Myth, marketing or misunderstanding?Last year I read an article about flying a Citation CJ4 that really bothered me. The author asserted that, with the system in control, it is "impossible to overspeed or over-temp an engine," and reiterated the commonly held belief that FADEC protects the engine from pilot error.He is repeating what the manufacturers say. Williams International's own literature describes the dual-channel FADEC as monitoring engine parameters to prevent exceedances that could damage the engine. The FAA's general aviation safety material describes electronic engine control as a safety enhancement providing overspeed and over-temp protections. Nobody in that chain is lying. Every one of those statements is defensible in some context.Yet later in the same piece, the author describes a CJ4 that suffered a hot start bad enough to catch fire and damage the tailcone. He describes another CJ4 damaged by a hot start where the recorded wind at engine start voided the warranty. And he describes his own crew leaving the levers in the takeoff detent past the five-minute limit, which Williams found in the data and charged as two engine cycles.That is not a gotcha. It is a good piece written by a very experienced pilot, and the contradiction sitting inside it is not carelessness. It is what happens when a precise engineering term travels a long way from the document that defined it, picking up meaning along the way.How far that meaning has traveled, and what it costs when the gap closes, is what the rest of this article is about.Why we believe itFor most of recorded European history, every swan in the known record was white.The Roman satirist Juvenal used the black swan in the second century as a figure for something that does not exist, and by sixteenth-century London the phrase was a standard expression of impossibility. Every swan Europeans had observed, cataloged, hunted, or eaten had white feathers. That was not superstition. It was the best available inference from every observation available to them.In 1697 Willem de Vlamingh sailed up a river in Western Australia and found black swans.Karl Popper built an argument on this. No quantity of white swans establishes a universal claim, and a single black one refutes it. Verification and falsification are not symmetric, and the asymmetry applies specifically to universals.Now consider a pilot with three thousand starts in a FADEC airplane. He has watched the system handle every one of them, no hot starts. No exceedances. Every horror story he has heard involved an older airplane or a hydromechanical fuel control. He concludes that the system prevents exceedances, and he concludes it based on a large, honest, unbroken body of evidence.He is doing exactly what sixteenth-century London did and doing it just as reasonably.The distinction Popper draws is the one this article turns on. FADEC removes many of the opportunities for pilot-induced engine exceedances. That is a bounded claim, the kind evidence can actually reach, and I will come back to it. It is impossible to over-temp an engine with FADEC in control. That is a universal claim. No number of uneventful starts can reach it, and the manufacturers publish the counterexample.The aviation version has a wrinkle that makes it worse. A European could have corrected the swan error by sailing south and looking. For us, that gap is built in. There is no cockpit annunciation for a takeoff time limit exceedance. Exceedances can surface in a data download months after the flight, found by a technician working an unrelated case. The falsifying instances happen, and many of them never reach the person forming the belief.None of this is a new observation. It has been studied for forty years, and the researchers gave it names that sound like accusations and are not meant as such. In this literature, bias and complacency are terms of art describing what happens to a competent person operating a reliable system, not verdicts on character.Kathleen Mosier and Linda Skitka named the first one in the mid-1990s. Automation bias is the use of automation as a heuristic replacement for vigilant information seeking, and it produces two error types. Commission errors are following the automation against contrary evidence. Omission errors are failures to respond to a problem because the automation did not flag it. The second one is ours, and it is worth being precise about what it describes. A crew that does not catch a takeoff time overrun is not ignoring an alert. There is no alert to ignore.The second finding is the uncomfortable one. Raja Parasuraman, Robert Molloy, and Indramani Singh demonstrated experimentally in 1993 that when automation is consistently reliable, operators get worse at catching the rare failure. Not because they stop caring. Because constant reliability is itself the condition under which monitoring degrades.Read that against a FADEC. Dual-channel, cross-linked, doing its job on every flight for years. The system's reliability is the mechanism that erodes the monitoring. The better it works, the easier it becomes to stop watching closely. Making the system more reliable does not solve that problem. It sharpens it, for as long as there is anything left for a person to catch.Lisanne Bainbridge explained why in 1983, in a paper called Ironies of Automation. Automating a task removes the parts that could be automated, which are the frequent and easy ones, and leaves the operator the residue, which is the rare and the hard. It removes the routine practice that kept the operator sharp and adds a monitoring burden humans are poorly built for. Earl Wiener made the same argument from the cockpit in his 1989 NASA study of glass cockpit aircraft.The degradation is a property of the arrangement, not of the person in it.What "full authority" actually meansIf the belief is that reasonable, where did it come from? Start with the name, because the term itself is the cleanest example of the whole problem. It does not mean what it sounds like.Engine control evolved in stages. Hydromechanical fuel controls came first. Then supervisory electronic engine control, where a computer trims a hydromechanical fuel control and hands the engine straight back to it on any fault. Then full authority, where the electronic control develops all the commands to all the actuators. Mechanical hardware remains, fuel metering units and valves and the actuators themselves, but there is no longer an independent hydromechanical control path capable of taking over the engine.That is the definition. Full authority means the computer holds all of it, and there is nothing underneath.As one maintenance text puts it, a true FADEC has no hydromechanical fuel control backup system. SKYbrary states the consequence plainly: if a total FADEC failure occurs, the engine fails.In engineering terms, then, full authority describes an architecture defined partly by an absence. The regulatory framework follows directly from the missing backup. 14 CFR 33.28 requires engine control systems to be single-fault tolerant with respect to loss of thrust or power control. The FAA's advisory material states that electronic systems should provide at least the level of safety and reliability achieved by engines equipped with hydromechanical control. That is why these FADECs are dual channel with cross-talk and dedicated permanent magnet alternators for power. Redundancy becomes fundamental rather than optional, because it is how a system with no mechanical fallback earns certification.Now put the two readings side by side. In the engineering documents, full authority is a statement about architecture and a source of certification burden. In the hangar, it has come to mean the computer is in charge and therefore the engine is safe.The second reading is a reasonable inference from the words. It is also exactly backward.What the manuals say the system doesIf the name will not tell us what the system does, the engine manuals might. Two common light-jet engine families publish exactly what their controls do, and neither manufacturer writes like a company that believes exceedances cannot happen.Read closely, both books describe roughly the same division of labor. The conditions most likely to threaten continued engine operation receive active protection. Many of the limits that primarily consume engine life are instead monitored, recorded, and handed back to the operator.Take the protections first, because they are real and they deserve their due. On the PW535E, acceleration and deceleration are governed to avoid surge and flameout. The FADEC performs automatic cool-down motoring before a start, and during a ground start it will abort on its own if it detects an unsatisfactory condition. Overspeed protection is genuine. All of this works with a precision no pilot could reproduce manually.Now look at what that list has in common. Surge, flameout, overspeed, an unsatisfactory start on the ground. These conditions can immediately threaten continued engine operation, and the FADEC actively intervenes.Turbine temperature is handled differently, and the manuals are precise about how. During a start, the Phenom 300 manual says the FADEC monitors ITT as the engine accelerates to idle. It does not describe that function as a hard temperature cap. And its automatic start-abort authority stops at the ground. In flight, the system no longer has that intervention available.If a start does go hot, Williams does not treat the aftermath as something the FADEC resolves on its own. The hot start procedure in the FJ44-4A line maintenance manual runs thrust lever off, motor the engine, then consult the chart. Every step belongs to a person.The pattern holds above idle. The Phenom manual says the FADEC does not ignore an intentional or accidental movement of the thrust lever, even during takeoff with one engine inoperative. The computer will faithfully execute an accidental lever movement at the worst moment in the flight, because faithfully executing lever movements is its job.And then there is the limit with no protection behind it. The Pratt andamp; Whitney maintenance manual, addressing takeoff time limit exceedances on the PW535E, states that no CAS message exists for one in the flight deck, and that the operator is responsible for preventing it. That sentence deserves to sit next to the Phenom 300's crew alerting table, which does include an ENG EXCEEDANCE caution for an operational limit exceeded in flight. The airplane has a dedicated exceedance annunciation. Time at takeoff power sits outside it, and the engine manufacturer assigned the responsibility to a human being in writing.Williams handles the recorded exceedance more strictly. On the FJ44-4A, a takeoff time overrun logs as a No Dispatch Fault, which the manual defines in capital letters: the aircraft shall not be operated until the problem is corrected and the fault is cleared. Once the FADEC logs one, the airplane is grounded until maintenance addresses it.But three distinctions matter. The fault happens after the exceedance, not before, so it is a maintenance requirement rather than a protection. It covers only what the ECU recorded, and an ITT excursion shorter than the signal-persistence threshold never sets a fault. And there is no corresponding fault for a takeoff time limit exceedance, so nothing grounds the airplane. That is how a CJ4 flies for two months before anybody learns that it happened twice.Where this bites in practiceThe start, with a tailwind, on a turn. Williams sets tight tailwind and crosswind start limits, and the recorded engine data includes the wind at the moment of start. Both hot starts in the CJ4 piece involved a recorded wind limit exceedance, and one of them voided the warranty on that basis. Check the sock before the start, not after.Configuration you did not know you were in. The Pratt andamp; Whitney overtemperature chart treats a given ITT for a given duration differently depending on why it happened. One named condition is mono-bleed, where one engine supplies air normally shared between two. Same temperature, same duration, different outcome, and the chart tells you to investigate why the airplane was in mono-bleed at all. The manufacturer is treating the exceedance as a symptom rather than an event.The takeoff detent on a busy departure. The CJ4 has takeoff, climb, and cruise detents, no autothrottle, and a five-minute takeoff limit. Nothing repositions the levers for you. Nothing tells you when the time is up. The aftermarket autothrottle option exists in part to move the levers from takeoff to climb after the five-minute limit, which is itself an admission of where the burden otherwise sits.One operator's weekAn operator flying a CJ4 had a pilot forget to set climb detent power on departure. Two days later, the same pilot did it again.The exceedances surfaced more than two months later, in a FADEC download performed during an unrelated case about a fuel control unit replacement. Williams Product Support answered unceremoniously: per the manual, two cycles per engine per occurrence, two occurrences, four cycles per engine. No investigation. No argument about whether the limit was actually exceeded. A rule, a count, a calculated result.The pilot was not doing anything reckless. He forgot a thrust reduction on two departures, in exactly the way Bainbridge predicted somebody eventually would.What it costsFour cycles per engine. To see why that number matters, look at how the two manufacturers dispose of an exceedance. They diverge in method while arriving at the same place, and the mechanisms are not what most people assume.Williams disposes graphically. The FJ44-4A manuals carry charts plotting interturbine temperature against duration above the exceedance threshold, divided into action zones, with separate charts for starting, takeoff, and continuous operation. A mild excursion means determine and correct the cause. A worse one adds a borescope, a ground run, and a FADEC download sent to Williams for disposition. The worst sends you into a hot section inspection, and if the visual shows overtemperature indications, into disassembly and non-destructive inspection of the turbine rotors.Two details in those charts earn more attention than they get. The takeoff and continuous charts have no worst-case zone at all, which means a running overtemperature above the upper threshold goes directly to hot section inspection. At the same time, a start can run considerably hotter and still land in a borescope disposition. Start temperatures are supposed to be high. Running temperatures are not.And one continuous-operation chart carries a note in red. An observed ITT exceedance can occur without being recorded as a fault, because the signal must persist before the ECU logs it. The crew can watch a needle move that the computer never wrote down. Williams found it necessary to explain to mechanics that the FADEC's record and the engine's experience are two different things.Pratt andamp; Whitney judges by area and adds a variable Williams does not use. Their chart makes the disposition depend on which rating you were in. The no-action region extends substantially for maximum takeoff and automatic power reserve, because those ratings exist for emergencies. The same temperature for the same duration in a normal takeoff sends you to inspection. The indicated exceedance is the same. The disposition is not, because the certified ratings carry different published allowances and the chart honors them.The same data stream cuts both ways. Williams extended midlife inspection intervals across the FJ44 line and attributes those extensions to data within its engine monitoring program. The fleet earns the extension. The individual engine with a documented exceedance history is pulled from the same dataset.Then there is the accounting, where the two manufacturers differ most, and where most of the folklore is wrong. Pratt andamp; Whitney keeps a running tab. For a takeoff time limit exceedance, you calculate the excess past the five-minute allowance and record both the individual and the accumulated values in the logbook. Twenty seconds here, forty there. Once the accumulated total passes sixty minutes, every subsequent exceedance triggers a power performance test and a borescope of nine named components. Sixty accumulated minutes is on the order of one hundred and eighty events of twenty seconds, none of which produces a dedicated cockpit annunciation. The record keeps count anyway.Williams charges cycles, which is the arithmetic the operator above was handed. On the FJ44-4A, exceeding the takeoff time limit costs two cycles per engine per occurrence. That number is worth understanding rather than shrugging off, because cycles are not an inspection item. Cycles drive life-limited part retirement, and life limits cannot be inspected away. Those parts come off at the number whether or not they look fine, because the limit is a fatigue calculation rather than a condition assessment.Two cycles is small. What it is not is reversible.What actually changedNone of this is an argument that FADEC made engine operation worse. It obviously did not, and this is the bounded claim from earlier getting its defense. FADEC removed enormous opportunities for pilot-induced exceedances. The acceleration schedules are better than any human's, the surge and flameout protections are real, the automatic cool-down motoring is real, and fleet data has allowed manufacturers to extend maintenance intervals in ways pilot technique never could. The evidence that produced the misconception is not fake. The system is genuinely excellent.What FADEC changed is not the underlying metallurgy. Turbine life is still consumed by temperature, stress, and time, whether a computer scheduled the fuel or a hydromechanical control did.What changed is how much harder these events are to lose. Many are now recorded, timestamped, quantified, and dispositioned against a published chart. Before, two crews could commit the identical error and receive different verdicts depending on whether anyone found out. The act was the same. The consequence turned on detection. FADEC did not abolish error, and it did not abolish damage. It made luck a lot harder to rely on.That is why these events are simultaneously less likely and much harder to pass unnoticed. The folklore feels true because FADEC removed so many of the opportunities. It did not remove the consequence.And it is why what remains matters more, not less, than it did when the fuel control was a hydromechanical box. Automation took the parts of the job that could be automated: the frequent and the easy parts. What is left is the rare, the ambiguous, and the five minutes on a departure when the only thing standing between the airplane and four cycles is somebody remembering.I will answer the question in the title: it is not marketing, and it is not really a myth either. It is a misunderstanding, and an honest one, assembled out of true statements by people with no intention of misleading anybody. That is what bothered me about the article, and it is why it is worth writing about rather than arguing with.