Beta Robotics

Safety Is an Architecture Decision, Not a Feature

Teams routinely treat safety as a layer added near the end: a bounding box on velocity, an emergency stop, a check that runs before each command is dispatched. It ships, it passes review, and it is structurally unsound.

A learned policy that has never been constrained during training will constantly probe the edges of whatever limits you bolt on afterward, because those edges are where the reward was highest. The safety layer becomes an adversary rather than a backstop, and every near-miss looks like a bug in the limiter instead of what it is.

The alternative is to make the constraint part of the system the policy is optimizing against from the first episode. Control barrier functions, action spaces that cannot express unsafe commands, hardware limits that are physically impossible to exceed. Safety you can remove without changing behavior was never doing anything.