NVIDIA Halos: Full-Stack Safety for Physical AI

Published · AI Daily — AI-assisted deep research, methodology & disclosure

NVIDIA has unveiled Halos, a five-layer safety architecture spanning hardware, software, AI behavior assurance, validation, and operational monitoring for autonomous vehicles and industrial robots, aimed at the scale ABI Research projects for 2035.

NVIDIA has detailed Halos, a full-stack safety architecture built for physical AI systems, autonomous vehicles and industrial robots, that are meant to operate at scale in the real world. The timing reflects a scale problem as much as a safety one: ABI Research projects an installed base of 49 million autonomous vehicles and 60 million industrial robots by 2035.

At that scale, a single safety checkpoint late in development is not enough. Physical AI systems operate in dynamic, uncontrolled environments where machines share space with people, so NVIDIA's argument is that safety has to be engineered into every layer of the stack, not bolted on at the end.

Five Layers, One Architecture

Halos is organized around five layers that NVIDIA presents as working together rather than as independent modules. At the design and hardware level, DRIVE AGX Thor for vehicles and IGX Thor for robotics provide safety-engineered compute built around dedicated "Functional Safety Islands." Above that sits a software foundation: Halos OS, which builds on the ASIL-D certified DriveOS, paired with Halos Core and a middleware layer that handle system isolation and deterministic communication between components.

The third layer, AI Behavior Assurance, is where NVIDIA Alpamayo comes in, bringing explainability to edge cases and addressing risks that are specific to AI decision-making rather than covered by traditional functional-safety engineering. A fourth layer handles validation, combining simulation in Isaac Lab and Omniverse with real-world testing under what NVIDIA calls the Halos Safety Evaluation Framework. The fifth layer, operational monitoring, uses the Halos Sensor Bridge together with an "Outside-In Safety Blueprint" to keep validating sensors continuously and to give facility operators oversight once a system is deployed.

The Real Problem: Proving It End to End

The core claim underlying Halos is less about any single layer and more about the burden of proof developers now face: they must demonstrate that hardware, software, AI behavior, and the operating environment can work together safely without human intervention, across the full lifecycle of a vehicle or robot, not only at the moment of deployment.

That framing matters because it is a much harder bar than certifying a chip or a sensor in isolation. Traditional functional safety standards were built for systems with predictable failure modes; physical AI adds a layer where the software's own decisions, not just component failures, are part of what has to be validated and monitored on an ongoing basis.

An Ecosystem Bet

NVIDIA is not deploying Halos alone. On the vehicle side, Geely, Nissan (working with Wayve), Isuzu, and Einride are named as manufacturers, alongside mobility providers Uber, Grab, and Lyft.

In robotics, Agility Robotics, KION Group, and NexCOBOT are integrating IGX Thor. A wider support ecosystem, spanning sensors, silicon, and validation, includes Bosch, Hesai, Sony, Valeo, QNX, Infineon, and NXP. That breadth suggests NVIDIA is positioning Halos less as a single product and more as a shared safety substrate that partners across the physical AI supply chain can build on, which is itself a bet that a common architecture reduces certification cost for everyone involved rather than forcing each partner to build a bespoke safety case.

Certification and What to Watch

NVIDIA points to third-party validation already underway: TÜV SÜD has certified DriveOS to ISO 26262 ASIL D, TÜV Rheinland is inspecting IGX Thor and Holoscan for functional-safety readiness, and ANAB has accredited the Halos AI Systems Inspection Lab as an ISO/IEC 17020 body. For regulators and insurers, a layered, end-to-end architecture like this could eventually offer a more legible way to underwrite risk than assessing autonomous systems purely on outcome statistics, since each layer carries its own auditable certification trail.

That said, physical AI safety differs from safety in purely digital AI: a software agent that errs can be rolled back, but a vehicle or robot operating among people cannot simply undo a physical action, which is why NVIDIA's framing leans so heavily on continuous monitoring rather than pre-deployment testing alone. What to watch next is whether Halos becomes a de facto standard that other physical AI stacks are measured against, how fast the named manufacturers and robotics integrators actually ship products certified under it, and whether the certification bodies named here extend their scope as the 2035 installed-base numbers get closer to being tested against reality.

Sources

FAQ

What is NVIDIA Halos?

Halos is NVIDIA's full-stack safety architecture for physical AI, covering hardware, software, AI behavior assurance, validation, and operational monitoring.

Why does Halos treat safety as layered rather than a single checkpoint?

Physical AI operates in dynamic, uncontrolled environments alongside humans, so safety must be built into every layer, not tested once before deployment.

What certifications has Halos received so far?

TÜV SÜD certified DriveOS to ISO 26262 ASIL D, TÜV Rheinland is inspecting IGX Thor and Holoscan, and ANAB accredited the Halos AI Systems Inspection Lab as an ISO/IEC 17020 body.