News /

An interview on why the consortium exists

Andra Keay talks to Ilia Baranov for Robots & Startups about the near-miss that started it, what a protective stop has to do that an emergency stop cannot, and what the consortium will and will not publish.

Andra Keay’s Robots & Startups newsletter ran a long interview with Polymath Robotics CTO Ilia Baranov on September 17: How close to that robot are you willing to get? It is the fullest account so far of why the consortium exists and how it intends to work. For anyone deciding whether to get involved, these are the parts that matter.

It started with a near-miss. Polymath’s first robot, a leased hobby tractor, turned toward a diesel storage tank the first time it was switched on, and the software stop did nothing; the integrator reached the physical e-stop first. Baranov’s point is that every roboticist has a story like this and almost none of them have a standard way to prevent the next one. Industrial deployments buy safety as part of a commercial package. Hobbyists have machines too small to matter. In between is a growing number of startups doing more dangerous work than they realize.

A protective stop defines the safe state as motionless and powered on. Cutting power to a 110-ton mining vehicle leaves it coasting until its brakes fire. A crane holding eight tons should not stop with the load in midair; it should stop at the maximum safe rate and then lower the load to remove the potential energy. The safe state depends on the machine, and the stop has to be designed around it rather than around the power supply.

One button per robot does not scale. A radio-to-relay stop works for one machine and one operator on site. It fails on a site with many robots and no way to know which remote controls which, and it fails when nobody is on site at all. The protective stop follows the black channel principle: the message itself carries everything needed to verify which robot it is for, how old it is, and what it is asking, so the transport underneath can be anything.

The consortium will not republish standards. IEC 61508 is copyrighted and should be bought and read. What the consortium publishes is the process: what compliance requires, worked examples of how each requirement was met, the templates, and the findings from external safety reviews. The analogy Baranov draws is to cryptography, where secret algorithms lost to open, constantly reviewed ones. He wants the same for safety.

The core is small and certifiable; what sits on top is open. The protective stop’s core is a C library written to MISRA so it can be safety-rated on its own, then deployed onto whatever microcontroller or language a member needs. A Rust implementation would be welcome; so would WebAssembly. Licensing follows the ROS model, commercially friendly and without share-alike terms.

The structure is still being built. Polymath is paying for the work for now. Baranov says plainly that the charter on this site is early stage, and that he is looking for early members, especially companies deploying robots in numbers, to test the system, report failure modes, push fixes upstream, and help decide how certification, safety-compliant continuous integration, and governance should work.

The interview closes with a warning to the public that applies just as well to engineers: cheap humanoids and robot dogs have heavy motors that move suddenly, most teleoperation rigs show no published certification effort, and people have stopped keeping the distance from robots that they still keep from heavy vehicles.

If any of this describes your work, get in touch.

← All news