What the Standards Actually Require
ISO 10218-1 specifies safety requirements applicable to the industrial robot itself, the manipulator, the controller, the safety-related control functions. ISO 10218-2 extends those requirements outward to the integrator and to the application: the cell, the end-effector, the workpiece, the human task. ISO/TS 15066, published as a technical specification rather than a full standard, fills the gap that the original 10218 left open: how to operate a robot in a shared workspace with a human present, which is the defining condition of a collaborative robot.
The collaborative-operation taxonomy in 15066 is structurally explicit. It enumerates four collaborative modes, safety-rated monitored stop, hand guiding, speed and separation monitoring, and power and force limiting, and specifies, for each, the admissibility conditions under which the mode is permitted, the monitoring required to maintain those conditions, and the protective behavior required when conditions are violated. Power and force limiting in particular reaches further: it incorporates biomechanical limit data (the 15066 Annex A pain-onset thresholds) that bound permissible transient and quasi-static contact forces by body region.
ANSI/RIA R15.06 adopts ISO 10218 substantively for the United States and is enforced through OSHA general-duty-clause findings and through customer specifications that name R15.06 directly. The EU Machinery Directive 2006/42/EC has, since 2009, required CE marking on industrial robots and has incorporated the harmonized standards by reference. The Machinery Regulation 2023/1230, applicable from January 2027, replaces the Directive with binding regulation, expands scope to include software-defined safety functions and AI-assisted control, and introduces conformity-assessment obligations that explicitly contemplate post-market modification and learning. Across all of these layers the structural pattern is the same: safety is a decomposition into declared modes with declared rules.
How Cobot Controllers Currently Implement Modes
Across the collaborative-robot market, controller vendors treat the 15066 mode set as an implementation requirement met inside the controller stack. The common pattern is consistent regardless of manufacturer. Each controller carries a safety-rated subsystem, typically a dual-channel safety controller distinct from the motion controller, that supervises the collaborative modes. Each vendor defines proprietary parameter sets that map the mode taxonomy onto its own kinematics. And each vendor engages a notified body to certify that the controller meets the performance-level and safety-integrity-level requirements that 10218-1 cross-references from ISO 13849-1 and IEC 62061. This holds for the lightweight torque-sensing cobot families that pioneered the category, for the high-payload collaborative arms that followed, and for the cobot-native entrants offering force-limited manipulators as standard product.
Each vendor likewise publishes a safety-function manual that enumerates the safety-rated I/O, the safety-rated tool-center-point limits, the safety-rated joint-torque limits, and the safety-rated zone-monitoring functions available on the controller. Each integrator is then expected to compose these vendor-specific functions into the application's risk assessment per ISO 12100 (the parent risk-assessment standard) and to document the resulting cell against 10218-2.
The certification produces a controller-level conformity assessment. What it does not produce is portable compliance evidence at the application layer. Integrators building cells under 10218-2 must reconstruct, for their specific application, that the active mode at any given moment was the correct mode, that the transition into that mode was admissible, that the protective behavior on transition matched the declared rule, and that the biomechanical limits applicable in the active mode were not exceeded. Today this reconstruction is an evidentiary exercise: log files, parameter dumps, video review, integrator narrative.
Graduated Modes as Structural Primitive
Governed Actuation discloses a graduated-actuation-mode selector that chooses one of a plurality of governance-policy-defined actuation modes for each proposed actuation, producing a continuous and bounded mapping from a composite-admissibility determination to an actuation mode rather than a binary permit-or-deny decision. That selector is the architectural counterpart of the 15066 taxonomy. Each mode in the actuation substrate carries a declared admissibility predicate, a declared protective-behavior contract, and a declared transition rule. Mode entry, mode operation, and mode exit are not log lines emitted as a side effect: they are credentialed events recorded into the actuation lineage, the lineage field that the disclosure attaches to every actuation decision. The lineage is the audit artifact.
Mapping is direct. Safety-rated monitored stop becomes the mode whose admissibility predicate is "operator-zone occupancy detected and zone-boundary monitoring nominal" and whose protective-behavior contract is "drive power maintained, motion zero, monitored." Hand guiding admits under "enabling-device engaged, force-input within hand-guide envelope." Speed and separation monitoring admits under "separation distance greater than protective separation distance for current speed vector." Power and force limiting admits under "kinetic and quasi-static energy bounds per body-region map within Annex A thresholds." Each predicate is declared, each transition is credentialed, each exit is recorded.
The substrate change is significant. Under the architecture, a notified-body auditor reading the lineage can verify mode admissibility by reading the declared predicate against the recorded sensor state at transition time. There is no reconstruction step. The compliance question collapses from "did the integrator's evidence support the claim" to "does the architectural record show declared admissibility."
Compliance Audit Under the Architecture
Notified-body audits, customer audits, post-incident regulatory audits, and OSHA inspections each traverse the same logical path: which mode was active, what sensor state triggered the mode, what protective behavior executed, whether mode transitions complied with declared rules, and whether biomechanical limits applicable to the active mode held throughout. Under conventional architectures that path is reconstructed from heterogeneous evidence. Under Governed Actuation it is read directly from the lineage. The disclosed actuation chain runs observation through evaluation through execution through verification: a proposed actuation is evaluated by the composite admissibility evaluator, which produces an accepted, gated, deferred, or rejected outcome rather than a binary go or no-go; the graduated-actuation-mode selector chooses the mode that matches that outcome; the actuator driver executes at the selected mode; and a post-actuation verification mechanism compares observed effects against expected effects, with every evaluation, mode selection, and verification outcome recorded into the lineage field.
The shift matters most at three audit boundaries. First, post-incident: when a contact event occurs, the lineage shows whether the active mode was admissible, whether sensing was nominal, and whether the protective behavior fired on rule. Because the selector supports mode de-escalation during execution, an actuation already in progress at one mode is transitioned to a reduced mode in response to a newly arriving observation indicating reduced admissibility, and that transition, with its triggering input and timestamp, is itself in the record. Second, post-modification: when an integrator changes end-effector mass, payload, or workspace geometry, the architecture re-evaluates declared admissibility against the new parameters and surfaces any mode that no longer admits, without waiting for a violation. Third, post-update: when the controller firmware or the safety-function software is revised, the architecture preserves the declaration history, so an auditor can trace which version of which rule governed which transition.
Two further behaviors of the disclosed substrate carry directly into cobot audit. A safety-rated monitored stop demanded by an emergency condition maps onto the disclosure's emergency-preemption mechanism, in which a credentialed emergency-authority observation elevates the actuator's selected mode subject to a preemption-budget enforcer that rate-limits how often a given authority may compel preemption within a temporal window and records budget exhaustion in the lineage; this distinguishes a genuine emergency stop from routine operational signaling and gives an auditor a frequency record. And when a cell loses a sensing tier at runtime, the confidence governor reduces the unit's execution readiness proportionally, degrading toward a conservative posture in which the robot operates on its own sensing with governance-policy-defined behavioral conservatism rather than continuing at nominal autonomy on stale inputs.
Controller vendors that adopt the graduated-actuation-mode selector gain structurally supported compliance audit at the controller layer. Integrators that build on those controllers gain the same property at the application layer. End customers, automotive bodyshops, electronics-assembly lines, pharmaceutical packaging cells, and the small-and-medium manufacturers who buy cobots precisely to avoid the integration cost of caged industrial robots, gain audit evidence without the integrator-narrative reconstruction step.
The Machinery Regulation 2023/1230 Inflection
The transition from Machinery Directive 2006/42/EC to Machinery Regulation 2023/1230 changes the compliance landscape in ways that favor architectural decomposition. The Regulation is binding rather than transposed, narrowing member-state interpretive variance. It expands scope to include software updates that alter safety functions, requiring re-assessment when post-market changes affect declared safety properties. It adds explicit obligations around cybersecurity of safety functions, recognizing that a safety controller's integrity depends on the integrity of the channels that command it. It introduces a category for "high-risk machinery" that includes machines with safety-related AI components and obligates third-party conformity assessment for those.
Each of these changes pulls compliance toward a model in which the architectural record is the audit artifact. A graduated-actuation substrate that records declared admissibility and credentialed transitions answers each new obligation in the same vocabulary the Regulation uses. Software-update reassessment becomes a re-evaluation of declarations against the new code; cybersecurity of safety functions becomes a property of the credentialing layer that admits commands into modes; AI-assisted control becomes a learnable predicate inside an otherwise unchanged admissibility framework.
Where Cobot Procurement Is Heading
Three procurement trends converge on the architectural primitive. The first is the migration of cobots out of the lab-and-pilot zone into production lines that previously used caged industrial robots: large automotive original-equipment manufacturers, electronics contract manufacturers, and their Tier-1 suppliers all run cobot programs at scale, and at scale the integration-narrative compliance model becomes the bottleneck. The second is the rise of robotics-as-a-service offerings, where the service operator is the duty-holder under 10218-2 and needs compliance evidence that survives customer churn and equipment redeployment. The third is the EU Machinery Regulation's January 2027 applicability date, which forces a re-assessment cycle across the installed base.
Controller vendors adopting the graduated-actuation-mode selector at the controller layer position their products for each of these trends. Integrators adopting it at the application layer position their cells the same way. The compliance regime is already structured around declared modes; the architecture matches the structure the standards have always required.
A further dimension worth naming is the convergence with functional-safety standards adjacent to 10218. ISO 13849-1 (performance levels for safety-related parts of control systems), IEC 62061 (safety integrity levels for machinery), IEC 61508 (the parent functional-safety standard), and ISO 13855 (positioning of safeguards relative to approach speeds) each contribute requirements that bear on cobot mode operation. The performance-level rationale that 13849-1 demands, a justified PL claim with diagnostic coverage, common-cause failure analysis, and category determination, is, structurally, a declaration about the mode's protective behavior under failure. Graduated modes carry exactly that declaration as a first-class architectural property. The cross-standard composition that integrators currently assemble through engineering documentation packages becomes a property of the architectural record.
The implication for the wider safety-of-machinery ecosystem is that the mode-decomposition primitive generalizes beyond cobots. Mobile robots under ISO 3691-4, autonomous mobile manipulators under the in-development ISO 25785 series, surgical and rehabilitation robots under the IEC 80601-2-77 and IEC 80601-2-78 family, and outdoor field robots under ISO 18497 each define mode taxonomies with the same structural shape. A substrate that handles graduated modes for industrial cobots handles graduated modes across these families with the same architectural vocabulary, which is the property that makes the primitive worth standing up at the substrate layer rather than rebuilding it inside each vertical.
Disclosure Scope
The governed-actuation technology described here, the graduated-actuation-mode selector, the composite admissibility evaluator producing accepted, gated, deferred, and rejected outcomes, the per-actuator confidence thresholds and their dispositional and capability-aware modulation, the emergency-preemption mechanism with its preemption-budget enforcer, the post-actuation verification mechanism, the lineage-recorded actuation provenance, and the graceful degradation toward an infrastructure-denied posture, is disclosed in U.S. Provisional Application No. 64/049,409. The application draws on the confidence governor disclosed in U.S. Patent Application No. 19/647,395 and the cryptographic governance disclosed in U.S. Patent Application No. 19/561,229.
The named standards and regulatory regimes (ISO 10218-1, ISO 10218-2, ISO/TS 15066 and its Annex A biomechanical limits, ANSI/RIA R15.06, ISO 12100, ISO 13849-1, IEC 62061, IEC 61508, ISO 13855, the EU Machinery Directive 2006/42/EC, the EU Machinery Regulation 2023/1230, ISO 3691-4, the ISO 25785 series, IEC 80601-2-77, IEC 80601-2-78, and ISO 18497) are referenced as the compliance context the technology serves. They are not claims of the disclosure, and no commercial robot, controller, or service named or unnamed is described as practicing the disclosed technology. The mapping of the 15066 collaborative-mode taxonomy onto the graduated-actuation modes is presented as one enabling implementation; the modes, predicates, and thresholds described are governance-policy-defined and configurable per actuator class, deployment domain, and authority level, and the disclosure expressly contemplates additional modes and additional deployment domains beyond those enumerated here.