
Every day, Embotech’s autonomous driving systems move around 2,500 vehicles through factories and ports.
They do this 24/7, in productive deployments and complex mixed-traffic environments where autonomous vehicles operate alongside workers, manually driven vehicles, trucks, forklifts, and other industrial equipment.
Each vehicle makes thousands of decisions in real time: where it is, what it sees, how fast it should move, whether another road user may cross its path, whether the planned trajectory is still safe, and much more.
Most of the time, these decisions are invisible. The vehicle simply drives.
But safe autonomy is not proven by what happens when everything works perfectly. It is proven by what happens when something goes wrong.
A worker crossing in front of an autonomous vehicle is a simple example.
For a human driver, the reaction may feel immediate: see the person, recognize the danger, brake.
For an autonomous vehicle, the same reaction depends on a chain of safety-relevant functions: the perception system must detect the worker, the planning software must request an emergency stop, and the braking system must execute the command.
A failure can occur anywhere in this chain. A sensor may degrade or fail, localization may drift, the planned trajectory may no longer be collision-free, a compute platform may fail, or the braking command may not be executed as expected.
This is where functional safety becomes essential.
Functional safety is the discipline of ensuring that a system remains safe when electrical, electronic, or software components malfunction. In simple terms, it asks: if something fails, what must the autonomous system do to prevent that failure from becoming an accident?
For autonomous driving, this is a system-level question. Safety does not come from one component alone. It depends on the correct interaction of sensors (perception and localization), compute, communication networks, and actuators (braking, acceleration and steering).
Why Machine Safety Matters
Because Embotech’s systems operate continuously in productive industrial environments, safety must be designed into the architecture from the beginning.
This is what “safe by design” means: the system is designed to detect degraded conditions, mitigate faults where required, and reach a safe state when continued operation is no longer safe.
For this reason, Embotech develops and certifies its systems according to machine-safety principles, especially ISO 13849.
ISO 13849 is particularly relevant for industrial autonomy because it focuses on safety-related control functions: the parts of a machine control system that are responsible for reducing risk. In Embotech’s systems, these include functions such as safe perception and localization, trajectory monitoring, and redundant emergency braking.
For risk analysis, Embotech applies the ISO 26262 methodology to analyze driving-related hazards, as it provides an equivalent approach to the risk assessment required by ISO 12100 while adding automotive-grade rigor.
The advantage of this approach is that safety is built into the system by design. It is traced from risk analysis to requirements, implemented through defined safety functions, and validated through testing.
From Risk Analysis to Safety Requirements
Embotech’s safety process starts with systematic risk analysis.
For each function, operating environment, and use case, the Hazard Analysis and Risk Assessment (HARA) identifies potential faults and the resulting hazardous events. Each hazardous event is analyzed in the corresponding operational situation by assessing the potential severity of harm, the exposure of humans to that situation, and the controllability of the hazard. These factors determine the risk classification and the safety measures required to reduce the risk to an acceptable level. From this analysis, we derive concrete safety requirements.
These define what the vehicle must monitor, which failures must be detected, when the vehicle is allowed to drive, and when it must stop.
Examples include:
These requirements influence architecture, hardware selection, software design, testing, validation, and certification.
Standards and Certification
Autonomous driving in gated industrial environments is not fully covered by one dedicated functional safety standard. As a result, Embotech combines the most relevant principles from multiple standards into one coherent safety concept.
ISO 12100 provides the foundation for machinery risk assessment and risk reduction.
ISO 13849 supports the design and validation of safety-related control functions and performance levels for machinery.
ISO 26262 contributes automotive functional safety thinking, especially for analyzing driving-related hazards caused by malfunctioning electrical and electronic systems.
The resulting safety concept and certification strategy were reviewed and agreed upon with TÜV SÜD, the independent assessment body responsible for the certification.
Safety That Scales
In industrial operations, safety is non-negotiable. But availability is also critical. A vehicle that stops unnecessarily may be safe, but it will not operate efficiently and integrate smoothly into existing processes.
The real engineering challenge is therefore to combine safety with industrial-grade availability and performance.
This balance is what separates a promising autonomous-driving prototype from a scalable industrial system.
Embotech has achieved this through an AI-powered autonomy stack built on a dual-path architecture: An AI driver optimizes the driving trajectory, learning from every drive, while a deterministic safety layer certified by TÜV SÜD provides the foundation for safe and reliable operations. This combination enables safety-certified Level 4 autonomy operating at scale, while achieving >99.5% availability in demanding industrial environments.
For customers, this means autonomy that is not only technically impressive, but also operationally deployable: engineered for safety from the start, validated in real environments, and designed to support productive operations at scale.
Written by:
Dany Yazbeck, Functional Safety Director
