Verified Fallback Control Law for Degraded Mode
Objective
Ensure degraded-mode operation substitutes a simple, independently verifiable control law rather than continuing to run the full learned policy at reduced parameters.
Control / requirement
Degraded mode substitutes a non-learned, formally simpler control function (e.g., a bounded deterministic motion profile) for the learned policy, rather than merely throttling the same model's outputs.
Applicability
Systems where immediate full stop is not the safest response and some continued controlled operation is required in degraded mode.
Expected evidence
Fallback control law specification and independent verification; test records comparing learned-policy- throttled vs. verified-fallback behavior. [T3]
Assurance expectation
Verification evidence for the fallback control law itself (ideally formal verification for higher-consequence systems), not just behavioral test results.
Dependencies
PAI-SF-DEG-001 (degraded-mode definition, entry/exit criteria).
Exclusions
Not applicable to systems where degraded mode is defined as immediate full stop with no continued operation.
Maturity / conformance relevance
Expected at High-Assurance level; Operational level may accept throttled-learned-policy degraded mode as an interim approach.
Ecosystem relationship
Addresses a question with no analog in non-AI functional safety (what replaces the AI during degradation) — another concrete instance of the framework's core justification.