Institute for Physical AI @ Bailey Military Institute · Charlot Lab
Living paper · No-harm certificate

The certificate for the object · seven verified slices

The No-Harm Certificate

A grasp can be force-closure-perfect, energy-bounded, and viscoelastically safe — and still crush the thing it holds. This is the certificate for the object: a guarantee that the manipulation does not permanently harm what it touches. It is a peer to the no-harm-to-others certificate — same shape, different protected party.

Charlot Lab, Institute for Physical AI @ BMI

Draft · 2026-07 · companion to The Grasp Certificate and One Energy, Both Roles · every number is a measured elastic-plastic computation

Yield barrier · elastic-plastic return mapping Crush-vs-hold feasibility · the patch resolves it Predictive, not reactive · irreversibility Under perception uncertainty · margin vs bias Calibrated perception · conformal coverage Detects its own invalidation · test martingale Repairs itself · adaptive conformal Lumped elastic-plastic · in simulation
Every certificate the Institute has built protects the body (it won't diverge), the grasp (it won't slip), or the release (it won't eject). None protects the object. Yet for real manipulation — food, tissue, fragile parts — the dominant failure is neither divergence nor slip but damage: the grasp holds perfectly and destroys the thing. Damage is a third fate for the energy a grasp puts in — not stored and recoverable, not dissipated as heat, but irreversible plastic work, spent permanently deforming the object. We build the no-harm certificate in three slices. (1) A yield barrier: a naive grip that squeezes "to feel secure" drives the contact past yield and leaves a 2.0 mm dent (31 mJ of plastic work); a yield-aware grip holds the same object with zero permanent set. (2) Crush versus hold: holding sets a floor on force, not-crushing a ceiling on pressure, and for a small contact the floor is above the ceiling — no grip is safe. The lever that opens the window is contact area: the same soft patch that stored energy and bought wrench capacity now spreads pressure below yield — deformation's third role. (3) Irreversibility: because the first yield is permanent, a controller that reacts to the damage signal is always one step too late (its dent grows with reaction latency), while a predictive certificate that gates on model-predicted stress books exactly zero. For an irreversible constraint, before-commit checking is not an optimization — it is the only thing that works. (4) And under perception uncertainty — the robot only estimates how fragile the object is — the certificate widens its margin to $\kappa\sigma$ and degrades gracefully, driving damage from 4.5% toward zero as $\kappa$ grows, at a measured cost in refused-but-holdable objects. But a symmetric margin covers only zero-mean noise: a systematic bias in the fragility estimate leaks straight through, exactly as it did for the energy certificate's observability. (5) Finally, that estimate comes from a learned model — and the certificate's guarantee is hostage to its honesty: an overconfident model makes the certificate's lower bound wrong 26% of the time while promising 5%, a silent failure it cannot see from inside. Split conformal prediction restores a distribution-free bound wrong at most $\alpha$ for any model — making calibration an auditable certificate requirement, not an ML hope. (6) And because even that bound assumes an unchanging world, the certificate monitors itself: a betting martingale on its own realized errors trips when a distribution shift silently breaks its guarantee, and it refuses until recalibrated — cutting post-shift damage 95% with a bounded false-alarm rate. A certificate that knows when it is no longer valid is the only kind you can deploy into a world that does not hold still. (7) And detecting is not enough — refusing forever is safe but sterile, so the certificate repairs itself: it recalibrates on a sliding window of its own recent outcomes, and after a shift its coverage snaps back to target (4.8% vs 5%) while it keeps working — the only regime that is both safe and useful under a world that keeps moving.

1 · The third fate of energy

Track the energy a grasp pushes into an object and it has three destinations. Some is stored elastically and is recoverable — the reservoir that ejects the object on release, certified in The Grasp Certificate, §6–7. Some is dissipated as heat by viscoelastic damping — which a certificate can even credit, since it shrinks the recoverable reservoir. And some is spent irreversibly, permanently deforming or fracturing the object. That last fate is damage, and no energy or force certificate sees it, because it is not about the body's state or the contact's slip — it is about the object's material integrity. The no-harm certificate is a barrier in a new variable: keep the contact stress under the object's yield surface, with margin, so no energy takes the irreversible path.

2 · The yield barrier

Model the contact as elastic-plastic (a 1-D return mapping with isotropic hardening): below the yield force $f_y$ it is a spring; above it, the material flows and takes a permanent set. A $0.30$ kg object needs only $f_n\ge W/\mu = 3.3$ N of grip to hold by friction — far below a fragile object's yield at $f_y=15$ N. So holding without damage is entirely possible; whether it happens is a choice the certificate makes.

controllerpeak gripheldpermanent dentplastic work (damage)
Naive — squeeze to 4 mm ("grip firmly")15.8 Nyes2.02 mm31.2 mJ
Yield-aware — stop at 0.8× yield12.0 Nyes0.00 mm0.0 mJ
The window you must land in

Two constraints face opposite directions. Grip below $W/\mu$ and the object slips; grip above $f_y$ and the material takes a permanent set. The certificate's job is not "grip firmly" — it is to land inside the window between them, and to notice when a heavy enough or fragile enough object closes that window entirely, which is the case no amount of careful gripping can rescue.

Both hold the object; the difference is entirely damage. The naive grip drives the contact to $2.1\times$ the yield depth — the force flows plastically, saturating near $f_y$ — and leaves a $2.0$ mm permanent dent, burning $31$ mJ into irreversible deformation. Gripping hard "to be safe" is exactly backwards for a fragile object: it holds fine and destroys the thing. The yield-aware grip stops below the yield surface and leaves the object pristine. This is the certificate none of the others provide.

3 · Crush versus hold — and the patch that resolves it

Slice 2 capped grip force. But two constraints now pull in opposite directions: holding needs a minimum normal force ($f_n\ge W/\mu$), while not-crushing caps the contact pressure ($f_n/A\le\sigma_y$). For a small contact the floor sits above the ceiling — the grasp cannot be certified at any grip force. The lever is not force but area. Spreading the same hold force over a soft patch drops the pressure below yield, so the certificate's real output is a minimum patch size that grows with how fragile the object is:

object (yield stress)min patch radius to hold without crushing
ripe berry (20 kPa)8.06 mm
soft fruit (50 kPa)5.10 mm
firm produce (150 kPa)2.94 mm
rigid part (500 kPa)1.61 mm

A near-point contact ($r=0.5$ mm) must impose 4159 kPa just to hold — it crushes everything, exceeding even the rigid part's yield. This is the third role of the one deformation. It was a liability — it stores the release reservoir (Grasp Certificate §6.1, §7); it was an asset — its patch buys wrench capacity against twist (§6.3); and here it is what makes fragile manipulation damage-safe at all. The certificate prices deformation on three ledgers at once, and they trade: a softer, larger contact is safer against crushing and stronger against twist, but stores more energy at a given force. There is no free grip — only a certified balance.

4 · Why the certificate must predict, not react

For a reversible failure you can afford to react — feel the slip, then re-grip. Damage is different: it is irreversible, and that changes what a certificate must be. A controller that reacts to the realized signal can only stop after it detects the plastic signature — which is the damage — so even at zero latency it books the yield step that revealed the problem, and every extra step of reaction latency adds permanent dent.

controller (grip closing fast toward yield)permanent dentplastic work
Reactive — 0-step latency0.005 mm0.07 mJ
Reactive — 2-step latency0.024 mm0.36 mJ
Reactive — 10-step latency0.100 mm1.50 mJ
Predictive certificate — gate first0.000 mm0.00 mJ

The predictive certificate refuses any increment whose model-predicted stress would cross the yield margin, so it halts one step before the first yield and books exactly zero — at any latency. This is the same before-commit gate as the Institute's first certificate — admit the action only if the predicted next state is inside the safe set1 — and irreversibility is what turns it from an efficiency into a necessity. It inherits that arc's requirement too: prediction needs a model (of the yield surface) and an estimate of the contact state, so the no-harm certificate stands on the same reality and observability footing as the rest.

5 · Under perception uncertainty

The slices so far knew the yield surface exactly. A real robot does not — it estimates how fragile the object is and senses the contact force with noise. Take a population whose true yield is $\sim\mathcal N(15,3)$ N and a task that needs $12$ N to hold: a thin margin, and 15.8% of objects are genuinely infeasible — too fragile to hold at that force at all. With perfect perception the certificate refuses exactly those and harms nothing. With noisy perception ($\sigma\!=\!2$ N) the line blurs, so it must grip only when confident by a margin $\kappa\sigma$ — and that margin has a measured price:

confidence margin $\kappa$damagedheld safelyholdable objects wrongly refused
0 (point estimate)4.48%75.3%8.5%
11.07%59.2%24.9%
20.12%37.7%46.5%
30.01%18.9%65.3%

There is no free safety. Raising $\kappa$ drives damage toward zero, but it refuses ever more objects it could actually have held — capability bleeds away, and $\kappa$ must be chosen from the damage rate the application can tolerate, exactly as the energy certificate sized its keep-out to the estimator's covariance. And the same hard limit recurs: a symmetric margin covers zero-mean noise, but a systematic bias leaks. An estimator that reads every object as $2$ N tougher than it is holds a damage floor a same-sized margin cannot clear — biased damage at margin $\kappa$ tracks unbiased damage at $\kappa\!-\!1$, so covering it costs a full extra unit of margin you only know to spend if you know the bias. The lesson holds across both certificates: buy down variance with margin, but de-bias, don't pad.

6 · Can the certificate trust the estimate?

Slice 5 sized its margin to a known $\sigma$. But that $\sigma$ comes from a learned model, and the certificate's whole safety rests on one thing: its lower bound $L(x)$ assumes the object is at least as tough as $L$, and grips only when that clears the task force. So the audit is a single number — how often is the bound wrong (true yield below it)? It should be at most $\alpha$. We take a model with a perfect (unbiased) mean but an overconfident uncertainty head — one that reports $0.40\times$ the true noise, the classic failure of learned uncertainty — and check.

certificate's lower boundbound wrong (target ≤ 5%)damage if grippedgrips
point estimate (no uncertainty)50.8%14.9%68.8%
Gaussian plug-in $\hat f - 1.645\,\hat\sigma$26.0%  FAIL7.8%52.9%
split conformal $\hat f - \hat q\,\hat\sigma$5.0%  ok2.0%27.7%

The Gaussian plug-in looks principled but trusts the model's own $\hat\sigma$, so it inherits the overconfidence: its bound is wrong 26% of the time — five times the promised rate, and worst exactly where the head is most overconfident (the ripe, high-variance objects). The certificate is running on a false premise a quarter of the time and cannot see it from inside. Split conformal fixes it at the root: it calibrates the multiplier on held-out residuals, keeping the model's $\hat\sigma$ shape but replacing the trusted $1.645$ with $\hat q$ — and $\hat q/1.645 = 2.5$ is precisely the $1/0.40$ the head was missing. The bound is now wrong at most $\alpha$ for any model, however miscalibrated: not a model you hope is honest, but a coverage bound you can audit. Calibration is a certificate requirement, and the operational damage-if-gripped falls in step, $8\%\!\to\!2\%$.

The flip side is stated, not hidden: conformal's guarantee rests on exchangeability. Hand the certificate a batch of objects $2.5$ N frailer than anything it calibrated on and the bound is wrong 46% of the time — coverage gone. So the perception layer owes the certificate two things, not one: a conformal bound and an out-of-distribution detector that forces a refuse (or a re-calibration) when the world moves.

7 · A certificate that detects its own invalidation

Every guarantee in this paper — and every one the Institute has built — rests on an assumption: the material model, the yield estimate, and now conformal's exchangeability. Slice 6 showed the last one breaks under a shift, silently. The property that separates a brittle guarantee from a trustworthy one is not that the assumption is always true, but that the certificate notices when it stops being true. So it watches its own outcomes — was the object actually more fragile than my bound believed? — and runs a betting martingale on that stream. While coverage holds the martingale drifts nowhere, and Ville's inequality caps its false alarms at the level we choose; the moment realized miscoverage climbs, the capital compounds and trips, and the certificate refuses until it is recalibrated.

a shift makes the bound wrong 30% (was 5%)detects it?post-shift damage (of 2000)
static conformal — calibrated then blindnever601
self-monitoring conformal100% of runs33  (−95%)

It cannot be instant, and that is stated rather than hidden: detecting a shift requires observing that outcomes have turned bad, so a bounded burst of damage in the detection delay (here a median of 107 objects) is unavoidable — reported, not hidden. But that converts unbounded harm into a small, quantified one, while false alarms on a world that has not shifted stay under the 1% we set (measured 0.7%). This is the shape a deployed certificate must have: not a proof issued once and trusted forever, but a live guarantee that audits itself and stands down when its own premises fail.

8 · And it repairs itself

Detecting a broken guarantee is not enough — a certificate that only refuses is safe but sterile: slice 7's certificate survives the shifted world by doing nothing in it (its bound stays wrong ~19% of the time; it just stops acting on it). Deployment demands more — keep the guarantee and keep working. So the certificate recalibrates on a sliding window of its own recent outcomes: it recomputes the conformal quantile from the last $W$ objects' scores, so as the world turns frailer the window fills with the new reality, the bound drops to match, and coverage returns to target. Under a persistent shift (objects $1$ N frailer), in steady state:

after the shift settlesbound wrong (target 5%)throughputdamage
static conformal — blind19.2%28.5%1.93%
refuse-only (§7) — safe but sterile19.2% (unfixed)0.0%0.00%
adaptive — self-repairing4.8%9.3%0.24%

The adaptive certificate is the only one that both restores coverage (4.8% vs the 5% target) and keeps gripping. The static one is blind and keeps damaging; the refuse-only one is safe but does nothing. The price is stated, not hidden: throughput is lower than before — partly because the world is genuinely frailer (fewer objects are safely holdable), partly because it grips more cautiously to buy back coverage; it needs a stream of outcome feedback; and during the recalibration window there is a real coverage excursion (11% here) — you cannot repair a break you have not yet felt. This is the mature shape of a certificate: not issued once and trusted forever, but continuously re-earned against the world it meets. Paired with §7's alarm, the deployment rule is simple — adapt when you can, refuse when you cannot.

Scope. All seven slices are in simulation: slices 2–4 on a lumped 1-D elastic-plastic contact (return mapping, isotropic hardening) with a static yield stress; slice 5 a population Monte Carlo with Gaussian perception error; slice 6 synthetic feature→yield data with a deliberately overconfident model; slices 7–8 a synthetic outcome stream with a shift and immediate feedback. Those are the right settings for the questions asked — did it yield, is there any grip that both holds and spares it, can a reactive loop ever be enough, what does uncertainty cost, can the certificate trust a learned estimate, can it tell when that trust has expired, and can it repair itself — but not a resolved constitutive law or a real perception system. The genuinely open work: a spatially-resolved damage field, true fracture (energy leaving as new surface, not bulk flow), rate- and temperature-dependent yield, adhesion, and — the handoff these slices make explicit — a learned, object-conditioned fragility estimator on real sensed objects, under delayed and partial feedback, with the online-level (Gibbs–Candès) conformal variant for shifts beyond a window's support. This paper certifies the lumped case exactly and names the material and perception frontiers as the edge; it never claims a grasp is "safe for any object."

References & lineage

  1. Charlot Lab, One Energy, Both Roles — the before-commit control-barrier gate this reuses (admit an action only if the predicted next state is inside the safe set), and the no-harm-to-others (human keep-out) certificate this is a peer to.
  2. Charlot Lab, The Grasp Certificate — the force-space certificate whose deformation (the contact patch) plays its third role here; §6–7 are the energy reservoir and viscoelastic credit referenced throughout.
  3. Elastic-plastic return mapping (radial return, isotropic hardening) — the standard computational-plasticity kernel used for the yield barrier and the predictive gate. Companion: the Agency Ladder and the J/VT scoreboard.
  4. V. Vovk, A. Gammerman & G. Shafer, Algorithmic Learning in a Random World (2005); split-conformal regression (Papadopoulos et al. 2002; Lei et al. 2018) — the distribution-free coverage guarantee slice 6 uses to make the fragility bound auditable.
  5. Test martingales and Ville's inequality for testing exchangeability (Vovk et al.); betting / e-value sequential tests (Shafer 2021; Ramdas et al.) — the self-monitoring detector of slice 7 and its bounded false-alarm guarantee.
  6. I. Gibbs & E. Candès, Adaptive Conformal Inference Under Distribution Shift (NeurIPS 2021), and sliding-window / online conformal — the self-repairing recalibration of slice 8 that restores coverage without a distributional assumption.
  7. The reproducible probe scripts (the yield barrier, the crush-vs-hold feasibility map, the predictive-vs-reactive damage sweep, the perception-uncertainty margin-vs-bias Monte Carlo, and the conformal-calibration coverage test) are the Institute's on-device research record. The uncertainty and calibration slices reuse the reality/observability method of One Energy, Both Roles — margin sized to the estimator's covariance; systematic bias leaks; a guarantee is only as honest as it is calibrated.