Section 52 of 55
99. Speed and Force Limitation
Stable section ID: S05-CON-011-SECTION-52 · 362 content blocks
Robot speed, force, torque, power, momentum, and stored energy shall be limited according to the task, contact possibility, human exposure, tooling, payload, and body regions at risk.
Limits shall apply to the complete moving system, including:
- Manipulator.
- Mobile base.
- Tool.
- End effector.
- Payload.
- Projecting fasteners or sharp elements.
- Cables and hoses.
- Moving temporary supports.
Nominal controller values shall not substitute for measured or validated physical behavior. Payload mass, reach, braking response, joint configuration, surface friction, and control delay may materially alter the resulting hazard.
Reduced-speed operation shall not automatically qualify an unsafe task as collaborative. Crushing, trapping, cutting, electrical, thermal, or dropped-load hazards may remain unacceptable even at low speed.
Where contact is permitted, the allowable contact conditions shall be explicitly defined and verified. Unexpected contact shall trigger detection, stop, and inspection appropriate to its severity.
- Safety-related limits shall not be adjustable by unauthorized production software or ordinary users.
- 100. Collision, Crushing and Pinch-Point Protection
Robotic design and process planning shall identify collision, crushing, trapping, shearing, entanglement, and pinch-point hazards throughout the entire motion and assembly sequence.
Special attention shall be given to:
- Robot-to-structure clearances.
- Component-to-Interface capture regions.
- Closing tools and clamps.
- Articulated joints.
- Moving platforms.
- Doors, gates, and access panels.
- Temporary supports.
- Narrow retreat routes.
- Human hand-positioning areas.
Interface and component design should eliminate unnecessary trapping geometry and provide predictable clearance, lead-in features, guarded locking mechanisms, and safe manual access.
Where a person must guide or inspect near a potential pinch point, robot motion shall use an approved collaborative or hold-to-run mode with appropriate limits.
Unexpected contact shall not be overcome through increased force. The system shall stop, preserve component stability, identify the obstruction, and follow the approved recovery procedure.
After significant collision, the affected robot, tool, component, Interface, calibration, and temporary structural state shall be inspected before further work.
- 101. Dropped-Load Protection
- Robotic lifting systems shall prevent uncontrolled release, fall, rotation, or collapse of payloads.
Protection may include:
- Positive mechanical retention.
- Redundant gripping or secondary support.
- Load-state monitoring.
- Check valves or mechanical brakes.
- Rated capture features.
- Controlled exclusion zones.
- Verified emergency landing positions.
- Temporary structural support.
The complete load path—from component through grasping feature, end effector, coupler, robot, support surface, and structure—shall be verified for the intended load and dynamic effects.
Loss of electrical, hydraulic, pneumatic, vacuum, communication, or controller power shall not cause foreseeable uncontrolled release.
A robot shall not release a component until the next supporting or capture state has been physically verified.
Personnel shall not enter beneath suspended loads except under a specifically authorized and protected procedure. Warning systems shall not substitute for physical risk reduction.
If grip quality, load identity, center of mass, support condition, or capture state becomes uncertain, the robot shall place or transfer the load to a verified safe support where possible.
102. Unexpected Resistance and Force Detection
Robotic systems performing approach, insertion, alignment, fastening, cutting, or disassembly shall monitor for unexpected resistance and abnormal force patterns.
The system should compare measured behavior with qualified envelopes for:
- Force.
- Torque.
- Displacement.
- Velocity.
- Tool current.
- Pressure.
- Vibration.
- Time and process sequence.
Unexpected resistance may indicate misalignment, obstruction, incorrect component identity, deformation, contamination, trapped material, an occupied pinch point, hidden fastener, utility conflict, or unintended structural loading.
Exceeding an applicable threshold shall cause controlled stop or withdrawal as permitted by the task.
The robot shall not treat increasing force as the default method for resolving uncertainty. Repeated force excursions shall trigger inspection and escalation.
Force detection shall account for sensor calibration, tool compliance, payload weight, gravity compensation, friction, and structural flexibility. A mathematically compensated force value shall not be accepted when the underlying sensor or model is invalid.
103. Robotic Tool Safety
Every robotic tool and end effector shall have a defined safety profile covering attachment, operation, energy, hazards, inspection, maintenance, and failure behavior.
Tool hazards may include:
- Cutting and crushing.
- High torque.
- Heat, sparks, and flame.
- Pressure and stored energy.
- Vacuum loss.
- Projectiles.
- Radiation or intense light.
- Chemical exposure.
- Noise and vibration.
- Sharp or contaminated surfaces.
Before activation, the system shall verify tool identity, secure coupling, configuration, calibration, operating limits, protective devices, and compatibility with the work package.
Tools shall prevent unintended activation during transport, attachment, detachment, pause, or communication loss.
Tool-change stations shall control dropped-tool, pinch-point, wrong-tool, and residual-energy hazards. A successful coupler command shall not alone prove secure attachment.
Consumable condition, wear limits, guards, cutters, bits, welding materials, adhesives, and calibration-sensitive parts shall be tracked where failure could affect safety or quality.
- 104. Energy Isolation and Lockout
- Robotic work involving hazardous energy shall use a controlled Energy Isolation and Lockout architecture.
Hazardous energy may include:
- Electrical.
- Hydraulic.
- Pneumatic.
- Mechanical.
- Gravitational.
- Thermal.
- Chemical.
- Pressure and vacuum.
- Stored spring or elastic energy.
- Battery and capacitor energy.
- Active utility systems.
Isolation shall identify the energy source, isolation point, responsible authority, verification method, affected equipment, and conditions for restoration.
A digital command indicating “off” shall not substitute for verified physical isolation where lockout is required.
Before intervention, stored energy shall be discharged, restrained, blocked, or otherwise controlled. Suspended or partially assembled components shall receive independent support.
Robots shall respect physical and digital lockout states. No remote command, software update, automated restart, or fleet rescheduling action shall override an active isolation.
Removal of isolation shall require confirmation that personnel, tools, temporary supports, guards, and affected systems are in the correct state.
105. Temporary Structural Stability
Robotic operations shall preserve structural stability during every intermediate state, not only in the final completed configuration.
The work package shall identify:
- Temporary load paths.
- Required braces and supports.
- Maximum unsupported duration.
- Permitted environmental loads.
- Component-release conditions.
- Monitoring requirements.
- Human-access restrictions.
- Safe pause and abort states.
- Robots shall not remove, reposition, or release a structural element based solely on final-state calculations.
Temporary supports shall have identifiable installation, loading, inspection, release, and removal states. Their presence in a Digital Twin shall not replace physical verification.
If unexpected movement, deformation, settlement, vibration, support damage, or load redistribution is detected, robotic work shall stop while maintaining the safest achievable support condition.
Productivity optimization shall not reorder structural tasks or remove temporary supports unless the revised sequence has been validated and authorized.
- 106. Power-Loss Behavior
- Every robotic system shall define and validate its behavior under partial and complete power loss.
Power-loss analysis shall consider:
- Manipulator brakes.
- Mobile-platform braking.
- Suspended payloads.
- Grippers and vacuum tools.
- Hydraulic and pneumatic systems.
- Active temporary supports.
- Hot or rotating tools.
- Computing and communication equipment.
- Safety sensors.
- Emergency lighting and alerts.
Simple de-energization may not always create the safest condition. A robot carrying a load may need sufficient stored or backup energy to maintain grip, establish controlled support, or execute a bounded safe-stop action.
The system shall identify which safety functions remain available, for how long, and under which battery or backup-power conditions.
Power restoration shall not cause automatic motion, tool activation, load release, or task resumption.
Before restart, the system shall reconcile robot position, payload state, structural condition, tool state, work-zone occupancy, and any work performed during the outage.
107. Communication-Loss Behavior
Loss, delay, corruption, or instability of communication shall cause a predefined response appropriate to the active task.
Communication dependencies may include:
- Robot-to-controller links.
- Safety networks.
- Fleet coordination.
- Tool communications.
- Building BIOS services.
- Edge and cloud systems.
- Human supervision interfaces.
- Inter-robot coordination.
- Safety-critical local functions shall remain effective without dependence on remote cloud connectivity.
The response to communication loss may include completion of a bounded safe action, controlled stop, maintenance of payload support, tool deactivation, zone protection, or transition to a qualified offline mode.
The robot shall not continue indefinitely using stale commands, obsolete maps, expired authority, or predicted responses from disconnected systems.
Multi-robot operations shall prevent conflicting motion when coordination is lost. Each robot shall preserve local collision protection and enter its defined safe state.
Reconnection shall not automatically authorize resumption. Identity, sequence, authority, physical state, and missed events shall first be reconciled.
108. Localization and Perception Failure
Failure or degradation of localization or perception shall be detected before uncertainty produces unsafe motion or incorrect physical work.
Relevant failures include:
- Excessive localization drift.
- Lost coordinate reference.
- Occluded safety region.
- Incorrect object classification.
- Conflicting pose estimates.
- Stale maps.
- Marker substitution or damage.
- Lighting or weather degradation.
- Sensor saturation.
- Unrecognized human or obstacle presence.
The required response shall reflect task consequence. Open-area navigation may allow reduced-speed recovery, while structural insertion, utility work, or human-adjacent operation may require immediate safe stop.
The robot shall not substitute an unqualified perception source merely to preserve productivity.
Recovery shall re-establish coordinate systems, sensor validity, work-zone condition, component identity, and current physical state. If retreat cannot be performed safely, controlled holding and human intervention may be required.
109. Sensor and Control-System Failure
The robotic system shall detect, isolate, and respond to failures in sensors, controllers, actuators, safety devices, and software processes.
Failure conditions may include:
- Missing or frozen data.
- Drift or bias.
- Out-of-range values.
- Conflicting redundant sensors.
- Timing errors.
- Controller restart.
- Memory or computation faults.
- Actuator runaway.
- Brake failure.
- Safety-device bypass.
- Common-mode software failure.
Safety-related diagnostics shall distinguish between a confirmed safe measurement and absence of a valid measurement.
Redundancy shall be designed for meaningful independence. Multiple devices sharing the same power supply, communication bus, environmental vulnerability, or software defect may not provide true fault tolerance.
A failed channel may permit a defined degraded mode only when the remaining controls continue to satisfy all requirements of the reduced task.
- Replacement, reset, or automatic failover shall be recorded and may require renewed calibration or validation.
- 110. Weather and Environmental Conditions
- Robotic operations shall remain within qualified environmental limits.
Conditions to be considered include:
- Wind and gusts.
- Rain, snow, ice, and standing water.
- Temperature and humidity.
- Dust, smoke, fog, and glare.
- Lighting variation.
- Surface friction.
- Lightning and electrical storms.
- Corrosive or explosive atmospheres.
- Noise and vibration.
- Flooding or ground instability.
Environmental limits shall account for the complete robot–tool–payload configuration. A robot that can safely stand in a given wind may not safely transport a large panel under the same condition.
Sensors, markers, brakes, tires, tracks, grippers, adhesives, seals, and electrical systems may have different environmental limitations.
Weather data from remote services may support planning but shall not replace relevant local observation.
When conditions exceed or approach authorized limits, the system shall pause, secure loads and temporary states, withdraw where safe, or enter the prescribed weather-safe configuration.
111. Fire, Smoke and Hazardous-Material Conditions
Robotic systems shall recognize and respond appropriately to fire, smoke, heat, combustion products, and hazardous materials.
The safety plan shall address:
- Battery and electrical fires.
- Hot-work ignition.
- Flammable liquids and gases.
- Dust explosion hazards.
- Toxic or oxygen-deficient atmospheres.
- Asbestos, lead, mold, and contaminated debris.
- Emergency egress.
- Firefighter and responder access.
Robots may assist with detection, inspection, isolation, or remote handling, but they shall not obstruct evacuation, suppress alarms, or delay emergency response.
Ordinary robotic sensors shall not be assumed suitable for life-safety fire detection unless qualified for that role.
Hot-work tasks shall verify permits, combustible-material controls, ventilation, monitoring, and post-operation inspection.
After a fire or hazardous-material event, exposed robots, batteries, tools, components, sensors, and structural elements shall be inspected before return to service.
112. Electrical, Gas, Water and Utility Hazards
Robotic interaction with utilities shall treat physical connection, testing, and energization as separate controlled states.
The system shall identify:
- Utility type.
- Location and route.
- Pressure or voltage.
- Isolation points.
- Stored energy.
- Contamination risk.
- Responsible authority.
- Required professional approval.
- Emergency shutoff procedure.
- Unknown or conflicting utility identity shall block work.
Robotic excavation, drilling, cutting, fastening, or deconstruction shall verify that hidden utilities are not present within the affected volume.
Water release may create structural, electrical, slip, contamination, and occupied-building hazards. Gas release may require immediate isolation, evacuation, ignition control, and emergency notification.
Completion of a connector motion shall not authorize energization. Required continuity, insulation, pressure, flow, leak, communication, and functional tests shall be completed and approved first.
113. Robotics in Occupied Buildings
Robotic operation in occupied buildings shall apply additional controls for people who are not trained construction workers.
The plan shall account for:
- Residents and visitors.
- Children and older persons.
- Persons with disabilities.
- Animals.
- Privacy and consent.
- Noise, dust, and vibration.
- Furniture and moving obstacles.
- Security boundaries.
- Emergency egress.
- Utility continuity.
- Cleanliness and contamination.
Work zones shall be understandable to occupants and shall not rely exclusively on technical warnings or specialized training.
Robots shall not assume predictable behavior from children, animals, or visitors.
Occupants shall receive appropriate information about the schedule, affected areas, alarms, access restrictions, privacy implications, and emergency contacts.
Cameras, microphones, maps, and occupant-related data shall be limited to legitimate operational and safety needs.
After work, access routes, fire protection, utilities, covers, locks, guards, and occupant spaces shall be restored and verified.
114. Emergency Stop Architecture
System05 shall provide an Emergency Stop Architecture appropriate to the size, mobility, task, and hazards of the robotic operation.
Emergency-stop devices shall be:
- Clearly identifiable.
- Accessible to affected personnel.
- Positioned according to foreseeable emergencies.
- Protected against confusing or unintended use.
- Independent from ordinary production commands.
- Capable of initiating a defined emergency response.
The architecture shall define whether activation applies to one robot, one tool, one zone, coordinated robots, or the complete workcell. Propagation shall be designed to avoid creating secondary hazards.
Emergency stopping may require controlled braking, tool isolation, load retention, and continued temporary support. Removing all energy indiscriminately may be unsafe for some configurations.
An emergency stop shall not substitute for guards, safe design, protective separation, or normal stopping functions.
Resetting the emergency-stop device shall only clear the stop condition; it shall not automatically restart motion or reauthorize the task.
Every activation shall be recorded, investigated as appropriate, and followed by physical-state verification before restart.
115. Safe-Stop Architecture
A Safe Stop is a controlled transition to a state in which unacceptable motion, energy, or physical change is prevented while necessary stability and protective functions are maintained.
Safe-stop states may include:
- Controlled motion stop.
- Protective stop with power retained.
- Tool-safe state.
- Payload-holding state.
- Temporary-support state.
- Utility-isolated state.
- Controlled de-energized state.
The correct safe state shall depend on the active task. A robot holding a structural panel may require a different response from an unloaded inspection robot.
Safe-stop design shall define stopping time, stopping distance, retained functions, brake behavior, payload behavior, zone status, alerts, and restart requirements.
The system shall distinguish a normal pause, protective stop, fault stop, emergency stop, and power-loss state.
A safe stop shall preserve sufficient information to determine the last reliable command, robot pose, tool state, component state, and reason for stopping.
116. Fail-Safe and Degraded Operation
Robotic systems shall fail toward a condition that minimizes harm, but “fail-safe” shall not be interpreted as universal and immediate de-energization.
The safest response may require:
- Maintaining grip.
- Applying brakes.
- Lowering a payload.
- Preserving temporary support.
- Isolating a tool.
- Restricting movement.
- Activating local warnings.
- Requesting human intervention.
Degraded operation may be permitted only when the failed capability is known, the remaining controls are sufficient, the reduced operating envelope is defined, and the active task is authorized for that condition.
A degraded mode shall specify:
- Available and unavailable functions.
- Reduced speed, force, payload, or zone.
- Required human supervision.
- Time or task limits.
- Prohibited operations.
- Recovery and exit conditions.
The system shall not gradually normalize repeated faults or expand degraded operation through accumulated exceptions.
- Unknown failure state shall be treated more conservatively than a diagnosed and bounded failure.
- 117. Manual Override and Human Takeover
Manual override and human takeover shall provide a controlled means for qualified personnel to stop, recover, reposition, or complete work.
Manual control shall require verified identity, role, training, and authority appropriate to the action.
The takeover process shall communicate:
- Current robot and task state.
- Payload and tool condition.
- Active hazards.
- Coordinate and localization status.
- Temporary structural state.
- Disabled or degraded safeguards.
- Permitted manual actions.
Manual override shall not silently bypass safety limits, utility isolation, structural constraints, or protected zones.
Where a safeguard must be temporarily bypassed for diagnosis or recovery, the action shall use a controlled maintenance mode, limited speed and force, appropriate hold-to-run control, additional protection, and complete logging.
- The robot shall not resist, countermand, or unexpectedly resume during valid human takeover.
- Return to automatic operation shall require explicit handback, renewed verification, and state reconciliation.
- 118. Restart, Reentry and State Reconciliation
Restart after a stop, failure, interruption, evacuation, manual intervention, or communication loss shall be treated as a new authorization point.
Before restart, the system shall verify:
- Cause of interruption.
- Robot and tool configuration.
- Payload and component state.
- Localization and calibration.
- Work-zone clearance.
- Human presence.
- Structural and temporary-support condition.
- Utility state.
- Environmental conditions.
- Validity of the work package and authority.
- Freshness of previous evidence.
- Physical changes occurring during the interruption shall be incorporated into the current state.
Reentry into a previously controlled zone shall follow defined inspection and access procedures. A zone shall not be presumed safe because the robot is stopped.
Conflicts among controller memory, robot position, Digital Twin state, BIOS records, and physical evidence shall be preserved and reconciled.
- Restart shall continue from a defined recovery state rather than blindly resuming the next stored command.
- 119. Human–Machine Interfaces, Alerts and Training
Human–Machine Interfaces shall communicate robotic state, hazards, authority, uncertainty, and required action clearly.
Interfaces should display:
- Active robot and tool.
- Operating mode.
- Task and work-package identity.
- Work-zone state.
- Motion or load condition.
- Warnings and faults.
- Safety-system status.
- Pending approvals.
- Recovery instructions.
- Communication and localization health.
Alerts shall be prioritized by consequence and designed to avoid alarm flooding, ambiguous symbols, hidden faults, and dependence on color alone.
Critical alerts shall identify what happened, where it happened, what remains dangerous, and what action is required.
Training shall be role-specific. Operators, supervisors, engineers, inspectors, occupants, maintainers, and emergency responders require different information and authority.
Interfaces shall not manipulate users into approving uncertain work, obscure degraded conditions, or treat acknowledgment as evidence that the hazard has been corrected.
120. Prohibition of Self-Approval and Unlimited Robotic Autonomy
No robot, AI agent, planner, controller, or fleet-management system shall possess unlimited authority over construction or lifecycle operations.
A robotic system shall not independently:
- Redefine structural requirements.
- Approve its own consequential work where independent verification is required.
- Expand its work-package scope.
- Override safety controls.
- Ignore failed preconditions.
- Energize utilities without required authority.
- Accept an unverified deviation.
- Alter protected BIOS configuration.
- Conceal uncertainty or failed evidence.
- Grant itself additional permissions.
- Expand its qualified Operational Design Domain.
Autonomy shall remain bounded by task, component, zone, time, configuration, consequence class, approved alternatives, and required evidence.
Learning from experience may improve future planning, but learned behavior shall not alter released safety rules or authorization boundaries without controlled validation and approval.
System05 shall preserve meaningful human and institutional authority for safety, compliance, ethics, and public welfare. Robotic execution may be highly autonomous; engineering authority shall remain explicitly governed.