When an AI robot causes an incident, the only record is self-reported — by the machine that caused it. Roboblackbox is the independent flight data recorder — the one they can’t rewrite.
Independent evidence for underwriting, claims, and subrogation.
Talk to us See a recorded runBefore a robot enters a facility, the operator and integrator establish a safety envelope through commissioning — a documented baseline of exactly how it moves: maximum reach, closest approach to people, force limits. This certified baseline is what the insurer prices against.
AI-controlled robots receive model updates the same way a phone receives a software update. The robot starts moving differently. No alarm sounds. No re-certification is triggered. The operator, the insurer, and the regulator have no way of knowing the certified safety envelope no longer reflects how the robot actually behaves.
We independently record every movement against the operator’s declared safety policy. When the robot’s actual behaviour crosses the certified line — as in the animation above — we derive a tamper-evident violation record. The robot’s own log showed no fault. Ours did.
Every existing record of a robot incident is produced, held, and formatted by the party that built the machine — the party with the most to lose.
Robots are commissioned with a safety envelope — a verified baseline of how they move, how much force they apply, how close they get to people. AI model updates can silently drift that behaviour past the certified envelope. The robot won't flag it. There is no external record it happened.
Without independent behavioural data, insurers have no independent way to verify claims, price the risk, or build a subrogation case. The only account of an incident comes from the party with the most to lose.
January 2026 ISO endorsements (Verisk CG 40 47) give insurers the tools to exclude generative AI injuries from standard policies. The specialty market is inheriting a risk it cannot price.
Roboblackbox sits alongside an AI-controlled robot — without touching it, modifying it, or interfering with what it does. It observes the robot’s commands and movements on the bus, seals each record so that any alteration is immediately detectable, and independently derives safety findings from the data after the fact. No modification to the robot. Nothing written to any actuator. Deploying it cannot cause an incident, by design.
Findings the robot never computed, derived from raw recorded data — and re-derivable by any third party from the record alone.
In any claim or dispute, the record cannot be challenged as having interfered with the incident — because it is architecturally incapable of doing so.
Every record is hash-chained at receipt. Alter one byte and verification fails — the tampering becomes the evidence.
No contact. No injury. No witness. The robot produced no evidence this happened — the sealed record did. That is the difference between an allegation and evidence.
On demand: an independent, tamper-evident record of the hours before an incident — which AI model version was running, and whether the robot stayed within its envelope.
Weekly and retrospective — the loss-run equivalent for robot behaviour. Proximity violations, envelope exceedances, drift since commissioning. Derived from the sealed chain, not self-reported by the robot.
Per AI model deployment: what changed, and whether it pushed the robot outside its envelope — tying behavioural change to the model version that introduced it.
This risk class has been priced on exposure, not behaviour — because behavioural data didn't exist. The Safety Scorecard is the loss-run equivalent for robot behaviour: how often the robot came closer than its policy allows, whether behaviour has drifted since commissioning. That data now exists.
Raw data stays on-site. Derived scorecards and dossiers leave only on explicit operator action.
Courts trust records created before a dispute begins. By the time a claim lands, the Roboblackbox record is already sealed and timestamped — it cannot be assembled after the fact. The dossiers collected before the incident become the subrogation case.
We create the record before it is needed — afterwards is too late.
One record — enables pricing before the incident, answers claims after it.
6 years Microsoft Defender — USB device control, security infrastructure (macOS). 5 years Meta — Messenger desktop update & install infrastructure, Facebook iOS performance/reliability, AI infrastructure (GPU allocation).
7 years Microsoft Defender — runtime security engineering, core backend services. Leads the recorder and policy-analysis architecture.
Eighteen combined years building security software at Microsoft Defender and Meta — recording adversary-grade events on machines we didn’t control. Both full-time. Working end-to-end proof of concept complete; validating the evidence standard with insurers and operators now.