For AI that acts
No permission means stop. Silence means stop. And it stays stopped until a person re-arms it.
Your AI can now take actions it cannot take back, a payment, a delete, a send. The brake stops the action before it runs, and holds an output before it is released. It sits outside the AI, where the AI cannot switch it off.
This is a demonstration, with sample dataThe system it governs has no way to disable it, reconfigure it, or forge its records.
FailStop is a fail-closed brake in the action path. Before an action runs, it must receive a positive yes. No yes means stop. A lost heartbeat means stop. Trip it, and it latches: nothing runs again until a person, not the AI, re-arms it. Disguised instructions, lookalike characters, and slow multi-turn escalation are checked before the decision, not after the damage.
The black box.
Every decision, every stop, and every re-arm lands in a sealed, tamper-evident record as it happens. There is no version of events to reconstruct later, because the record was written at the moment, and anyone can check it with the free verifier.
When software is not enough.
For machines that move, the filed design includes a physical channel: a safety-rated interlock that removes motive power in about a tenth of a second. A robot arm, a vehicle, a production line. The software says stop, and the hardware makes it true.
Where it belongs.
A brake, so it stops before it goes wrong. A black box, so it can prove what it did.
An autonomous agent does the thing, and then you find out.
Guardrails built inside the model can be talked around, and a log written afterward is a postmortem, not a stop. The missing piece is a brake on the action path, something outside the AI that can halt the action before it runs.
A brake that sits outside the model.
How the brake holds
At the moment of inference, on the machine, with proof. Not post-hoc detection in the cloud.
The rest of the market detects after the fact, from a server you do not control. The brake governs before the action, on your own hardware, and proves it.
What it stops
Why you can trust it
The safe answer is always the default. Nothing slips through while you are not looking, and every stop is yours to verify.
Breaking it can only make it stop, never leak.
It stops an action before it runs, and holds an output before it is released. It runs out of process, beside the model, and changes nothing about the model you use. It is evidence, not a guarantee. It captures, it does not certify.
FailStop is the engine name. "The brake" is the plain one.
The absence of a yes is a stop.