
25 years ago today, the system failed. Here’s what the 9/11 Commission said went wrong, and what it still teaches us.
The Commission didn’t blame one person or agency. It found five compounding failures.
- A failure of imagination. Nobody conceived of hijacked airliners as guided missiles. NORAD watched outward. The FAA’s playbook assumed hijackers wanted to land and negotiate. Lesson: the next attack won’t look like the last one. Imagine novel threats now, not after.
- Agencies hoarded what they knew. The CIA tracked two future hijackers to the U.S. and didn’t tell the FBI for over a year. The dots stayed in separate boxes. Lesson: silos kill. If critical information can’t cross internal boundaries, you have a plumbing problem.
- Known threats weren’t flagged. Both men were known al Qaeda operatives, never watchlisted. They got U.S. visas and lived openly in San Diego. Lesson: data you don’t act on is theater. Every alert needs an owner and a response.
- Aviation security was built for the last war. Screening looked for guns and bombs. Nobody designed for attackers who treated the plane itself as the weapon. Lesson: defend against how attackers actually behave, not how your model wishes they would.
- Nobody owned the problem. Counterterrorism was scattered across a dozen agencies, with no one holding the authority to connect the dots. That’s why the Commission created the DNI and the National Counterterrorism Center. Lesson: fragmented responsibility is no responsibility. Someone must own the whole picture.
The Commission’s warning still lands: institutions are optimized for the threats they’ve already seen. The job is to build systems that can see the one they haven’t.
Source: The 9/11 Commission Report (2004), via govinfo.gov.
Photo: AI (Meta)
You must be logged in to post a comment.