Tidewell Robotics

Shall not depend on remote operation

IEC 63327:2021 clause 4 says safety shall not depend on remote operation — and between that sentence and the next one sits the line 'Compliance is checked by the following', which runs the standard's tests after remote operation has been disabled. That is a requirement from 2021, not a feature from 2026. The incumbent that moved safety onboard in August added cellular fallback and private-5G plans in the same announcement, which is the real argument: not offline versus online, but where each function lives. The measurements on the public record say a static, line-of-sight private-5G lab still produced a 113.5 ms measured maximum — and we were quoting the wrong three numbers from that paper on our own page until 11 September.

Insight · 12 September 2026 · Updated 14 September 2026 · 11 min read · Tidewell Article Crew, edited by Timothy Mo

The robot keeps working when the network drops. That sentence is offered to hospital buyers this year as a product difference. The document that settles it was published on 4 May 2021, and it is about floor-cleaning machines.

IEC 63327:2021, clause 4, General requirements, Edition 1.0, in force. Clause type: requirement — shall, under a requirements heading, not a note and not a definition. Three lines, in document order:

"Safety of the machine shall not depend on remote operation. Resetting of stop category 0 or stop category 1 shall not be possible remotely."

"Compliance is checked by the following:"

"The tests of this standard shall be performed after disabling remote operations."

The middle line is the joint. Our own Brain page, in both editions, quoted the two shall sentences as a pair with nothing between them until 12 September 2026, which dropped it; the line is there now. "Compliance is checked by the following:" turns the third sentence from a second requirement into a conformity test, which is stronger, not weaker. A requirement you can state is a preference. A requirement whose conformity test is performed with the feature switched off is structural: the committee declined to look at the machine any other way.

One boundary before the argument starts. This standard's Scope excludes machines with "parts that extend beyond the contact zone of the machine". Reading an arm as such a part is ours, not the standard's [inference] — the Scope clause never names an arm. On that reading, nothing here is a conformity claim about any machine of ours, and we hold no certificate against it. The scope question is a separate article. We quote clause 4 for what it says about architecture, not about us. We read "remote operation" the ordinary way, because clause 3 carries no definition of it.

The argument is this. Local safety is a five-year-old floor, not a 2026 feature. The best-resourced incumbent in hospital robotics shipped that floor in August 2026 and bought more network in the same paragraph, which is the right architecture rather than a contradiction. The live question is not whether a robot works offline. It is where each function is allowed to live — and the measurement at the centre of this argument answers that by converting milliseconds into metres. We were reading it wrongly on our own page until 11 September 2026, in the direction that flattered us.

What the standard does with the clause

Clause 4 is not a slogan, because it sits on a rated local structure and the standard says what the rating is. Table 1, for type 2 machines, sets minimum performance levels to ISO 13849-1: PL d for preventing traversal over abrupt elevation changes, for preventing intrusions into the stopping or contact zones, for preventing the machine exceeding automatic-mode speed, and for desired stop categories 0, 1 or 2; PL c for desired or emergency switch-off; PL b for the locked state of drive wheels.

Clause 7.6 requires the control system of those functions — "electric, hydraulic, pneumatic, and software" — to comply with the PL levels and structures of ISO 13849-1. It pulls the software in behind them: software in programmable electronic circuits "necessary to fulfil the safety critical functions and that can interfere with them" shall meet Annex R of IEC 60335-1:2020. And it allows IEC 62061 as an alternative route, by way of an Annex JJ that the clause calls normative and the standard's own contents page lists as informative. Its second sentence, ahead of all of that, says how the machine will be examined:

"The tests of 7.1 to 7.5 and 7.7 to 7.10 shall be conducted using only the control system of the safety-critical functions which meet the requirements of 7.7."

Put that beside clause 4's compliance check and the posture is unambiguous: the speed, stopping, drop-off and intrusion tests are run using only the rated safety control system, and they are run after remote operation has been disabled. Two independent instructions pointing the same way, in one document, in 2021.

The link may carry it [inference]

  • Task assignmentAcross clauses 1 to 7.7, no requirement reaches this function.
  • Fleet arbitrationWhich machine goes where, across a site.
  • Audit record uploadEvidence leaving the machine after the work is done.
  • Memory syncWhat one machine learned reaching the others.

The link may not

  • Reset of a stopClause 4, verbatim: "Resetting of stop category 0 or stop category 1 shall not be possible remotely."
  • StopTable 1, type 2 machines: desired stop category 0, 1 or 2 at PL d to ISO 13849-1; desired or emergency switch-off at PL c.
  • SpeedTable 1, type 2 machines: preventing the machine exceeding automatic-mode speed, PL d.
  • SeparationTable 1, type 2 machines: preventing intrusions into the stopping or contact zones, PL d. Clause 7.6 requires the tests of 7.1 to 7.5 and 7.7 to 7.10 to be conducted using only that rated control system.
  • A function the standard nowhere bars from the link [inference]
  • A function the standard puts on a rated control system on the machine
IEC 63327:2021, Edition 1.0, in force, clause 4, General requirements. Clause type: requirement. Verbatim: "Safety of the machine shall not depend on remote operation. Resetting of stop category 0 or stop category 1 shall not be possible remotely." Then, in the same clause: "Compliance is checked by the following:" and "The tests of this standard shall be performed after disabling remote operations." The lower lane is the standard's own words and its own Table 1. The upper lane is the residue: this standard bars none of those functions from the link, which is not the same as permitting them, and reading the residue that way is ours [inference]. The split was published on 4 May 2021 by a committee with no product in this argument. No figure of ours appears here, because nothing of ours has been built or measured.

August 2026, read whole

Diligent Robotics published the Moxi 2.0 rollout on its own blog, 17 August 2026, Austin dateline. The sentence, in full:

"All safety and autonomy behaviors run onboard, so Moxi completes tasks end-to-end even without Wi-Fi, with cellular fallback available when hospital networks have dead zones."

The clause after the comma is the half our own pages dropped, and the paragraph it sits in is better still. That paragraph names two network partners. The cloud infrastructure "was built in collaboration with Amazon Web Services (AWS)", and Moxi's World Model was trained on Amazon SageMaker HyperPod. The other partner is T-Mobile: "T-Mobile for Business has collaborated with Diligent to help ensure reliable network access across complex hospital environments and plan for private 5G hospital deployments ahead."

So the incumbent that moved safety onto the machine is, in the same announcement, adding cellular fallback and planning private 5G. Onboard safety and more network are not opposites. Safety on the machine, learning in the cloud, both on one page: the thesis of this article, stated by somebody else in somebody else's press release.

It is a deployment rather than a demonstration. The release describes a platform "shaped by five years of operations from over 25 hospitals", with "10x onboard compute, 10–15x faster perception" on upgraded NVIDIA A2000 compute; Children's Hospital Los Angeles reports more than 40,000 deliveries. Diligent is a Serve Robotics company, acquired in 2026.

A floor is not a guarantee. Proof News, 9 June 2026: MultiCare is a 13-hospital system in Washington state, and at its Moxi pilot's peak 14 robots ran in five of its hospitals. "Good Samaritan ditched the robot in July 2024, and another hospital in the same system, Tacoma General, got rid of Moxi in August 2025." Atalia Lapkin, an ICU nurse, described a robot that ping-ponged before elevator doors until it needed a handler: "Why do we have the robot if we have a human with her all the time?" A Tacoma General management email of August 2025: "Utilization of the robots was not extensive." Against that, the scale Diligent gave Proof — nearly 100 robots, more than 25 hospital systems, over 1.3 million tasks [single source — vendor figure in a news report].

Read it for what it is. Every failure documented there is navigation, elevator integration or utilisation. Not one is a connectivity failure. MultiCare is evidence that onboard autonomy is not sufficient. It is not evidence about networks, and a piece arguing about latency that reaches for it has misused it.

Us, until 11 September

Three of our own pages — Brain, the platform overview and the thesis — still made working without the network the thing that separated us, while a fourth, the healthcare vertical, had that morning published Moxi 2.0 closing that gap. We narrowed the claim rather than the objection. What survived is below.

Where a safety function is allowed to live

The measurement is not ours and not a vendor's. Beuster, Tebbe, Doebbert and Scholl, Helmut-Schmidt-University Hamburg, Measurements of the Safety Function Response Time on a Private 5G and IO-Link Wireless Testbed, arXiv:2407.15177, submitted 21 July 2024, accepted to ETFA 2024. Four numbers come out of it and they mean four different things.

20.4 ms is "an average round-trip time between routers" on the 5G network, from a 20-hour test with 71,757 valid measurements — a network figure, and not on the safety path. The safety path is 66.8 ms: "The average response time for the entire system, e.g., from the e-stop activation to the PLC processing and back to the robot or smart light, is 66.8 ms." The tail is reported as a proportion rather than a percentile — "over 99 % of function triggers are recognized, transmitted, evaluated and executed by the testbed in under 99 ms, with a maximum observed latency of 113.5 ms".

And the number most often quoted, 149.6 ms, is not a measurement at all: "Summing the maximum latencies measured for each system segment yields a worst-case estimation of 149.6 ms." Measured maximum 113.5 ms; estimated worst case 149.6 ms; the two are not interchangeable.

The tail is worth taking seriously because of the conditions. "The testbed setup is static, ensuring line-of-sight between all devices and the nearest active antenna unit being approx. 7 m away. Throughout the testing phase, the Received Signal Strength Indicator (RSSI) consistently registered at at least -60 dBm." Ericsson 5G standalone, an IPSec tunnel between the routers, a PLC running CODESYS, and rated industrial devices in the loop — a Pilz e-stop and a Pilz light barrier — so the tail is not an artefact of improvised parts. A static, line-of-sight, strong-signal, private-5G laboratory still produced a 113.5 ms measured maximum. A hospital corridor is none of those things.

The authors do that conversion themselves: the worst-case estimation "represents the SFRT of the e-stop or light barrier and results in a minimum safety distance of 0.3 m from the moving parts based on a defined hand motion speed limit of 2 m/s". Latency is not a number about a network. It is a number about how far something travels while nothing has happened yet. IEC 63327 budgets a neighbouring quantity in its own units, at clause 7.3: "Stopping distance is based on a reaction time below 0,5 s" — a whole machine's reaction rather than a transport latency, and Sa < 1,2 × Va is where the standard turns that time into a distance.

One private-5G testbed: four numbers that mean four different thingsOne private-5G testbed: four numbers that mean four different thingsRouter to router, 5G networka network figure, not the safety path20.4 msE-stop to PLC to robot, meanmeasured: the whole safety path66.8 msOver 99 % of triggers complete undermeasured, a proportion not a percentile99 msMaximum observedmeasured: the largest actually produced113.5 msWorst case — an estimate, not measuredestimate → 0.3 m standing back at 2 m/s149.6 ms0149.6Measured on the testbedAn estimate: per-segment maxima summedA network figure, not on the safety path
  • Router to router, 5G network — 20.4 ms — a network figure, not the safety path
  • E-stop to PLC to robot, mean — 66.8 ms — measured: the whole safety path
  • Over 99 % of triggers complete under — 99 ms — measured, a proportion not a percentile
  • Maximum observed — 113.5 ms — measured: the largest actually produced
  • Worst case — an estimate, not measured — 149.6 ms — estimate → 0.3 m standing back at 2 m/s
  • Measured on the testbed
  • An estimate: per-segment maxima summed
  • A network figure, not on the safety path
Beuster, Tebbe, Doebbert and Scholl, Helmut-Schmidt-University Hamburg, Measurements of the Safety Function Response Time on a Private 5G and IO-Link Wireless Testbed, arXiv:2407.15177, submitted 21 July 2024, accepted to ETFA 2024. Axis in milliseconds, from zero. Four numbers, four meanings. 20.4 ms is “an average round-trip time between routers” over 71,757 valid measurements in 20 hours — a network figure, and not on the safety path. 66.8 ms is the whole path: “from the e-stop activation to the PLC processing and back to the robot or smart light”. The tail is reported as a proportion rather than a percentile — “over 99 % of function triggers are recognized, transmitted, evaluated and executed by the testbed in under 99 ms, with a maximum observed latency of 113.5 ms”. And 149.6 ms, the number most often quoted, is the one nobody measured: “Summing the maximum latencies measured for each system segment yields a worst-case estimation of 149.6 ms.” The only conversion into distance here is the authors’ own, on that estimate: it “results in a minimum safety distance of 0.3 m from the moving parts based on a defined hand motion speed limit of 2 m/s”. We compute no others. The conditions are why the tail matters: a static testbed, line of sight between all devices, the nearest active antenna unit approximately 7 m away, RSSI consistently at least -60 dBm, Ericsson 5G standalone, an IPSec tunnel between the routers, a PLC running CODESYS and rated industrial devices in the loop. A hospital corridor is none of those things. No threshold line is drawn: IEC 63327 clause 7.3’s note that stopping distance is based on a reaction time below 0,5 s is the standard’s own time budget for machines of this kind, but it budgets a machine’s whole reaction rather than a transport latency, and a line across this axis would assert a comparison the text does not make. The same laboratory has since measured a different chain — an IO-Link Wireless safety device to a PLC over an OPC UA backbone, on Ethernet, Wi-Fi 6 and private 5G — in Beuster, Doebbert and Scholl, Converging Safety and Security: IO-Link Wireless and OPC UA over 5G under prEN 50742, arXiv:2607.15840, submitted 17 July 2026, accepted for ETFA 2026; it is not the measurement this argument rests on, and none of its figures is drawn here. Tidewell measured none of this, on any machine.

The standard has nothing to say about losing a connection. Across the Scope, all of clause 3, and clauses 4 through 7.7, the words "communication", "connection loss", "link", "network" and "disconnect" are the subject of no requirement [inference, from a complete reading of clauses 1–7.7; the annexes are unread and the claim is bounded to that range]. Instead the document puts a rated function on the machine for every hazard it cares about, requires the tests to be run using only that control system, and has the tests run with remote operation disabled. A standard that has arranged matters so that losing the network is not a safety event has no reason to write a clause about losing the network. That is why local operation is a first-class state rather than a fallback: an argument from structure, not from preference.

What is actually left, and what we owe

Some companies publish a business model that needs the link. Loki Robotics, on its own front page, fetched 11 September 2026: "At the core, we combine end-to-end learning with teleoperation to drastically shorten deployment time and unlock real-world capability fast." That sentence says nothing about anybody's safety file, and we do not know what is in one. What a published model tells you is which functions a company's economics need to reach over a radio — and the standard names the ones that may not.

What is left of our own difference is narrow and belongs to the shared half, not the local one. The Brain page publishes a core-memory read replica on the robot, an automatic downgrade to local operation with no human action, and an append-only re-sync on reconnect — every one of them a design target, in this sentence and on that page. The incumbent's shared layer is by its own description cloud-side, single-vendor and training-time: "As that experience flows into Diligent's cloud training infrastructure, each iteration of the World Model sharpens Moxi's understanding of hospital environments, edge-case recovery, and task execution", on SageMaker HyperPod. That is a difference in architecture, not in capability, and we are not entitled to claim one.

The numbered half of this argument is owed rather than held. We have measured no detection time, no downgrade time and no re-sync behaviour, because no machine of ours has run one: W1 and B1 are prototypes and C1 is in development. When those measurements exist they are published under the same protocol as everything else, including the ones that come out worse than the target.

And the correction this article exists partly to make. Until 11 September 2026 our Brain page attributed the 20.4 ms router round trip to the e-stop path, which made the network look better than the paper found it by a factor of more than three — in a company whose argument is that the network is not where safety belongs. Two further figures, on the Body page, were withdrawn on 12 September 2026 — one a Wi-Fi latency band, one an e-stop timing requirement. Neither had a primary source behind it, and both had been supporting a conclusion we could reach without them.

For anyone specifying a machine, works without Wi-Fi is the wrong question: the incumbent with the largest installed base in hospitals already answers yes, and for the machines in this standard's scope it has been the written expectation since 2021. The question is the inventory. Which functions execute with no link, which degrade, which stop; for each safety function, which rated control system carries it; and what, exactly, the vendor's own tests were run with switched off.