The Software Safety Ceiling: Why Physical AI Cannot Be Made Safe in Software Alone
- Author
- Mati Melchior · Independent Physical AI Safety Researcher
- Published
- 2026-05-06
- Licence
- CC BY 4.0
- Spine for
- Book C
Abstract
Physical AI systems control actuators that can cause physical harm. Current safety practice in this domain leans heavily on software mechanisms: monitors, watchdogs, redundant channels, and formal methods. This paper argues that software-only safety has a fundamental architectural limit. The mechanism is fate-sharing: a software safety monitor and the components it monitors share a substrate — CPU, memory, operating system, firmware, power, clock, supply chain, and design assumptions. Failures in any shared resource can affect both the monitor and the monitored. The probability of correlated failure can be reduced by careful engineering, but cannot be eliminated by software design…
Keywords Physical AI Safety · software safety · hardware safety · common-cause failure · IEC 61508 · functional safety
Cite as
Mati Melchior (2026). The Software Safety Ceiling: Why Physical AI Cannot Be Made Safe in Software Alone. Physical AI Safety Press. https://doi.org/10.5281/zenodo.20048098