Multi-Rate Cadences plus the observation age of Sensor Perception; at 912.9 mm it still fits, although later chapters add a stop profile and a tracking bound. Case 3 raises speed to a hypothetical 2 m/s, above the drive limit, with the same delay; braking travel grows by 77.8 percent and the stop, at 1,417.2 mm, breaches the clear distance.">
The Physical Body
The Physical Body
Purpose
What physical limits bound a learned policy the moment its outputs command motors and moving mass?
A moving machine cannot pause for software. During inference, the physical world advances: positions change, contact surfaces shift, and observations age. Arresting physical motion requires finite time to process a command and finite distance to dissipate kinetic energy. Electric motors and mechanical gearsets strictly constrain how quickly torque can ramp, while winding currents and inverter switching losses continuously heat electromagnetic coils. Policies that ignore these constraints request impossible forces, trigger supply-rail voltage collapses, or shear transmission gear teeth. Faster neural inference helps only within this physical chain; it cannot eliminate braking distance, mechanical inertia, or thermal limits.
Physical artificial intelligence demands that these limits be measured on the fully assembled machine under operational loads, rather than transcribed from optimistic component datasheets. At the causal boundary, the Body establishes the hard physical budgets—clearance distance, peak force, and thermal headroom—that perception, planning, and control must share. Under the first bedrock law, every such budget must be verified before an action command is issued. By characterizing the mechanical plant’s torque-speed curves, friction cones, and thermal dissipation rates, systems engineers ground learned proposals in the uncompromising physics of the physical plant.
↰ Prerequisite: The physical plant grounds the three machine classes defined in Three Machine Classes.
Learning Objectives
- Calculate observation freshness limits from measurement age and the machine’s allowable motion
- Calculate stopping distance and the admissible speed ceiling from pre-brake delay, credible deceleration, and clearance overheads
- Evaluate actuator and transmission choices against response limits and reflected inertia
- Estimate sustainable motor duty cycles from heat generation, cooling, and operating conditions
- Budget electrical supply margins for simultaneous actuation, computation, and regenerative braking
- Specify the elements of a limit record that states a measured limit’s conditions, uncertainty, margin, runtime detector, and evidence category
The Five Physical Budgets
A robotic manipulator can shatter its transmission even after receiving an emergency stop command before contact. The stop command traverses software buffers, the power inverter switches states, and the motor generates peak reverse torque. Yet if the moving link possesses kinetic energy exceeding the mechanical work the actuators can perform over the remaining clearance, impact is unavoidable. In pure software, a faulted thread can be killed instantly by the operating system kernel. In physical reality, moving mass carries momentum that cannot be caught by an exception handler, and an electrical power stage cannot deliver infinite current without thermal destruction or voltage collapse. Software cannot override the physics of moving mass, heat, and current.
Above the proposal boundary, a learned policy may propose any motion, but the physical body delivers only what mechanics, thermodynamics, and electromagnetism allow. That body is the plant of actuators, transmissions, linkages, power buses, and transducers that acts on the world, and every setpoint the policy issues draws against five of its physical budgets:
- Measurement freshness: The rate at which the physical environment changes relative to the age of the sensor data reaching the controller. Because the world does not pause for computation, elapsed time during communication and inference means the machine always acts on historical state.
- Kinetic momentum: The stopping distance and braking force required to dissipate stored kinetic energy (\(E_k = \frac{1}{2} m v^2\)) before colliding with obstacles or exceeding workcell boundaries.
- Actuator bandwidth and reflected inertia: The speed at which mechanical torque and velocity can change before winding inductance (\(\tau_e = L/R\)), inverter current clamps, or gear transmission inertia (\(N^2 J\)) choke mechanical acceleration.
- Thermal capacity: The rate at which resistive Joule heat accumulates in stator coils and power semiconductors relative to the chassis dissipation rate, bounding sustained duty cycles before thermal throttling intervenes.
- Electrical power integrity: The transient voltage droop, peak current capacity, and regenerative energy surges across the shared direct-current distribution bus during rapid acceleration and braking.
The warehouse mobile manipulator that this book follows draws on all five. Loaded to at most 368 kg and moving at its 1.5 m/s drive limit (illustrative; see the Reader Guide), it carries 414 J of kinetic energy through aisles it shares with people.
Each budget becomes a limit established on the assembled machine under declared thermal and electrical stress. The first is the age of the measurement on which every command rests, which runs from physical transduction, before any software process receives the data.
Measurement Freshness
Software benchmarks often report latency as the execution time of a network on an accelerator, but that compute slice is only one segment of the causal chain of The Causal Boundary. A measurement decays from transduction; what matters is its age when acted upon. That age spans the interval from the moment photons strike a photodiode or flux passes a Hall sensor to the moment motor coils generate torque that changes a link’s acceleration. If a perception model computes an obstacle location in \(15\text{ ms}\) but camera integration, sensor readout, transport, queue dispatch, and motor current rise time add another \(45\text{ ms}\), the physical age of the measurement when the joint moves is \(60\text{ ms}\). During that entire window, the physical world has continued to evolve.
↳ Downstream: Belief Through Occlusion derives how long a stored belief stays valid as its measurement ages.
Tracking measurement age means decomposing that path into eight stages (figure 1): exposure, timestamped at the midpoint of integration; sensor readout over an interface such as MIPI CSI-2; direct memory access (DMA) transport into host memory; kernel buffering into user-space queues; model computation; operating-system scheduling and inter-process dispatch across the processor boundary; command transmission over a fieldbus or shared-memory mailbox; and actuator response, as the drive builds flux in the stator windings. On a two-processor implementation the path runs from the image sensor through inference on the application processor, a lock-free mailbox, and a \(1\text{ kHz}\) permission check on the safety microcontroller, to gate-driver switching and current rise. Every stage consumes a slice of the total time budget.
The rate of world-state change dictates how long a measurement remains valid before acting on it introduces intolerable error. Let \(e_{\max}\) denote the maximum acceptable error in a tracked state, such as a joint angle or the position of a part on a conveyor, and let \(v_{\max}\) denote the fastest credible velocity at which that state can evolve. The freshness deadline \(\Delta t_{\text{fresh}}\) is the upper bound on measurement age before a control action based on that measurement becomes invalid, defined by the inequality \[\Delta t_{\text{fresh}} \le \frac{e_{\max}}{v_{\max}}\]
For a vision-guided picker on a parcel sorter, tracking parcels at a maximum relative velocity \(v_{\max} = 1.2\text{ m/s}\) with a geometric clearance tolerance \(e_{\max} = 24\text{ mm}\), the freshness deadline is \(24\text{ mm} / (1200\text{ mm/s}) = 20\text{ ms}\). If an actuation command reaches the motor based on an image captured \(35\text{ ms}\) earlier, the parcel has displaced by \(42\text{ mm}\), exceeding the position allowance by \(18\text{ mm}\) and missing the grasp. The deadline governs a target that keeps moving while its measurement ages, such as the parcel here or the mug riding the mobile manipulator’s pick-station conveyor. For such a target it limits only motion-induced error, and only while relative velocity is bounded and the initial observation is credible; sensing and estimation errors consume additional tolerance. A person standing in the aisle does not move while the observation ages. The base does, so the age appears as distance the base covers before braking, which section 1.3 charges against the stopping budget.
Engineers often compute total latency by summing the \(P_{99}\) values of individual stages, but the percentile of a sum is not the sum of the percentiles.1 Shared memory contention and kernel queues can correlate stage delays, so the distribution of complete sense-to-torque age must be measured on the integrated machine under declared load, and even that measured percentile is not the analyzed bound a safety deadline needs (Moving Commands on Time).
To see how stage timing differs from end-to-end age, consider a timing profile for the camera-to-joint path under continuous inference load (table 1), judged against the same \(20\text{ ms}\) deadline.
| Pipeline Stage | Physical Mechanism / Contention Source | \(P_{50}\) (ms) | \(P_{99}\) (ms) | Max (ms) |
|---|---|---|---|---|
| 1–2. Sensor Exposure & Readout | \(60\text{ Hz}\) rolling shutter exposure midpoint | \(11.2\) | \(16.6\) | \(16.7\) |
| 3–4. Host Transport & DMA | PCIe DMA transfer into host memory | \(1.4\) | \(3.2\) | \(6.8\) |
| 5. Vision Backbone & Policy | Onboard accelerator inference (memory throttling tail) | \(18.5\) | \(24.1\) | \(38.4\) |
| 6. OS Scheduling & IPC | Kernel preemption and mailbox dispatch to safety microcontroller | \(0.6\) | \(2.1\) | \(12.3\) |
| 7. Fieldbus Transmission | Deterministic EtherCAT cyclic packet exchange | \(1.0\) | \(1.0\) | \(2.0\) |
| 8. Actuator Current Rise | Gate driver switching and stator flux buildup | \(2.3\) | \(3.0\) | \(4.5\) |
| Arithmetic Stage Sum | Sum of each column’s stage values; not an end-to-end quantile | 35.0 | 50.0 | 80.7 |
| End-to-End Age | System-level profile (\(t_{\text{transduction}} \to \tau\)) | 35.0 | 46.2 | 80.7 |
The \(50.0\text{ ms}\) sum of stage \(P_{99}\) values differs from the \(46.2\text{ ms}\) system percentile, and against the \(20\text{ ms}\) deadline even the \(35.0\text{ ms}\) median would be late.
Acting on expired data adds phase lag to the feedback loop and can excite chatter when corrective torques reinforce rather than damp tracking errors,2 so a high inference rate does not by itself make the response timely. The system must carry a hardware timestamp from transduction (using IEEE 1588 gPTP3 or hardware strobe capture at the Ethernet PHY / MIPI CSI-24 interface) through the pipeline. Before applying a policy command, the permission path compares the observation age \(t_{\text{age}} = t_{\text{now}} - t_{\text{transduction}}\) with the age its budget allows. If the age exceeds that limit, it rejects the stale proposal and executes a fallback whose braking or holding behavior has been validated within the remaining physical margin (Brooks 1986).
Throughout that sense-to-actuation interval, the body continues moving, carrying momentum that no software interrupt can cancel.
Kinetic Momentum
The loaded mobile manipulator drives down an aisle at its 1.5 m/s drive limit. A person steps out from the end of a rack 1.10 m ahead and stands in the aisle. Software cannot simply pause execution or instantaneously zero the velocity vector. The base, the arm, and the totes carry mechanical momentum, and bringing that mass to rest requires dissipating kinetic energy across physical distance. Stopping distance grows linearly with delay and quadratically with speed, and that difference sets the speed limit.
The distance from sensing a hazard to zero velocity comprises two phases: blind travel and braking travel. During the pre-brake delay, the machine runs the pipeline of section 1.2. Throughout this delay \(\tau_{\text{delay}}\), which runs from the exposure of the frame that shows the hazard until retarding force begins, the actuators apply no retarding force, and the vehicle continues moving along its existing trajectory at its speed \(v\) when that frame is exposed. Assuming velocity remains constant across this window, the blind travel evaluates to \[d_{\text{blind}} = v\,\tau_{\text{delay}}\]
Once the brake command arrives and the actuators engage, the body enters the braking phase. The mechanical work done by the braking force \(F_{\text{brake}}\) over the braking distance \(d_{\text{brake}}\) must dissipate the initial kinetic energy of the machine, \(W = \Delta K\). For a machine of mass \(m\) decelerating to rest under a sustained retarding force \(F_{\text{brake}} = m a_{\text{brake}}\), the work-energy balance yields \[m a_{\text{brake}} d_{\text{brake}} = \frac{1}{2} m v^2\] Dividing by mass and solving for distance gives the kinematic braking travel \[d_{\text{brake}} = \frac{v^2}{2 a_{\text{brake}}}\] The parameter \(a_{\text{brake}}\) is the credible deceleration the body can actually exert against the physical environment, not a theoretical peak rating printed on an actuator datasheet. It represents the sustained negative acceleration the mechanical structure, tires, and gears can produce before losing grip (tire-road shear slip saturation), tipping forward, or structural drive-train yield.
The closed form assumes constant deceleration, instantaneous torque buildup, zero grade, and rigid contact. Each fails on hardware, since force takes time to build, tire friction falls during slip, and structure deflects, so on grades or uncertain floors the model underestimates the stop. Loaded stopping trials across the declared conditions supply a conservative low-tail deceleration, with uncertainty and margin, to replace the idealized \(a_{\text{brake}}\); a sample percentile alone is not a hard lower bound.
↳ Downstream: Unmanaged kinetic momentum translates directly into the destructive contact shock loads analyzed in section 1.4.
The differing exponents of the blind-travel and braking terms make velocity the dominant multiplier of spatial risk (figure 2), a scaling that 1.1 works numerically.
In unstructured environments, a machine cannot allocate its entire clearance to nominal stopping dynamics. Obstacle tracking carries state estimation uncertainty, sensor calibration drifts over time, and localization algorithms introduce position error. The stopping distance \(d_{\text{stop}}\) that the system defends must therefore include a spatial localization uncertainty bound \(\delta_{\text{loc}}\) and a minimum physical clearance margin \(\delta_{\text{margin}}\):5
\[d_{\text{stop}} = v\,\tau_{\text{delay}} + \frac{v^2}{2 a_{\text{brake}}} + \delta_{\text{loc}} + \delta_{\text{margin}} \tag{1}\]
The sum \(\delta_{\text{loc}} + \delta_{\text{margin}}\) is fixed spatial overhead that must remain unoccupied when the body comes to a complete rest.
Definition 1.1: Dynamic stopping distance
Dynamic stopping distance (\(d_{\text{stop}}\)) is the minimum physical clearance required to bring a moving mass to a complete halt from its speed \(v\) when the hazard is first imaged. It sums the travel during the pre-brake delay \(\tau_{\text{delay}}\), which runs from the exposure of the frame that shows the hazard until retarding force begins; the braking travel under the credible deceleration \(a_{\text{brake}}\); and the localization bound \(\delta_{\text{loc}}\) and protective clearance \(\delta_{\text{margin}}\), as equation 1 states.
- Significance: Quantifies the non-negotiable physical spatial margin that software proposals must clear before motion permission can be granted.
- Distinction: Unlike static geometric obstacle clearance in classical kinematics, dynamic stopping distance grows quadratically with speed (\(v^2\)), so doubling velocity quadruples the braking term whatever the controller loop rate.
- Common pitfall: Assuming an emergency stop command halts the machine instantaneously, ignoring that moving mass carries kinetic energy (\(E_k = \frac{1}{2}m v^2\)) that requires finite mechanical work and braking distance to dissipate.
For a stationary obstacle detected at distance \(D_{\text{clear}}\), such as a person standing at the rack end or a dropped tote, the modeled stopping distance must fit the clear path, \(d_{\text{stop}} \le D_{\text{clear}}\). This is the condition that principle \(\ref{pri-vol4-irreversibility}\) places on every stop, now with each term of \(d_{\text{stop}}\) a limit of this machine. With conservative timing and braking bounds, the permission path can solve this inequality for a ceiling on new velocity proposals \(v_{\text{max}}\). The positive root of the quadratic inequality6 is: \[v_{\text{max}} = -a_{\text{brake}} \tau_{\text{delay}} + \sqrt{(a_{\text{brake}} \tau_{\text{delay}})^2 + 2 a_{\text{brake}} (D_{\text{clear}} - \delta_{\text{loc}} - \delta_{\text{margin}})}\] When sensor range degrades or an obstacle enters the trajectory, \(D_{\text{clear}}\) contracts and lowers the ceiling, provided the available distance remains nonnegative. At zero available distance the ceiling is zero. If the machine is already moving, however, a zero setpoint cannot remove its current stopping distance; a negative available distance means the admission condition is already violated and requires an emergency response.
Napkin Math 1.1: The body's stopping distance
1. Braking travel: Mass cancels from the work-energy balance, so the loaded machine’s 414 J of kinetic energy sets how much heat the brakes must absorb but not how far the base travels: \[d_{\text{brake}} = \frac{v^2}{2 a_{\text{brake}}} = \frac{(1.5 m/s)^2}{2 \times 2 m/s²} = 562.5 mm\] The stopping distance so far is 562.5 mm.
2. Fixed overhead: \[\delta_{\text{loc}} + \delta_{\text{margin}} = 50 mm + 100 mm = 150 mm\] The running total rises to 712.5 mm.
3. Brake onset: Between the brake command and the first retarding force, the base still moves at full speed: \[v\,T_{\text{act}} = (1.5 m/s) \times (20 ms) = 30 mm\] \[d_{\text{stop}}\big|_{\text{body}} = 562.5 mm + 150 mm + 30 mm = 742.5 mm\] The body’s own terms leave 357.5 mm of the 1.10 m clear distance for every delay the body does not own.
4. The body-only ceiling: Solving equation 1 for speed with \(\tau_{\text{delay}} = T_{\text{act}}\): \[v_{\max} = -a_{\text{brake}} T_{\text{act}} + \sqrt{(a_{\text{brake}} T_{\text{act}})^2 + 2 a_{\text{brake}} (D_{\text{clear}} - \delta_{\text{loc}} - \delta_{\text{margin}})} \approx 1.91 m/s\] The body alone would permit 1.91 m/s, above the drive limit. The Nervous System and Sensor Perception add the delay terms that spend part of this headroom.
5. Speed against delay: At a hypothetical 2 m/s, above the drive limit, the braking term alone grows to 1,000 mm, 77.8 percent more than at the drive limit. At the drive limit, each additional 100 ms of pre-brake delay adds 150 mm.
Architect’s Rule of Thumb: Never raise a velocity setpoint without re-solving the clearance quadratic.
Example 1.1: Dynamic velocity ceiling governor
Inputs:
- \(D_{\text{clear}} \in \mathbb{R}_{\ge 0}\): Detected obstacle distance along travel vector \([\text{m}]\).
- \(\tau_{\text{delay}} \in \mathbb{R}_{> 0}\): Conservatively bounded sense-to-braking delay, including actuator response \([\text{s}]\).
- \(a_{\text{brake}} \in \mathbb{R}_{> 0}\): Conservative lower bound on available brake deceleration under the declared load and surface \([\text{m/s}^2]\).
- \(\delta_{\text{loc}}, \delta_{\text{margin}} \in \mathbb{R}_{\ge 0}\): Localization uncertainty bound and physical clearance margin \([\text{m}]\).
- \(v_{\text{now}} \in \mathbb{R}_{\ge 0}\): Current forward speed \([\text{m/s}]\).
- \(v_{\text{cand}} \in \mathbb{R}_{\ge 0}\): Candidate forward velocity setpoint proposed by neural policy \([\text{m/s}]\).
Output:
- \(v_{\text{safe}} \in \mathbb{R}_{\ge 0}\): Clamped velocity request within the modeled ceiling \([\text{m/s}]\).
Admission Check (while the current state is feasible):
- Modeled stopping distance: \(d_{\text{stop}}(v_{\text{safe}}) = v_{\text{safe}} \tau_{\text{delay}} + \frac{v_{\text{safe}}^2}{2 a_{\text{brake}}} + \delta_{\text{loc}} + \delta_{\text{margin}} \le D_{\text{clear}}\) for a stationary obstacle.
- Non-Negativity: \(v_{\text{safe}} \ge 0.0\).
Algorithm Steps:
Compute available physical braking distance: \[D_{\text{avail}} \leftarrow D_{\text{clear}} - \delta_{\text{loc}} - \delta_{\text{margin}}\]
If \(D_{\text{avail}} \le 0.0\), reject the proposal; hold at zero if stationary, or request the maximum available risk-reducing brake response if moving, and flag lost clearance. Otherwise check \(v_{\text{now}}\tau_{\text{delay}} + v_{\text{now}}^2/(2a_{\text{brake}}) \le D_{\text{avail}}\) before admitting another proposal. If that check fails, request the same emergency response and flag lost feasibility. A zero velocity setpoint cannot stop existing motion immediately.
Compute quadratic discriminant: \[\text{disc} \leftarrow (a_{\text{brake}} \tau_{\text{delay}})^2 + 2 a_{\text{brake}} D_{\text{avail}}\]
Solve positive physical root for dynamic velocity ceiling: \[v_{\max} \leftarrow -a_{\text{brake}} \tau_{\text{delay}} + \sqrt{\text{disc}}\]
Enforce dynamic clamping against policy proposal: \[v_{\text{safe}} \leftarrow \min(v_{\text{cand}}, \max(0.0, v_{\max}))\]
Return \(v_{\text{safe}}\).
The quadratic turns a fixed speed limit into a clearance-dependent ceiling for new proposals, but the ceiling preserves stopping feasibility only if the machine enters each control cycle inside the feasible set and can apply the assumed brake force within the bounded delay. Control Barrier Functions (CBF-QP) (Ames et al. 2019) extend this reasoning to more general systems under valid dynamics, state estimates, timing bounds, and feasible control authority; the 1D root here is a simplified kinematic admission check. If range degrades or delay exceeds its bound, the permission path must reduce speed before margin is exhausted or execute a defined risk-reducing fallback.
Enforcing this speed limit assumes the permission path can demand the deceleration \(a_{\text{brake}}\) whenever safety requires it. Yet commanding rapid deceleration requires sudden, large mechanical torque from the drive motors and gearboxes. If the permission path requests a torque step that exceeds what the actuator bandwidth budget allows, the mechanical body cannot deliver the required deceleration, invalidating the model-based stopping ceiling and risking collision.
Actuator Transmission Limits
An electromechanical actuator has no error return. When a policy commands a torque step beyond what the magnetic field can generate, or a discontinuous acceleration the gear teeth cannot carry, the actuator pulls maximum phase current from the power stage, twists its shafts, and strains its teeth while the command registers continue to report nominal execution. An actuator may damage itself instead of reporting an error.
An actuator contract cannot be specified in terms of digital setpoints. It must be written at the physical interface in terms of delivered force, torque, or mass flow, response latency, slew rate limits, and output error. A digital setpoint is merely a software request; physical action is bounded by winding inductance, bus voltage ceilings, magnetic saturation, and transmission elasticity.
The delay between commanding a torque and delivering it begins in the stator windings. Because the coils have inductance, current, and with it torque, rises along the motor’s electrical time constant rather than instantaneously (Systems and Hardware derives the RL response). A policy that assumes torque appears at once spends that rise as unguided drift before the arm can correct or brake.
Field-oriented control (FOC) synthesizes this torque on dedicated drive silicon at \(10\text{--}25\text{ kHz}\).7 Torque is proportional to current (\(\tau = K_t I\)), but the rate at which current can rise is bounded by the bus voltage headroom: \[\frac{di}{dt} \le \frac{V_{\text{bus}} - e_{\text{bemf}}}{L}\] As the rotor spins, the motor also acts as a generator whose back-electromotive force (\(e_{\text{bemf}} = K_e \omega\)) opposes the supply. At low speed the headroom \(V_{\text{bus}} - e_{\text{bemf}}\) permits a fast current rise and full peak torque. As \(\omega\) approaches its base rating, back-EMF consumes the headroom, and the inverter can no longer force current through the winding inductance whatever its duty cycle, so a policy that commands hard acceleration at high speed does not get the torque step it asks for.
Headroom limits how fast the current can rise; the drive electronics limit how much of it can flow at all. Power inverters enforce a maximum current ceiling \(I_{\text{max}}\) to protect switching transistors from thermal destruction and to prevent ferromagnetic saturation in the stator core. When the motor drives a mechanical transmission with gear reduction ratio \(N\) and transmission efficiency \(\eta\), the ceiling on delivered output torque is: \[\tau_{\text{out, max}} = \eta N K_t I_{\text{max}}\]
The clamp answers the question the stopping budget left open, whether the drives can deliver \(a_{\text{brake}}\) when the permission path demands it, and it answers silently. A braking demand above \(\tau_{\text{out, max}}\) is clipped at the power stage without any report to the software that issued it, so the base decelerates more gently than the stopping distance assumed and comes to rest beyond its calculated boundary. The credible deceleration therefore holds only for the drive current limits configured when it was established, and a firmware change to \(I_{\max}\) withdraws it until it is measured again, a dependence that section 1.7 writes into the conditions of its limit record.
Only part of that clamped current produces torque, and field-oriented control separates it by a change of coordinates. In a surface-magnet motor only stator current whose field is perpendicular to the rotor flux produces torque, so the drive reads rotor angle from an encoder and rotates the three measured phase currents into the rotor-fixed \(dq\) frame, where the quadrature current \(I_q\) produces torque and the direct current \(I_d\), aligned with the flux, produces none. A push straight down on a bicycle pedal at the top of its stroke behaves the same way, straining the crank without turning it. The controller regulates \(I_q\) to the torque command, holds \(I_d\) near zero below base speed, and writes the resulting voltage into the inverter’s complementary pulse-width-modulation timers.8 Outside field weakening, where the drive deliberately injects negative \(I_d\) to offset back-EMF above base speed, direct-axis current heats the winding without moving the joint and spends thermal margin (section 1.5) for no torque.
Gearing adds a mechanical asymmetry. High-reduction joints use ratios of \(50{:}1\) to \(160{:}1\) to get high torque from a compact motor, which scales delivered torque by \(N\) but spins the rotor \(N\) times faster than the joint. A load that backdrives the output must spin the rotor \(N\) times faster too, and because kinetic energy scales with the square of speed (\(\frac{1}{2} J \dot{\theta}^2\)), the rotor’s inertia \(J_{\text{rotor}}\) resists joint acceleration multiplied by the square of the gear ratio (1.2).
Through a 100:1 transmission, a 50 g rotor presents the joint with the inertia of a 11.2 kg flywheel of 10 cm radius (Lynch and Park 2017). An obstacle striking the gripper must accelerate that flywheel through the gear teeth, whose roots can crack under the shock (figure 4).
Definition 1.2: Reflected rotor inertia
Reflected rotor inertia (\(J_{\text{ref}}\)) is the apparent rotational inertia of an actuator rotor at the load-side joint output, scaling with the square of the transmission gear ratio: \[J_{\text{ref}} = N^2 J_{\text{rotor}}\]
- Significance: In high-reduction transmissions (\(N \ge 100\)) it dominates the apparent load, capping joint acceleration \(\ddot{q}\) and setting impact shock loads.
- Distinction: Unlike rotor inertia \(J_{\text{rotor}}\) or link inertia \(J_{\text{load}}\), it acts through transmission stiffness and backlash, so backdriving from the environment meets an \(N^2\) barrier.
- Common pitfall: Ignoring reflected rotor inertia during collision and contact modeling. Under sudden obstacle impact, the reflected kinetic energy of the spinning rotor concentrates stress directly on gear teeth before drive current can be interrupted.
The combined equation of motion for a geared joint driving load inertia \(J_{\text{load}}\) with motor torque \(\tau_{\text{motor}}\) is: \[ \ddot{q} = \frac{N \tau_{\text{motor}}}{J_{\text{load}} + N^2 J_{\text{rotor}}} \] Differentiating with respect to gear ratio \(N\) reveals that peak joint acceleration occurs at the inertia matching ratio: \[ N^* = \sqrt{\frac{J_{\text{load}}}{J_{\text{rotor}}}} \] Below \(N^*\) joint acceleration is torque-limited. Above it, more gearing decreases delivered acceleration, because the motor spends most of its torque accelerating its own rotor rather than the link.
Because the motor cannot instantly deliver the torque to spin up this amplified inertia, the transmission acts as a mechanical low-pass filter, smearing a sharp command into a delayed response whose lag erodes feedback stability and excites structural resonance. The control path therefore shapes requested motion, with quintic splines or S-curve rate limiters, to keep joint acceleration \(\ddot{q}\) within the current and voltage limits of the hardware (Lynch and Park 2017).
Transmissions also introduce backlash and compliance that decouple motor from load. On reversal the motor shaft crosses mechanical clearance before the teeth engage the opposite flank, and torsional compliance in teeth and flexsplines (figure 3) makes the link an elastic system rather than a rigid bar (Spong 1987), whose flexible-joint model Flexible joint dynamics and singular perturbations derives. Discontinuous torque steps excite that elasticity and can drive the transmission into limit-cycle chatter. A motor-side encoder conceals the deadband, because the motor turns smoothly while the output stays still, so the joint position \(q_{\text{out}}\) departs from \(q_{\text{motor}} / N\) by a load-dependent error \(\delta_{\text{lost}}\). The controller sees continuous tracking while the end-effector hesitates and then takes an impulsive shock as the teeth snap closed, and repeated shocks end in fatigue fracture (figure 4).
Systems Perspective 1.1: Impedance control for contact safety
Impedance control (Hogan 1985) frames contact as neither pure position nor pure force control. The environment behaves as an admittance, accepting force and yielding motion, so the manipulator is controlled as an impedance, accepting motion deviations and generating compliant force (\(F = Z(v)\)). The joint’s drive controller converts position setpoints into a virtual spring-damper system: \[F_{\text{contact}} = K_p (x_{\text{des}} - x) + K_d (\dot{x}_{\text{des}} - \dot{x})\] The joint then behaves like a programmable suspension with stiffness \(K_p\) and damping \(K_d\), yielding on contact and capping force long enough for higher-level software to detect the contact and replan.
The choice of transmission trades continuous torque density against backdrivability, and table 2 contrasts the backdrivable and high-reduction ends of that range. Cycloidal reducers, at \(30:1\) to \(100:1\), sit between those ends and tolerate shock better than a strain wave gear.
| Transmission | Gear Ratio (\(N\)) | Reflected Inertia (\(N^2\)) | Implication for Learned Policies |
|---|---|---|---|
| Quasi-Direct Drive (QDD) | \(3:1\text{--}10:1\) (\(N \le 10\)) | \(N^2 \le 100\) (Low) | Backdrivable; motor current senses contact torque; tolerates impact. Direct drive (\(N = 1\)) is its limit, at the lowest torque density. |
| Strain Wave (Harmonic Drive) | \(50:1\text{--}160:1\) (\(N \ge 50\)) | \(N^2 \ge 2500\text{--}25{,}600\) (Extreme) | Zero initial backlash and compact; torsionally compliant and fragile under sudden tooth shear impact. |
This architectural divide across transmission ratios dictates the mechanical transparency and specific torque envelope of the embodiment (figure 5). In direct-drive joints (\(N = 1:1\)), such as the seminal CMU Direct Drive Arm (Asada and Kanade 1983), reflected inertia is negligible (\(N^2 = 1\)), eliminating backlash and enabling perfect mechanical backdrivability. However, because electric motors produce torque in proportion to stator copper volume and gap radius, direct-drive actuators rarely exceed \(5\,\text{N}\cdot\text{m/kg}\) of continuous specific torque density, burdening manipulators with heavy, bulky linkages. Conversely, classical industrial arms (such as the KUKA LBR iiwa or Universal Robots UR5) and high-load industrial machinery employ high-reduction strain wave or cycloidal gearboxes (\(N = 100{:}1\text{ to }160{:}1\)). While high gearing boosts specific continuous torque density to \(22\text{--}45\,\text{N}\cdot\text{m/kg}\), it inflicts an extreme reflected rotor inertia penalty (\(N^2 \ge 2{,}500\text{ to }25{,}600\)), rendering joints virtually non-backdrivable. Under unexpected contact or obstacle collision, the kinetic energy of the rapidly spinning rotor cannot backdrive the motor; instead, stress concentrates at the gear root fillet, risking catastrophic tooth shear before digital torque loops can intervene.
Modern dynamic physical AI platforms resolve this impasse through quasi-direct drive (QDD) actuation (Seok et al. 2015; Wensing et al. 2017; Katz et al. 2019). By pairing high-torque-density frameless outrunner brushless motors with low single-stage planetary reductions (\(N \le 10{:}1\)), QDD architectures cap reflected inertia multiplier below \(N^2 \le 100\). This preserves mechanical transparency, allowing motor phase currents measured at the inverter to serve as accurate, low-latency proxies for contact force—a property termed proprioceptive sensing. As illustrated by quadruped and humanoid milestones including the MIT Cheetah 3, MIT Mini Cheetah, Unitree Go1/H1, and Boston Dynamics Electric Atlas, QDD actuators achieve peak intermittent torque densities up to \(70\text{--}95\,\text{N}\cdot\text{m/kg}\) while safely absorbing impact shocks during explosive dynamic maneuvers.
A contact-dominated arm either uses backdrivable Quasi-Direct Drive (QDD) actuators (Seok et al. 2015; Wensing et al. 2017) or stays behind real-time torque limits and impedance control.
With either choice, load-side position or torque sensing exposes the disagreement with the motor encoder that backlash or a damaged tooth creates, and the permission path can then reject further force commands and enter a defined fallback.
↳ Downstream: Mechanical gearhead fatigue cycles set the sample efficiency limits for reinforcement learning in Learning by Trial.
Operating near current and torque limits also has a thermodynamic cost. Every ampere that accelerates rotor inertia or sustains peak torque dissipates \(I^2 R\) in the copper, and that heat accumulates in the actuator’s thermal mass, bounding how long peak torque can last before insulation breaks down.
Thermal Duty Cycles
Holding a load motionless at full reach places deceptive demands on an articulated arm such as the mobile manipulator’s. Maintaining a static load against gravity demands continuous phase current through the stator coils, actively converting electrical energy into accumulating heat. Heat arrives in seconds and leaves in minutes, making duty cycle a primary design variable.
Momentum can be redirected and flux decays within milliseconds of opening a switch, but heat has no fast exit. Thermal capacity integrates power loss over time, and it protects two material thresholds (figure 6). Winding insulation is rated by class under IEC 60085, Class F to a continuous hotspot of \(155^\circ\text{C}\) and Class H to \(180^\circ\text{C}\), and above its rating the enamel softens until adjacent turns short and destroy the phase winding. Neodymium-iron-boron (\(\text{NdFeB}\)) rotor magnets demagnetize irreversibly between \(80^\circ\text{C}\) and \(150^\circ\text{C}\) under strong stator fields.
Heat generation follows from the current, as Joule dissipation puts \(P_{\text{loss}}(t) = I^2(t) R(T)\) into the stator copper. That power divides between heating the winding’s thermal mass and conducting out to the casing and surrounding air (Systems and Hardware integrates the thermal equation and derives the steady state).
Thermal capacitance \(C_{\text{th}}\) and thermal resistance \(\theta_{JA}\) behave like a leaky bucket. Joule loss pours in, the thermal mass of the copper and stator iron sets the bucket’s volume, and \(\theta_{JA}\) sets the drain, with a higher resistance narrowing it. A burst of a few seconds raises the level quickly but survives as long as it stays below the insulation rating, while a sustained holding torque raises the level until inflow matches outflow, and if that equilibrium lies above the rating, the enamel fails. Because the thermal time constant \(\tau = \theta_{JA} C_{\text{th}}\) is of the order of minutes while heating acts in seconds, dissipation low-pass filters the power loss, and the steady-state temperature is set by average loss and thermal resistance.
Policies trained in simulation optimize rewards in which torque is an instantaneous, cost-free variable, so they may hold a heavy payload indefinitely, stiffen a joint by co-contraction, or chatter across a contact boundary without consequence. On hardware, sustained current heats the winding at an initial rate \(dT/dt \approx I^2 R / C_{\text{th}}\) before conduction establishes any equilibrium. Copper’s positive temperature coefficient (\(\alpha_{\text{Cu}} \approx 0.00393\text{ K}^{-1}\)) compounds the cost. From 20 °C to a 140 °C engineering ceiling, phase resistance rises by 47.2 percent according to \(R(T) = R_0 [1 + \alpha_{\text{Cu}}(T - T_0)]\), so holding the same torque (\(\tau = K_t I\)) dissipates 47.2 percent more power just when cooling is least effective, and the added heat raises the resistance further.
Datasheet thermal ratings are optimistic because they are measured on an unconstrained motor mounted to a large heat sink in free air at \(20^\circ\text{C}\) or \(25^\circ\text{C}\). Installed in a sealed chassis beside power electronics, battery packs, and other joints, the motor loses convective airflow, which raises \(\theta_{JA}\), and neighboring loads can raise its local ambient to \(45^\circ\text{C}\) to \(55^\circ\text{C}\) before its own coils carry current. Thermal margins must therefore be budgeted from heating and cooling time constants measured with the enclosure sealed and adjacent loads at their \(P_{99}\) power draw.
↳ Downstream: Real-time telemetry for thermal and power integrity budgets is transported by the deterministic fieldbuses analyzed in Moving Commands on Time.
Because thermal capacity integrates power over time, a peak torque9 or peak current rating is meaningless without four parameters: the initial winding temperature \(T(0)\), the allowed duration \(t_{\text{on}}\), the ambient \(T_{\text{amb}}\), and the recovery time \(t_{\text{off}}\). An actuator that can produce three times its continuous torque sustains it only while the integral of \(I^2 R\) stays within the margin below the insulation limit, which from a cold winding can last tens of seconds and from a heat-soaked one a fraction of that (1.2).
Napkin Math 1.2: Transient thermal accumulation under cold vs. hot starts
Problem: How does the initial winding temperature change how long a threefold rated-current burst can last before the insulation limit?
Math:
- Continuous equilibrium: At \(I_{\text{cont}} =\) 5 A the winding settles at \(T_{\text{eq}} = T_{\text{amb}} + I_{\text{cont}}^2 R\,\theta_{JA} =\) 115 °C, below the limit.
- Peak burst: At \(I_{\text{peak}} =\) 15 A the dissipation rises ninefold to \(P_{\text{peak}} =\) 270 W, whose asymptote \(T_\infty = T_{\text{amb}} + P_{\text{peak}}\theta_{JA} =\) 715 °C lies far above the limit.
- Survival horizons: With \(T(t) = T_\infty - (T_\infty - T(0))\,e^{-t/\tau}\), the time to reach the limit is \[t_{\text{limit}} = \tau \ln\frac{T_\infty - T(0)}{T_\infty - T_{\text{limit}}}\] which gives 56.0 s from a cold start at ambient and 20.7 s from a heat-soaked start at \(T_{\text{eq}}\).
Result: The heat-soaked joint holds the burst 63.1 percent less time than the cold one, so peak torque cannot be budgeted without tracking thermal history.
For repeated cycles of period \(t_{\text{cycle}} = t_{\text{on}} + t_{\text{off}}\), an engineering ceiling \(T_{\max} =\) 140 °C sets a cycle-average power ceiling \(\bar{P}_{\max} = (T_{\max} - T_{\text{amb}})/\theta_{JA} =\) 40 W. With peak dissipation during \(t_{\text{on}}\) and none during \(t_{\text{off}}\), this average-power screen bounds the duty cycle \(D = t_{\text{on}}/t_{\text{cycle}}\) by \[D \le \frac{T_{\max} - T_{\text{amb}}}{P_{\text{peak}} \theta_{JA}}\] which here is 14.8 percent, so a 3 s burst calls for a recovery of \(t_{\text{off}} = t_{\text{on}}(1 - D)/D \approx\) 17.3 s. The average does not bound the hottest instant. In the fixed-resistance first-order model the periodic peak obeys \[T_{\text{peak}} - T_{\text{amb}} = P_{\text{peak}}\theta_{JA}\,\frac{1 - e^{-t_{\text{on}}/\tau}}{1 - e^{-t_{\text{cycle}}/\tau}}\] and the screened schedule reaches 142.7 °C, above the ceiling, before the rise of \(R(T)\) adds more. Average-power screening is optimistic, and a burst schedule is accepted only against the transient hotspot trajectory. Figure 7 distinguishes continuous duty \(S_1\) from intermittent periodic duty \(S_3\), whose peak acceleration depends on both initial temperature and cooling time.
The safety microcontroller therefore runs a thermal observer that integrates measured phase current into an estimated hotspot temperature. When the estimate crosses a ceiling, the observer derates the current limits, and if the limit is breached, it vetoes the policy with a thermal shutdown before dielectric breakdown. A static hold shows why the observer must model copper’s feedback (1.3).
Napkin Math 1.3: Static holding torque and thermal stall derating
Problem: With copper’s resistance rising with temperature, where does the stalled winding settle, and what holding torque is thermally sustainable?
Math:
- Stall current: \(\tau_{\text{motor}} = \tau_{\text{hold}}/(\eta N) =\) 1 N·m, so \(I = \tau_{\text{motor}}/K_t =\) 10 A and the cold dissipation is \(P_0 = I^2 R_0 =\) 80 W.
- Runaway: With \(R(T) = R_0[1 + \alpha_{\text{Cu}}(T - T_0)]\), the steady rise satisfies \[\Delta T = I^2 R_0 \left[1 + \alpha_{\text{Cu}}(T_{\text{amb}} - T_0 + \Delta T)\right] \theta_{JA}\] which evaluates to \(\Delta T =\) 155.32 \(+\) 0.5659 \(\Delta T\), so \(\Delta T =\) 357.8 K and the winding would settle near 397.8 °C, far above its rating.
- Derating: At the limit the allowable rise is 115 K, so the sustainable dissipation is \(P_{\max} = \Delta T_{\max}/\theta_{JA} =\) 63.89 W. At the hot resistance \(R(T_{\text{limit}}) \approx\) 1.224 Ω, that allows \(I_{\max} = \sqrt{P_{\max}/R} \approx\) 7.22 A and a hold of \(\tau_{\text{hold,max}} = \eta N K_t I_{\max} \approx\) 30.7 N·m.
Result: Held without control, the stall drives the winding toward 397.8 °C, and staying within the insulation rating requires a 27.8 percent derating, from 42.5 N·m to 30.7 N·m. Continuous gravity holding belongs to friction brakes or counterweights, not to stall current.
Delivering the current pulses that generate these thermal loads also stresses the upstream electrical supply, moving the burden from heat in the copper to transient current on the power bus.
Electrical Power Integrity
When the mobile manipulator swerves hard to avoid a collision, every drive motor, joint inverter, and accelerator demands peak current at once from one direct-current distribution bus. In simulation, current flows from an idealized source. On hardware, delivery is bounded by finite capacity, source impedance, and transient voltage stability. A machine that browns out mid-motion fails physically; the electrical supply is a shared resource.
Rail sag, regenerative overvoltage, and thermal accumulation are manifestations of one bounded energy network on different time scales. Of the three, voltage moves fastest, within microseconds to milliseconds whenever current demand exceeds what the source can deliver at that instant. Compute, sensing, and motor inverters draw from a common bus, so when a policy commands coordinated accelerations across several joints, the sum of their currents changes the voltage delivered to every node on the machine.
The supply cannot deliver an arbitrary current step. Every bus has a nonzero source impedance,10 the sum of the battery’s internal resistance and the resistance of harnesses, connectors, and protection switches, and bulk capacitors only buffer high-frequency transients locally. A rapid step in total current therefore sags the bus at once through the resistive drop across \(R_{\text{bus}}\), the inductive kick across harness inductance \(L_{\text{bus}}\), and the depletion of local capacitors (Systems and Hardware derives the transient droop). If the sag crosses the undervoltage lockout threshold, supervisor silicon asserts a brownout reset and drops the machine mid-motion.
That reset turns the electrical fault into a mechanical one. Voltage supervisors pull the reset line on microcontrollers and gate drivers, clocks halt, register configurations vanish, and communication buses float. An acceleration command issued just before the reset stays physically active until the gate-driver stage collapses. If the driver then floats, phase current ceases, torque falls to zero, and the body coasts under gravity and inertia into workpieces or hardstops. If it instead shorts the low-side switches for dynamic braking, back-EMF (\(e_{\text{bemf}} = K_e \omega\)) produces an immediate, violent counter-torque that jerks the mechanics at the joint limits.
Power removal is an unmanaged state transition, not an automatic return to safety. Cutting power leaves an actuator in one of three unpowered states, namely free coasting, phase-short dynamic braking, or spring-engaged mechanical braking, and each enforces a distinct mechanical behavior. An electromechanical friction brake requires 30 ms to 80 ms for its mechanical spring to overcome magnetic coil decay and engage its friction pads, during which gravity accelerates an overhead arm downward. Phase-short dynamic braking acts like viscous fluid damping, providing resistance proportional to velocity but generating zero holding torque at zero speed. Free coasting simply allows gravity to accelerate unconstrained joints without any resistance. The trajectory a machine follows after an electrical cutoff must be measured under full mechanical payload, not deduced from circuit diagrams. The choice of which safe fallback state the machine should enter belongs to system safety architecture in Safety Enforcement, but the physical dynamics of an unpowered joint are unalterable mechanical constraints of the body.
Deceleration drives the bus toward its opposite boundary, overvoltage, as kinetic energy stored in moving mass returns to it. Braking converts mechanical energy into electrical energy that the supply network must absorb or dissipate. If the source cannot accept reverse current, regenerative energy can charge the local DC link according to \(\frac{1}{2} C_{\text{bus}} (V_{\text{final}}^2 - V_{\text{initial}}^2) = E_{\text{regen}}\) (see Systems and Hardware). This relation gives a capacitor-only endpoint under idealized assumptions, not a voltage waveform. Protection must divert energy before the bus exceeds inverter and converter ratings.11
Power integrity is an architectural constraint. The design sets coordinated power budgets and current slew-rate limits across accelerators and drives, the permission path arbitrates simultaneous multi-axis accelerations so that their \(dI/dt\) transients do not compound, and brake choppers protect the inverters from regenerative feedback during emergency stops. 1.4 works both halves of that budget, the rail’s sag and the stop’s regenerative surge, on the mobile manipulator’s battery rail.
Napkin Math 1.4: DC bus voltage sag and regenerative overvoltage
Problem: Under the coincident current step of an inference burst and the drive motors, and then a stop from the drive limit, does the rail remain within the operating limits of the regulators and the motor inverters?
Math:
- Parameters:
- Machine mass, travel speed, and credible deceleration: \(m =\) 368 kg (upper bound, full tote rack), \(v =\) 1.5 m/s, \(a_{\text{brake}} =\) 2 m/s²
- Rail characteristics: \(V_{\text{rail, nom}} =\) 24 V, harness resistance \(R_{\text{bus}} =\) 60 mΩ, parasitic inductance \(L_{\text{bus}} =\) 2 μH, bulk link capacitance \(C_{\text{bus}} =\) 22,000 μF
- Operating limits: point-of-load regulator dropout \(V_{\text{uvlo}} =\) 18 V, inverter MOSFET breakdown \(V_{\text{breakdown}} =\) 40 V
- Transient droop:
- As an illustrative coincident load, the two drive motors and the arm’s joint drives add 66 A while the application processor adds 4 A on the same rail. Their aggregate step is \(\Delta I =\) 70 A over \(\Delta t =\) 0.5 ms (\(dI/dt = 1.4 \times 10^{5}\,\text{A/s}\)). The example assumes no separate compute-rail hold-up during this step.
- Transient voltage droop evaluates across resistive, inductive, and capacitive terms: \[\Delta V_{\text{droop}} \approx \Delta I R_{\text{bus}} + L_{\text{bus}} \left(\frac{dI}{dt}\right) + \frac{\Delta I \Delta t}{2 C_{\text{bus}}}\] \[\Delta V_{\text{droop}} = 4.20 V + 0.28 V + 0.80 V = 5.28 V\]
- Minimum rail voltage at full charge: \[V_{\text{rail, min}} = 24 V - 5.28 V = 18.72 V\]
- The headroom to the regulators’ dropout is 6 V, and the modeled 5.28 V droop leaves 0.72 V of it. The inductive and capacitive terms last only through the rise, but the ohmic term persists for as long as the load does, and the shared-rail fallacy in section 1.9 follows it from a depleted battery.
- Regenerative surge:
- During a stop from the drive limit, the loaded machine’s kinetic energy must be dissipated: \[E_k = \tfrac{1}{2} m v^2 = \tfrac{1}{2}\,(368 kg)(1.5 m/s)^2 = 414 J\]
- If the battery management system disconnects charge input and an illustrative 75 percent of kinetic energy returns to the bus (\(E_{\text{regen}} =\) 310.5 J), an unprotected, lossless capacitor-only energy balance would end at: \[V_{\text{final}} = \sqrt{V_{\text{rail, nom}}^2 + \frac{2 E_{\text{regen}}}{C_{\text{bus}}}} \approx 169.7 V\]
- Failure mechanism: Long before the bus reached that endpoint, it would cross the 40 V switch rating.
- Sizing brake chopper:
- Under constant deceleration the regenerative power falls linearly from its peak to zero over the stop, which lasts \(t_{\text{stop}} = v / a_{\text{brake}} =\) 750 ms. The area under that triangle is \(E_{\text{regen}}\), so a \(V_{\text{clamp}} =\) 30 V design faces the peak: \[P_{\text{regen, peak}} \approx \frac{2 E_{\text{regen}}}{t_{\text{stop}}} = 828 W\]
- Maximum chopper resistance to divert peak power: \[R_{\text{brake}} \le \frac{V_{\text{clamp}}^2}{P_{\text{regen, peak}}} \approx 1.09 Ω\]
- Component screening: A 1 Ω resistor with a nominal 1 kW pulse rating is a candidate. Verify its 310.5 J pulse-energy and temperature limits, chopper switch safe operating area, and clamp response for the actual braking profile before treating the absorption path as protective.
Result: At full charge the coincident step leaves the rail at 18.72 V, only 0.72 V above the 18 V regulator dropout, so a depleted battery erases the margin. Unbuffered regenerative braking would drive the bus past the 40 V MOSFET rating, which calls for a dynamic brake chopper whose resistor is no larger than 1.09 Ω and absorbs an 828 W peak.
Systems insight: Mechanical motion and electrical power are bidirectionally coupled: acceleration requires capacitive hold-up to prevent brownouts, while deceleration requires active dynamic braking to prevent silicon overvoltage destruction.
Checkpoint 1.1: The five physical budgets
Before measuring these limits on an assembled machine, verify your understanding of the five budgets:
Measuring a Machine’s Own Limits
Before an actuator is integrated into a chassis, it is characterized on a dynamometer stand (figure 8). Software treats parameters as nominal constants in a configuration file, but in physical systems engineering a measurement that cannot state its instrument, its percentile, and its sample count cannot support an argument later.
A measurement begins from the decision it will govern in the permission path, which fixes the quantity, the observation point, the sensor bandwidth, the resolution, and the reference clock. Establishing the mobile manipulator’s credible deceleration, for example, calls for the peak phase current and the deceleration trajectory from the instant of the brake command, captured by an isolated current probe sampled at \(100\text{ kHz}\) and the wheel encoders on a common hardware timebase; an averaging bench meter yields no usable number. An instrument whose analog bandwidth falls below the electrical rise time attenuates the true transient peak, and margins built on it rest on a measurement artifact rather than on the machine.
Every probe also intrudes on the process it observes. A passive voltage probe loads high-frequency lines, a series current shunt drops the rail enough to trigger an early brownout, and a thermocouple inside a motor housing changes its heat paths. Instrument uncertainty is therefore a compound budget, not a single tolerance from a calibration sheet, combining sensor linearity, quantization, frequency-dependent phase lag, probe loading, and clock drift between acquisition channels. When an optical encoder with \(0.05^\circ\) quantization is sampled at \(1\text{ kHz}\) to compute joint velocity through discrete backward differences, numerical differentiation noise introduces velocity variance of several degrees per second that exists entirely in the measurement pipeline rather than in the mechanical joint.
A limit means nothing without the context of its test. Every recorded limit states the payload, ambient temperature, supply voltage, enclosure state, firmware version, and concurrent computational workload of the run. A thermal time constant measured on an open bench at \(20^\circ\text{C}\) can differ by an order of magnitude from the same actuator’s constant in a sealed fairing in sunlight at \(45^\circ\text{C}\), and a rail characterization that omits whether vision-language model inference (Brohan, Brown, Carbajal, Chebotar, Dabis, et al. 2023; Brohan, Brown, Carbajal, Chebotar, Chen, et al. 2023) was running during motor stalls describes an idle board rather than the combined draw of full compute and peak torque.
Every number that governs a machine is a direct measurement, a value derived from measurements through a stated model, a datasheet rating, or an illustrative example, and only the first two can support a safety margin or a timeout. A budget the designer sets, such as the protective clearance \(\delta_{\text{margin}}\), is instead chosen, and it binds only once it is checked against the measured number it must fit (see the Reader Guide).
The absence of a failure during testing bounds the failure rate statistically; it does not establish safety. If the mobile manipulator completes \(n =\) 3,000 loaded stops without a brownout or an overrun, the data support only a per-stop failure rate below roughly \(3/n\) (What Twenty Clean Runs Establish), about one stop in 1,000 at 95 percent confidence, and only if the trials are independent and stationary. Windings that heat across successive trials and gears that wear make consecutive trials correlated and non-stationary, so the same stops run on a cool morning say nothing about the afternoon, when a hotter winding has higher resistance and less peak torque.
Characterization is therefore a standing record, re-established as the machine ages, because physical limits drift over operational time, a process called lifecycle degradation. Brake pad friction glazing and tire tread wear degrade the sustainable deceleration limit \(a_{\text{brake}}\); chemical aging in lithium-ion battery packs increases internal DC bus impedance \(R_{\text{bus}}\), exacerbating voltage droop (\(\Delta V_{\text{droop}}\)) during dynamic maneuvers; and mechanical gear tooth wear widens backlash clearance \(\delta_{\text{lost}}\).
A limit whose violation can cause damage is kept not as a bare number but as a limit record with six elements, which table 3 defines and fills in for two limits of the mobile manipulator: the credible deceleration on which its stopping distance rests, and the dropout of the regulators on its shared control rail.
| Element | What the record states | Credible deceleration \(a_{\text{brake}}\) | Control-rail regulator dropout |
|---|---|---|---|
| Value | The value or empirical distribution, with its sample count and the tail percentiles it reports | 2 m/s², taken as the credible low tail of loaded stops; no samples yet | 18 V at the point-of-load regulators; no samples yet |
| Conditions | The context listed earlier under which it was established, plus the surface for any limit that depends on traction | Loaded to at most 368 kg; dry floor with \(\mu \ge\) 0.204; drive current limits as configured; tires at commissioning wear | Valid only while the permission path runs on its own isolated, held-up rail, the design decision of section 1.8, so that a crossing resets only the application processor; the regulators on that rail are assumed to have the same dropout |
| Uncertainty | The measurement uncertainty of each instrument, with its observation point and bandwidth | Not established | Not established |
| Margin | The engineering margin separating the operating target from the breakdown threshold | None on the value; the 100 mm protective clearance \(\delta_{\text{margin}}\) absorbs its error | 0.72 V at full charge under the coincident step; none from a depleted battery |
| Detector | The runtime check that catches an excursion while the machine runs, such as a phase-current sensor, an optical interrupter, or a supply-rail monitor | Deceleration monitor comparing commanded with measured deceleration from the wheel encoders and the Bosch BMI088 inertial unit, on every stop | Rail-voltage monitor on the shared rail, whose undervoltage flag the permission path answers with a stop |
| Provenance | The evidence category and the instrument or model that produced the value | Illustrative, from the base’s class profile; to be replaced by loaded stopping trials | Illustrative, from the machine’s profile; to be replaced by a rail characterization under coincident load |
Each degradation mechanism above changes a limit’s conditions, so a deployed machine re-establishes its records by periodic recalibration rather than trusting the values measured at commissioning. The saturation duration against which the Schiaparelli lander’s inertial unit had been accepted was such a limit, and the lander’s loss in 2016 shows what follows when a limit’s conditions are exceeded in operation and nothing downstream checks the result.
War Story 1.1: ExoMars Schiaparelli IMU saturation and altitude collapse (2016)
Mechanism: About three minutes after atmospheric entry, the parachute inflated and set the lander oscillating. The IMU measured a pitch rate larger than expected and raised a saturation flag, which persisted longer than the 15 ms assumed when the unit was accepted. While the flag was set, the GNC software integrated the saturation threshold rate as though it were the true rate, although the lander was in reality oscillating, and its attitude estimate drifted by about \(165^{\circ}\), nearly upside down. When the radar altimeter later returned valid slant ranges, the software projected them onto that attitude and computed a negative altitude. No onboard check tested that altitude for plausibility.
Impact: Taking the negative altitude as a valid estimate, the guidance logic released the parachute and backshell, fired the braking thrusters for \(3\text{ seconds}\) instead of the planned \(30\text{ seconds}\), and activated its on-ground systems as if it had landed. The lander was still about \(3.7\text{ km}\) above the surface. It fell freely for about half a minute and struck the ground at about \(150\text{ m/s}\) (\(540\text{ km/h}\)).
Response: The ESA inquiry board recommended robust sanity checks in the onboard software, among them that altitude cannot be negative and cannot change from \(3.7\text{ km}\) to a negative value in one second, and a design that handles IMU saturation explicitly, for example by inhibiting IMU inputs during parachute deployment.
Systems lesson: A physical body cannot transcend the saturation ranges of its sensory transducers. When a sensor’s physical limit (a gyroscope’s rate ceiling or an accelerometer’s dynamic range) is exceeded, a state estimator that integrates the saturated measurement as if it were valid drifts away from the physical state. The saturation duration against which the IMU had been accepted was a limit with conditions, and once descent exceeded them, no detector checked the estimate before it commanded an irreversible action.
Measured and recorded one at a time, the five limits describe the body budget by budget, each under its own conditions. Which of them binds first depends on the machine and the command.
Which Budget Binds First
A single command from the chunk policy to accelerate the loaded mobile manipulator spends from all five budgets at once. It rests on a camera frame that is already aging, it adds kinetic energy that the brakes must later remove, it accelerates reflected rotor inertia through the drive gearing, it deposits Joule heat in windings that shed it only over minutes, and it draws current from the rail that also feeds the application processor. Table 4 sets the five budgets side by side, with the law that governs each, the assumption a policy trained in software makes about it, the machine class it binds first, and the design response and runtime invariant that answer it.
↳ Downstream: The degraded limits recorded here bound the supervisor intervention thresholds derived in Authority Transitions.
The mobile manipulator carries two of the machine classes of Three Machine Classes on one chassis, a Class 1 base that binds first on momentum and stopping distance and a Class 2 arm that binds first on reflected inertia, contact stiffness, and holding heat.
A Class 3 plant binds on heat rather than on stopping distance. A directed-energy-deposition cell, which builds a metal part by melting fed powder with a laser, drives a 5 kW beam into a melt pool under a 1 kHz control loop, so each control period delivers 5 J of heat in the part whether or not the gantry moves. Its limit is the heat the melt pool and the surrounding part can absorb. A 100 ms controller stall with the laser still on delivers 500 J, more than the 414 J of kinetic energy the loaded mobile manipulator carries at its drive limit, and no brake can take that heat back out. For flow-dominated plants, thermal dissipation and electrical power integrity govern survival, and long thermal time constants (\(\tau = \theta_{JA} C_{\text{th}}\)) hide heat that accumulates slowly until a small continuous overload has already crossed an insulation or material limit.
| Physical Budget / Factor | Governing First Principle & Scaling Law | Software Illusion vs. Hardware Ground Truth | Primary Binding Class | Systems Architect Takeaway & Runtime Invariant |
|---|---|---|---|---|
| 1. Measurement Freshness & Age | \(\Delta t_{\text{fresh}} \le \frac{e_{\max}}{v_{\max}}\); end-to-end age measured, not summed from stage percentiles | Illusion: High inference rate (\(50\text{ Hz}\)) guarantees real-time response. Truth: Age begins at exposure; pipeline latency injects phase lag (\(-\omega \tau\)). | Class 1 & 2: Erodes clearance margins and destabilizes high-gain contact loops. | Tag frames with hardware timestamps; enforce \(t_{\text{age}} \le\) the budgeted age at motor registers; drop stale commands. |
| 2. Momentum & Stopping Distance | \(d_{\text{stop}} = v\,\tau_{\text{delay}} + \frac{v^2}{2 a_{\text{brake}}} \le D_{\text{clear}}\) | Illusion: Deceleration can be commanded instantaneously. Truth: Braking distance scales quadratically (\(v^2\)); kinetic energy requires friction work (\(W = F d\)). | Class 1 (Mobility): Primary constraint. Doubling speed quadruples the braking term. | Solve clearance quadratic \(v_{\max}(D_{\text{clear}}, \tau_{\text{delay}})\) on the safety microcontroller at the rate the stopping budget sets; clamp policy velocity. |
| 3. Actuator & Reflected Inertia | \(J_{\text{ref}} = N^2 J_{\text{rotor}}\); \(\tau_e = \frac{L}{R}\); \(I(t) \le I_{\max}\) | Illusion: Motor torque tracks policy setpoints without mechanical resistance. Truth: Gearbox squares rotor inertia (\(N^2\)); inductance delays current rise; shock steps shear teeth. | Class 2 (Manipulation): Primary constraint. Rigid contacts create extreme \(dF/dt\) force spikes and gear fatigue. | Enforce \(C^2\) spline (S-curve) trajectory rate limits; sample load-side optical encoders; deploy quasi-direct drive (QDD) actuators. |
| 4. Thermal Limits & Duty Cycle | \(C_{\text{th}} \frac{dT}{dt} = I^2 R(T) - \frac{\Delta T}{\theta_{JA}}\); \(D \le \frac{T_{\max} - T_{\text{amb}}}{P_{\text{peak}} \theta_{JA}}\) | Illusion: Motors deliver peak catalog torque continuously. Truth: Joule heat (\(I^2 R\)) has positive thermal feedback (\(\alpha_{\text{Cu}}\)); heat accumulates in sealed housings. | Class 3 (Thermal) & Class 2: Static holding draws stall current, overheating coils in seconds. | Run discrete \(I^2 t\) thermal observers on the safety microcontroller; dynamically derate speed and torque when hotspot models approach limits. |
| 5. Electrical Power Integrity | \(\Delta V_{\text{droop}} \approx \Delta I R_{\text{bus}} + \frac{\Delta I \Delta t}{2 C_{\text{bus}}}\); \(V_{\text{final}} = \sqrt{V_{\text{rail, nom}}^2 + \frac{2 E_{\text{regen}}}{C_{\text{bus}}}}\) | Illusion: Power rails act as infinite, ideal voltage sources. Truth: Bus impedance collapses rail voltage under combined compute+motor bursts; braking surges overvoltage. | Class 1 & 3: Peak multi-axis acceleration trips microcontroller brownout resets; regen surges destroy inverter FETs. | Enforce coordinated compute-actuation power budgets and \(dI/dt\) limits; install dynamic brake choppers; characterize unpowered fallbacks. |
The table separates the budgets, but the machine does not, and the margins computed on the mobile manipulator differ in how much a single command can spend. The shared control rail has none left. From a battery depleted to 21.5 V, the coincident step of 1.4 sags it to 17.3 V, below the 18 V dropout of its regulators, so its margin is already negative. A heat-soaked arm joint has a margin measured in time, since a sustained threefold current burst carries its winding to the insulation limit in 20.7 s. The stopping distance at the 1.5 m/s drive limit still keeps 357.5 mm of the clear distance, which only added delay spends, and a thermally throttled application processor would take 16.5 mm of it.
Because the rail binds first, the design answer is to take the permission path off it. The safety microcontroller, the drive logic, and the spring-brake coils run on an isolated rail that a local store holds up for a chosen 2 s, long enough to outlast the longest stop the permission path can command (The Fallback Ladder sizes that stop). Those loads draw 70 W, so the hold-up needs 140 J, which a 2.025 F store delivers between the battery-low point and the regulators’ dropout. A brownout of the shared rail then resets the application processor, while the permission path rides through it, flags the undervoltage, and stops the machine. The complete coupling, in which the body’s stopping distance sets the lease the permission path grants and that lease sets what the Brain must supply, is worked once for Part I in One coupled budget for the anatomy.
Fallacies and Pitfalls
Physical limits interact across subsystem boundaries. A design that meets each component budget can still fail when heat, timing, power, and motion change together.
Fallacy: Model inference time defines the measurement freshness latency.
A team quantizes its vision backbone and reduces inference time from \(30\text{ ms}\) to \(10\text{ ms}\). The improvement shortens one stage, but the controller still acts on measurements that pass through exposure, readout, transfer, and operating-system queues. Commands then travel over the network fieldbus before the motor coil current rises to apply force. A \(45\text{ ms}\) transport spike elsewhere in this chain can consume the clearance margin even when inference meets its benchmark. The engineering budget must measure the true “photon-to-torque” elapsed time from sensing to physical response and bound its tail, rather than declaring the loop real-time from model execution time alone.
Fallacy: Software step commands deliver instantaneous physical torque.
A simulated policy issues piecewise-constant setpoints at \(50\text{ Hz}\) and assumes the actuator follows each change immediately. The physical joint, however, responds through stator inductance (\(L/R\)) and reflected rotor inertia (\(N^2 J_{\text{rotor}}\)). An abrupt command can exceed the actuator bandwidth budget, saturating the inverter’s current limit and violently loading the transmission before the joint achieves the requested motion. This physical lag alters the feedback behavior learned in simulation. Setpoint shaping and the actuator model must account for these physical time constants; a software update rate does not set the joint’s achievable response.
Pitfall: Treating isolated component datasheets as operational system guarantees.
An engineer uses a motor’s continuous torque rating to set the planner’s limits. The rating carries the vendor’s free-air test conditions (section 1.5), not those of the sealed joint beside the compute unit, so it overstates what the installed motor can sustain. Because the planner treats that rating as its torque limit, every trajectory it later generates inherits the error, and the fault surfaces only after the enclosure has heat-soaked, far from the design decision that caused it. Planning limits must derive from measurements on the fully assembled machine under expected environmental and cooling conditions.
Pitfall: Treating dynamic voltage and frequency scaling (DVFS) as a transparent software optimization.
The mobile manipulator’s drive motors heat the shared chassis until its application processor triggers dynamic voltage and frequency scaling (DVFS) to throttle clock frequencies and avoid junction overtemperature. This thermal intervention stretches the vision backbone from 22 ms to 33 ms. The extra 11 ms enters the observation age \(t_{\text{age}}\), and at the 1.5 m/s drive limit it adds 16.5 mm of travel to the stopping budget before any brake command can follow from what the camera saw. The power manager has protected the silicon, but it has silently changed the timing the stopping budget assumed. A previously adequate stopping margin may no longer be adequate. Thermal telemetry must therefore inform the motion budget, with travel speed reduced when processor throttling increases the time needed to perceive and respond.
Pitfall: Scaling operational velocity without recalculating quadratic braking distances and thermal dissipation.
Repeated high-current braking heats the motor windings, so a stop the mobile manipulator survives once at a raised operating speed may exceed its allowable thermal duty cycle (the thermal capacity budget) when repeated through a shift, on top of the quadratic growth in braking travel that Case 3 in figure 2 shows at 2 m/s. A higher operating speed requires a new stopping-distance calculation and a thermal assessment of repeated maneuvers before the planner can safely treat that speed as available.
Fallacy: Compute accelerators and motor inverters operate on independent, ideal power rails.
On the mobile manipulator, a heavy inference burst coincides with the drive motors pushing the base over the cage-door threshold. The combined 70 A transient across the 60 mΩ harness resistance of the shared 24 V control rail produces a 4.2 V drop. With the battery already depleted to 21.5 V, the rail sags to 17.3 V, below the 18 V dropout threshold of the onboard point-of-load regulators, and the application processor resets. Had the safety microcontroller shared that rail, the same brownout would have reset it too while the machine carried active momentum, leaving the base and arm to the unpowered states of section 1.6 instead of a commanded stop. Separate software budgets for compute and actuation ignore their physical reliance on a shared electrical supply. Power qualification must test coincident peak loads from a depleted battery, with the controller that stops the machine on its own held-up rail (section 1.8).
Fallacy: Passing isolated single-variable bench tests guarantees physical survival under compound operational stress.
A robot arm passes a maximum-payload trial in a \(20^\circ\text{C}\) air-conditioned laboratory and an empty-gripper trial in a \(45^\circ\text{C}\) thermal chamber. Neither test establishes its ability to carry that maximum payload in the hotter environment while running on a depleted battery. Under these combined conditions, the heavy physical load raises resistive winding losses, the hotter surroundings reduce the system’s ability to reject that heat, and the lower supply voltage leaves less headroom above back-EMF, capping speed and current slew. Consequently, each subsystem can approach its failure limit much sooner than the separate, isolated trials suggest. Qualification must therefore exercise realistic combinations of payload, temperature, and battery condition on the assembled machine, rather than treating individual test passes as evidence about the combined conditions.
Summary
The body sets the budgets that every learned proposal spends, and none of them can be renegotiated while the machine runs. A moving mass cannot shed its kinetic energy faster than its credible deceleration allows, a winding cannot shed heat faster than its thermal resistance allows, and an observation cannot be younger than the path from transduction to torque. The chapter reduced the body to five such budgets, each a quantity the permission path can check before it admits a command, and each entering that path as a bound rather than a typical value (the percentile-versus-bound distinction of Moving Commands on Time). Every physical limit depends on a declared operating configuration and loses authority when it changes, which is why the chapter keeps each one as a limit record that names its conditions, uncertainty, margin, detector, and provenance. A stopping distance or thermal time constant cannot be taken from a component datasheet into a safety case, and a change of payload, surface, cooling, supply voltage, or wear requires the limit to be measured again before a timing, force, or energy budget reuses it. Of the margins computed on the machine, the shared control rail binds first, so the permission path runs on its own held-up rail. On the mobile manipulator at its 1.5 m/s drive limit, braking, fixed overhead, and brake onset already spend 742.5 mm of the 1.10 m clear distance, leaving 357.5 mm for the delays of sensing and computation, the stop profile, and the tracking bound that later chapters add.
Key Takeaways: The physical body and invariant budgets
- Age is counted from transduction: Observation age begins when the sensor integrates light or flux, not when inference starts, and the end-to-end tail is not the sum of stage tails. The permission path compares the hardware timestamp with the age its budget allows, which for a tracked moving target is \(e_{\max}/v_{\max}\), and rejects a stale proposal.
- Speed sets the stopping envelope: Blind travel grows linearly with pre-brake delay and braking travel quadratically with speed, so the admissible speed is the positive root of \(d_{\text{stop}} \le D_{\text{clear}}\), recomputed whenever clearance or delay changes.
- Gearing trades torque for responsiveness: A gear ratio \(N\) multiplies reflected rotor inertia by \(N^2\). Past the inertia-matching ratio, more gearing delivers less joint acceleration and concentrates impact stress in the gear teeth.
- Heat is an integral state: Joule loss arrives in seconds and leaves over minutes, and copper’s temperature coefficient feeds it back. A peak-torque rating means nothing without its initial temperature, duration, ambient, and recovery time.
- The supply rail is shared: The drives and the application processor draw on one rail, so a coincident current step from a depleted battery can cross its regulators’ dropout, and an unclamped regenerative stop can destroy the inverter that brakes it. The controller that must stop the machine therefore runs on its own rail, held up long enough that a brownout of the shared rail cannot reset it before the stop completes.
- A limit is a record, not a number: A limit governs a decision only with its conditions, uncertainty, margin, detector, and evidence category, and it lapses when wear, heat, a new payload, or a new build changes those conditions.
What’s Next: From the body's limits to the Brain's proposals
Footnotes
Quantile Convolution: In general, the quantile of a latency sum differs from the sum of equal-percentile stage quantiles (\(Q_p(X + Y) \ne Q_p(X) + Q_p(Y)\)). Independence alone does not make their arithmetic sum a worst-case bound. Correlation from shared buses and queues changes the end-to-end tail and must be characterized at the system boundary.↩︎
Bode Delay Theorem and Phase Margin: Pure transport delay \(\tau_d\) introduces an unyielding frequency-dependent phase lag \(\Delta \phi = -\omega \tau_d\) radians without altering loop gain magnitude. In closed-loop feedback systems, this phase erosion degrades the phase margin (\(\text{PM} = 180^\circ + \angle L(j\omega_c)\)); once \(\tau_d\) erodes the margin to zero at the gain-crossover frequency \(\omega_c\), the closed-loop poles cross into the right-half complex plane, destabilizing the physical plant into destructive limit-cycle oscillations.↩︎
IEEE 1588 gPTP: The Generalized Precision Time Protocol (gPTP) provides sub-microsecond clock synchronization across Ethernet networks by exchanging hardware-timestamped packets directly at the network chip (media access control [MAC] PHY) layer. Capturing the timestamp in hardware keeps the operating system scheduler’s jitter out of the measurement.↩︎
MIPI CSI-2: The Mobile Industry Processor Interface Camera Serial Interface 2 (MIPI CSI-2) is a high-bandwidth, high-speed differential protocol used for transmitting uncompressed video data directly from image sensors to host system-on-chip (SoC) devices with minimal latency.↩︎
ISO/TS 15066 Separation Distance: ISO/TS 15066 (Clause 5.5.4), building on ISO 13855, specifies this protective separation distance for Speed and Separation Monitoring (SSM): \(S = (v_r \cdot T_r) + (v_h \cdot T_r) + S_r + S_s + C\), where \(T_r\) is worst-case processing delay, \(S_r\) is braking travel, and \(C\) is clearance margin (\(100\text{--}200\text{ mm}\)). For learning policies operating in collaborative human workspaces, failing to bound compute tail latency directly inflates \(T_r\), expanding the required separation zone and forcing premature protective stops.↩︎
Kinematic Velocity Root: Grouping the constant spatial terms into available physical distance \(D_{\text{avail}} = D_{\text{clear}} - \delta_{\text{loc}} - \delta_{\text{margin}}\) yields the quadratic inequality \(\frac{1}{2 a_{\text{brake}}} v^2 + \tau_{\text{delay}} v - D_{\text{avail}} \le 0\). Multiplying by \(2 a_{\text{brake}}\) produces \(v^2 + 2 a_{\text{brake}} \tau_{\text{delay}} v - 2 a_{\text{brake}} D_{\text{avail}} \le 0\). Applying the quadratic formula and taking the positive physical root defines the dynamic velocity ceiling.↩︎
Field-Oriented Control (FOC) Current Loop: The current loop runs on the drive’s own controller, not on the processor that runs the policy, so a torque step the policy issues reaches the winding only as the ramp that the loop and the bus headroom permit.↩︎
Inverter Dead Time: A short hardware-inserted interval in which both switches of an inverter half-bridge are off, so that the high-side and low-side switches of one leg never conduct together and short the DC bus, a failure called shoot-through.↩︎
Actuator Intermittent Duty Limits: Robotics motor datasheets prominently advertise peak torque (\(\tau_{\text{peak}}\)), but this rating is strictly intermittent, and how long it can be held depends on the winding’s starting temperature. Sustained dynamic maneuvering must be budgeted against continuous root-mean-square torque (\(\tau_{\text{cont}}\)), otherwise aggressive neural policy commands will trip thermal protection and cause mid-motion limb collapse.↩︎
Power Distribution Bus Impedance: The lumped source impedance of an embodied direct-current bus is \(R_{\text{bus}} = R_{\text{cell}} + R_{\text{harness}} + R_{\text{switch}}\), the sum of battery cell, harness and connector, and protection-switch on-state resistances. A current surge \(\Delta I\) drops the rail by \(\Delta V = \Delta I R_{\text{bus}}\).↩︎
Dynamic Braking Chopper Circuit: A power switch and a low-inductance braking resistor placed across the DC bus. When regenerated energy drives the bus above a comparator threshold, the switch conducts and the resistor dissipates the excess as heat, clamping the bus below the breakdown rating of the inverter and converter silicon.↩︎




