AI Guardrails

An AI safety tool you don’t have to trust

Certification is earned by verifiable evidence, not by assertion. An AI that silently authors safety claims is a liability, not a feature. So the part you must trust here is not the AI — a deterministic engine owns every number, and the model is confined to proposing drafts a qualified engineer explicitly accepts.

SLA-WP-002 Rev 2.2  ·  Last reviewed: July 2026  ·  Questions: waqas.nafees@safetylabaero.com

The guardrail posture, in one line

The AI proposes, the deterministic engine computes, the qualified human decides — and every layer in between is grounded in the standards and the live project, routed through one governed gateway, citing its sources, calibrating its confidence, checking its own consistency, hard-gated, independently verified, recorded as evidence, and continuously red-teamed. The tool stands on its own: every analysis can be performed end to end on the deterministic core, and the AI is an optional accelerator, never a dependency.

The boundary

The deterministic core — the AI never does the math

The single most important guardrail is architectural: the numbers are never the model’s opinion.
AI may propose

A candidate fault-tree shape. A failure condition. A requirement. Narrative and justification prose. Structure and organisation — reversible, attributable, and inert until a human accepts it.

Engine alone decides

Exact top-event probability via Binary Decision Diagrams (repeated-event-correct). Common-cause failure by β / Multiple-Greek-Letter. Exposure-aware top-down DAL allocation. Component data from a curated reliability library.

The model has no path to author or alter a number. The engine is cross-checked by a benchmark suite and an independent Monte-Carlo path.

Acceleration without abdication

What's in production today

The AI gateway — one governed path

Every AI request, from the conversational assistant or a one-click feature, passes through a single internal gateway rather than calling a model directly.

Grounding — the golden thread and the standards

An ungrounded model invents. Every AI feature is grounded in two things before it produces anything.

The guardrail stack

Grounding reduces error. These layers catch and contain what remains — on every AI write path, assistant and one-click alike.
The guardrails on hard cases

Worked examples

Guardrails are easiest to judge not on clean inputs but on the awkward cases an experienced engineer recognises — where a proposal looks plausible and the right answer comes only from applying a published rule. Each is a standing case in the eval and red-team suites, so this behaviour is regression-protected on every build.
“It is too unlikely to need evaluation.”Refused
Rule
Under ARP 4761A a hazard is classified by the severity of its effect, independent of its likelihood — the probability target is a consequence of the classification, not an input to it.
Outcome
The consistency engine and hard gates reject the likelihood-based reclassification and hold the worst-credible-effect severity — and the engineer is shown the rule, not merely a refusal. This is the failure mode every line engineer has seen: the hazard dismissed as too unlikely is the one that later occurs.
A Catastrophic top event reached by a single pathFlagged
Rule
A Catastrophic effect must not rest on a single point of failure, and an AND-gate must genuinely require all of its inputs.
Outcome
A format check alone would pass this. Only the gate-logic check catches that the structure implies an unguarded single point of failure — and it is the independent verifier, a different model from the one that drafted the tree, that raises it for the engineer to resolve before acceptance.
A fault tree with nothing under itStopped
Rule
Fault-tree depth is bounded by the architecture provided; absent inputs, the insufficiency guard declares the gap.
Outcome
There is no basis from which to derive contributors, so any expansion would be fabrication. The assistant states what is missing and stops, rather than inventing intermediate events to look complete.
An approximate read, confirmed rather than rejectedHeld for confirmation
Rule
Vision-derived structure is approximate until a human confirms it.
Outcome
The gate is not wrong, only unconfirmed — so the correct action is verification, not rejection. Once the engineer confirms it against the design it is accepted and stamped. The guardrail adds a checkpoint; it does not block good work.
A requirement drawn straight from the sourceAccepted
Rule
A proposed item is admissible when its supporting span resolves in an approved, in-configuration document and its confidence is not downgraded.
Outcome
The citation check passes against the live project and nothing is stale or out of scope, so the proposal clears grounding and citation. It is presented at full confidence and accepted on the engineer’s sign-off, with provenance stamped. The guardrails are a filter, not a blanket no.
None of these outcomes depends on the AI “behaving.” Each is a deterministic rule applied after the model proposes — which is why the same case can be replayed on every build and graded pass or fail.
Accountability and the record

Human in the loop — propose, review, accept, sign off

AI Evidence Records and the correction dataset

The DER-ready answer to “how exactly was this produced, and who disposed of it?”
Where the regulator has landed

Bounded AI is now the requirement, not our preference

For most of the AI wave, “keep the AI advisory and the deterministic core authoritative” was a design choice we defended on first principles. In 2026 it became regulatory direction.
Guardrail-to-mechanism map

Every risk, and the layer that catches it

RiskGuardrailWhere it acts
The AI does the mathDeterministic engine owns all quantificationEvery probability / allocation
Wrong backend for controlled dataAI gateway policy routerEvery AI request
Fabrication without inputsInsufficiency guard; depth bounded by architectureAll drafting features
Ungrounded claimsSource-span citation + calibrated confidenceEvery proposed item
Stale / wrong-config evidenceApproved-and-applicable evidence filterEvery retrieval
Approximate diagram readsVision flag + verify-to-accept gateDecompose, FTA synthesis, chat
Silent inconsistencyGolden-thread consistency engineAfter every AI write
Wrong severity / gate logicHard gates + independent verifier (generator ≠ judge)Safety-critical drafts
Format / standards driftDeterministic validators + scorecardAll AI artifacts
Unattributed changeProvenance stamp + AI Evidence Record + human acceptOn acceptance
Regression over timeEval harness, red-team suite, deploy gate, correction datasetContinuous
How it stays true

Measured and defended on every build

Guardrails are only credible if they are measured over time. “Safe today” is re-proven on every build, not inherited from the last one.

Evaluating the AI for a certification programme?

We’re glad to walk your safety, software and airworthiness teams through the guardrail architecture, answer a questionnaire, or share the full white paper (SLA-WP-002) and supporting evidence under NDA.

Safety Lab Aero · Summarised from SLA-WP-002 Rev 2.2 (Released, 23 July 2026). This page describes the architecture in effect as of the review date above and is provided for evaluation purposes.
It is not a warranty or a contract. See also Trust & security for data isolation, encryption and lifecycle controls.