, against a flight plan NATS says was entirely normal. While the system was part way through updating a value for that request, a higher priority message arrived and the squawk allocation was paused.
Switching between tasks by priority is what the system is built to do. The defect was that when it came back to the paused request, it did not resume correctly, and the output it produced was corrupt.
NATS puts the exposure window at approximately one millisecond. Had the higher priority message arrived a millisecond earlier or later, the report says, the update would have completed normally and nothing would have happened.
Why this is a hard class of bug to find
A defect that only fires when two events collide inside a one millisecond window is a race condition, and race conditions are the classic blind spot of testing. The code is correct in every run where the timing does not line up, which is almost every run. NATS says the module is legacy code and the defect was previously unknown, and that further investigation will look at whether anything else in the wider system raised the odds of hitting that window.
Two and a half hours of nothing, then a cascade
The corruption did not announce itself. Two minutes after the bad request, controllers and engineers saw the link between the London Area Control system and the NAS drop, then re-establish itself after about 45 seconds. An engineering incident was logged at 10:06 as recovered and stable, and morning health checks found no hardware fault.
What was actually happening, the report explains, is that each time the system tried to process a piece of the corrupted flight data it took too long and timed out, and the link dropped to protect both systems. As more requests touched corrupted data, the drops came faster.
At 12:32 the link dropped and the system entered a period of instability. At 13:32 it dropped for good, and London Area Control, which handles roughly 6,500 flights on a typical September day above 24,500 feet, moved to manual fallback procedures.
10:00
The trigger. A correct manual squawk code request hits the defect. Nobody knows anything is wrong.
10:02
First symptom. The LAC to NAS link drops and self-recovers in about 45 seconds. Logged as a routine engineering incident.
12:45
Passengers start to feel it. Sector entry limits are applied and UK departures are stopped. NATS marks this as the moment airlines, airports and the public are directly affected.
13:32
Link lost for good. Controllers switch to practised fallback, coordinating handovers with neighboring centers by hand.
13:38
Hard restrictions. Entry into LAC sectors capped at 30 aircraft per hour, plus arrival limits at UK airports that stop departures abroad.
15:17 to 16:09
The restart. The NAS is restarted and flight data reloaded from the LAC system.
16:09 to 18:50
Reconciliation. Nearly three hours spent resolving duplicate flight plans and code to callsign mismatches before ATC is fully restored.
19:30
Clear. All airspace restrictions lifted, about six hours after the first restriction.
Why the fix took longer than the restart
Restarting the NAS was a documented procedure, but not a local one. The NAS feeds flight data to several UK airports and to other national and international ATC units, so the restart needed coordination, and NATS wanted as few aircraft airborne as possible while it ran.
That is the part travelers experienced. Departures were stopped for roughly four and a half hours across a six hour period, and because arrivals kept outnumbering departures, airports filled up and inbound aircraft were diverted.
The restart itself ran from 15:17 to 16:09. The remaining two hours and 41 minutes went on reconciling data that had drifted out of sync while the systems were disconnected: duplicate flight plans, mismatched code and callsign pairings, and plans filed during the restriction period.
That is the recurring lesson of ATC outages. The outage is short and the cleanup of the data it corrupted is long, which is why a fault technically over by late afternoon rolled into two more days of recovery flying.
What the report says about safety
All aircraft stayed safely separated throughout, and controllers could speak to every aircraft and see it on radar for the entire incident. The link drop itself was designed behavior, intended to isolate a fault rather than let corrupted data spread. NATS also states there is no evidence of a malicious actor or cyber activity, and no link to the 2023 FPRSA failure or the radar issue in July last year.
What happens next, and who is unhappy
The permanent software fix has already been developed by the supplier and is in testing, with an engineering framework in place meanwhile to catch and escalate any further link drops quickly. NATS has committed to a full Major Incident Investigation report within 60 days of the incident, which puts it in early November.
Transport Secretary Heidi Alexander called the disruption completely unacceptable and has tasked the Civil Aviation Authority with an independent review of both the findings and NATS investment plans, according to PA Media. That review is expected to report within six months. Ryanair has renewed its call for NATS chief executive Martin Rolfe to resign.
Passengers hoping for cash already have their answer. On September 9 the CAA said the disruption counts as extraordinary circumstances, so compensation is unlikely, though airlines still owe duty of care: meals, accommodation where needed, and a refund or rerouting.
This is preliminary
NATS is explicit that the findings are based on the information available so far, that reported times may change, and that the Major Investigation could amend this report. The precise millisecond timing of the original squawk allocation request is still under investigation.
The uncomfortable part is not the millisecond. It is that the UK’s core flight data system carried an unknown defect in legacy code, and that the first warning of it, at 10:02, looked exactly like a link glitch that fixed itself.
Sources and references used for research and fact-checking.
Get the Newsletter
The latest aviation news and stories sent to your inbox.
About the Author
Tim is the owner and lead editor of AeroCorner since 2019, overseeing aviation content covering aircraft, airlines, airports, and the broader aviation industry. Through years of researching, writing, editing, and publishing aviation-focused content, he has developed extensive practical knowledge of commercial aviation and air travel. Based in Asia and a frequent traveler himself, Tim also brings firsthand passenger experience to AeroCorner’s coverage. Outside of publishing, he has also explored aviation firsthand through hands-on flight training in New Zealand.