How SIGMA handles DEGRADED and CRITICAL runtime regimes

From intelligent orchestration to controlled survival
An AI system is not safe merely because its initial plan was valid. Networks time out. Sensors drift. APIs return partial success. Hardware degrades. External systems change between authorization and execution.
SIGMA addresses this problem through three operational regimes:
- NOMINAL — normal conditions remain inside the authorized corridor;
- DEGRADED — assumptions have weakened, but a bounded safe mode remains available;
- CRITICAL — the safe operating corridor can no longer be established and execution must fail closed.
These regimes turn failure handling from improvised model behavior into governed state management.
1. Detecting divergence from the approved action
During execution, SIGMA compares live telemetry with the preconditions and expected effects recorded in the Governed Action Envelope.
A divergence can include:
- an API timeout or contradictory response;
- a partial write or incomplete transaction;
- a sensor-quality drop;
- a resource or latency threshold violation;
- a security-control failure;
- an unexpected external state transition;
- evidence that the authorized assumptions are no longer true.
SIGMA records the delta between expected and observed state, classifies its severity, and determines whether execution remains inside a pre-authorized recovery corridor.
2. DEGRADED: preserve safety while reducing capability
DEGRADED mode is not “continue and hope.” It is a deliberately narrower operating profile.
Depending on the deployment, SIGMA can:
- reduce autonomy depth or multi-step lookahead;
- lower throughput and resource limits;
- switch selected operations to read-only;
- require additional human checkpoints;
- disable optional tools or network paths;
- retry only idempotent operations under bounded policies;
- invoke pre-authorized compensation when the external system supports it.
The last condition is essential. Not every action is reversible. A compensating transaction is not the same thing as erasing history, and SIGMA must never assume that a generic rollback can undo an external consequence.
If the environment stabilizes and the original preconditions can be re-established, a governed transition back to NOMINAL may be permitted. Otherwise, the system escalates.
3. CRITICAL: fail closed before uncertainty becomes authority
SIGMA enters CRITICAL mode when a constitutional constraint is violated, a security prerequisite fails, a DEGRADED corridor cannot be stabilized, or the system can no longer prove that continued execution remains bounded.
A conforming deployment can respond by:
· revoking or expiring outstanding execution envelopes;
· stopping new external writes;
· isolating affected tools, endpoints, or actuators;
· preserving evidence and volatile telemetry;
· transitioning to a deployment-specific minimal-risk state;
· requiring explicit human or multi-party re-authorization.
Whether isolation is implemented in software, hardware, network controls, or an external safety controller is deployment-specific. The architectural requirement is invariant: uncertainty must not silently inherit execution authority.
4. Regime-transition logic
5. Forensic anchoring
Every regime shift should create a structured incident record containing the last verified state, the triggering telemetry, the active policy and software identities, the envelope being executed, the containment action, and the human response.
AEGIS can attest the record, NPoI can evaluate the applicable governance evidence, and NV-CHAIN can anchor the provenance needed for later reconstruction.
This is the strategic value of SIGMA: it does not ask a generative model to improvise safety during a crisis. It turns runtime uncertainty into an explicit, governed state transition—with less authority at every step, never more.
Learn more: neurovatic.ai/sigma
-----
This post, including all associated text and visuals, has been generated and assisted by artificial intelligence under the regulatory requirements of the EU AI Act. Powered by NEUROVATIC AI systems.
