How a Tornado Navigator Dropped Two Fuel Tanks by Mistake
Dear Algorithm,
The neuroscience of the perfectly executed wrong decision, and what it means for every expert.
Dear Algorithm,
I want to tell you about a day in the early 1990s when a highly trained, deeply experienced Royal Air Force fast jet aviator, a man who had spent over a thousand hours in the cockpit of one of the most demanding aircraft in the British inventory, reached down in a Tornado F3 and made a perfectly executed, entirely wrong decision.
He intended to change a channel on the missile management system. A routine switch action. The kind of thing you do dozens of times during a sortie without so much as a conscious flicker. His hand moved to the panel, his fingers found a switch, and he actioned it with the clean confidence of someone who knew exactly what they were doing.
What he was doing, as it turned out, was jettisoning two Lima fit fuel tanks into a farmer’s field somewhere below.
The aircraft was fine. The Navigator was fine, if perhaps a little warm around the ears. The farmer, one imagines, had a considerably more eventful afternoon than anticipated. And the subsequent human factors debrief was, in the RAF tradition, thorough, structured, and entirely free of comfort.
I was not the Navigator in question, I should clarify. But I was around for the aftermath, and the questions it prompted have stayed with me ever since. Because what happened that day was not a lapse of skill, a failure of training, or a moment of carelessness. It was something more fundamental and, in many ways, more troubling than any of those things. It was the brain doing exactly what brains are designed to do, at precisely the wrong moment.
The Engine That Runs Without You
There is a passage in Daniel Kahneman’s Thinking, Fast and Slow that, when you first encounter it, feels almost too simple to be profound. He proposes that human cognition operates through two distinct systems. System 1 is fast, automatic, associative, and largely unconscious. System 2 is slow, deliberate, effortful, and conscious. System 1 drives most of what you do. System 2 is the one you think you are using.
The reason this framing is so useful, and so quietly unsettling, is that it reframes the entire question of human error. We tend to think of mistakes as failures, gaps in knowledge or attention where something went wrong. Kahneman’s model suggests that most errors are not failures at all. They are successes of the wrong kind. System 1 fired, as it was designed to, and delivered an answer that was wrong for the current context but entirely consistent with the patterns it had learned.
Your brain is, in the most fundamental sense, a prediction machine. It does not passively observe the world and consciously respond. It continuously generates predictions about what is happening and what should happen next, and it updates those predictions based on incoming information. When the incoming information is familiar, and the stakes feel manageable, System 1 handles the whole thing without troubling System 2 at all. This is the basis of expertise. It is also, in specific and important circumstances, the mechanism of catastrophic error.
James Reason, the British psychologist whose work on human error is as foundational as anything in the field, gave a more granular taxonomy to the kinds of mistakes that emerge from this architecture. He distinguished between slips, lapses, mistakes, and violations. The incident in the Tornado falls cleanly into the category he called a capture error, a specific type of action slip in which a well-practised, highly automatic routine “captures” an intended action because the two share enough of their initiation sequence to be, at the critical moment, indistinguishable.
The navigator intended to do X. He had done X hundreds of times before. X and Y begin with the same motor programme. And in the fraction of a second between intention and execution, under the cognitive load of a live tactical environment, System 1 delivered Y with total confidence.
The brain did not malfunction. It ran the wrong subroutine, perfectly.
Why Expertise Is a Double-Edged Instrument
Here is the counterintuitive truth at the heart of this, the one that tends to produce a slightly uncomfortable silence in any room full of high-performers. The more expert you are, the more vulnerable you are to this specific category of error.
This is not a paradox once you understand the mechanism. Expertise is, essentially, the progressive migration of competence from System 2 to System 1. When you are learning a skill, every component demands conscious attention. You think about your feet, your hands, the sequence of actions, the consequences of each decision. It is effortful, slow, and exhausting. As you practise, the conscious overhead reduces. Subroutines that once required deliberate execution become automatic. Eventually, the skill runs without you.
This is not merely convenient. In high-demand environments, it is essential for survival. A fast jet aviator who had to consciously think through every switch action would be overwhelmed long before they left the circuit. The automaticity that expertise confers is what creates the cognitive headroom to manage the tactical problem, the threat picture, the fuel state, the radio calls, and the hundred other things competing for attention at any given moment.
But that same automaticity has a cost. When a skilled operator reaches for a control in a familiar environment, the action is not consciously initiated in the way a deliberate act would be. It is triggered by context. The wrong context, or an ambiguous one, can trigger the wrong action with the same fluency and confidence as the right one. And crucially, the subjective experience is identical. There is no internal alarm, no hesitation, no felt sense that something has gone wrong. You perform the wrong action and it feels exactly like performing the right one.
This is why error analysis in aviation shifted so significantly in the 1980s and 1990s away from pilot culpability and towards systems thinking. The question stopped being “why did the pilot do the wrong thing?” and became “what features of the environment, the interface, the task design, and the cognitive architecture made this error not just possible but, under the circumstances, predictable?”
That reframing, from blame to mechanism, is one of the most important intellectual moves in the history of applied psychology.
The Load Problem
Capture errors do not occur in isolation. They have conditions that favour them, and those conditions are not random. The research consistently identifies a cluster of factors that reliably increase the likelihood of an action slip: high cognitive load, time pressure, fatigue, divided attention, environmental ambiguity, and the presence of a competing habitual response that shares its early motor sequence with the intended action.
In the Tornado cockpit, essentially all of those factors are present as a matter of routine. The aircraft is generating information faster than any person can consciously process. Radio calls are coming in on multiple channels. The tactical picture is evolving. Fuel and weapon states need tracking. And somewhere in the middle of all of that, a routine switch action is required, one that the pilot or navigator has performed correctly hundreds of times before, alongside a different switch action that they have also performed correctly hundreds of times before, on a panel that they know intimately well.
The panel knowledge is the problem, in a very specific way. Deep familiarity with a physical environment means that navigation of it becomes partly automatic. You do not look at each switch and consciously identify it. You know roughly where things are, and you move to them with the confidence of established spatial memory. But spatial memory is coarse. It gets you close. Under high load, close is sometimes close enough to trigger the wrong programme.
There is an elegant and slightly grim metaphor in Reason’s work involving garden paths. He observes that errors tend to occur at the points where the path you intended to take diverges from a more familiar path. The further you are from the divergence point, the more committed you are to the wrong route, and the less likely you are to notice. In a cockpit at operational tempo, by the time you notice the divergence, you have already switched the switch.
Where Psychological Type Enters the Frame
So far, this is a story about cognitive architecture, which is universal. We all have a System 1 and a System 2. We all generate prediction errors. We are all vulnerable to capture errors under sufficient load. None of that is type-dependent.
But not all of it is type-neutral either.
The STAR Framework maps four fundamental psychological orientations, each grounded in a distinct motivational need drawn from Self-Determination Theory and related psychological literature. Socialisers are driven by Relatedness. Thinkers are driven by Competence. Adventurers are driven by Autonomy. Realists are driven by Security. These are not personality quirks or stylistic preferences. They are deep motivational structures that shape how people perceive threat, process information, make decisions, and respond to error.
And when you map those structures onto the conditions that generate cognitive failure, some genuinely interesting and differentiated vulnerabilities begin to emerge.
The Thinker processes the world through the lens of competence and mastery. Their cognitive architecture is oriented towards accuracy, precision, and systematic execution. This is, in many respects, an excellent profile for high-skill technical environments. Thinkers build robust mental models, maintain detailed procedural awareness, and tend to be resistant to shortcuts. But that same architecture creates a specific vulnerability under load: the Thinker’s deep investment in procedural accuracy means that when automaticity runs a familiar subroutine, there is very little motivational friction to interrupt it. The subroutine feels right, because it is precise and practised, which are the very things the Thinker’s System 1 is calibrated to trust.
The Realist operates from a Security drive. Procedural adherence, established routines, and predictable sequences are not just professional standards for the Realist; they are psychologically reinforcing. Every time the established procedure works, it confirms the Realist’s cognitive model of the world as a place that responds well to careful, methodical action. This makes the Realist highly effective in stable, procedure-rich environments. But it also means that automatic routines are more deeply grooved, and more psychologically rewarded, than in other types. The capture error risk is high, not because the Realist is less careful, but because their entire motivational structure is oriented towards the very behaviours that automaticity exploits.
The Adventurer presents a different picture. The Autonomy drive means that Adventurers tend to resist rigid proceduralism and are more likely to maintain a degree of deliberate conscious engagement with tasks, even familiar ones, because the routine itself is mildly aversive. This is not necessarily an advantage in a cockpit, where departing from established procedure is a category of error in its own right. But in terms of capture error specifically, the Adventurer’s tendency to engage System 2 more actively with familiar tasks may provide a partial buffer. They are paying attention, even when they do not strictly need to, because the routine demands a kind of conscious presence that sits better with their motivational wiring.
The Socialiser brings yet another dimension. The Relatedness drive means that Socialisers are highly attuned to interpersonal context, team dynamics, and the social meaning of actions. In single-seat aviation this matters less, but in multi-crew environments, or in any operational setting where team coordination is part of the task load, the Socialiser’s attention is partly allocated to relational monitoring. This creates a specific divided-attention vulnerability. The cognitive load generated by social context awareness competes with the procedural task, and when load spikes, the capture error window opens.
None of this is deterministic, and it would be a misreading of the STAR model to treat it as a simple risk matrix. What it offers is not a prediction of who will make errors, but a richer account of the conditions under which different psychological types are most vulnerable, and therefore the most useful places to direct both individual self-awareness and system-level design.
The Interface Problem
There is a parallel thread running through the human factors literature that deserves its own moment here, because it changes the nature of the problem in a fundamental way.
Much of the early work on cockpit error focused, implicitly, on the human as the locus of the problem. The pilot did the wrong thing. The question was why. The shift that occurred through the 1980s and into the 1990s, driven in large part by the commercial aviation sector’s adoption of Crew Resource Management and by work at institutions like the NASA Ames Research Center, was a recognition that the design of the environment was as much a cause of error as any feature of the human inside it.
Two switches that look alike, feel alike, and sit adjacent to each other in a panel are not a neutral design feature. They are a latent error trap. The human is not failing when they confuse them under high load; they are behaving entirely predictably given the cognitive architecture they are working with and the environment that has been created for them. The responsibility shifts, at least partly, from the operator to the designer.
This principle, now foundational to human factors engineering, has migrated well beyond aviation. It underpins how medical device interfaces are designed, how nuclear power plant control rooms are laid out, how road signage is standardised, how software interfaces handle destructive actions. The irreversible action that requires multiple deliberate confirmations before it executes is a direct response to capture error research. Someone, somewhere, learned about a switch flipped at the wrong moment, and decided to make that particular mistake structurally harder to make.
The Lima fit tanks are, in a very real sense, why your computer asks you “are you sure?” before it empties the bin.
The Human Under Pressure Is Not a Defective Machine
There is a temptation, when surveying the evidence on cognitive failure, to conclude that the human is fundamentally unreliable, a biological system prone to systematic error in ways that should probably be replaced, wherever possible, by something more consistent. This conclusion is both understandable and entirely wrong.
The same mechanisms that generate capture errors, the automaticity, the pattern completion, the confidence of System 1, are the mechanisms that make human expertise possible at all. You cannot have one without the other. A cognitive architecture that never ran automatic programmes would be an architecture incapable of the kind of fluid, integrated performance that high-skill tasks demand. The pilot who has to consciously think through every switch action is not a safer pilot. They are an overwhelmed one.
Kahneman’s great contribution is not to indict System 1. It is to make us honest about what it is, what it does, and under what conditions its outputs need to be checked by System 2. The practical question is not how to eliminate automaticity but how to design environments, procedures, training regimes, and team structures that engage deliberate cognition at the moments when it is most needed, and create the conditions for error detection and recovery when it fails.
This is where the STAR Framework has something genuinely useful to contribute to the conversation, because the design of those interventions is not type-neutral. A training programme that works with the Thinker’s existing orientation towards systematic review will not land the same way for an Adventurer, who needs the intervention to engage their sense of active agency rather than procedural compliance. A debriefing culture that works well for a Realist, structured, sequential, procedurally anchored, may feel constraining and counterproductive to a Socialiser, who processes experience most effectively through relational dialogue and shared meaning-making.
The goal of reducing cognitive failure in high-stakes environments is the same across all types. The path to that goal is not.
What the Farmer’s Field Taught Me
The debrief that followed the Lima fit incident was, by all accounts, conducted with the thoroughness the RAF applied to these things. The mechanism was understood, the contributing factors were documented, and the navigator in question returned to flying having added one more layer to a mental model that was already rich and carefully maintained. He did not stop being a good navigator. He became a more self-aware one.
That, in miniature, is the whole project. Not the elimination of the human from the loop, not the replacement of System 1 with something more reliable, but the cultivation of a more honest relationship with the cognitive architecture we actually have, rather than the one we imagine ourselves to have.
We are not, any of us, running on a clean logical process that produces the right answer when correctly supplied with the right information. We are running on a biological prediction engine shaped by evolution, experience, habit, and motivation, and it is extraordinary, and it fails in predictable ways, and understanding those ways is not a concession to weakness. It is the beginning of genuine competence.
Somewhere in a field that may by now have grown quite a decent crop of cognitive psychology metaphors, two Lima fit tanks are sitting in the soil. And the question they pose is not “how could he have been so careless?” but “what does it mean to understand your own mind well enough to trust it where you should, and check it where you must?”
That question does not have an algorithm. Not yet.
~ David Chadderton
David Chadderton began his career making split-second decisions at 30,000 feet as a Royal Air Force Top Gun Instructor. He has spent the years since trying to understand why intelligent people, in considerably less pressurised circumstances, still make avoidable mistakes. That question led him to create the STAR Framework, a behavioural science model built on seven psychological theories, which he now applies through STAR Dynamics, his consultancy, and in his role as Chief Marketing Officer at Homes for Students, VervLife and Orla, a portfolio of student accommodation brands generating over £650 million in annual revenue. His book “The STAR Framework: Rewriting The Rules of Consumer Engagement” won the NYC Big Book Award 2025. This Substack is where he thinks out loud about human behaviour, organisational psychology, and why the gap between intention and outcome is almost always more interesting than either.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.