Emergency handoff is the most dangerous form
Aliases: emergency handoff · critical takeover · takeover request
What it is
Emergency takeover hazard combines the system's weakest capability, the most complex condition, the shortest time, and a person least aware of current context. “Human takeover if needed” is therefore not an independent safety barrier.
Why it happens
Automation retains control until confidence or ability crosses a threshold, after hazard development. A person reconstructs, chooses, and adapts under narrowed attention and coarse input. Ambiguous recipient identity can leave a gap or dual control.
Studying it
Safe simulation or limited-energy rigs can vary lead time, anomaly complexity, disengagement, and continued protection, measuring missed takeover, stable control, near miss, wrong direction, and workload. High quantiles and noncompletion matter more than means. Trained performance does not represent incidental operation.
Where it stops holding
Some events need human judgement, but automation should first constrain consequence and offer a minimum-risk condition. If hazard evolution is faster than verified takeover, emergency handoff is not viable. Drills improve practice without ensuring perpetual readiness.
Applying it
- Transfer progressively at early degradation rather than after total failure.
- Continue verified protection while identifying one recipient, deadline, and non-acknowledgement behaviour.
- Drill shortest lead, highest load, and communication failure; replace unacceptable tail failure with an automatic safe condition.