The Causal Boundary

The Causal Boundary

Isometric blueprint of a physical AI machine: learned models labeled Brain, a controller module labeled Nervous System, and a robot arm labeled Body, with the causal boundary marked where commands enter the arm.

Purpose

What must a machine guarantee before a learned model’s proposal becomes physical work?

A learned policy may select actions the machine cannot safely execute. Once a command reaches a motor, current generates torque and moving mass carries momentum. Canceling the computation cannot undo that motion. As a robot’s software processes observations, its physical chassis continues coasting toward an obstacle. Every millisecond of computational delay consumes physical space, irreversibly shrinking the available braking envelope. Prediction accuracy alone cannot determine if an action should proceed; a policy with 99.9 percent benchmark precision still commands catastrophic collisions when scaled across thousands of operating hours in unconstrained physical environments.

Physical artificial intelligence resolves this tension by structuring the machine across five distinct operating levels. High-capacity learned models residing in the Brain propose candidate trajectories, but between statistical proposals and physical execution sits the causal boundary: the definitive interface where digital bits command motor currents. The Brain holds proposal authority, while the deterministic Nervous System retains hard real-time execution authority to verify commands against the Body’s measured kinematic and thermal limits. When a learned policy experiences tail latency, memory exhaustion, or semantic error, the Nervous System arrests motion via a verified stopping suffix before the machine exhausts its clearance budget.

↳ Downstream: The plant limits behind the causal boundary are measured and recorded in Measuring a Machine's Own Limits.

Learning Objectives
  • Explain why a command that crosses the causal boundary cannot be recalled by software
  • Calculate the blind travel of a pre-brake delay and compare it with the braking distance
  • Classify physical machines by the budget that exhausts first: clearance, contact force, or a thermal or phase margin
  • Apply the physical AI scope test to distinguish advisory models from autonomous physical systems
  • Locate the proposal boundary in the five-level machine and explain why only the permission path may command the actuators
  • Diagnose how timing and authority failures combine in an autonomous machine incident
  • Evaluate how irreversibility, closed-loop data, and limited evidence each make an independent permission path necessary
  • Explain why physical authority depends on state, so that safety, security, and accountability meet at the permission path

Artificial Intelligence Beyond Glass

A robot approaching an open doorway must do more than recognize the portal in its camera stream. It must evaluate whether its physical chassis fits through the opening, select a viable trajectory, and continuously adjust that path as momentum carries it forward. If a sudden obstacle appears, canceling the software thread or throwing an unhandled exception cannot stop the machine’s momentum. Designing this behavior requires tracing a decision all the way from sensory evidence to electromagnetic torque and mechanical work. That complete closed loop is the domain of physical artificial intelligence systems engineering.

In a physical machine, digital bits can command electrical currents across power inverters, magnetic flux generates mechanical torque, and moving mass accumulates momentum. An erroneous command can therefore produce a sheared gearbox, a collapsed battery voltage rail, or a collision before software can correct it.

Moravec’s paradox1 (Moravec 1988) explains why learned models are entering this loop at all: tasks that require intense human conscious effort, such as playing chess or proving theorems, require modest computation, whereas sensorimotor skills executed effortlessly (such as walking across uneven gravel or grasping an egg without crushing it) demand vast computational and control resources. As high-capacity neural networks are deployed to master these sensorimotor tasks, engineering teams encounter the exposure wall, which Physical Trial Limits derives. Offline benchmark accuracy cannot predict closed-loop stability in the open world, and no feasible amount of failure-free testing can by itself demonstrate the rare-failure rates that growing physical deployment requires, so safety arguments must cover cumulative exposure, not only controlled demonstrations.

When digital models command physical actuators, they enter the closed causal feedback loops first formalized by Norbert Wiener in cybernetics2 (Wiener 1948). Information ceases to be an open-loop stream terminating at a display. Instead, every physical motion repositions the machine’s sensors, reshaping subsequent observations under the deterministic laws of classical mechanics. Building such a machine draws on four technical cultures (machine learning, computer systems, classical robotics, and embedded silicon and safety), and teams that bridge them find each culture framing the problem in its own terms.

The machine learning perspective focuses on scaling parameter counts, transformer backbones, and diffusion policies across millions of simulation steps, treating real-world deployment as a challenge of broader demonstration datasets and dataset coverage. The computer systems perspective focuses on memory bus bandwidth, cache hierarchies, and tail-latency percentiles, recognizing that streaming multi-gigabyte neural weights at high frequencies threatens to saturate memory interconnects and starve camera direct memory access pipelines (Williams et al. 2009). The classical robotics perspective relies on Newton-Euler dynamics to manage mechanical forces and motion. If a neural network commands rapid changes in motion (high-frequency jerk), it can shear gearboxes or trigger structural resonance, making classical stability margins critical. Finally, the embedded silicon and safety perspective focuses on bare-metal interrupt service routines, hardware trip zones, and functional safety standards (such as ISO 26262 and UL 4600), ensuring that unverified statistical models never hold direct write access to motor power stages.

Each perspective offers a critical insight. Gradient descent does not repair a fractured transmission or prevent a supply-voltage collapse, while a hand-tuned classical controller cannot provide open-world semantic scene understanding. A viable physical AI systems architecture must unify their responsibilities without asking any single discipline to shoulder the entire problem.

↳ Downstream: The separation of learned proposals from actuation authority is mapped to isolated silicon domains in Where the Permission Path Runs.

Definition 1.1: Physical artificial intelligence

Physical artificial intelligence is the engineering of closed-loop physical machines in which high-capacity learned models propose actions that classical mechanics, thermodynamics, and hard real-time silicon constrain.

  1. Significance: Advisory AI outputs lack direct actuator authority, although people or downstream systems may act on them. Physical AI crosses into a continuous plant, where digital bits command motor currents, kinetic momentum accumulates, and software stalls can contribute to mechanical fractures, overheating, or collisions.
  2. Distinction: Unlike classical robotics (which relies on hand-engineered state machines and explicit kinematic models) or internet-scale machine learning (which operates on static offline datasets), physical AI couples high-capacity statistical generalization with deterministic hardware safety filters across an endogenous closed causal loop.
  3. Common pitfall: Treating physical embodiments as peripheral I/O devices for foundation models. Scaling laws and benchmark accuracies do not prevent supply-voltage collapse, gearbox shear, or actuator force saturation; physical safety requires an asymmetric architecture in which an independent real-time check can veto any learned proposal.

The chapter follows a command from computation to physical work, compares the budgets of three machine classes, applies a scope test to decide which machines fall within the discipline, orders the machine into five levels, and uses the Tempe collision to test the boundary between learned proposals and actuation permission. The final sections turn that failure analysis into four laws, trace where safety, security, and accountability meet, and set out the architecture of the book.

The Causal Boundary

An advisory model that only displays a recommendation has no direct path to a motor or valve. A user may dismiss the recommendation, and a database transaction may be rolled back before an external action commits.3 Neither property makes digital errors harmless: a person may follow bad advice, and an automated trading system may execute a consequential order. The relevant distinction is whether a model’s output can automatically reach a physical actuator.

Physical AI removes the gap between a model’s output and an actuator. In a physical machine, the final instruction of a control loop does not write to a screen or populate a web response. For a machine learning systems engineer accustomed to writing action = policy(observation) in PyTorch, the causal boundary is where floating-point tensors meet physical silicon. The policy’s output tensor, typically an action chunk predicting a sequence of upcoming waypoints (joint positions, velocities, or 6-DOF Cartesian poses),4 cannot execute directly on physical motors.

An independent check must stand between a learned proposal and the actuator command. If the check admits the proposal, its setpoints pass through a deterministic cascade of drive loops that turns them into motor current, and the last software act in that cascade is a value written to a hardware register. Depending on the machine architecture, that hardware register acts as a digital-to-analog converter latch holding a commanded reference voltage, a pulse-width modulation (PWM) compare register setting inverter duty cycle, or a serial control word configuring a gate driver. At that exact memory address, informational abstraction ends. Modulating the gate voltages across power MOSFETs draws current from the high-voltage DC bus into the stator windings, generating Lorentz forces that accelerate the rotor against its reflected load inertia.

Definition 1.2: Causal boundary

Causal boundary is the physical and electrical interface where digital computational bits convert into physical forces, currents, or flows.

  1. Significance: Before actuation, a proposal can be rejected without applying physical work. After actuation, actions can alter the environment, dissipate heat (\(I^2 R\) resistive heating, kinetic friction), and reshape subsequent sensory observations.
  2. Distinction: Unlike a staged digital proposal, which can be rejected before it commits, an applied force cannot be canceled, and the physical work it has already performed remains in the plant.
  3. Common pitfall: Assuming software exceptions or thread cancellations can arrest physical momentum. Once a PWM compare register latches, current flows and mass accelerates; arresting that motion requires dedicated stopping distance (\(d_{\text{stop}}\)) and friction braking.

Transitioning from digital state to physical force breaks the assumption, central to offline machine learning, that the data do not depend on the model’s outputs. In offline vision, natural language processing, and tabular prediction, data collection is exogenous: the world generates a distribution of inputs, and the model processes them without altering the mechanism that created them. In a physical system, the environment evolves in a closed causal loop: the next physical state and sensor observation depend directly on the action produced by the prior model inference.

The sensory input stream is endogenous, generated by the machine’s own past actions. When a policy produces an erroneous torque command, the joint rotates, the platform shifts, and mounted cameras or lidar units swing into new viewpoints. The machine drives itself into an unfamiliar region of the state space where training data is sparse, increasing the probability of subsequent inference errors and compounding the divergence from nominal operation (figure 1).

Flowchart contrasting advisory predictions with physical AI. The upper path ends at an informational interface; the lower path carries sensor observations to a proposal, the permission path, motor actuators, and a changing physical plant.
Figure 1: The closed causal loop: Advisory output (top) stops at an informational interface. In physical AI (bottom), permitted model proposals reach hardware registers, where electrical current produces force and motion. Those actions alter the environment and subsequent sensor observations.

Because physical mass possesses inertia and computation takes finite time, latency in physical AI translates directly into physical displacement. As shown on the autonomous testbed in figure 3, real-world robotic systems rely on dense multi-modal sensor suites (spinning lidar scanners, camera arrays, and radar units) that continuously stream high-bandwidth telemetry to onboard processors. Every stage in this pipeline, from photodiode exposure and sensor bus serialization,5 to neural inference on accelerator silicon and packet transmission over deterministic fieldbuses, consumes milliseconds.

As a concrete example, consider the wheeled base of a warehouse mobile manipulator (introduced in full in section 1.3), cruising down an aisle at its 1.5 m/s drive limit (illustrative; see the Reader Guide). Its pre-brake delay, which later chapters assemble term by term, is at most 133.6 ms, from the capture of the camera frame that shows a person stepping out from a rack end to the onset of braking force. Over that interval the base travels 200 mm with no response to anything the frame recorded. A person who steps out closer than that is reached before braking begins, and no amount of model capacity can alter that outcome.

This trade-off between computational delay and physical clearance is formalized by the kinematic roofline. In classical computer systems architecture, the Roofline Model (Williams et al. 2009) bounds achievable throughput by the lower of two ceilings, peak memory bandwidth times arithmetic intensity (the ratio of arithmetic operations to bytes moved, in \(\text{FLOPs/byte}\)) and peak compute. In physical AI, the kinematic roofline couples the delay before braking \(\tau_{\text{delay}}\) and platform velocity \(v\) to bound physical stopping clearance against the credible braking deceleration \(a_{\text{brake}}\), but it adds its two terms rather than capping one by the other.

Williams, Samuel, Andrew Waterman, and David Patterson. 2009. “Roofline: An Insightful Visual Performance Model for Multicore Architectures.” Communications of the ACM 52 (4): 65–76.

Under emergency braking, the total stopping distance \(d_{\text{stop}}\) is the sum of the blind travel during the delay, which grows linearly with the delay, and the braking distance, which grows with the square of speed. Kinetic Momentum derives the relation. The blind travel is non-negotiable. During the delay, no braking force can be applied, because the sensor exposure has not yet propagated through perception and the fieldbus to the brakes. As table 1 shows across representative embodied platforms, the delay’s share of the stop is largest for slow, agile platforms, while its absolute travel is largest for fast vehicles.

Table 1: Kinematic roofline nomogram: Stopping clearance trade-offs across embodied platforms. The warehouse mobile manipulator’s row uses its drive limit and credible deceleration. The three delay columns are classes of pre-brake delay, not the delay of any one platform. Stopping distances are rounded to three significant figures, and the added blind travel is given in centimeters to the nearest millimeter. At 200 ms of delay, an autonomous passenger car travels an additional 4 m, an entire vehicle length, before its brakes engage.
Physical Platform & Velocity \(v\) Braking Decel \(a_{\text{brake}}\) Mechanical Braking \(d_{\text{braking}}\) \(\tau_{\text{delay}} =\) 10 ms (Reflex Class) \(\tau_{\text{delay}} =\) 50 ms (Short Class) \(\tau_{\text{delay}} =\) 200 ms (Long Class) Latency Fraction at 200 ms
Humanoid / Quadruped (1 m/s = 3.6 km/h) 4 m/s² (0.41 g) 0.125 m 0.135 m (+1 cm) 0.175 m (+5 cm) 0.325 m (+20 cm) 61.5% of total stop
Warehouse Mobile Manipulator, Base (1.5 m/s = 5.4 km/h) 2 m/s² (0.20 g) 0.563 m 0.578 m (+1.5 cm) 0.638 m (+7.5 cm) 0.863 m (+30 cm) 34.8% of total stop
Urban Delivery Bot (6 m/s = 21.6 km/h) 4.5 m/s² (0.46 g) 4 m 4.06 m (+6 cm) 4.30 m (+30 cm) 5.20 m (+120 cm) 23.1% of total stop
Autonomous Vehicle (20 m/s = 72 km/h) 7 m/s² (0.71 g) 28.6 m 28.8 m (+20 cm) 29.6 m (+100 cm) 32.6 m (+400 cm) 12.3% of total stop

Just as an architect cannot resolve a memory-bound arithmetic pipeline by adding more ALU execution units, an autonomous vehicle systems engineer cannot resolve an emergency stopping clearance violation by adding model parameters if doing so lengthens the delay \(\tau_{\text{delay}}\) before braking. A heavier foundation model that adds 150 ms of computation consumes an extra 3 m of physical travel at highway speeds, distance that no friction brake or collision-avoidance logic can recover.

The physical reality of this trade-off is captured longitudinally across five decades of autonomous vehicle systems (figure 2). The safe operating speed of any physical AI platform is strictly bounded by the kinematic stopping roofline: \[d_{\text{stop}} = v \tau_{\text{delay}} + \frac{v^2}{2 a_{\text{max}}} \le R_{\text{sensor}}\] where \(v\) is vehicle velocity, \(\tau_{\text{delay}}\) is the end-to-end sense-to-act loop latency, \(a_{\text{max}}\) is emergency braking deceleration (\(0.7\,\text{g} \approx 6.86\,\text{m/s}^2\) on dry asphalt), and \(R_{\text{sensor}}\) is the effective sensor perception horizon.

In the early deliberative era (1970–1980), SRI’s Shakey and Moravec’s Stanford Cart operated with loop latencies between \(15\) and \(30\,\text{seconds}\) due to offboard mainframe compute bottlenecks, capping safe crawl speeds below \(0.2\,\text{km/h}\). By the mid-1980s and 1990s, Ernst Dickmanns’ VaMoRs demonstrated that running custom 4D dynamic vision algorithms at \(25\,\text{Hz}\) (\(\tau = 40\,\text{ms}\)) unlocked \(96\,\text{km/h}\) highway speeds on the German Autobahn, proving that control loop cadence—rather than raw cognitive deliberation depth—governs safe mobility. During the DARPA Grand Challenges (2004–2007), Stanford Stanley and CMU Boss operated at \(10\text{--}12\,\text{Hz}\) (\(85\text{--}100\,\text{ms}\)) to navigate desert trails and urban intersections at \(48\text{--}60\,\text{km/h}\). Today, production robotaxis such as the Waymo Driver maintain \(\sim 80\,\text{ms}\) loop latencies to ensure stopping envelopes remain well within their \(200\,\text{m}\) sensor horizons at highway velocities (\(110\,\text{km/h}\)), while autonomous racing vehicles (such as the Indy Autonomous Challenge PoliMOVE team) push loop latencies down to \(28\,\text{ms}\) (\(>35\,\text{Hz}\)) to operate safely at speeds exceeding \(309\,\text{km/h}\).

Figure 2: The causal boundary: sense-to-act loop latency versus vehicle operational speed envelope (1970–2026): Empirical milestones spanning five decades of autonomous ground vehicles plotted against physical kinematic stopping rooflines under emergency deceleration (\(a_{\text{max}} = 0.7\,\text{g} = 6.86\,\text{m/s}^2\)) across four sensor horizons (\(R = 5\,\text{m}\) to \(200\,\text{m}\)). Vehicles above the \(R = 200\,\text{m}\) ceiling enter the physically unrecoverable regime, where stopping distance exceeds sensor range regardless of downstream algorithm cleverness. Milestones: SRI Shakey (1970), Stanford Cart (1979), CMU Navlab 1 (1986), UniBwM VaMoRs (1987), CMU Navlab 5 (1995), Stanford Stanley (2005), CMU Boss (2007), Waymo Driver Gen 5/6 (2024), and Indy Autonomous Challenge PoliMOVE AV-24 (2024).

Once digital commands transition into mechanical work, the state change becomes thermodynamically irreversible. The physical world provides no rollback mechanism.6 When an actuator controller applies current to a motor, electrical energy transfers from the battery into kinetic energy in mechanical linkages or thermal energy dissipated through resistive Joule heating (\(I^2 R\)) in the stator windings. If an incorrect joint torque drives a manipulator into a rigid steel fixture, the kinetic energy converts into plastic deformation of the tool, mechanical strain on the gearbox teeth, and heat. No software interrupt can pull that kinetic energy out of the crushed structure or restore sheared gear teeth to their original geometry.

↳ Downstream: The non-smooth contact mechanics and torque saturation limits governing motor irreversibility are derived in Actuator Transmission Limits.

Close-up photograph of a roof-mounted 64-beam spinning optical lidar sensor assembly on an autonomous research vehicle testbed, showing optical lenses and aluminum housing.
Figure 3: Lidar sensor ingress: A 64-beam spinning optical lidar assembly mounted aboard an autonomous research testbed. In physical AI, sensor streams delivering over 1.3 million points per second must be serialized over real-time hardware interfaces, synchronized to microsecond timestamps, and processed through neural perception backbones within strict latency deadlines. (Source: Steve Jurvetson, CC BY 2.0).

Physical AI inherits the learned model of advisory machine learning and the actuator of classical control, and with them a combination of failure modes that neither field faces alone (table 2).

Table 2: Comparison matrix of computing paradigms across the causal boundary: Advisory digital machine learning (left), classical robotics and control theory (middle), and physical artificial intelligence (right) compared by operational substrate, model formulation, feedback dynamics, execution cadence, actuation authority, failure semantics, and safety certification primitives.
Architectural Dimension Digital Machine Learning (Advisory) Classical Robotics & Control Physical Artificial Intelligence (Closed-Loop)
Operational Substrate Decoupled virtual memory buffers (GPU VRAM, DRAM, web endpoints) Continuous analog state space governed by differential equations Hybrid: high-dimensional neural representations mapped to analog physical actuators
Model Formulation High-capacity statistical approximators (LLMs, ViTs, diffusion policies) Analytically specified transfer functions and deterministic state-space matrices Foundation policies paired with deterministic runtime safety filters
Feedback Dynamics Exogenous and static; independent and identically distributed samples Continuous deterministic state feedback with Gaussian sensor noise Endogenous, non-stationary closed loop; actions shape future observations
Execution Cadence Throughput-optimized batching; soft or unbounded latency budgets Hard real-time single-rate loops on microcontrollers (100 Hz to 1 kHz) Multi-rate: an intent model (1–5 Hz) and a chunk policy (10–50 Hz) propose; a permission loop, 1 kHz in one implementation, admits
Actuation Authority Advisory; sandboxed APIs, display buffers, or human-in-the-loop validation Hardcoded feedback directly driving power inverter timers and PWM registers Learned proposals checked by an independent path before any reaches an actuator
Failure Semantics Outputs may be dismissed or transactions reversed before external action; downstream harm remains possible Actuator saturation, tracking error, or loss of stability Irreversible thermodynamic work, plastic deformation, kinetic collision, or stator overheating
Safety Assurance Offline statistical loss minimization on validation splits Formal mathematical stability proofs (Lyapunov functions, gain/phase margins) Layered runtime invariant enforcement, forward-invariant barrier filters, and fault injection

The failure-semantics and actuation-authority rows of the right-hand column trace to irreversibility. A permitted command delivers work that no later software action can recall, so the check on it has to finish first. What that work damages first, and how quickly, depends on what the machine moves, and that dependence sets the deadline the check must meet.

Three Machine Classes

An autonomous delivery drone navigating turbulent wind gusts seems to share nothing with a six-axis robotic arm assembling an automotive transmission, and neither appears related to a containerized battery management plant regulating liquid coolant. One curriculum can cover them all, without becoming a collection of ad hoc recipes, only if it classifies them by something deeper than their shape.

The key is to look past cosmetic form factors to the underlying physical conservation laws. Every embodied AI system is governed by one or more of three foundational physical classes, each defined by the conservation law that dominates its actuators (figure 4, figure 5): moving mass across space, applying force through physical contact, or regulating continuous fluid and thermal flows. A humanoid couples all three on one chassis. Classifying a machine this way allows system architects to determine which resource budget exhausts first during a software stall or anomaly and to size the machine’s safety response to it. Table 3 sets those budgets beside the failure each one ends in and the gate that has to catch it.

Three machine classes of physical AI classified by binding conservation laws: mass-dominated mobility governed by momentum and stopping clearance, contact-dominated manipulation governed by mechanical impedance and structural yield stress, and flow-dominated process plants governed by thermal capacitance and transport lag.
Figure 4: Three machine classes: The three foundational physical embodiments classified by their primary binding conservation laws: (a) mass-dominated mobility (Class 1) governed by momentum and spatial clearance; (b) contact-dominated manipulation (Class 2) governed by mechanical impedance and structural yield stress; and (c) flow-dominated process plants (Class 3) governed by thermal capacitance and transport lag.
Table 3: Binding budget by class: Each class exhausts a different resource first when software stalls, and that resource determines the enforcement mechanism the machine must carry. The gates are design responses to the failure mode in the same row, not certified performance claims.
Class Exemplars First budget to exhaust Failure mode Safety gate
Mass-dominated AMRs, AVs, drones, mobile bases Stopping distance and pre-brake delay (\(\tau_{\text{delay}}\)) Kinetic collision; momentum breach Independent braking check at a rate set by the stopping budget (\(1\text{ kHz}\) in one implementation)
Contact-dominated Manipulators, grippers, presses Actuator current and gearbox stress Gear tooth shear; workpiece damage Torque-derivative clamp and \(C^2\)-smooth trajectory limit (continuous acceleration)
Flow-dominated Thermal loops, inverters, bioreactors Thermal or phase margin Thermal runaway; insulation blowout Hardware thermal observer and interlock
Photographic plate showing three physical AI embodiments: Boston Dynamics Spot quadruped robot on a forest trail, Franka Panda robot arm on an assembly fixture, and a containerized Tesvolt battery energy storage system.
Figure 5: Three machine classes in the field: Field deployments representing the three foundational physical conservation regimes: (a) mass-dominated mobility exemplified by Boston Dynamics’ Spot quadruped negotiating unstructured terrain; (b) contact-dominated manipulation exemplified by the Franka Emika Panda collaborative arm regulating fine assembly contact forces; and (c) flow-dominated process plants exemplified by containerized utility-scale battery energy storage systems (Tesvolt BESS) governing high-capacity thermal dissipation and liquid cooling loops. (Attribution: Wikimedia Commons, CC BY-SA 4.0).

This book follows one machine from its first chapter to its last. The warehouse mobile manipulator is a wheeled base that carries a seven-joint arm, a navigation camera and lidar, a wrist camera, and two computers. An application processor runs its learned models, and a separate safety microcontroller decides, on a fixed short period, whether a proposed motion may reach the motors. Its chunk policy is a whole-body action-chunking model that proposes base velocity and arm joint targets together, as mobile manipulation systems of this class do (Fu et al. 2024). The base is a mass-dominated Class 1 machine that must stop before it reaches a person who steps out from the end of a rack. The arm is a contact-dominated Class 2 machine that must open a spring-latched cage door, lift an unfamiliar mug from a moving conveyor, and hand the mug to a coworker at the packing station, each without exceeding a contact force. The chapters that own a term of the machine’s stopping budget add that term in turn, so the value one chapter computes is the value the next one uses. The remaining chapters treat the proposer that spends that budget and the evidence that decides how much of it the proposer may spend. A Class 3 process plant appears once in each part as a contrast.

Fu, Zipeng, Tony Z. Zhao, and Chelsea Finn. 2024. “Mobile ALOHA: Learning Bimanual Mobile Manipulation with Low-Cost Whole-Body Teleoperation.” Proceedings of the 8th Conference on Robot Learning (CoRL), Proceedings of machine learning research, vol. 270.

Class 1: Mobility systems

Class 1 machines move mass across space, bound by momentum conservation and kinetic energy dissipation (figure 4 a, figure 5 a). In autonomous transport platforms, quadruped robots navigating rugged terrain (such as Boston Dynamics’ Spot), mobile manipulators, and aerial drones, the actuator bridge applies force to translate or rotate a body with mass \(m\) at velocity \(v\). Because kinetic energy \(E_k = \frac{1}{2}m v^2\) cannot be instantaneously erased once delivered to the chassis (it must be scrubbed off through friction, aerodynamic drag, or regenerative braking), safety is primarily measured as remaining spatial clearance. The stopping distance of table 1 is this class’s budget, and the first boundary breached during a software stall or model misclassification is the physical distance to an external obstacle.

To see how the two terms of that budget scale, return to the warehouse base cruising at its 1.5 m/s drive limit toward a rack end where a person has stepped out. Loaded with its tote rack, its mass is at most 368 kg, and it carries 414 J of kinetic energy, which braking must shed through the grip of its wheels on the floor. At a credible deceleration of 2 m/s², braking alone takes 562.5 mm of floor. The 200 mm of blind travel over the 133.6 ms pre-brake delay comes before any of that braking and adds 35.6 percent to the braking distance. Table 1 reaches a similar figure for the same base, 34.8%, by a different measure, the travel over its 200 ms long delay class as a share of the whole stop. The two terms answer to different design choices. A larger model that lengthens the delay lengthens the blind travel in proportion, whereas doubling the cruising speed would quadruple both the energy and the braking distance.

Class 2: Manipulation systems

Class 2 machines apply mechanical force through contact, limited by actuator torque saturation, environmental stiffness, and current loop bandwidth, meaning how quickly the motor controller senses and regulates current to control torque (figure 4 b, figure 5 b). In articulated manipulators, precision assembly fixtures, and robot learning workcells executing contact-rich insertion and grasping, the end-effector interacts directly with a rigid or compliant workpiece. Unlike a mobile platform, an arm in contact with a surface cannot resolve unexpected displacement by rolling forward. When an actuator commands position into a rigid boundary, physical displacement is blocked, and the interaction acts like a compressed spring governed by mechanical impedance. By Hooke’s law, the contact force generated by a spatial penetration error \(\Delta x\) against an environment of stiffness \(k\) is \(F = k \Delta x\).7

Contact stiffness can make a held motion command expensive before the high-level planner returns. Consider the arm of the same warehouse mobile manipulator driving its gripper toward the strike plate of the cage door at 0.10 m/s, and suppose its low-level controller keeps executing that command while the high-level process stalls for 75 ms. The plate acts as a spring of stiffness 4.0 × 10⁵ N/m, the latch tolerates at most 100 N of contact force, and the arm is assumed to have enough torque to keep moving through contact. The plate then deflects by \(\Delta x = v \cdot \Delta t =\) 7.5 mm, and the spring model gives \(F = k \cdot \Delta x =\) 3,000 N, 30 times the limit. Motor saturation, compliance elsewhere, or a controller that stops on stale commands would change that result. Against a plate this stiff, the time available to detect contact and bring commanded motion within the limit is a matter of milliseconds, far shorter than the stall, and Policy Training derives that budget for this plate.

Class 3: Process and energy systems

Beyond moving linkages and contacts, Class 3 machines regulate continuous fluid, thermal, or electrical power flows (figure 4 c, figure 5 c). A cooling loop must remove heat as fast as the process generates it. With net heating power \(P\) and thermal capacitance \(C_{\text{th}}\), a stalled pump produces a temperature rise \(\Delta T = \int P/C_{\text{th}}\,dt\) until flow resumes; a transport delay adds time before new coolant reaches the hot component. For an illustrative constant \(P\) of 1 kW and \(C_{\text{th}}\) of 10 kJ/K, the component warms at 0.1 K/s, so a 5 K margin provides about 50 s before the assumed limit. A grid-tied inverter faces a different budget: on a 60 Hz network, an uncompensated 1 ms phase-estimation delay corresponds to 21.6° of phase error. Whether that error causes unacceptable current depends on the inverter’s impedance and protection design; the 8.33 ms half-cycle is not itself a universal failure deadline. In each plant, the permitted software delay follows from the physical margin and the available protection, rather than the clock period alone.

The humanoid couples all three

A humanoid robot does not belong to a single machine class. All three physical regimes operate and contend simultaneously on its single, tightly constrained mobile chassis:

  1. Class 1 Dynamics in Locomotion: Underactuated bipedal balancing, dynamic footstep placement, momentum conservation (\(m\mathbf{v}\)), and ground contact slip during walking and stair climbing require continuous spatial clearance and kinetic energy management.
  2. Class 2 Dynamics in Manipulation & Contact: Bimanual end-effectors, multi-fingered grasping, and rigid contact transitions with environmental workpieces subject kinematic chains to high shock loads (\(F = k \Delta x\)), joint torque saturation, and transmission yield stress during physical interaction.
  3. Class 3 Dynamics in Actuation & Power Delivery: Driving 20 to 50 high-torque actuators simultaneously from a single onboard DC battery pack pushes inverter thermal dissipation (\(I_{\text{phase}}^2 R_{\text{phase}}\)) to its limits.

Systems Perspective 1.1: The humanoid crucible
A humanoid couples stopping clearance, contact force, and electrical power on one chassis, so a demand in one regime becomes a demand in the other two within a single step. When a hand catches an unexpected load:

  • Contact becomes momentum (Classes 1 and 2): The contact force perturbs the center of mass, and the robot must place a recovery step before it tips, turning a contact problem into a braking problem.
  • Momentum becomes heat (Classes 1 and 3): The recovery step draws peak current through the hip and knee drives, and winding temperature forces the drives to derate torque when balance needs it most.
  • Current becomes brownout (Class 3): The same current transient sags the shared battery bus and can reset the computer running the learned models in mid-step unless its power domain is decoupled from the drives.

Each part of this book ends by testing its law on a humanoid.

While a single-class machine (such as a wheeled AMR or a fixed industrial arm) isolates its physical budget to a single dominant conservation law, a humanoid robot forces the systems architect to manage coupled contention across classes, in which no one budget can be sized without the other two (Electrical Power Integrity quantifies the bus droop).

For any physical AI system, designing the independent check begins by determining which physical budget is exhausted first during a failure. In software systems, resource constraints center on processor cycles, memory allocation, and network bandwidth. In physical systems, the systems architect must identify whether spatial clearance, structural stress, or heat dissipation creates the critical timing deadline. In a high-speed vehicle or quadruped, spatial clearance fails within fractions of a second while motor winding temperatures remain safely below thermal limits. In an assembly press, mechanical stress exceeds the yield point of structural members within tens of milliseconds long before the chassis moves perceptibly or heats up. In a chemical reactor or battery pack, mechanical stress is negligible, but accumulated thermal energy breaches safe operational envelopes over several seconds. The shortest time to failure across these three domains defines the deterministic execution deadline that the independent check must meet.

Belonging to one of these three physical classes does not by itself mean that a machine requires the full systems discipline of physical AI. A classical hydraulic press or a deterministic PID drone autopilot manipulates mass and contact force, but operates entirely within classical control theory.

The Physical AI Scope Test

Without a scope boundary, teams err in two directions, putting neural models where closed-form PID control already suffices, or granting stochastic models unverified motor authority in safety-critical loops.

The scope of physical AI is defined by the simultaneous intersection of three structural criteria (figure 6):

  1. Learned Statistical Model (Unspecifiable Policy): The system relies on a policy, perception encoder, or world model acquired from data (e.g., neural networks, foundation models, diffusion policies (Chi et al. 2024)) whose input–output transfer function cannot be written in closed-form analytical equations and whose worst-case outputs cannot be mathematically bounded offline.
  2. Consequential Physical Feedback: Actuator actions alter the material state of the physical environment, which in turn directly dictates what the sensors observe next under the governing laws of classical mechanics, thermodynamics, or electromagnetism.
  3. Delegated Physical Authority (System-Level Actuation): A learned component supplies live proposals that an automated system can execute without synchronous human approval. The learned model need not write an actuator register itself; the system holds physical authority because an accepted proposal can reach one.
Chi, Cheng, Zhenjia Xu, Siyuan Feng, Eric Cousineau, Yilun Du, Benjamin Burchfiel, Russ Tedrake, and Shuran Song. 2024. “Diffusion Policy: Visuomotor Policy Learning via Action Diffusion.” The International Journal of Robotics Research 44 (10-11): 1684–704. https://doi.org/10.1177/02783649241273668.
Three-set Venn diagram defining physical AI at the intersection of learned models, physical feedback, and physical authority. The pairwise overlaps show advisory systems, digital autonomy, and classical control.
Figure 6: The physical AI scope test: Physical AI combines a learned component, consequential physical feedback, and system-level authority to execute accepted proposals without human approval. An independent veto belongs inside this intersection because accepted proposals can still move the plant. The pairwise overlaps locate advisory systems, digital autonomy, and classical control.

A closed feedback loop is necessary for physical interaction, but feedback alone does not qualify a machine for this domain. Classical proportional-integral-derivative (PID) controllers run at \(1\text{ kHz}\) across aerospace and industrial automation, regulating valve positions and motor torques through tight sensory feedback. Their feedback loops are continuous and physical, but their control laws are specified entirely by fixed mathematical formulas whose stability bounds can be proven analytically from transfer functions. They hold physical authority and experience physical feedback, but they lack a learned model. Conversely, high-frequency algorithmic trading engines execute automated market orders under learned predictive models within microseconds. They combine learned policies with delegated transactional authority, but the feedback they receive is purely digital and informational. When an order executes, it alters an electronic order book rather than momentum, friction, or thermal energy. An unhandled stall in algorithmic trading costs financial capital, but it does not cause an inertia-driven collision with a structural fixture.

A learned model alone cannot define the field. An offline neural trajectory optimizer may compute paths for a manipulator, but if an engineer must inspect and explicitly load each path before execution, its outputs have no delegated runtime authority. Similarly, a neural network that only logs assembly-line defects or flags a display remains advisory because its output cannot automatically command the line.

The remaining pairing, a learned model with physical feedback but no authority, completes the boundary. A real-time driver drowsiness monitor uses a learned computer vision model to track eyelid movement and vehicle lane position, receiving continuous physical feedback from the vehicle state. Yet it lacks delegated physical authority because its only output is an auditory warning chime. If the vision model fails completely during an inference timeout or pipeline stall, the speaker simply emits no sound, but the physical steering rack and brake calipers remain safely under human control.

The most demanding edge cases arise in shared autonomy, where physical authority is dynamically divided between a human operator and a learned model. In robotic surgery or advanced driver assistance, a human operator provides continuous steering or tool guidance while a learned policy injects corrections to filter hand tremors, avoid anatomical boundaries, or compensate for vehicle slip. These architectures satisfy both the learned component and physical feedback criteria. Whether they fall within the scope of physical AI depends strictly on the temporal authority granted to the model. If the learned policy can command even \(2.0\text{ N}\) of force or adjust steering angle without requiring human confirmation within the human reflex interval of \(150\text{--}250\text{ ms}\), the model possesses delegated physical authority. During that window, an erroneous model output or a delayed inference packet exerts real physical forces on the world, potentially causing a swerve or tissue damage, before the human operator’s neuromuscular system can physically react to intercede.

Evaluating an ambiguous machine means testing each criterion independently, as table 4 does for representative systems. A deterministic veto does not remove delegated authority; a mandatory human review of an offline plan does. When all three tests pass, the system operates as physical AI, and its engineering must respect the causal boundary established in section 1.2.

Table 4: The physical AI scope test decision matrix: Representative engineering systems tested against the three joint criteria (Learned Model, Consequential Physical Feedback, and Delegated Physical Authority), establishing the governing engineering discipline, limiting physical factors, and primary failure modes for each candidate.
System Candidate / Case Criterion 1: Learned Model (Unspecifiable Policy) Criterion 2: Consequential Physical Feedback Criterion 3: Delegated Physical Authority (Automatic Gated Execution) Scope Classification & Discipline Limiting Physics & Critical Failure Mode
Autonomous Warehouse AMR (Class 1) Yes (Learned navigation policy / costmap) Yes (Kinetic momentum, chassis inertia, and wheel traction) Yes (Accepted proposals reach motor control without human approval) Physical AI Kinetic impact; traction slip and odometry loss
Articulated Contact Manipulator (Class 2) Yes (Transformer action chunking for assembly (Zhao et al. 2023)) Yes (Mechanical contact impedance and reaction forces) Yes (Safety-gated proposals drive live joint commands) Physical AI Structural yield stress exceedance; gearbox tooth shear
High-Speed Drone Classical Autopilot No (Analytically tuned \(1\text{ kHz}\) PID / cascaded loop) Yes (Aerodynamic lift, drag, and gyroscopic dynamics) Yes (Direct PWM motor speed control) Classical Control Theory Control margin erosion; rotor thrust saturation
High-Frequency Market Maker Yes (Deep transformer sequence predictor) No (Digital order-book state; memory and network queues) No (No physical actuation; orders execute automatically) Digital Machine Learning / FinTech Financial capital loss; market disruption
Advisory Driver Drowsiness Monitor Yes (Facial landmark vision network) Yes (Vehicle kinematics and driver physiology) No (Auditory warning buzzer and dashboard LED only) Advisory Decision Support Human perception-reaction latency; zero physical authority
Offline Trajectory Optimizer Yes (Deep neural network for time-optimal path search) No (Static CAD workcell model; offline batch execution) No (Motion plan verified and loaded via human engineer) Offline Optimization Tool Numerical non-convergence; zero direct runtime plant coupling
Shared-Autonomy Surgical Assist Yes (Learned haptic tremor filter / virtual fixtures) Yes (Anatomical tissue compliance and reaction forces) Conditional (Model injects forces within human reflex window) Borderline / shared physical AI Human neuromuscular reflex latency vs. tool force rise rate
Checkpoint 1.1: Binding budgets and the scope test

Before examining the five-level machine, verify that you can place an unfamiliar machine by its binding budget and by the scope test:

The Machine in Five Levels

A machine that passes the scope test needs an organization that keeps its learned models from writing directly to the actuators they could damage, while still letting those models steer it.

The machine in this book has five levels, ordered from the learned models down to the physics they act on and divided by a single line of authority. Control rates rise from the Brain to the Body; below the Body, the Boundary is timed by events and the World runs continuously. The Brain holds the learned proposers. An intent model revises goals at 1 to 5 Hz, and a chunk policy emits short sequences of future setpoints at 10 to 50 Hz; perception and memory run on the same side at sensor rates.

The Brain may only propose. Beneath it lies the proposal boundary, and beneath that the Nervous System, which holds the permission path. The permission path checks every proposal against fresh state and the margin that delay has left, admits, modifies, or refuses it, and owns a fallback that does not wait for the proposer. A 1 kHz loop on a dedicated microcontroller is one implementation; the rate a machine actually needs follows from its stopping budget. The Body is the machine’s own physics under its drives, from the current loop that turns an admitted setpoint into torque at 10 to 25 kHz to the transmissions, windings, and power rails whose limits The Physical Body measures. The Boundary is the causal boundary itself, the transducers that face both ways. At one face a register write becomes current in a winding; at the other, light or force becomes a measurement with a capture time. The World is everything the machine does not own, including floors, payloads, contact, and people, and it evolves continuously whether any level is watching or not.

Governance is not a sixth level. It is the lifecycle envelope around all five, deciding who may command the machine, what evidence licenses it to operate, and when that license expires, and it changes on the timescale of interventions and releases rather than control cycles.

↳ Downstream: Transfers of command authority, and preemption of the proposal stream, are governed by the supervisor state machine in Authority Transitions.

Definition 1.3: Proposal boundary

Proposal boundary is the line between a learned model, which may only propose an action, and the permission path, an independent mechanism with bounded latency that the model cannot delay or corrupt and that alone may permit the action to reach an actuator. The permission path checks each proposal against fresh evidence, the stopping envelope, and a fallback feasible from the current state, and refuses when any check fails.

  1. Significance: Keeps model outputs from directly commanding actuators; the protection holds only while the permission path’s sensing, physical limits, and fallback remain valid.
  2. Distinction: A policy that outputs torque values still has no actuator-write authority; its output is a proposal until the permission path admits it.
  3. Common pitfall: Treating the permission path as a post-processing clamp on model outputs rather than an independent mechanism that can refuse execution when the proposer is late, wrong, or silent.

The margin stack that opens every chapter draws the same five levels (figure 7) and highlights the one that chapter works on; table 5 pins their rates and lists the chapters for each.

Table 5: The five levels and their pinned rates: These are the only rates the book attaches to a level. A machine that needs a different rate derives it from its own measured limits rather than relabeling a level.
Level What it is Pinned rate Where the book works on it
Brain Learned proposers and the evidence they consume Intent model 1–5 Hz; chunk policy 10–50 Hz; perception at sensor rate The Cognitive Brain, Policy Training, Sensor Perception to Trajectory Planning
Proposal boundary Above may only propose; below may command — —
Nervous System The permission path: timing, lease, admission, fallback, and its silicon 1 kHz as one implementation; the required rate follows from the stopping budget The Nervous System, Safety Enforcement, Silicon Placement
Body The plant under its drives Current loop 10–25 kHz The Physical Body
Boundary Actuator register write and sensor capture Event-timed This chapter; the capture epoch in Sensor Perception
World Contact, friction, payload, people, and the operating domain Continuous Physical Data, Closed-Loop Evaluation
Governance envelope Who may command, what licenses operation, and when that license expires Lifecycle; no control rate Supervisory Intervention to The Epistemic Frontier
Five stacked horizontal bands labeled from top to bottom Brain (learned proposers, intent model 1 to 5 hertz, chunk policy 10 to 50 hertz), Nervous System (permission path, lease, fallback, a 1 kilohertz loop in one implementation), Body (drives, transmission, windings, rails, current loop 10 to 25 kilohertz), Boundary (register write and sensor capture, event-timed), and World (contact, friction, payload, people, continuous). A wider gap between Brain and Nervous System is labeled proposal boundary, above may only propose, below may command. A dashed outline enclosing all five bands is labeled governance, lifecycle envelope, Part IV, no control rate. Chapter numbers sit at the right edge of each band: Brain 3, 6, 8 to 11; Nervous System 4, 12, 13; Body 2; Boundary 1, 8; World 5, 7.
Figure 7: The five-level machine: Each band carries its pinned rate and the chapters that work on it. The wider gap between Brain and Nervous System marks the proposal boundary, above which a component may only propose. A chapter-opening stack with no level highlighted marks a governance chapter. The permission-loop rate shown is one implementation.

This organization operationalizes Rodney Brooks’s principles of situatedness and subsumption (Brooks 1986; Brooks 1991), in which fast reactive layers protect the plant directly from sensory feedback while high-level deliberative goals modulate behavior across verified contract boundaries. For diagnosing a failure, a sense–plan–act decomposition locates the earliest broken contract; S·P·A Diagnostic Playbook develops it as a playbook.

Brooks, Rodney. 1986. “A Robust Layered Control System for a Mobile Robot.” IEEE Journal on Robotics and Automation 2 (1): 14–23.
Brooks, Rodney A. 1991. “Intelligence Without Representation.” Artificial Intelligence 47 (1–3): 139–59. https://doi.org/10.1016/0004-3702(91)90053-M.

The five levels span five orders of magnitude in operational frequency and latency (table 6). At the top, deliberative foundation models plan at human reaction scales (1–5 Hz); at the bottom, power electronic inverters switch stator currents at tens to hundreds of kilohertz (50–200 kHz). Bridging these extremes is the physical reality that latency is distance: every millisecond of uninspected delay in a machine moving at \(1\text{ m/s}\) produces \(1\text{ mm}\) of unrecoverable blind travel.

Table 6: Latency and Rate Numbers for Physical AI Systems: Order-of-magnitude frequencies, cycle periods, and kinetic translation rates across the five machine levels that dictate physical feasibility. Spanning five frequency decades, from sub-microsecond MOSFET switching up to second-scale foundation model deliberation, these physical constraints dictate how computational delay converts into irreversible mechanical motion. For a comprehensive quick-reference including thermal time constants, edge rooflines, bus jitter, and statistical safety bounds, see Numbers to Know in Physical AI.
Machine Level Frequency Band Cycle Period Blind Travel at 1 m/s Architectural Role & Dominant Constraint
Brain (Deliberation) 1–5 Hz 200–1,000 ms 200–1,000 mm Multimodal VLA reasoning; compute- and memory-bound
Brain (Action Chunking) 10–50 Hz 20–100 ms 20–100 mm Reactive trajectory generation; bandwidth amortized
Nervous System (Permission) 1 kHz 1 ms 1 mm Barrier certificates & stopping envelopes; deadline hard
Body (Current Loop) 10–25 kHz 40–100 µs 40–100 µm FOC stator current & torque control; inductive \(L/R\)
Body (Inverter Switching) 50–200 kHz 5–20 µs 5–20 µm MOSFET gate drive & dead time; \(L dI/dt\) droop

↳ Downstream: The Brain’s committed trajectory is built in Continuous Trajectories.

When the Boundary Fails

A physical crash can involve both an inaccurate prediction and a failure to respond when available evidence already warrants intervention. The Tempe investigation shows how object tracking, braking policy, operator reliance, and lost redundancy interacted.

The 2018 Tempe autonomous collision

On a March night in 2018, a modified Volvo XC90 operating Uber Advanced Technologies Group’s developmental automated driving system (ADS) struck and fatally injured a pedestrian pushing a bicycle across a road in Tempe, Arizona (National Transportation Safety Board 2019).8

The vehicle carried lidar, radar, and cameras (figure 9). The ADS first detected the pedestrian \(5.6\text{ s}\) before impact, but detection alone did not provide a correct path prediction (National Transportation Safety Board 2019).

Classification changes and lost tracking history

Despite continuing to track the detected object, the ADS did not brake in response to it. The NTSB record shows classification changes among vehicle, bicycle, and other before \(T-1.2\text{ s}\) (National Transportation Safety Board 2019).

When the classification changed, the ADS path predictor did not use the object’s earlier locations; for an “other” object it could assume a static path.9 The resulting path predictions did not place the pedestrian in the SUV’s lane until \(T-1.2\text{ s}\) (National Transportation Safety Board 2019).

↳ Downstream: The stopping envelopes in Stopping Envelopes bound what a classification change like Tempe’s can cost.

Action suppression and the lost stopping margin

At \(T-1.2\text{ s}\), with the vehicle traveling at \(43.2\text{ mph}\), the ADS recognized an emergency and entered its one-second action-suppression period. The design withheld braking while it checked the hazard or waited for operator intervention. At \(T-0.2\text{ s}\), suppression ended. The ADS then initiated a plan for gradual slowdown and sounded an alert; it did not request emergency braking. The NTSB notes that communication delay leaves unclear whether that slowdown began before the operator disengaged the ADS at \(T-0.02\text{ s}\) (National Transportation Safety Board 2019).

Napkin Math 1.1: The kinematic stopping budget
  • Problem: Given the reported one-second suppression period and speed at its end, could idealized full braking beginning at \(T-0.2\text{ s}\) stop the vehicle before the impact point?
  • Assumptions: Approximate speed near hazard recognition as \(v_0 =\) 19.2 m/s, speed at \(T-0.2\text{ s}\) as 18.1 m/s (reported as \(40.5\text{ mph}\)), and idealized constant braking deceleration as \(a_{\text{brake}} =\) 8 m/s². Travel is computed at constant speed.
  • Suppression interval: Over the reported 1 s, holding \(v_0\) constant would give \(d_{\text{blind}} = v_0 t_{\text{suppress}} =\) 19.2 m. The vehicle was in fact slowing for a turn, so this is not measured suppression travel.
  • Braking comparison: From the rounded speed at \(T-0.2\text{ s}\), idealized stopping requires \(d_{\text{brake}} = v^2/(2a_{\text{brake}}) \approx\) 20.5 m. Holding that speed for the remaining \(0.2\text{ s}\) gives only about 3.6 m of travel to impact. Even immediate full braking at that late instant could not stop before the impact point. The ADS in fact planned gradual slowdown, not full braking (National Transportation Safety Board 2019).

Figure 8 draws the recorded event times and that braking comparison on one time axis, which places the one-second suppression interval directly against the stopping distance the vehicle needed at the moment suppression ended.

Timeline with detection at T minus 5.6 seconds, hazard recognition at T minus 1.2 seconds, one-second action suppression, gradual slowdown planned at T minus 0.2 seconds, and impact. A separate idealized braking comparison shows about 20.5 meters needed to stop versus about 3.6 meters of travel remaining at T minus 0.2 seconds.
Figure 8: Tempe ADS event timeline: NTSB recorded first detection at \(T-5.6\text{ s}\), hazard recognition and the start of one-second action suppression at \(T-1.2\text{ s}\), and a gradual-slowdown plan at \(T-0.2\text{ s}\). The lower comparison assumes a constant \(8\text{ m/s}^2\) deceleration from the recorded \(40.5\text{ mph}\) speed. Idealized stopping distance at \(T-0.2\text{ s}\) is about \(20.5\text{ m}\), far beyond the roughly \(3.6\text{ m}\) of constant-speed travel remaining.
NTSB side-view diagram of the Volvo test vehicle with colored outlines marking lidar, cameras, radar, ADS computing and data storage, and GPS equipment.
Figure 9: Tempe test vehicle sensor locations: The NTSB diagram identifies the developmental ADS vehicle’s lidar, camera, radar, computing, and telecommunications locations. (Source: NTSB, public domain).

War Story 1.1: The disabled safety redundancy (2018)
Context: On March 18, 2018, a developmental ADS on a 2017 Volvo XC90 struck and killed a pedestrian crossing a road in Tempe, Arizona (National Transportation Safety Board 2019).

Mechanism: As traced above, classification changes discarded the object’s tracking history, and the one-second suppression withheld braking until only a gradual slowdown was planned. The design did not use maximum braking solely to mitigate an unavoidable collision (National Transportation Safety Board 2019).

Impact: The vehicle struck and fatally injured the pedestrian. The late gradual-slowdown plan could not recover the lost stopping opportunity.

Response: The NTSB found that disabling the Volvo warning and braking systems, which Uber ATG had done over possible radar interference, removed a safety redundancy layer and recommended stronger safety risk management for testing automated vehicles (National Transportation Safety Board 2019).

Systems lesson: Classification uncertainty, a delayed response rule, and reliance on an inattentive operator can combine. A design needs timely hazard assessment and a response that can mitigate impact when avoidance is no longer possible; the investigation does not prescribe a particular processor or mailbox architecture.

The investigation supports a broader architectural requirement. A developmental ADS needs safety redundancy and a timely mitigation path even when perception or path prediction fails, and simulation tests by Volvo that the NTSB cites suggest that the factory emergency braking might have prevented or mitigated this collision. The report does not establish when a separate permission path would have triggered or where it would have stopped the vehicle.10

Tempe illustrates failure before impact, where classification changes and a software suppression delay prevented timely braking. The 2023 Cruise robotaxi incident (Quinn Emanuel Urquhart and Sullivan, LLP 2024) marks the opposite pole after impact, a post-collision fallback that moved the vehicle while a pedestrian was pinned beneath it (The Fallback Ladder).

Quinn Emanuel Urquhart and Sullivan, LLP. 2024. Report to the Boards of Directors of Cruise LLC, GM Cruise Holdings LLC, and General Motors Holdings LLC Regarding the October 2, 2023 Accident in San Francisco. Quinn Emanuel Urquhart; Sullivan, LLP.

Neither failure reduces to an inaccurate model. The first spent stopping distance before braking began, and no later action could recover it. The second chose motion after the impact. Together they show what must hold before the machine acts and what a fallback may do once harm has begun, and the four laws that follow state those demands for every machine.

Checkpoint 1.2: Forensics of boundary and authority failures

Before studying the four bedrock laws, verify your understanding of the failure mechanisms diagnosed in the Tempe incident:

The Four Bedrock Laws

Tempe’s lost second is the first law at work. That law and three others hold for every machine whose learned proposals can reach an actuator, and each leads a part of this book. Together they turn the causal boundary into requirements.

The first law: irreversibility. Physical work cannot be recalled, so every check must finish before actuation, inside the margin that delay has not yet consumed. An actuator converts electrical energy into motion, strain, or heat, and no software action removes it afterward. Braking can oppose momentum only by applying force over time and distance, and a deformed fixture stays deformed when its setpoint is reversed. Because the machine keeps moving while it computes, delay is paid in distance: every millisecond between capture and response is travel the stop can no longer use. Part I turns this law into budgets.

The second law: endogenous data. A physical agent’s actions choose its next observations, so competence holds only for the states a closed-loop test has covered. In an offline benchmark, a prediction does not change the next example. On a machine, an erroneous command moves the joints and the cameras and delivers the policy into states its demonstrations never showed. Under bounded per-step cost, the worst-case excess cost of a behavior-cloned policy grows as \(T^2\epsilon\) over a horizon of \(T\) steps with per-step disagreement \(\epsilon\) (Ross et al. 2011); Endogenous Experience develops the bound. The bound predicts no particular failure rate, but it shows why single-step accuracy cannot certify a closed loop. Part II asks what a learned proposer’s competence rests on.

Ross, Stéphane, Geoffrey Gordon, and Drew Bagnell. 2011. “A Reduction of Imitation Learning and Structured Prediction to No-Regret Online Learning.” Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics, 627–35.

Illustrative plot comparing a quadratic upper bound on cumulative cost with a linear reference as the episode horizon grows.

The behavior-cloning bound grows with the square of the horizon, against a linear reference.

The third law: proposal is not permission. A learned model may propose; only an independent path that the model cannot delay or corrupt may permit. The permission path decides every action on state of known age, within a deadline set by the plant, and owns a fallback it can execute without the proposer. Separate silicon is one way to build it. Hardware isolation within one chip is another, provided the response bound and the fault containment are demonstrated. Freshness is part of the test, because a proposal computed from an old observation describes a machine that has already moved. Part III builds the runtime around this law.

The fourth law: evidence bounds authority. Authority to act is granted on recorded evidence; it expires with that evidence, and a premise the evidence cannot settle must restrict operation. Average performance over finite trials cannot certify a tail whose failures are mechanical, and a demonstration is not evidence of safety. A release case instead bounds sensing, model error, actuator response, stopping clearance, and hardware faults for a declared operating domain, and it names what it leaves open. Part IV decides who may command the machine and which conditions it may enter.

The third law is the one the other three serve. Irreversibility makes permission necessary, endogenous data leaves the proposer’s competence partial, and evidence bounds how much authority the permission path may grant. Scaling the proposer does not relax the third law. Richard Sutton’s “bitter lesson” (Sutton 2019) holds that general methods that exploit growing computation eventually overtake engineered heuristics. On a machine, that lesson meets what this book terms the physical wall. Onboard compute is bounded by battery energy, heat dissipation, memory bandwidth, and the integrity of the supply rail, so added model size is paid for in delay. Once that delay outruns the stopping budget, the machine reaches the obstacle before the forward pass finishes. Supply, Freshness, and the Memory Wall measures what that wall leaves the machine’s proposers. In the terms of hardware protection rings, the learned model proposes from an unprivileged domain and the permission path refuses from a trusted one, with the difference that a refusal must also leave the machine a physical fallback, because no page fault stops a moving mass.

Sutton, Richard. 2019. “The Bitter Lesson.” Incomplete Ideas (Blog) 13 (1): 38.

Safety Convergence

Safety examines whether the machine caused harm. Security considers whether an external agent forced it. Accountability assesses whether an auditor can determine what occurred and why. In software services, these concerns reside in separate engineering organizations and distinct runtimes, divided by application logic, network firewalls, and audit logging databases. In a machine that moves mass and commands current, all three converge on the causal boundary, where the question becomes whether the permission path has the state and authority to refuse a register write before the command becomes torque acting on the plant.

Safety failures arise without an adversary. A camera lens accumulates dust over \(500\text{ h}\) of operation, shifting the input distribution away from the training domain until an attention head generates an out-of-distribution steering torque. A joint bearing develops mechanical play, introducing unmodeled backlash and joint compliance that converts a stable learned position trajectory into a destructive limit-cycle oscillation. A sudden change in surface friction can also drop tire traction below the friction coefficient assumed by the learned policy. In each case, the proposer generates an action that is statistically plausible to the network but physically hazardous to the body. If the permission path lacks an independent kinematic model or thermal budget to detect exceedance, the unrefused command writes to the motor drive registers, releasing stored kinetic energy into the workspace.

Security failures introduce an adversary who deliberately exploits the gap between statistical inference and physical reality. An attacker does not need to compromise cryptographic keys or gain root access on the host operating system if they can manipulate sensory inputs. Projected structured light can spoof a depth sensor, acoustic injection can resonate the micro-machined capacitive proof masses inside MEMS gyroscopes at their natural frequencies, tricking the sensor into reporting phantom angular velocity,11 or patterned stickers (adversarial visual perturbations) on a factory floor can induce a vision-language-action model (a learned policy that maps camera images and a language instruction to actuator commands) to output maximum actuator velocity. On a traditional server, an injection attack compromises data confidentiality or integrity within an abstract memory space. In physical AI, an injection attack commands physical work, turning an unvalidated inference into mechanical force. The security perimeter cannot terminate at the network interface or the operating system syscall boundary. It terminates at the permission path, which must evaluate every candidate command against physical invariants regardless of whether the proposer acted in good faith or under adversarial control.

Traditional software authorization models fail in physical machines because capability tokens and access control lists assume discrete, memoryless transactions. In a web service, possessing a valid credential grants permission to write a record to a database, and the cost of the operation is bounded by compute cycles and storage bytes. In physical space, permission is not a static binary entitlement. In an analytical robotic joint, a command to apply \(50\text{ N}\cdot\text{m}\) of torque is valid when the link is stationary at mid-stroke, but the identical command causes structural yield (shaft fracture or gear tooth shear) if the joint is \(2\text{ mm}\) from its hard stop moving at \(1.5\text{ rad/s}\). Physical authority is state-dependent, continuous, and dynamic, governed by velocity, momentum, thermal accumulation, and spatial occupancy. The permission path cannot evaluate an action in isolation as a stateless remote procedure call. It must integrate the action over time against the current physical state of the body, checking whether the proposed motion stays within a validated recoverable set12 for the plant, load, state-estimation error, and response deadline.

Accountability requires proving the exact causal chain that led to actuation when a machine damages hardware or breaches an envelope. In standard computing systems, logging is asynchronous, best-effort, and coarse-grained, dropping records during buffer pressure or recording timestamps with millisecond jitter. At the causal boundary, accountability demands deterministic, high-rate telemetry captured synchronously with the control loop. If a joint actuator commands \(1\text{ kHz}\) updates with a \(1\text{ ms}\) deadline, the permission path must record the raw candidate vector proposed by the model, the state estimate it judged against, the criterion it applied, and the exact vector written to the hardware registers. Sealing these records in tamper-evident, append-only circular buffers in battery-backed SRAM or FRAM (memory that survives a sudden power loss when a safety breaker trips) provides post-incident reconstruction. When an anomaly occurs, an engineer can verify mathematically whether the failure originated in a corrupted sensor reading, a degraded policy proposal, an erroneous permission rule, or a mechanical component that failed to produce the commanded counter-torque.

Safety, security, and accountability therefore ask the same three things of the permission path that guards the causal boundary: state fresh enough to judge the command, authority to refuse it, and a record of what was proposed, what was admitted, and what was written. Building that path, and the evidence that it does what its record claims, is the work of the rest of the book.

The Architecture of This Book

The four parts of the book pursue the question this chapter opened with. What the Four Laws Leave Open answers it in conditional form, each guarantee holding only while its premises do. Each part is led by one of the four laws, and every chapter of Parts I to IV except The Cognitive Brain closes by producing a record that a later chapter consumes (figure 10). Read in order, the records carry the argument forward: what the plant can do, what the learned proposer has shown it can do, what it proposes now, what the permission path admits, and what the evidence licenses. The first two of these run as one strand and the third as another, and the two strands meet at the permission decision, which is the third law in the form of an interface.

The Cognitive Brain produces a record that a later one consumes. What the plant can do and what the proposer has shown it can do run as one strand, what the proposer proposes now as another, and the two meet at the permission decision.">Flow diagram of fifteen record boxes, each labeled with its chapter number, on shaded bands for the four parts. A label at top left reads Chapter 1, What must be guaranteed. In the Part I band, labeled Irreversibility, the limit record of Chapter 2 feeds the handoff record of Chapter 4, and a dashed arrow labeled Chapter 3, proposer limits, also enters the handoff record. The handoff record forks into two rows. The upper row, in the Part II band labeled Endogenous data, runs provenance record 5, policy manifest 6, and evaluation record 7. The lower row, in the Part III band labeled Proposal is not permission, runs observation contract 8, belief record 9, intent lease 10, and trajectory record 11. Both rows converge on the enforcement record of Chapter 12, which feeds the placement record of Chapter 13. An arrow then runs down to a lower row in the Part IV band, labeled Evidence bounds authority: authority record 14, fault record 15, and release manifest 16, which feeds the residual-claims register of Chapter 17, labeled Conclusion and What the evidence supports. A separate arrow runs from the evaluation record around the top and right edges to the release manifest.
Figure 10: The spine of the book: Each part is led by one law, and each chapter of Parts I to IV except The Cognitive Brain produces a record that a later one consumes. What the plant can do and what the proposer has shown it can do run as one strand, what the proposer proposes now as another, and the two meet at the permission decision.

Part I, The Machine Anatomy, is led by the first law. The Physical Body measures the plant’s budgets and writes each one as a limit record, the root of the chain. The Cognitive Brain states what the learned proposer can supply and how quickly its evidence ages. The Nervous System derives the permission path’s rates and lease from the stopping budget and records every handoff in a handoff record that extends the limit record. Part II, Teaching the Machine, is led by the second law. Physical Data, Policy Training, and Closed-Loop Evaluation turn demonstrations into a provenance record, a policy manifest, and an evaluation record whose claims stay inside a declared operating domain and whose gaps are cataloged. Part III, Running the Machine, is led by the third law. Sensor Perception through Silicon Placement follow one command from a timestamped observation to a belief, an intent lease, a committed trajectory, an admitted command, and the silicon that keeps the permission path on time. Part IV, Governing the Machine, is led by the fourth law. Supervisory Intervention, Adversarial Verification, and Deployment Release decide who may command the machine, what the fault tests established, and which conditions the machine may enter. The Epistemic Frontier concludes the book with what the records support and a register of the premises that remain open. Every record is worked out on one machine, the warehouse mobile manipulator introduced in section 1.3.

Fallacies and Pitfalls

Each misconception below imports an assumption that holds for software, for offline learning, or for classical control into a machine whose learned proposals can reach an actuator. The first assumes that training can do the permission path’s work, and the other three assume that a human can intervene instantly, that latency only degrades performance, or that physical work can be undone.

Fallacy: Safety constraints can be trained into the policy.

Reinforcement and imitation learning pipelines often try to make a policy safe by adding penalty terms, barrier losses, or negative reward shaping to its objective. These terms steer gradient descent and lower the frequency of undesirable states across the training distribution, but they do not bound what the deployed policy emits. Under novel sensor noise, a lens occlusion, or an out-of-distribution combination of states, nothing in the offline objective prevents an unsafe command. A training incentive shapes a probability distribution, whereas a stopping envelope requires a bound that holds on every cycle. The constraint therefore belongs downstream of the model, as a gate between the policy output and the actuator registers, which is where the third law places the permission path.

Pitfall: Treating human supervisory intervention as instantaneous in shared-autonomy systems.

A surgical tool applies haptic guidance force feedback from a learned anatomical model while a surgeon holds the instrument. Human supervision does not remove delegated authority during the interval before the surgeon can respond. If an actuator builds force faster than the stated human reflex interval of \(150\text{--}250\text{ ms}\), its commands can deform tissue before the operator corrects them. The engineering question is how much force the system can apply during that interval. Local force limits enforced by the permission path must constrain the actuator without depending on either a timely neural prediction or an immediate human response.

Pitfall: Assuming software latency merely degrades performance gracefully.

Suppose the machine’s chunk policy stalls for 300 ms while its memory subsystem throttles. The computation pauses, but physical momentum ensures the base keeps moving. A base that kept executing its last proposal at 1.5 m/s would travel blind for 450 mm before the next command arrived, and that displacement can consume the clearance it needs to stop if a person steps out. The machine does not allow that blind travel. A lease bounds how long the base may act on the last proposal, and when it expires the permission path brakes whether or not a new proposal has arrived, so the stopping envelope holds while the deliberative policy is unavailable. Multi-Rate Cadences sizes that lease from the stopping budget, and The Authority to Refuse prices one held too long.

The physical reality of this constraint is governed by the kinematic roofline: stopping envelope \(d_{\text{stop}} = v \tau + \frac{v^2}{2 a_{\max}} \le R_{\text{sensor}}\) under emergency braking (figure 11). Across fifty years of autonomous systems, every order-of-magnitude reduction in sense-to-act loop latency \(\tau\) unlocked a corresponding expansion in safe operational speed \(v\), from the stop-and-plan deliberation of Shakey (\(\tau \approx 30\text{ s}, v = 0.18\text{ km/h}\)) and the Stanford Cart (Moravec 1988), through the early neural vision of ALVINN (Pomerleau 1989), to modern autonomous vehicles operating at highway velocities.

Figure 11: The causal boundary: sense-to-act loop latency versus safe vehicle operating speed (1970–2026): The kinematic roofline dictates maximum safe operational speed \(v\) as a function of total round-trip control loop latency \(\tau\) and emergency deceleration (\(a = 6.86\text{ m/s}^2\), \(0.7\text{ g}\)) across four sensor horizons \(R\). Historical milestones from SRI Shakey (1970) and Stanford Cart (Moravec 1988) through CMU Navlab (Pomerleau 1989), the DARPA Grand Challenges, and modern autonomous fleets demonstrate how latency reductions directly expand the safe physical operating envelope.
Pomerleau, Dean A. 1989. “ALVINN: An Autonomous Land Vehicle in a Neural Network.” Advances in Neural Information Processing Systems (NeurIPS) 1: 305–13.

Fallacy: Assuming physical actions can be rolled back like database transactions.

A manipulator applies an erroneous \(50\text{ N}\cdot\text{m}\) torque to a delicate fixture. Its monitor detects the anomaly \(50\text{ ms}\) later and reverses the motor command. Reversing a command cannot restore a fixture that has already plastically deformed or recover the energy already dissipated as physical heat in the motor windings (\(I^2 R\)). Detection can limit further damage, but it cannot erase the intervening physical work. The control architecture must therefore check commands against force and motion limits before execution. Recovery remains necessary, but it complements preventive enforcement rather than replacing it.

Summary

The causal boundary marks the physical and electrical threshold where digital bits convert irreversibly into kinetic momentum, contact force, and Joule heat at memory-mapped actuator registers. Past this boundary, computational abstraction ends. Latency is paid in unguided physical displacement, so the chapter’s requirements on timing and authority place the check before the register write rather than after it.

Key Takeaways: The causal boundary invariant
  • Delay is paid in distance: A permitted command becomes motion and heat that no later software action recalls, and a moving machine travels \(v\,\tau_{\text{delay}}\) before braking begins. On the warehouse mobile manipulator at its drive limit, that blind travel adds 35.6 percent to the braking distance.
  • The binding budget sets the deadline: Mass-dominated machines exhaust stopping clearance first, contact-dominated machines exhaust force, and flow-dominated machines exhaust thermal or phase margin. The shortest time to failure fixes the deadline the independent check must meet, and a humanoid couples all three.
  • Scope requires all three criteria: A learned component, consequential physical feedback, and delegated authority together make a machine physical AI. An independent veto does not remove delegated authority; mandatory human approval of each action does.
  • Proposal is not permission: In the five-level machine, the Brain’s learned proposers may only propose, and the permission path in the Nervous System admits, modifies, or refuses each proposal against current state and owns a fallback that does not wait for the proposer. Safety, security, and accountability meet at that path, which also records what it admitted.
  • Physical failures combine: At Tempe, classification changes, a designed one-second braking suppression, and reliance on an inattentive operator interacted, and the factory emergency braking that might have mitigated the impact had been disabled. No single component’s accuracy explains the outcome, which is why the requirements fall on timing, response, and redundancy.
  • Four laws organize the book: Irreversibility, endogenous data, proposal is not permission, and evidence bounds authority each lead one part of the book. The third law is the one the other three serve, and the records the later chapters produce carry each law forward on the warehouse mobile manipulator.

What’s Next: From the causal boundary to physical limits
With the five-level machine and the four laws in place, Part I begins with the first law. This chapter took the machine’s speed, braking deceleration, and contact stiffness as given, yet every deadline the permission path must meet is derived from them. The Physical Body asks which physical limits actually bound the machine, how each one is measured, and under what conditions it holds, and it writes each limit down as a limit record, the first record in the chain the rest of the book extends.

Back to top

Footnotes

  1. Moravec’s Paradox: The observation in artificial intelligence (Moravec 1988) that high-level reasoning requires comparatively little computation, whereas low-level sensorimotor coordination demands enormous perceptual and computational resources.↩︎

  2. Cybernetic Feedback Loops: In Norbert Wiener’s cybernetic framework (Wiener 1948), feedback denotes adjusting future action using past performance.↩︎

  3. Idempotency: Repeating an idempotent operation has the same specified result as executing it once. A motor setpoint command can have idempotent command semantics, but repeated execution may still dissipate energy. Idempotency does not imply reversibility or harmlessness.↩︎

  4. Action Chunk Representations: In robot learning literature (Zhao et al. 2023), action chunks are typically tensors of shape \([B, H, d_a]\) where \(B\) is batch size, \(H\) is the planning prediction horizon, and \(d_a\) is action dimension (such as target joint positions \(\hat{\mathbf{q}} \in \mathbb{R}^d\) or 3D Cartesian position and orientation deltas). The formal Lie group formulation (\(SE(3)\)) is deferred to Spatial coordinate frames and lever-arm kinematics; The Cognitive Brain defines the chunk and its horizon.↩︎

  5. Automotive Serializer/Deserializer (SerDes): High-speed physical-layer links (such as FPD-Link or GMSL) that transport uncompressed, low-latency multi-gigabit video streams over lightweight coaxial or shielded twisted-pair cables. Combined with dedicated hardware trigger lines, SerDes interfaces ensure microsecond-synchronized shutter capture across the sensor ring. For bus specifications, see Systems and Hardware.↩︎

  6. Thermodynamic Limits of Computation: At a fundamental level, Landauer (1961) established that erasing logical bits dissipates at least \(k_B T \ln 2\) of heat per erased bit. In physical AI systems, however, the dominant irreversibility is macroscopic: motor inverters draw tens of Amperes from battery packs, dissipating kilowatt-scale Joule heat (\(I^2 R\)) and imparting momentum to moving linkages.↩︎

  7. Rigid Contact Mechanics: Unilateral physical contact is fundamentally one-way: an end-effector can push against an obstacle, but it cannot pull without gripping. Modeling rigid contact mathematically leads to Linear Complementarity Problems (LCPs), where abrupt collisions create impulse chatter and non-smooth forces. Real-time physical systems avoid chatter through compliant impedance models (\(F = k \Delta x\)); the complete mathematical formulation of contact complementarity is deferred to Rigid Body Contact Mechanics.↩︎

  8. 2018 Tempe Autonomous Collision: The event times and design details in this section come from NTSB highway accident report NTSB/HAR-19/03 (National Transportation Safety Board 2019).↩︎

  9. Tracking History: A path predictor can estimate motion from successive object locations. In the Tempe ADS, a changed classification caused the predictor to omit earlier locations; the NTSB report does not specify a Kalman-filter reset or a zero-velocity initialization (National Transportation Safety Board 2019).↩︎

  10. Safety-Critical Standards: Functional safety and intended-functionality standards can inform the safety case for sensing, actuation, and fallback. Their applicability and required implementation depend on the system and jurisdiction; the NTSB Tempe report did not mandate an isolated microcontroller architecture.↩︎

  11. MEMS Acoustic Resonance: Resonant acoustic frequencies (\(18\text{--}32\text{ kHz}\)) can physically vibrate the micro-machined capacitive proof masses inside MEMS gyroscopes, inducing signal saturation and false rate readings. Hardening against acoustic spoofing requires physical damping barriers and real-time kinematic cross-validation on the microcontroller.↩︎

  12. Recoverable Sets: A modeled set of physical states (positions, velocities, and temperatures) from which an admissible controller can keep the plant within specified bounds under stated disturbances and actuator limits (Mitchell et al. 2005). Admission against this set is meaningful only while those state, plant, and timing premises hold.↩︎

Moravec, Hans. 1988. Mind Children: The Future of Robot and Human Intelligence. Harvard University Press.
Wiener, Norbert. 1948. Cybernetics: Or Control and Communication in the Animal and the Machine. John Wiley & Sons.
Zhao, Tony Z., Vikash Kumar, Sergey Levine, and Chelsea Finn. 2023. “Learning Fine-Grained Bimanual Manipulation with Low-Cost Hardware.” Robotics: Science and Systems (RSS). https://doi.org/10.15607/RSS.2023.XIX.016.
Landauer, Rolf. 1961. “Irreversibility and Heat Generation in the Computing Process.” IBM Journal of Research and Development 5 (3): 183–91. https://doi.org/10.1147/rd.53.0183.
National Transportation Safety Board. 2019. Collision Between Vehicle Controlled by Developmental Automated Driving System and Pedestrian, Tempe, Arizona, March 18, 2018. HAR-19/03. National Transportation Safety Board.
Mitchell, Ian M., Alexandre M. Bayen, and Claire J. Tomlin. 2005. “A Time-Dependent Hamilton-Jacobi Formulation of Reachable Sets for Continuous Dynamic Games.” IEEE Transactions on Automatic Control 50 (7): 947–57. https://doi.org/10.1109/TAC.2005.851439.