
Let’s pick up right where the torque-limit safeguards leave off, because that’s the bridge into engagement criteria. I want you to hold onto this idea: the autopilot’s servomotors are deliberately weak. They are limited in torque, and they are allowed to slip or fully disengage if their torque limits are exceeded. That’s a safety feature, and the methods used to achieve it are mechanical, electrical, or electromechanical. Now, before the autopilot is ever allowed to take control, the system has to prove it is healthy. That proof is handled by what we call the Autopilot Interlocks.
Here’s the logic. Before coupling an autopilot with the aircraft’s control system, the integrity of the Autopilot Inner Loop must be established. The inner loop is the part of the autopilot that actually commands and monitors the control surfaces. If that loop is faulty, you absolutely do not want it flying the aircraft. So, to monitor the performance of the inner loop components, a system of interlocks is provided. These interlocks close to allow autopilot engagement, and they hold it engaged, but only if the correct valid signals have been received. Think of the interlocks as a chain of switches that must all be closed before power can flow to the engage circuit.
The function of the interlocks can be represented by a number of relays in series. I want you to picture that: relays in series means every single relay must be closed for the circuit to be complete. If any one of them opens, the chain breaks. In modern aircraft, the actual switching is more likely accomplished by solid state logic switching rather than physical relays, but the series concept is identical. Now, the critical failure behavior: if a circuit monitored by a relay fails, the autopilot will disengage, and that disengagement is accompanied by the associated aural and visual warning indications. So you get a sound and a light. And operating the disengage switch has the same effect — it breaks the chain and drops the autopilot out, with the same warnings.
Now, interlocks prove the system is healthy. But there’s a second layer: the Conditions of Engagement. These are the pilot-controlled conditions that must be met before the autopilot will even accept an engage command. And I want to be clear — these conditions vary with aircraft type. I’m going to give you the 737-400 specifics, because that’s what we have here.
On the 737-400, each autopilot can be engaged by pressing a separate CMD or CWS engage switch. Let me unpack those acronyms. CMD is Command mode — that’s the autopilot actually flying the aircraft. CWS is Control Wheel Steering — that’s a mode where the autopilot assists but the pilot provides the steering inputs through the control wheel. Both are engaged through the same switch, but they behave differently.
Now, engagement in either CMD or CWS is inhibited unless both of the following pilot-controlled conditions are met. First: no force is being applied to the control wheel. If you’re holding the yoke, the autopilot won’t engage. Second: the Stabilizer Trim Autopilot Cut-out Switch is at NORMAL. That switch is a guard — if it’s not in the NORMAL position, the autopilot is locked out.
Once both conditions are satisfied, and no failures exist, either autopilot can be engaged in CMD or CWS by pressing the respective engage switch. And here’s a subtle but important behavior: control pressure applied after an autopilot is engaged in CMD overrides the autopilot into CWS pitch and/or roll. So if you’re in full Command mode and you grab the yoke and apply pressure, the autopilot doesn’t fight you — it drops back to Control Wheel Steering, letting you take over in pitch, roll, or both. And the light remains illuminated in the CMD engage switch. That light staying on tells you the CMD mode is still armed or selected, even though you’ve overridden into CWS.
So the full picture is this: interlocks prove the inner loop is healthy, conditions of engagement prove the pilot is ready and the guards are set, and then the engage switch arms the system. If anything fails along that chain — a relay opens, a circuit fails, or you press the disengage switch — the autopilot drops out with aural and visual warnings. And if you, the pilot, apply force after engagement, the system gracefully steps back from full command to control wheel steering rather than fighting you. That’s the safeguard architecture in a nutshell.
This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.
Continue in BlueFlash