Part I — Situation overview

On the morning of 29 August 2026 a 24-year-old man from Szomor took without permission a Cessna 172 light aircraft from the airfield at Kalocsa and set course with it towards the Paks nuclear power plant. According to the information later published by the police, the man tore the aircraft’s tie-down ropes out of the ground, got in and then took off from the service road. The radars of the armed forces detected the aircraft, and a quick reaction pair of fighters rose into the air from the base at Kecskemét. A few minutes later the small aircraft made a forced landing in a sunflower field on the edge of Gerjen in Tolna county; the undercarriage broke off and the fuselage tipped over on its side. The man, in a confused state, left the aircraft behind and walked along road 512, then tried to take the vehicle of a motorist who had stopped to help, whereupon the police called to the scene apprehended him. The county police headquarters of Bács-Kiskun and of Tolna opened proceedings for unlawful taking of a vehicle and other criminal offences, and initiated the man’s pre-trial detention; the investigation also extends to whether, beyond intoxication, he was under the influence of another substance. The presumption of innocence applies unchanged at every stage of the proceedings and to everyone concerned.

The case has a precedent, and it is not unique. A day earlier, on the afternoon of 28 August, the Gripens had to be scrambled on account of a PA28 light aircraft with French registration: the aircraft was heading from Slovenia through Austria towards the Czech Republic, but established no radio contact with civil air traffic control. Noticing the Austrian fighters, it entered Hungarian airspace without permission near Fertőszentmiklós and left it near Kapuvár. In that matter the defence ministry filed a complaint for airspace violation and breach of air traffic rules. Civil flight is prohibited within a radius of three kilometres around the Paks nuclear power plant, up to an altitude of six thousand metres; this restriction has been in place for a long time, and in the Kalocsa case it was precisely this that provided one of the legal grounds for the scramble alongside the theft. At the same time the case revealed a third, rarely discussed layer: the physical protection of the rural landing sites of general aviation — the world of sport and private flying. The operator of Őcsény airfield put it publicly that the airfield rulebook has a twofold purpose: on the one hand the protection of outsiders from a hazardous operation, on the other the prevention of unauthorised persons gaining access to the aircraft and taking them away. In the present case this second function did not work.

MIAK’s reading is that the essence of the story is disproportion. Preventing access to an aircraft parked unguarded which can be started with a few switches is among the cheapest conceivable security measures; the answer given to it, however, was the most expensive instrument at the disposal of the Hungarian state. This is not the fault of the armed forces — the quick reaction service did exactly what it was created for, and did it fast. The fault is at the beginning of the chain: there is no compulsory, checked and audited minimum standard for how a general aviation aircraft must be stored and secured at a public landing site, and there is no compulsorily used official database of the prohibited zones around critical facilities either.

Part II — Foundations in the literature

Three conceptual reference points arise for the assessment of the situation. The EU directive on the security of network and information systems (NIS2) lays down for critical and highly critical entities the principle that risk management must be based on an all-hazards approach: not only the digital systems but also their physical environment has to be protected — against theft, fire, flood and unauthorised physical access to facilities alike — and an access control policy is expressly part of this. The Fundamental Law of Hungary provides the domestic framework of competences: under Article 44 the fundamental task of the Hungarian Defence Forces is the military defence of the country, while under Article 45 the prevention and detection of criminal offences and the protection of public security belong to the police. In the present case the control of the airspace was a defence task and the apprehension of the suspect a law-enforcement one, and the two are not interchangeable. Daniel Kahneman (Israeli-American psychologist, one of the founders of behavioural economics, awarded the Nobel memorial prize in economics in 2002), in his chapters on the weighting of rare events, describes the bias which explains why protection is missing before such events and why the reaction overshoots after them. The detailed treatment of the literature — author by author, with quotations — can be found in section 6.4 Literature in detail.

Part III — MIAK’s concrete proposal

MIAK proposes three measurable measures. All three are cheap, all three are politically neutral, and none of them requires the setting up of a new authority — only a standard at the level of a decree, one public database and one written escalation ladder.

3.1 A risk-based minimum standard for access control and aircraft securing at every public landing site (within 90 days)

The civil aviation authority should draw up, and the minister responsible for transport should promulgate by decree, the minimum standard which every registered Hungarian landing site has to meet. The standard should contain four elements: the separate, locked storage of aircraft keys and onboard documents; the physical securing of unused aircraft (control lock or an equivalent solution, not merely tying down); camera surveillance of the aircraft parking area; and an annual self-inspection, the result of which the operator sends to the authority. The standard should be risk-based: landing sites lying within a radius of fifty kilometres of critical facilities — nuclear power plants, large water treatment and waterworks sites, gas storage facilities — should be subject to a stricter requirement, and those further away to a basic level. It is this differentiation that makes the proposal proportionate: Hungarian sport and private aviation is a small community with narrow financial room for manoeuvre, and an expensive package of requirements imposed uniformly on everyone would not increase safety but would squeeze out legal flying. The structural model for the standard is the risk management logic of NIS2 (see 6.4.2): the obligation does not prescribe a list of equipment but the level of protection to be attained, and leaves it to the operator how to reach it. The proposal applies the risk-based resource allocation principle of MIAK’s KB5 programme point to the protection of facilities.

3.2 A public, machine-readable database of the prohibited zones around critical facilities (by the first half of 2027)

The airspace restrictions in force today are legally valid but in practice hard to access: whoever wants to take off has to find out for themselves where a prohibited zone lies. MIAK proposes that the civil aviation authority create and maintain an official, free, machine-readable database of the prohibited and restricted zones in Hungary — including the three-kilometre zone around Paks valid up to six thousand metres — in a standard format which onboard navigation devices and flight planning applications can load directly. With commercial drones the manufacturers’ geofencing, that is the software delimitation of prohibited zones, has been a working and proven solution for years; the proposal carries this logic over into general aviation, with the difference that here the publication and maintenance of the database is a state task, while its incorporation belongs to the device manufacturers and the operators. The measure helps the law-abiding pilot rather than obstructing the bad-faith one — but that is precisely the point: a significant part of today’s scrambles falls into the second category, where the breach of the rules is caused not by intent but by lack of information. The database is the natural extension into physical space of MIAK’s D5 cybersecurity and critical infrastructure protection programme point.

3.3 A written escalation ladder and an annual public scramble statistic

In current practice two states are visible to the public: “nothing happens” and “the Gripens take off”. MIAK proposes that the defence and the law-enforcement body jointly put in writing the graduated order of intervention which lies between the two — from the radio call and the notification of air traffic control, through the alerting of ground interception forces and helicopter tracking, to the launch of the quick reaction fighter pair — clearly marking which rung falls within whose competence. The separation of competences is not a formality: under Article 44 of the Fundamental Law the military defence of the airspace belongs to the Defence Forces, and under Article 45 the apprehension of the perpetrator and the detection of the criminal offence belong to the police, and blurring the two tasks causes legal disputes afterwards. Part of the order should be an annual public statistic: how many airspace policing events took place, at which rung they were closed, and how many required a fighter scramble. The proposal follows the multi-model crisis management decision support of MIAK’s HV13 programme point; and before the introduction of the measure the public impact assessment under I3 should be prepared — precisely because the cognitive bias audit prescribed by I3 is particularly warranted in this case.

The three proposals are bound together by a single principle: protection has to be strongest where it is cheapest. The combined cost of an aircraft lock, a camera and a downloadable zone list is orders of magnitude smaller than a single quick reaction sortie — and, most importantly, these also work at times when nobody is paying attention.

Part IV — Expected effects and risks

Dimension Expected effect Risk
Defence Fewer, more targeted quick reaction scrambles; the fighter sortie genuinely becomes the last resort Thinning out live scrambles takes away practice occasions, if quick reaction training is not supplemented by exercises
Public security Unauthorised access runs into a physical obstacle; the great majority of cases are averted at the beginning of the chain Formal compliance with the standard (a camera existing on paper) does not increase security without inspection
Transport and general aviation Predictable, uniform requirements; it becomes simpler for the law-abiding pilot to comply With a disproportionate requirement the operation of small landing sites becomes impossible and flying turns informal
Public administration A clear ladder of competences, fewer subsequent legal disputes about the legal basis of intervention Regulation at the level of a decree can be withdrawn by a subsequent government just as easily

The main question for deliberation is proportionality. A very strict standard applying uniformly to everyone is apparently safer, but in reality it causes deterioration in two directions: it closes some of the small rural landing sites, and the remaining flying activity partly moves outside the registers — where no rule reaches it at all. This is why MIAK proposes risk-based differentiation: strictness is warranted in the vicinity of critical facilities, elsewhere the basic level is sufficient.

The second question for deliberation is timing. The series of official inspections now under way — launched by the police together with the aviation authority at Kalocsa and then at the country’s other airfields — is an excellent opportunity for taking stock, but in itself it is not a standard. If the result of the inspection does not become a compulsory requirement, in a few months’ time the situation will remain unchanged: the attention passes, the measure fails to come. It is precisely this pattern that Kahneman describes (see 6.4.1) — in the days after the event we overestimate the risk and overreact, and a few months later we underestimate it and do nothing. The value of regulation lies in withdrawing the decision from this oscillation.

Part V — Measurability and summary

5.1 What is worth following? (proposed KPIs)

The performance indicators (KPIs, Key Performance Indicators) below are suitable for judging in 12–24 months whether the intervention works. These are proposed indicators, not government undertakings.

  • Inspection coverage: at what percentage of registered Hungarian landing sites an actual, documented safety inspection has been completed, and what percentage of these met the minimum standard. Proposed target: 100 per cent coverage by mid-2027.
  • Airspace policing events and their distribution: how many events occurred per year, and what percentage of these were closed at the lowest rung of the escalation ladder (radio call, contact by air traffic control). This indicator — not the absolute number of scrambles — shows the maturity of the system.
  • Zone database coverage: how many flight planning applications and onboard devices have incorporated the official zone database, and how many downloads there have been. Proposed target: by 2028 the overwhelming majority of flight planning applications used in Hungary.
  • Unauthorised access attempts: in how many cases an operator reported unauthorised entry or an attempt to gain access to an aircraft. A rising number of reports is a good sign here, because it shows an improvement in detection.

5.2 Summary

MIAK’s request is concrete: the Government should not stop at the series of inspections now under way, but should ensure that the minister responsible for transport promulgates by decree, within ninety days, the minimum standard for access control and aircraft securing at landing sites, and that the civil aviation authority publishes the machine-readable database of the prohibited zones around critical facilities. The proposal is not about the suspect of 29 August — in his case the investigating authority and then the court will decide — but about the structural gap which this case made visible. Closing the gap is not costly, and it is not a political question either.

Two MIAK foundational values move together here. Data-drivenness, because the centre of gravity of the proposal is set not by the drama of the event but by the cost-benefit ratio of the points of intervention: protection goes where it is worth most for the least, and measuring this requires an annual public statistic. And being free of ideology, because this day exceptionally brought a matter whose facts the whole Hungarian press spectrum reported identically — so MIAK too can process it exclusively as a regulatory question, without any political framing.


Part VI — Justifications and further sources

6.1 The framing of the press, spectrum by spectrum

This event belongs to the rare exceptions: it appeared across the whole breadth of the Hungarian press with essentially identical facts, without heat. The difference between the segments lies not in the framing but in whose point of view the story is told from, and in whether a regulatory question is put at all.

The left-liberal segment worked by placing official facts and facts from its own sources side by side. Telex led with the defence minister’s communication and the police information, and lifted the parameters of the prohibited airspace around Paks into the text as well. 444.hu, on the basis of the police statement, added in a late-morning update the circumstances of the apprehension and the legal classification of the pending proceedings. HVG carried the topic in two separate articles: in the first, citing its own information, it reported that the aircraft had flown and manoeuvred in the prohibited airspace above the nuclear power plant, and in the second the details of the police video — the tearing out of the tie-down ropes and the take-off from the service road. This was the only segment which pursued the question of how did he gain access in documentary fashion.

The general public affairs segment went furthest beyond the mere reporting of facts, but in two different directions. 24.hu tied the story to its own analysis of the reliability of the Hungarian Gripen fleet — that is, it put the question from the side of the equipment. ATV, by contrast, asked exactly what this analysis is about too: how an unauthorised, intoxicated person was able to start and take away an aircraft. ATV gave the floor to an instructor pilot, who said that starting such a small aircraft is not technically complicated, and to an airfield operator, who explained the twofold purpose of the rulebook. From a policy point of view this was the most valuable report of the day.

The business segment worked with technical precision but with the narrowest context. Portfolio carried the Friday afternoon French PA28 matter and the Saturday Kalocsa case in two separate articles; it was the only segment to report that in the former matter the defence ministry had filed a complaint for airspace violation and breach of air traffic rules. This detail is important, because it shows that airspace policing events do have an established legal follow-up — only the prevention side is missing.

The conservative segment carried the case in a short, factual form. Magyar Nemzet and Mandiner alike narrowed the account to the defence minister’s communication and the forced landing, and put no regulatory question; the focus of these papers on that day was on another domestic political topic. The overall picture that emerges is nonetheless unusual and worth mentioning: in Hungarian public life today it is rare to have a news item whose facts not a single segment disputes.

6.2 Facts and data

Event Time Facts Official consequence
Airspace violation by a French PA28 Afternoon of 28 August 2026 Aircraft heading from Slovenia through Austria towards the Czech Republic; established no radio contact with civil air traffic control; entered Hungarian airspace without permission near Fertőszentmiklós, left it at Kapuvár Scramble of the quick reaction pair; complaint by the defence ministry for airspace violation and breach of air traffic rules
Aircraft theft at Kalocsa Morning of 29 August 2026 A Cessna 172 taken from the airfield at Kalocsa; forced landing on the edge of Gerjen, the undercarriage broke off; the 24-year-old man was intoxicated Scramble of the quick reaction pair; proceedings by the county police headquarters of Bács-Kiskun and of Tolna for unlawful taking of a vehicle and other criminal offences; criminal custody, initiation of pre-trial detention
Official follow-up 29–30 August 2026 Joint safety inspection at Kalocsa airfield, extended to the country’s other airfields Joint proceedings of the police and the aviation authority; on-site inspection with the involvement of experts

The parameters of the prohibited airspace around the Paks nuclear power plant: a circle with a radius of three kilometres, up to an altitude of six thousand metres, which it is prohibited to enter except for military aircraft. This restriction is not new, nor is it stricter than international practice — the present case showed not the inadequacy of the restriction but the absence of the first link in the chain of enforcement.

6.3 Policy dimensions

  • Defence (programme points) — putting the escalation decision tree in writing is the application of multi-model crisis management decision support (programme point ID: HV13) to a domestic, non-war type of event; the framework of civil-military cooperation follows from the societal defence resilience programme point (programme point ID: HV7).
  • Public security and law enforcement (programme points) — risk-based differentiation between airfields is a direct adoption of the resource allocation logic of predictive policing (programme point ID: KB5); the annual public scramble statistic can be fitted into the data scope of the criminal data platform (programme point ID: KB1).
  • Digitalisation and AI regulation (programme points) — the zone database is the physical-space equivalent of the critical infrastructure protection branch of the cybersecurity strategy (programme point ID: D5).
  • Justice (programme points) — a compulsory public impact assessment and cognitive bias audit before the introduction of the standard at the level of a decree (programme point ID: I3).

6.4 Literature in detail

6.4.1 Daniel Kahneman: Thinking, Fast and Slow

Kahneman describes two biases running in opposite directions, and it is precisely the alternation between the two that explains the typical regulatory cycle of critical infrastructure protection. One is the availability heuristic: after an event has occurred, similar cases come easily to mind, so we overestimate their probability. The other is its mirror image: as long as nothing happens, the risk is not available, so it appears not to exist. The movement between the two is described by the author as a distortion of decision weights:

“Because of the possibility effect, we tend to overweight small risks and are willing to pay far more than expected value to eliminate them altogether.”

The observation cuts both ways, and for that very reason can be used as a yardstick. In the days after an event the readiness grows to take disproportionately expensive, spectacular measures — for example to provide every small airfield with permanent physical guarding — while in the period before the event not even the purchase of an aircraft lock costing a few tens of thousands of forints took place. MIAK’s proposal is deliberately placed in the band between the lower and the upper point of the wave: it proposes cheap, compulsory and continuously checked measures which do not depend on the present attention. The cognitive bias audit of programme point I3 is a compulsory element of the proposal precisely for this reason: regulation is good if it is still good three months later.

📖 Source: Daniel Kahneman: Thinking, Fast and Slow

6.4.2 Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2)

The NIS2 directive is known primarily as a cybersecurity rule, even though its risk management chapter expressly goes beyond the digital boundary. According to the recitals of the directive, risk management measures have to be based on an all-hazards approach, aimed at protecting the systems and their physical environment from every event such as theft, fire, flood, disruption of supply, or unauthorised physical access to facilities; within this framework the entities concerned have to have an appropriate access control policy. The directive moreover expressly links itself with the EU regulation on the resilience of critical entities, and prescribes that the competent authorities of the two systems share information with each other on cyber and non-cyber risks alike.

This structure carries three lessons for the Hungarian case. First: the EU yardstick for the protection of critical facilities does not know the separation of “physical” and “digital” security — access control is the same category in both. Second: the regulation does not prescribe equipment but a level of protection to be attained and a compulsory risk assessment, leaving the manner of implementation to the operator; this model can be taken over for landing sites as well. Third: the principle of compulsory information exchange between authorities is precisely the missing link which MIAK’s proposal 3.3 would supply in the escalation ladder — between the defence and the law-enforcement body there is today no written, public order of cooperation for this type of event.

📖 Source: Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity (NIS2)

6.4.3 The Fundamental Law of Hungary

The demarcation of competences is not hair-splitting: it decides whether an intervention is lawful and who answers for it. Article 44 of the Fundamental Law sets out the fundamental task of the Hungarian Defence Forces as the military defence of the independence, territorial integrity and borders of the country, the performance of common defence and peacekeeping tasks arising from international treaties, and humanitarian activity; the operation of the Defence Forces is directed by the Government. Article 45, by contrast, defines the fundamental task of the police as the prevention and detection of criminal offences and the protection of public security, public order and the order of the state border.

The case of 29 August touched both remits, but not in the same moment. The control of the airspace, the identification of the aircraft and the launch of the quick reaction pair were a defence task; the apprehension of the person who took the aircraft, the opening of proceedings and the carrying out of the airfield safety inspection were law-enforcement ones. Blurring the two — for example if a regulation entrusted the Defence Forces with checking the protection of airfield facilities — would be not only a conceptual but also a practical error: responsibility and the avenue of legal remedy would both become blurred. This is why MIAK’s proposal 3.3 prescribes that at every rung of the escalation ladder it be named which body acts.

📖 Source: The Fundamental Law of Hungary (text in force on 17 April 2026), Articles 44 and 45

6.5 International comparison

The international framework of the question has long been given, only its domestic transposition is incomplete. The basic international document for the protection of civil aviation is Annex 17 to the Chicago Convention of the International Civil Aviation Organization (ICAO), which lays down the general requirements for protection against acts of unlawful interference; the European Union Aviation Safety Agency (EASA) has developed a separate, proportionate system of recommendations for general aviation, precisely on the ground that requirements tailored to commercial air transport, if forced upon light aviation, would not increase safety. For the physical protection of nuclear facilities the International Atomic Energy Agency (IAEA) issues recommendations which likewise follow a risk-based, graded approach: the extent of protection is adjusted to the assessment of the threat.

At the level of practical solutions two models deserve attention. One is the community model of preventing unauthorised access, operated in several countries by the operators of small airfields and by pilots’ organisations themselves: a simple, voluntary list of requirements (key handling, aircraft lock, reporting of suspicious movement), to which the authority provides communication and training support. The other is the geofencing practice for drones, where the database of prohibited zones is built into the device by the manufacturer and the software simply does not permit take-off or entry. MIAK’s proposal is a combination of the two approaches: the compulsory minimum standard provides the legal framework, while the public zone database makes it possible for compliance to be technically easier than breaking the rules.

Defence

  • HV13 — Multi-model crisis management decision support
  • HV7 — Societal defence resilience

Public security and law enforcement

  • KB5 — Predictive policing with an ethical framework
  • KB1 — Criminal data platform

Digitalisation and AI regulation

  • D5 — Cybersecurity strategy

Justice

  • I3 — Legislative impact assessment

Proposed new programme point: Minimum standard for airspace and facility protection around critical installations — for the Defence area, jointly managed with the Public security and law enforcement area.

6.7 List of sources

Press sources (MIAK press monitor, 30 August 2026 — topic 2):

Knowledge base references (literature and legal sources):

  • 📖 Daniel Kahneman: Thinking, Fast and Slow
  • 📖 Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity (NIS2)
  • 📖 The Fundamental Law of Hungary (text in force on 17 April 2026)

MIAK internal materials:

  • MIAK policy area: Defence (programme points; programme point ID: HV13, HV7)
  • MIAK policy area: Public security and law enforcement (programme points; programme point ID: KB5, KB1)
  • MIAK policy area: Digitalisation and AI regulation (programme points; programme point ID: D5)
  • MIAK policy area: Justice (programme points; programme point ID: I3)
  • MIAK press monitor, 30 August 2026 — topic 2, score: 89/100

Supplementary public data sources:

  • ICAO Chicago Convention, Annex 17 (Security) — the international framework for the protection of civil aviation against acts of unlawful interference
  • EASA — proportionate safety recommendations for general aviation
  • IAEA — recommendations on the physical protection of nuclear facilities

Generation metadata