A full-stack functional-safety architecture for physical AI — and the hardware expression of a principle Enkidu already builds by: models propose; deterministic code or humans commit.
NVIDIA Halos is a full-stack safety system for physical AI — machines that sense, decide, and act in the real world. Introduced for autonomous vehicles in 2025 and extended to robotics in June 2026, it unifies safety across three layers: platform safety in hardware, on NVIDIA IGX Thor and the Holoscan Sensor Bridge; a certified safety software stack, Halos OS; and an ecosystem layer for assurance and third-party certification. It is a system architecture rather than a software package, and its relationship to NVIDIA’s sensor-processing platform is one sentence long: Holoscan makes the sensor and AI pipeline fast; Halos makes the overall system trustworthy.
Source: NVIDIA Halos for Robotics — AI Trust Center · NVIDIA Technical Blog, June 2026.
AI perception runs on the main compute domain of NVIDIA IGX Thor. A physically isolated Functional Safety Island — its own processors, memory, clocks, and power — runs a deterministic decision maker that alone releases consequential action. Recovery from a safe state is not automatic: it requires an explicit, authorised release.
Halos does not take a model’s confidence score at its word. One monitor independently examines the sensor input for occlusion, degradation, and out-of-distribution conditions; another checks the health and output validity of the perception pipeline itself. Only when both hold is the AI’s evidence used.
The Holoscan Sensor Bridge attaches guarantees to sensor data at the point of capture: link authentication and encryption, integrity watermarking, health diagnostics, and precision time synchronisation — so downstream fusion works from data with provenance, integrity, and a shared clock.
The AI identifies the situation. The AI does not hold final authority.
Baru, the trusted intelligence-fusion platform, fuses every source into one trusted picture and leaves the decision to a human. Two lines govern every Enkidu design: “Fuse intelligence. Never authorise combat.” and “Models propose; deterministic code or humans commit.” Halos is that second sentence implemented in silicon — which is why Enkidu is evaluating it not as a bolt-on safety product, but as a platform whose trust architecture already matches the one Ekur commits to.
Enkidu is currently experimenting with this technology in three areas within Enlil — the Defence implementation of Baru.
Enkidu is evaluating the Holoscan Sensor Bridge as the sensor ingestion path for Enlil’s edge units — extending verifiable provenance to the point of capture.
Enkidu is evaluating NVIDIA IGX Thor at the Enlil hub tier — a deterministic authority layer between AI-derived conclusions and consequential action.
Enkidu is prototyping the Halos Safety Core pattern as a Kittu runtime pattern in software-in-the-loop simulation.
Evaluation and prototyping activity — no availability, customer, or performance claims.
Halos for Robotics was announced in June 2026, and its core software is early access. Adopting it does not certify a finished system: NVIDIA’s ANAB-accredited inspection assesses the integration of preassessed platform elements, and the final safety case remains the builder’s own. Enkidu treats Halos as a pre-engineered safety foundation, not a certificate — and evaluates it the way the fabric requires: evidence before confidence.
NVIDIA Halos for Robotics (AI Trust Center)
Inside NVIDIA Halos for Robotics (NVIDIA Technical Blog, 22 June 2026)
NVIDIA, NVIDIA Halos, Holoscan, IGX, and Jetson are trademarks of NVIDIA Corporation. Referenced for identification; no endorsement implied.