Energy First Architecture
The physics-first thesis, built in the browser: one scalar energy a body descends to act, and the same energy is the proof it will not diverge. Descend it to control, read its decrease as the certificate, get that certificate for free by structuring the energy as a port-Hamiltonian (at any number of joints, where a box proof cannot), and gate a task policy so it verifies before it commits. No bolted-on verifier; one energy, and the proof is the objective. This is an active research line, not ours alone (co-learned port-Hamiltonian models with passivity-based safety certificates, arXiv 2604.26172 and 2512.24493, and physics-driven world models like PH-Dreamer); what you build here is the open, on-device, readable version of it.
▶ Start the course ← All coursesWhere this sits, and what moves it.
Binding constraint · Dimension. A certificate you obtain by checking boxes costs exponentially in the number of joints; a certificate you obtain from structure costs nothing extra.
Guaranteeing a controller would not diverge meant a proof per system, redone whenever anything changed. For a robot with many joints, box-refinement walls out -- not slowly, but astronomically.
A port-Hamiltonian structure gives the certificate by construction at any joint count, and this course earns it in the browser. What it does not give you is a free lunch: expressing a task in that structure is a modelling skill, and a policy that will not fit the structure is not certified by wishing.
The consequential step is gating a learned policy on the certificate -- a guarantee that arrives before the action commits, not after the incident. That is the seam where a language model's fluent prior meets a physical bound, and it is the most direct answer this Institute has to whether learned control can be trusted with a body.
Every hard thing was impossible until the constraint that made it impossible was named. How we read a frontier →
One energy, both roles
Act by descending an energy, and see that the same energy is the stability certificate.
- L3To act is to descend an energyYou want a pendulum to stand upright. You shape an energy function whose minimum is the upright state and let the system descend it. What is the controller?Control a pendulum by descending a shaped energy, the energy IS the controller, not a policy bolted to one.→
- L3The same energy is the proofYou have a controller that descends a shaped energy. Now you want a proof the pole cannot diverge. What do you have to build?See that the energy you descended is, unchanged, a Lyapunov certificate: it provably decreases along the closed loop.→
Structure, not proof
Earn the certificate by construction, at any number of joints, where proving it walls out.
Verify before you commit
Gate a real task policy with the energy certificate: a guarantee before the action commits.