The Aviation Safety Reporting System has been processing voluntary safety reports from pilots and air traffic controllers for fifty years. More than two million reports have entered the system. No reporter's identity has ever been compromised.1
The day after OpenAI published its misalignment reporting framework, we sat down with a longtime ASRS analyst to talk about what it actually feels like to work inside a mature reporting system. The daily rhythm. The craft. What you learn about human honesty when your job is to read 20 confessions a day and systematically erase the names.
Vern Strikethru spent 26 years as an airline captain before joining the ASRS analyst corps at NASA Ames, where he has spent the last 15 years reading other people's close calls. His name, like the identifying details in the reports he processes, has been altered to protect the source.
You read roughly 20 reports a day. What does that feel like by 3 p.m.?
Vern: Like being a priest who hears confessions but can't assign penance. You read someone's worst Tuesday. They busted an altitude, misheard a clearance, landed on a taxiway. Your job is not to judge it, not to fix it, just to receive it. Code it. Strip it. File it. Move on.
What people don't understand is that most of what I read on any given day is ordinary. A pilot confused by a NOTAM. A controller who issued a clearance that didn't quite parse. Individually? Noise. But I can't treat it like noise, because I have no idea which report becomes the 40th data point in a pattern that gets someone's attention six months from now.
So you're building a corpus, not solving cases.
Vern: We issue maybe one alert for every 400 reports.2 The other 399 go into the database. Their value is latency. They're waiting to matter.
Let's talk about de-identification. People assume it's redaction. Blacking out names.
Vern: Yeah, that's... no.
A pilot writes in and says, "On the 14th, operating the 737 Denver to Houston, at 1847 Zulu, I received a clearance from approach that I interpreted as..." Now. If I just remove the pilot's name but leave "737, Denver to Houston, Tuesday the 14th, 1847Z," there are maybe three flights that match. Anyone in the industry could identify the reporter in about four minutes.
My job is to know that. To know which details narrow the field. The aircraft type might be safe to keep. There are thousands of 737 flights. But a specific route on a specific date at a specific time? That's a fingerprint. So I generalize: "a narrow-body transport operating between two major hubs." I shift the time to a range. The date becomes "mid-month."
And I have to do all of this while preserving whatever made the event instructionally valuable. If the clearance confusion was specific to the airspace geometry around Denver, I can't just write "Airport ZZZ" and call it done. I need the terrain context without the location.
"Airport ZZZ"?
Vern: Our term of art. The fictional airport identifier we use in de-identified reports. If you see "Airport ZZZ" in a document, you know it came through us. It's become this weird cultural marker. Pilots joke about it. "Great landing at ZZZ today." I've heard controllers say they've been to ZZZ more times than O'Hare.
You mentioned the ID strip gets physically destroyed. That seems almost theatrical.
Vern: Theatrical? No. The word you want is structural.
Every report comes in with an identification strip at the top: name, address, certificate number. We time-stamp it and mail it back to the reporter as a receipt. Then we destroy our copy. Not "file it separately." Not "encrypt it." Destroy it.3
NASA cannot give the FAA what NASA does not have.
That's the whole game. That's why pilots file. Not because they trust us personally, but because the system is designed so that betrayal is structurally impossible. You can't leak what you've already shredded.
Does the quality of reports vary?
Vern: Enormously. Some pilots write three sentences. Some write three pages. The best reports are the ones where someone is genuinely trying to understand what happened to them. They're thinking on paper. Those are gold.
The worst are the ones clearly filed just to get the immunity protection. The "get out of jail free card." Ten days to file, and you can tell they're watching the clock.4
But even a bad report has data. Even "I busted my altitude, not sure why" tells me something if I see 200 of them in the same airspace over six months.
The taxonomy has been evolving for decades. What's that like to work with?
Vern: [laughs] Like an archaeological dig. You can see the strata.
We still have to search both "FLC" and "Flight Crew" because the abbreviation was standard until 2009, and nobody went back and recoded 30 years of records.5 The categories weren't designed top-down. They grew out of what people reported. Someone started seeing a pattern, so they added a code. Then the pattern shifted, and the code didn't quite fit anymore, but it was already in the database, so you keep it and add another one next to it.
It's messy. But it's honestly messy. The mess is the history. If you tried to clean it all up, you'd lose the ability to query across time. I've watched people come in from the software world and want to normalize everything, and you have to explain: that inconsistency you want to fix is actually twenty years of institutional memory wearing a bad label.
You've been doing this for 15 years. Has it changed how you think about your own flying career?
Vern: I think about all the reports I didn't file. Every pilot has events they never reported because it didn't seem worth it, or they were embarrassed, or they didn't know the system existed. I read reports now and think, "That exact thing happened to me in 2003 and I just... went home."
That's the denominator problem. We know we're seeing the lower bound.6 But we have no idea what the actual number is. We can't know what people didn't tell us. And you can't survey for it either, because the same reluctance that kept someone from filing keeps them from admitting they didn't file.
OpenAI just published a misalignment reporting framework. Six incident reports. Company self-reporting on its own models. Any reaction?
Vern: [long pause]
It's a start. Better than nothing. But the thing that makes our system work isn't the form, or the database, or the taxonomy. It's the structural independence. NASA runs this, not the FAA. I can't have an ongoing employment relationship with any airline or the regulator.7 I have no economic interest in what I read. None.
When a company reports on itself, I'm not saying they're lying. I'm saying the architecture doesn't make lying impossible. And those are very different things. Our system doesn't rely on NASA being trustworthy. It relies on NASA being unable to betray the reporter even if it wanted to. That's a higher standard than good intentions, and it's the only standard that survives a change in leadership.
What would you tell someone designing a reporting system for AI incidents?
Vern: Two things.
First, you need reporters to file before they know if something matters. Our 10-day window forces that. You file because something felt wrong, not because you've confirmed it was wrong. If you wait for confirmation, you've already filtered out the weak signals. And weak signals are the whole point.
Second, you have to show your work back to the community. We publish CALLBACK. Twelve issues a year, 32,000 subscribers.8 Pilots read it and see that the system did something with what they reported. If reports disappear into a void, people stop filing. Reporting is a relationship. You have to hold up your end.
After 15 years of reading other people's mistakes, what's the one thing you wish the public understood about safety reporting?
Vern: That it's boring. That it's supposed to be boring. The spectacular stuff, the crashes, the near-misses that make the news, that's not where the value is. The value is in the 399 reports that nobody will ever read individually, sitting in a database, waiting for someone to ask the right question.
Safety is a very patient enterprise. And patience is not a quality that gets a lot of venture funding.
Footnotes
-
NASA Human Systems Integration Division, "Aviation Safety Reporting System (ASRS) Overview," March 3, 2026. https://www.nasa.gov/human-systems-integration-division/aviation-safety-reporting-system-overview/ ↩
-
NASA ASRS TRB presentation by Becky Hooey, PhD, October 20, 2021. 160 alerts from 65,656 reports in 2020. https://ntrs.nasa.gov/api/citations/20210023200/downloads/ASRS_NAS_TRB_10.20.2021b.pdf ↩
-
FAA Advisory Circular 00-46F, "Aviation Safety Reporting Program." https://asrs.arc.nasa.gov/overview/immunity.html ↩
-
The 10-day filing requirement is codified in the Advisory Circular; reporters must submit within 10 days of the event to qualify for enforcement protections. ↩
-
NASA ASRS, "Coding Taxonomy" page. https://asrs.arc.nasa.gov/search/dbol/databasecoding.html ↩
-
NASA ASRS describes its data as providing "definitive lower-bound estimates of the frequencies at which various types of aviation safety events actually occur." https://en.wikipedia.org/wiki/Aviation_Safety_Reporting_System ↩
-
NASA ASRS, "Caveats" page: analysts may not have ongoing employment relationships with the FAA, air carriers, or similar organizations. https://asrs.arc.nasa.gov/overview/caveats.html ↩
-
NASA ASRS TRB presentation, 2021. CALLBACK newsletter reaches over 32,000 subscribers across 12 annual editions. ↩
