Any AI can drive. It only gets the moves the rules allow.
A controller built to crash sent 64,952 rule-breaking commands over 40 km of photoreal driving. The floor overrode every one: zero collisions. Pull the floor and the same commands crashed the car twice within seconds. Swap in any model on top — it still only gets the allowed moves.
Someone is going to put a model on your team. Models are fast at seeing and suggesting; nobody can prove what one will do next. So let the smart, unproven part suggest, and let a small part you can check decide what actually happens. That pattern is called runtime assurance. Perslis is not another model. It is the small part, and every refusal is written down with the evidence behind it.
Not our idea. Here is whose, and what we add
Runtime assurance is not our invention. The Simplex architecture (Sha, 2001) hands control from an unproven controller to a proven one near the edge of the safe zone; shielding (Alshiekh et al., 2018) filters a learning system's actions against a written specification; ASTM F3269 sets a standard for bounding the behaviour of unmanned aircraft that contain complex functions. We build on them. What Perslis adds:
- The allowed list comes first. The list of moves it is allowed to make right now (we call it the admissible set) is worked out from sourced rules and human orders before the driver picks. It never gets to pick a bad move and wait to be told no (the runtime).
- Orders only tighten. A standing order outranks any amount of experience (Theorem 2 in Fail-First Models).
- Learning cannot loosen it. The floor learns from failures as rules you can read, each one citing the failures behind it. It is proved that learning can remove and reorder options but never add one (Theorem 1, pinned by tests in the same paper). It cannot learn its way around your orders.
The evidence
| what was driving | what happened | written up in |
|---|---|---|
| A controller built to crash CARLA, photoreal driving simulation | Over one unbroken 40,052 m run it sent 64,952 commands that broke the rules. The floor overrode every one: 0 collisions. With the floor removed, the same commands reached the controls: 43 dangerous commands got through, 2 collisions within seconds. | CARLA admission control |
| Language models driving frontier and local models, CARLA | 0 collisions under the floor. But they are slow: a measured ~0.8–2.0 s between looks, so a model holds an old command and drives ~10 m blind at 40 km/h. Every language model crawled at ~8–10 km/h; the classical controller drove at 34 km/h. | CARLA admission control |
| Language models in a live 3D tank arena BZFlag, one headline match | Rules 20–20 on 60,140 decisions; DeepSeek 10–18 at ~1.0 s per decision; a frontier model reached through its command-line interface 1–15 at 7.6 s per decision (58 decisions — a limit of how we connected to it, not a measurement of the model). BZFlag's own AI beat our rules. | Rules at the Wheel |
| The game's own bot AI driving Quake III Arena engine with OpenArena content, skill-5 opponents | 9 paired ten-minute matches: the same bot with the floor underneath finished at K/D 1.05 against 0.93 without it, net +12.2 per match (t = 2.02, p = 0.08) — a lean, not proof. Its escapes still cost lava and void deaths on hazard maps, and learning from them is not shown yet. Measured in-house; run logs kept. | — |
What it guarantees, and what it does not
- Guarantees (proved, and pinned by tests in VDSG): every move it makes is on the allowed list or is a safe hold, in every state the learner can reach; an order outranks experience.
- Does not make whatever is driving any good. A correct floor can refuse the mission: on Freeway, three correct rules blocked the only scoring move (−12%).
- Does not certify anything. Nothing here carries a functional-safety qualification, and a sensor that lies to the floor lies to the proof.
What it buys your squad
Machine speed and accountability in one package. Whatever is driving runs as fast as it can think. The floor checks the real state every cycle (20 Hz in CARLA) and writes down every refusal with its evidence. You get machine-speed decisions and an account of every one of them — for the after-action review, and for whoever has to answer when something goes wrong, blue-on-blue included.