Scope: This assessment examines the September 2026 flydubai cockpit attack and the reported foreign-aircrew disclosure in Israel, comparing the security implications for Israel, the United States, the European Union, Italy, France, Germany, the United Kingdom and Middle Eastern aviation authorities, with an outlook to October 2031.
Executive Summary / BLUF
The flydubai incident raises an international national-security question: how authorities detect and stop a threat from someone already authorised to operate an aircraft.
On 3 October 2026, the UAE Attorney-General stated that the co-pilot of flight FZ1073 had attempted a terrorist act, attacking the captain and attempting to take control of the aircraft. Investigations remained ongoing. Emirates News Agency
The supplied 1,240-aircrew figure, its reporting period and the asserted Iran–Iraq–Syria breakdown could not be established from a public official record retrieved for this assessment.
The United States has explicit requirements connecting approved master crew lists, advance flight manifests and consequences for discrepancies. European jurisdictions combine common aviation-security standards with national personnel checks. These provisions establish controls; they do not establish their effectiveness in every case.
The central policy requirement is an auditable connection between intelligence, personnel approval, actual crew assignment and the authority to prevent a departure or entry.
Nationality can inform lawful risk assessment, but neither a foreign passport nor the absence of diplomatic relations establishes individual terrorist intent.
Aviation security depends on the decision that reaches the aircraft
Israel’s reported foreign-aircrew admissions, disclosed on 6 October 2026, expose a decision problem with consequences well beyond its borders: governments can approve an airline, facilitate a crew member’s entry and still leave uncertainty over the person exercising operational access. The governing test is whether relevant information produces a timely, enforceable and reviewable decision about that individual. Citizenship may identify difficulties in obtaining records; it cannot resolve them. The US crew-list framework, European national clearance arrangements and destination-specific airline procedures distribute responsibility across institutions whose information and powers differ. When those arrangements fail, the result can be continued access by an unsuitable person or interruption of legitimate operations. Airlines, passengers and public authorities then absorb different parts of a cost that neither additional paperwork nor a blanket restriction necessarily removes.
Nationality cannot carry the evidential burden
The 6 October 2026 disclosure reported by The Times of Israel justifies scrutiny of Israel’s foreign-crew decisions, but it does not establish that every admission was unlawful or that every individual presented a threat. An accountability review must connect the applicable requirement to the information available, the decision taken and its implementation. Without that connection, an admission count can establish the scale of a question while leaving its substance unanswered.
Israel’s Aeronautical Information Publication places an Aviation Security Operations Centre review within foreign commercial operator approval. Its separate crew-entry provisions allow documentary facilitation under specified conditions while preserving compliance with security instructions. Neither publication reconstructs every individual foreign-crew assessment. Treating operator permission or facilitated entry as proof of complete personnel assurance would therefore exceed the published record.
The US framework makes the separation more visible. Under 19 CFR 122.49c, covered operations depend on TSA-approved personnel lists; 19 CFR 122.49b connects information to the actual flight. Immigration examination remains a further decision. The analytical advantage is identifiable responsibility at successive stages. The limitation is that an approved identity must still correspond to the person operating when circumstances or assignments change.
The figures identify scale without establishing culpability
The reported Israeli figure is 1,240 aircrew from countries without diplomatic relations over the preceding year. It is not a count of security failures, and the public account does not supply the individual decision records necessary to calculate one. The distinction matters politically: a large admission population can support an audit without supporting a finding against that entire population.
The Commission’s aviation-security report records approximately 9,200 reported cyber incidents affecting aviation stakeholders worldwide in 2025. That is not an insider-attack series. Its significance is the breadth of the information and service dependencies exposed to disruption. The same report describes the Collins Aerospace MUSE attack, after which affected European airports resorted to manual processing and experienced delays and cancellations.
EASA’s March 2025 ground-handling explanation identifies more than 300,000 workers at EU airports and estimates that auditing can reach as many as 600 audits a year for one provider serving 100 stations. These figures expose the difference between administrative intensity and coherent oversight. Multiplying examinations of the same organisation does not necessarily establish who must execute a restriction or confirm a correction.
The monetary consequences are more definite where passenger eligibility is established. EU cancellation compensation can reach €250, €400 or €600 per eligible passenger under the applicable categories and conditions; corresponding UK cancellation amounts include £220, £350 and £520. These liabilities are distinct from refunds and passenger care. They cannot be aggregated into an incident loss without bookings, eligibility decisions and actual expenditure.
A restriction must reach the organisation controlling access
The Commission’s account of the MUSE disruption shows how a shared service failure can affect several airports. The personnel-assurance implication is conditional but direct: if identity, restriction or acknowledgement records become unreliable, the authority may lose the evidence needed to permit access. Restoring the service does not itself establish that its information is trustworthy.
INTERPOL’s Stolen and Lost Travel Documents database illustrates another boundary. It checks whether a document has a reported adverse status; its records depend on submissions by the issuing country. A negative search does not establish occupational suitability or absence of adverse intelligence. Recording what each check actually answers is therefore more useful than an unexplained declaration that a person has been cleared.
The TAP Portugal judgment concerning an unexpected co-pilot death supplies the commercial mechanism. The remaining crew declared itself unfit, and a replacement crew had to travel from Lisbon to Stuttgart. The Court treated unexpected absence through illness or death as inherent in normal airline activity. That reasoning cannot automatically determine a government security prohibition, but it demonstrates why the actual cause of cancellation and the availability of replacement personnel matter.
Under the US foreign-carrier security-programme rules, TSA can impose an emergency amendment effective on receipt. Its effectiveness then depends on implementation by the carrier. An airline reserve arrangement can reduce the resulting interruption only when the substitute personnel satisfy the operational and destination requirements; staffing flexibility cannot override the restriction.
Legal authority constrains both disclosure and exclusion
GDPR Article 10 restricts processing of criminal-conviction and offence data to official-authority control or legally authorised arrangements with safeguards. The Law Enforcement Directive separately governs transfers within its scope. The European Data Protection Board’s guidance makes clear that general cooperation language does not necessarily establish the safeguards required for a particular transfer. An airline cannot resolve that legal boundary by assembling an unrestricted international personnel file.
France’s Code des transports, Germany’s Aviation Security Act and Italy’s ENAC Circular SEC-010 provide different instruments for changing access through clearance decisions, subsequent information and credential management. Their common policy implication is that initial approval must remain connected to later decisions. An employer’s credential administration cannot substitute for the competent public assessment; the assessment cannot substitute for removing access.
The UK CAA’s overseas-record guidance addresses genuine inability to obtain a foreign certificate through exceptional supporting arrangements. That permits a decision process, but alternative evidence must retain its limitations. Treating an unavailable record as a clean history would remove the distinction the procedure exists to manage.
Passenger law imposes a separate constraint. EU guidance preserves assistance and care even where extraordinary circumstances remove compensation entitlement. US refund rules can apply to cancellation regardless of its reason when the passenger declines the relevant alternatives. A justified security intervention can therefore leave the carrier with continuing obligations. Governments and airlines need a disruption plan alongside the restriction.
International cooperation needs an instruction that travels
ICAO distinguishes the Aircraft Operator Security Programme from Supplementary Station Procedures addressing requirements imposed by other states. That distinction locates the international dependency: a destination’s requirement must enter the carrier’s operational arrangements. Agreement between governments is incomplete if the instruction never reaches the organisation assigning crews or controlling access.
The UAE’s CAR Part VII establishes personnel-assurance and international-cooperation duties. The published Estonia–UAE and Spain–Qatar aviation agreements also provide consultation and urgent-action mechanisms. These instruments demonstrate channels for action; they do not demonstrate an unrestricted common intelligence system. Their value must be assessed through the communication and execution of a specific requirement.
An assurance arrangement supporting ICAO’s Aircraft Operator Security Programme should identify what was assessed, what remains unavailable and how a changed decision will be communicated. The carrier may need an authoritative instruction concerning an identified employee without receiving the underlying intelligence file. Such an arrangement preserves the distinction between protected evidence and operational action, subject to the applicable legal basis and safeguards.
ICAO’s Global Aviation Security Plan provides implementation checkpoints, while the EU ground-handling framework introduces defined future requirements. Neither should be converted into an assurance that foreign-crew information is complete. The relevant evidence is whether oversight identifies defects, corrective action repairs them and the receiving organisation can demonstrate the result.
The next two years will expose who carries unresolved responsibility
During the next 12–24 months, ICAO’s 2027 checkpoint and the EU ground-handling framework’s application from 27 March 2028 provide concrete opportunities to examine implementation. The Council’s July 2026 passenger-rights decision also requires attention to its delayed commencement. Authorities and carriers must distinguish obligations already applicable from provisions entering the operational timetable later.
For Israel, the immediate requirement is a competent account of the decisions implicated by the disclosure, distinguishing the scope of eAIP GEN 1.2 and GEN 1.3 from the individual assessments. For European authorities and Middle Eastern operator states, the corresponding test is execution of destination requirements and subsequent restrictions or corrections. For the United States, it is coherence between approved personnel information and the actual operation. These are observable outputs, rather than a promise that another system will solve the problem.
Implementing the proposed package alongside CAR Part VII and the applicable European and US requirements, airlines would carry the cost of qualified replacement capacity, secure operational integration and continuing passenger obligations. Authorities would carry the cost of protected review, lawful exchange and enforcement. Inaction would leave passengers bearing interrupted journeys, carriers absorbing avoidable disruption and governments unable to establish whether their decisions changed access. The defensible choice is to fund and verify those connections while retaining targeted restriction when the evidence warrants it.
Navigational Index
Pillar One — The Incident and the Security Baseline
- Chapter 1: FZ1073, the reported Israeli disclosure and the verified official record.
- Chapter 2: Insider access, personnel assurance and the limits of physical security.
Pillar Two — National Authorities and International Dependencies
- Chapter 3: Israel and the United States: crew approval, intelligence and border control.
- Chapter 4: European Union, Italy, France, Germany and the United Kingdom.
- Chapter 5: Middle Eastern carriers, departure states and international cooperation.
Pillar Three — Decisions, Accountability and Strategic Outlook
- Chapter 6: Cross-border information failures and commercial disruption.
- Chapter 7: Scenarios and observable indicators, 2026–2031.
- Chapter 8: Policy options and final net assessment.
Master Abstract
An authorised insider changes the security problem
The incident is relevant to national security beyond Israel because an aircraft’s security depends on decisions made across several jurisdictions before it reaches its destination. Recruitment, licensing, personnel checks, flight assignment, departure authorisation and destination-state assessment are separate functions. An individual can satisfy one requirement while remaining unsuitable under another. The analytical danger is to treat a valid professional credential, an accepted crew manifest or permission to cross a border as a complete security assurance.
The official record establishes a serious event involving authorised cockpit personnel. Flydubai confirms that FZ1073, operating from Dubai to Tel Aviv on 30 September 2026, experienced a flight-deck altercation and diverted safely to Tabuk, Saudi Arabia. Its published updates also record the temporary suspension of Israel services. The UAE Attorney-General subsequently described the co-pilot’s conduct as an attempted terrorist act while reserving final findings on circumstances, motives and links. Together, these statements support an assessment of an aviation insider threat; they do not establish an Iranian direction, a wider terrorist network or the complete sequence of institutional failures. news.flydubai.com
The reported Israeli number requires a defined denominator
The supplied assertion combines several propositions that must be assessed separately: a total of 1,240, a period described as “this year,” citizenship in particular countries, entry into Israel, and an implied failure of security scrutiny. A public official dataset or parliamentary disclosure establishing those elements was not retrieved. The figure therefore remains a proposition requiring official confirmation rather than the quantitative foundation of this assessment.
Even if confirmed, the number would not, by itself, measure a security breach. It must distinguish unique individuals from repeated arrivals; pilots from cabin crew; operating crew from personnel travelling as passengers; and authorised exceptions from entries contrary to applicable rules. It also needs the total number of relevant crew arrivals, the checks performed and the decisions taken. Without those definitions, neither a failure rate nor a valid comparison with Europe, the United States or Middle Eastern states can be calculated.
The same discipline applies to diplomatic categories. “No diplomatic relations,” “hostile state,” “restricted nationality” and “individual security concern” are different classifications. A government may impose additional scrutiny under its applicable law, but the assessment of that scrutiny must examine what information was available, which authority received it and whether it could change the flight assignment.
The United States connects personnel approval to flight operations
The American framework provides a concrete comparison. Under 19 CFR §122.49c, covered carriers must submit master crew information; the initial list must be transmitted at least two days before a covered flight. TSA reviews the lists and identifies persons who must be removed. Additions or changes generally require transmission at least 24 hours before the relevant flight, subject to the regulation’s exceptions and superseding TSA provisions. ecfr.gov
Under 19 CFR §122.49b, covered arrival and overflight crew manifests generally must be transmitted at least 60 minutes before departure. Crew must appear on the previously submitted master list. Discrepancies can result in denied departure clearance, diversion or denied entry into US territorial airspace; late manifest changes require TSA approval before departure. ecfr.gov
The analytical significance is the connection between a personnel decision and an operational consequence. This is a documented control architecture, not proof that the United States would necessarily have detected the FZ1073 suspect. Detection still depends on identity accuracy, relevant information and timely action.
Europe has common standards and national implementation
The European Commission identifies Regulation (EC) No 300/2008 as the common aviation-security framework, supplemented by detailed implementing measures. Member states must designate a competent authority and establish national security and quality-control programmes; operators must implement their own security programmes. Staff recruitment and training form part of the common standards. European Commission
For Europe, the decision question is whether these arrangements translate information about an individual into an enforceable restriction on access or employment—and whether equivalent assurance exists for foreign operating crews. The existence of a domestic personnel-checking regime cannot automatically be extended to every visiting foreign pilot.
Italy. ENAC’s Circular SEC-010, dated 27 January 2022, requires enhanced background checks and security training for the covered national-operator personnel obtaining a Crew Identification Card. It assigns the enhanced check to the State Police’s Border Police office and provides for refusal where the result is negative. The circular’s scope is national operators; it does not demonstrate identical Italian checks for every foreign airline’s visiting crew. Italy’s audit priority is therefore the interface between domestic credential assurance and foreign-carrier oversight. enac.gov.it
France. The Transport Code provides for prefectural personnel authorisation and permits suspension or withdrawal where conduct is incompatible with state security, public safety or the activity concerned. It also allocates elements of enhanced background verification between public authorities and employers and requires renewal of those measures at intervals not exceeding 12 months. These provisions establish responsibilities for the covered categories, without proving that every foreign operating crew member undergoes the same process. Légifrance
Germany. Section 7 of the Aviation Security Act, LuftSiG, provides reliability checks for specified personnel categories, consultation with police and security bodies, and notification duties when relevant information emerges after approval. The policy strength is the ability to revisit reliability rather than regard clearance as permanent. Its actual effectiveness depends on information reaching the competent authority and producing timely consequences. Einzelnorm
United Kingdom. CAA guidance distinguishes criminal-record checks from national-security vetting and requires a separate criminal-record certificate even where an Accreditation Check or Counter Terrorist Check is required. Overseas certificates cover countries where the applicant resided continuously for at least six months during the previous five years. Guidance also addresses exceptional cases where credible official records cannot be obtained. The resulting audit question is how such exceptions are assessed and documented within the applicable role’s requirements. UK Civil Aviation Authority
Israel needs the decision trail behind the arrivals
For Israel, the immediate requirement is to establish who authorised the relevant operations and on what evidence. The reported nationality count cannot answer whether crew information arrived too late, whether it was incomplete, whether a warning existed, whether an exception was authorised or whether agencies disagreed about responsibility.
Those explanations imply different remedies. A missing-information problem requires better collection; an unprocessed-warning problem requires escalation and accountability; a last-minute substitution problem requires renewed approval of the actual crew. A general prohibition may be quicker to announce, but it cannot resolve an unidentified failure mechanism.
The decisive Israeli record would connect the applicable foreign-crew rules to actual manifests, screening decisions, exception approvals and operational assignments. That would permit an assessment of the reported arrivals without treating all foreign nationals as security failures.
Middle Eastern states occupy different roles
The Middle East cannot be assessed as a single security jurisdiction. In this case, the UAE’s official record establishes an investigation by its prosecution authorities, coordination with its aviation regulator and a jurisdictional claim based on UAE aircraft registration. Saudi Arabia was the state where the aircraft landed after diversion. These are distinct responsibilities within the same event. Emirates News Agency
For other regional authorities—including Oman and Qatar—the appropriate comparison requires their own current personnel rules, information-sharing arrangements and enforcement records. The retrieved official evidence does not support ranking their effectiveness or attributing a specific failure to them.
The regional policy issue is whether a warning or adverse decision in one jurisdiction can be identified, authenticated and acted upon when a person seeks aviation employment or operates elsewhere. This is an analytical dependency, not a finding that such a warning was transmitted or ignored in the present case. Any proposed exchange mechanism must identify competent recipients, permissible data, response deadlines and the operational effect of an adverse assessment.
Key Evidence Table
| Indicator | Value/status | Reference date | Definition/scope | Issuer | Exact source |
|---|---|---|---|---|---|
| FZ1073 incident | Flight-deck altercation; safe diversion to Tabuk | 30 September 2026 | Dubai–Tel Aviv flight; airline account | flydubai | Updates on FZ 1073 DXB-TLV on 30 September 2026. news.flydubai.com |
| Terrorism assessment | Attorney-General stated that the co-pilot attempted a terrorist act; investigation ongoing | 3 October 2026 | Official investigative position, not final adjudication | UAE Attorney-General, through WAM | Planning, attempted terrorist act behind flydubai flight FZ1073 incident. Emirates News Agency |
| Israeli aircrew total | Supplied figure of 1,240 not established from a retrieved public official record | Period unresolved | Unique persons versus arrivals, nationality breakdown and checks unresolved | Official issuing body not established | Parliamentary disclosure or administrative dataset required |
| US master crew lists | Initial submission ≥2 days; additions/changes generally ≥24 hours | eCFR displayed current through 6 October 2026 | Covered commercial operations; exceptions and superseding provisions apply | CBP/TSA regulatory framework | 19 CFR §122.49c. ecfr.gov |
| US flight crew manifests | Generally ≥60 minutes before departure | Current text retrieved 8 October 2026 | Covered arrivals and overflights; special cases apply | CBP/TSA regulatory framework | 19 CFR §122.49b. ecfr.gov |
| Italian crew credentials | Enhanced check and security training required for covered national-operator personnel | 27 January 2022 | Crew Identification Card procedure | ENAC | Circular SEC-010, §§1 and 5. enac.gov.it |
| French enhanced checks | Renewal intervals ≤12 months for covered measures | Applicable text retrieved 8 October 2026 | Personnel categories specified by the Transport Code | French Transport Code | Article R6342-35. Légifrance |
| German reliability checks | Initial checks and subsequent relevant-information duties | Text retrieved 8 October 2026 | Categories specified in §7 | German legislation | LuftSiG §7. Einzelnorm |
| UK overseas criminal records | Five-year residence history; six-month continuous-residence threshold | Guidance retrieved 8 October 2026 | Applicable regulated aviation background-check requirements | UK CAA | Criminal record checks. UK Civil Aviation Authority |
These are different controls with different legal scopes. They cannot be converted into a country security ranking.
Competing Explanations and Indicators
The official record supports the occurrence and official characterisation of the attack, but does not establish which personnel-assurance failure enabled it. The following are investigative alternatives, which may overlap.
| Possible explanation | Record that would support it | Record that would weaken it |
|---|---|---|
| Relevant information existed but did not reach the decision-maker | Timestamped warning held by one authority, absent from the approving authority’s file | Evidence that the competent authority received and assessed it |
| Information reached the authority but did not change the decision | Recorded adverse information followed by approval without an adequate documented resolution | A lawful, evidenced resolution or proof that the information concerned another person |
| The actual crew differed from the approved assignment | Roster or manifest changes without renewed approval | Matching approved roster, final manifest and operating crew |
| Required checks were completed but did not identify the threat | Complete, authentic check records with no relevant adverse information then available | Missing checks, inaccurate records or overlooked information |
Principal Gaps and Watch Indicators
Israeli disclosure. The consequential missing record is an official release defining the 1,240 figure, reference period, citizenship categories, crew functions and authorisation status. Publication would determine whether the issue concerns lawful entries, unauthorised exceptions, repeated movements or a broader screening deficiency.
FZ1073 investigation. Final prosecutorial and technical findings are needed to establish planning, links and the sequence of personnel decisions. The UAE Attorney-General’s 3 October statement expressly left those enquiries ongoing. Emirates News Agency
Operational implementation. Useful indicators include whether final crew assignments match approved lists, whether late changes trigger renewed checks and whether adverse decisions reach the operator before departure. These are proposed audit measures, not reported performance statistics.
Cross-border assurance. The relevant evidence is a documented procedure for communicating adverse personnel information and confirming receipt, assessment and action. An agreement’s existence alone would not establish effective implementation.
Proportionality and continuity. Any new restrictions should be assessed against their demonstrated security effect, the availability of cleared replacement personnel, operational disruption and the ability to correct mistaken identity or inaccurate records. Restrictions can reduce exposure under specified conditions; their effectiveness cannot be inferred from their severity.
Aviation Insider Threats: A National Security Test Beyond Israel
National security depends on connecting personnel intelligence, crew approval and the actual flight assignment to an enforceable operational decision.
Coverage: Israel · United States · European Union · Italy · France · Germany · United Kingdom · Middle East. Strategic outlook: October 2026–October 2031.
The verified event and the unresolved count
Confirmed airline account Official investigative assessment Open official record30 September 2026: flydubai confirms a flight-deck altercation aboard FZ1073, Dubai–Tel Aviv, and a safe diversion to Tabuk, Saudi Arabia. Its updates also record suspension of Israel services. flydubai: FZ1073 updates .
3 October 2026: the UAE Attorney-General stated that the co-pilot attempted a terrorist act, attacking the captain and attempting to take control of the aircraft. Investigation of circumstances, motives and links remained ongoing. WAM: Attorney-General statement .
Three distinct control layers
An analytical relationship diagram: these functions must connect, but one approval does not establish completion of the others.
- Personnel suitability Identity, relevant background information and reassessment when new information emerges. National rules differ.
- Actual flight assignment The operating crew must match the applicable approval and manifest. Late substitutions need the required review.
- Border and airspace decision Permission to enter or operate must reflect applicable requirements. Entry permission alone does not prove full personnel assurance.
Interpretation: conceptual layers, not measured security performance. Depth, colour and geometry carry no quantitative scale. Evidence anchors: US 19 CFR §§122.49b–c; ENAC SEC-010; German LuftSiG §7; sources below.
United States: approval linked to operations
-
≥2 days
Initial master list
Initial transmission before a covered flight. TSA reviews the list and identifies persons to be removed.
-
≥24 hours
Master-list additions or changes
Transmit new or changed crew information before the relevant covered flight.
-
≥60 minutes
Flight-specific crew manifest
Generally before departure for covered arrivals and overflights. Late changes require TSA approval.
Master-list discrepancies can lead to denied departure clearance, diversion or denied entry into US territorial airspace. These are regulatory controls, not proof of guaranteed detection.
Unit: minimum advance notice before the relevant flight/departure. Equal-sized blocks show procedural relationships, not proportional elapsed time. Exceptions and superseding TSA provisions apply. Sources: 19 CFR §122.49c and §122.49b ; current text reviewed 8 October 2026.
Jurisdiction and evidence table
Different legal scopes prevent a valid country security ranking. Audit questions below are analytical proposals, not findings of non-compliance.
| Jurisdiction | Documented baseline | Scope or evidence limit | Priority audit question |
|---|---|---|---|
| Israel | Reported 1,240-aircrew disclosure remains an open official-record question in this assessment. | Period, nationality breakdown, unique persons and authorisation status unresolved. | Who received, assessed and approved the actual crew information? |
| United States | TSA-approved master lists and advance flight manifests. 19 CFR §122.49c ; §122.49b . | Covered operations, exceptions and alternative TSA procedures; effectiveness not inferred. | Does a crew substitution trigger the applicable renewed approval? |
| European Union | Common standards, national competent authorities and operator security programmes. European Commission: Aviation Security . | Common standards do not demonstrate identical national implementation. | How does relevant personnel information become an operational restriction? |
| Italy | Enhanced checks and training for covered national-operator Crew Identification Cards. Border Police perform the check. ENAC SEC-010, 27 Jan 2022, §§1 and 5 . | National-operator credential procedure; not evidence of identical checks on all visiting foreign crew. | How is foreign-carrier crew assurance connected to domestic oversight? |
| France | Prefectural authorisation and suspension powers; covered enhanced-check measures renewed within 12 months. Transport Code, R6342-19–20 and R6342-31–35 . | Applies to specified personnel categories; cannot be assumed for every foreign operating crew. | Are adverse findings translated promptly into suspension or refusal? |
| Germany | Reliability checks and duties to report subsequently emerging relevant information. LuftSiG §7 . | Statutory personnel categories; duties alone do not prove timely enforcement. | Does new information reach the competent authority and change access? |
| United Kingdom | Separate criminal-record and security-vetting requirements; overseas records cover qualifying residence in the previous five years. CAA: Criminal record checks . | Role-specific requirements; exceptional unavailable-record cases require separate assessment. | How are unavailable foreign records and documented exceptions evaluated? |
| UAE / Middle East | UAE prosecution investigated FZ1073; the aircraft diverted to Saudi Arabia. WAM, 1 Oct 2026 . | Distinct jurisdictions; no supported comparative effectiveness ranking for UAE, Saudi Arabia, Oman or Qatar. | Can relevant cross-border warnings be authenticated, received and acted upon? |
Reference cut-off: 8 October 2026. Legal duties, investigative assertions and analytical questions are distinct evidence categories.
What the official decision trail must resolve
These explanations may overlap. They identify records to examine; they do not attribute a proven failure in FZ1073.
Information did not reach the decision-maker
Examine timestamped warnings, recipient records and the approving authority’s file. A warning held elsewhere is not evidence that the responsible authority received it.
Information arrived but did not change the decision
Examine the adverse information, assessment, documented resolution and approval. Verify identity matches before drawing conclusions.
The actual crew differed from the approved assignment
Compare the approved roster, subsequent substitutions, final manifest and operating crew. Check whether required renewed approval occurred.
Required checks were completed but did not identify the threat
Examine authentic check records and information available at the time. Distinguish an undetected threat from an omitted check or overlooked warning.
Pillar One — The Incident and the Security Baseline
Evidence cut-off: 8 October 2026. Reported disclosures, official investigative statements and completed investigation findings are identified separately.
Chapter 1: FZ1073, the reported Israeli disclosure and the verified official record
FZ1073 makes the security of authorised flight personnel a concrete national-security question. The central issue is whether the organisations granting professional status, operational access and destination approval can identify a material concern and act before departure.
The Israeli disclosure adds a second question: how much confidence can a destination state place in foreign personnel checks when diplomatic relations, access to records or intelligence cooperation are limited? Answering that requires examining the underlying admission decisions, rather than treating a nationality count as a measurement of dangerous individuals.
1.1 The incident: what the public record establishes
The available record developed in stages. An airline’s initial operational account, a prosecutor’s subsequent assessment and a final judicial finding carry different evidentiary weight.
| Date | Source and institutional role | Publicly established position | Remaining evidentiary limit |
|---|---|---|---|
| 30 September 2026 | flydubai, aircraft operator | FZ1073, travelling from Dubai to Tel Aviv, experienced a flight-deck altercation, diverted to Tabuk and landed safely. Other flydubai crew travelling onboard intervened. | The operator’s initial account did not establish motive. |
| 1 October 2026 | UAE Attorney-General | A specialist prosecution team was established, working with the GCAA and relevant authorities. Its remit included motives, terrorist links and prior planning or direction. | Opening those lines of inquiry did not establish their outcome. |
| 3 October 2026 | UAE Attorney-General, through WAM | Investigators described an attempted terrorist act involving an attack on the captain with a crash axe and an attempt to take control. | Investigation of circumstances, motives and possible links remained ongoing. |
| 6 October 2026 | Times of Israel, reporting leaked remarks from a closed Knesset hearing | Approximately 1,240 aircrew from countries without diplomatic relations with Israel reportedly entered Israel over the past year. | The article does not publish the underlying administrative dataset. |
Sources: flydubai — Updates on FZ1073; WAM — Attorney-General orders investigation, 1 October 2026; WAM — Planning of attempted terrorist act, 3 October 2026; Times of Israel — Reported Israeli disclosure, 6 October 2026. news.flydubai.com
The prosecutor’s 3 October statement materially strengthens the basis for discussing terrorism. It remains an investigative statement; it does not establish a conviction, an external sponsor or a wider organisation. Those propositions require their own evidence. WAM — Official investigative statement. Emirates News Agency
The safe landing also needs careful interpretation. flydubai credits intervention by other crew travelling onboard. Analytical inference: their presence contributed to recovery, but the public account does not establish that an equivalent recovery capability is routinely available on comparable flights. A successful intervention should therefore prompt examination of staffing and recovery arrangements, without assuming they constitute a dependable preventive control. flydubai — Operational account. news.flydubai.com
1.2 The Israeli figure: its significance and its boundaries
The Times of Israel article is a relevant, attributable report. Published on 6 October 2026, it cites Hebrew-media reporting of leaked remarks from a closed Foreign Affairs and Defense Committee meeting. Its stated period is “over the past year”, which differs from a calendar-year-to-date count. The linked article does not provide an Iran–Iraq–Syria breakdown. Times of Israel — Some 1,240 aircrew reportedly entered Israel. The Times of Israel
| Element | What can be retained | What needs the underlying record |
|---|---|---|
| Reported scale | Approximately 1,240 aircrew | Whether the total counts unique people, entries or another administrative unit |
| Population description | Personnel from countries without diplomatic relations with Israel | Citizenship categories, dual nationality and country totals |
| Reporting period | The preceding year | Exact start and end dates |
| Security relevance | A substantial population for an assurance audit | Screening coverage, exceptions and adverse findings |
| Committee context | Reported remarks from a closed hearing | An authorised transcript, published findings or administrative confirmation |
Analytical assessment: the figure justifies a targeted review of how Israel assessed these personnel. It does not itself establish that 1,240 people were unvetted, that any particular nationality was represented in a specified number, or that a stated share posed a threat.
Diplomatic distance matters because it can affect access to trustworthy records and cooperation. The appropriate question is therefore measurable: what information was available for each decision, what remained unavailable, and who accepted the residual uncertainty?
1.3 What an auditable Israeli disclosure would contain
A headline total becomes useful for oversight when it can be reconciled with operational and screening records. The following is a proposed disclosure structure, not a claim about what Israeli authorities currently collect or publish.
| Required field | Why it matters | Oversight question it answers |
|---|---|---|
| Defined reporting period | Prevents comparisons between incompatible periods | What dates does “the past year” cover? |
| Unique-person identifier, protected from public disclosure | Separates repeat travel from distinct personnel | How many individuals were involved? |
| Number of entries or assignments | Measures repeated exposure | How frequently did approved personnel operate? |
| Citizenship and relevant identity history | Supports identity resolution | Which records were used to establish identity? |
| Airline and employing organisation | Identifies the organisation responsible for personnel assurance | Who performed and maintained the checks? |
| Operational role | Distinguishes pilots, cabin crew and positioning personnel | What access did each person actually hold? |
| Screening scope and completion date | Separates an approval from its evidentiary basis | Which checks were completed, and how recently? |
| Unavailable records and compensating measures | Makes uncertainty visible | What could not be verified? |
| Exception authority and rationale | Establishes accountability | Who approved a departure from ordinary requirements? |
| Subsequent adverse information and action | Tests continuing assurance | Was approval reconsidered when circumstances changed? |
Publishing individual identities would generally be unnecessary for this oversight purpose. Aggregate totals, defined categories and independent examination of protected records could establish whether the process operated consistently.
A meaningful report would distinguish completed checks, checks with unresolved limitations, approved exceptions and denied or withdrawn approvals. Combining them under “admitted personnel” conceals the decisions most relevant to security.
1.4 Four records that should remain distinct
An incident of this kind generates several questions with different evidentiary needs.
| Record | Principal question | Evidence needed | Conclusion to avoid |
|---|---|---|---|
| Criminal investigation | What offences occurred, with what intent and participation? | Witnesses, forensic evidence, communications and legally tested findings | Treating an early statement as a final judgment |
| Safety investigation | How did the event develop, and which safeguards affected the outcome? | Recorded aircraft data, operational procedures and human-factors evidence | Assuming criminal motive makes safety analysis unnecessary |
| Personnel-assurance review | What was known before the assignment? | Employment, screening, reporting and decision records | Assuming the later event was necessarily predictable |
| Destination admission review | On what basis was the crew accepted? | Submitted identities, screening results, exceptions and approval history | Treating lawful entry as proof of comprehensive assurance |
The UAE Attorney-General explicitly asserted UAE jurisdiction because the aircraft was UAE-registered, including for offences committed outside UAE territory. That establishes the prosecution’s stated jurisdictional basis; it does not answer every question concerning evidence obtained in other countries. WAM — Jurisdiction and investigation remit, 1 October 2026. Emirates News Agency
ICAO’s March 2026 announcement concerning Amendment 20 to Annex 13 addresses investigation independence and circumstances involving suspected unlawful interference. Its applicability date is 23 November 2028. It provides relevant direction for future safeguards, but should not be presented as an already applicable October 2026 requirement. ICAO — Strengthened accident-investigation framework, 27 March 2026. icao.int
Analytical inference: a criminal investigation and a safety inquiry can produce complementary findings. One may establish intent and responsibility; the other may identify procedural weaknesses that would remain important even if no external network were found.
1.5 Evidence that would distinguish competing explanations
The public record supports investigation of several possibilities without selecting among them prematurely.
| Question | Evidence that would strengthen concern | Evidence that would narrow concern |
|---|---|---|
| Was relevant information available before departure? | A documented warning received before assignment | No identifiable warning in the available records |
| Was a warning acted upon? | An unresolved concern left outside the assignment decision | A timely assessment with a documented resolution |
| Did identity verification have material gaps? | Unresolved identity discrepancies or unavailable essential records | Consistent identity resolution across authoritative sources |
| Was approval reused without reconsideration? | Material changes omitted from subsequent reviews | Recorded reassessment following relevant changes |
| Were failures concentrated? | Similar unresolved weaknesses across personnel or carriers | An isolated event amid independently verified controls |
| Was external direction involved? | Corroborated communications, financing or coordination | Completed investigative findings excluding such involvement |
These are proposed evidentiary tests. They avoid assuming that every serious event reveals the same cause.
Key judgments
- FZ1073 warrants examination of authorised personnel, information flow and recovery capability.
- The Israeli disclosure warrants an audit of admission decisions and their evidentiary basis.
- The available public record does not establish nationality-specific totals, a threat rate among admitted personnel or an external sponsor.
- The decisive distinction is between information that was unavailable, information that was missed and information that was received but not acted upon.
What would change the assessment: a completed investigation, authenticated pre-incident warnings, a defined Israeli dataset, or an independent review showing whether any weakness was isolated or recurrent.
Open official record: the screening and assignment history, the admission-decision methodology behind the reported total, and final investigative findings remain necessary for firmer conclusions.
Chapter 2: Insider access, personnel assurance and the limits of physical security
The central security problem is the use or misuse of legitimate access. An authorised person can possess professional competence, valid credentials and operational knowledge while a separate concern remains undetected or unresolved.
ICAO’s insider-threat guidance treats assurance as an employment-lifecycle responsibility. It includes initial and recurrent checks and recognises that harmful intentions can develop after employment begins. ICAO — Insider Threat Toolkit, August 2022. icao.int
2.1 Different insider pathways require different responses
ICAO distinguishes malicious insiders from coerced, complacent and ignorant personnel. This matters because deliberate violence, pressure from another person and procedural negligence cannot be addressed through an identical intervention. ICAO — Managing Insider Risks, November 2022. icao.int
| Pathway | Nature of the concern | Proposed assurance response |
|---|---|---|
| Deliberate malicious conduct | Intentional misuse of access | Investigate credible indicators and restrict access when warranted |
| Coercion or pressure | A person is induced to misuse their position | Provide confidential reporting and assess the source of pressure |
| Complacency | Familiarity weakens adherence to procedures | Use supervision, proportionate checks and corrective training |
| Insufficient knowledge | A person does not understand a security obligation | Clarify responsibilities and verify practical understanding |
The response column is analytical guidance. It is not a finding about the FZ1073 crew.
Analytical assessment: nationality may affect which records are obtainable. Behaviour, corroborated information, access and the quality of verification determine what an individual assessment can establish. Substituting nationality for that assessment leaves important questions unanswered.
2.2 Assurance consists of separate functions
The word “cleared” can obscure the scope of a decision. A person may be cleared for employment, medically certified, permitted to enter a country and assigned to a flight through different processes.
| Assurance function | Question it answers | Limit of its conclusion |
|---|---|---|
| Professional qualification | Can the person perform the aviation role? | Competence alone does not establish security suitability |
| Medical certification | Does the person meet applicable medical standards? | A certificate cannot establish every future health condition |
| Criminal-history review | Are relevant recorded offences identified? | Available records may be incomplete or geographically limited |
| Security-information assessment | Is relevant adverse information identified and assessed? | Effectiveness depends on identity matching, information coverage and adjudication |
| Identity and credential verification | Are identity and employment claims authentic? | Authentic documents do not establish harmless intent |
| Current assignment approval | Is the individual suitable for this duty now? | Historical approval may require reconsideration after new information |
This is an analytical separation of functions, rather than a universal regulatory checklist.
EASA makes a corresponding institutional distinction: its Third Country Operator assessment is principally a flight-safety assessment, with limited aviation-security elements. An airline’s TCO authorisation should therefore not be represented as comprehensive counterterrorism vetting of each employee. EASA — Third Country Operators FAQ. EASA
A 2025 Canadian working paper submitted to the ICAO Assembly, co-sponsored by IATA and IFALPA, also describes divergent approaches to crew identification and facilitation. It is a proposal, rather than an adopted global rule. Its relevance here is the difficulty of making interoperable credentials carry a consistently understood assurance meaning. ICAO Assembly — Crew Identification and Facilitation, 29 July 2025. icao.int
2.3 Three historical cases show different failure mechanisms
These cases are useful comparisons because official records distinguish deliberate action, unauthorised aircraft use and sudden incapacity. They should not be combined into a single terrorism category.
| Case | Officially documented outcome | Relevant mechanism | Analytical lesson |
|---|---|---|---|
| Germanwings 9525, 24 March 2015 | Deliberate crash; 150 fatalities | An authorised pilot acted while the other pilot was outside the cockpit | Protection against outside intrusion can leave an internal threat unresolved |
| Horizon Air aircraft, 10 August 2018 | An employee took an aircraft without authorisation and intentionally crashed; the FBI found no apparent terrorist connection or wider conspiracy | Legitimate airport access preceded unauthorised aircraft use | Access permission and authority to operate an aircraft require separate controls |
| Lufthansa Frankfurt–Seville flight, 17 February 2024 | Copilot incapacitation while alone; captain regained access and diverted to Madrid; no deaths or serious injuries | Sudden medical incapacity | Recovery arrangements also matter when intent is absent |
Sources: BEA — Germanwings final investigation report, March 2016; FBI — Completed investigation of the August 2018 unauthorised flight; Spain’s CIAIAC — Annual Report 2024, incident summary on printed page 118. bea.aero
The Germanwings investigation examined failures involving medical information, self-reporting and access to treatment and support. Its findings support attention to reporting incentives and confidentiality; they do not justify treating mental illness as evidence of terrorism. BEA — Final report and safety recommendations. bea.aero
The Spanish incident adds an important boundary: safeguards must support recovery from both deliberate action and unexpected incapacity. A system designed only around hostile intent would leave part of the operational problem unaddressed. CIAIAC — Official incident summary. cdn.transportes.gob.es
2.4 Historical US audit data: information coverage can matter as much as screening activity
A 16 June 2015 congressional hearing records the DHS Inspector General’s findings on aviation-worker vetting. These are historical audit figures concerning airport workers, not current statistics about foreign pilots.
| Historical finding | Recorded scale | What the figure demonstrates |
|---|---|---|
| Workers examined through an NCTC data match | More than 900,000 | A large credentialed population was examined |
| Active credential holders with terrorism-related TIDE category codes | 73 | Information-category coverage affected what TSA could identify |
| Active non-US-citizen worker records without passport numbers | 75,000 | Identity records had completeness limitations |
| Those records also lacking alien registration numbers | More than 14,000 | Some records lacked both listed identifiers |
Source: US House of Representatives — How TSA Can Improve Aviation Worker Vetting, 16 June 2015. The last row is a subset of the preceding row. The 73 matches are not a count of proven terrorists or attacks. govinfo.gov
Analytical inference: a screening process can run successfully against its authorised dataset while still missing information held elsewhere. Counting checks performed does not establish the completeness of the underlying assessment.
Later oversight must also be included. GAO’s February 2020 report identified weaknesses in TSA’s insider-threat strategy and performance measurement. Its recommendation status records subsequent implementation. Describing the identified deficiencies as unchanged today would omit that corrective-action history. GAO — Aviation Security: Insider Threat Program, report and recommendation status. U.S. GAO
2.5 Physical barriers protect particular boundaries
A physical safeguard should be assessed against the problem it was designed to address.
| Safeguard | Principal protective purpose | Residual question |
|---|---|---|
| Flight-deck door | Restrict unauthorised entry | What protects against a person already authorised inside? |
| Secondary flight-deck barrier | Protect the opening while the primary door is open | How are internal conduct and incapacity addressed? |
| Airport access control | Restrict entry to protected areas | Does the holder still require that access? |
| Personnel screening | Identify prohibited items or applicable concerns | Could authorised equipment or privileges be misused? |
| Cockpit-occupancy procedure | Provide another authorised person in the compartment | Are roles, training and recovery capability adequate? |
The FAA’s secondary-barrier requirement applies to covered aircraft manufactured after 25 August 2025. It should not be described as proof that every aircraft in the existing fleet has been retrofitted. Its purpose concerns intrusion when the flight-deck door is open. 14 CFR §121.313 — Required equipment; FAA — Secondary flight-deck barrier announcement, 14 June 2023. ecfr.gov
The crash-axe allegation also requires a distinction between equipment presence and misuse. US operating rules illustrate that a crash axe can be required emergency equipment. That US provision does not establish the requirements applicable to FZ1073, but it shows why the presence of such an object does not, by itself, prove a prohibited weapon passed through screening. 14 CFR §121.309 — Emergency equipment. ecfr.gov
2.6 Europe’s cockpit-occupancy guidance changed again in 2026
The policy chronology matters because relying exclusively on the 2016 position would miss the latest published revision.
| Publication | EASA position | Status |
|---|---|---|
| 27 March 2015 | Recommended at least two crew, including a qualified pilot, in the cockpit | Temporary recommendation following Germanwings |
| July 2016 | Adopted a more flexible risk-based approach | Two-person occupancy became one possible mitigation |
| 18 May 2026 | Reinstated two authorised persons as the preferred measure, including at least one pilot | Non-mandatory bulletin; documented alternatives can provide equivalent safety |
Sources: EASA — March 2015 recommendation; EASA — July 2016 explanatory announcement; EASA — SIB 2016-09R1, 18 May 2026. EASA
The 2026 bulletin addresses both deliberate acts and incapacitation and calls for attention to operational consequences, training and responsibilities. It expressly remains non-mandatory. EASA — Current minimum-cockpit-occupancy bulletin. ad.easa.europa.eu
Analytical assessment: additional occupancy can reduce some periods of isolation. It cannot be assumed to resolve violence occurring between two people already present, nor can headcount substitute for practical recovery capability.
2.7 Continuing assurance needs both reporting and action
ICAO’s toolkit supports recurrent checks and attention to changes during employment. The practical objective is to connect new information to an accountable decision about access or duty. ICAO — Insider Threat Toolkit. icao.int
EASA’s air-operations rules require a flight-crew support programme. Associated guidance emphasises trust, confidentiality, assistance and procedures for serious safety concerns. These arrangements support earlier disclosure and intervention; they do not replace security investigations. EASA — Easy Access Rules for Air Operations, CAT.GEN.MPA.215 and associated guidance. EASA
Analytical inference: reporting channels lose value if personnel expect every disclosure to end their career, or if a serious report reaches nobody empowered to act. Effective assurance needs proportionate confidentiality and an explicit escalation path.
2.8 Measure decisions and unresolved uncertainty
The following proposed indicators could support oversight in Israel, Europe, the United States and Middle Eastern aviation systems. They are analytical measures, not published results or universal legal requirements.
| Proposed indicator | Measurement | Why it is useful |
|---|---|---|
| Identity-record completeness | Records meeting defined identity requirements ÷ records reviewed | Exposes weak matching inputs |
| Verification coverage | Required checks completed, unavailable and unresolved, reported separately | Prevents unavailable information being counted as a clean result |
| Review freshness | Time since the latest relevant review | Shows whether assurance has become outdated |
| Alert-to-decision time | Elapsed time between receipt of a concern and an accountable decision | Tests operational responsiveness |
| Exception frequency | Approved exceptions ÷ decisions, separated by reason | Reveals routine dependence on waivers |
| Restriction implementation | Time from restriction decision to operational enforcement | Tests whether decisions affect actual access |
| Reconciliation accuracy | Agreement between approved personnel and current assignments | Detects discrepancies between records and operations |
| Corrective-action durability | Independent verification after a finding is closed | Tests whether improvements continue to operate |
No numerical target should be invented without knowing the legal framework, operational population and consequences of delayed decisions or mistaken identity.
The regional relevance follows from this structure. A destination state needs assurance about incoming personnel; an airline needs a reliable assignment decision; an airport needs current access permissions; investigative bodies need preserved evidence. These responsibilities can be distributed across countries, making their interfaces central to oversight.
Key judgments
- Physical security and personnel assurance address different parts of the problem.
- Professional credentials establish competence and identity within their scope; they do not establish every dimension of security suitability.
- Historical audits show why information coverage and decision accountability deserve examination alongside the number of checks performed.
- Current European guidance must be described using the May 2026 revision.
- The strongest assessment connects identity, current information, assignment decisions, access restrictions and recovery arrangements.
What would change the assessment: independent evidence of complete identity resolution, timely action on relevant warnings, enforceable restrictions and operationally credible recovery procedures would strengthen confidence. Repeated unresolved gaps, unrecorded exceptions or delayed action would weaken it.
Open official record: for FZ1073, the personnel-review history and pre-departure decision trail remain essential. For the Israeli disclosure, the count’s definition and screening methodology are essential. Broader international conclusions require comparable audits with consistent populations and reporting periods.
Pillar Two — National Authorities and International Dependencies
Evidence reviewed through 8 October 2026. Published rules establish responsibilities and procedures; they do not, by themselves, demonstrate how those procedures operated in an individual case. Undated official guidance cited below was retrieved on that date.
Chapter 3: Israel and the United States — crew approval, intelligence and border control
The central judgment is that admission of a foreign crew member, approval of an airline and authorisation to serve on a particular flight are separate decisions. An investigation into national security must establish which decision was made, by whom, against which information, and whether it remained valid when the aircraft departed.
This distinction changes how the Israeli disclosure should be examined. The question is whether the competent authorities had sufficient information and an effective opportunity to act before an individual obtained operational access.
Israel: the published division of responsibility
Israel’s Aeronautical Information Publication identifies a security review within the process for approving foreign commercial operators. Applications for scheduled operations go through the Civil Aviation Authority’s Air Transport Division and are forwarded to the Ministry of Transport Security Department’s Aviation Security Operations Centre, or ASOC, for the security aspects. Changes to application information must be notified in advance. These are published operator approval requirements, rather than a publicly disclosed account of every individual crew check. Source: Israel eAIP, GEN 1.2, effective 6 August 2026. e-aip.azurefd.net
The accompanying entry regulations provide a specific form of crew facilitation. Under the stated conditions, a commercial crew member’s licence or crew certificate can be accepted instead of a passport or visa, with restrictions concerning location and onward departure. The same publication requires compliance with instructions from the relevant Israeli security authorities. Documentary facilitation therefore does not establish exemption from security controls. Source: Israel eAIP, GEN 1.3, sections 2.3 and 4.7, effective 6 August 2026. e-aip.azurefd.net
| Published Israeli process | What it establishes | What it does not establish |
|---|---|---|
| Foreign commercial operator application and ASOC review | A security decision within airline operating permission | The complete method used to assess each foreign employee |
| Advance notification of changed application information | An obligation to keep operator information current | Whether every roster substitution triggers a fresh individual assessment |
| Conditional acceptance of a licence or crew certificate | A route for crew immigration facilitation | Automatic permission to disregard security instructions |
| Israeli crew-certificate issuance service | Requirements for the personnel covered by that domestic service | An identical procedure for all incoming foreign crews |
Sources: GEN 1.2, GEN 1.3, and Israeli CAA — application for a crew certificate.
The domestic certificate service provides a useful illustration of a different scope. Applications involve the employer, its security department and checks concerning criminal convictions. However, the service concerns eligible personnel departing Israel in the specified crew or observer roles. Its existence cannot be used as proof that an incoming employee of a foreign airline underwent precisely the same process. Source: Israeli CAA — application for a crew certificate. רשות התעופה האזרחית
The distinction matters because several nationalities can be involved in one operation: the crew member’s citizenship, the airline’s state, the aircraft’s registration state and the departure state. A restriction concerning one category cannot automatically be applied to another.
For example, the Israeli publication’s diplomatic-relations condition for certain non-scheduled overflights concerns the aircraft’s state of registration. It does not establish a general prohibition on every crew member holding citizenship of a country without diplomatic relations. The separate general-aviation procedures also should not be transplanted into commercial airline operations. Source: Israel eAIP, GEN 1.2.
What the Israeli disclosure still requires
The user-specified report remains relevant as the starting point for parliamentary scrutiny. It does not provide a complete decision record showing how individual cases were assessed. Source: The Times of Israel — reported disclosure at the Knesset committee, 6 October 2026. www.timesofisrael.com
The following questions develop the accountability issue without assuming that the disclosed admissions were unlawful.
| Decision requiring examination | Evidence needed | Why it changes the assessment |
|---|---|---|
| Which authority approved the individual? | Applicable procedure and identifiable decision owner | Establishes whether responsibility was explicit |
| What personal information was available? | Fields submitted and verification records | Distinguishes a documented assessment from reliance on incomplete identity data |
| Was an absence of information recorded? | Treatment of unavailable foreign records | Prevents “no adverse information found” being confused with “information unavailable” |
| Did the approved identity match the operating crew member? | Final roster reconciliation and document verification | Tests the connection between an earlier decision and actual operational access |
| What happened after a change or warning? | Reassessment, notification and restriction records | Establishes whether approval could be withdrawn in time |
These are analytical questions, not findings that such failures occurred.
United States: approved roster, flight manifest and admission
US regulations make two separate crew-data mechanisms visible.
Under 19 CFR 122.49c, covered carriers submit master crew information electronically to Customs and Border Protection. TSA reviews the lists and identifies names to be removed; the regulation links covered operations to TSA-approved lists. The information includes identity, citizenship, residence and relevant document details. The rule also allows specified alternative requirements through TSA security programmes or directives. Source: 19 CFR 122.49c — Master crew member and non-crew member lists. ecfr.gov
Under 19 CFR 122.49b, the carrier submits information for the actual flight. Certain late changes require TSA approval before departure. The regulation provides consequences where a person is absent from the applicable master list, including restrictions on departure or entry into US territorial airspace. It also requires verification that transmitted document information belongs to the person concerned. Source: 19 CFR 122.49b — Electronic manifests for crew members and non-crew members. ecfr.gov
Immigration is a further decision. Where a visa is required, the State Department’s crew-visa process concerns eligibility for the appropriate immigration category. Separately, the arrival regulation requires a foreign crew member seeking landing privileges to appear before a CBP officer and establish admissibility. An approved aviation roster therefore does not settle the arrival decision. Sources: US Department of State — Crewmember Visa and 8 CFR 252.1 — Examination of crewmen. travel.state.gov
| US decision | Principal actors | Published purpose | Separate unresolved question |
|---|---|---|---|
| Master-list approval | Carrier, CBP and TSA | Establish the approved personnel list for covered operations | Is the current employee correctly represented? |
| Flight-specific submission | Carrier, CBP and TSA | Connect personnel data to a particular flight | Was the final operating roster reconciled? |
| Visa adjudication, where required | State Department | Determine eligibility for the crew immigration category | Does the person satisfy arrival requirements? |
| Landing permission | CBP | Examine admissibility and entitlement to landing privileges | Does the person retain the airline’s operational authorisation? |
| Foreign-carrier security programme | TSA and carrier | Establish the carrier’s security obligations | Are the prescribed measures being implemented? |
Sources: 19 CFR 122.49c, 19 CFR 122.49b, Crewmember Visa, 8 CFR 252.1, and 49 CFR 1546.105.
Classification also matters. Under the manifest rule, an airline employee travelling on a passenger aircraft without operating as crew is treated as a passenger for that submission. “Airline employee” and “operating crew member” are therefore not interchangeable categories. Source: 19 CFR 122.49b.
Intelligence must reach a decision that can change
The published US framework also provides an enforcement mechanism at carrier level. TSA can impose an emergency amendment to a foreign carrier’s security programme, effective on receipt; a request for reconsideration does not suspend its effect. This establishes a route for changing requirements urgently, although it does not disclose the intelligence behind a particular instruction. Source: 49 CFR 1546.105 — Acceptance and amendments of security programmes. ecfr.gov
The analytical issue for both countries is whether relevant information reaches an authority that can prevent the next access event. A warning received after departure may support an investigation but cannot provide the same preventive opportunity as a warning received before roster release.
| Possible information problem | Why the distinction matters |
|---|---|
| Correct identity, unavailable foreign history | The uncertainty concerns coverage of the person’s background |
| Ambiguous name match | The uncertainty concerns whether the warning identifies the same person |
| Correct warning, wrong recipient | Information exists but may not reach the decision owner |
| Correct recipient, obsolete roster | The authority may act against a person no longer assigned while missing a replacement |
| Restriction issued, access still active | The decision exists but has not been implemented operationally |
This is an analytical classification of possible failures, not a description of established Israeli or US incidents.
Key judgments
- The US public record provides a clearer separation between roster approval, flight-specific reporting and immigration examination. That visibility does not establish superior performance in every case.
- Israel’s published operator and entry rules cannot independently reconstruct individual foreign-crew assessments.
- The decisive security question is whether a current, correctly identified person remained authorised when operational access occurred.
What would change the assessment: an official Israeli account of foreign-crew approval procedures, audited evidence of roster reconciliation, or documented cases showing how new adverse information altered an existing approval.
Open official record: the sources examined do not establish which intelligence holdings were consulted for each person covered by the Israeli disclosure, or how unavailable foreign information affected those decisions.
Chapter 4: European Union, Italy, France, Germany and the United Kingdom
The central judgment is that Europe combines common aviation-security requirements with national decisions on personnel assurance. A shared regulatory baseline does not mean that every country has the same intelligence access, administrative procedure or ability to obtain foreign criminal records.
The EU baseline and national responsibility
The European Commission describes a system in which each Member State designates a single appropriate authority and maintains national aviation-security and quality-control programmes. Airports and airlines also maintain their own security programmes. The Commission establishes and oversees the common framework, while national authorities retain implementation responsibilities. Source: European Commission — Aviation security. European Commission
Official Austrian guidance explaining the EU requirements distinguishes a background check from an enhanced background check. The former covers identity, relevant criminal records and employment, education and gaps over the prescribed history. The enhanced version additionally includes intelligence and other relevant information available to competent authorities and considered pertinent to suitability. “Available” is consequential: the requirement does not guarantee access to every foreign intelligence or police record. Source: Austrian ministry — Scope of aviation-security background checks. bmimi.gv.at
The resulting comparison must distinguish the governing standard from the information actually obtainable in an individual case.
Italy: authorised issuance remains dependent on public checks
Italy’s ENAC Circular SEC-010 addresses the Union Crew Identification Card. Its procedure connects issuance to an enhanced background check involving the Border Police. It also permits authorised operators to issue cards within the prescribed arrangements.
This authorisation does not transfer the police assessment to the airline. The circular separately addresses the return and cancellation of cards when employment, qualifications or the need for access ends. Source: ENAC Circular SEC-010 — Union Crew Identification Card, 27 January 2022. enac.gov.it
The practical accountability issue is the connection between the public suitability decision and the employer’s credential management. A valid initial check cannot compensate for a card that remains usable after its operational justification disappears.
ENAC’s published oversight description identifies national and local inspection arrangements involving ENAC personnel and, where applicable, State Police or Border Police. This gives a public basis for examining both government oversight and operator compliance. Source: ENAC — Regulatory framework and activities. Ente Nazionale per l’Aviazione Civile
France: the prefectural decision and the airport credential
France’s Transport Code assigns the security-clearance decision to the competent prefectural authority. The employer initiates the application. The Code also provides for suspension or withdrawal where the person’s behaviour no longer provides the required security guarantees.
A further administrative detail matters: silence for four months after receipt of a complete application constitutes refusal. An unanswered application therefore cannot simply be treated as an approval. Source: French Transport Code, Articles R6342-18 to R6342-22. Légifrance
The implementing order provides another, more operational control: the airport operator must verify the validity of airport access credentials at least every seven days. It also specifies documentary requirements concerning criminal records and previous foreign residence. Source: French aviation-security implementing order of 11 September 2013, consolidated version consulted. Légifrance
The seven-day requirement concerns credential validity. It should not be presented as a complete new criminal-record or intelligence investigation every week.
Germany: relevant later information must return to the authority
Germany’s Aviation Security Act makes the reliability decision an assessment by the aviation-security authority. The law provides for enquiries to specified public bodies and, where appropriate, employers.
Its continuing-information provision is especially important: relevant subsequent information must be communicated to the aviation-security authority by the bodies and organisations covered by the provision. This creates a legal connection between initial approval and later developments. Source: Germany, Aviation Security Act — section 7. Einzelnorm
The implementing regulation requires a ten-year residence history in the application and provides a five-year period for a positive reliability finding before repeat review. These periods perform different functions. A longer residence history expands the information sought; it does not make a finding immune to relevant intervening developments. Source: Germany, Aviation Security Reliability Checking Regulation. gesetze-im-internet.de
German law also allows certain information to be transmitted for an external review at the individual’s request. This should not be interpreted as automatic worldwide acceptance of a German assessment for every foreign airline operation.
United Kingdom: employer sponsorship and unavailable overseas records
The UK CAA describes national-security vetting as an employer-sponsored process for the roles covered by the relevant requirements. Counter Terrorist Checks involve criminal and security records. The published guidance gives a five-year validity period while allowing further action where circumstances change. Source: UK Civil Aviation Authority — National security vetting. UK Civil Aviation Authority
The overseas-record guidance addresses a dependency that affects international aviation directly. Where an official foreign criminal-record certificate genuinely cannot be obtained, the CAA specifies exceptional supporting arrangements, including evidence of the inability to obtain it and alternative documentation. Source: UK Civil Aviation Authority — Overseas criminal record checks. UK Civil Aviation Authority
An alternative evidence package can support a decision, but its contents must remain distinguishable from an official search of the relevant foreign criminal-record system. The analytical question is how the decision accounts for that difference in evidential coverage.
National differences that matter operationally
| Jurisdiction | Published mechanism | Security significance | Interpretation to avoid |
|---|---|---|---|
| Italy | Border Police check linked to crew-card issuance; authorised operator issuance is possible | Public suitability assessment and employer credential administration have separate responsibilities | Assuming airline issuance means airline-only vetting |
| France | Prefectural clearance, with suspension and withdrawal powers | A public authority can reconsider the suitability decision | Treating an issued credential as irreversible |
| Germany | Relevant later information must reach the aviation-security authority | New information can affect an existing reliability finding | Assuming periodic renewal is the only reassessment route |
| United Kingdom | Employer-sponsored national-security vetting and specified overseas-record procedures | Sponsorship, public vetting and foreign evidence acquisition remain distinct | Treating unavailable foreign records as a clean criminal history |
Sources: Italy — SEC-010, France — Transport Code, Germany — section 7, and UK — National security vetting.
| Published period or frequency | Jurisdiction | What it measures |
|---|---|---|
| Four months without a decision after a complete application | France | The point at which administrative silence constitutes refusal |
| At least every seven days | France | Verification of airport access-credential validity |
| Criminal-record documentation less than three months old | France | Freshness of the specified supporting document |
| Ten years | Germany | Residence history required in the reliability-check application |
| Five years | Germany | Period of a positive reliability finding before repeat review |
| Five years | United Kingdom | Published validity of the Counter Terrorist Check |
Sources: French Transport Code, French implementing order, German implementing regulation, and UK CAA vetting guidance.
These figures describe different controls and cannot be ranked on one scale. Seven-day credential verification and five-year vetting validity are not competing versions of the same procedure.
What the latest EU oversight data demonstrate
The Commission’s 2025 annual report, published on 13 July 2026, identifies seven full-time Commission inspectors supported by a pool of approximately 70 national auditors. It also reports continuing weaknesses in aspects of national monitoring. These are observations about oversight arrangements, rather than measurements of the likelihood of an insider attack. Source: European Commission — 2025 Annual Report, COM(2026) 361 final. data.consilium.europa.eu
The accompanying annex supplies country-level inspection counts:
| Jurisdiction | Commission inspections in 2025 | Cumulative inspections, 2004–31 December 2025 |
|---|---|---|
| Italy | 1 | 37 |
| France | 2 | 41 |
| Germany | 1 | 39 |
| Commission total, including Switzerland | 19 | 571 |
Source: Annex 1 to the Commission’s 2025 aviation-security report — official parliamentary copy. Counts include the authority and airport inspection categories specified in the annex. parlament.gv.at
These data establish that inspection activity occurred. They do not establish that France is safer because it received two inspections, or that Italy and Germany had weaker systems because each received one. A defensible comparison would require inspection scope, findings, corrective-action completion and relevant exposure denominators.
The United Kingdom must also be assessed through its own framework; absence from this EU comparison is not evidence of an absence of oversight.
Domestic clearance and incoming foreign crew remain different questions
The national documents above explain personnel checks and credentials within their respective legal scopes. They should not be used to claim that every foreign pilot arriving briefly undergoes the same procedure as a locally employed person seeking continuing access.
For an incoming foreign crew, the destination may depend on evidence generated elsewhere. The important comparison is therefore whether the destination can understand that evidence, identify its limitations and act when new information emerges.
Key judgments
- Common EU requirements coexist with material national differences in decision ownership, supporting evidence and continuing notification.
- Italy’s issuance arrangements, France’s credential-validity checks, Germany’s later-information duty and the UK’s overseas-record exceptions address different parts of the assurance process.
- Published inspection counts demonstrate oversight activity, but cannot support national safety rankings.
What would change the assessment: comparable findings on foreign-record coverage, restrictions following new information, unresolved credential withdrawals and completed corrective actions.
Open official record: the material examined does not provide a comparable country-by-country dataset showing how incoming foreign airline crews were individually assessed.
Chapter 5: Middle Eastern carriers, departure states and international cooperation
The central judgment is that an international carrier operates across several security jurisdictions whose responsibilities overlap without becoming interchangeable. Its home-state programme, departure-airport controls and destination requirements must work together. None can automatically substitute for the others.
The carrier’s programme and the destination’s requirements
ICAO’s published guidance explains the relationship between an Aircraft Operator Security Programme and Supplementary Station Procedures. The operator programme must meet the requirements of the operator’s state. Supplementary procedures address requirements imposed by other states that are not already covered by that programme. Source: ICAO — Aircraft Operator Security Programme and Supplementary Station Procedures. AOSP and SSP
This distinction is central to Middle Eastern airlines serving Israel, Europe and the United States. A destination-specific requirement needs a defined place in the carrier’s operational arrangements. Its existence in a government document is insufficient if it does not reach the personnel who assign crews and authorise departures.
| Jurisdictional connection | Responsibility to establish | Why another connection cannot automatically replace it |
|---|---|---|
| State of the operator | Oversight of the airline’s security programme | Does not settle every foreign destination requirement |
| Departure state | Applicable security measures at the originating airport | Cannot guarantee access to all destination intelligence |
| Destination state | Conditions for the operation and relevant entry decisions | May depend on background information generated abroad |
| State of citizenship or previous residence | Potential source of identity and historical records | Is not necessarily the state supervising the employer |
| Airline | Implementation, staffing and communication of applicable requirements | Cannot assume government-held information is already reflected in its records |
This is an analytical allocation of dependencies, informed by the ICAO programme guidance, rather than a claim that every state uses identical procedures.
United Arab Emirates: published personnel and cooperation duties
The UAE’s aviation-security regulations provide a substantive public baseline. Edition 05 of CAR Part VII, effective 1 July 2025, requires relevant background checks before personnel undertake specified security duties or receive unescorted restricted-area access. It also requires recurring checks under national requirements and denial of relevant access where suitability is not established.
The public regulation does not supply one universal numerical recheck interval for all such personnel. Source: UAE GCAA — CAR Part VII, Edition 05, May 2025. gcaa.gov.ae
GCAA describes its Aviation Security Affairs function as approving or accepting stakeholder security programmes and conducting risk-based oversight. Its Intelligence and Threat Assessment function includes analysis, threat reporting and coordination with domestic and international counterparts. These descriptions establish institutional responsibilities; they do not reveal every check performed on a named employee. Sources: GCAA — Aviation Security Affairs and GCAA — Intelligence and Threat Assessment. gcaa.gov.ae
| Published UAE requirement | Cross-border significance | Limit of the public evidence |
|---|---|---|
| Background checks before specified duties or access | Establishes personnel-assurance obligations | Does not disclose the foreign databases consulted in each case |
| Recurring checks under national requirements | Establishes continuing assurance | Does not publish a single interval applicable to everyone |
| Verification of outsourced security services | Extends obligations beyond direct employees | Does not demonstrate the outcome of each contractor inspection |
| Cooperation on additional foreign security measures | Provides a basis for destination requirements | Does not establish unrestricted access to another state’s intelligence |
Source: UAE CAR Part VII, sections 2.2 and 3.5.
An important inference follows: publishing a cooperation obligation does not demonstrate that a usable warning crossed a particular border before a particular flight. That requires records of receipt, interpretation and action.
Carrier scale must be measured with the correct denominator
First-party operational data illustrate why categories matter. Emirates’ results published on 7 May 2026 report the following figures for the financial year ending 31 March 2026:
| Reported measure | Figure | Scope |
|---|---|---|
| Emirates Group workforce | 130,919 | Group employees, including Emirates and dnata |
| Emirates cabin crew | Approximately 25,000 | Cabin crew, rather than all aircrew |
| Emirates passengers carried | 53.2 million | Passenger carriage during the financial year |
Source: Emirates Group — 2025–26 annual results, 7 May 2026. emirates.com
These figures show organisational scale. They cannot supply a denominator for Israeli foreign-crew admissions, establish the number of pilots screened, or demonstrate another carrier’s performance.
For an assurance comparison, the relevant population would need to be defined: operating flight crew, cabin crew, employees with restricted-area access, or individuals assigned to a particular destination. Mixing these categories produces impressive numbers but weak conclusions.
Bilateral agreements provide mechanisms, with defined limits
Published aviation agreements show that cooperation can include assistance, additional security measures and responses to non-compliance.
The Estonia–UAE agreement signed in 2018 contains an aviation-security article addressing assistance, threat-specific measures and consultations. The Spain–Qatar agreement signed in 2011 likewise contains aviation-security obligations and a consultation mechanism. These are examples from particular treaty texts; their wording should not be assumed to govern every bilateral relationship. Sources: Estonia–UAE Air Services Agreement, Article 12 and Spain–Qatar Air Transport Agreement, Article 13. riigiteataja.ee
| Published agreement | Consultation provision | Urgent-action provision |
|---|---|---|
| Estonia–UAE, signed 28 September 2018 | Failure to reach a satisfactory agreement within 15 days can support specified action under the agreement | Emergency interim action is contemplated before that period expires |
| Spain–Qatar, signed 26 April 2011 | A 15-day period follows the request for consultations under the security provision | Extraordinary circumstances can justify interim action before expiry |
Sources: Estonia–UAE, Article 12 and Spain–Qatar, Article 13.
The consultation period concerns escalation between states. It is not a waiting period during which an individual must remain authorised to fly. Nor does the treaty language establish a shared, comprehensive database of airline personnel.
The operational dependency remains specific: can a warning be communicated with sufficient identity detail and authority for the receiving state or carrier to act?
Regional institutions should be examined individually
The available official record also cautions against treating the Middle East as one regulatory system.
Oman’s CAA publishes a service concerning airport-entry security permits. Syria’s published aeronautical information identifies an aviation-security division and describes responsibilities under its national programme. These establish declared functions within those jurisdictions. They do not independently demonstrate how foreign employment histories are verified or how another country can obtain the resulting information. Sources: Oman CAA — Aviation security and facilities service and Syria eAIP — GEN 3.6, aviation security. الرئيسية
For Iran, Iraq and other jurisdictions mentioned in the Israeli reporting, the record examined here does not establish the completeness or accessibility of individual background information. That uncertainty should be stated directly rather than converted into an unsupported finding about every citizen.
International capacity-building supplies activity data, not outcome certainty
The Commission’s latest annual report also records cooperation through the EU–ECAC CASE II project, covering partner countries in Africa, Asia and the Middle East.
| CASE II measure | Reported value | Interpretation |
|---|---|---|
| Project budget | €8 million | Overall project budget, rather than expenditure solely in 2025 |
| Activities between 1 January and 30 November 2025 | 56 | Delivery count |
| Participants during that period | 950 | Participation count |
Source: European Commission — 2025 aviation-security annual report, international cooperation section.
These figures demonstrate cooperation and training activity. They do not establish the number of insider threats prevented or prove that participating authorities subsequently obtained complete foreign records.
ICAO’s audit framework creates a further evidence limit. Its published USAP principles explain that detailed audit reports are confidential, while specified information is available to Member States through restricted arrangements. Consequently, the absence of a public country report cannot support a finding that a jurisdiction has no deficiencies—or that it has failed an audit. Source: ICAO — Universal Security Audit Programme principles. icao.int
Where an international dependency becomes a security gap
The principal analytical concern is a decision made on evidence generated elsewhere, without a clear account of its scope or limitations.
| Dependency | Possible gap | Evidence that would resolve the uncertainty |
|---|---|---|
| Foreign criminal-record information | A certificate covers only part of the relevant history | Defined territorial and temporal coverage |
| Home-state personnel assessment | The destination does not know what was examined | An authoritative description of the assessment’s scope |
| Destination-specific requirement | The instruction does not reach crew assignment | Records showing incorporation into station and rostering procedures |
| New adverse information | The receiving authority cannot identify or restrict the person promptly | Identifiable notification and action records |
| Third-party credential or service | Withdrawal does not propagate across organisations | Confirmation that the relevant access was disabled |
These are possible dependency failures requiring evidence, rather than established findings against a carrier or country.
Key judgments
- The UAE publishes personnel-assurance and cooperation duties, but those duties do not reveal the complete assessment of every international crew member.
- ICAO’s distinction between operator programmes and supplementary station procedures identifies where destination requirements must be incorporated.
- Treaty consultation provisions, training participation and published institutional mandates demonstrate mechanisms and activity. They cannot independently prove effective individual threat prevention.
- Citizenship, employer jurisdiction and departure state identify different connections; each needs its own evidential treatment.
What would change the assessment: official evidence showing how foreign-record limitations were handled, how destination requirements entered crew-assignment procedures, and whether warnings produced timely restrictions.
Open official record: publicly available documents do not provide a comparable Middle Eastern dataset on individual crew vetting, foreign-information coverage or cross-border warning outcomes.
Pillar Three — Decisions, Accountability and Strategic Outlook
Assessment as of 8 October 2026. The outlook extends to 2031. Scenarios and policy proposals below are analytical judgments; published regulatory dates and institutional targets are identified separately.
Chapter 6: Cross-border information failures and commercial disruption
The principal judgment is that an information failure can produce two different national-security consequences: an unsuitable person retains access, or an unresolved assessment disrupts legitimate operations. Effective policy must reduce both, while preserving the ability to stop a flight when the available evidence warrants intervention.
The accountability problem extends beyond whether information was collected. Authorities must establish whether the information concerned the correct person, remained current, could lawfully reach the relevant decision-maker and resulted in an operational instruction. Commercial disruption becomes consequential when uncertainty persists beyond the carrier’s ability to supply a qualified, eligible replacement crew.
A successful database search answers a limited question
INTERPOL’s Stolen and Lost Travel Documents database illustrates the importance of understanding what a check establishes. It contains records concerning documents reported as stolen, lost, revoked, invalid or stolen blank. The issuing country supplies the relevant document record. A search therefore depends on both database access and the underlying reporting process. SLTD database — INTERPOL — undated, retrieved October 2026. interpol.int
| Published INTERPOL measure | Value | Reference period | Correct interpretation |
|---|---|---|---|
| Records in the database | Approximately 138 million | Undated current webpage, retrieved 8 October 2026 | Document records, rather than a count of dangerous individuals |
| Searches worldwide | 3.6 billion | 2023 | Searches, potentially including repeated checks |
| Positive matches | 232,423 | 2023 | Matches to recorded document status, rather than confirmed terrorist identifications |
Source: SLTD database — INTERPOL.
A negative result in this system does not establish the holder’s occupational suitability, employment history or absence of adverse intelligence. Conversely, a document-status match requires appropriate examination; its existence alone does not establish terrorist intent. The policy implication is that decision records should preserve the question each search answered, rather than collapse several limited checks into an unexplained declaration that a person was “cleared.”
Different information failures require different remedies
The following distinctions concern the cause of an unresolved decision. They are analytical categories, not findings against a particular authority.
| Failure category | What has gone wrong | Appropriate corrective direction | Why indiscriminate additional screening may fail |
|---|---|---|---|
| Missing underlying record | Relevant historical information was never recorded or cannot be obtained | Identify the coverage gap and assess alternative evidence | Repeating the same search does not create the missing record |
| Identity uncertainty | Information cannot reliably be connected to the individual | Resolve identity using authoritative supporting information | More alerts can increase ambiguity |
| Obsolete information | A record does not reflect a subsequent correction or decision | Obtain and propagate the authoritative update | Repetition can reproduce an outdated restriction |
| Legal transfer obstacle | Information exists but the proposed transfer lacks the required basis or safeguards | Establish a lawful, appropriately limited exchange | Informal circulation can create a second governance failure |
| Delivery failure | The authorised recipient does not receive or acknowledge an instruction | Repair notification and escalation arrangements | The original assessment may already have been adequate |
| Implementation failure | A restriction is decided but the relevant access remains available | Confirm execution by the organisation controlling access | Further analysis does not substitute for implementing the decision |
These categories also separate accountability. An airline cannot correct an unavailable foreign government record by improving its roster software. A government cannot resolve an operator’s failure to implement a restriction merely by issuing another assessment. Responsibility should follow the failed function, supported by evidence of the information available at the relevant time.
Lawful exchange must be designed before an emergency
For processing within the GDPR’s scope, the principles reproduced by France’s CNIL require accuracy, data minimisation and appropriate limits on retention. Article 10 separately governs criminal-conviction and offence data, requiring official-authority control or authorisation in Union or Member State law with appropriate safeguards. These provisions do not establish that every airline may build its own comprehensive international criminal-record database. GDPR, Chapter II: Principles — CNIL official reproduction — undated, retrieved October 2026. CNIL
Transfers governed by the EU Law Enforcement Directive have a different legal framework. The European Data Protection Board’s guidance on Article 37 explains the assessment of safeguards for particular transfers or categories of transfers. A cooperation agreement does not necessarily supply sufficient safeguards simply because it permits cooperation in general. Guidelines 01/2023 on Article 37 Law Enforcement Directive, version 2.1 — EDPB — September 2024, particularly sections 2.3 and 3. edpb.europa.eu
The operational implication is to distinguish the protected information supporting a decision from the instruction necessary to implement it. A carrier may need an authoritative restriction concerning an identified employee without receiving the underlying intelligence file. Such arrangements still require the applicable legal basis, reliable identification, defined recipients and correction procedures.
This is a policy design principle, not a claim that one existing mechanism governs all Israeli, American, European and Middle Eastern exchanges.
A crew interruption can outlast the initial security decision
Once a crew member becomes unavailable, the commercial consequence depends on replacement capacity. A substitute must satisfy the relevant operational and destination requirements. The carrier must also account for the remaining crew, aircraft availability and the onward schedule.
An actual European case demonstrates the replacement problem without involving a terrorist incident. In the TAP Portugal litigation, the Court’s official account records that a co-pilot died shortly before a Stuttgart–Lisbon flight and the remaining crew declared itself unfit. A replacement crew had to travel from Lisbon. The cancellation of a flight due to the unexpected death of the co-pilot does not exempt the airline from its obligation to compensate passengers — Court of Justice of the EU — May 2023. curia.europa.eu
| Event in the Court’s account | Time on 17 July 2019 |
|---|---|
| Original scheduled departure from Stuttgart | 06:05 |
| Replacement crew departed Lisbon | 11:25 |
| Replacement crew arrived in Stuttgart | 15:20 |
| Replacement flight’s scheduled departure | 16:40 |
Source: Court of Justice official account of Joined Cases C-156/22 to C-158/22.
The Court’s summary reports that unexpected staff absence through illness or death belongs to the normal exercise of the carrier’s activity and did not establish the claimed extraordinary-circumstances exemption. That judgment should not be extended automatically to a government security prohibition. It nevertheless demonstrates why the factual cause of a cancellation must be identified precisely.
Refunds, care and compensation are separate exposures
EU official guidance distinguishes reimbursement or rerouting, passenger care and financial compensation. Even where extraordinary circumstances remove entitlement to compensation, assistance and care obligations can remain. Air passenger rights: frequently asked questions — Your Europe, European Union — retrieved October 2026. Your Europe
The applicable geographic scope also matters. EU guidance covers departures from the EU on EU or non-EU airlines, and specified arrivals from outside the EU operated by EU airlines. A Middle Eastern airline’s inbound and outbound services therefore cannot automatically be treated identically. Air passenger rights — Your Europe, European Union — retrieved October 2026. Your Europe
| Regime | Published monetary or timing measure | Qualification |
|---|---|---|
| EU cancellation compensation | €250, €400 or €600 per eligible passenger, according to the applicable distance category | Subject to notice, rerouting and extraordinary-circumstances provisions |
| UK cancellation compensation | £220, £350 or £520 per eligible passenger in the applicable circumstances | Eligibility depends on notice, replacement-flight timing and the cause |
| US significant itinerary change | Includes arrival at least three hours later domestically or six hours later internationally | These are among the refund-triggering changes |
| US prompt-refund definition | Seven business days for credit-card purchases; 20 calendar days for other payment forms | The applicable refund trigger must also be established |
Sources: EU passenger-rights guidance; Cancellations — UK CAA — retrieved October 2026; Refunds — US Department of Transportation — retrieved October 2026; 14 CFR Part 260 — Refunds for Airline Fare and Ancillary Service Fees — current eCFR consulted October 2026. UK Civil Aviation Authority
US DOT guidance states that cancellation can establish refund entitlement regardless of its reason when the passenger declines the relevant alternatives. UK CAA guidance likewise distinguishes care during a qualifying delay from compensation. A security explanation therefore should not be used as a universal statement that passengers have no remaining rights. Refunds — US DOT; Delays — UK CAA — retrieved October 2026. UK Civil Aviation Authority
Financial accountability requires a reconciled ledger
A disruption assessment should distinguish cash paid, revenue forgone and incremental operating costs. Adding gross refunds to the entire value of cancelled-flight revenue can double-count the same economic effect.
| Exposure | Evidence required | Accounting distinction |
|---|---|---|
| Ticket refunds | Refund transactions and affected bookings | Cash repayment versus revenue previously recognised or deferred |
| Statutory compensation | Eligible passengers and applicable decisions | Separate from repayment of the fare |
| Passenger care | Hotel, meal and transport invoices | Actual expenditure rather than an assumed allowance |
| Replacement operation | Crew positioning, handling and other incremental invoices | Additional cost versus expenditure already planned |
| Subsequent schedule disruption | Aircraft and crew rotation records | Direct interruption versus demonstrable downstream effects |
| Insurance recovery | Applicable policy, accepted claim and payment record | Claimed coverage versus realised recovery |
This is a proposed analytical ledger. It does not estimate the cost of FZ1073 or of the Israeli disclosure.
Digital failure can create the same operational uncertainty
The Commission’s latest aviation-security report identifies disruption following the attack on Collins Aerospace’s MUSE system, including manual processing, delays and cancellations. It also reports approximately 9,200 cyber incidents affecting aviation stakeholders worldwide in 2025, drawing on EUROCONTROL/EATM-CERT reporting. That figure is not a count of insider attacks or successful aircraft compromises. 2025 Annual Report on the Implementation of Regulation (EC) No 300/2008 — European Commission — July 2026, section 2.2. data.consilium.europa.eu
The implication for personnel assurance is conditional: if the systems holding identities, restrictions or acknowledgements become unavailable or unreliable, an authority may temporarily lose the evidence needed to permit access. Recovery procedures must restore confidence in the information, rather than merely restore connectivity.
Key judgments
- A database result must retain its scope; document validity and individual suitability answer different questions.
- Disruption depends on both the restriction and the availability of eligible replacement personnel.
- A justified security intervention can leave substantial passenger and commercial obligations intact.
- Financial reporting should separate refunds, compensation, incremental costs and recoveries.
What would change the assessment: official findings identifying a missed warning, evidence that an interruption arose from incorrect data, or a reconciled carrier account linking a specific restriction to its operational and financial consequences.
Open official record: the sources examined do not establish a verified total commercial loss attributable to the Israeli crew disclosure, nor a complete cross-border notification record for the individuals concerned.
Chapter 7: Scenarios and observable indicators, 2026–2031
The principal judgment is that the most useful planning assumption is uneven improvement across jurisdictions, accompanied by occasional targeted disruption. A universal international crew-clearance system should not be assumed. The outlook must distinguish implementation of existing commitments from evidence that authorities can exchange and act on individual information.
The scenarios below describe pathways that can overlap or follow one another. They are not mutually exclusive outcomes, and the available record does not support numerical probabilities.
Published milestones provide checkpoints, not guarantees
ICAO’s second Global Aviation Security Plan establishes milestones under which 65% of states should reach or exceed 75% effective implementation by 2027, increasing to 80% of states by 2030. These are global implementation milestones; they do not measure the probability of preventing an insider attack. The plan explicitly states that the milestones do not impose additional obligations on Member States. Global Aviation Security Plan, second edition, Doc 10118 — ICAO — 2024, printed page 13. icao.int
Europe also has a defined implementation calendar. EASA identifies separate Part-IS applicability dates for the organisations and authorities covered by the relevant instruments. The ground-handling framework introduces later dates for its general requirements and specified information-security provisions. These measures concern their stated safety and information-security scopes; they should not be presented as a new universal foreign-crew vetting regime.
| Date or checkpoint | Published measure | Status at the assessment date | Relevance to the outlook |
|---|---|---|---|
| 22 February 2026 | Applicability of Part-IS requirements under the implementing act for covered organisations and authorities | Applicable baseline | Oversight must examine implementation, beyond the existence of documentation |
| From 27 March 2027 | Transitional declarations by existing covered ground-handling organisations, under agreed plans | Future transition provision | Tests whether authorities and providers prepare in time |
| By 2027 | ICAO milestone: 65% of states at or above 75% effective implementation | Institutional target | Global checkpoint, rather than an individual clearance measure |
| 27 March 2028 | General application of the EU ground-handling framework | Published future application date | Changes responsibility and oversight at operational interfaces |
| By 2030 | ICAO milestone: 80% of states at or above 75% effective implementation | Institutional target | Later global implementation checkpoint |
| 27 March 2031 | Application of specified ground-handling information-security requirements | Published future application date | Extends the relevant information-security arrangements |
Sources: Information Security: Part-IS — EASA — guidance retrieved October 2026; Easy Access Rules for Ground Handling, Regulation 2025/20, Articles 5–6 — EASA — November 2025; Global Aviation Security Plan — ICAO — 2024; Easy Access Rules for Information Security — EASA — December 2025. EASA
The sequence creates an important distinction between legal commencement and operational maturity. A date can establish when a requirement applies without proving that every organisation’s implementation is effective. EASA’s Part-IS guidance itself discusses development and oversight of implementation stages for organisations under its responsibility. That should not be converted into a general exemption from the applicable deadlines.
Commercial regulation is also changing
On 13 July 2026, the Council announced final clearance of revised EU passenger-rights legislation. Its announcement describes commencement 12 months and 20 days after Official Journal publication. This delayed commencement means that approval and immediate applicability must remain separate in commercial planning. Council gives final clearance for stronger air passenger rights — Council of the EU — July 2026. Consilium
The relevant watch indicator is the operative published text and commencement date. Political announcements should not be used to apply future provisions retrospectively to a cancellation occurring under the earlier framework.
Four pathways define the strategic choices
| Scenario | Mechanism | Observable evidence supporting it | Evidence weakening it | Commercial implication |
|---|---|---|---|---|
| Managed improvement | Authorities clarify responsibilities and make exchanges more reliable | Completed corrective actions; documented implementation of restrictions; tested continuity arrangements | Recurrent unresolved handoffs despite revised procedures | More predictable decisions and fewer avoidable interruptions |
| Regulatory fragmentation | Destinations impose diverging requirements without compatible implementation | Conflicting data requests; repeated route-specific reassessment; incompatible notification arrangements | Agreed definitions and documented recognition arrangements | Greater administrative burden and less flexible crew allocation |
| Incident-driven restriction | A serious event produces urgent measures before a settled long-term framework | Binding directives, targeted suspensions and urgent official reviews | Prompt withdrawal or narrowing after evidence-based reassessment | Abrupt cancellations and replacement-capacity pressure |
| Digital false assurance | More connected systems reproduce incomplete, incorrect or compromised information | Official findings of corrupted records, unreliable interfaces or failed recovery | Successful integrity checks and demonstrated correction propagation | Rapid decisions followed by expensive reversals or interruptions |
These are analytical scenarios derived from the institutional dependencies already established and the implementation milestones cited above.
The managed-improvement pathway has the clearest mechanism for preserving both security and connectivity: a restriction reaches the organisation controlling access, its implementation is confirmed, and correction or reinstatement is equally traceable. Its principal obstacle is that several organisations must maintain a coherent understanding of the same person and decision.
Fragmentation can emerge even when every authority acts within its own competence. A requirement that is individually reasonable may conflict with another jurisdiction’s data format, timing or permitted disclosure. The resulting burden can reduce operational flexibility without supplying proportionate additional assurance.
Incident-driven restriction is an escalation pathway rather than a permanent prediction. Its significance depends on whether temporary measures acquire defined review conditions. Digital false assurance is different again: successful automation can make a defective premise travel faster. Its falsifier is demonstrated information integrity, not the quantity of software deployed.
Country indicators must follow the decision each country controls
The following are proposed collection priorities. They do not repeat the national procedures described in Pillar Two.
| Jurisdiction | Indicator to monitor | Record or observation required | Decision significance |
|---|---|---|---|
| Israel | Official clarification of the foreign-crew assurance arrangements implicated by the disclosure | Parliamentary finding, competent-authority procedure or audit | Establishes whether the disclosed admissions reveal an implementation defect |
| United States | Findings on the connection between approved personnel data and actual flight submissions | TSA/CBP oversight findings and relevant enforcement records | Tests whether existing mechanisms remain coherent during operational changes |
| European Union | Closure of cross-border and information-integrity deficiencies | Commission reporting and completed corrective actions | Tests convergence beyond common requirements |
| Italy | Effective removal of credentials when eligibility ends | ENAC and operator compliance evidence | Tests whether administrative decisions alter access |
| France | Consistency between security decisions and airport credential status | Competent-authority and airport records | Tests implementation of suspension, withdrawal and correction |
| Germany | Action following relevant later information | Aviation-security authority findings | Tests continuing assurance between scheduled reviews |
| United Kingdom | Handling and review of unavailable overseas records | CAA findings and documented case procedures | Tests how evidential uncertainty affects decisions |
| Middle Eastern operator states | Incorporation and execution of destination-specific instructions | Regulator and operator findings | Tests whether international obligations reach operations |
Institutional anchors: Israel eAIP, GEN 1.2; US master-list regulation; ENAC SEC-010; French Transport Code; German Aviation Security Act, section 7; UK CAA overseas-record guidance; ICAO operator and supplementary station procedures.
Evidence can initially look worse when detection improves
An increase in reported concerns, restrictions or corrections can reflect better identification and reporting. It can also reflect a worsening threat or a defective process. The count alone cannot distinguish these explanations.
Assessment should therefore examine what happened after detection. A reported concern followed by timely, justified action differs from a growing backlog of unresolved cases. Likewise, fewer restrictions could indicate improved assurance, reduced exposure or weaker detection. A credible outlook requires denominators, stable definitions and examination of outcomes.
Escalation and de-escalation need observable triggers
| Observation | Proposed analytical response | Evidence needed before broadening the response |
|---|---|---|
| Credible adverse information concerning an identified person | Assess and, where justified, restrict that person’s relevant access | Identity confirmation, authority and evidential basis |
| A confirmed failure recurring across an operator’s process | Examine the affected organisational control | Evidence establishing the extent of the common defect |
| Information integrity cannot be established | Limit operations dependent on the unreliable information | Confirmation of affected systems and trustworthy recovery |
| A restriction is based on a corrected identity error | Reassess and propagate the correction | Authoritative correction and confirmation of implementation |
| An operator demonstrates verified corrective action | Review the continuing need for restrictions | Evidence of effectiveness, rather than a new policy document alone |
These are proposed decision triggers, not descriptions of current mandatory thresholds.
Key judgments
- Published dates create opportunities to test implementation; they do not guarantee improved personnel assurance.
- The four scenarios can coexist across different routes and jurisdictions.
- More reports or restrictions can indicate improved detection, increased threat or poorer processing; outcome evidence is necessary.
- Restriction and restoration should both depend on observable conditions.
What would change the assessment: demonstrated convergence in cross-border procedures, repeated official findings of common information failures, or evidence that corrective measures consistently improve operational outcomes.
Open official record: the available evidence does not support numerical probabilities for these scenarios, a comparable forecast of security-related cancellations, or a forecast of individual insider attacks through 2031.
Chapter 8: Policy options and final net assessment
The principal judgment is that policy should make individual and organisational decisions enforceable, reviewable and proportionate to the evidence. The strongest package combines targeted intervention with reliable information exchange, operational continuity and independent examination of failures.
A restriction justified by credible evidence should not be weakened to protect the timetable. Equally, uncertainty should not become a permanent, unexplained restriction on an entire population when the demonstrated defect concerns a specific person, record or process.
Start with the scope of the demonstrated defect
A nationality category can identify a jurisdiction from which records may be difficult to obtain. It does not, by itself, establish the completeness of an individual’s history or the presence of hostile intent. Citizenship also cannot capture every relevant residence, employment relationship or subsequent change.
The defensible policy question is therefore what evidence is available for the decision required. Where that evidence is insufficient, the authority should identify the insufficiency and the conditions for resolving it. Where an individual threat is substantiated, the response should address the person and access concerned. Where a common organisational defect is substantiated, the response can expand to that demonstrated scope.
Compare implementation requirements before selecting an option
The options below are proposals. Their availability and implementation must be assessed under the relevant jurisdiction’s powers; the table does not confer new legal authority.
| Option | Responsible authority or organisation | Expected effect | Implementation burden | Time to effect |
|---|---|---|---|---|
| Focused assurance audit | Competent aviation-security authority, with authorised oversight access | Identify the decision or implementation defect | Access to records, appropriately cleared personnel and operator cooperation | Can begin through existing oversight; findings depend on record quality |
| Acknowledged restriction and correction notices | Competent authorities and organisations controlling access | Confirm that a decision reached the correct recipient and was implemented | Agreed identities, recipients, secure communication and records | Procedural improvements first; full effect after integration and testing |
| Eligible replacement-crew arrangements | Airline management under applicable operational and destination requirements | Reduce disruption without overriding restrictions | Staffing, positioning and maintenance of operational eligibility | Effective when qualified substitutes are available |
| Structured bilateral assurance arrangements | Relevant governments, security authorities and aviation regulators | Clarify what an assessment covers and how changes are communicated | Legal agreements, safeguards, common definitions and verification | Depends on negotiation and demonstrated implementation |
| Information-integrity and continuity controls | Operators, service providers and competent oversight authorities | Preserve trustworthy decisions during system failure | Technical controls, recovery testing and organisational coordination | Phased effect as controls are implemented and exercised |
| Review and correction mechanism | Decision authority and competent review body | Correct mistaken or obsolete restrictions | Protected access to evidence and a workable review process | Case-level effect when authoritative decisions are implemented |
| Targeted operational restriction | Authority possessing the applicable power | Prevent exposure while a demonstrated serious defect remains unresolved | Evidential justification, enforcement and review | Potentially immediate under the applicable power |
The legal and institutional starting points include existing US foreign-carrier security-programme powers, European national aviation-security responsibilities, and UAE aviation-security regulations.
| Option | Reversibility | Second-order consequence | Principal risk |
|---|---|---|---|
| Focused audit | Scope can be adjusted; findings remain part of the record | Can identify failures outside the original allegation | A narrow sample may miss a common defect |
| Acknowledged notices | Procedures can be revised | Makes organisational handoffs auditable | Incorrect identity information can propagate rapidly |
| Replacement crews | Staffing allocation can change | Protects connectivity during justified intervention | Reserve personnel may not satisfy the destination’s requirements |
| Bilateral arrangements | Can contain review and suspension provisions | May reduce duplicated assessment | Recognition can exceed what the underlying evidence supports |
| Integrity and continuity controls | Architecture changes can be costly to reverse | Reduces exposure to some common service failures | A poorly controlled fallback can undermine the original restriction |
| Review and correction | Individual decisions can change | Reduces repeated disruption from obsolete information | Review may be ineffective if the decision cannot be examined meaningfully |
| Targeted restriction | Can be narrowed or withdrawn | Produces immediate connectivity and commercial effects | Scope or duration can outlast the demonstrated necessity |
The practical preference is a combined package. Audit identifies the defect; acknowledged notices make decisions executable; continuity arrangements reduce avoidable disruption; review corrects mistakes. Targeted restriction remains available where the evidence and authority support it.
Exchange the information necessary for the decision
A proposed bilateral arrangement should define the meaning of any transmitted assurance. “Eligible” is insufficient unless the recipient understands the assessment’s scope, relevant limitations and means of notification when circumstances change.
For an operator, the essential output may be permission, restriction or a requirement for further assessment. The supporting intelligence can remain with the competent authority, subject to the applicable arrangements. This approach reduces unnecessary circulation while preserving responsibility for the operational instruction.
It must not be treated as a legal shortcut. Criminal-record processing and international transfers still require their respective bases and safeguards. UK ICO guidance similarly requires organisations processing criminal-offence data to identify the relevant authority or legal condition and account for minimisation and security. What are the rules on criminal offence data? — Information Commissioner’s Office — undated, retrieved October 2026. ICO
Reduce duplicate paperwork without reducing accountability
EASA’s ground-handling initiative provides a relevant institutional example. Its March 2025 explanation identifies a workforce exceeding 300,000 at EU airports and estimates that duplicate industry auditing can reach as many as 600 audits for one provider serving 100 stations. The latter is an illustrative upper scale reported by EASA, not an average for all providers. Ground handling’s importance for aviation safety recognised with new rules — EASA — March 2025. EASA
The policy lesson is limited but useful: repeated assurance activity can consume resources without resolving responsibility at interfaces. It does not follow that safety oversight substitutes for security vetting. Instead, policymakers should identify which decisions require independent examination and which administrative tasks can be coordinated.
The Commission’s aviation-security report separately identifies vulnerabilities involving supplier dependence, remote maintenance and information integrity. These findings support scrutiny of the systems and services on which assurance depends, rather than an exclusive focus on the employee being assessed. 2025 aviation-security annual report — European Commission — July 2026, section 2.2.2.
National implementation should address a concrete unresolved decision
| Jurisdiction | Proposed priority | Deliverable that permits accountability |
|---|---|---|
| Israel | Establish how the disclosed foreign-crew cases were assessed and handled | Competent review distinguishing lawful admissions, information limitations and substantiated failures |
| United States | Examine reconciliation when actual personnel or relevant information change | Oversight findings showing whether approval and flight-specific action remained coherent |
| European Union | Coordinate assurance definitions and information safeguards | A common description of assessment scope and exceptions |
| Italy | Test implementation of credential withdrawal and return | Compliance findings connecting eligibility changes to access removal |
| France | Test reconciliation between prefectural decisions and airport credentials | Evidence that restrictions and corrections reach the airport |
| Germany | Examine action following subsequent relevant information | Findings identifying notification, reassessment and resulting action |
| United Kingdom | Review the use of alternative overseas evidence | Findings explaining how limitations affect suitability decisions |
| Middle Eastern operator states | Test execution of destination-specific requirements | Regulator-verified evidence of notification, implementation and correction |
These are proposed outputs, not claims that the respective authorities have already adopted them.
Oversight should protect sensitive details while exposing performance
Public accountability does not require publication of intelligence sources, individual files or exploitable operational details. It does require enough information to distinguish a functioning system from one whose effectiveness is merely asserted.
A useful reporting arrangement would separate the public account from protected oversight access.
| Suitable subject for aggregate public reporting | Material requiring protected examination |
|---|---|
| Scope and period of an assurance review | Individual identities and personal histories |
| Categories of substantiated deficiencies | Intelligence and confidential source material |
| Corrective actions completed or outstanding | Detailed operational vulnerabilities |
| Restrictions reviewed, narrowed or withdrawn | Case-specific evidence and matching information |
| Operational disruption attributed to identified causes | Protected airline and authority records |
| Definitions and limitations of published statistics | Data necessary to verify those statistics |
This is a proposed reporting distinction; publication decisions remain subject to the applicable law.
Such reporting should also preserve disagreement. A regulator’s account, an airline’s account and a parliamentary finding may concern different questions. Repeated statements should not be converted into corroboration when they derive from the same underlying record.
Final net assessment
The Israeli disclosure warrants examination of decisions and implementation. The user-specified report does not independently establish that each admission was unlawful, that each individual presented a threat, or that the reported population supplies a measure of attack risk. Some 1,240 aircrew from countries that don’t recognize Israel reportedly entered country in past year — The Times of Israel — October 2026. www.timesofisrael.com
The wider national-security concern applies wherever an authority permits operational access partly on information generated elsewhere. The danger lies in an unidentified limitation, an uncorrected record, a warning that does not reach its recipient or a restriction that is never implemented. The commercial counterpart is prolonged uncertainty that prevents legitimate operations from recovering.
Through 2031, the relevant test will be demonstrated performance at those handoffs. Published implementation milestones and expanding information-security obligations create opportunities for scrutiny. They cannot substitute for evidence that a decision concerning the correct person reaches the organisation controlling access and changes what that person can do.
Key judgments
- The strongest policy package combines targeted intervention, executable notifications, qualified replacement capacity and effective correction.
- Restrictions should expand to the demonstrated scope of a defect and contract when verified evidence supports restoration.
- Cooperation should communicate the meaning and limits of assurance, rather than create unexplained declarations of clearance.
- Public reporting and protected oversight should provide different levels of detail while supporting the same accountable conclusions.
What would change the assessment: an official finding of systematic foreign-crew approval failures, demonstrated correction of those failures, or evidence that a proposed intervention produces substantial disruption without addressing the identified defect.
Open official record: decisive gaps remain in individual assessment outcomes, cross-border warning implementation and verified incident-specific commercial costs. Those gaps prevent country rankings or numerical attack forecasts; they do not prevent authorities from examining responsibility and acting on substantiated evidence.
The final policy test is whether credible information changes operational access in time, and whether verified correction restores legitimate access without avoidable delay.

















