A modern airport can have clear runways, working terminals, fueled aircraft, available crews, functioning gates and perfect weather — and still be unable to operate normally. The reason is that the airport is only one visible endpoint of a much larger machine. Behind every arrival and departure is a distributed air-traffic-control system of towers, approach-control facilities, en-route centers, surveillance, radios, flight-data systems, telecommunications networks, traffic-flow management and people.
On September 21, 2026, that hidden architecture became visible. A telecommunications failure affecting the Philadelphia Terminal Radar Approach Control facility, combined with a severed backup fiber-optic path in New Jersey, disrupted traffic at major Northeast airports and propagated delays across the United States. Reuters reported more than 5,600 disrupted U.S. flights, including roughly 1,200 in the New York area, as the event developed.
The lesson is larger than a damaged cable. Redundancy is not the number of cables on a diagram. It is the number of genuinely independent failure paths in the real world.

What Happened: A Failure Chain, Not Merely a Cable Cut
Current reporting, including statements attributed to FAA and Transportation officials, indicates that a primary telecommunications circuit at Philadelphia TRACON failed. When the system needed its backup path, a critical fiber-optic line in New Jersey had been severed during Amtrak-related construction. Verizon confirmed that affected fiber was near an Amtrak rail line. The operational problem was therefore a sequence: primary-path failure + unavailable backup path = loss of sufficient redundancy.
That distinction matters. If the backup had remained healthy, the primary failure might have been operationally manageable. If the primary path had remained healthy, the fiber cut might have been largely invisible to passengers. It was the coincidence of failures, and the architecture connecting them, that transformed a local infrastructure event into a major air-traffic disruption.
It is: “Why could a primary telecommunications failure plus loss of a backup path remove enough capability to force large-scale traffic restrictions?”
The Five-Airport Headline Is Only Part of the Story
Newark Liberty (EWR), John F. Kennedy (JFK), LaGuardia (LGA), Teterboro (TEB) and Philadelphia International (PHL) were among the core airports caught in the disruption. Boston and other airports also experienced restrictions or downstream effects. The important point is that these airports do not operate as five independent islands. Their arrival and departure flows are embedded in interconnected terminal and en-route airspace, and the airlines themselves operate nationwide aircraft-and-crew networks.
A ground stop at Newark can leave an aircraft in Chicago. That aircraft may then fail to operate its next flight from Newark. A crew can time out. A gate can remain occupied. Connecting passengers can miss subsequent flights. An aircraft diverted from New York may consume gate, fuel and crew resources elsewhere. The network effect continues after the original technical problem is repaired.
How an Airport Actually Operates
Passengers see terminals and airplanes. The operational stack is much deeper. Airport operators maintain runways, taxiways, terminals, lighting, emergency response and other physical infrastructure. Airlines manage aircraft, dispatch, crews, maintenance, gates, baggage, fueling and passenger operations. FAA tower controllers manage aircraft on and immediately around the airport. TRACON controllers sequence arrivals and departures through busy terminal airspace. Air Route Traffic Control Centers manage aircraft across the en-route system. The Air Traffic Control System Command Center manages demand and capacity across the national network.
All of those layers depend on data and communications. Voice links connect controllers and pilots. Surveillance sources show aircraft positions. Automation systems correlate tracks with flight plans. Telecommunications move data between facilities. Traffic-management systems coordinate demand across hundreds or thousands of miles.

Why Philadelphia Matters to Newark
Newark's approach-control architecture changed materially in July 2024, when FAA transferred responsibility for Newark-area TRACON operations from New York TRACON (N90) to Philadelphia. DOT's Office of Inspector General says the transfer was intended to address chronic understaffing at N90. That relocation made telecommunications between New York-area systems and Philadelphia particularly important.
The vulnerabilities were demonstrated in 2025. DOT OIG records an approximately 90-second loss of radar and radio contact on April 28, 2025, associated with a burned copper wire, followed by another approximately 90-second outage on May 9 involving failures of primary and redundant communications infrastructure. The Inspector General subsequently opened an audit examining FAA's planning, risk assessment and operational effects of the relocation.
FAA then installed a new fiber-optic network between New York and Philadelphia TRACON. On July 3, 2025, FAA described the new architecture as using two separate communications paths intended to keep equipment operating if one path was disrupted. FAA also described a temporary satellite backup and plans for a Philadelphia STARS hub so Newark controllers would not depend on a telecommunications feed from the New York STARS hub.
That history makes the September 2026 incident especially important. It does not, by itself, prove that the 2025 redundancy project failed: the primary circuit and severed backup involved in the new event may not map one-for-one to the paths described in 2025. But it makes the exact physical and logical topology an essential post-incident question.
Redundancy Is a Physical Concept, Not a PowerPoint Concept
Two circuits are not necessarily two failure domains. Two carriers may lease strands in the same conduit. Two conduits may share the same railroad right-of-way. Separate fibers may enter a facility through the same vault. Independent links may depend on the same power source, router, optical equipment, software service, timing source or network operations process.
For safety-critical infrastructure, redundancy should be tested against common-cause failure. A backhoe, flood, fire, power failure, carrier outage, software defect, cyber incident or facility evacuation should not be able to eliminate every supposedly independent path.

A Practical Resilience Architecture
A future architecture should treat communications as a multi-layer safety system. Primary fiber should be physically diverse from secondary fiber, not merely logically separate. Where practical, separate carriers should use independently verified routes and independent building entrances. A third path should use a different medium — for example microwave or other terrestrial radio — and an emergency path can use satellite where latency, availability, security and certification requirements permit.
Facilities should have independent power, UPS and generator support; redundant switching and routing; spare optical and radio equipment; geographically separated control capability; automatic but deterministic failover; continuous path-health monitoring; and regularly exercised degraded-mode procedures. Failover that exists only in documentation is not resilience. It must be tested under load.
Build for Five Times the Traffic — Even If Five Times Is Not the Forecast
FAA's current forecast does not say conventional airline traffic will suddenly become five times today's level. GAO cites FAA forecasting average passenger air-travel growth of about 2.4 percent annually. The future airspace, however, will not contain only today's scheduled airlines. It increasingly must accommodate commercial drones, advanced air mobility, business aviation, general aviation, commercial space activity and other emerging entrants.
That is why a 5× traffic scenario should be treated as a resilience and architecture stress target, not as a forecast. A system intended to remain in service for decades should be designed against conditions materially beyond today's normal demand. Five times today's transaction, surveillance, coordination and trajectory workload is an intentionally aggressive engineering test: Can the data fabric scale? Can automation maintain deterministic performance? Can communications survive multiple failures? Can controllers remain cognitively within safe workload limits? Can a neighboring facility assume responsibility? Can the national system degrade gracefully instead of collapsing abruptly?
Capacity planning should therefore use multiple dimensions: aircraft movements, simultaneous tracks, messages per second, surveillance updates, trajectory changes, weather events, reroutes, UAS operations, facility failures and cyber contingencies. Designing only for an average-day passenger forecast risks building tomorrow's infrastructure around yesterday's definition of traffic.
AI Must Be Part of the New Architecture
Artificial intelligence should not be bolted onto air traffic control as a novelty. It should be engineered into the modernization program as a carefully bounded, safety-assured capability that improves prediction, detection, planning and human situational awareness. FAA already maintains an AI/ML technical discipline and an AI Safety Assurance Roadmap, and in 2026 FAA said it plans to use AI and machine-learning tools to better simulate and manage National Airspace System performance before the day of departure.
FAA has also selected new flow-management technology intended to become the technological backbone of the Air Traffic Control System Command Center. Its Strategic Management of Airspace, Routes, and Trajectories capability is intended to coordinate schedules and trajectories before aircraft depart. This is precisely the layer where advanced prediction and optimization can produce system-wide benefits.
Where AI can add concrete value
- Predictive congestion management: forecast sector, runway, route and facility overload before queues form, then propose demand-smoothing and trajectory alternatives.
- Infrastructure anomaly detection: identify rising optical errors, packet loss, radio degradation, latency shifts, power irregularities and correlated alarms before a hard outage occurs.
- Failure-correlation analysis: recognize that two “independent” services are degrading simultaneously and may share a hidden physical dependency.
- Digital twins: maintain high-fidelity simulations of airspace, communications and facility topology, then continuously test failures, weather, traffic surges and reroutes before they happen operationally.
- Dynamic contingency planning: calculate safe reduced-capacity operating modes and recommend which traffic flows should be held, rerouted or resequenced.
- Controller decision support: surface the most relevant conflicts and options while leaving operational authority with qualified human controllers.
- Maintenance intelligence: combine age, failure history, telemetry, spare-parts availability and operational criticality to prioritize replacement before failure.
- Post-incident reconstruction: correlate network, facility, surveillance, voice, traffic and maintenance logs to identify root causes and hidden dependencies rapidly.

The Digital Twin Should Include the Fiber in the Ground
Traditional airspace simulation models aircraft and sectors. The next generation should model the infrastructure underneath them as well. A national ATC digital twin should know which radar feed traverses which carrier, conduit, equipment room, router and facility; which services share power; which “backup” paths converge physically; and what operational capacity remains when any component disappears.
That creates a powerful capability: before approving a maintenance window or excavation near a critical corridor, the system could simulate the simultaneous loss of that route and another component. Before declaring two circuits redundant, engineers could verify their physical separation. Before deploying a software change, the digital twin could stress the network under 2×, 3× and 5× workload scenarios.
Zero Trust Should Apply to Resilience Claims Too
Cybersecurity popularized the principle “never trust, always verify.” Critical infrastructure needs an analogous rule for redundancy: never assume independence; continuously verify it. Route records become stale. Carriers re-home circuits. Contractors move fiber. Network equipment is consolidated. A path that was physically diverse five years ago may no longer be diverse today.
FAA and its telecommunications providers should maintain machine-readable dependency maps and require periodic physical-route attestation. Critical paths should be geospatially compared for common trenches, bridges, rail corridors, utility tunnels, central offices, power substations and building entrances. Any change in routing should automatically trigger a resilience review.
Modernization Is Already Urgent
The September 2026 GAO report provides sobering context. FAA's assessment of 138 ATC systems found 51, or 37 percent, unsustainable and another 54, or 39 percent, potentially unsustainable. Of those 105 systems, 73 had been deployed more than 20 years ago, 40 more than 30 years ago and six more than 60 years ago. GAO says telecommunications forms the communications backbone connecting roughly 5,000 FAA facilities, radars, voice systems and flight-data communications.
FAA's Brand New Air Traffic Control System modernization effort aims to accelerate replacement. GAO reported that, as of May 2026, FAA had replaced 2,560 of 5,170 old and fragile copper connections with high-speed fiber. Phase 1 is targeted for completion by December 2028, while a later phase is intended to develop new automation systems to track aircraft and optimize traffic.
Replacing copper with fiber is necessary. But the September event illustrates why modernization cannot be measured simply by miles of fiber or number of circuits replaced. The outcome metric must be operational survivability.
A 12-Point Resilience Standard for Critical ATC Communications
- Physically diverse routes: verified separation from end to end.
- Carrier diversity: where practical, prevent one provider or shared wholesale network from becoming the common failure domain.
- Medium diversity: fiber plus independent terrestrial wireless and/or certified satellite contingency capability.
- Facility diversity: alternate control capability at geographically separate sites.
- Independent power: UPS, generators, fuel plans and periodically load-tested backup power.
- No shared choke points: separate entrances, vaults, switching equipment and critical network nodes.
- Automatic health monitoring: continuous telemetry on every primary and backup path.
- AI-assisted anomaly detection: detect degradation and correlated failures before service loss.
- Digital-twin stress testing: continuously simulate single, double and common-cause failures.
- 5× capacity stress target: verify infrastructure and automation well beyond today's nominal workload.
- Human-in-command degraded modes: controllers must have clear, practiced procedures for safe reduced-capacity operation.
- Independent resilience audits: periodically prove that the architecture in the field still matches the architecture on paper.
Graceful Degradation Is as Important as Redundancy
No system can guarantee that nothing will ever fail. A better goal is that failures become progressively less consequential. Losing one path should be invisible. Losing two should reduce spare capacity but preserve core service. Losing a facility should shift workload to another facility. Only multiple independent failures should force substantial traffic restrictions, and even then the system should know exactly what safe capacity remains.
This is the difference between a brittle system and a resilient one. A brittle system operates normally until a threshold is crossed and then falls sharply. A resilient system absorbs failures, sheds nonessential load, reconfigures itself and continues delivering its most critical functions.
What the Post-Incident Investigation Needs to Publish
A useful public technical report should establish a precise timeline; identify the failed primary circuit and the severed backup path; describe what services each carried; explain the physical route and ownership of each path; identify shared dependencies; state whether the July 2025 Newark fiber architecture was involved; describe the status and role of the Philadelphia STARS hub and satellite contingency system; quantify which frequencies, surveillance feeds and data services were degraded; document failover behavior; and explain why restrictions propagated to each affected airport.
It should also quantify restoration times, diversions, delays and cancellations, and identify corrective actions with accountable completion dates. The objective is not blame. It is to convert a disruptive event into engineering knowledge.
The Larger Lesson
The most important infrastructure is often the infrastructure nobody sees. A traveler sees a Boeing or Airbus, a runway and a control tower. The operational reality includes thousands of facilities and communications connections, decades of legacy technology, highly specialized controllers and a national network that must make safe decisions continuously.
September 21 exposed that interdependence. The correct response is not merely to repair the severed fiber. It is to ask whether every critical path has truly independent backups; whether those backups are continuously verified; whether the system can transfer responsibility across facilities; whether AI can identify the next failure before it becomes an outage; and whether today's modernization is being designed for the airspace of 2040 and 2050 rather than the traffic of 2026.
Build the communications fabric for multiple simultaneous failures. Build the automation for a five-fold stress scenario. Use AI to predict, simulate and assist. Keep trained humans in command. And make “redundant” mean physically and operationally independent.
Sources and Further Reading
- Federal Aviation Administration, National Airspace System — https://www.faa.gov/air_traffic/nas
- FAA, Newark Liberty International Airport statements and modernization updates — https://www.faa.gov/newsroom/faa-statements-newark-liberty-international-airport
- FAA, July 3, 2025 Newark fiber network announcement — https://www.faa.gov/newsroom/secretary-duffy-announces-completion-another-major-milestone-operations-newark-liberty
- DOT Office of Inspector General, Audit of FAA's Relocation of Newark-Area TRACON Responsibilities — https://www.oig.dot.gov/library-item/46879
- U.S. Government Accountability Office, GAO-26-107992, Air Traffic Control Systems: Ambitious New Modernization Effort Needs Cost and Schedule Planning — https://www.gao.gov/products/gao-26-107992
- U.S. Government Accountability Office, GAO-25-108162, Air Traffic Control: FAA Actions Urgently Needed to Modernize Systems — https://www.gao.gov/products/gao-25-108162
- FAA Aerospace Forecasts 2026-2046 — https://www.faa.gov/data_research/aviation/aerospace_forecasts
- FAA, Artificial Intelligence / Machine Learning technical discipline — https://www.faa.gov/aircraft/air_cert/step/disciplines/artificial_intelligence
- FAA, Roadmap for Artificial Intelligence Safety Assurance — https://www.faa.gov/aircraft/air_cert/step/roadmap_for_AI_safety_assurance
- FAA, 2026 controller hiring and system-modernization plan — https://www.faa.gov/newsroom/faa-releases-bold-new-air-traffic-controller-hiring-plan
- U.S. DOT / FAA, Flow Management Data and Services and SMART selection, June 22, 2026 — https://www.faa.gov/newsroom/modern-skies-trumps-transportation-secretary-sean-duffy-selects-air-space-intelligence
- Port Authority of New York and New Jersey, 2025 Airport Traffic Report — https://www.panynj.gov/content/dam/airports/statistics/statistics-general-info/annual-atr/ATR_2025.pdf
- Reuters, September 21, 2026, reporting on the Northeast telecommunications disruption — https://www.reuters.com/world/us/faa-halts-some-us-east-coast-flights-due-communication-issues-2026-09-21/
