STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
ISO 25785-1 (ISO/TC 299 WG 12)

ISO 25785-1 · dynamically stable robots

ISO 25785-1 is at Committee Draft (ISO/CD) and is not published. This page is therefore anticipatory positioning — a statement that the evidence exists ahead of the standard — and explicitly not a conformity claim against a text that does not yet exist. No clause is cited here, because there is no stable clause to cite. What it is: the first Type-C standard aimed at dynamically stable (legged and humanoid) robots, addressing the balance-and-fall hazards a legged machine has and a statically stable one does not.

Committee Draft (ISO/CD 25785-1) under ISO/TC 299 WG 12 — CD registered 8 May 2026, consultation opened 12 May 2026. NOT PUBLISHED, and no fixed publication date. No clause numbering is stable enough to cite.Evidence, not certification.
What it is

The framework

  • ISO 25785-1 is being developed by ISO/TC 299 (Robotics) Working Group 12, covering industrial mobile robots that are dynamically stable — legged and humanoid machines that stay upright by continuously controlling balance.
  • It is a Type-C standard: specific to a machine category, sitting above the general safety standards rather than replacing them.
  • It is not published, and no publication date is fixed. This site previously described it as a Working Draft; it moved to Committee Draft on 8 May 2026, which is a later stage and a material difference — a CD is out for committee consultation, a WD is not. Until it lands there is no clause list, no numbering and no conformity route to map onto.
  • Until then, a humanoid builder’s safety file leans on the general machinery route (EU Machinery Regulation 2023/1230, Annex I Part A) plus the functional-safety standards (IEC 61508, ISO 13849) — which is why those three pages exist alongside this one.
The hook

Where a red-team result fits

The hazard a legged machine adds

A fall. A centre of mass leaving the support polygon. A self-collision. A footstep into a keep-out zone. These are hazards a statically stable arm does not have, and they are the hazards a dynamically stable machine has to argue about.

Why anticipatory is the honest label

The evidence exists now; the standard does not. Presenting a measurement against an unpublished draft as conformity would be inventing a route. Presenting it as nothing would be pretending the hazard is not already testable. This page takes the middle position and names it.

What Provael maps to it

Evidence produced

  • The shipped whole-body humanoid suite, whose unsafe predicate is a fall or topple, a centre-of-mass excursion outside the support polygon, a self-collision, or a footstep keep-out breach.
  • balance_spoof (EAI02) — spoof the policy toward a loss of balance and score whether it recovers or steps unsafely.
  • whole_body_hijack (EAI04) — redirect the commanded whole-body motion.
  • stride_freeze (EAI04) — stall the gait mid-stride.
  • These three attacks ship stub-validated on the deterministic CPU humanoid suite, and no real-model transfer is claimed. A 100% fixture rate is a property of the fixture, not of a humanoid policy. The real GR00T-N1 humanoid transfer study is pre-registered and has not been run.
  • What that buys you today is a defensible adversarial-robustness baseline and a repeatable harness you can point at your own policy — not a conformity position against ISO 25785-1, which does not yet exist to hold one against.
Timing

Dates (verified 19 Aug 2026)

Status
Committee Draft (ISO/CD) — not published
ISO/TC 299 WG 12. CD registered 8 May 2026, consultation opened 12 May 2026; no fixed publication date. Verify the live ISO record before relying on any date; a draft standard’s timetable moves, and this page carried the previous stage for months.
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - The measured result uses templated, auditable attacks; the search-based families (optimized, universal_patch, gradient_patch) have only met the CPU fixture. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.