DOT Reclassifies Cyberattacks as "Not Controllable" Delays
The Department of Transportation published a final rule last week that reshapes what airlines owe passengers when a cyberattack disrupts a flight. As reported by CyberScoop, the rule creates a new category of "not controllable" delay causes and, for the first time, places cyberattacks inside it — provided the airline can show it was in compliance with applicable cybersecurity regulations at the time.
The rule was published on September 3, 2026, and takes effect October 19, 2026. It implements Section 511(b) of the FAA Reauthorization Act of 2024, which directed DOT to define which disruption causes count as within an airline's control versus outside it. Because Congress mandated the change, DOT issued it as a final rule without the usual notice-and-comment period — a point consumer advocates have specifically criticized.
Cyberattacks are one of ten newly listed "not controllable" events, alongside things like extreme-weather aircraft damage, sabotage, certain baggage-system outages, unexpected government system failures, medical emergencies, and specific unscheduled-maintenance scenarios. When a delay or cancellation falls into one of these buckets, airlines are no longer expected to treat it the way they treat delays within their own control.
What Changes for Passengers
| Scenario | Meals / Hotel Typically Expected | After the New Rule |
|---|---|---|
| Delay/cancellation deemed within airline's control | Meal vouchers and hotel accommodations for significant disruptions, per each carrier's customer service plan | Unchanged |
| Delay/cancellation caused by a cyberattack, airline compliant with applicable cybersecurity regulations | N/A (previously would likely have been treated as controllable) | Classified "not controllable" — meal/hotel obligations reduced or eliminated |
| Delay/cancellation caused by a cyberattack, airline not compliant with applicable cybersecurity regulations | N/A | Cybersecurity carve-out does not apply; normal customer-service obligations still apply |
A few caveats worth flagging:
- These amenity commitments come from each airline's own customer service plan, not a federal law guaranteeing meals and hotels — DOT has said it holds carriers "accountable" to those pledges, but they aren't independently binding.
- The rule's compliance bar is deliberately broad. Kate Growley, a partner at Crowell & Moring, has noted the final rule's language on "applicable cybersecurity regulations" isn't narrowly defined, likely to account for the range of frameworks that could apply depending on the airline and the nature of an attack.
- The United States still has no EU-style legal mandate requiring meals, hotels, or cash compensation for every delayed or canceled flight, unlike the EU's 2026 agreement reinforcing passenger care obligations.
Why This Matters
The rule is explicitly designed to reward airlines for cybersecurity investment: comply with the applicable rules, and a cyberattack-driven meltdown gets treated like a hurricane rather than a self-inflicted IT failure. That logic has real precedent. The July 2024 CrowdStrike update failure — not itself a cyberattack, but a global IT outage — grounded roughly 7,000 Delta Air Lines flights over five days and disrupted travel for more than a million passengers. DOT determined that incident was within Delta's control, and the airline faced scrutiny and passenger claims over its response.
Consumer groups see the new carve-out differently. FlyersRights argues that cybersecurity is fundamentally an airline responsibility, not an external shock like weather, and objects that the rule was finalized without public comment. It says it will track whether the change leads to reduced amenities for stranded travelers. The National Consumers League welcomed the added clarity but warned airlines could lean on adjacent categories, like "unscheduled maintenance," to sidestep compensation even when the underlying cause is murkier than a clean-cut cyberattack.
The tension is straightforward: incentivizing airlines to harden their systems is a reasonable regulatory goal, but doing so by narrowing what passengers are owed shifts real financial risk onto travelers precisely when an airline's own security posture is in question. Whether "compliance with applicable cybersecurity regulations" becomes a meaningful bar — or a broad enough exemption to swallow the rule — will likely only become clear after the next major airline outage.