Standards

What is 'safe-by-design'?

2 min readMati Melchior
What is 'safe-by-design'?

"Safe-by-design" is the most used phrase in Physical AI marketing — and the least defined.

The term sounds engineering-grade. It isn't. "Safe-by-design" does not appear as a defined term in IEC 61508, ISO 13849, or the EU Machinery Regulation 2023/1230. The EU does use "Safe and Sustainable by Design" (SSbD) as a formal regulatory concept — but in the chemicals and materials domain under the 2020 Chemicals Strategy, not in machinery or robotics. The term "safe-by-design" itself has roots in nanotechnology and synthetic biology research, where it was used to address safety in the R&D phase of emerging technologies. In robotics, the closest formal concept is ISO 12100's inherently safe design methodology — a three-step hierarchy where the first obligation is to eliminate hazards through design choices, before adding safeguards, before providing information about residual risks.

In practice, "safe-by-design" has become a marketing claim. Robot companies use it to signal that safety is integrated rather than bolted on. The intention is sound. The problem is that the phrase carries no verifiable engineering content. A company can say "safe-by-design" without specifying a safety integrity level, without documenting a redundancy architecture, without having any plan for re-certification after software updates, and without demonstrating what the robot does when a sensor fails.

Four engineering markers distinguish the real thing from the brochure.

First: a named SIL or PL target. A real safety architecture has a quantified target derived from risk assessment. "Working toward certification" is not a target.

Second: a documented redundancy architecture. Dual-channel, voting logic, diverse implementations. "We have dual processors" is not an architecture — it's a bill of materials line item.

Third: a re-certification plan for software updates. Under EU 2023/1230, the manufacturer retains lifecycle obligations for software modifications that affect safety functions. "We'll figure that out later" means it isn't designed in.

Fourth: demonstrated fallback behavior under sensor failure. What does the robot do when the LiDAR returns garbage data? If the answer is "it stops" — that may be the right answer. If there is no answer, the safety claim is aspirational.

These four markers aren't a standard. They're a filter. If a vendor passes all four, the conversation is worth continuing. If they use "safe-by-design" but can't show any of the four — it's positioning, not engineering.

Share

Physical AI Safety Dispatch

Monthly analysis. No spam. One exclusive insight per issue.

One issue per month. Unsubscribe in one click from any email. Privacy policy.

We use cookies

This site uses essential cookies to function and, with your consent, analytics cookies (Google Analytics) to understand how the site is used. Learn more.