The Compliance Challenge Nobody Talks About: AI in Safety-Critical Operations

Physical AI | Compliance | Functional Safety | Manufacturing | Week 31 · Part I

PHYSICAL AI | COMPLIANCE | JULY 2026

Why Functional Safety Standards Weren't Built for Learning Machines, and What Manufacturers Must Build Instead

Week 30 asked who is responsible when an AI Agent gets a decision wrong on the shop floor. Week 31 asks a quieter, earlier question: how do you even prove the decision was safe in the first place — before anything goes wrong at all?

That is the compliance challenge nobody talks about at the keynote stage. Functional safety engineering has spent decades building a discipline around one core promise: a certified system is a system that has stopped changing. Physical AI breaks that promise by design. Efficiency Before Fuelhas always meant that the real cost sits in the decision, not the machine — and nowhere is that truer than in the safety case nobody has finished writing yet.

Executive Summary

IN 60 SECONDS:

  • Functional safety standards like IEC 61508, ISO 26262 and IEC 61511 were built to certify systems that stop changing, AI systems that keep learning or get retrained break that core assumption, and standards bodies are only now building the missing layer (ISO/IEC TR 5469, ISO/IEC TS 22440).

  • Compliance for safety-critical AI is no longer one certificate, it is four layers (sector functional safety, AI-specific technical guidance, the EU AI Act's evolving Machinery Regulation path, and internal QMS) that don't yet fully talk to each other.

  • Manufacturers that treat every deployed model as a "frozen, certified" snapshot, and capture safety evidence continuously rather than reconstructing it for audits, are the ones avoiding costly recertification surprises.

1. Why Safety-Critical Standards Were Never Built for Learning Machines

Ask a functional-safety engineer what "validated" means, and you get a precise answer: tested, documented, frozen. Ask an AI engineer the same question about their model, and the honest answer is closer to "as of last Tuesday."

IEC 61508, the parent framework for functional safety of electrical, electronic and programmable electronic systems, and the basis for sector standards like ISO 26262 in automotive, IEC 61511 in process industries and ISO 13849 in machinery, requires continuous, bidirectional traceability from hazard analysis through requirements, design, implementation and verification, maintained in real time across every change. Teams that build this discipline in from the start find compliance becomes a natural output of engineering; teams that defer it find the rework compounds with every release (Ketryx, 2026). That model assumes a system that eventually stops changing long enough to be certified.

Adaptive, data-dependent AI behavior does not fit neatly inside that assumption, and the standards bodies say so themselves. The IEC has acknowledged that its existing functional-safety standards "do not take into account specific domains where AI plays a role," and published ISO/IEC TR 5469 as a first technical report addressing the specification, design and verification of functionally safe AI systems (IEC, 2026). The gap is significant enough that a dedicated new standard, ISO/IEC TS 22440 on "Functional Safety and AI Systems," is now being paired with classic IEC 61508 training, the two run back-to-back at the first ever Physical AI Safety Week in September 2026 (SRES, 2026).

👉 Key Insight

Functional safety standards were built to certify systems that stop changing. AI systems that keep learning break that assumption at its foundation.

2. The New Compliance Stack: Where AI Standards Meet Functional Safety

No single standard covers an AI-driven safety function today, which means no single audit does either.

Four layers now have to hold together at once. The sector functional-safety layer IEC 61508, ISO 26262, IEC 61511, ISO 13849, still governs hardware and software safety integrity. The AI-specific technical layer, led by ISO/IEC TR 5469 and the emerging ISO/IEC TS 22440, addresses the specification, design and verification questions the sector standards were never written to answer (IEC, 2026). The EU AI Act layer increasingly runs through product safety law rather than beside it: AI embedded as a safety component of regulated products, much shop-floor machinery included, is being folded into the EU Machinery Regulation, with delegated acts on AI-specific health and safety requirements due by 2 August 2028 (European Commission, 2026; Travers Smith, 2026). And the internal QMS layer has to translate all three into procedures a plant can actually run.

These four layers do not yet share a common vocabulary, let alone a joint audit trail, which is exactly why compliance teams that treat "AI Act done" or "IEC 61508 done" as sufficient on its own are the ones most likely to be surprised at recertification.

👉 Key Insight

Compliance for safety-critical AI isn't one certificate, it's four layers that currently don't fully talk to each other, and the gaps between them are where risk hides.

3. Practical Lessons from Early Safety-Critical AI Deployments

The organizations getting this right are not waiting for the standards to finish catching up, they are building the traceability those standards will eventually require anyway.

Three practices recur. They capture safety evidence continuously as work happens, rather than reconstructing it retroactively when an audit is announced, the release delays that accumulate when evidence has to be rebuilt after the fact are avoidable, not inevitable (Ketryx, 2026). They separate the "learning" pipeline from the "certified" release: a specific, version-locked model snapshot goes through the safety case, while ongoing training or fine-tuning happens in a parallel track that has not yet earned deployment. And they send safety engineers and AI/ML engineers through joint training rather than parallel tracks, so both disciplines share a lifecycle and a vocabulary, precisely the pairing SRES is building into its first Physical AI Safety Week, which runs classic IEC 61508 training immediately alongside the new ISO/IEC TS 22440 AI-systems course (SRES, 2026).

None of this waits for Brussels or Geneva to finish publishing. It is available to build today, with the standards that already exist.

👉 Key Insight

Treat every deployed model version like a certified snapshot, not a live document, the moment it can drift silently, the safety case is already out of date.

Action Plan for Decision Makers

Checklist

Final Thought

Proving a learning system is safe is hard enough when the standards themselves are still catching up. Part II of this Week 31 pair looks at a second, related problem: the ground under those standards has been moving too, Brussels rewrote its own AI Act timeline in the middle of this compliance conversation.

Efficiency Before Fuel means building the safety case before the incident, not after. It also means not mistaking a regulatory delay for a reason to slow down.

Systems don't fail. Decisions do.

Take the Next Step

Subscribe to the Weekly Punch for weekly strategic clarity, direct to your inbox.

Get clarity on AI, leadership, and the systems behind performance

No noise. No frameworks. Just insights that matter

Subscribe if you want clarity, not comfort

    No noise. Unsubscribe at any time.

    References

    • European Commission (2026) AI Act — Shaping Europe's Digital Future. Brussels: European Commission, Directorate-General for Communications Networks, Content and Technology.

    • IEC (2026) New Standard to Increase Safety of AI. Geneva: International Electrotechnical Commission.

    • Ketryx (2026) Navigating ISO 26262 and IEC 61508-3 Functional Safety Standards for Safety-Critical Software. [Online guide].

    • SRES (2026) SRES Announces New IEC 61508 Training and First Physical AI Safety Week. [Press release].

    • Travers Smith (2026) EU Agrees to Delay Key AI Act Compliance Deadlines. London: Travers Smith LLP.

    Disclaimer: This article synthesizes publicly available standards guidance and regulatory reporting current as of publication. No detailed section brief was supplied for this week; body sections, framing and evidence selection were originated by the writer from the two given titles. Regulatory and standards timelines are subject to further change. Readers should verify current requirements against primary standards bodies (IEC, ISO) and EU sources before relying on them for compliance decisions. Verification Gate: flagged for pre-publication source check.

    Note: This article reflects my personalviews based on industry experience and publicly available information. It does not constitute professional, legal, or investment advice and does not represent the views of my employer. AI-generated visuals, concept and content by the author.

    Previous
    Previous

    AI Regulation vs. Innovation, The European Tightrope

    Next
    Next

    AI Accountability in Complex Industrial Environments