HomeAircraftHow Autoland Can Fly an Airliner From the ILS Approach Through Flare,...

How Autoland Can Fly an Airliner From the ILS Approach Through Flare, Touchdown and Rollout

Autoland is one of the most misunderstood systems on a modern airliner. It is not simply an autopilot left engaged until the wheels touch. A certificated automatic landing system combines precision approach guidance, redundant flight-control channels, radio-altimeter data, automatic thrust or speed control, flare logic, touchdown control and, on suitably equipped aircraft, automatic rollout guidance. The FAA’s current AC 20-191, issued on 20 May 2026, provides the active U.S. airworthiness guidance for low-visibility take-off, precision approach, landing and rollout systems and replaced the older AC 120-28D and AC 120-29A. [1]

Autoland is most closely associated with Category II and Category III operations, where visibility can be too poor for a conventional manual landing to be safely completed using ordinary external visual references. EASA’s CS-AWO defines an automatic landing system as the airborne equipment that provides automatic control of the aeroplane during approach and landing, and distinguishes fail-passive from fail-operational architectures according to what happens after a failure. [2]

Autoland starts with a precision approach source

An automatic landing system needs highly accurate lateral and vertical guidance. Traditionally, that guidance comes from the Instrument Landing System. The localiser provides lateral alignment with the runway centreline, while the glideslope provides vertical approach guidance. Modern certification can also support GBAS Landing System guidance in approved installations. FAA AC 20-191 explicitly addresses both ILS and GBAS-based low-visibility landing systems. [3]

The autoland system does not create the radio guidance itself. It receives navigation information from the aircraft’s ILS or GLS receivers, compares the aircraft’s actual path with the commanded path and uses the flight-control system to reduce deviations. This is why a functioning ground facility remains important even when the aircraft is capable of landing automatically.

Capturing the localiser and glideslope

During the approach, the autopilot or flight-guidance system captures the lateral and vertical guidance in much the same broad sense as during a normal coupled instrument approach. The aircraft turns onto the localiser, intercepts the glideslope and begins descending along the precision path.

For autoland, however, the system must continue with much tighter integrity and redundancy requirements into the very low-altitude phase. The aircraft therefore monitors navigation signals, autopilot channels, sensors and system status so that a failure is either safely tolerated or clearly annunciated before the approach reaches the point where manual recovery would be difficult. [4]

Why multiple autopilot channels are used

A single autopilot can fly a highly accurate approach, but a Category III automatic landing demands greater fault tolerance. EASA describes typical fail-passive systems using a monitored autopilot or two autopilots with comparison, while typical fail-operational systems can use two monitored autopilots or three autopilots so that sufficient control capability remains after a failure. [2]

The exact architecture depends on aircraft generation. The important point is not the number of boxes but the redundancy objective: one fault must not silently command a dangerous flight path, and the system must know whether enough healthy capability remains to complete the landing automatically.

Fail-passive autoland

EASA defines a fail-passive automatic landing system as one in which a failure does not create a significant out-of-trim condition or unsafe deviation, but the automatic landing is not completed after that failure. The pilot takes control. [2]

In practical terms, the system is designed to fail benignly. It should not suddenly roll or pitch the aircraft into an unsafe condition just because one monitored channel has failed. However, the crew may no longer have the automatic capability needed for the original low-visibility minima and may need to go around unless sufficient visual or system capability remains.

Fail-operational autoland

A fail-operational system goes further. EASA defines it as an automatic landing system in which, after a qualifying failure, the remaining system can still complete the approach, flare and landing. After that failure, the surviving configuration generally operates with fail-passive characteristics. [2]

This is essential for the lowest visibility operations because there may be insufficient external visual reference for the crew to take over safely after a late failure. The aircraft must therefore retain enough automatic control authority and monitoring to continue the landing after one defined failure.

Alert height

Fail-operational Category III systems use the concept of alert height. EASA defines alert height as a specified radio height based on the aircraft and landing-system characteristics. If a required redundant system fails above alert height, the approach is normally discontinued unless an approved reversion remains available. If the relevant failure occurs below alert height and the remaining system is capable of completing the landing, the failure can be ignored for the immediate landing decision. [2]

This is a carefully certificated concept, not a general rule that “failures below a certain height do not matter”. Only the defined failure cases within the approved fail-operational architecture are treated this way.

Radio altitude becomes critical

The aircraft needs a precise indication of height above the ground to transition from approach tracking to flare and touchdown. Radio altimeters provide that direct measurement. At higher altitude, the autopilot primarily follows the precision approach path. As radio height decreases, the autoland control laws enter the low-altitude phases for flare and rollout according to type-specific logic.

Redundant radio-altimeter information is therefore important to autoland integrity. A false height could command flare too early or too late, which is why low-visibility landing certification treats sensors, flight controls and power supplies as one complete landing system. [3]

Flare is an automatic control-law transition

During the final part of a normal landing, a pilot gradually changes pitch attitude and vertical speed so the aircraft touches down within acceptable limits. Autoland has to reproduce this automatically. At the appropriate radio-height region, the flight-control system changes from simply tracking the glideslope to a flare control law that reduces the descent rate and manages pitch.

The exact flare-height trigger and pitch law differ among aircraft. They depend on landing-gear geometry, aircraft response, approach speed and control-system design. A universal figure should not be transferred from one type to another.

Automatic thrust or speed control

Low-visibility automatic landing requires accurate energy control as well as accurate flight path. EASA CS-AWO specifies automatic speed control for the lower Category III configurations unless it can be shown unnecessary under the applicable criteria. [5]

On aircraft with autothrottle or autothrust, the propulsion-control system manages thrust so the aircraft maintains the commanded approach speed. As flare and touchdown occur, thrust is reduced according to the aircraft’s autoland logic and crew procedures. The flight-control and thrust systems therefore work together rather than as isolated automations.

Crosswind capability

Autoland does not mean the aircraft can land automatically in unlimited crosswind. Every aircraft has certificated or operator-defined autoland wind limits. The automatic system must maintain localiser tracking, manage yaw/roll behaviour and place the aircraft within acceptable touchdown geometry.

Some aircraft use automatic de-crab or alignment logic; others have different control strategies. The exact maximum crosswind, tailwind and headwind components are aircraft-specific and can be more restrictive than manual landing limits.

Touchdown control

The automatic system must place the main landing gear within the approved touchdown zone and with acceptable vertical and lateral conditions. This requires accurate control of pitch, roll, yaw and sink rate through the last seconds of flight.

Certification therefore examines touchdown dispersion across many conditions, including wind, navigation-signal variation, aircraft loading and system tolerances. Autoland is not certificated because one demonstration looked good; it has to show statistical and deterministic performance over the required operating envelope. [3]

Rollout

On aircraft approved for very low Category III minima, automatic control can continue after touchdown. EASA requires appropriate fail-operational or fail-passive ground-roll control or head-up guidance for specified minima and states that systems can control the aircraft along the runway down to a safe speed for taxiing where applicable. [5]

Automatic rollout normally uses rudder and nose-wheel steering or related control channels according to aircraft design. EASA notes that if automatic rollout uses rudder control, the rudder axis must be engaged during the approach phase. [2]

Autobrake is related but separate

Autoland controls flight path and, where fitted, runway centreline tracking. Autobrake controls deceleration. The systems can operate together during a low-visibility landing, but they are not the same automation. The crew selects the appropriate braking mode and the aircraft brake system manages wheel-brake demand after touchdown.

Reverse thrust is also normally commanded by the pilots rather than by the autoland system on conventional transport aircraft. The exact post-touchdown sequence is type-specific.

Localiser sensitivity near the runway

ILS localiser signals become very sensitive to lateral displacement near the transmitter geometry. Small deviations can therefore generate significant guidance changes as the aircraft approaches touchdown. Autoland control laws and navigation receivers are designed to use this high sensitivity without becoming unstable.

Ground vehicles or aircraft near protected ILS critical areas can distort the signal. Airports therefore protect ILS sensitive areas during low-visibility operations so that large reflecting objects do not corrupt the guidance being used by an autoland aircraft.

Why airports enter low-visibility procedures

Category III landing is not purely an aircraft capability. The airport must have the required approach lighting, runway lighting, navigation-facility status, protected areas and operational procedures. ATC and airport operators may establish Low Visibility Procedures to protect the ILS and manage ground movement.

An autoland-capable aircraft cannot simply conduct the lowest-category operation at any runway with an ILS. The aircraft, crew, operator and aerodrome all have to meet the applicable requirements.

Aircraft capability annunciations

The flight crew must know what autoland capability is currently available. Aircraft displays therefore provide status indications associated with the active channels and system redundancy. EASA CS-AWO requires the pilot to be able to determine the aircraft’s landing-system capability at alert height and requires failures requiring a missed approach to be clearly annunciated. [4]

Terms such as LAND 2, LAND 3, CAT 3 SINGLE, CAT 3 DUAL or similar are manufacturer-specific implementations. They should not be assumed to have identical meaning across all aircraft.

Why pilots monitor an automatic landing closely

Autoland does not remove the pilots from the safety loop. The crew verifies system engagement, navigation performance, aircraft configuration, speed and landing-system status. If the aircraft deviates beyond permitted limits or a required capability is lost above the applicable decision point, the crew executes a go-around.

Certification specifically addresses displays and alerts because the pilots must be able to monitor the approach, flare and ground roll while performing normal flight-deck tasks. [4]

Automatic go-around

Low-visibility landing systems include go-around capability appropriate to the approved configuration. EASA CS-AWO specifies automatic or flight-director go-around functions for different categories and requires fail-passive automatic go-around in the lower Category III configurations. [5]

The purpose is to ensure that abandoning the approach does not require the crew to reconfigure a complex flight-control system at the exact moment visibility and workload are most demanding. Exact engagement and thrust procedures remain type-specific.

Why not use autoland on every flight?

Autoland can be used in good weather when permitted, and operators often require periodic automatic landings to maintain crew or system currency and verify serviceability. But manual flying remains an essential pilot skill, and an autoland can have more restrictive wind or runway conditions than a normal manual landing.

Some airports or runways may also have local restrictions because of ILS geometry, terrain or signal characteristics. Autoland is therefore a capability used when appropriate, not a default requirement for every arrival.

What if the ILS signal becomes unreliable?

The aircraft monitors localiser and glideslope behaviour and can detect some excessive deviations or receiver faults. If the guidance becomes unreliable above the relevant low-altitude decision point, the correct response is generally a go-around rather than trusting the automation blindly.

Airport procedures also protect the ground transmitter environment during low visibility. Autoland safety depends on both airborne monitoring and the integrity of the external navigation signal.

Fail-operational does not mean failure-proof

A fail-operational system is designed to complete the landing after specified failures. It does not mean that any imaginable combination of failures can occur without consequence. Multiple failures, common-mode events or loss of required external guidance can exceed the system’s remaining capability.

The term should therefore be used precisely: after a defined failure, sufficient automatic landing capability remains. EASA’s definition explicitly says the remaining system then operates as fail-passive. [2]

Why power-supply redundancy matters

Multiple autopilot computers are not useful if they all depend on one electrical bus that can fail. Category III certification therefore treats sensors, instruments and power supplies as part of the landing system. EASA’s terminology explicitly states that the landing system includes related sensors, instruments and power supplies. [2]

Electrical segregation, hydraulic redundancy, independent sensors and monitoring channels all contribute to the required fault tolerance. Autoland is a system-of-systems safety architecture, not one software mode.

GBAS and GLS

The traditional autoland story centres on ILS, but FAA AC 20-191 now explicitly includes Ground Based Augmentation System landing guidance within its low-visibility airworthiness framework. GBAS supplies corrected GNSS-based precision guidance through the GLS concept. [3]

The aircraft still needs suitable automatic flight-control, flare and landing capability. Changing the navigation source does not remove the need for redundant onboard landing systems; it changes how the precision path is generated and received.

The runway is still there even when the pilots cannot see much of it

In the lowest visibility operations, the aircraft may continue below heights where a normal manual landing would require stronger external visual references. That is possible only because the complete system — navigation guidance, autopilot redundancy, radio altitude, flare, landing and rollout — has been certificated for that environment.

The pilots remain responsible for confirming that the required capability exists and for going around when it does not. Autoland reduces dependence on outside vision; it does not reduce the need for procedural discipline.

From radio beam to wheel contact

An autoland can therefore be understood as a sequence. The aircraft captures precision lateral and vertical guidance. Redundant flight-control channels track the path. Automatic speed control manages energy. Radio altitude tells the system when the ground is close. Flare logic reduces the descent rate. The main wheels touch down within a certified envelope, and on suitably equipped systems automatic rollout keeps the aircraft aligned as it decelerates. [3]

What makes the system extraordinary is not that a computer can move the controls. It is that the entire chain is designed to remain predictable and safe when visibility is so poor that the crew cannot rely on ordinary visual landing cues. The aircraft, airport, navigation facility, crew and operator all have to meet the required standard. Autoland is therefore not a clever autopilot trick; it is one of commercial aviation’s most tightly integrated low-visibility safety systems.

Verified Sources / References

  1. Federal Aviation Administration AC 20-191 — Airworthiness Approval of Airborne Systems Used for Takeoff, Precision Approach, Landing and Rollout in Low-Visibility Conditions. Active FAA guidance issued 20 May 2026; it replaced AC 120-28D and AC 120-29A.
  2. EASA CS-AWO Issue 2 — Category III automatic landing terminology and flight-path/ground-roll control.
  3. FAA AC 20-191 PDF. Detailed current airworthiness criteria for ILS/GBAS low-visibility approach, landing and rollout systems.
  4. EASA CS-AWO — Category III indications and alerts.
  5. EASA CS-AWO — Installed equipment and fail-passive/fail-operational requirements.

Editorial Notice

Editorial Notice: This article was prepared using information considered reliable and publicly available at the time of publication. Every reasonable effort has been made to ensure accuracy; however, aviation requirements, technical standards and operational guidance may change as further information or revised regulation becomes available. This article is for general aviation education and reporting and is not a substitute for approved aircraft manuals, operator procedures, regulatory material or professional training. Cockpit King does not allege fault or responsibility against any person or organisation unless confirmed by an authoritative source. If you believe any material is inaccurate, misleading, improperly attributed or should be reviewed for amendment or removal, please contact us with the article title, the specific passage concerned and supporting evidence. We will assess legitimate requests promptly and, where appropriate, correct, clarify, update or remove the material.