Skip to main content
QUICK REVIEW

[Paper Review] A Promise Theoretic Account of the Boeing 737 Max MCAS Algorithm Affair

J.A. Bergstra, Mark Burgess|arXiv (Cornell University)|Dec 24, 2019
Air Traffic Management and Optimization18 references9 citations
TL;DR

This paper applies Promise Theory to analyze the Boeing 737 Max MCAS software incident, framing system failures as broken promises among agents (Boeing, FAA, pilots, software). It reveals that Boeing's false promise—that MCAS was not an anti-stall system—undermined trust and contributed to crashes, advocating for promise-based transparency in safety-critical systems.

ABSTRACT

Many public controversies involve the assessment of statements about which we have imperfect information. Without a structured approach, it is quite difficult to develop an approach to reasoning which is not based on ad hoc choices. Forms of logic have been used in the past to try to bring such clarity, but these fail for a variety of reasons. We demonstrate a simple approach to bringing a standardized approach to semantics, in certain discourse, using Promise Theory. As a case, we use Promise Theory (PT) to collect and structure publicly available information about the case of the MCAS software component for the Boeing 737 Max flight control system.

Motivation & Objective

  • To address the lack of structured, non-technical tools for analyzing public debates on complex system failures, especially in safety-critical software.
  • To investigate how flawed or misleading promises by key agents—particularly Boeing—contributed to the MCAS-related crashes of two 737 Max aircraft.
  • To demonstrate that Promise Theory offers a semantically clear, scalable framework for assessing trust, fidelity, and accountability in human-machine systems.
  • To challenge the public perception of MCAS as an anti-stall system, showing that Boeing’s explicit denial of this role (Promise 3.3) was central to the failure analysis.
  • To advocate for integrating promise-based reasoning into certification and post-mortem analysis of software-intensive systems to improve transparency and systemic safety.

Proposed method

  • Modeling the 737 Max system as a network of agents (Boeing, FAA, pilots, software) interacting through explicit promises.
  • Classifying promises as 'behavior offered' (+) or 'behavior accepted' (-), with varying precision and fidelity.
  • Analyzing the fidelity of promises made by Boeing (e.g., MCAS is not an anti-stall system) and assessing whether they were kept or broken.
  • Using transparency as a core mechanism: unkept promises are exposed as failures, and public trust erodes when promises are ambiguous or false.
  • Applying Promise Theory’s semantics to deconstruct public discourse, avoiding reliance on formal logic or overly technical jargon.
  • Mapping the chain of responsibility across human and machine agents, emphasizing that system safety depends on promise-keeping across all levels.

Experimental results

Research questions

  • RQ1How can Promise Theory be used to structure and clarify public discourse on complex, high-stakes system failures like the 737 Max crashes?
  • RQ2What role did Boeing’s explicit promise—that MCAS was not an anti-stall system—play in the development and perception of the software’s function?
  • RQ3Why do traditional formal logics and technical checklists fail to capture the nuances of trust and accountability in human-machine systems?
  • RQ4How does the fidelity of promises—especially ambiguous or misleading ones—impact system safety and public trust?
  • RQ5Can a promise-theoretic framework improve certification processes and post-incident analysis in software-intensive systems like fly-by-wire aircraft?

Key findings

  • Boeing’s promise (Promise 3.3) that MCAS was not an anti-stall system was false and central to the accident analysis, as MCAS’s actual behavior mirrored that of an anti-stall system.
  • The public and technical communities often conflated MCAS with an anti-stall system, creating a misleading 'temporary association' that obscured the real issue: a broken promise.
  • Promise Theory reveals that system safety depends not only on technical correctness but on the integrity and clarity of promises made by system agents.
  • The FAA’s certification process, based on checklists, failed to detect structural risks because it did not analyze promises across system levels or assess fidelity.
  • Misleading or ambiguous promises—especially when made by powerful agents like Boeing—can erode trust and lead to catastrophic outcomes, even if technical specifications are correct.
  • Promise Theory provides a practical, semantically grounded alternative to formal logic for analyzing complex, uncertain, and high-stakes system failures in public discourse.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.