The Word “Takeoff” Had Two Meanings

On 27 March 1977, two Boeing 747s collided on a runway at Los Rodeos Airport on Tenerife.

Five hundred and eighty-three people died.

It remains the deadliest accident in aviation history.

The immediate physical event was simple: a KLM aircraft began its takeoff while a Pan Am aircraft was still on the same runway.

Everything around that event was not simple.

There was dense fog. The airport was congested after flights had been diverted from Gran Canaria because of a bomb. Aircraft had to taxi along the runway because parked planes blocked the parallel taxiway. The tower could not see the aircraft and had no ground radar.

Then language failed.

The KLM crew reported, in accented and non-standard phrasing, that it was “at takeoff.” The controller responded with “OK” followed by an instruction to stand by—but part of that transmission was obscured by radio interference.

Different people heard the same exchange and constructed different realities.


The idea in 20 seconds

  • Communication is not successful because a message was sent.
  • Ambiguous words become dangerous when the receiver can act before meaning is confirmed.
  • Readbacks are interface feedback: they expose misunderstanding while it is still reversible.
  • Hierarchy can silence the information a system most needs.

In a critical system, “I said it” and “they understood it” are entirely different states.

A chain of ordinary complications

Neither flight was supposed to be at Los Rodeos.

Both had been diverted from Gran Canaria. The smaller airport became crowded. When Gran Canaria reopened, the aircraft prepared to continue their journeys.

The KLM 747 taxied down the runway, turned around and lined up for departure.

The Pan Am 747 followed on the same runway and was instructed to leave through the third exit. In the fog, the crew had difficulty identifying the correct unmarked turn.

The KLM aircraft was now positioned at one end of a runway that the Pan Am aircraft had not yet cleared.

The controller issued the KLM its route clearance.

A route clearance explains what an aircraft should do after departure.

It is not the same as permission to take off.

But the exchange used the word “takeoff” in a context where the distinction was not clear enough.

The KLM began accelerating.

The KLM Boeing 747 PH-BUF, named The Rhine, on a taxiway in 1976 — the aircraft later destroyed in the 1977 Tenerife runway collision.
KLM’s Boeing 747 “The Rhine” (PH-BUF), photographed in 1976. A year later, in fog at Tenerife, its captain treated “we are now at takeoff” as clearance — and began the run that killed 583 people. Photo: clipperarctic, CC BY-SA 2.0.

“OK” is not a state

The word “OK” feels reassuring because it can mean almost anything:

  • I heard you.
  • I agree.
  • Your request is approved.
  • Continue.
  • Wait while I respond.

That flexibility is useful in conversation.

It is dangerous in a protocol.

The tower’s “OK” was followed by “stand by for takeoff, I will call you.” A simultaneous radio transmission created a shrill interference sound that obscured part of the message in the KLM cockpit.

If “OK” can be interpreted as approval, then the most immediately audible part of the message points in the wrong direction.

The accident report concluded that the KLM captain took off without clearance and did not stop when the uncertainty should have become apparent.

But the communication system also allowed a catastrophic misunderstanding to survive.

Silhouette of an air traffic controller speaking into a microphone at Amsterdam Schiphol Airport's control tower, with the airfield visible through the glass behind him.
A controller's transmission is only ever as clear as the words chosen to carry it. Photo: Mark Brouwer, CC BY-SA 2.5.

A protocol is designed language

Natural language is rich because it tolerates ambiguity.

Protocols work by removing it.

After Tenerife, aviation placed greater emphasis on standard phraseology. The word “takeoff” became reserved for the actual takeoff clearance or its cancellation. In other situations, crews use “departure.”

Pilots read back critical instructions. Controllers listen for errors in the readback and correct them.

This creates a loop:

instruction → repetition → confirmation

The repeated message may feel inefficient.

But its purpose is not to move information faster.

Its purpose is to reveal whether the same meaning exists in two minds.

Air traffic controllers wearing headsets and microphones work at radar consoles beneath wall-mounted sector maps at an FAA air route traffic control center.
Standard phraseology and readback exist so that every instruction like this one is repeated back before it is acted on. Photo: Federal Aviation Administration, public domain.

Readback is the human version of a confirmation screen

Imagine transferring ₹2 lakh through an app.

You select an account and enter an amount.

Before the money moves, the app shows:

You are sending ₹2,00,000 to Archita Joshi.

That screen is a readback.

The system translates your input into its own interpretation and gives it back to you for verification.

Critical interfaces use this pattern everywhere:

  • a pharmacist repeats a prescription,
  • a surgical team confirms the patient and procedure,
  • a bank shows the recipient before payment,
  • a deployment tool shows the environment and version,
  • a deletion dialog names the item that will disappear.

“Are you sure?” is weak.

“Delete the production database customers-eu?” is a real readback.

Confirmation works only when it repeats the meaning, not merely the intention to act.

The cockpit had a hierarchy problem too

Communication did not fail only between aircraft and tower.

Inside the KLM cockpit, the flight engineer questioned whether the Pan Am aircraft had cleared the runway.

The captain responded emphatically that it had.

The takeoff continued.

The captain was highly experienced and held substantial authority. That authority made disagreement harder at exactly the moment when disagreement was valuable.

Modern crew resource management grew partly from aviation’s recognition that technical skill is not enough. Teams need explicit ways for junior members to challenge decisions, surface uncertainty and escalate concerns.

An interface can show a warning.

A culture can teach somebody not to press it.

System design includes both.

The three-crew flight deck of a classic KLM Boeing 747-200, showing the captain and first officer seats and the overhead panel facing the flight engineer's station.
A classic 747 flight deck seated three: captain, first officer and flight engineer. At Tenerife, the engineer's doubt was overridden. Photo: Felix Stember, CC BY-SA 3.0.

Ambiguity grows under pressure

The Tenerife collision did not happen in a calm room where everybody could pause and clarify.

It happened amid fog, delay, congestion, radio interference, time pressure and unfamiliar conditions.

This matters because many systems are designed and tested under polite circumstances.

Then they are used:

  • by a tired nurse at the end of a shift,
  • by a driver in heavy rain,
  • by a customer whose payment just failed,
  • by an operator during an outage,
  • by somebody speaking a second language,
  • by a team already expecting one particular answer.

Stress does not create every ambiguity.

It removes the spare attention that normally compensates for it.

The burnt-out fuselage skeleton and landing gear of one of the Boeing 747s wrecked on the runway at Los Rodeos airport after the 1977 collision.
The wreckage at Los Rodeos afterward. None of the pressures that produced it — fog, delay, congestion, interference — were unusual on their own. Photo: Nationaal Archief / Anefo, CC0.

The shared-meaning test

For every consequential instruction, ask:

Does each important word have one operational meaning?

Reserve critical words for critical states.

Does the receiver repeat the interpreted instruction?

Confirmation should expose meaning, destination, quantity and state.

Can the system act before confirmation?

Delay irreversible action until shared understanding exists.

What happens when two messages collide?

Design for missing, delayed, duplicated and interrupted communication.

Can a junior person stop the process?

Escalation must be structurally safe, not merely culturally encouraged.

Does uncertainty look different from approval?

“Received,” “approved” and “completed” should never collapse into “OK.”

One final thought

We like to believe that language becomes clear when the stakes are high.

People will be precise because the moment is serious.

Tenerife shows the opposite.

High stakes often arrive with noise, urgency, expectation and hierarchy. Those conditions make ambiguity more dangerous and clarification more difficult.

So serious systems cannot depend on everybody choosing perfect words in the moment.

They must design the words, the sequence and the confirmation in advance.

The safest language is not the language that sounds professional. It is the language that makes two different interpretations difficult.

A message was transmitted at Tenerife.

What was missing was shared meaning.

Sources and further reading

More writing

systems designerror preventionhuman factors

The $125 Million Unit Label

The Mars Climate Orbiter was lost at the boundary between two teams—and that boundary is where many systems actually fail.

human factorssystems design

The Game Was a Disguise

A protest campaign for Afghanistan's banned women cricketers, and the lesson that design's first job is to protect the people in it.

human factorssystems design

We Made Them Better Traders. They Still Lost.

I designed a crypto app that made trading simple, fun, and better. People still lost money — because the real game was never about skill.