Safe-State & Degraded-Mode Behavior
Predictable transition to bounded or safe operation when confidence or capability falls.
Domain controls
The following identifiers, titles, objectives and implementation expectations reproduce the canonical public PAI-SF™ v1.0 Control Catalogue. Evidence requirements, assurance expectations, dependencies, exclusions and conformance relevance remain available in the full catalogue.
Objective: Ensure the system has a defined safe state for each credible failure mode, triggerable independently of the primary AI system. Requirement: Credible failure modes identified through hazard analysis; appropriate safe state defined per mode (halt, reduced capability, minimal-risk maneuver, human handover); at least one independent trigger path implemented.
Objective: Ensure safe-state logic accounts for gradual AI model drift, not only discrete hardware/software faults. Requirement: Monitoring for gradual divergence between expected and observed model behavior; defined safe-state or degraded-mode response to sustained drift, distinct from discrete-fault triggers.
Objective: Ensure the safe-state trigger remains functional even if the AI compute/inference stack is adversarially compromised, not merely faulty. Requirement: Safe-state activation path tested specifically under simulated adversarial compute compromise, verifying the trigger fires independent of an actively hostile primary system.
Objective: Ensure degraded-mode operation substitutes a simple, independently verifiable control law rather than continuing to run the full learned policy at reduced parameters. Requirement: Degraded mode substitutes a non-learned, formally simpler control function (e.g., a bounded deterministic motion profile) for the learned policy, rather than merely throttling the same model's outputs.
Objective: Ensure the system can operate in a defined degraded mode with reduced physical capability and risk when full capability is not assured. Requirement: At least one degraded mode defined that reduces physical risk (lower speed/force/reach/autonomy), is independently enforceable, has defined entry/exit conditions, and does not rely on the compromised component for its own safe operation.