Summary

  • On 11 March 2011, Units 1, 2 and 3 at Fukushima Daiichi automatically shut down after the Great East Japan Earthquake. The earthquake disrupted off-site power, and emergency diesel generators initially supplied essential loads. The subsequent tsunami inundated the site and disabled most alternating-current sources, electrical switchgear and other support systems. Batteries and surviving steam-driven systems provided only bounded capability. Loss of power, heat removal, reliable indications and access then progressed into core damage in Units 1 to 3, hydrogen explosions in the Unit 1, 3 and 4 reactor buildings, radioactive releases and a prolonged regional emergency.
  • The tsunami was the physical trigger, not a complete root-cause statement. The National Diet investigation found the accident foreseeable and preventable in its institutional sense and described collusion between operator, regulator and government as a central governance failure. The government investigation, the International Atomic Energy Agency and Tokyo Electric Power Company, or TEPCO, documented weaknesses in external-hazard evaluation, severe-accident preparation, command, information, training and equipment. Those are institutional findings within their mandates, not criminal verdicts against every official or employee.
  • Practical control existed at several layers. TEPCO's board and nuclear leadership controlled corporate hazard review, capital priorities and severe-accident capability. Plant management and crews controlled time-critical operation but worked with damaged equipment, fragmentary indications, high radiation, debris, darkness and conflicting demands. The Nuclear and Industrial Safety Agency controlled pre-accident regulatory review and enforcement. The Cabinet, ministries, Nuclear Safety Commission, prefecture and municipalities controlled different parts of emergency declaration, protective action, monitoring and public communication. Residents controlled none of the plant barriers yet bore evacuation, health, property and livelihood consequences.
  • The strongest supported causal account is a common-cause loss. Flood water reached low-lying generators, distribution panels and service systems; unit-specific cooling systems then failed at different times. Instrumentation and valves depended on power, air, accessible equipment and credible readings. Fire engines and improvised injection were valuable but were not equivalent to a pre-engineered, seismically and flood-protected severe-accident system. Important details of core progression, leak paths and release timing remain model-dependent because instruments failed and direct access is still constrained.
  • Health language requires precision. International reviews have not documented acute radiation deaths among residents and do not expect a population-wide cancer increase to be discernible from radiation exposure. WHO's preliminary assessment nevertheless identified particular higher-exposure subsets requiring long-term monitoring, while evacuation and displacement produced independently serious psychosocial, medical-access, livelihood and community harms. A conclusion about low or non-discernible radiological risk is not a conclusion that the evacuation, contamination and loss of home were harmless.
  • Legal forums answered narrower questions than accident investigations. Japan's Supreme Court held in 2022 that the State was not liable under the State Redress Act in the four consolidated cases because the required counterfactual causal relationship was not established. In 2025, the Supreme Court let stand criminal acquittals of former TEPCO executives under the demanding test for professional negligence. Neither disposition converts TEPCO's operator obligations, compensation duties or the documented safety-control failures into non-events; equally, investigation findings cannot be restated as convictions that courts did not enter.
  • Repair evidence is real but incomplete. Japan created the Nuclear Regulation Authority, introduced backfitted requirements for external hazards and severe accidents, and subjected reactors seeking operation to new review. At Fukushima Daiichi, spent-fuel removal, contaminated-water controls, remote investigation and two small Unit 2 fuel-debris trial retrievals demonstrate technical progress. Yet roughly 880 tonnes of estimated fuel debris, damaged structures, waste, groundwater, long-term storage, continuing compensation and more than 23,000 recorded evacuees in early 2026 keep the accountability test open.
  • Durable closure requires evidence, not elapsed time: independently reviewed hazard models; protected and diverse power and heat sinks; instruments qualified for severe conditions; valves operable without normal infrastructure; portable equipment with tested connectors, routes, fuel and crews; realistic multi-unit drills; unambiguous public authority; addressable compensation; transparent radiological data; and decommissioning milestones tied to actual inventories and retrieval performance rather than calendar aspiration.

The forensic question is how a natural hazard crossed controlled barriers

Fukushima Daiichi was a six-unit boiling-water-reactor site. Units 1 to 3 were operating on 11 March; Units 4 to 6 were shut down for inspection or maintenance. The earthquake initiated automatic shutdown of the operating reactors. Shutdown terminated the sustained fission chain reaction, but it did not terminate radioactive decay heat. Fuel still required cooling, water inventory and a path by which heat could move from the reactor to an ultimate sink.

This distinction defines the case. A reactor can shut down exactly as intended and still suffer severe core damage if decay heat is not removed. Off-site power was lost after the earthquake. Emergency diesel generators started, showing that one defensive layer initially responded. The tsunami then struck the site, flooding and disabling most diesel generators, electrical distribution equipment and seawater-dependent support. One air-cooled diesel at Unit 6 survived and later assisted Units 5 and 6, but it did not preserve the operating units.

The IAEA's comprehensive 2015 accident report provides the international technical synthesis for this sequence and for the resulting multi-unit station blackout.

The phrase station blackout can sound narrower than the lived condition. It was not merely a dark control room. Operators lost dependable alternating current, portions of direct current, lighting, communications, valve motive power, instrument confidence, cooling-water support and access to equipment. The tsunami deposited debris and damaged roads. Aftershocks continued. Radiation and explosions progressively restricted movement. Multiple units demanded intervention at the same time, while normal assumptions that one unit could support another or that external resources could quickly arrive no longer held.

Each unit followed a different path. Unit 1 had an isolation condenser, but its status and operation were difficult to determine after power and indications were lost. Unit 2's reactor core isolation cooling system continued for a much longer period before cooling was lost. Unit 3 used reactor core isolation cooling and high-pressure coolant injection before those capabilities ended. These differences affected the timing of core damage, depressurisation, injection and release.

They do not change the common control problem: systems that could temporarily cool without external alternating current still depended on finite steam conditions, batteries, valves, instruments and operators who needed to know whether water was actually reaching the core.

Core damage generated hydrogen through high-temperature reactions involving zirconium fuel cladding and steam. Hydrogen escaped containment and accumulated in reactor buildings. Explosions damaged Unit 1 on 12 March and Unit 3 on 14 March. Unit 4 was shut down and had no fuel in its reactor, yet its reactor building exploded on 15 March; later analyses support hydrogen migration from Unit 3 through shared exhaust arrangements rather than an operating Unit 4 core. That finding is a warning about system boundaries: a unit that appears safe in isolation can inherit another unit's severe-accident products through shared infrastructure.

The accident was rated Level 7 on the International Nuclear and Radiological Event Scale because of the scale of release, but a rating is not a causal model. It says nothing by itself about which person could have prevented flooding, which valve could have been opened, whether an order was legally valid or whether an evacuation route was workable. Forensic accountability has to follow control from hazard assumption to equipment placement, from indications to decisions, and from decisions to consequences.

The timeline of prevention began decades before the inundation

Fukushima Daiichi's original design reflected the knowledge, methods and regulatory practices of its era. The plant platform, seawater pumps, emergency generators, cable routes and electrical rooms embodied assumptions about the maximum credible earthquake and tsunami. Later revisions increased the design tsunami level, but a protection strategy remained concentrated around keeping water below a bounded height rather than maintaining safety functions after substantial site flooding.

That is not hindsight merely because the 2011 wave was exceptional. External-hazard governance is a process for handling uncertain extremes, not a claim that one forecast will predict the exact event. Japan had historical tsunami evidence, evolving seismology and a 2002 long-term assessment from the government's earthquake research body addressing tsunami earthquakes along the Japan Trench. TEPCO and regulators debated how that assessment should influence design. A TEPCO calculation in 2008, using the long-term assessment as a premise, produced a tsunami height of about 15.7 metres at the site.

The exact status and engineering meaning of that calculation became contested in later litigation, but its existence is confirmed in the 2022 Supreme Court's detailed state-liability judgment.

The control failure was not simply that management possessed a correct forecast and refused a known solution. The 2008 result was based on a contested model; engineers considered further study, and proposed countermeasures depended on wave source, direction, height and route. The stronger finding is procedural: a result capable of overwhelming safety-related equipment did not trigger a time-bounded, independently challenged decision on interim protection. Uncertainty functioned as a reason to continue analysis rather than a reason to add diverse protection against the consequence.

The National Diet's independent commission examined this history and concluded that the accident could and should have been foreseen and prevented. Its archived chapter on preventability described a relationship in which TEPCO, regulators and government did not develop the independence and challenge expected in nuclear safety. The commission used the language of regulatory capture and institutional collusion. That is a parliamentary investigation finding supported by testimony and records; it should be attributed to the commission, not presented as a judicial finding of conspiracy or individual corrupt intent.

Severe-accident policy compounded the external-hazard gap. Measures beyond the design basis were treated substantially as voluntary operator initiatives rather than fully enforceable, integrated requirements. Station-blackout assumptions emphasised restoration within a limited duration. Probabilistic arguments, operating experience and confidence in Japan's plant standards helped sustain the idea that a prolonged, multi-unit loss of power and heat sink was too remote to control the design.

The later IAEA report found that the basic assumption that nuclear plants were sufficiently safe resulted in safety improvements not being introduced promptly.

Flood protection was also not functionally segregated. Emergency diesel generators had been added in different locations and configurations, but critical electrical distribution remained vulnerable. Seawater pumps and support systems were exposed. Portable alternatives were not staged as a complete system with protected fuel, compatible connectors, cables, hoses, routes, lighting, communications and trained teams. A pump in a warehouse is not a cooling function. The safety function exists only when power or water can be delivered to the correct connection at the required pressure and flow under the environmental conditions of the accident.

TEPCO's own later reassessment is unusually important because it goes beyond defending the initial investigation. Its 2013 Nuclear Safety Reform Plan acknowledged equipment imperfections and organisational problems, including limited public evidence preparation against low-frequency, high-consequence events. This is a corporate finding and reform commitment, not an independent adjudication. It nevertheless supports the conclusion that the pre-accident weakness extended from plant hardware into safety consciousness, technical capability and communication.

The regulator's structure mattered. The Nuclear and Industrial Safety Agency sat within the Ministry of Economy, Trade and Industry, which also promoted nuclear energy policy. Organisational location alone does not prove that every technical decision was biased. It created a conflict-risk architecture in which a regulator needed exceptional independence to challenge a nationally important industry and its own ministry's policy. The Diet commission found that challenge ineffective. The absence of a binding backfit system also meant evolving knowledge did not automatically compel older plants to meet newer protections.

By 10 March 2011, therefore, no one could know the exact magnitude, source or inundation pattern of the next day's tsunami. But responsible actors did know the consequence class: external events could remove off-site power, threaten emergency generators and disable heat sinks. They knew severe accidents require cooling, depressurisation, containment control and information. Prevention should be judged against those functions, not against an impossible requirement to predict the exact wave minute and height.

Eleven to fifteen March: a forensic sequence of shrinking options

At 14:46 local time on 11 March, the magnitude 9 earthquake struck. The operating units scrammed. Off-site power was lost, and the emergency diesel generators supplied alternating current. In the first period, the event resembled a serious but bounded loss of grid power for which the plant had designed responses.

The tsunami changed the state of the site. Waves arrived in the following hour, overtopped and bypassed protective assumptions, inundated low areas and flooded electrical and mechanical equipment. Most emergency diesel generation was lost, along with switchgear that would have been required to route power even if a generator could be brought close. Unit control rooms lost lighting and indications. The legal threshold for a nuclear emergency was reported, and the government declared a nuclear emergency that evening.

At Unit 1, the isolation condenser had operated after shutdown, but operators had to manage rapid cooling and containment conditions. The loss of direct-current indications made valve position and water level uncertain. Later investigators disagreed over details of isolation-condenser performance and what operators understood at particular moments. The responsible statement is bounded: cooling was not sustained, reactor water inventory fell, core damage began early, and the information available to decision makers did not reliably display that progression.

At Unit 2, reactor core isolation cooling continued without alternating current for roughly three days, buying time. At Unit 3, steam-driven systems also delayed complete loss of injection. That time was a safety resource, but the site could not convert it into a robust replacement system. Portable generators encountered incompatible connections, damaged distribution and deployment delays. Fire engines were assembled to inject water, but reactor pressure first had to be reduced and routes had to remain intact. Fresh water was limited; seawater injection became a last-resort measure.

Containment venting was another nominal safety function that depended on accident-damaged support. Vent paths were designed to reduce containment pressure, not to make radioactive release harmless. Valves required power, compressed air or manual access. Radiation, darkness, uncertain indications and locked or damaged paths complicated field work. Operators and government officials debated when venting should occur, whether it had occurred and what information could be communicated to the public. A procedure that says open a valve is not an executable control if the operator cannot see its state, energise its actuator or safely reach it.

The Unit 1 reactor building exploded on the afternoon of 12 March. The explosion destroyed the upper structure, injured workers, scattered debris and interrupted preparations serving other units. It was both a consequence and a new initiating event. Equipment staged outside became vulnerable; access routes changed; protective clothing and radiation controls became more burdensome; and attention shifted across a site already managing three deteriorating reactors.

Seawater injection into Unit 1 later became the subject of claims that political interference caused a halt. The record shows confusion between TEPCO headquarters, the plant and government over approval and potential consequences, while plant superintendent Masao Yoshida continued or resumed injection. The broader control lesson does not depend on dramatising one instruction. Emergency authority was not translated into a shared, technically current operating picture.

Headquarters and government could ask for consultation while the plant had minutes to act, and the plant could not assume that external decision makers understood equipment status.

Unit 3 lost high-pressure injection, was depressurised and received improvised injection, but core damage and hydrogen generation occurred. Its reactor building exploded late on the morning of 14 March. The blast injured personnel and again disrupted work. Unit 2's cooling then ended, water level declined and containment conditions deteriorated. On 15 March, a loud event and a sharp change in conditions at Unit 2 coincided with major release concerns, but the exact failure and release paths remain less certain than early public narratives suggested.

The Unit 4 reactor building explosion on 15 March intensified fear over its spent-fuel pool. Early information was limited public evidence to exclude a pool fire, and international concern became acute. Later observation and analysis did not support the feared complete loss of pool water; hydrogen backflow from Unit 3 is the supported explanation for the explosion. This is an example of how an emergency decision can be reasonable under uncertainty even when a feared mechanism is later rejected.

Accountability should examine whether uncertainty was disclosed and acted on, not punish responders for lacking facts that only later inspection could establish.

The government-appointed Investigation Committee reconstructed these operating and governmental decisions in a detailed archived accident-response volume. Its separate lessons and prevention volume identified weaknesses in severe-accident preparation, command, training, information and protective action. The committee's hearing-based chronology is strong evidence of what witnesses, logs and records supported. It does not make every minute exact: clocks differed, instruments were unreliable, memories were gathered after trauma, and some internal reactor states were reconstructed from models.

By 15 March, the accident had crossed from plant emergency into long-term national disaster. Large releases contaminated land northwest and elsewhere depending on wind and precipitation. Workers continued injection, power restoration, monitoring and stabilisation. A condition described as cold shutdown was announced in December 2011, meaning temperatures and releases had been brought under defined control. It did not mean the reactors had returned to an intact shutdown configuration. Melted fuel, damaged containment, contaminated buildings and continuing water management remained.

Trigger, root cause and contributing factors must not be collapsed

The initiating hazard was the earthquake-generated tsunami. The direct escalation mechanism was inundation that created common-cause loss of electrical power and heat-removal support. Those are confirmed facts. The earthquake also damaged off-site supply and the wider region, limiting response. Whether seismic motion caused safety-significant primary damage before tsunami arrival has been debated, particularly for Unit 1.

The public evidence has not established such damage as the necessary explanation for loss of cooling; it remains an issue that should be described with unit-specific uncertainty rather than used to displace the demonstrated flood pathway.

The root cause was governance of defence in depth. A nuclear operator is not accountable for preventing an earthquake. It is accountable for converting external-hazard uncertainty into protected safety functions. TEPCO's process did not require a high-end tsunami calculation to produce immediate, independently reviewed interim controls. Regulators did not force the issue through a strong backfit or severe-accident regime. Safety assurance therefore depended too heavily on the claim that the design event would not be exceeded.

Physical concentration was a major contributing factor. Several units shared a coastal site, roads, response resources, command arrangements and some ventilation or support infrastructure. Critical electrical equipment was placed where one inundation could affect multiple trains. The accident simultaneously invalidated redundancy that looked adequate under single-failure logic. Diversity on a diagram did not equal geographical and environmental separation.

Severe-accident procedures were another factor. Manuals could not create power, air, connectors or readable instruments. They were not sufficiently developed around a long-duration, multi-unit event with building damage and high radiation. The plant had to improvise fire-engine injection and manual venting. Improvisation by skilled crews was necessary and at times effective, but dependence on it is evidence that engineered controls had run out.

Instrumentation contributed both technically and organisationally. Water-level, pressure and radiation readings could be unavailable, misleading or misunderstood outside their qualified range. Decision makers in Tokyo asked for precise answers from a plant whose sensors and communication channels had failed. In severe accidents, a displayed number needs a validity envelope: power source, environmental qualification, calibration state, expected failure mode and corroborating indicators. Without that metadata, automation can turn instrument output into false confidence.

Emergency logistics were not treated as part of the safety system. Portable generators and pumps needed transport through a tsunami-damaged region; connectors and voltages had to match; cables had to cross debris; workers required dosimetry, lighting and protective equipment; diesel fuel and water had to be sustained. The 2011 response demonstrated that procurement and arrival are not the same as commissioning. Every interface between portable equipment and a plant should be a tested control point.

Institutional communication also promoted delay. The Diet commission's archived emergency-response chapter found confused roles between the Prime Minister's Office, regulators, TEPCO headquarters and the plant. The off-site emergency centre was impaired by loss of infrastructure and radiological conditions. Data systems did not give authorities a common, trusted picture. These weaknesses did not cause the tsunami, but they affected venting, resource allocation, public explanation and protective action when margins were disappearing.

Finally, confidence in prior compliance contributed. A plant can meet the rules applied at the time and still retain intolerable risk if the rules lag evidence. TEPCO could point to approved design and regulatory interactions; NISA could point to existing guidance. Accountability asks who owned the residual risk when evidence did not fit the approved case. If every actor can say another actor set the standard, the system has no owner for beyond-design-basis safety.

Detection failed when information was most valuable

The earliest detection was successful in a narrow sense: earthquake protection initiated shutdown, emergency diesels started, and operators recognised loss of power and cooling. The deeper failure was loss of observability. Flooding removed instruments and communications at the same time that operators needed to distinguish temporary cooling from core damage.

Reactor water level was particularly consequential. Some indicators later suggested water where analyses showed substantial core exposure. Severe conditions can alter reference legs, pressure relationships and sensor behaviour. A value read from an instrument therefore was not equivalent to a confirmed physical inventory. The lesson is not that operators should ignore instruments. It is that severe-accident procedures need diverse, qualified measurements and explicit rules for acting conservatively when values conflict with heat balance, radiation or pressure trends.

Radiological monitoring also degraded. Fixed stations lost power or communication, mobile monitoring was constrained, and release estimates were uncertain. Japan's System for Prediction of Environmental Emergency Dose Information, known as SPEEDI, generated dispersion information, but source-term uncertainty and fragmented decision processes limited its use in directing early evacuation. A plume model cannot identify absolute dose without credible release data, yet wind-direction information can still be operationally useful.

The failure was not one missing map; it was the absence of a pre-agreed method for using incomplete model output in protective decisions.

Public detection occurred through evacuation orders, explosions, dose readings and changing official statements. The government expanded the evacuation radius from a small initial zone to 10 kilometres and then 20 kilometres as the event escalated. Residents and municipal officials often lacked timely detail about plant conditions, plume direction, shelter duration and destination. Hospitals and care facilities faced transportation and continuity problems. Detection that does not reach the person who must act is not a completed safety function.

Later forensic detection improved through multiple independent investigations, simulations, muon imaging, robotic entry and sample analysis. TEPCO maintains a public series on unresolved accident-mechanism questions, an important admission that the internal states cannot be fully reconstructed from 2011 records. Continued uncertainty is not proof of concealment. It is a consequence of destroyed instruments, inaccessible high-dose spaces and model sensitivity, and it should remain visible in safety claims.

Response reduced worse outcomes, but recovery is not the erasure of consequence

Front-line response deserves control-specific assessment. Operators used surviving steam-driven systems, batteries, temporary power, fire engines, venting attempts and seawater. Firefighters, contractors, Self-Defense Forces and other agencies supported water delivery, monitoring and logistics. Workers remained on or returned to a hazardous site after explosions. These actions helped establish injection and limit further deterioration. They do not establish that initial preparation was sufficient; heroic response and deficient system design can coexist.

Command was divided by law and capability. TEPCO remained the licensed operator with detailed plant knowledge. The national government held emergency powers and responsibility for public protection. NISA advised and communicated through the ministry. The Nuclear Safety Commission provided technical advice. Fukushima Prefecture and municipalities had evacuation and public-service duties. In practice, the Prime Minister's Office intervened deeply because information was unreliable and consequences national.

The government investigation found that this produced duplication and confusion, while TEPCO headquarters did not always provide the plant or government with a stable common picture.

The claim that TEPCO intended to abandon the entire site became one of the most charged allegations. Available investigation records distinguish consideration of withdrawing non-essential personnel from complete abandonment. The Diet commission was critical of communication; other reviews did not establish a corporate decision to evacuate everyone. The accurate classification is unresolved or disputed in its strongest form. It should not be used to infer that all executives planned to desert the reactors, nor should semantic dispute obscure the genuine command failure over who would remain and under whose authority.

Evacuation reduced potential radiological exposure, but its execution caused serious secondary harm. Frail hospital and nursing-home residents were moved under disrupted medical conditions; families were separated; municipalities lost records and services; and repeated relocations extended stress. WHO's account of health consequences identifies medical-access, non-communicable-disease, mental-health and psychosocial effects among displaced populations. It does not assign every post-disaster death to radiation or to one evacuation order.

Radiological health evidence must be equally bounded. WHO's 2013 preliminary risk assessment projected low risk for the general population while identifying certain more exposed age, sex and location groups for whom estimated relative risks for some cancers were higher and long-term monitoring warranted. The assessment used conservative preliminary dose estimates. It was prospective risk modelling, not an observed cancer-causation judgment.

UNSCEAR's later 2020/2021 scientific review incorporated a much larger evidence base and concluded that no adverse health effects among Fukushima residents had been documented as directly attributable to accident radiation and that future population effects were unlikely to be discernible. This does not mean a mathematical risk of zero for every person. It means epidemiology is not expected to separate any accident-related increase from baseline variation at the assessed doses.

Fukushima Prefecture's current Health Management Survey overview reports that 99.8 percent of respondents with four-month external-dose estimates were below 5 millisieverts and that the thyroid evaluation through the fifth full-scale round found no association between thyroid cancer and radiation exposure. The same page exposes important limits: the basic survey response rate was 27.7 percent, later thyroid participation declined, and ultrasound screening detects abnormalities that would not have been found in an unscreened comparison population.

Observed diagnoses must not be called proof of radiation causation, while continuing voluntary follow-up remains justified.

Recovery therefore has several meanings. Reactor temperatures and releases were stabilised. Immediate exposure pathways were controlled through evacuation, food restrictions, monitoring and decontamination. Infrastructure and communities began reconstruction. Compensation moved resources to affected people and businesses. None of these actions restores the counterfactual in which residents were never displaced, land never contaminated and community networks never fractured.

Responsibility control map

TEPCO board and executive nuclear leadership. This layer controlled enterprise risk appetite, capital allocation, organisational design and the response to tsunami studies. It could require interim flood barriers, relocate or waterproof electrical equipment, procure diverse power, challenge severe-accident assumptions and elevate unresolved hazard results to the board. Its accountability is institutional even where criminal intent or individual foreseeability was not proved.

Corporate engineering and nuclear divisions. These functions controlled hazard calculation, probabilistic assessment, equipment standards, maintenance, emergency planning and information presented to regulators. They had a duty to preserve dissent and trace assumptions from analysis to disposition. A calculation marked provisional still needed an owner, deadline, compensating measures and closure evidence.

Fukushima Daiichi plant superintendent, shift teams and field crews. They controlled reactor operation and emergency action within the capability remaining onsite. Their decisions affected condenser use, injection, depressurisation, venting, personnel deployment and radiation protection. Their practical freedom narrowed dramatically after flooding. Accountability must account for unavailable instruments, unsafe access, damaged equipment and orders from outside; it should not transfer years of corporate design responsibility to the people operating during the final hours of margin.

NISA and the pre-2012 regulatory structure. The regulator controlled licensing interpretation, inspection, enforcement, backfit expectations and the review of tsunami and station-blackout risk. It could demand evidence or restrict operation. The structural connection to a ministry promoting nuclear policy increased the importance of transparent challenge. The Diet commission found that challenge inadequate. This is regulatory accountability, distinct from the Supreme Court's later decision about the State's monetary liability to particular plaintiffs under a specific causation test.

Nuclear Safety Commission, ministries and Cabinet. These bodies controlled parts of policy, emergency declaration, technical advice, protective action, resource mobilisation and public communication. During the accident they needed one authoritative operating picture and a clear division between setting public-protection objectives and directing plant tactics. Intervening without current plant knowledge could consume scarce attention; failing to intervene when the operator could not coordinate national resources would also be irresponsible.

Fukushima Prefecture and municipalities. Local authorities controlled evacuation execution, shelters, transport, health and resident communication within their resources. They were also victims of the regional infrastructure failure. National plans assumed functioning local offices, roads, communications and medical transport. Accountability requires resourcing local implementation, not merely sending an order from Tokyo.

Equipment designers, vendors and contractors. They controlled detailed design, maintenance and supplied systems within contracts and regulatory approvals. Shared ventilation, generator configuration, valve actuation and instrumentation all involved vendor knowledge. The public record does not support assigning the accident wholesale to a reactor designer or contractor. The licensed operator retained integration responsibility: it had to demonstrate that components formed a complete plant safety case under site-specific hazards.

Post-accident NRA, METI and decommissioning institutions. The NRA now regulates nuclear safety and the specified Fukushima Daiichi facility. METI and inter-ministerial bodies set decommissioning policy and roadmap. TEPCO executes much of the work, while research organisations and contractors provide technology. These actors control present-tense risk. Historic blame does not substitute for current retrieval, waste, water, worker and emergency controls.

Courts, compensation bodies and the Diet. Courts decide claims under pleaded law and evidence. Compensation and alternative-dispute mechanisms translate categories of damage into payment. The Diet legislates, investigates and oversees the regulator. None operates a cooling pump, but each controls whether failure produces enforceable remedy, transparent learning and future incentives.

Residents, workers and local industries. They control personal choices only within constraints created by authorities: whether to return, accept a settlement, participate in a survey or challenge a plan. They do not own the burden of proving nuclear safety. Consultation over decommissioning and water can improve legitimacy, but consent cannot be manufactured by withholding technical uncertainty or by treating economic dependence as agreement.

Legal and regulatory boundaries

Accident investigations use a prevention standard broader than tort or criminal law. The Diet commission could ask whether institutions should have identified and controlled risk. It did not need to prove beyond reasonable doubt that a named executive foresaw the precise tsunami, possessed a legally defined duty and caused specified deaths. Its findings support regulatory reform and political accountability, not a criminal conviction.

The 2022 Supreme Court decision concerned State liability. The majority reasoned that even if the economy minister had ordered measures based on the long-term earthquake assessment, the seawall or other response likely to have followed would not necessarily have prevented inundation and a similar accident. It therefore rejected the required causal relationship for damages under the State Redress Act. The judgment did not hold that no tsunami warning existed, that regulatory design was optimal or that TEPCO owed no compensation.

A separate opinion also emphasised the State's broad social responsibility for relief even while addressing the statute's limits.

Criminal liability followed another path. Former TEPCO executives were compulsorily indicted after a citizen-review process and tried for professional negligence resulting in death and injury connected to evacuation. Trial and appellate courts acquitted them. In 2025, the Supreme Court rejected the appeal; the official decision left the acquittals final. The court assessed foreseeability, duty, available preventive action and proof under criminal standards. The disposition must be reported as acquittal, not as an unresolved allegation of guilt.

It also does not revoke corporate safety duties or turn a criminal standard into the threshold for regulatory prevention.

Civil compensation has proceeded through operator payments, guidelines, mediation and litigation. TEPCO's live payment record reported approximately JPY 11.7296 trillion paid by 10 July 2026, including categories for individuals, businesses, property and decontamination. This is company-reported administrative evidence. The total should not be read as a verdict quantifying all harm, as money delivered only to individual residents, or as an admission resolving every disputed claim.

Settlement and payment can acknowledge compensable loss without establishing every alleged act. Conversely, an unsuccessful claim may fail because of limitation, proof, category or statutory causation without establishing that no harm occurred. Responsible reporting identifies the forum, parties, standard, date and disposition before drawing an accountability conclusion.

Post-accident requirements must not be applied retroactively as if they were the legal rules in 2011. Japan's new regulatory requirements strengthened earthquake and tsunami assessment, severe-accident measures, protection against common-cause events and backfitting of existing reactors. They are compelling evidence of what the post-Fukushima system considers necessary. They do not prove that every element was a binding pre-accident violation.

Institutional separation is also evidence of reform, not proof of completed reform. The NRA's published core principles commit it to independent decision making, field-oriented regulation, transparency, continuous improvement and emergency readiness. An IAEA 2016 integrated regulatory review documented strengths and recommendations. The correct assurance question is whether staffing, inspection, enforcement, technical competence and openness continue to demonstrate those principles in hard cases.

Counterfactuals identify where control was practical

The weakest counterfactual is that any sufficiently high seawall would certainly have prevented the accident. A wall designed around one model can be overtopped, flanked or damaged; it may also redirect flow. The Supreme Court majority specifically found the causal case for the State's expected measure limited public evidence. Seawalls can be valuable, but accountability should not depend on one geometric prediction.

A stronger pre-accident counterfactual protects functions after flooding. Watertight and separated electrical rooms, elevated or diverse generators, protected direct-current capacity, flood-isolated switchgear, robust air-cooled alternatives and connections placed above inundation could have reduced common-cause loss. No single item guarantees success. Their diversity makes it less likely that one water path disables every route to power and heat removal.

Another strong counterfactual treats the 2008 high-tsunami calculation as a trigger for interim action. TEPCO could have established a formal hazard disposition with independent review, a fixed deadline and temporary protection while model disputes continued. Regulators could have required disclosure, periodic status and functional testing of compensating measures. This does not assume the 15.7-metre output predicted the actual wave perfectly. It recognises that the consequence of being wrong was core damage across several units.

Severe-accident preparation offers a practical counterfactual. Hardened, accessible venting with reliable actuation and filtration; instruments qualified for severe temperature, pressure and radiation; staged generators and pumps with standardised connectors; protected fuel and compressed air; and drills involving simultaneous loss at multiple units could have preserved options. These features have cost and engineering limits, but they were within institutional control in a way that the earthquake was not.

A response counterfactual begins with shared information. A joint command structure could have defined the plant superintendent's authority over immediate safety actions, the government's authority over protective action and resource mobilisation, and a disciplined channel for technical questions. This would not restore failed hardware. It could reduce delay, duplicate demands and contradictory public messages.

Protective-action counterfactuals are more difficult. Earlier, wider evacuation might reduce dose in a release path but increase medical and transport harm. Shelter can be protective for a short period but unsafe without supplies or if later evacuation occurs through a plume. SPEEDI output without a reliable source term could misstate magnitude, yet wind and scenario information could still guide monitoring and route selection.

The supported alternative is not one perfect radius; it is preplanned, dose-informed, medically supported evacuation with transport inventories, receiving facilities, iodine policy, monitoring and explicit rules for uncertainty.

For recovery, the counterfactual is transparent milestone governance. Decommissioning schedules could define what evidence changes a date: internal inspection, sample properties, dose, tool reliability, waste pathway and worker exposure. If a trial slips, public reporting should show the failed assumption and revised decision, not preserve the appearance of schedule certainty. The same logic applies to return policy and compensation: lifting an order should not automatically terminate every form of support before homes, services and livelihoods are viable.

Counterfactuals have limits. The record cannot calculate precisely which measure would have preserved each core, how much release a filtered vent would have avoided, which evacuation death would not have occurred, or what each community would look like without displacement. They are decision tests, not alternative histories presented as fact.

Repair evidence must be read as a chain of controls

The first repair was stabilisation. Injection, electrical restoration, cooling, monitoring and containment management lowered immediate risk. Subsequent removal of spent fuel from Unit 4 and Unit 3 reduced hazards in damaged reactor buildings. Covers, rubble removal, groundwater bypass, subdrains, frozen-soil barriers, water treatment and tank management addressed different release pathways. Each measure has a defined purpose; none is a certificate that the site is decommissioned.

Fuel debris is the central unresolved inventory. TEPCO estimates about 880 tonnes across Units 1 to 3. Its current fuel-debris evidence page explains that retrieval will proceed step by step and that final disposal arrangements remain to be determined with government. The estimate depends on modelling because the debris cannot yet be directly weighed or mapped completely.

In November 2024, TEPCO completed the first small trial retrieval from Unit 2; a second was completed in April 2025. The company's retrieval archive records sampling, transport and analysis. These are significant first-of-kind operations through a constrained penetration in a high-radiation environment. Their evidentiary meaning is capability at sample scale. They do not demonstrate industrial-scale retrieval, packaging, storage or disposal of the estimated inventory.

The government's mid- and long-term roadmap portal retains the policy framework for completing decommissioning 30 to 40 years after the initial 2011 roadmap. Earlier milestones have moved, including the start of trial debris retrieval. A target extending to 2041-2051 is a planning commitment, not a confirmed completion date. Credible schedule control requires ranges and dependencies for access, remote equipment, waste classification, storage and final-state decisions.

Contaminated water is another chain. Groundwater and injected cooling water contact contaminated structures; treatment removes many radionuclides, while tritium remains difficult to separate at this scale. Japan chose controlled discharge of treated, diluted water after regulatory review. The IAEA's 2023 comprehensive assessment concluded that the plan was consistent with relevant international safety standards and that the radiological impact, as planned, would be negligible. The IAEA also made clear that the discharge policy was a national decision, not its recommendation.

That finding should neither be dismissed nor inflated. It supports the safety case for the assessed discharge configuration, monitoring and controls. It does not prove that every tank batch automatically meets release criteria, that operational deviations cannot occur, or that fishers' economic and trust concerns are radiological errors. Batch measurement, independent sampling, discharge limits, shutdown interlocks, marine monitoring and transparent anomalies are the continuing proof.

Off-site repair includes decontamination, infrastructure, services, health support, compensation and decisions about return. Fukushima Prefecture reported a peak of about 160,000 evacuees in May 2012 and 23,410 recorded evacuees as of 1 February 2026. The decline demonstrates large-scale return or resettlement. The remaining number demonstrates that recovery is not complete. Registration methods, voluntary evacuees and changing categories also mean the figure is an administrative count, not a complete measure of everyone living with displacement effects.

Regulatory repair is visible in reactor review. Existing reactors do not resume operation merely because they operated before 2011; they must demonstrate conformity to the new requirements and complete review and inspection. The requirements include backfit, stronger natural-hazard treatment and measures to prevent core and containment damage if design assumptions are exceeded. This changes the formal control architecture from voluntary severe-accident preparation toward enforceable evidence.

Corporate repair is harder to prove. TEPCO created nuclear-safety oversight, reform reporting and external monitoring. It has published accident analyses, current plant data and unresolved questions. Those are positive control artefacts. Because they are produced within a company that remains operator, claimant counterparty and decommissioning executor, independent regulatory access and reproducible data remain essential. Transparency is strongest when outsiders can test a claim, not merely receive it.

A repair evidence register for nuclear accountability

External hazards: current probabilistic and deterministic hazard analyses; raw geological and historical inputs; uncertainty ranges; independent challenge; cliff-edge identification; interim measures; and tracked closure. A model result cannot disappear into a study queue without an accountable disposition.

Flood and common-cause protection: as-built elevations, watertight boundaries, penetration tests, drainage capacity, door and seal inspection, separated cable routes, protected switchgear and demonstrated survival of at least one complete cooling path under each inundation scenario.

Power and heat removal: load-tested fixed and portable generators, battery endurance, fuel logistics, black-start procedures, compatible connectors, cable routes, pump curves, water sources and proof under simultaneous multi-unit demand. Inventory lists are weaker than timed deployment tests.

Severe-accident observability: qualified water-level, pressure, temperature, hydrogen, radiation and containment instruments; independent power; known failure signatures; remote displays; protected communications; and decision rules when readings conflict.

Containment and venting: valve operability without normal power, protected air supplies, accessible manual alternatives, filtration performance, radiation conditions on access routes, release monitoring and drills that demonstrate completion before pressure margins expire.

Emergency organisation: one command doctrine across operator, regulator and government; authority thresholds; plant-to-government data formats; municipal contact; alternate centres; satellite and radio communications; shift depth; and exercises in which roads, phones and neighbouring units are unavailable.

Public protection: transport and receiving capacity for hospitals and care homes, resident registries, multilingual alerts, shelter support, route monitoring, dosimetry, iodine governance, pet and family arrangements, and continuity of medicine, records and local government. An evacuation order is an input, not proof of safe evacuation.

Health and social recovery: longitudinal participation, dose uncertainty, independent epidemiological review, mental-health and primary-care access, support for non-returners, privacy protection and communication that separates screening detection from radiation causation.

Compensation: category rules, claims received, offers, mediation outcomes, payment time, rejected grounds, reopening mechanisms and treatment of emerging loss. Aggregate yen totals do not show whether similarly situated people received consistent remedy.

Decommissioning: verified radioactive inventories, internal maps, sample data, tool reliability, worker dose, secondary waste, packaging, storage capacity, groundwater trends, discharge batches, incidents, schedule dependencies and funded end states. A milestone is evidence only when its acceptance criteria are public.

Regulatory independence: appointment safeguards, budget and staffing, inspector competence, meeting records, enforcement history, dissent handling, industry contacts and follow-up of international recommendations. Legal separation is necessary but must be tested through conduct.

Confirmed facts, supported inference and unresolved questions

Confirmed facts include the earthquake, automatic shutdown, loss of off-site power, tsunami inundation, loss of most emergency power and electrical distribution, core damage in Units 1 to 3, hydrogen explosions, radiological release, evacuation and long-term contamination. Investigations confirm that external-hazard, station-blackout, severe-accident, emergency-command and communication preparations were inadequate. Japan subsequently changed its regulatory structure and requirements. TEPCO remains responsible for compensation and decommissioning under the governing framework, and extensive payments and site work have occurred.

Regulatory and institutional findings are also confirmed as findings. The Diet commission found the accident preventable and the pre-accident relationship captured. The government committee identified preparation and response failures. The IAEA identified weaknesses in the assumption of safety and defence in depth. These findings can be compared and supported; they do not become findings about every individual's mental state.

Court dispositions are confirmed and narrower. The Supreme Court did not impose State Redress Act liability in the 2022 cases. Criminal acquittals of the surviving former executives became final in 2025. Those outcomes constrain claims about legal responsibility. They do not require erasing different administrative, political, corporate or ethical standards.

Supported inference includes the proposition that functionally separated and flood-protected power, distribution and cooling would have materially reduced the probability of three-unit core damage. Better severe-accident instrumentation and venting would likely have improved response. Clearer authority and plume-informed monitoring could have improved protective action. These are supported because they address observed failure modes, but the precise release and health counterfactual cannot be calculated.

Unresolved questions remain inside each damaged unit: exact timing and extent of core relocation, some containment leak paths, details of hydrogen transport, instrument behaviour and the distribution and properties of fuel debris. Long-term waste disposition and the final physical end state of the site are not settled. The future pace and cost of retrieval are uncertain.

Social unknowns are equally important. Administrative data do not capture every displaced person's preferred home, uncompensated loss, mental-health trajectory or reason for not returning. Epidemiology cannot identify a zero-risk individual, and screening cannot by itself attribute a tumour to radiation. Compensation totals cannot establish complete restorative justice.

Conclusion

Fukushima Daiichi was triggered by an extreme natural event and transformed into a severe nuclear accident by controllable dependencies. The earthquake shut the reactors down; the tsunami removed layers that were not sufficiently protected against common-cause flooding; weak observability and severe-accident preparation then narrowed the response. The accountability lesson is not that engineers must predict nature exactly. It is that uncertainty about an external hazard must increase protection of the functions whose loss can contaminate a region.

Investigations, courts and scientific bodies have answered different questions. Their conclusions remain coherent when kept within mandate: institutional prevention failed; particular State and criminal claims did not meet their legal tests; population radiological effects are expected to be low or non-discernible; evacuation and community harm were nevertheless profound; and present risk has been reduced without decommissioning being complete.

The event will be repaired only in stages. New regulation, independent review, compensation, monitoring, spent-fuel work, water controls and fuel-debris samples are evidence of movement. The remaining inventory, displaced residents, unresolved plant states and decades of hazardous work are evidence against premature closure. Durable nuclear-safety accountability is the capacity to show, before the next extreme event, who owns every assumption, which diverse safety function survives when it is wrong, how responders will know the plant's real state, and what independent evidence proves that those controls work together.