Safe-State Definition for Credible Failure Modes
Objective
Ensure the system has a defined safe state for each credible failure mode, triggerable independently of the primary AI system.
Control / requirement
Credible failure modes identified through hazard analysis; appropriate safe state defined per mode (halt, reduced capability, minimal-risk maneuver, human handover); at least one independent trigger path implemented.
Applicability
All physical AI systems.
Expected evidence
Hazard analysis identifying failure modes and safe states; safe-state architecture documentation; transition test records; physical-achievability validation (e.g., stopping-distance analysis). [T2/T3]
Assurance expectation
Comprehensive hazard analysis plus validated transitions; higher-consequence systems expect fault- injection testing.
Dependencies
PAI-SF-ACT-001 (kinematic limits for enforcement); PAI-SF-HOV-001 (human override as an ultimate trigger).
Exclusions
None — all physical AI systems require safe-state definition; complexity scales with risk.
Maturity / conformance relevance
Expected at all conformance levels; sophistication scales with consequence severity.
Ecosystem relationship
Extends GAISSF™ availability/resilience controls. Provides safe-state-failure categories for UAIF™. Safe- state activation is a primary AI-IRF™ response action; this control specifies the physical requirements.