PAI-SF™ / DOMAIN 5

Safe-State & Degraded-Mode Behavior

Predictable transition to bounded or safe operation when confidence or capability falls.

D5domain identifier
5canonical controls
v1.0Final Publication

Domain controls

The following identifiers, titles, objectives and implementation expectations reproduce the canonical public PAI-SF™ v1.0 Control Catalogue. Evidence requirements, assurance expectations, dependencies, exclusions and conformance relevance remain available in the full catalogue.

PAI-SF-SAF-001
Safe-State Definition for Credible Failure Modes

Objective: Ensure the system has a defined safe state for each credible failure mode, triggerable independently of the primary AI system. Requirement: Credible failure modes identified through hazard analysis; appropriate safe state defined per mode (halt, reduced capability, minimal-risk maneuver, human handover); at least one independent trigger path implemented.

PAI-SF-SAF-002
Model-Drift-Triggered Safe-State

Objective: Ensure safe-state logic accounts for gradual AI model drift, not only discrete hardware/software faults. Requirement: Monitoring for gradual divergence between expected and observed model behavior; defined safe-state or degraded-mode response to sustained drift, distinct from discrete-fault triggers.

PAI-SF-SAF-003
Safe-State Trigger Independence Under Compute Compromise

Objective: Ensure the safe-state trigger remains functional even if the AI compute/inference stack is adversarially compromised, not merely faulty. Requirement: Safe-state activation path tested specifically under simulated adversarial compute compromise, verifying the trigger fires independent of an actively hostile primary system.

PAI-SF-SAF-004
Verified Fallback Control Law for Degraded Mode

Objective: Ensure degraded-mode operation substitutes a simple, independently verifiable control law rather than continuing to run the full learned policy at reduced parameters. Requirement: Degraded mode substitutes a non-learned, formally simpler control function (e.g., a bounded deterministic motion profile) for the learned policy, rather than merely throttling the same model's outputs.

PAI-SF-DEG-001
Degraded Operating Mode Definition

Objective: Ensure the system can operate in a defined degraded mode with reduced physical capability and risk when full capability is not assured. Requirement: At least one degraded mode defined that reduces physical risk (lower speed/force/reach/autonomy), is independently enforceable, has defined entry/exit conditions, and does not rely on the compromised component for its own safe operation.

Download full Control Catalogue ↓