PAI-SF™
Physical AI Security Framework
A practitioner-first assurance framework for AI-enabled systems that can affect physical state, movement, access, infrastructure, operating environments or human proximity.
Purpose and scope
PAI-SF™ addresses the assurance chain between digital model behaviour and physical effect: perception → model decision → autonomy boundary → kinetic command → physical effect → monitoring → intervention → recovery.
It applies to robotics, autonomous vehicles, drones and uncrewed systems, industrial automation, medical robotics, smart infrastructure, logistics, embodied agents and other AI-enabled systems that interact with the physical world.
Domains and controls
Sensor & Perception Integrity
Trustworthiness of sensed inputs, perception pipelines and uncertainty handling.
D2Actuator & Kinetic Command Safety
Authorization, validation and constraint of commands that produce physical action.
D3Edge Hardware & Model Attestation
Integrity and provenance of edge compute, firmware, models and trusted execution.
D4Autonomy Boundaries
Explicit limits on delegated authority, mission scope and permissible action.
D5Safe-State & Degraded-Mode Behavior
Predictable transition to bounded or safe operation when confidence or capability falls.
D6Human Override & Intervention
Timely, usable and authoritative human intervention across operating conditions.
D7Runtime Monitoring & Telemetry
Operational visibility into state, decisions, commands, anomalies and interventions.
D8Incident Response & Physical Recovery
Containment, restoration, investigation and learning after physical-AI events.
D9Supply Chain & Update Assurance
Integrity of components, dependencies, maintenance paths and deployed updates.
D10Simulation, Testing & Validation
Evidence across simulation, scenario testing, field validation and operating limits.
D11Functional Safety Interface
Defined handoffs and boundaries between AI security controls and safety mechanisms.
D12Physical Operating Environment
Environmental, spatial, human-proximity and site-specific operating constraints.
Publication library
Start with the framework standard and control catalogue. Use the sector, readiness and reference publications for the relevant operational context.
Core framework
Physical AI Security Framework Standard
The primary public framework standard for PAI-SF™ v1.0.
Download standard →PAI-SF Control Catalogue
The 41-control public catalogue organized across 12 domains.
Download catalogue →Technical + Compliance Report
Technical foundation, assurance model, limitations and standards context.
Download report →PAI-SF Executive Brief
Decision-level explanation of the framework, its purpose and adoption boundary.
Download brief →Start and reference
Overview and quick start
Reference set
Crosswalks
JSON Schema Package
Machine-readable public record structures. No scoring thresholds or certification decisions are encoded.
Download schema package →Sector guidance
Robotics & Industrial Automation
Download guide →Autonomous Vehicles
Download guide →Drones & Uncrewed Systems
Download guide →Medical Robotics
Download guide →Smart Infrastructure & Physical AI
Download guide →Assessment readiness
Scope and evidence
Readiness and operator reference
Using this publication
- Start with the framework standard for scope, definitions and normative structure.
- Use the control catalogue to identify domain-level requirements and evidence expectations.
- Select sector guidance only where its operating context applies.
- Treat public readiness materials as preparation aids, not assessment outcomes.
Publication boundaries
- No certification, conformity, safety approval, regulatory recognition or guaranteed effectiveness is implied.
- No pass/fail threshold, weighting model, maturity trigger, assessor-calibration procedure or certification-decision rule is published here.
- PAI-SF™ does not replace functional-safety, aviation, medical-device, road, machinery, infrastructure, workplace-safety or other applicable obligations.