Skip to content
Menu ▾
Patent pending

FailStop · a Regulayer surface

The brake for consequential AI.

FailStop places an independent control point before execution. When current human authority cannot be established, or an action exceeds that authority, the action is held or stopped before consequence and the decision is preserved as independently verifiable evidence.

The situation

If an AI can act, something outside it must be able to stop the action.

FailStop governs consequential actions before execution. It places the control point outside the system being governed and applies current human authority before an action can proceed. When an action is held or stopped, the decision, its reason and the governing authority are preserved as independently verifiable evidence.

The governed system does not get the final word on whether its own consequential action proceeds.

A robotic production line in operation

How it behaves

Fail closed

Every action requires a positive yes before it runs. No answer is a no. The default state is stopped.

Latched

Tripped, it stays tripped. Nothing runs again until a person re-arms it. The system under control cannot re-arm itself.

The halt and its proof, sealed together

Every decision, every stop and every re-arm lands in a sealed, tamper-evident record at the moment it happens. There is no version of events to reconstruct later.

FailStop is software consequence control.

It does not replace a hardware safety interlock.

Where it belongs

AI agents

How do we govern an agent that can act across multiple systems without asking for approval at every step? A brake before every irreversible act, outside the agent.

Robots and cobots

Motive power removed on trip, and the stop itself recorded.

Vehicles and drones

A latched stop that the vehicle cannot override, with the record of why it fired.

Production lines

Stop authority outside the control system, in the pattern machinery safety already understands.

Deployment

It runs on your machines, and enforcement and evidence signing require no network egress.

Regulayer operates within the customer-controlled environment. Ordinary enforcement and evidence signing do not require network egress, and the underlying work is not sent to Regulayer. Where independent time evidence is used, the underlying content remains within the customer environment.

Every answer your security function will ask for, on one page you can forward

Related capabilities

What do you need to control or prove?

Licensing begins with the problem, not the product.

Describe the system, what it decides, and what it would cost you to be unable to prove it. A written scope follows before any call.

Ways to begin:

hello@regulayer.com