TrustRobotics Publishes TB-PAS 1.0 White Paper: A Runtime Safety Standard for Physical AI
TrustRobotics has published a new white paper for the TrustBoundary Physical AI Safety Standard (TB-PAS 1.0), a working framework for governing the critical boundary between AI-generated intent and physical actuation.
As humanoid robots and other Physical AI systems move from controlled laboratories into factories, hospitals, warehouses, homes, schools, transportation systems, and public spaces, safety can no longer be treated only as a mechanical design problem. Increasingly capable AI models can generate actions dynamically from vision, language, sensor data, world models, and changing objectives. The industry therefore needs a runtime answer to a new question: when should an AI-generated action be permitted to move the physical world?
TB-PAS 1.0 starts with a simple principle.
A conforming Physical AI system shall prevent an AI-generated candidate physical action from reaching an actuator-control endpoint unless a TrustBoundary has produced a valid release authorization for that candidate physical action.
A RUNTIME SAFETY PIPELINE FOR PHYSICAL AI
The standard defines a minimum action pipeline: Generate → Intercept → Normalize → Predict → Evaluate → Authorize → Enforce → Monitor → Revoke or Complete.
This pipeline is intentionally implementation-neutral. TB-PAS does not require a particular neural model, robot operating system, processor, controller vendor, or actuator architecture. Instead, it defines observable safety interfaces and outcomes so different manufacturers can implement compatible safety boundaries while retaining their own hardware and software stacks.
FIVE VALIDATION CLASSES
TB-V1 provides deterministic constraint validation, including joint limits, torque and velocity ceilings, geofences, payload limits, prohibited objects, and human-clearance requirements.
TB-V2 adds predictive physical validation using world models, learned dynamics, collision prediction, balance prediction, force prediction, trajectory simulation, digital twins, or comparable forward-looking evaluators.
TB-V3 adds contact and tactile prediction for grasping, object transfer, tool use, human contact, fragile objects, high-force manipulation, and dexterous hand operation.
TB-V4 extends validation across multi-agent and infrastructure contexts, including nearby robot actions, shared occupancy, common-object state, infrastructure permissions, robot-to-robot conflicts, and public-space authorization.
TB-V5 establishes independent safety authority through logically or physically independent enforcement, protected execution, non-bypassable actuator gating, fail-closed behavior, and independent minimum-risk actions.
A HUMANOID-SPECIFIC SAFETY PROFILE
The TB-PAS-H1 Humanoid Physical Action Safety Profile addresses hazards created by whole-body, dynamically balanced machines operating in human environments. The profile includes whole-body stability, predicted center of mass, angular momentum, foot contact, terrain condition, recovery-step availability, fall direction, and proximity to nearby people and objects.
It also treats fall consequences as a first-class safety problem. A humanoid may satisfy an internal balance calculation and still create unacceptable consequences if a fall would strike a person, crush an object, damage critical equipment, or place the robot in an unrecoverable state. TB-PAS therefore calls for evaluating likely impact regions, human strike risk, object crush risk, safe-fall or kneeling alternatives, protective arm placement, and actuator-energy dissipation.
The profile also recognizes that humanoid manipulation and locomotion cannot always be evaluated independently. Pulling, lifting, reaching, grasping, or carrying can materially change the stability of the torso, feet, object, and surrounding environment. Cross-body validation is therefore required where a local action can materially affect whole-body safety.
THE PHYSICAL-AUTHORITY TOKEN
One of the central technical concepts in TB-PAS 1.0 is the Physical-Authority Token: a machine-readable authorization object binding an approved action to a specific robot, candidate action, source model, actuator or body region, validator set, policy version, physical context, execution envelope, validity period, and revocation conditions.
An actuator firewall or protected hardware controller can reject a command when the token is missing, expired, replayed, generated for another robot or actuator, inconsistent with the validated action, or outside the authorized trajectory, force, velocity, torque, current, range, or timing envelope.
This changes the safety model from simple permission to bounded physical authority. The question is not merely whether a robot is generally enabled. The question is whether this particular action remains authorized under this particular physical context and within this particular execution envelope.
TESTING AND CERTIFICATION
A safety standard becomes commercially meaningful when conformance can be tested. TB-PAS 1.0 therefore includes repeatable certification scenarios covering unsupported terrain, human-space intrusion, excessive grasp force, environmental change after validation, fall onset during manipulation, source-model substitution, altered or replayed authorization tokens, actuator requests that differ from validated actions, communications failure, validator unavailability, repeated regeneration of blocked unsafe actions, independent minimum-risk intervention, validator disagreement, and degraded sensor conditions.
Each test is structured around an initial state, candidate action, injected fault or hazard, required TrustBoundary response, response-time requirement, permitted fallback action, required audit evidence, and measurable pass/fail criteria.
COMPLEMENTING EXISTING ROBOTICS AND FUNCTIONAL-SAFETY STANDARDS
TB-PAS is intended to complement, not replace, established robotics, machinery, functional-safety, and AI-governance standards. Existing standards address critical issues such as machine design, integration, contact limits, safety functions, risk management, and organizational governance. TB-PAS focuses on the emerging runtime layer between AI inference and real-world physical execution.
In practical terms, an existing safety standard may establish a permitted force, speed, separation distance, stability criterion, or safety integrity requirement. A TrustBoundary can consume those requirements as constraints, predict whether a candidate action is likely to violate them, and prevent or modify physical execution before the hazard is realized.
WHY TRUSTBOUNDARY
Emergency stops remain essential, but Physical AI needs more than a mechanism for stopping a machine after a dangerous condition emerges. The TrustBoundary architecture is designed to create a mandatory decision point before physical authority is granted, and to keep monitoring that authority while the action is being executed.
The objective is straightforward: no actuation merely because an AI model requested it. Physical execution should require evidence, authorization, enforceable limits, and continuing validity.
JOIN THE TECHNICAL DISCUSSION
TB-PAS 1.0 is a working draft. TrustRobotics is inviting technical feedback from humanoid and robotics manufacturers, AI developers, safety engineers, actuator and controller vendors, insurers, researchers, testing laboratories, standards organizations, regulators, premises operators, and others building the Physical AI ecosystem.
The goal is to develop common terminology, interfaces, validation requirements, authorization mechanisms, and certification tests that can improve interoperability and public trust as increasingly capable intelligent machines enter the physical world.
No inference without validation. No validation without evidence. No actuation without authority. No continued authority outside the authorized physical envelope.



Comments