The Weekly Reflektion 41/2026
A fail-safe is a design feature, mechanism, or strategy that ensures a system automatically reverts to a safe condition if it malfunctions, loses power, or experiences a failure. A fail-safe accepts that failure can happen but focuses on minimizing harm to people, equipment, or the environment when it does. The term “fail-safe” can create a dangerous sense of security especially when we assume that the system will respond as expected in all situations.

Are your fail-safe systems fail proof?
At about 20:59 on 18 April 2026, Deepsea Atlantic was drilling on the Rosebank Development west of Shetland. The water depth isapproximately 1,100 m. The operation was running the BOP and riser. The suspended load was approximately 646 metric tonnes. Main Drawworks A was driven by four electric motors. A power failure occurred and the braking system failed to restrain the BOP and riser and these were lost to the seabed. The Health and Safety Executive (HSE) in the UK described the following sequence of events.
• Motor No. 1 tripped.
• Shortly afterwards, the remaining three motors tripped.
• The rig therefore lost normal drive/load control and its main braking capability.
• The floor-saver system detected the loss of control and commanded the emergency disc brakes to engage.
• The emergency brakes applied but did not generate enough braking force to arrest the descending load.
• The load continued accelerating downwards.
• The descending load pulled the wire rope off the Main Drawworks A drum.
• The momentum of the sheaves caused the wire rope to flail violently, damaging equipment and the derrick structure.
• The BOP and approximately 400 m of riser fell to the seabed.
Remarkably, no personnel were injured. Odfjell also reported that the rig was made secure and operations suspended.
The emergency disc brakes had been subjected to routine static holding-capacity testing and had passed. But when they were actually required to stop a 646-tonne moving load, they could not develop sufficient dynamic braking torque. HSE stated that this deterioration in dynamic performance was not detectable through the routine static brake test. In other words, the system passed the test used to demonstrate that the fail-safe system worked yet failed when the actual fail-safe function was demanded. HSE subsequently highlighted possible contributors that need to be considered across these systems, including corrosion and contamination, broken springs, component wear and alignment, brake-pad ageing, water ingress, thermal capacity/friction fade, maintenance quality and even changes in replacement consumable parts. HSE does not, at least in the published notice, say that all or any one of these has been established as the specific root cause on Deepsea Atlantic.
This incident illustrates an important principle for major accident prevention. We need to test safety systems against the accident they are intended to prevent, not simply against convenient test conditions. Fail-safe systems present a particular challenge because they may spend almost their entire operational life in an inactivestate. The normal system operates every day and failures become apparent. The emergency system may remain dormant for years. During this period, degradation processes may progressively reduce the systems capability. Inspection and maintenance alone cannot completely solve this problem. We must understand what performance is actually required. A brake can look acceptable, dimensions can remain within tolerance, and a static test can be successful, while its dynamic stopping capability has degraded. As a result of the incident the HSE recommends that manufacturers and operators consider dynamic performance, worst allowable conditions, degradation mechanisms, wear tolerances and environmental effects when establishing performance standards.