When the Knob Lied: The 787 Mode Control Panel AD (2026-12-07) Through a DO-254 and ARP4761A Lens

There is a specific category of failure that ruins your afternoon as a safety engineer: the one where the system is not confused, not degraded, and not annunciating anything. It has a number. It believes the number. It flies the number. And the number is wrong because a power rail inside a knob assembly sagged. That is the 787 mode control panel, and on July 20, 2026 the FAA stopped asking politely and made 163 U.S.-registry airplanes swap the box.

1. The public record

AD 2026-12-07 (91 FR 35873, Amendment 39-23377, Docket No. FAA-2025-3426, Project Identifier AD-2025-00342-T) was published June 15, 2026 and became effective July 20, 2026. It applies to Boeing Model 787-8, 787-9, and 787-10 airplanes as identified in Boeing Alert Requirements Bulletin B787-81205-SB220004-00 RB, Issue 001, dated April 22, 2025. It is filed under ATA Code 22, Auto Flight.

The unsafe condition, verbatim from paragraph (e):

"This AD was prompted by reports of an uncommanded change to the mode control panel (MCP) selected altitude. The FAA is issuing this AD to address uncommanded changes to the MCP selected altitude. The unsafe condition, if not addressed, could result in controlled flight into terrain (CFIT) or traffic conflict, which may result in mid-air collision."

The required action is not a software load, not an inspection, not a procedure. It is a parts replacement: remove MCP part numbers 4091640-901, -902, or -903; install P/N 4091640-904; run the MCP installation test until it passes. Two work-hours of labor at $85/hour, and up to $405,000 for the part — a figure the FAA carried through to up to $66,042,710 across 163 U.S.-registry airplanes, 28 of which are on the registers of two foreign carriers. Honeywell, the MCP manufacturer, has indicated that retrofit to the -904 configuration may be covered under warranty (90 FR 51225).

The root cause is the sentence that matters, and it is in the NPRM Background section, not the final rule:

"The FAA has received operator reports indicating occurrences of an uncommanded change to the MCP selected altitude. The causes of the uncommanded change were determined to be a series of events in the software, the airborne electronic hardware, and the electrical circuits in an internal power supply for the encoders in the MCP knob selectors."

Read that as an engineer and not as a press officer. Three distinct assurance domains are named in one sentence: software (DO-178C), airborne electronic hardware (DO-254), and electrical circuits in an internal power supply — which, depending on how it was classified, may live under neither of them in any rigorous sense. The initiating physics is in the analog domain, the propagation is digital, and the manifestation is a number on a glareshield window that the autopilot then obeys.

Two procedural details from the docket are worth keeping. First, Etihad Airways asked the FAA to prohibit installation of the affected part numbers as of the effective date. The FAA declined, reasoning that "there are very few affected spares in operators' inventories because the MCP is not typically replaced in service," and that operators will most likely pull the affected unit, install a scarce new unaffected one, and return the old panel for retrofit. Second, the fix has been available since Boeing issued the alert service bulletin on April 22, 2025. The NPRM published November 17, 2025. The AD became effective July 20, 2026. That is roughly fifteen months from a released repair to a mandatory one — a normal-looking AD timeline that happens to be the exposure window for a Catastrophic-outcome failure mode.

The FAA record does not name the flights. Trade press has linked the MCP work to two in-service upsets — a United 787-8 operating UA613 out of Lagos, which returned to Lagos after an abrupt altitude excursion with injuries reported by Nigerian authorities, and LATAM LA800 Sydney–Auckland on March 11, 2024, which injured roughly 50 people (Simple Flying, FlightGlobal). I will be careful here, and you should be too: the LA800 investigation has been publicly associated with a separate seat-movement mechanism, and the FAA's own docket says only "operator reports." The engineering lesson below does not depend on which airframe did what. It depends on the FAA's stated root cause, which is on the record.

2. The standards lens

Four clauses and one classification decision.

14 CFR 25.1329, Flight guidance system. This is the governing rule, and it is more specific than people remember. 25.1329(i) requires that the flight guidance system functions, controls, indications, and alerts be designed to minimize flightcrew errors and confusion; 25.1329(l) requires that following a flight guidance system failure, the airplane be controllable and any transient not be hazardous. AC 25.1329-1C fills in the intent: the crew must be able to determine the active and armed modes and targets of the FGS at all times, and the system must not silently substitute its own targets. An uncommanded change to selected altitude is precisely the failure 25.1329 exists to prevent — not a loss of the function, but an erroneous target accepted as valid. The MCP altitude window is the primary means by which the crew knows what the autopilot intends to do. When that window is wrong, the regulation's entire monitoring premise is void.

14 CFR 25.1309 and the classification arithmetic. Take the FAA at its word: the credible outcomes are CFIT and mid-air collision. Both are Catastrophic under AC 25.1309-1B — quantitative objective on the order of ≤ 1×10⁻⁹ per flight hour, and no single failure may produce the condition. Nobody certified this function at Catastrophic without mitigation, which means the safety assessment credited something in between. Almost certainly it credited the crew: the assumption that a pilot cross-checking the MCP window and the flight-mode annunciator will catch a wrong altitude before the airplane does anything about it. That credit is not unreasonable in the abstract. It is the credit that shifts the failure condition from Catastrophic to Hazardous or Major, and with it the development assurance level of the MCP hardware and software.

ARP4754A §5.2, FDAL/IDAL allocation. Here is the structural problem. The MCP altitude select path is a single-thread function: one knob, one encoder pair, one internal power supply, one processing chain, one output to the autopilot flight director system. There is no second independent source of "what the pilot dialed." ARP4754A lets you assign a lower item development assurance level when the failure condition is mitigated by an independent member — but the mitigating member here is the flight crew reading the same display the failure corrupts. When the failing item and the monitoring channel share a display, the independence claim is thin. Two in-service upsets with injuries is the empirical answer to whether crew detection is fast enough to hold the classification down.

DO-254 and the "simple hardware" escape hatch. RTCA/DO-254 draws a line between complex electronic hardware, which needs the full design assurance lifecycle, and simple hardware, which may be verified by test alone if a comprehensive combination of deterministic tests and analyses can ensure correct functional performance under all foreseeable operating conditions with no anomalous behavior. An internal linear power supply feeding quadrature encoders is exactly the kind of item that gets classified simple, dispositioned with a bench test at nominal and worst-case corners, and never again analyzed for what its degraded output does to the digital stage downstream. The FAA's root cause puts the electrical circuits of that supply in the causal chain by name. That is what a simple-hardware classification looks like when it turns out to be wrong: no anomalous-behavior analysis was ever required of the item that produced the anomalous behavior.

The missing artifact is at the interface. A quadrature encoder does not report an altitude. It reports edges on two phase-shifted channels, and software decides that a particular edge sequence means "the pilot turned the knob one detent clockwise, add 100 feet." If the supply rail feeding the encoder LEDs or Hall elements sags, droops on a transient, or sits in a marginal band, the channels produce edges nobody's fingers created. The counting logic — whether in an FPGA under DO-254 or in code under DO-178C — has no way to distinguish a phantom edge from a real one unless someone wrote a requirement that it must. That requirement is a hardware/software interface requirement, and it is the single most under-specified class of requirement in avionics and automotive alike. ARP4754A §5.4 asks for exactly this: allocation of requirements to items, including the assumptions each item makes about the others. Nobody wrote down "the encoder channels shall be considered valid only when the encoder supply rail is within tolerance and the observed edge rate is physically achievable by a human hand."

3. A worked snippet — the FHA row, the tree, and the AND gate that was a display

The failure condition as it should have appeared in the FHA:

| ID | Function | Failure condition | Phase | Effect on airplane/crew | Classification | Objective | |---|---|---|---|---|---|---| | FHA-AFS-07 | Provide flight crew altitude target to the AFDS | Loss of MCP selected altitude (blank/invalid, detected) | All | Crew reverts to manual altitude control; workload increase | Minor | ≤ 1×10⁻³ /FH | | FHA-AFS-08 | Provide flight crew altitude target to the AFDS | Erroneous and undetected change of MCP selected altitude; displayed value equals the corrupted value | Climb / Cruise / Descent | Autopilot captures an altitude the crew did not select; vertical excursion; unrestrained occupant injury; loss of separation | Hazardous, trending Catastrophic in terminal/RVSM airspace | ≤ 1×10⁻⁷ /FH, and no single failure |

FHA-AFS-08 is the row that governs, and the distinction between it and FHA-AFS-07 is the whole discipline. Loss is cheap. Erroneous-and-undetected is expensive. The 787 MCP delivered the expensive one.

The fault tree, as the AD's root cause implies it:

                    TOP: Uncommanded change to MCP selected
                         altitude, displayed as valid
                                    |
                                  [OR]
              ----------------------+----------------------
              |                                           |
        E1: Spurious encoder                      E2: Corrupted altitude
            transitions generated                     value in AFDS output
            without knob rotation                     path (SW/AEH)
              |                                           |
            [AND]                                       [OR]
      --------+--------                          -------+-------
      |               |                          |             |
  BE1: Encoder    BE2: No validity           BE3: Latent    BE4: No range /
  supply rail     gate on encoder            state in       rate plausibility
  degrades        channel inputs             AEH counter    check on selected
  (analog PSU)    (HSI requirement           logic          altitude before
                   never written)                           output
      |
   [classified "simple hardware" -> no
    anomalous-behavior analysis performed]

                    CREW DETECTION LEG (credited in the SSA)
                                    |
                    M1: Flight crew observes incorrect value
                        in MCP altitude window and FMA
                                    |
                    *** NOT INDEPENDENT ***
                    The window displays the corrupted value.
                    The FMA reports the mode, not the target's
                    provenance. Detection latency is bounded
                    only by scan interval, not by design.

Note what happens at the AND gate under E1. Two conditions are required: a degraded rail and the absence of an input validity gate. The first is a physical fault with some rate. The second is not a fault at all — it is a permanent design state with probability 1.0. An AND gate with one input pinned at unity is an OR gate wearing a disguise, and the top-event probability collapses to the failure rate of the power supply alone. This is the single most common way fault trees flatter a design: a mitigating branch is drawn for a mitigation that was never implemented, because the requirement it would have come from was never written.

The crew-detection leg has the same disease in a different organ. It is drawn as an independent barrier. It is not independent, because the corrupted value is exactly what the barrier is asked to read.

And a Software FMEA row, for the counting logic specifically:

| Item | Function | Failure mode | Cause | Local effect | System effect | Detection | Sev | Occ | Det | AP | |---|---|---|---|---|---|---|---|---|---|---| | ENC_DECODE | Convert A/B channel edges to selected-altitude delta | Wrong data — increments target on edges not produced by knob rotation | Marginal encoder supply rail produces phantom transitions; no rail-health or edge-rate qualification of input | Selected altitude increments/decrements without crew action | AFDS captures unselected altitude; vertical excursion | None onboard; display shows corrupted value as valid | 9 | 4 | 9 | High | | ENC_DECODE | Convert A/B channel edges to selected-altitude delta | Too fast — target slews at a rate no human hand can produce | Burst of phantom edges during supply transient | Large single-step target change | Large commanded vertical rate; occupant injury risk | None | 9 | 3 | 9 | High |

A Detection rating of 9 is the honest number when the only detection mechanism in the design is a human being looking at the display that is lying to them.

4. Derived requirements (excerpt)

These are the requirements that, had they existed in the item development spec, would have made AD 2026-12-07 unnecessary. Stable IDs, traced to the tree.

| Req ID | Requirement text | Trace | Verification | |---|---|---|---| | REQ-MCP-201 | The MCP shall continuously monitor the internal supply rail feeding the knob-selector encoders. When the rail is outside its qualified tolerance band for more than 5 ms, all encoder channel transitions occurring during and for 50 ms after the excursion shall be discarded, and the selected-altitude target shall be held at its last valid value. | BE1, BE2 | Rail-injection test at the item level, sweeping supply voltage across and below the tolerance band; count phantom target changes (acceptance: zero) | | REQ-MCP-202 | The MCP shall reject encoder edge sequences implying a knob rotation rate exceeding 25 detents per second, on the basis that faster rates are not achievable by a flight crew member. Rejected sequences shall be logged as a maintenance-visible event. | BE4 | Signal-injection test with synthetic edge bursts at 10, 25, 40 and 200 detents/s; verify rejection above threshold and no false rejection below | | REQ-MCP-203 | Any change to the selected-altitude target shall be qualified by a mechanically independent knob-motion sense (detent contact or second sensing element on a separate supply) before the new target is output to the AFDS. Absence of the independent motion sense shall inhibit the target change. | BE2, E1 AND-gate integrity | Fault injection on each sensing element independently; demonstrate that no single element can command a target change | | REQ-MCP-204 | The MCP shall transmit selected altitude to the AFDS with an integrity wrapper — sequence counter plus CRC over the target value — computed downstream of the qualification logic of REQ-MCP-201 through REQ-MCP-203. The AFDS shall reject targets failing the integrity check and annunciate the rejection. | E2, BE3 | End-to-end bus test with seeded corruption; verify AFDS rejection and alert within 1 s | | REQ-MCP-205 | The MCP internal encoder power supply shall not be classified as simple hardware. A design assurance analysis shall be performed enumerating the behavior of every downstream consumer of that supply under undervoltage, overvoltage, ripple, and slow-ramp conditions, with each anomalous downstream behavior dispositioned as a failure mode in the SSA. | BE1 classification decision / DO-254 §1.6 | Analysis review; independent audit of the simple/complex classification rationale | | REQ-SSA-206 | Where the system safety assessment credits flight crew detection as a mitigating member for an erroneous-target failure condition, the assessment shall demonstrate that the crew's detection channel does not derive from the same display or data path as the corrupted value. Where it does, no independence credit shall be taken and the failure condition shall retain its unmitigated classification. | Crew detection leg / ARP4754A §5.2 | SSA review against ARP4761A independence criteria; documented rationale per credited member |

REQ-MCP-205 is the one that would have cost the least and saved the most. Reclassifying one power supply out of the simple-hardware bucket is a few weeks of analysis at design time. The alternative, priced by the FAA, is up to $405,000 per airplane and up to $66,042,710 across the U.S. fleet — before you count fifteen months of exposure and the injuries in Lagos.

REQ-SSA-206 is the one that will get argued about in your review board, because taking away crew-detection credit re-classifies failure conditions upward and re-classifies development assurance levels with them. That argument is the point. If your Hazardous stays Hazardous only because a pilot is assumed to catch it on a display the failure corrupts, you do not have a mitigation. You have a hope with a probability number attached.

5. What the headline really tells us

The headline says the FAA is making airlines replace a $405,000 control panel on 163 Dreamliners. What actually happened is smaller and much worse: a power supply nobody was required to analyze fed encoders nobody was required to validate, into counting logic nobody told to be suspicious, producing a target the display presented as authoritative and the autopilot flew. Every one of those "nobody was required to" clauses is a requirement that does not exist in a document. The missing artifact is not the -904 panel. It is the hardware/software interface specification that says what the digital side is allowed to believe about the analog side — and the SSA discipline to refuse independence credit when the monitor and the monitored share a screen.

There is no version of this failure that is exotic. Swap the words: an encoder rail on a steer-by-wire hand controller, a resolver supply on a surgical robot's joint, an ADC reference on an infusion pump's rate selector. Same tree, same missing AND gate, same display confidently showing the wrong number. The 787 got an AD because aviation has a public record. Most industries get the same defect and no Federal Register citation to read about it in.

6. Sources

— Jherrod Thomas, The Lion of Functional Safety™