Spherity Research Topic Page · Executive Brief + Full Research

PACE: Verifiable Safety and Cyber Evidence Graphs for Physical AI

Faster commissioning, controlled change and continuous assurance for robots, connected products and cross-company operations

Author
Affiliation
Dr. Carsten Stöcker — Spherity GmbH
Published
Updated
Research cut-off
· Standards, regulation and implementation evidence reviewed to this date
This version
https://spherity.github.io/spherity-research/physical-ai-compliance-evidence-pace.html
Latest version
https://spherity.github.io/spherity-research/physical-ai-compliance-evidence-pace.html
Browse this paper

In brief

What does this research establish?

PACE—Physical AI Compliance Evidence—is a Spherity research initiative and vendor-neutral best-practice concept for turning fragmented robot, component and lifecycle records into verifiable safety and cyber evidence graphs. The architecture binds evidence to product identity and configuration, supports controlled change and faster justified commissioning, and keeps deterministic safety functions and qualified human assessment outside the evidence graph itself.

Key takeaways

  • Physical AI needs configuration-bound, lifecycle-aware evidence because a component certificate alone cannot prove that a changed robot system remains safe, secure or compliant in its actual use case.
  • A Verifiable Safety Assurance Evidence Graph connects product identity, claims, provenance, tests, configurations, dependencies, status and authorization without pretending that a graph or credential itself confers conformity.
  • PACE can reduce evidence-search and coordination time, support faster justified return to service and create reusable validation services across manufacturers, integrators, operators and assessors.
  • Europe can connect DPP infrastructure, eIDAS trust services, European Business Wallet concepts and established safety engineering, while the core architecture remains extensible to other jurisdictions.

Download the executive brief

Download the executive brief

PACE: From Physical AI Trials to Industrial Operation. A decision-focused brief on verifiable safety and cyber evidence for faster commissioning, controlled change and new validation services.

Download the full research paper

Download the full research

Verifiable Safety Assurance Evidence Graphs for Modular Humanoid Robot Arms. The vendor-neutral reference architecture, standards analysis and evaluation protocol.

First page of the PACE executive brief From Physical AI Trials to Industrial Operation by Dr. Carsten Stöcker.
Executive brief. A concise implementation and business-value guide for industrial leaders, engineers and assurance professionals. Published under CC BY 4.0.
First page of the full research paper Verifiable Safety Assurance Evidence Graphs for Modular Humanoid Robot Arms by Dr. Carsten Stöcker.
Full research paper. The detailed architecture, standards map, evidence model and industrial evaluation design. Published under CC BY 4.0.

Why PACE matters for Physical AI

Physical AI moves AI from recommendations into machines that change the physical world. A modular robot arm can combine components, safety functions, software, AI models, tooling, parameters and operating constraints from multiple organizations. Every material change can alter the evidence needed to justify commissioning or return to service.

Spherity proposes Physical AI Compliance Evidence (PACE) as an industry-leadership research initiative and vendor-neutral best-practice concept. Its core mechanism is a Verifiable Safety Assurance Evidence Graph (VSAEG): a machine-readable, cryptographically verifiable map from a specific product configuration and use case to the claims, tests, provenance, dependencies, status and authority needed for a decision.

PACE turns scattered documents into configuration-bound evidence paths so qualified parties can find, verify and reuse the right evidence faster—without moving deterministic safety functions into the graph or treating a credential as a certificate of safety.

This distinction is essential. PACE supports evidence discovery, integrity, selective disclosure and decision traceability. It does not replace risk assessment, functional-safety engineering, cybersecurity engineering, conformity assessment, technical documentation or the responsibility of manufacturers, integrators, operators and assessors.

Executive brief: from trials to industrial operation

The executive brief translates the detailed research into an operating proposition for Physical AI programs. It focuses on the transition from a promising demonstration to an industrial system that can be commissioned, changed, validated and maintained across a multi-company lifecycle.

The business problem

Evidence is commonly distributed across supplier portals, technical files, certificates, test reports, configuration tools, maintenance systems and email. Teams must repeatedly determine whether a record belongs to the installed component, the current software and parameter set, the intended use and the applicable lifecycle state. The cost is not only audit preparation: slow evidence discovery delays commissioning, change approval, maintenance and justified return to service.

The problem becomes harder when no single organization controls the complete evidence chain. A robot manufacturer, component supplier, AI provider, system integrator, operator, notified or accredited body and regulator may each hold only part of the relevant evidence. Bilateral document exchange does not scale well when products are modular, software changes frequently and access must be restricted.

The solution and business benefits

PACE separates two interoperable planes:

The expected business value must be tested against a document-based baseline. Suitable measures include evidence-search time, time to determine configuration applicability, time to identify affected claims after a change, re-test coordination time, commissioning lead time, justified return-to-service time, duplicate assessment work and the reuse rate of validation evidence.

PACE also enables new service models: continuous evidence monitoring, configuration-delta analysis, supplier evidence validation, machine-readable test coordination, controlled disclosure and reusable assurance packages. These services create value only when evidence quality, authority, current status and responsibility remain explicit.

Full research: a verifiable evidence architecture

The full paper develops a seven-axis reference model for modular humanoid robot arms and a typed evidence graph capable of representing open-world evidence while applying closed-world decision profiles to a specific decision. That combination reflects industrial reality: the wider evidence ecosystem can continue to grow, while commissioning or change approval must use explicit completeness rules and defined acceptance criteria.

Robot Arm Reference Model: from the physical arm to a scoped assurance decision

The Robot Arm Reference Model treats a modular arm as a configured cyber-physical system rather than a single undifferentiated product. The seven axes, exchangeable tool, drives, brakes, sensors, firmware and safety functions contribute component-level evidence. The arm assembly contributes the installed modules, interfaces and system limits. Application evidence adds the tool, payload, task, workspace, people and operating conditions that determine whether earlier evidence is applicable to the actual deployment.

Four evidence scopes must therefore remain connected:

  1. Component passports identify individual modules and link their firmware, calibration, test evidence, limits and current status.
  2. The arm-assembly record names the installed configuration and records interfaces, integration assumptions and system-level safety limits.
  3. Application evidence describes intended use, task, tool, payload, workspace, interaction with people and the validation results for that operating context.
  4. The scoped decision profile specifies which requirements and evidence must be satisfied for commissioning, change approval, continued operation or return to service.
Robot Arm Reference Model showing a seven-axis physical arm and local protection, component passports, arm-assembly records and application evidence feeding an access-controlled VSAEG and scoped assurance decision.
Figure 1. Robot Arm Reference Model: From the physical arm to a scoped assurance decision. Component passports, arm-assembly records and application evidence contribute to an access-controlled VSAEG. Assessment uses the installed configuration, intended use and current status. Immediate sensing and protective action remain in the local safety path. Source: Spherity GmbH.

The reference model draws a deliberate line between assurance evidence and runtime protection. The VSAEG can explain which evidence supports a decision and which change triggers revalidation. It must not sit in the time-critical sensing and protective-action loop. Immediate sensing, the safety controller and the drive or brake path remain local, independent and engineered to the applicable functional-safety requirements.

How the access-controlled VSAEG works

The access-controlled VSAEG combines a control plane for identity, authority and access with a data plane for linked evidence. The separation prevents two common category errors: reliable evidence does not prove that the requester is authorized to see or use it, and a valid mandate does not prove that the underlying safety, cybersecurity or AI claim is supported.

Robot Evidence Control and Data Plane showing Business Wallet and Edge Wallet authority services governing access to linked safety, Cyber Resilience Act and AI evidence in a CRA-capable DPP and VSAEG.
Figure 2. Robot Evidence Control and Data Plane: Shared evidence with distinct regulatory responsibilities. Safety, CRA and AI records are linked through the product and configuration in a CRA-capable DPP/VSAEG. Organisational trust and Edge Wallet services govern authority and access; authorised parties evaluate the evidence under the applicable profile. Source: Spherity GmbH.

The end-to-end process is intentionally scoped:

  1. Identifiable issuers create evidence. Component manufacturers, integrators, test providers and operators issue safety, CRA, AI and lifecycle records with explicit scope, provenance and status.
  2. The product and configuration connect the records. A CRA-capable DPP and the VSAEG link evidence to the relevant component, assembly, software version, parameters, dependencies and use case rather than copying every record into a public passport.
  3. Organizational authority is evaluated separately. Business Wallet or equivalent trust services establish the organization, role and mandate. Edge Wallet or issuer services bind device or issuer keys to scoped signing and verification functions.
  4. Policy controls disclosure and use. The relying party requests a defined evidence view; authorization evaluates identity, mandate, purpose, role and context before protected evidence or references are released.
  5. An applicable profile drives the decision. An authorized party checks the required claims, evidence, arguments, current status and completeness rules for the specific regulatory or operational decision.
  6. Change closes the loop. A changed component, firmware version, AI model, parameter, tool, payload or operating context identifies affected claims and triggers the appropriate review, restriction, test or revalidation.

Together, Figures 1 and 2 form a Spherity content-leadership reference model for robot and robot-component passports, compliance evidence, functional safety, cyber resilience and robot/AI compliance. The model keeps regulatory responsibilities distinct while making their evidence relationships usable across manufacturers, integrators, operators, assessors and trust-service providers.

The architecture evaluates five forms of verifiability:

  1. Cryptographic verifiability — signatures, issuer identity, integrity, status, revocation and time evidence can be checked independently.
  2. Semantic verifiability — shared vocabularies, identifiers, shapes and validation rules make the meaning and structure of claims machine-readable.
  3. Engineering verifiability — evidence is bound to the actual component, software, parameters, interfaces, environment and use case rather than to a generic model alone.
  4. Assurance verifiability — tests, evaluations, credentials and claims expose their scope, method, assessor, result, limitations and dependencies.
  5. Operational verifiability — lifecycle changes, current status, revalidation triggers, incidents and recovery actions remain visible after initial commissioning.

The graph is an evidence and decision-support layer, not the real-time safety controller. Emergency stops, protective stops, speed-and-separation monitoring, power-and-force limiting and other deterministic safety functions remain in qualified local control paths. This preserves a clear boundary between operational safety enforcement and the evidence used to justify, inspect and update the system.

Standards and regulation: a layered evidence map

PACE does not collapse distinct standards or legal regimes into a single compliance claim. It provides a way to connect scoped evidence while preserving which requirement, product role, lifecycle stage and assessor each record supports.

Layer Relevant sources PACE use and boundary
Robot and machinery safety EU Machinery Regulation 2023/1230, ISO 10218-1:2025, ISO 10218-2:2025, ISO 13849-1:2023, IEC 62061, IEC 61800-5-2, ISO 12100 and ISO/TS 15066:2016 Connect hazards, safety functions, performance evidence, tests, configuration and integration conditions. The applicable standard set depends on the machine and use case.
Cybersecurity and product lifecycle Cyber Resilience Act 2024/2847, IEC 62443-4-1 and IEC 62443-4-2 Link secure-development, vulnerability, software-component, update and incident evidence. The CRA does not mandate a DPP; a CRA-capable DPP is an architecture for carrying or referencing governed evidence.
AI assurance AI Act 2024/1689 and ISO/IEC TR 5469:2024 Represent intended purpose, data and model lineage, evaluation, human oversight, monitoring and change evidence without assuming every Physical AI component has the same legal classification.
Product data and identity ESPR 2024/1781, eIDAS 2024/1183, W3C Verifiable Credentials 2.0 and W3C SHACL Use product-linked identity, verifiable credentials and validation shapes for governed evidence exchange. Statutory DPP duties depend on product-specific delegated acts; the proposed European Business Wallet remains prospective.
Assurance cases and attestation OMG SACM 2.3, W3C PROV-O and IETF EAT / RFC 9711 Connect claims, argumentation, provenance and hardware or runtime attestation while retaining the scope and limitations of each evidence source.

Europe’s opportunity—and global extensibility

Europe has an unusually strong combination of machinery and product-safety practice, industrial automation, conformity assessment, regulated product data and cross-border digital-trust infrastructure. PACE can connect those capabilities around a practical task: proving whether the current evidence supports a defined action on a defined configuration at a defined time.

European Business Wallets, if adopted and implemented, could improve reusable organizational identification, representation rights and evidence exchange. The core PACE architecture does not depend on that future legislation. Current eIDAS trust services, organizational credentials, contractual governance and sector-specific mechanisms can support pilots now.

The model is deliberately vendor-neutral and jurisdiction-extensible. International safety, cybersecurity, semantic-web, credential and attestation standards provide portable building blocks. Deployments outside Europe can substitute the relevant legal identities, conformity regimes, accreditation systems and sector rules while retaining the separation of product evidence, organizational authority, policy and operational controls.

An implementation path for manufacturers and ecosystems

  1. Build the evidence foundation and prove customer value. Start with component identity, a verified evidence index and configuration matching. Measure how quickly a team can find the right evidence and determine whether it applies to the installed system.
  2. Pilot controlled change and operational assurance. Connect representative configuration changes to affected claims, required tests, authorization and status. Demonstrate faster, traceable revalidation and justified return to service while keeping local safety controls authoritative.
  3. Evaluate and scale across the ecosystem. Compare the graph-based process with a document baseline, validate interoperability across vendors, establish governance and responsibility, and develop reusable validation and monitoring services.

The first production scope should be narrow enough to test end to end: one modular subsystem, a defined use case, identified organizations, an explicit decision profile and measurable baseline. A larger ontology or more credentials are not substitutes for evidence that the approach improves the real commissioning and change process.

Sources, citations and evidence boundaries

Executive brief citation. Stöcker, Carsten (2026). PACE: From Physical AI Trials to Industrial Operation—Verifiable safety and cyber evidence for faster commissioning, controlled change and new validation services. Spherity Research. Executive Brief PDF.

Full research citation. Stöcker, Carsten (2026). Verifiable Safety Assurance Evidence Graphs for Modular Humanoid Robot Arms—A vendor-neutral architecture for functional safety, cyber resilience, lifecycle assurance and use-case-specific compliance. Spherity Research. Full Research PDF.

The papers distinguish adopted law, published standards, proposals and architectural recommendations. The PACE label and reference architecture are Spherity research concepts, not a regulatory designation, certification scheme or claim of industry consensus. Product classification, legal obligations and conformity routes must be determined for each deployment and jurisdiction.

Google Trends was reviewed on 9 September 2026 for editorial wording. The comparisons used normalized relative-interest indices, not absolute search volumes. “Physical AI” supplied the clearest discovery signal; “robot safety”, “AI compliance”, “Cyber Resilience Act”, “Digital Product Passport” and “Maschinenverordnung” connect the specialist architecture to established audience language. The authority terms Physical AI Compliance Evidence and Verifiable Safety and Cyber Evidence Graph were retained because they precisely describe the contribution even where specialist query volume is below reporting thresholds.

Creative Commons Attribution 4.0 International

Open research

License and citation

This PACE research collection—the topic page, executive brief and full research paper is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.

How to cite this work

Dr. Carsten Stöcker (2026-09-09). “PACE: Verifiable Safety and Cyber Evidence Graphs for Physical AI: Faster commissioning, controlled change and continuous assurance for robots, connected products and cross-company operations.” Spherity GmbH. https://spherity.github.io/spherity-research/physical-ai-compliance-evidence-pace.html. Licensed CC BY 4.0.

Direct answers

Questions this research answers

What is PACE for Physical AI?

PACE means Physical AI Compliance Evidence. Spherity presents it as an industry-leadership research initiative and vendor-neutral best-practice concept for organizing verifiable safety, cybersecurity, lifecycle and use-case evidence across company boundaries.

What is a Verifiable Safety Assurance Evidence Graph?

It is a typed graph that links product and component identity, configuration, claims, evidence, provenance, tests, dependencies, status and authorization. It helps a relying party find and verify evidence paths, but it does not itself certify a product or replace safety engineering and qualified assessment.

What does the PACE Robot Arm Reference Model connect?

The model connects component passports, the installed arm assembly and application-specific evidence to a named configuration, intended use, validation profile and current status. The resulting evidence path supports a scoped assurance decision while immediate sensing and protective action remain in the independent local safety path.

How can PACE accelerate commissioning and controlled change?

PACE makes evidence discoverable, configuration-bound and reusable. When a component, software version, parameter or use case changes, teams can identify affected claims, required tests and missing evidence faster, then document a justified decision and return to service.

How do DPPs and European Business Wallets fit the architecture?

A DPP can provide the product-linked evidence entry point and lifecycle subgraph. Organizational identity, mandates and access policy form a separate control plane that can use current eIDAS trust services and, if adopted, future European Business Wallet capabilities.

Does a credential or evidence graph prove that a robot is safe or legally compliant?

No. Credentials and graphs support integrity, provenance, scope and verification. Safety, conformity and legal authority still depend on applicable law, the complete technical file, competent assessment, system integration, the operating context and current product status.

Can the PACE architecture be used outside Europe?

Yes. The reference combines European regulation and trust infrastructure with international safety, cybersecurity and web standards. Its modular identity, evidence, policy and assurance layers can be profiled for other legal regimes and sector-specific requirements.