Hardware-bound AI governance

AI may think anything.
But only do what's allowed.

EHOX is the guard that can't crash with the AI. It runs on its own processor, with no operating system and no shared software, and checks every command before it reaches the machine. Safe ones pass. Rule breakers are denied. Critical ones wait for a human. Mathematically proven, measured on real hardware, open for anyone to check.

Engineering candidate · design partners wanted for Q4 2026

537 / 0source-level properties checked with CBMC — zero violations
43 / 43proof obligations solved and valid in Z3
44 nspolicy decision on the R5F core (internal benchmark)
50 cyclesof stable behaviour in a row before the gate reopens
The problem

Software can't be the last line of defence for software.

Autonomous systems are leaving the screen and entering the physical world — power grids, drones, trains. Their AI is powerful, but not deterministic. And the safety filters meant to catch it usually run on the very processor that just failed.

Watchdogs are too slow

Software safety filters search for a response at runtime. Under load or attack, that means timeouts — exactly when every microsecond counts.

Jamming blinds the system

Electronic warfare and cyber attacks target the software layer. Once it's compromised, every safeguard running on top of it goes down with it.

AI isn't predictable

Neural networks can't be tested exhaustively. What you can prove is the boundary they must never cross — and enforce it in hardware.

How it works

Three steps. No guesswork at runtime.

EHOX separates what is decided from what is allowed. The AI may compute anything — but only proven-safe commands ever reach the actuator.

AI / Host APU non-deterministic EHOX gate Cortex-R5F · real-time 16 domains · 31 rules Actuator pin motor · valve · breaker safe only commands on fault → DENY / ABSTAIN
01 — Prove

Verified before it runs

Safety invariants are verified ahead of deployment with bounded model checking (CBMC) and SMT solving (Z3). At runtime there's nothing left to search — only to enforce.

02 — Enforce

Checked before actuation

A dedicated real-time core sits between the application processor and the actuator. Every command is checked against the invariants before it touches the hardware.

03 — Recover

Hold, then reopen

On heartbeat loss or a rule violation, the gate decides DENY or ABSTAIN — in 44 ns on the core. It only reopens after 50 consecutive stable cycles (TemporalGuard). Clamping the physical output via FPGA logic is the next integration milestone.

Use cases

Built for systems where failure is physical.

Wherever an AI decision turns into voltage, torque or motion, EHOX is designed to be the last checkpoint — the one that doesn't crash with the software. All domains run on the same reference policy model.

Cyber security · assume breach

Hacked — and still harmless.

An attacker takes over a water utility's control room and sets the chemical dosing to 100 times normal. Firewall and operating system are bypassed, but the command still has to pass EHOX — and a dose above the limit is designed to be denied.

  • No OS, no network stack
  • Root is not enough
  • Tamper-evident log
  • NIS2 · CRA · IEC 62443
NIS2 · SCADA

Energy & critical infrastructure

Power grids, substations, generation plants. If an attack corrupts the control software, EHOX is designed to hold switching commands within verified limits — to prevent blackouts and physical damage.

Contested environments

Defence & autonomous UAS

Drones, guidance systems, space hardware. Effector use stays blocked until a human confirms. If the operator link is jammed, the gate halts instead of releasing without authorisation.

Level 4 autonomy

Rail & heavy mobility

Autonomous trains, vehicles and logistics. Decision logic that cannot change in an over-the-air update — and does not wait for a scheduler under load.

EU AI Act

Enterprise AI & compliance

Meaningful human control, outside the software it supervises. EHOX gives you a reviewable hardware boundary and a tamper-evident audit trail, aligned with Article 14 of the EU AI Act.

Proof & integration

Proof, not promise. Running beside your AI.

Every number on this page is published — with a DOI, a reproduction guide and a live API. And it runs on real silicon: bare-metal on the Arm Cortex-R5F cores of an AMD Zynq UltraScale+ MPSoC, with no operating system and no network stack.

Verified

  • CBMC537 source-level properties across safety requirements S1–S19, zero violations. Covers the checked source — not an attestation of loaded firmware.
  • Z3 SMT43 of 43 proof obligations solved and valid.
  • Timing44 ns policy decision on the Cortex-R5F (internal benchmark, Kria-1). 88.8 µs measured end-to-end transport via RPMsg.
  • RecoveryTemporalGuard: the gate reopens only after 50 consecutive stable cycles (Z3-proven temporal safety).

Integrated

Cortex-R5F · TCMBare-metal — zero OS, zero stack
AMD Kria KV260Reference platform (XCZU5EV)
3.3–3.7 WMeasured power draw (INA260)
16 domains · 31 rulesOne firmware, one policy model

Open, sovereign, reviewable

🇪🇺 ITAR-free · EU-sovereign Open licence OHL-EHOX-1.0 36+ Zenodo DOIs · CC-BY-4.0 Target alignment: EU AI Act Art. 14 · DO-178C · NATO AEP-55

Developed in St. Johann in Tirol, Austria. Status: EHOX Inside (Kria-2) is an engineering candidate — not a released or certified product.

Design partners · Q4 2026

Take EHOX to the next milestone — with us.

EHOX Inside is an engineering candidate. We're looking for a small number of design partners in defence, aerospace, energy and medical to bring physical enforcement onto real platforms. Tell us about your system — we'll get back to you personally.

Request a scoped evaluation →