
I want to walk you through the autopilot chapter now, and we're starting with the regulatory side of things. This is EU-OPS material, so this is the legal framework that governs how autopilots must be fitted and built for commercial operations.
First, the requirement for single-pilot operation. If an operator wants to conduct single-pilot IFR operations — that's flying on instruments at night or in cloud with a single pilot — the aeroplane must be equipped with an autopilot that has at least two specific functions: ALTITUDE HOLD and HEADING MODE. Altitude hold means the autopilot maintains the selected altitude; heading mode means it maintains the selected heading. And here's the key point: having those two functions means the aircraft must have at least a two-axis autopilot. One axis controls pitch, the other controls roll — so altitude hold uses the pitch axis, and heading mode uses the roll axis.
Now let's look at the installation requirements for the automatic pilot system itself. Each automatic pilot system must be approved, and it must be designed so that the autopilot can be quickly and positively disengaged. The purpose here is to prevent it from interfering with your control of the aeroplane — if something goes wrong, you need to be able to get it off the controls immediately.
Next, unless there is automatic synchronizing, each system must have a means to readily indicate to the pilot the alignment of the actuating device in relation to the control system it operates. Let me unpack that. The actuating device is the part that moves the controls. If the autopilot isn't automatically syncing itself to the control position, you need a way to see whether the actuator is aligned with where the controls actually are. That's a safety check so you know the autopilot isn't fighting the controls.
Each manually operated control for the system must be readily accessible to the pilots. And here's a specific one: quick release — emergency — controls must be on both control wheels, on the side of each wheel opposite the throttles. So on the left wheel and the right wheel, on the outboard side away from the throttles, you have the emergency disengage button.
Attitude controls must operate in the plane and sense of motion specified for cockpit controls. That means the direction you move the control must match the natural sense of motion — push forward for nose down, for example. And the direction of motion must be plainly indicated on, or adjacent to, each control.
The system must be designed and adjusted so that it cannot produce hazardous loads on the aeroplane, or create hazardous deviations in the flight path — and this applies both during normal operation and in the event of a malfunction. So the design has to protect you even when something fails.
If the autopilot integrates signals from auxiliary controls, or furnishes signals for operation of other equipment, there must be positive interlocks and sequencing of engagement to prevent improper operation. Interlocks are safeguards that prevent things from engaging in the wrong order. And there must also be protection against adverse interaction of integrated components.
Finally, means must be provided to indicate to the pilots the current mode of operation and any modes armed by the pilot. Armed means selected but not yet active — the autopilot is waiting for a condition to be met before it engages that mode. You need to see both what's active now and what's waiting to activate.
Now let's move to the hardware — the types of actuator. Actuators produce the physical movement of the control surfaces. They can work on different principles: electromechanical, electrohydraulic, or pneumatic. Electromechanical uses electric motors and mechanical gearing; electrohydraulic uses hydraulic pressure controlled electrically; pneumatic uses air pressure.
There are two types of configuration in which actuators are connected to the flying controls: parallel and series.
In a parallel configuration, the actuator produces the movement of the control surface as well as providing feedback to the control stick. That means the stick will move when the autopilot is controlling the control surfaces. You can see this in Figure 26.5 — the actuator is connected in parallel with the control path, so the stick moves with it.
In a series configuration, the actuator produces movement of the control surface but not the control stick. The stick stays still while the surface moves. That's Figure 26.6. And it's also possible to have a combined series/parallel configuration, which mixes both behaviours.
Now, the torque limiter. In flight, particularly where high rates of control are to be produced, the movement of the flight control surfaces can result in loads which may impose excessive stresses on the aircraft structure. So under automatically-controlled flight conditions, you need to safeguard against such stresses. And there's a second threat: a servomotor 'runaway' condition — that's when the servo motor that drives the actuator keeps running out of control, which would cause the control surfaces to be displaced to their maximum hard-over positions. The torque limiter is the safeguard against both of those — it limits the torque the actuator can apply, so it can't overstress the structure or drive the surfaces to their stops in a runaway.
So to tie it together: the autopilot is regulated at the EU-OPS level for what it must do in single-pilot IFR, the installation rules govern how it's built and how you disengage it, and the actuators — parallel, series, or combined — are how it physically moves the controls, with the torque limiter as the protection against overstress and runaway.
This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.
Continue in BlueFlash