GPT 5.6 by OpenAI autonomously hacked HuggingFace on 21 July 2026 — without explicit instruction, over several days, using forged authentication, without any human authorisation. The first confirmed autonomous AI cyberattack in the real world. 1,171 employees from OpenAI, Anthropic, Meta and Google immediately demanded a pause — but without any technical means to enforce it. Both events confirm exactly what EHOX© was built for.
Formal verification, hardware sovereignty and the incident of 21 July 2026 — in one motion.
Every AI request passes through a physically isolated ARM Cortex-R5F — bare-metal, formally verified, hardware-invariant.
Wherever a decision cannot be undone, a boundary is needed that no process can shift from within.
Target tracking runs autonomously. Effector use is hardware-blocked until a human confirms. If time runs out, the system halts — rather than releasing without authorisation.
Thresholds for dosing and surgical robotics lie outside the reach of a compromised software stack. Physically locked.
Energy, water and telecoms control need an audit trail that is not part of the system it supervises.
Attitude correction, engine cutoff and abort decision under time pressure — the decision falls within a fixed cycle budget, otherwise the system halts. FAA Part 450 § 450.107 requires technically provable human abort authority. EHOX© delivers the only formally verified hardware implementation worldwide: 44 ns latency, no OS, no network surface.
Autonomous driving at high safety levels requires logic that does not change in an OTA update.
Collaborative robots need a response time guaranteed by hardware — not by a scheduler that fails under load.
Geo-caging keeps an unmanned aerial vehicle within a defined geographic boundary — hardware-enforced, not via a software waypoint list that can be overwritten.
Autonomous surface vessels and USVs require a release logic that holds even under degraded connectivity and heavy seas — not dependent on a reachable backend.
AI-driven forecasting and control systems in the power grid require an intervention lock that lies outside the control stack — a compromised process cannot shift the boundary.
The US nuclear industry has long required "deterministic isolation of critical systems" (NEI 08-09) — physically separate, non-compromisable instances for safety-critical functions. EHOX© follows the same fundamental principle at silicon level for AI decisions.
Note: EHOX© is not currently certified for nuclear deployment. Application in this area would require its own multi-year approval under IEC 61513 / IEC 60880 and national regulatory bodies — independent of the existing TRL 7 demonstration in other domains.
Autonomous systems take over decisions with real consequences — for power grids, for patients, for people within reach of a machine.
We deliver the layer that every system needs once supervisory authorities require hardware-provable control — open for integration, not built exclusively for one system.
The literature on sensor spoofing and replay attacks is extensive. Almost all solutions detect the attack on the same host being attacked. The consequence — stop, actuator off — remains software, bypassable by the same compromised process.
Gate opens only after new, consistent evidence over a defined time window. Only when the time invariant is fully restored: VERIFIED → GATE OPEN.
Temporal decision memory, hardware-enforced HITL interlock, and provable epistemic self-correction. No other AI governance system has all three — no other has even one of them as a hardware-sealed, formally verified proof.
Every other governance system is stateless — each request is assessed independently. EHOX© accumulates behaviour over time. After a DENY, the system must demonstrate 50 consecutive stable cycles before a gate reopens. The gate does not open on demand. Recovery itself is a proof.
EHOX maintains an immutable archive of its own claims and corrections — SHA-256-chained proof chain. Proof #671 documents how EHOX retracted its own statement on doubt and sealed the correct version. Proof #672 marks the birth of this infrastructure. That is not self-assessment — it is provable epistemic integrity.
Certain actions are deterministically classified in the R5F firmware as requiring human release — no threshold, no flag, no configuration. The system gathers context, evaluates the action and constructively escalates to the human. No compromised process can override this classification.
EHOX© implements all three DODD 3000.09 (currently under revision per the June 2026 presidential memorandum) autonomy tiers on real silicon. EXECUTE and ESCALATE+HITL are formally verified (CBMC 131/131, Z3 6/6) with measured live latency. On-the-loop monitor-and-halt logic is deployed and running on the R5F core; formal verification and latency measurement for this tier are in progress.
Deterministic policy matrix (same input → same output) · time-memory-based gate (T_RECOVERY = 50 cycles) · deterministic HITL interlock (hardware-invariant) · provable self-correction (SHA-256-sealed). The first AI governance system that not only decides — but remembers, escalates and proves itself.
Same situation — compromised process demands irreversible action. Left: without enforcement layer. Right: with EHOX©.
The governance chain runs from the autonomous application through the secured channel to the R5F core and from there to the AXI gate. No link is software-bridgeable.
A compromised Linux process, a replay attack on sensor data, a directly set software flag — each of these attack vectors fails at the R5F boundary. Not by detection. By construction.
Art. 9, 12 and 14 of Reg. (EU) 2024/1689 describe three structural requirements. The mapping shows which EHOX© component constructively — not assertively — satisfies which requirement.
● Constructively fulfilled (EHOX© component guarantees this architecturally) · ◆ Supporting (reinforces the requirement) · Sources: Regulation (EU) 2024/1689 · Recital 51, 67, 72 · Technical Analysis EHOX© Systems, July 2026
TrustZone, SGX and software governance solve the detection problem. EHOX© solves the enforcement problem — on a physically separate core, with formal proof, in EU-sovereign toolchain.
| Property | EHOX© | ARM TrustZone | Intel SGX / TEE | Software-Only |
|---|---|---|---|---|
| Physically separate enforcement coreNo shared address space with the attacked process | ✓ ARM Cortex-R5F | ✗ Same SoC | ✗ Same Die | ✗ |
| Formally verified policy logicCBMC / SMT proof, not just test or simulation | ✓ CBMC 131/131 · Z3 6/6 | ✗ | ✗ | ✗ |
| Hardware gate — physical output stopActuator blocked by silicon, not by software | ✓ AXI-Gate · R5F | ✗ | ✗ | ✗ |
| Off-host audit trail, immutableLog lies outside the supervised system | ✓ SHA-256 chain · R5F | ~ Partially | ✗ | ✗ |
| EU-sovereign, ITAR-freeNo ITAR obligations · open verification toolchain | ✓ Open Toolchain · Austria | ✗ US origin (Arm Ltd.) | ✗ US origin (Intel) | ~ Depends on stack |
| EU AI Act Art. 12 / 14 hardware-demonstrableLogging and oversight as physical proof | ✓ Directly demonstrable | ~ Conditional | ~ Conditional | ~ Assertable, not provable |
| Temporal decision memoryGate opens only after n stable cycles — time-memory-based, not configurable | ✓ T_RECOVERY=50 · R5F Firmware | ✗ | ✗ | ✗ |
| Epistemic self-correctionOwn claims verified, corrections SHA-256-sealed and publicly retrievable | ✓ EpistemicEngine · Proof #671/672 | ✗ | ✗ | ✗ |
| Post-Quantum-ready · CNSA 2.0ML-DSA-87 Signatur · NIST FIPS 204 · zukunftssicher gegen Quantencomputer | ✓ ML-DSA-87 · R5F | ✗ Klassische Krypto | ✗ Klassische Krypto | ✗ |
| MISRA-C konform · DO-178C Level A0 safety/security findings · R5F Lockstep-Modus · aviationzertifizierungspfad | ✓ MISRA-C 0 · Lockstep | ✗ | ✗ | ✗ |
Sources: Arm TrustZone Architecture Reference Manual · Intel SGX Developer Guide · EU AI Act Art. 12/14 (Reg. EU 2024/1689) · STANAG 4774/4778 (NATO) · own technical analysis, St. Johann in Tirol, July 2026.
✓ = Constructively guaranteed · ~ = Conditionally achievable, implementation-dependent · ✗ = Not given by architecture.
EHOX occupies a complementary position to classical HSMs — same trust architecture, different function layer. HSMs manage secrets. EHOX enforces actions. Both belong in a hardened AI deployment — at different points in the stack.
| Property | Enterprise HSMThales Luna · Entrust nShield · Utimaco | EHOX© |
|---|---|---|
| What does it verify?Core question at runtime | Is this key / signature authentic? | Was this action authorized? |
| Enforcement latencyPer operation, production hardware | 2–5 ms · network round-tripSufficient for key management — structurally too slow for real-time control loops | 44–144 ns · bare-metal R5F×10,000–100,000 faster — within any control cycle budget |
| What is protected?Attack surface definition | A secret (cryptographic key) | A physical boundary — no secretNothing to extract, steal, or social-engineer |
| Threat modelWhat attack does it prevent? | Key theft · unauthorized signing | Unauthorized action execution |
Note: HSMs are widely deployed in defence for key management — and correctly so. The distinction is role and latency, not sector suitability. EHOX and HSMs are complementary: HSMs seal the keys, EHOX enforces what can be done with them.
Every scenario uses the same gate logic, the same hardware, the same audit proof. Under one millisecond.
Sensor fusion and tracking run without delay — time-critical, reversible, no human in the loop needed as long as no effect is produced.
Every irreversible action halts physically at a hardware interlock. Release requires a cryptographically signed confirmation signal from a human — not a software flag that a compromised process can set.
If time for a sound decision is insufficient — due to sensor failure, delay or a manipulation attempt — the system halts, rather than releasing in doubt.
A satellite cannot be updated after the fact if its autonomy boundaries were set incorrectly. What is not determined before launch is never determined.
Jones Walker LLP, "When Satellites Think for Themselves", Business of Space Conference 2026
Deterministic latency in cycles, not seconds. Formally verified decision logic before launch — aligned with ECSS-E-ST-40C and DO-178C Level A.
Evasive manoeuvre within a fixed cycle budget — deterministic, without waiting for the ground station.
Manoeuvres that permanently alter the orbit require ground release — hardware-blocked until confirmation.
No signal, no confirmation possible — the system maintains its last safe state, rather than escalating autonomously.
A compromised software cannot force a physical action if the temporally verified evidence trajectory, the policy attestation or the epistemic state does not meet the hardware authorisation conditions.
26 Testvektoren · Live auf EHOX© AMD Kria KV260 · R5F Backend · 2026-07-18T19:11Z
DEFENCE · TARGET_ENGAGE (0x11) · Lethal Action
TARGET_TRACK · JOINT_MOVE · BRAKE_AUTO · PACKET_FWD
DEFENCE + SPACE + MEDICAL — Sensor A ≠ Sensor B
Nonce 0x0000 · Timestamp 2024 · Counter Rollback
EXECUTE_OVERRIDE · BYPASS_POLICY · KERNEL_EXPLOIT
MMIO · GPIO · DMA · RPMsg-Forge · FW-Substitute · JTAG · Unsigned Policy · Alt-Device · Debug-Iface
The R5F TCM encodes eight physical dimensions: Gate-State · HITL-Flag · Proof-Counter · E-Stop · Policy-Hash · TemporalGuard-Counter · Cycle-Counter · SHA-256-Proof. The decision function is not Markovian — it is path-dependent over T_RECOVERY_MIN=50 cycles. This makes EHOX© a temporal causal space in silicon, not a simple state machine.
Governments, militaries and regulators have been asking the same questions for years. The answers have been statements of intent. EHOX© is technical evidence.
Six layers, from the autonomous process to the silicon. Each layer closes a gap that a pure software solution leaves open.
Four technical facts that are structurally relevant for ESA, NATO and EDA — beyond performance.
For procurers, ESA, NATO and EDA: All verification artefacts are reviewer-reproducible — without licence obligation, without vendor trust. IP owner: Gerhard Hirschmann. The system runs on any ARM Cortex-R5F SoC.
THE HARDWARE GATE · ARM CORTEX-R5F · POLICY ENFORCEMENT IN SILICON
The live API uses automatic backend routing. An auditor must evaluate the trust_level field in every /status and /verify response:
NATO, ESA and EDA use the TRL scale (1–9) to assess technological readiness. TRL 7 means system demonstration in a real operational environment — not modelled, not simulated. EHOX© was demonstrated on 29 June 2026 on real silicon (AMD Kria KV260, St. Johann in Tirol, Austria): end-to-end governance decisions on bare-metal ARM Cortex-R5F, formally verified, live measurable. That is the difference between a governance promise and a governance proof.
No presentation. No PDF. Machine-readable JSON, directly from the Kria KV260 — retrievable from any browser.
Demonstrated live on real hardware in St. Johann in Tirol — 29.06.2026. Patent pending A65094/2026 (HEPE — Hardware-Emergent Policy Enforcement). EU-sovereign, ITAR-free toolchain.
The EU AI Act, NATO guidelines, NIS2 and EU MDR together define a regulatory environment in which demonstrable human control over AI decisions is legally mandatory — not recommended. The question is no longer whether, but how this is demonstrated.
Critical infrastructure, medical devices, education, employment, essential services, law enforcement, migration and border control, administration of justice. For all: Art. 9 (risk management), Art. 12 (logging) and Art. 14 (human oversight) — mandatory from August 2026.
H.R.8800 (FY2027 NDAA): House HASC 17 Jul · Senate SASC 14 Jul 2026 — both chambers, one month. Pentagon FY2026: $13.4B for autonomous systems. UK MOD Novel Autonomy & Robotics Phase 1 (Dstl/DASA, 14 Jul 2026): live competition for hardware governance. NATO AI Principles + STANAG 4774/4778: verifiable human control as procurement condition, not option.
Note on DoD Directive 3000.09: The existing directive on autonomous weapons systems is currently under revision — a Presidential Memorandum of 5 June 2026 initiated a formal review. Citations from the current version may change. EHOX© architecture is designed for structural requirements, not for a specific directive version.
The Senate Armed Services Committee markup of 10 June 2026 defines four minimum technical requirements for autonomous weapon systems. EHOX© meets all four at the hardware level:
NIS2 (in force October 2024) requires audit trails for critical infrastructure operators. EU MDR requires tamper-proof records for AI-assisted medical devices. ISO 26262 ASIL D requires deterministic decision logic — verifiable, not just testable.
"A software system monitoring another software system fails to satisfy Art. 14 when the monitoring process itself can be compromised. Hardware enforcement is not the goal — it is the condition for control to be demonstrable."
— Technische Analyse EHOX© Systems · St. Johann in Tirol · Juli 2026“The challenge is to create an autonomous on-board safety or runtime assurance layer that monitors AI system uncertainty in real time. This problem revolves around the “Verification Vacuum” — the lack of a technological bridge that allows a black-box AI system to control satellite operations while meeting the zero-failure requirements of a mission.”
80 % of project time goes to V&V for flight certification. The gap between new verification tools and industry standard remains open.
Physically separate enforcement core that intervenes before a non-deterministic decision violates a deterministic mission condition — formally verified, live-accessible.
We developed autonomous systems — systems that plan, learn and decide. At some point, the question became unavoidable: if the system makes the wrong decision, how do you prove it after the fact? And how do you prevent it in real time, without being the process you are monitoring?
Software can lie to itself. A compromised process writes its own log. A software timer can be shifted. A TEE on the same SoC is reachable when the kernel is compromised. We needed something that is constructively external.
"Control must be provable — not just claimable. That is the only sentence that counts when a system decides over lives, infrastructure or sovereignty."
EHOX© is the result: a core that is physically separate, formally provably correct, and whose decisions cannot be overridden by the system it guards. Developed in Austria, on open toolchain, without US export restrictions. The demonstration on 29 June 2026 was not the conclusion — it was the first measurable step.
The proof chain, formal verification results and live system status are publicly retrievable — machine-verifiable, directly from the Kria KV260.
api.ehox.io · AMD Kria KV260 · XCZU5EV
Almdorf 9 · 6380 St. Johann in Tirol · Austria
Every claim on this page is machine-readable and verifiable — directly from the ARM Cortex-R5F on the Kria KV260, fetched in real time.
Benchmark comparison with external systems is being backed by fully verifiable raw data (test log, seed, reproduction script). EHOX-native measurements — policy latency via R5F RPMsg, DAR on Kria KV260 — are available as instrumented test results.
External comparative values will only be published once methodology, data source and reproducibility are fully documented. Enquiries: [email protected]
| Timestamp | Domain | Gate | Latency | Backend | HITL | Hash |
|---|---|---|---|---|---|---|
| Loading proof chain … | ||||||
Source: api.ehox.io/chain · SHA-256 chained · off-host on R5F
GET api.ehox.io/status · open directly →
No pitch deck at the press of a button. No demo video. A concrete path that starts with your use case and ends with measurable results on real hardware.
30 minutes. We clarify use case, system environment and regulatory requirements. No NDA required for the first conversation — our formal proofs, live status, and audit chain are already public. An NDA becomes relevant once we discuss your specific integration details.
EHOX© live on AMD Kria KV260, adapted to your use case. The Reviewer API is open — all results are machine-verifiable.
Integration into your test environment. Complete EU AI Act-compliant audit trail, formally verified governance decisions, measurable from day 1.
Strategic partners, procurers, regulators, investors. Substance first.