Why the AI layer has to sit outside the safety-rated control loop

Save as PDF: File → Print → Save as PDF  |  ← Back to the article

PRAXORALAB
Operations & Systems

Insight Report · Praxora Lab

Why the AI layer has to sit outside the safety-rated control loop

A machine's safety function runs on a certified, bounded response time. A model's inference time is neither certified nor bounded. Most of what gets called an AI integration challenge on the plant floor is really that mismatch, misdiagnosed as a data or model problem.

Veronica Loh

Veronica Loh

Co-Founder & Head, Operations · Managing Director & Chief Sustainability Officer · Praxora Lab

Ask what is stopping AI from running a piece of machinery and the answer usually comes back as a data problem or a model problem. On the floor it is neither. The machine's safety function and the AI's decision loop are governed by two different engineering disciplines, run on two different timing guarantees, and most integration proposals never draw the boundary between them. That boundary is the actual challenge. Get it right and an AI layer can sit alongside a machine doing real work. Get it wrong, by letting a model's output reach an actuator directly, and the result cannot be certified, insured, or defended after an incident.

Exhibit · The mismatch

Two disciplines, two timing guarantees

  • 3

    standards governing a safety-related control system — none written with a model in mind

  • 2

    loops a well-integrated AI-assisted machine actually runs, kept deliberately separate

A safety-rated control system, the circuit that stops a press, drops a guard, or cuts power to a conveyor, has to respond within a bounded, tested time from the moment a hazard is detected. That response time is part of what gets verified during certification: fixed logic, on fixed hardware, with a known worst case. Model inference does not offer that. Even a small model returns an answer somewhere in a range, not a guaranteed figure, and the range widens under load, on a cold start, or when the input falls outside what the model has seen before. A control loop built to a certified response time cannot wait on an answer that only ever arrives inside a range.

Exhibit · What certification requires

Three standards, none written for a model

StandardWhat it covers
IEC 61508Safety Integrity Level for electrical, electronic and programmable systems performing a safety function — verified against defined failure modes.
ISO 13849-1Performance Level for the safety-related parts of a machine's control system — most mechanical guarding and interlock circuits.
IEC 62061Same ground as ISO 13849-1 for more complex, programmable safety systems, where the logic is software rather than a hardwired relay.

Three standards cover most machinery in this position, and none of them were written with a model in mind. All three require the safety function's behaviour to be fully specified and independently testable, a requirement a model, whose output is drawn from a distribution rather than a fixed program, cannot meet on its own.

None of this rules AI out of a mechanical system. It rules out one specific placement: inside the certified loop, with its output wired straight to an actuator. Everywhere else, flagging an anomaly, recommending a maintenance window, throttling a feed rate within limits a person already approved, the model does real, valuable work without ever being asked to meet a certification standard it structurally cannot meet. The practical pattern is two loops, not one: the safety-rated loop stays hardwired, and the AI runs a separate, advisory loop alongside it, with anything it wants to act on passing through the rated safety controller rather than commanding the machine directly.

Exhibit · Before commissioning

What to ask the integrator

  1. 01

    Draw the boundary

    Which functions stay hardwired and certified, and which run in the advisory layer.

  2. 02

    Confirm the command path

    The model's output reaches the machine only through a rated safety controller, never a direct command path.

  3. 03

    Check the response-time budget

    The certified loop was verified against a budget — confirm nothing new asks it to wait on an inference.

  4. 04

    Treat the interface as its own project

    On legacy equipment, the sensor, relay and wiring get their own sign-off, not a detail folded into the AI scope.

On equipment that predates any of this, there is often no interface for the AI to read state from or request an action through, safety-rated or otherwise. Wiring one in is its own small project, with its own certification and sign-off, before the model ever sees live data. Skipping that step to get a pilot running faster is how a supervisory system quietly ends up with more authority over the machine than anyone signed off on. That boundary, not the model's accuracy, is what usually decides whether an AI layer on a piece of machinery survives its first safety audit.

Reference

This piece is adapted for Praxora Lab from the original: Originally published at orionfive.ai  (https://orionfive.ai/insights/ai-outside-the-safety-loop).

About The Author
Veronica Loh

Veronica Loh

Co-Founder & Head, Operations · Managing Director & Chief Sustainability Officer

Co-founder and Head of Operations at Praxora Lab, and Managing Director and Chief Sustainability Officer of Orion Five Engineering, with twenty-six years managing business operations across logistics, food technology R&D, manufacturing mechanisation and digitalisation in Singapore and the region.

Want this applied to your organisation?

Praxora Lab runs the AI Governance & ROI Executive Programme and the AI Masterclass, turning frameworks like this one into a deployment roadmap.

Explore workshops →

© 2026 Praxora Lab. Author: Veronica Loh. Read online at praxoralab.com/insights/ai-outside-the-safety-loop