Physical AI
Engineering that tests its own assumptions.
Some uncertainties only a physical experiment can settle: friction on a real surface, the strength of a printed part, a film's resistance after annealing. This part of Terranoux turns those questions into bounded, measured, auditable runs, and sends the evidence back into the design.
Overview
Hypothesis, experiment, measurement, design update.
The engineering model decides what it needs to know. Authority comes from LucidRail. Everything between, Terranoux handles with the care physical actions need.
- 01Engineering model
Experiment specification
objective · variables · controls · measurements · budget · stop
- 02Terranoux
Environment adapter
capabilities · envelope · channels · calibration · cost model
- 03Terranoux
Simulation and validation
predicted outcome · resource use · envelope violations
- 04LucidRail
Authority
identity · policy · budget · approvals · scoped grant
- 05Terranoux
Physical execution
configure · interlocks · stopping conditions · deviations
- 06Terranoux → model
Raw evidence and provenance
observations · calibration · actions · custody
01
Experiment specification
A contract written before anything moves. If a field is missing, the experiment is not ready.
01 / 09
Objective
What is being tested?
One measurable aim. If it cannot be measured, it is not ready to run.
Example value
sheet resistance of film batch A after annealing
Checked by
Engineering model
# Draft experiment contract. Field names are not final.
experiment:
id: exp_example_0142
objective: "sheet resistance of film batch A after annealing"
question_ref: q_example_0142 # the uncertainty this resolves
variables:
anneal_temp: { values: [120, 160, 200], unit: degC }
controls:
duration: { value: 30, unit: min }
atmosphere: N2
substrate: batch_A
interventions:
- anneal(sample, anneal_temp, duration)
- measure(sample, sheet_resistance)
measurements:
sheet_resistance: { unit: ohm_per_sq, replicates: 3 }
chamber_temp: { unit: degC, rate_hz: 1 }
stopping_conditions:
- chamber_temp > 225 degC
- interlock.open
- samples_complete == 9
budget: { samples: 9, instrument_hours: 4, cost_usd: 180 }
risk_class: R2
authority: required # filled only by LucidRail02
Environment adapters
Terranoux should not need to own the lab. An adapter describes an existing instrument in a common model and translates to whatever interface it already speaks.
Each adapter declares capabilities, its risk envelope, measurement channels, calibration source, cost model and stop mechanisms. The experiment model only ever talks to that declaration. Native protocols stay behind it: vendor SDKs, OPC UA, SiLA 2, ROS 2, Modbus or whatever the equipment exposes.
# What an adapter declares about one instrument (illustrative)
adapter: furnace_example
capabilities: [set_temperature, hold, ramp, purge_n2]
envelope: envelopes/furnace_example.yaml
channels:
chamber_temp: { sensor: tc_02, unit: degC, max_rate_hz: 10 }
calibration: { source: tc_02.cal, valid_until: <date> }
cost_model: { per_hour_usd: 28, consumables: [n2_gas] }
stop: { software: abort(), hardware: e_stop_relay }
native: vendor_sdk | opc_ua | sila2 | ros2 | modbusNo adapters exist today. Protocol names are examples of the interfaces an adapter would translate to, not integrations.
03
Risk envelopes
The safe operating range of a physical system, written so a machine can check it before acting.
- Operating range
- Allowed values for each controllable parameter.
- Prohibited states
- Combinations that are never allowed, even if each value is.
- Hard maxima
- Motion, force, pressure, temperature, voltage, concentration.
- Materials
- Permitted and forbidden material classes.
- Space and time
- Physical boundary and the window the grant covers.
- Stop and approval
- Emergency stop, and which approvals each class needs.
Out-of-envelope requests are refused and returned with a reason. Terranoux does not quietly adjust a parameter to make a request fit. Widening an envelope is an authority decision, made outside Terranoux.
Try to leave the envelope
Example instrument
instrument reactor_07 # exampletemperature 54°C # range 20–80°Cpressure 1.2 bar # ≤ 2.5 barduration 45 min # ≤ 90 minmaterial_classes [aqueous, non_oxidizing]prohibited_states [dry_heat, sealed_over_2bar]cost_ceiling $400 / runphysical_boundary vessel_interiortime_boundary grant window onlyauthority grant_example_7f3aemergency_stop enabledRefusal log
- no refusals
R1 Reversible
Move a calibrated stage within its travel.
Physical change, easily undone.
Required from LucidRail before Terranoux may act
- Identity of requesting system verified (required)
- Policy permits this action type (required)
- Budget reserved before execution (required)
- Simulation or dry run passed (not required)
- Named human approver (not required)
- Second, independent approver (not required)
- Operator physically present (not required)
04
Simulation first
Simulate, inspect, authorize, execute. Physical runs are for what models cannot answer.
Where a credible model exists, the proposal is simulated before approval is requested. The result carries the model's identity and validity range. Where no credible model exists, that is stated, and the experiment may need a smaller first run or a higher level of approval.
- Predicted outcome
- A band, not a point. Used later to flag surprises.
- Resource use
- Materials, instrument time, energy and cost.
- Envelope violations
- Steps that would cross a limit, removed before review.
- Fidelity
- Which model, which version, and where it is known to fail.
State · Proposed
The engineering model proposes four anneal temperatures. Nothing has been checked yet.
- conditions
- 120 · 160 · 200 · 240 °C
- samples
- 12
- envelope check
- not run
- authority
- none
06
Execution
Configure, check, run, watch. The physical system keeps the right to refuse.
- 01ConfigureSet up equipment to the contract through its adapter.
- 02PreflightConfirm calibration validity, interlock state and the grant window.
- 03RunPerform interventions in order, recording each action as performed.
- 04WatchMonitor stopping conditions and envelope limits continuously.
- 05Deviate or stopRecord every deviation. Stop on any stopping condition, interlock or revocation.
Hardware interlocks and emergency stops sit below software and override it. If an instrument refuses an action, the refusal is recorded as data, not retried around.
07
Measurement
Raw first. Interpretation later, where it can be checked.
- Raw observations
- Unprocessed readings, with units and sampling rate.
- Instrument identity
- Which sensor, which firmware, which channel.
- Calibration state
- When it was last calibrated and against what.
- Uncertainty
- Declared resolution and known error where available.
- Environmental state
- Ambient conditions that could affect the reading.
- Timestamps
- Monotonic and wall-clock, so ordering survives clock drift.
| t | channel | value | source |
|---|
- Experiment specificationsha256 9f1c…e04a
- Authorizationgrant_example_c41e
- Equipment identityfurnace · tc_02 · 4pp_01
- Calibration4pp_01 cal 14 days old
- Actions performed3 setpoints · 9 placements
- Deviations1 · run 7 overshoot
- Raw measurements0 readings, unprocessed
- Environmental stateN₂ · 21.4 °C ambient
- Failuresnone
- Timestampsmonotonic + UTC
- Costs9 samples · 3.57 h · $158
Verdict: not included. The engineering model decides what the evidence means.
08
Provenance
Every run returns an evidence package: the physical equivalent of a receipt.
The package links the exact specification, the authorization, the equipment and its calibration, the actions actually performed, deviations, failures, raw measurements, environmental state, timestamps and costs. It is signed along its chain of custody. The engineering model then decides what the evidence means for the design.
# Evidence package (draft structure)
evidence:
experiment: exp_example_0142 sha256: 9f1c…e04a
grant: grant_example_c41e issuer: lucidrail
equipment:
- furnace_example firmware: <version>
- tc_02 calibration: tc_02.cal (14 d)
- 4pp_01 calibration: 4pp_01.cal (14 d)
actions: # what was actually done, in order
- t: 00:03:41.870 set_temperature 120 degC
- …
deviations:
- t: 02:20:31.761 chamber_temp +1.8 degC over setpoint
observations: raw/ (27 files, unprocessed)
environment: { ambient_c: 21.4, atmosphere: N2 }
failures: []
cost: { samples: 9, instrument_hours: 3.57, usd: 158 }
custody: signed by adapter → executor → engineering model
verdict: null # interpreted downstream, where it can be checkedWhere experiments could run
Existing equipment, through adapters.
Terranoux does not operate labs or facilities. These are the kinds of environments the adapter model is designed for.
Laboratories
chemistry · biology · materials
Keeping calibration state and sample lineage attached to every reading.
Manufacturing
processes · inspection · optimization
Running experiments on a live line without disturbing production outside the envelope.
Robotics
manipulation · mobility · testing
Expressing spatial and force envelopes precisely enough for a machine to check before moving.
Infrastructure
energy · sensors · environmental systems
Attributing a measured change to an intervention when the environment never holds still.
Field environments
agriculture · geology · ocean · climate
Recording environmental state well enough that the experiment means something later.
Principles
Rules for touching reality.
Physical experiments are not cheap and not always reversible. The architecture is held to these.
- 1Simulation before execution.No approval request without a simulation result, or an explicit statement that none is credible.
- 2Authority is external.Terranoux holds no means to issue, widen or extend its own grants.
- 3Every action is bounded.An action with no declared envelope is not available to the experiment model.
- 4Raw evidence before interpretation.The execution layer leaves the verdict empty. Interpretation happens in the engineering model.
- 5Failures are first-class data.Every stop, deviation and refusal is recorded with a timestamp and cause.
- 6Physical systems must be able to refuse.A refusal from equipment ends the step and is reported. It is never retried silently.
- 7Reproducible where possible.Contracts and evidence packages are versioned and content-addressed.
- 8No silent expansion of the envelope.Out-of-envelope requests are refused with a reason and returned unchanged.
When simulation isn't enough, test reality.