The certificate for the object · seven verified slices
The No-Harm Certificate
A grasp can be force-closure-perfect, energy-bounded, and viscoelastically safe — and still crush the thing it holds. This is the certificate for the object: a guarantee that the manipulation does not permanently harm what it touches. It is a peer to the no-harm-to-others certificate — same shape, different protected party.
Charlot Lab, Institute for Physical AI @ BMI
1 · The third fate of energy
Track the energy a grasp pushes into an object and it has three destinations. Some is stored elastically and is recoverable — the reservoir that ejects the object on release, certified in The Grasp Certificate, §6–7. Some is dissipated as heat by viscoelastic damping — which a certificate can even credit, since it shrinks the recoverable reservoir. And some is spent irreversibly, permanently deforming or fracturing the object. That last fate is damage, and no energy or force certificate sees it, because it is not about the body's state or the contact's slip — it is about the object's material integrity. The no-harm certificate is a barrier in a new variable: keep the contact stress under the object's yield surface, with margin, so no energy takes the irreversible path.
2 · The yield barrier
Model the contact as elastic-plastic (a 1-D return mapping with isotropic hardening): below the yield force $f_y$ it is a spring; above it, the material flows and takes a permanent set. A $0.30$ kg object needs only $f_n\ge W/\mu = 3.3$ N of grip to hold by friction — far below a fragile object's yield at $f_y=15$ N. So holding without damage is entirely possible; whether it happens is a choice the certificate makes.
| controller | peak grip | held | permanent dent | plastic work (damage) |
|---|---|---|---|---|
| Naive — squeeze to 4 mm ("grip firmly") | 15.8 N | yes | 2.02 mm | 31.2 mJ |
| Yield-aware — stop at 0.8× yield | 12.0 N | yes | 0.00 mm | 0.0 mJ |
Two constraints face opposite directions. Grip below $W/\mu$ and the object slips; grip above $f_y$ and the material takes a permanent set. The certificate's job is not "grip firmly" — it is to land inside the window between them, and to notice when a heavy enough or fragile enough object closes that window entirely, which is the case no amount of careful gripping can rescue.
Both hold the object; the difference is entirely damage. The naive grip drives the contact to $2.1\times$ the yield depth — the force flows plastically, saturating near $f_y$ — and leaves a $2.0$ mm permanent dent, burning $31$ mJ into irreversible deformation. Gripping hard "to be safe" is exactly backwards for a fragile object: it holds fine and destroys the thing. The yield-aware grip stops below the yield surface and leaves the object pristine. This is the certificate none of the others provide.
3 · Crush versus hold — and the patch that resolves it
Slice 2 capped grip force. But two constraints now pull in opposite directions: holding needs a minimum normal force ($f_n\ge W/\mu$), while not-crushing caps the contact pressure ($f_n/A\le\sigma_y$). For a small contact the floor sits above the ceiling — the grasp cannot be certified at any grip force. The lever is not force but area. Spreading the same hold force over a soft patch drops the pressure below yield, so the certificate's real output is a minimum patch size that grows with how fragile the object is:
| object (yield stress) | min patch radius to hold without crushing |
|---|---|
| ripe berry (20 kPa) | 8.06 mm |
| soft fruit (50 kPa) | 5.10 mm |
| firm produce (150 kPa) | 2.94 mm |
| rigid part (500 kPa) | 1.61 mm |
A near-point contact ($r=0.5$ mm) must impose 4159 kPa just to hold — it crushes everything, exceeding even the rigid part's yield. This is the third role of the one deformation. It was a liability — it stores the release reservoir (Grasp Certificate §6.1, §7); it was an asset — its patch buys wrench capacity against twist (§6.3); and here it is what makes fragile manipulation damage-safe at all. The certificate prices deformation on three ledgers at once, and they trade: a softer, larger contact is safer against crushing and stronger against twist, but stores more energy at a given force. There is no free grip — only a certified balance.
4 · Why the certificate must predict, not react
For a reversible failure you can afford to react — feel the slip, then re-grip. Damage is different: it is irreversible, and that changes what a certificate must be. A controller that reacts to the realized signal can only stop after it detects the plastic signature — which is the damage — so even at zero latency it books the yield step that revealed the problem, and every extra step of reaction latency adds permanent dent.
| controller (grip closing fast toward yield) | permanent dent | plastic work |
|---|---|---|
| Reactive — 0-step latency | 0.005 mm | 0.07 mJ |
| Reactive — 2-step latency | 0.024 mm | 0.36 mJ |
| Reactive — 10-step latency | 0.100 mm | 1.50 mJ |
| Predictive certificate — gate first | 0.000 mm | 0.00 mJ |
The predictive certificate refuses any increment whose model-predicted stress would cross the yield margin, so it halts one step before the first yield and books exactly zero — at any latency. This is the same before-commit gate as the Institute's first certificate — admit the action only if the predicted next state is inside the safe set1 — and irreversibility is what turns it from an efficiency into a necessity. It inherits that arc's requirement too: prediction needs a model (of the yield surface) and an estimate of the contact state, so the no-harm certificate stands on the same reality and observability footing as the rest.
5 · Under perception uncertainty
The slices so far knew the yield surface exactly. A real robot does not — it estimates how fragile the object is and senses the contact force with noise. Take a population whose true yield is $\sim\mathcal N(15,3)$ N and a task that needs $12$ N to hold: a thin margin, and 15.8% of objects are genuinely infeasible — too fragile to hold at that force at all. With perfect perception the certificate refuses exactly those and harms nothing. With noisy perception ($\sigma\!=\!2$ N) the line blurs, so it must grip only when confident by a margin $\kappa\sigma$ — and that margin has a measured price:
| confidence margin $\kappa$ | damaged | held safely | holdable objects wrongly refused |
|---|---|---|---|
| 0 (point estimate) | 4.48% | 75.3% | 8.5% |
| 1 | 1.07% | 59.2% | 24.9% |
| 2 | 0.12% | 37.7% | 46.5% |
| 3 | 0.01% | 18.9% | 65.3% |
There is no free safety. Raising $\kappa$ drives damage toward zero, but it refuses ever more objects it could actually have held — capability bleeds away, and $\kappa$ must be chosen from the damage rate the application can tolerate, exactly as the energy certificate sized its keep-out to the estimator's covariance. And the same hard limit recurs: a symmetric margin covers zero-mean noise, but a systematic bias leaks. An estimator that reads every object as $2$ N tougher than it is holds a damage floor a same-sized margin cannot clear — biased damage at margin $\kappa$ tracks unbiased damage at $\kappa\!-\!1$, so covering it costs a full extra unit of margin you only know to spend if you know the bias. The lesson holds across both certificates: buy down variance with margin, but de-bias, don't pad.
6 · Can the certificate trust the estimate?
Slice 5 sized its margin to a known $\sigma$. But that $\sigma$ comes from a learned model, and the certificate's whole safety rests on one thing: its lower bound $L(x)$ assumes the object is at least as tough as $L$, and grips only when that clears the task force. So the audit is a single number — how often is the bound wrong (true yield below it)? It should be at most $\alpha$. We take a model with a perfect (unbiased) mean but an overconfident uncertainty head — one that reports $0.40\times$ the true noise, the classic failure of learned uncertainty — and check.
| certificate's lower bound | bound wrong (target ≤ 5%) | damage if gripped | grips |
|---|---|---|---|
| point estimate (no uncertainty) | 50.8% | 14.9% | 68.8% |
| Gaussian plug-in $\hat f - 1.645\,\hat\sigma$ | 26.0% FAIL | 7.8% | 52.9% |
| split conformal $\hat f - \hat q\,\hat\sigma$ | 5.0% ok | 2.0% | 27.7% |
The Gaussian plug-in looks principled but trusts the model's own $\hat\sigma$, so it inherits the overconfidence: its bound is wrong 26% of the time — five times the promised rate, and worst exactly where the head is most overconfident (the ripe, high-variance objects). The certificate is running on a false premise a quarter of the time and cannot see it from inside. Split conformal fixes it at the root: it calibrates the multiplier on held-out residuals, keeping the model's $\hat\sigma$ shape but replacing the trusted $1.645$ with $\hat q$ — and $\hat q/1.645 = 2.5$ is precisely the $1/0.40$ the head was missing. The bound is now wrong at most $\alpha$ for any model, however miscalibrated: not a model you hope is honest, but a coverage bound you can audit. Calibration is a certificate requirement, and the operational damage-if-gripped falls in step, $8\%\!\to\!2\%$.
The flip side is stated, not hidden: conformal's guarantee rests on exchangeability. Hand the certificate a batch of objects $2.5$ N frailer than anything it calibrated on and the bound is wrong 46% of the time — coverage gone. So the perception layer owes the certificate two things, not one: a conformal bound and an out-of-distribution detector that forces a refuse (or a re-calibration) when the world moves.
7 · A certificate that detects its own invalidation
Every guarantee in this paper — and every one the Institute has built — rests on an assumption: the material model, the yield estimate, and now conformal's exchangeability. Slice 6 showed the last one breaks under a shift, silently. The property that separates a brittle guarantee from a trustworthy one is not that the assumption is always true, but that the certificate notices when it stops being true. So it watches its own outcomes — was the object actually more fragile than my bound believed? — and runs a betting martingale on that stream. While coverage holds the martingale drifts nowhere, and Ville's inequality caps its false alarms at the level we choose; the moment realized miscoverage climbs, the capital compounds and trips, and the certificate refuses until it is recalibrated.
| a shift makes the bound wrong 30% (was 5%) | detects it? | post-shift damage (of 2000) |
|---|---|---|
| static conformal — calibrated then blind | never | 601 |
| self-monitoring conformal | 100% of runs | 33 (−95%) |
It cannot be instant, and that is stated rather than hidden: detecting a shift requires observing that outcomes have turned bad, so a bounded burst of damage in the detection delay (here a median of 107 objects) is unavoidable — reported, not hidden. But that converts unbounded harm into a small, quantified one, while false alarms on a world that has not shifted stay under the 1% we set (measured 0.7%). This is the shape a deployed certificate must have: not a proof issued once and trusted forever, but a live guarantee that audits itself and stands down when its own premises fail.
8 · And it repairs itself
Detecting a broken guarantee is not enough — a certificate that only refuses is safe but sterile: slice 7's certificate survives the shifted world by doing nothing in it (its bound stays wrong ~19% of the time; it just stops acting on it). Deployment demands more — keep the guarantee and keep working. So the certificate recalibrates on a sliding window of its own recent outcomes: it recomputes the conformal quantile from the last $W$ objects' scores, so as the world turns frailer the window fills with the new reality, the bound drops to match, and coverage returns to target. Under a persistent shift (objects $1$ N frailer), in steady state:
| after the shift settles | bound wrong (target 5%) | throughput | damage |
|---|---|---|---|
| static conformal — blind | 19.2% | 28.5% | 1.93% |
| refuse-only (§7) — safe but sterile | 19.2% (unfixed) | 0.0% | 0.00% |
| adaptive — self-repairing | 4.8% | 9.3% | 0.24% |
The adaptive certificate is the only one that both restores coverage (4.8% vs the 5% target) and keeps gripping. The static one is blind and keeps damaging; the refuse-only one is safe but does nothing. The price is stated, not hidden: throughput is lower than before — partly because the world is genuinely frailer (fewer objects are safely holdable), partly because it grips more cautiously to buy back coverage; it needs a stream of outcome feedback; and during the recalibration window there is a real coverage excursion (11% here) — you cannot repair a break you have not yet felt. This is the mature shape of a certificate: not issued once and trusted forever, but continuously re-earned against the world it meets. Paired with §7's alarm, the deployment rule is simple — adapt when you can, refuse when you cannot.
References & lineage
- Charlot Lab, One Energy, Both Roles — the before-commit control-barrier gate this reuses (admit an action only if the predicted next state is inside the safe set), and the no-harm-to-others (human keep-out) certificate this is a peer to.
- Charlot Lab, The Grasp Certificate — the force-space certificate whose deformation (the contact patch) plays its third role here; §6–7 are the energy reservoir and viscoelastic credit referenced throughout.
- Elastic-plastic return mapping (radial return, isotropic hardening) — the standard computational-plasticity kernel used for the yield barrier and the predictive gate. Companion: the Agency Ladder and the J/VT scoreboard.
- V. Vovk, A. Gammerman & G. Shafer, Algorithmic Learning in a Random World (2005); split-conformal regression (Papadopoulos et al. 2002; Lei et al. 2018) — the distribution-free coverage guarantee slice 6 uses to make the fragility bound auditable.
- Test martingales and Ville's inequality for testing exchangeability (Vovk et al.); betting / e-value sequential tests (Shafer 2021; Ramdas et al.) — the self-monitoring detector of slice 7 and its bounded false-alarm guarantee.
- I. Gibbs & E. Candès, Adaptive Conformal Inference Under Distribution Shift (NeurIPS 2021), and sliding-window / online conformal — the self-repairing recalibration of slice 8 that restores coverage without a distributional assumption.
- The reproducible probe scripts (the yield barrier, the crush-vs-hold feasibility map, the predictive-vs-reactive damage sweep, the perception-uncertainty margin-vs-bias Monte Carlo, and the conformal-calibration coverage test) are the Institute's on-device research record. The uncertainty and calibration slices reuse the reality/observability method of One Energy, Both Roles — margin sized to the estimator's covariance; systematic bias leaks; a guarantee is only as honest as it is calibrated.