Fuel Switches Blamed As Air India Flight AI171 Crash Raises Global Aviation Safety Alarms

Two unexplained fuel switch movements caused Air India Flight AI171 to lose thrust and crash, killing 260 people and raising global safety concerns

Fuel Switches Blamed As Air India Flight AI171 Crash Raises Global Aviation Safety Alarms

The preliminary report issued by India’s Aircraft Accident Investigation Bureau into the crash of Air India Flight AI171 is composed, technical, and profoundly unsettling. It does not indulge in conjecture. It refrains from assigning blame. It confines itself to verified data. That data, however, tells a story no aviation system wants to read.

On 12 June 2025, just 32 seconds after take-off from Ahmedabad, a Boeing 787 Dreamliner with 241 people on board lost all engine thrust. The engines did not fail due to weather, impact, fuel starvation, or any expected mechanical fault. They stopped producing power because the fuel control switches for both engines moved from RUN to CUTOFF within one second of each other. The aircraft then lost altitude, struck a residential hostel belonging to BJ Medical College, and exploded. Everyone on board died. Nineteen more people on the ground were also killed. Two switches moved. The consequences were absolute.

The aircraft was not old. It had been delivered to Air India just over a decade earlier and had no deferred maintenance. It had landed in Ahmedabad the previous evening after a flight from Delhi. Routine checks were completed. No warnings were logged. The cockpit was staffed by two qualified pilots. The captain had over fifteen thousand flight hours. The first officer had over three thousand four hundred. Both were medically cleared, properly rested, and trained to fly this exact model. There was nothing irregular in the preflight inspection or in the departure itself. Until the fuel flow to the engines stopped.

The voice recorder captured a conversation between the pilots that lasted only moments. One of them asked, “Why did you cut off the fuel supply?” The other replied, “I did not.” The words are important. They were not shouting. They were not confused. They were reacting to something that made no sense in that moment. Two fuel switches located on the overhead panel had moved to CUTOFF without any apparent command. There were no alerts. There was no prior system failure. Yet both engines lost thrust while the aircraft was climbing through less than 500 feet.

This incident was not caused by turbulence, weather, or misjudgment; it was caused by two switches moving to a position that no one had ordered and that no one had expected

After the engines stopped producing power, the aircraft’s emergency systems responded. The Ram Air Turbine deployed automatically to supply limited electrical and hydraulic control. The crew acted quickly. They moved the switches back to RUN. Engine 1 responded, but too late. Engine 2 did not recover. The aircraft could not sustain flight without both engines. The nose never rose again.

What makes this case deeply disturbing is not only the unexplained loss of thrust, but the fact that a known advisory about the vulnerability of these very switches existed. In August 2018, the United States Federal Aviation Administration issued a safety bulletin. That document warned of the possibility that fuel control switches on Boeing aircraft could become unreliable or move unintentionally due to guard design or locking failure. The bulletin urged operators to inspect and confirm the reliability of these components. But it was not a mandatory directive. It was advisory only. Air India did not act on it. The aircraft involved in this crash was never subjected to any inspection or modification of the fuel switch mechanism. That decision was legal. But it now raises a quiet and unavoidable question about shared responsibility. If a known weak point in an essential system is left unaddressed and later becomes the trigger for a disaster, who is responsible for the silence that followed the warning?

The report also mentions that on its previous flight, the aircraft recorded a stabiliser position sensor fault. That fault was reviewed by Air India’s engineering team and cleared. No connection has yet been proven between that earlier fault and the failure of the fuel switches. But the AAIB is now investigating the aircraft’s electrical control architecture and all subsystems that interface with the cockpit controls. The possibility of a software error or electrical anomaly remains open.

What makes the loss of Flight AI171 unique is its complete deviation from known failure patterns. Modern twin-engine aircraft are designed to tolerate the failure of one engine. Losing both engines during take-off, without a fire, impact, or external disruption, is almost unheard of in contemporary aviation. That both engines stopped producing thrust due to internal switch movement—and that this occurred without input or awareness from the crew—creates a scenario that is not only rare but difficult to model.

Investigators from the United States, the United Kingdom, and Boeing itself are assisting in the analysis. The switches have been recovered. The aircraft’s data recorders are intact. System-level tests are being conducted on the entire engine control chain. Every piece of cockpit hardware and software related to power management is under forensic review.

The AAIB has not issued any recommendations. This is a preliminary report. But the evidence already published raises difficult and immediate questions. Should advisories regarding safety-critical controls be left to airline discretion? Should there be mandatory inspection intervals for all physical engine control interfaces? Should Boeing review its design logic and protection barriers around the switch mechanisms in all aircraft of this class?

This was the first fatal crash of a Boeing 787 Dreamliner since it entered commercial service in 2011. The aircraft type had developed a reputation for reliability. But that reputation now faces a rare and serious challenge. Because this incident was not caused by turbulence, weather, or misjudgment, it was caused by two switches moving to a position that no one had ordered and that no one had expected. That should not be possible in a system built to protect against exactly that.

There is no closure yet. The questions remain technical. The consequences remain human. An aircraft took off. Two switches were moved. The engines died. The recovery came too late. The silence that followed must now be filled with clarity, accountability, and truth.

The author is a freelance analyst on domestic affairs, public policy and geopolitics. She can be reached at maham1fazal@gmail.com & X: @MahamFazal_