Objections
Four objections with honest answers. Placeholder structure until voice pass.
A. Who may press it — and abuse
Authority to trigger a safe state can be misused. The answer must address who is authorised, under what conditions, and what audit exists — without pretending abuse is impossible.
B. The fallback can fail too
Non-AI stop paths fail as well. Functional safety treats that with integrity levels and independence — not with a claim of perfection.
C. Cost and deployment speed
Safe-state capability adds cost and can slow deployment. The trade-off should be stated plainly: which deployments warrant the requirement.
D. A badly designed safe state can be worse
Stopping into the wrong state can increase harm. The requirement is a defined safe state for the deployment context — not an undifferentiated cut of power.