Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › L1 · Control Plane
L1 · Control Plane

Fail-Safe vs Fail-Operational

Some L1 functions must fail into a safe state; others must keep operating through a fault. Kronos chooses per function based on which failure is worse.

THE STACK · click to jumpL7Ecosystem & StrategyL6Experience & VisualizationL5Applications & CopilotsL4OrchestrationL3Twin Modeling & AIL2Data FabricL1Control PlaneL0Foundation▲tlmctl▼L1 · CONTROL PLANEHard real-time actuation and the autonomous failsafe.1Edge FPGAµs-determinism2Real-Time Actuationcoils · heating · fuel3Hardware Failsafeautonomous trip4Sync Gatephase-locked timing5Signal I/OADC / DAC6Watchdogliveness & interlocksMACHINE TIEDrives magnets, ice-piston, and gas puff on the sub-10 µs loop.KRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORCONTROL PLANESHEET 03REV. 2026-08L1 · AI-NATIVE STACK
L1 · Control Plane — its place in the stack (left, click any layer) and its internal components (right). Telemetry rises; control descends.

Two failure philosophies

When a component fails, a system can be designed to fail-safe (go to a defined safe state) or fail-operational (keep working despite the fault). Neither is universally right. Kronos assigns each L1 function the philosophy whose failure mode is less harmful, given what the function protects and what a safe state costs.

Fail-safe functions

For these, the safe state is well-defined and reaching it is protective, so failure should drive toward it. The hardware failsafe is the archetype: it is biased so that any failure of its own path still results in protection, not exposure.

Fail-operational functions

Here an abrupt safe-state jump would itself cause the harm — dropping vertical control ends in a disruption. So these functions carry redundancy and graceful degradation to keep operating through faults, escalating to a controlled safe shutdown only if degradation runs out. This is why vertical control is redundant and DEC ride-through exists.

Choosing correctly

The choice follows the safety-integrity analysis: if the safe state is quickly reachable and protective, fail-safe; if reaching it abruptly is itself dangerous, fail-operational with a controlled path to safety. Most machines mix both, and the boundaries between them are exactly where careful design pays off.

Content reviewed August 2026 · design-and-simulation stage