Physical Ai Safety
Domain purpose
Controls and requirements
D9-CTL-01Physical Harm Boundary Enforcement
Ensure AI systems cannot cause physical harm by operating outside defined safety boundaries, regardless of model output or adversarial manipulation.
D9-CTL-02Safe State And Graceful Degradation
Define and implement a minimum-risk condition for each AI-controlled physical system, reached automatically when AI confidence falls below threshold, anomaly is detected, or human override is activated.
D9-CTL-03Human Override And Emergency Stop
Ensure humans can always override AI control of physical systems unconditionally — including under adversarial conditions where the AI system may be attempting to prevent override.
D9-CTL-04Cyber-Physical Attack Detection
Detect adversarial attacks targeting the cyber-physical interface — sensor spoofing, actuator hijacking, command injection, and AI inference manipulation — before they cause physical harm.
D9-CTL-05Physical Environment Integrity Monitoring
Continuously verify the integrity and reliability of physical environment sensor data on which AI decisions are based, preventing AI actions grounded in corrupted, degraded, or spoofed environmental inputs.
D9-CTL-06Actuator Command Verification
Verify every actuator command against physical safety constraints, operational bounds, and system state before execution — preventing AI model errors, adversarial manipulations, or software defects from translating directly into unsafe physical actions.
D9-CTL-07Physical Incident Evidence Preservation
Preserve comprehensive, tamper-evident, time-stamped evidence of AI system state, sensor inputs, model outputs, actuator commands, and human interactions immediately before, during, and after any physical AI incident.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.