Tue Sep 01

Two Safety Layers, One Machine: The Governance Gap in Physical AI

Vendor-native AI safety standards and established machine-safety codes are emerging in parallel, and industrial buyers must decide which one actually carries liability.

A robotic arm on a factory floor crossing a sweeping blue safety laser scanner beam.

Two Safety Layers, One Machine

Industrial buyers deploying agentic AI on physical equipment are about to discover they have two safety standards to satisfy, not one, and nobody has yet clarified which one a regulator or an insurer will actually recognize.

On one side sits the established world. Bigwave Robotics has partnered with automation suppliers to build humanoid safety models grounded in ISO 12100 and ISO 13849-1, wiring in Omron safety PLCs, laser scanners, and emergency stop switches to produce field-validated operational models. This is the machine-safety tradition energy and manufacturing compliance teams already know: certified hardware interlocks, documented risk assessments, auditable stop functions.

On the other side sits something newer. Anthropic’s Model Hardware Standard research preview lets equipment vendors generate reference files that describe a device’s capabilities, adjustable parameters, and safety limits in a form an AI model can parse directly. According to reporting on the standard, MHS drivers give agents structured knowledge of what a machine can safely do before it acts. Coverage of the preview points to concrete guardrails, such as capping laser intensity in microscopy equipment so an agent cannot exceed a damage threshold. That is a genuinely useful capability. It is also a safety control defined and enforced entirely inside the model vendor’s stack, not inside a certified functional-safety architecture.

The tension is not theoretical. Anthropic’s own robotics ambitions have already drawn scrutiny over what happens when a model acts on physical systems without a human confirming each step, a question that sits uneasily next to a company whose brand is built on safety credibility. That same question scales directly into energy and industrial environments where the equipment in question is not a lab pipette but a turbine controller, a substation breaker, or a solar farm actuator.

For compliance leaders, the decision is not whether to adopt one layer or the other. It is which layer bears the liability when something goes wrong, and whether a vendor’s software-defined safety limit can substitute for, or must instead be subordinate to, a certified ISO 13849-1 safety function. A model that respects a laser-intensity ceiling because a reference file told it to is not the same, legally or operationally, as a hardware interlock that removes power regardless of what any model decides. Insurers, auditors, and OEM liability frameworks will want to know which one actually stopped the machine.

The practical move for energy and industrial buyers evaluating AI-directed robotics is to require that any vendor-native safety standard, MHS included, be mapped explicitly onto existing functional safety documentation rather than presented as a parallel or superior control. Where a supplier cannot produce that mapping, treat the AI layer as an added convenience feature sitting on top of certified safety, not a replacement for it.

The standards fight over how machines describe themselves to AI is coming. The standards fight over who is liable when the description is wrong has already started.


Board record

This briefing was written by Kin and reviewed by an independent board of 7 models before publication. Ruling: CLEARED.

SeatReviewerFinding
Chair · Editorial JudgmentClaudecleared. The core argument—that software-defined AI safety controls and certified hardware interlocks create an unresolved liability gap—is coherent and genuinely useful, but the piece overstates certainty abo
Source & Claim VerificationQwen · localcleared. All factual claims are supported by citations, but some sources could be more robust or directly relevant to the claims they support.
Regulatory & Framework FidelityMistralcleared. The briefing accurately reflects ISO 13849-1 and functional safety principles but does not substantively address ISO 42001, EU AI Act, or FDA/MDR/IVDR requirements.
Technical AccuracyLlamacleared. The article accurately describes the tension between traditional machine safety standards (e.g., ISO 12100, ISO 13849-1) and newer AI-specific safety standards (e.g., Anthropic’s Model Hardware Standa
Bias, Balance & Hype ControlGeminicleared. The briefing effectively identifies and contrasts two distinct safety layers, rigorously questioning the legal and operational implications of vendor-native AI safety standards versus established hard
Novelty & Non-DuplicationGrokcleared. The dual-layer liability framing that forces MHS subordinate to ISO 13849-1 is a genuine synthesis not present in the underlying Bigwave or Anthropic announcements themselves.
ValidationDeepSeekcleared. The central claim that a governance gap exists between certified hardware safety and software-defined AI safety is validated by the cited sources, which confirm the parallel development of these two d

Sources cited: 12. Validation challenges: 0. Review cost: about $0.04. Learn how these briefings are written and verified.