PAI-SF / 5 / PAI-SF-SAF-003

Safe-State Trigger Independence Under Compute Compromise

Objective

Ensure the safe-state trigger remains functional even if the AI compute/inference stack is adversarially compromised, not merely faulty.

Control / requirement

Safe-state activation path tested specifically under simulated adversarial compute compromise, verifying the trigger fires independent of an actively hostile primary system.

Applicability

Systems where compute compromise (not just random failure) is a credible threat per the Section 5 threat catalog.

Expected evidence

Adversarial fault-injection test records distinguishing compromise scenarios from random-failure scenarios. [T3/T4]

Assurance expectation

Test evidence specifically covering the adversarial case — evidence of resilience to random failure alone is insufficient for this control.

Dependencies

PAI-SF-ATT-001 (Domain 3, attestation) — a compromised system that fails attestation should itself be a trigger condition.

Exclusions

Not applicable to air-gapped systems with no plausible compute-compromise threat model.

Maturity / conformance relevance

Expected at High-Assurance level; Foundational/Operational may address only random- fault independence.

Ecosystem relationship

This is a security concern layered onto a safety mechanism — the clearest example in the register of PAI-SF™'s stated boundary between AI security and functional safety. Relevant to AI-IRF™ investigation of compromise-related incidents.

Domain

Domain 5. Safe-State and Degraded-Mode Behavior

Download full Control Catalogue ↓