Endstop

Rev 0.3.4 · in integration

Standards posture and certification path

Our certification route, the evidence for it, and the next decisions

IEC 61508-3 supports separating an untrusted planner from a fixed safety monitor. Its Table A.2 marks artificial intelligence fault correction not recommended at every integrity level above SIL 1, and recommends a monitor running on hardware separate from the machine it watches.15 In Endstop, the monitor/output path is the proposed safety function; the separate bounded interpreter contains model-authored computation before it can request an effect. Under the Machinery Regulation it is a safety component, not yet placed on the market as one: no certificate, not for sale.

§1

What IEC 61508-3 already decided

Table A.2 rates architecture and design features by integrity level. R is recommended, HR highly recommended, NR not recommended. Five entries land on decisions already made here. Ratings are at SIL 2, our target.15

Our decisionTable A.2 entryAt SIL 2
The monitor runs on its own hardware, not on the machine it watches3c, diverse monitor techniques with separation between the monitor computer and the monitored computerR
The model is outside the safety function and cannot be inside it5, artificial intelligence — fault correctionNR
Target: dual-budget execution with an independently enforced maximum cycle time13a, cyclic behaviour with guaranteed maximum cycle timeHR
No heap. Every region fixed at build time14, static resource allocationR
A machine-checked interpreter core8, use of trusted or verified software elementsHR

Entry 5 decides the argument. Putting a language model inside the safety function requires a technique the standard marks not recommended at every level above SIL 1. Move the model out and entry 3c is what remains.

Table A.2 selects techniques and awards no level. An assessor reads the lifecycle, competence and configuration-management record long before any architecture table.

§2

The claim ledger

  • Align with

    IEC 61800-5-2 function vocabulary · ISO 13849-1 categories and diagnostic coverage · ISO 13855 latency accounting · ISO 10218-2:2025 cybersecurity provisions

  • Target, not yet met

    Suitable for use within a defined PL d / SIL 2 safety function, subject to the system architecture, diagnostics, application validation and assessment. §4 has the preliminary arithmetic.

  • Current software evidence

    Machine-checked memory isolation and absence of undefined behaviour in the interpreter core. Step-fuel-bounded termination and pre-execution timing-credit accounting; the target-specific cost table remains provisional and operational timing admission is disabled. An enumerable program-facing effect vocabulary. A bounded capability journal with an Ed25519 seal when the program requests one, demonstrated in emulation with a published verifying key. Trusted-side per-verdict recording, durable chaining and periodic sealing are not implemented.

  • Not yet claimed

    Endstop is not yet certified and does not currently carry a performance level, SIL or CE mark. Software and RTL tests exercise the configured envelope in disclosed cases; deciding whether that envelope is appropriate for a specific application remains part of the integrator’s application-level risk assessment.

How to position us in your safety case

What is specified today, without anyone’s signature. The target architecture gives a separate monitored stopping path authority to remove drive power without asking the interpreter to cooperate. The gate regenerates the drive-facing command and can therefore produce motion. Neither path has yet been integrated or rated on pilot hardware.

What a certificate would add is the other failure direction: a quantified probability that the gate, powered and running, permits a motion it should have refused. That number needs DCavg and a safe failure fraction demonstrated on assembled hardware, and we do not have it. Until then, Endstop should supplement rather than replace a safety PLC, a safety-rated drive function or an emergency stop.

On a platform with no rated envelope, an integrated Endstop could become the only command bound present. Where one already exists, the intended additional value is adversarial execution containment and a gate-observed evidence record. Whether an existing supervisor already authenticates commands or records refusals must be checked for that installation.

§3

What the design takes from the standards

The envelope checks carry IEC 61800-5-2’s names for safe-motion functions, because certified drives already implement them: safe torque off is the state we degrade to, safe stop 1 the ramped abort, safely-limited speed and position the per-axis, Cartesian and keep-out ceilings, safe direction the per-mode constraint.

The names are wider than what we may assert against them, and the difference is measurement. A rated safely-limited speed or position function watches an encoder, and the reference Category 3 architecture takes two of them into a safety PLC. The pilot takes none wired to the gate. The command monitor's only input is the proposed joint command, so what it enforces is a ceiling on what can be commanded, which is a weaker thing than a supervised limit on what the machine does. Two of the other names narrow for the same reason. Safe operating stop is the drive holding position under full torque, which is the hold-last state we treat as unsafe, so it is ruled out by our own policy. Safe stop 1 is available in its time-based form only, because we command a deceleration and do not verify one. The relay in series with drive power demonstrates what safe torque off is for, and a rated STO would need an architecture, diagnostics and a PL or SIL calculation that we do not claim. So the honest reading of every name in the paragraph above is that we enforce it on the command channel, which is the half of the function that sits between a model and a machine.

Closing that gap needs an independent measurement of the machine's state — an encoder tap, a potentiometer or a current sense, wired to the gate and not through the host. We now have an implemented feedback supervisor, exercised against the open-source arm simulation, that checks direct snapshots for freshness, measured position/rate and following error, separately from the command monitor. Freshness derives from the capture block’s monotonic sample sequence, not a host-provided flag. It does not run a second forward-kinematics pass. The PC-assisted arm rig reads the SO-101's own encoders, but through the trusted PC rather than a direct tap, so it does not close this gap. The physical capture hardware, timing bound and end-to-end verification remain open. Until they exist, what we can say is what a supervisor vendor already says: the untrusted program could not command outside the envelope. Whether the arm then went there is a question this gate does not answer.

Monitoring is multi-point. ISO/TS 15066 states in a normative note that a speed limit watching only the tool centre point “does not monitor other parts of the robot that might pose hazards to the operator”, and that joint speed monitoring may also be needed.2 ABB supervises tool centre point, elbow and wrist together; Universal Robots extended pose limits to the elbow.

Configuration is checksummed and signed, and the value exposed so a controller can interlock against it. FANUC gates changes behind a code number and a CRC signature; ABB moves a configuration through validated and locked states. A monitor is only as trustworthy as the parameters it enforces.

Enforcement acts on predicted stopping position, following FANUC’s Dual Check Safety and the generational change at Universal Robots from “exceeding a limit causes a stop” to “limits will not be exceeded”. The architecture page has why that distinction matters.3

None of this replaces offline validation. In ISO 10218-1:2011 verification and validation take an entire top-level clause, clause 6.3 is titled “Required verification and validation”, and stopping-time measurement has a normative annex of its own.1 The monitor enforces a conclusion reached offline; no certified vendor’s monitor reaches it either.

§4

The integrity target: PL d / SIL 2, on one channel

PL d and SIL 2 are one target. ISO 13849-1:2023 Table 4 pairs them exactly and puts PL e with SIL 3.16 PL d is also what ISO 10218-1:2025 gives as the default for a protective stop.9

PL d does not require a second channel. Figure 12 of ISO 13849-1:2023 puts it within reach of Category 2 at medium diagnostic coverage with a high MTTFD, and of Category 3; Category 4 is what PL e requires.16 IEC 61508-2 Table 3 draws the same boundary: a Type B element at zero hardware fault tolerance reaches SIL 2 once its safe failure fraction passes 90%, and reads Not Allowed below 60%.10

So one enforcement core is admissible on both scales. What it costs is diagnostics: DCavg at medium and a safe failure fraction above 90%, demonstrated on the built hardware. That is work we would rather do than carry a second board.

Both ISO 10218-1:2025 figures here are second-hand: the protective-stop default, and a reported route with no architectural category requirement below 4.43 × 10-7 per hour. We do not hold that standard.

§5

Three regimes, and the category we fall in

A device of this description falls under three separate bodies of European law, each with its own assessor and commencement date. Confusing them is how budgets get set wrong.

RegimeWhat it grantsApplies from
Machinery Regulation (EU) 2023/1230the legal right to place a safety component on the EU market, and the CE mark20 January 20274
IEC 61508 / ISO 13849the integrity figure that lets an integrator include us in their own safety calculationwhenever the first serious customer asks
Cyber Resilience Act (EU) 2024/2847the legal right to sell a product with digital elements11 December 20275

The AI Act used to be a fourth. During 2026 the Digital Omnibus moved the Machinery Regulation from Annex I Section A to Section B of that Act, removing the direct application of its Chapter III obligations to machinery and folding AI-specific health and safety requirements into the Machinery Regulation by delegated act, due 2 August 2028.6

We expect Annex I Part B, as a logic unit to ensure safety functions, which is a named Part B category.4 Part A carries mandatory third-party assessment with no self-declaration route at all, and two of its items could reach us: safety components, and machinery with embedded systems, having self-evolving behaviour using machine learning approaches ensuring safety functions.

The frozen-model defence is available, and we decline it. At least one notified body reads “self-evolving” by capability rather than by timing.7 Our position is that no machine learning sits inside the safety function at all. The monitor is fixed, hand-written and machine-checked; the model is upstream of it and generates the programs it constrains. Both Part A items qualify the component by the phrase ensuring safety functions, and where the learned component does not ensure it, the item does not attach.

Declining that defence is the point. An exclusion argument that survives only under a favourable reading of “self-evolving” has to be re-argued every time the reading moves. Ours assumes the worst available one: that the model is self-evolving, that it will be retrained, and that an attacker controls its inputs and therefore its outputs. It is unaffected, because it never turns on what the model does. It turns on what the model can reach, which is three capabilities with the index fixed before execution starts and a 512-byte region with every access bounds-checked.

The whole argument is written out as a standalone document rather than left as prose here. It quotes the Annex I items, names the safety function in one sentence, states four separately checkable claims about what the learned component cannot do, and ends with the four findings that would change our view. It is drafted and not yet signed: the verbatim Annex I text and a counsel reading stand between it and issue. We will publish it when it is issued, because a classification argument nobody can read is worth about as much as an uncorrected claim.

Two conformity questions

The integrated machine. If a model in the control loop had to be assessed as part of the safety function, Part A would put the whole machine into mandatory third-party assessment. Keeping the model out of the safety function is what keeps it off that list. This is our current reading, not a notified body’s conclusion, and it should be confirmed by the project’s assessor.

Endstop itself. Endstop is a Part B logic unit, and we expect to need a notified body anyway, because §5’s note explains why Module A is closed to us. So the argument does not save us an assessment. What it does for us is narrower and more important: it decides whether an assessor is being asked to evaluate a language model, for which no method exists, or 539 lines of fixed machine-checked code.

Why we budget for a notified body

Part B permits internal production control only where harmonised standards cover all the essential health and safety requirements for the category; partial coverage forces type examination, full quality assurance or unit verification.8 Nothing currently cited in the Official Journal covers a device that executes programs supplied after validation.

The Cyber Resilience Act is the one regime where that answer could still go the other way, and we have not settled it. There, self-assessment is the default. Class I under Annex III may use harmonised standards or a third party, and industrial automation and control systems not otherwise listed are named in it, with PLCs, DCS, CNC and SCADA as the examples. Class II requires a notified body, and it names tamper-resistant microcontrollers and microprocessors.5 We hold a signing key, produce a signed audit trail and describe the device in terms of tamper-evidence, which invites the Class II reading. Where we land is a legal question we have not yet put to counsel, and it decides whether that regime needs a notified body at all. It is on this page because it is open, not because it is answered.

§6

Three assessment stages, in this order

#Assessment stageWhat it establishesWhen it bites
1Independent functional-safety architecture review, including selection of the IEC 61508 / ISO 13849 assessment and certificate scopea written route, gap analysis and agreed definition of the safety functionbefore the product hardware architecture is frozen
2CE mark under Machinery Regulation (EU) 2023/1230, by type examination or full quality assurancethe legal right to place a safety component on the EU marketonce a design partner ships
3Cyber Resilience Act conformity assessment, scoped alongside certificate 2the legal right to sell a product with digital elements at all11 Dec 2027

The first stage comes before selecting a certificate label. PL and SIL apply to defined safety functions and their supporting systems, not to 539 lines of software in isolation. The review must settle the safety function, channel architecture, diagnostics, hardware platform, toolchain argument and application assumptions before an assessor can agree the appropriate certification scope.

The path to certificate 1

ConditionStatus
Safety function and integrity target agreed with an assessornext — current product objective is suitability for use within a PL d / SIL 2 safety function
Annex I classification argument issued as a signed documentdrafted 7 August 2026 — pending verbatim Annex I text and counsel review, then issued and published
Cyber Resilience Act class settlednext, and it is the one place a self-assessment survives — §5
Certifiable platform chosennext decision
Written quotes from two or three bodiesfollows the platform choice

The bring-up board is a Lattice ECP5 with an open synthesis and place-and-route flow and an open RISC-V soft core, chosen so every layer can be inspected. IEC 61508-3 requires every tool contributing to executable output to be justified, so the certified product moves to a platform with a functional-safety package. Microchip’s Libero suite was certified by TÜV Rheinland in September 2024 for the PolarFire families with data packages supporting SIL 3,12 and lockstep safety microcontrollers carry the equivalent. Choosing belongs before the board spend.

Cost: the number goes here when an assessor signs one

No certification body publishes fees. Not TÜV SÜD, TÜV Rheinland, UL Solutions, exida or Intertek. Every figure circulating in this industry is folklore, and folklore here would be worth less than the space it filled. A quote for a product whose Annex I category is unargued, on a platform nobody has chosen, prices a guess.

The binding constraint is elapsed time, not the fee. Veo Robotics took a novel safety function to TÜV Rheinland for ISO 13849 PL d Category 3 in 2021;13 FORT Robotics had a controller assessed to IEC 61508 SIL 3 by exida in 2023.14 Hence the order above: cheapest credential first, on the smallest unit anyone can assess.

References

  1. ISO 10218-1:2011, clause 6 and clause 6.3, with normative annexes on stopping-time measurement. Clause titles from the publisher’s front matter; clause-level text not held.
  2. ISO/TS 15066:2016, clause 5.5.4.2.3 note, with a companion note at 5.5.5.4. Full text held.
  3. Hsu, Hu & Fisac, The Safety Filter: A Unified View of Safety-Critical Control in Autonomous Systems, Annual Review of Control, Robotics, and Autonomous Systems, 2024. arXiv:2309.05837
  4. Regulation (EU) 2023/1230, Annex I Parts A and B, and Article 25. Applies from 20 January 2027. Text read at EUR-Lex; the Annex I category lists via published notified-body summaries.
  5. Regulation (EU) 2024/2847, the Cyber Resilience Act. In force 10 December 2024; most provisions apply from 11 December 2027. Text read at EUR-Lex.
  6. The Digital Omnibus on AI, agreed and given final Council approval during 2026, moves Regulation (EU) 2023/1230 from Annex I Section A to Section B of the AI Act and requires AI-specific health and safety requirements in the Machinery Regulation by 2 August 2028. Read through Freshfields’ and Gibson Dunn’s published analyses of the final text.
  7. Intertek, Decoding “Self-Evolving Behaviour” in the EU Machinery Regulation, September 2025: the Regulation gives no technical definition, so a model trained before deployment but able to adapt is, on that reading, still in scope.
  8. Machinery Regulation Article 25(3): internal production control is available for Annex I Part B only where harmonised standards cover all relevant essential health and safety requirements. Text read at EUR-Lex.
  9. ISO 10218-1:2025 and ISO 10218-2:2025, published February 2025. The default performance level table reaches us through secondary analysis. Clause-level text not held.
  10. IEC 61508-2:2010, Table 3, architectural constraints on Type B subsystems, read with 7.4.4.2.1 and 7.4.4.2.2. Route 1H is the route it belongs to, and ISO 13849-1:2023, 6.1.2 requires that route of any subsystem brought in under the IEC 61508 series. Standard text held and read.
  11. SAFERTOS, pre-certified to IEC 61508 SIL 3 by TÜV SÜD since 2007, supplied with a design assurance pack per processor and compiler combination. Cited as the shape of an element certificate, not as a component we use.
  12. Microchip Libero SoC Design Suite, certified by TÜV Rheinland in September 2024 for the PolarFire FPGA and SoC families, with functional safety data packages supporting IEC 61508 SIL 3 and ISO 26262 ASIL D.
  13. Veo Robotics FreeMove, certified by TÜV Rheinland to ISO 13849 PL d Category 3, announced April 2021.
  14. FORT Robotics Endpoint Controller, assessed to IEC 61508 SIL 3 by exida, announced September 2023.
  15. IEC 61508-3:2010, Table A.2, software architecture design, read with 7.4.3. Ratings were read from the table as rendered, not from the PDF text layer, because the commented edition interleaves two editions’ values in one cell. Standard text held and read.
  16. ISO 13849-1:2023: Table 4 for the PL-to-SIL correlation, and 6.1.8 with Figure 12 for category, DCavg, MTTFD and the performance level achieved. Figure 12 assumes a 20-year mission time, constant failure rates within it, and a CCF beta factor of 2%. Standard text held and read.
  17. IEC 61508-4:2010, 3.5.9 and 3.5.10. Systematic capability is “expressed on a scale of SC 1 to SC 4”, and 3.5.10 records that software has no SIL in its own right. Standard text held and read.