"The feed-water pneumatic control valve is running — if the air supply suddenly fails, where does the valve end up?" A simple-looking question that drew sixty-plus replies in the power plant community, because the answer bears directly on unit safety during upsets: valve behavior at the moment of power/air loss is the heart of the Fail-Safe principle in I&C design.
- Electric valve (electric actuator) loses power: the valve holds its position. No power, no motor rotation; the worm and gearing self-lock and the valve stays exactly where it was;
- Pneumatic valve loses air: three possibilities, depending on the actuator's air-connection type — it may close, open, or hold position.
The lost-air position is determined by the cylinder design, in three classes:
| Type | Structure | Action on air loss | Typical use |
|---|---|---|---|
| Air-to-open (FC, fail-close) | Spring opposes air; **opens only with air** | Spring drives the plug **closed** | General control loops |
| Air-to-close (FO, fail-open) | **Closes only with air**; spring pushes open | Spring drives the plug **open** | Drains, vents — open-is-safe duties |
| Double-acting with positioner locking | No spring; held by **lock-up valves/accumulators** | **Holds position** | Large dampers/valves, critical control valves |
One-line memory: "on air loss, the valve must reach the safest position for the unit" — air-to-open, air-to-close, or lock-up is chosen by reasoning backwards from that safe position. The classic example from the discussions: drain valves use air-to-close — when the air supply fails, drains open to prevent water accumulation in heaters and piping; the fail position of a feed-water control valve is designed around "which state is safer for the boiler once feed control is lost."
A double-acting cylinder needs air in both chambers to move; with air lost the piston is in balance and could theoretically drift anywhere — in practice, triple-loss protection locks it: on loss of air, loss of power, or loss of signal, lock-up (check) valves cut both chamber lines and the valve freezes in place. One plant described its standard explicitly: "all our pneumatic actuators carry triple-loss protection." Without lock-up, a double-acting valve can drift slowly under media pressure and stem weight — "the plug drifted slowly closed after air loss" is exactly this case — so critical control valves must have lock-up, never run bare.
An electric actuator holds position when de-energized — both a virtue and a hazard:
- Virtue: the position does not jump, buying operators time to respond;
- Hazard: it will not move toward a safe position. For critical valves that MUST move on power loss (fast-closing shutoff valves, for instance), the loop must be designed as normally-energized/trips-de-energized, or a spring-return pneumatic/hydraulic actuator must be used instead. The perennial debate "should electric valves have a UPS" is, at its core, a judgment on whether "hold on power loss" is acceptable;
- Note also: for electric modulating valves, loss of signal (4–20 mA) may behave differently from loss of power — many intelligent actuators allow configuring signal-loss behavior to hold, full-open, or full-close; confirm each unit against the design documents during commissioning.
1. On loss of air / power / signal, which position is safest for the unit — open, closed, or as-is?
2. Working backwards from that position: air-to-open, air-to-close, or double-acting with triple-loss protection?
3. For electric actuators, is "hold on power loss" acceptable? If not, can the circuit be designed to act on de-energization, or should a spring-return actuator be used?
"Where does the valve go on air/power loss" is not trivia — it is the language of fail-safe design: air-to-open, air-to-close, or lock-up, and a wrong choice only shows itself during an upset. When field behavior after air loss does not match expectations, first check the actuator's air-connection type against the design documents' fail position, then the lock-up valves and spring cylinder — most "wrong fail positions" are lock-up configurations that do not match the design intent.


