I love this comment and I think it's right on the money to say that we ought to engineer things in the best possible way we can.
I have a couple of thoughts...
There is a sort of dialectic that unfolds with regards to what fail-safes should be engineered and how to engineer them. It perhaps might be possible in some cases to compute a priori what fail-safe mechanisms a system needs to include, but for the most part it seems that a catastrophe (or a string of them) first unfolds which then gives you the necessary information as to what the requirements are for the fail-safe. I think this is a very important point worth stressing. As it relates to this incident, I'll grant you they probably could have done better from the outset, but I stand by the comment that sometimes it's not possible to compute ahead of time what fail-safes you need and experiencing these kind of PR disasters is just part of the journey towards a system that works better. Call it dialectical engineering if you will. If there is another, better, actual name that concept goes by I'd like to know if anyone can tell me.
The other comment would be that I like to think about things from a control-theoretic and systems thinking point of a view and that this particular statement of "It's extremely hard to engineer a situation in which no one ever experiences a negative outcome" is a real core, axiomatic belief for me that I base a lot of my thinking and critiques of things around. I like what you have to say about engineering. It's very apt. I always couch my thoughts / analyses in the broadest possible context. So in the case of the regulator for scuba diving my mind flashes back to the terrifying stories I have read about people who let their concentration lapse at a critical juncture in a cave and panicked when they realised they couldn't find their way back and in that case it didn't matter that their regulator worked or not because it was their mind that had failed them. You mention training as being a crucial input to the system and I absolutely agree. I go so far as to include the cave itself as a constraint in the whole system design as well as all the pitfalls of the human mind. So it's not just the device but the entire context in which the device operates that's the important thing.
Human engineered machines gracefully fail; humans do not. We have this deep need to play the blame game when things go wrong. We all do it and we all understand it, but it's not always justified and I think that matters. I like to try and get to the bottom of whether the moral outrage suffered by people is justified in situations where they were harmed but it wasn't necessarily the fault of someone. Well, it might be the fault of someone, but that also might just be a necessary part of the process a la my concept of dialectical engineering. It's a complicated topic.
Of course you will be outraged or upset if your dog dies while in the care of somebody else and you aren't likely to sit and get all philosophical about it, but when you play the blame game you search for the most salient (to you) cause or potential cause of your effect and you attribute it to that. I think it's often stunningly likely you're making an error in judgement when you do this, because of the hard problem of delineation you can't necessarily compute what the actual cause is with any degree of accuracy so epistemology comes in to play. How do you know that what you're mad at is the appropriate thing to be mad at?