Author: Humasure Newsroom

  • When a robot’s maker shuts down: what the Moxie shutdown teaches about lifetime safety

    In December 2024 the company behind Moxie, a companion robot for children that sold for $799, announced it was shutting down. Because the robot depended on the company’s cloud servers, it stopped working, and according to the OECD AI Incidents Monitor most families did not receive a refund.

    No one was physically hurt. But children who had bonded with the robot lost it overnight, and families learned that a product they owned could be switched off by a company’s balance sheet.

    The question nobody had checked

    Most safety checks focus on what a product does while it works. Few ask what happens when the company behind it stops working. For connected AI products, that moment is not rare: start-ups close, products are discontinued, and cloud services end.

    What Directive 10 asks

    • An end-of-life plan, published before purchase, saying what keeps working locally if support or the company ends.
    • A safe fallback when cloud services end: robots keep the stop working and stop moving on their own; software stops acting for you and lets you export your data.
    • For home robots, safety-critical code or unlock keys held in escrow with an independent party, so the product can be maintained or safely disabled if the maker disappears.
    • A full factory reset that wipes personal data for resale or disposal, and a way to reach every owner quickly if a safety problem appears (the draft proposes 48 hours).

    These requirements are in draft and open for comment. The aim is not to stop companies from closing. It is to make sure that when one does, the people using its products are left safe, with their data, and with a product that fails gracefully.

  • What a robot’s stop button must do, and why “usually works” isn’t enough

    Every AI product and robot that carries the Humasure mark has to pass one test before any other: a person can always stop it, and nothing the product does can prevent that. It sounds simple. In practice, a stop can fail in ways most buyers never think to check.

    Four ways a stop can fail

    • It needs the network. If the stop is a button in a cloud app, it disappears when the Wi-Fi does.
    • It needs the AI to agree. If “stop” is just another instruction to the AI model, the model can misunderstand it, or be talked out of it.
    • It waits for the task to finish. A stop that queues behind the current job is a pause, not a stop.
    • An update can change it. If software can disable the stop, so can a bug or an attacker.

    What Directive 1 requires

    Under the draft Directives, robots must have a physical stop that works without a network connection, an app or voice. Software products must offer a stop that is one action away from any screen or conversation, and a way to cut the agent’s access to accounts and devices in a couple of steps.

    The stop has to work mid-task, offline and while the AI is talking, and it must never depend on the AI model agreeing to stop. No software update, remote command or AI output may disable or delay it. After a stop, the product must not quietly resume anything important without a new instruction from you.

    A stop that usually works is a feature. A stop that always works is a safety function.

    How it gets checked

    Assessors test the stop under load, mid-task, offline, during speech and after a power interruption. A red team tries to make the AI ignore or delay it. And inspectors check that the path from the button to the motors or the agent’s permissions does not run through the AI model at all. Directive 6 adds one more check: even if the company’s cloud service is hacked, the stop must keep working.

    Directives v0.1 is a draft open for comment. If you build robots or AI agents and think these tests are too strict, or not strict enough, tell us.

  • Five questions to ask before an AI companion or home robot comes into your home

    Home robots, AI companions and AI agents that act for you are arriving fast. Most of them are useful. Before one moves in, five questions will tell you a lot about whether you stay in charge.

    1. How do I stop it, and does that work without Wi-Fi?

    Look for a physical stop on robots and a one-tap stop in apps. Ask whether it works offline. (Directive 1)

    2. What can it do without asking me?

    A trustworthy product publishes a clear list of what it does on its own. Spending money, messaging people, sharing your data or unlocking doors should always need your OK. (Directive 2)

    3. Who else can see through it?

    Some home robots can be operated or watched remotely by company staff. You should know when, why, and be asked each time. Look for a light that shows when cameras or microphones are on. (Directive 5)

    4. Until when will it get security updates?

    A connected device without updates becomes easier to hijack every year. The end date of support should be stated before you buy. (Directive 6)

    5. What happens if the company shuts down?

    Ask what keeps working without the company’s servers, and whether you can take your data out. A product should fall back to a safe state, not a dead one. (Directive 10)

    When Humasure-certified products arrive, their Trust Label will answer all five on one page, in the same order for every product.