For AI that acts

FailStop. The brake that cannot be talked out of stopping.

No permission means stop. Silence means stop. And it stays stopped until a person re-arms it.

Your AI can now take actions it cannot take back, a payment, a delete, a send. The brake stops the action before it runs, and holds an output before it is released. It sits outside the AI, where the AI cannot switch it off.

This is a demonstration, with sample data
14:02:04send report · permittedallowed ✓
14:02:11schedule meeting · permittedallowed ✓
14:02:19delete client records · no permissionSTOPPED
Latched. Nothing runs until a person re-arms it.
The halt and its proof, sealed together ✓

It sits outside the AI it stops.

The system it governs has no way to disable it, reconfigure it, or forge its records.

FailStop is a fail-closed brake in the action path. Before an action runs, it must receive a positive yes. No yes means stop. A lost heartbeat means stop. Trip it, and it latches: nothing runs again until a person, not the AI, re-arms it. Disguised instructions, lookalike characters, and slow multi-turn escalation are checked before the decision, not after the damage.

The black box.

The halt and its proof are produced together.

Every decision, every stop, and every re-arm lands in a sealed, tamper-evident record as it happens. There is no version of events to reconstruct later, because the record was written at the moment, and anyone can check it with the free verifier.

When software is not enough.

It can pull the plug, physically.

For machines that move, the filed design includes a physical channel: a safety-rated interlock that removes motive power in about a tenth of a second. A robot arm, a vehicle, a production line. The software says stop, and the hardware makes it true.

Where it belongs.

AI agentsSoftware that pays, sends, deletes, and signs needs a brake before every irreversible act.
Robots & cobotsMotive power removed on trip, and the stop itself recorded.
Vehicles & dronesA latched stop that survives the software failing, with the flight recorder built in.
Industrial controlFail-closed by design: the absence of permission is itself the stop signal.
Medical roboticsThe stop, the reason, and the human re-arm, each sealed as evidence.
InsuranceEach deployment carries a risk grade built for pricing and underwriting, from the record itself.

A brake, so it stops before it goes wrong. A black box, so it can prove what it did.

Most agents ship with no way to stop them.

An autonomous agent does the thing, and then you find out.

Guardrails built inside the model can be talked around, and a log written afterward is a postmortem, not a stop. The missing piece is a brake on the action path, something outside the AI that can halt the action before it runs.

A brake that sits outside the model.

How the brake holds

Four things, and breaking any one of them fails safe.

Outside the modelIt runs out of process, beside the AI, not inside it. The model has no handle to disable, reconfigure, or forge it.
Fails toward stopIf the system fails, stalls, or goes silent, the action does not slip through. It stops. Safe is the default, not the exception.
LatchedOnce stopped, it stays stopped until a person re-arms it. No silent automatic recovery.
On the recordEvery stop is sealed into a signed receipt anyone can verify, so you can show exactly what was held, and when.

A category, not a feature.

At the moment of inference, on the machine, with proof. Not post-hoc detection in the cloud.

The rest of the market detects after the fact, from a server you do not control. The brake governs before the action, on your own hardware, and proves it.

What it stops

The actions you cannot afford to let happen.

  • An agent action you cannot undo, a payment, a delete, a send.
  • An attempt to talk the AI past its own rules, in one prompt or slowly across a conversation.
  • Work or data trying to leave when it should not.
  • An output crossing a line before it ever reaches a person.

Why you can trust it

Break it, and it only stops.

The safe answer is always the default. Nothing slips through while you are not looking, and every stop is yours to verify.

Breaking it can only make it stop, never leak.

What it is, and what it is not.

It stops an action before it runs, and holds an output before it is released. It runs out of process, beside the model, and changes nothing about the model you use. It is evidence, not a guarantee. It captures, it does not certify.

FailStop is the engine name. "The brake" is the plain one.

The absence of a yes is a stop.