A commercial jet touching down in fog so thick the pilots can’t see the runway until seconds before the wheels hit isn’t a rare emergency procedure — it’s a certified, routine capability called autoland, and airlines use it more often than most passengers realize. The genuinely interesting part isn’t that a computer can fly the approach; it’s the layered redundancy built specifically around the one failure mode that can’t be allowed to happen: the system getting it wrong with nobody able to see well enough to catch it in time.
What “Category III” actually means
Instrument approaches are classified by how little visibility a pilot is legally permitted to have and still land — and Category III is the tier built specifically for near-zero visibility. A CAT IIIa approach permits landing with a Runway Visual Range as low as 200 meters and a decision height around 50 feet — the altitude at which a human pilot still needs enough visual reference to confirm the landing is safe to continue. CAT IIIb goes further: Runway Visual Range down to 75 meters, with a decision height that can be zero — meaning the aircraft is certified to complete the entire landing without the pilots ever needing to see the runway visually at all. A theoretical CAT IIIc, zero visibility with zero decision height, exists on paper but isn’t used operationally anywhere — because even a perfect zero-visibility landing leaves you with an aircraft that then has to taxi to the gate, and taxiing blind is a genuinely unsolved, separate problem.
How the aircraft actually flies the approach
Autoland doesn’t work by guessing — it flies a precise electronic beam. The aircraft’s automatic flight systems follow the glideslope and localizer signals broadcast by the airport’s Instrument Landing System, tuned to that specific runway, giving the autopilot continuous, precise lateral and vertical guidance all the way to touchdown. The pilots aren’t passengers during this — they’re monitoring the approach and are fully capable of taking over, but the system is doing the actual physical flying.
Why one autopilot channel was never going to be enough
The real engineering answer to “what if the automation is wrong” is redundancy, not trust. Autoland systems run dual or triple autopilot channels simultaneously, each computing its own independent version of the approach and continuously cross-checking the others in real time. If one channel disagrees with the rest, the system has two possible responses depending on how it’s architected: a fail-operational system disconnects just the faulty channel and keeps flying the approach on the remaining ones, while a fail-passive system disconnects the entire autoland and hands control back to the pilots — while there’s still enough altitude and time left to safely do so. Either way, the failure response is decided before the fault ever happens, not improvised in the moment.
The actual takeaway
Autoland isn’t a backup system for an emergency — it’s a certified, routinely used capability, engineered around the specific, worst-case question of what happens when the automation itself might be wrong, not just when the weather is bad. CAT IIIb genuinely allows a landing with zero decision height, but the reason CAT IIIc doesn’t exist operationally is a reminder that “the plane can land itself” and “the plane can get you fully off the runway with zero visibility” are two different, separately unsolved problems — and only the first one is routine today.


