跳至正文

Hyperion Physical AI Decision Lab

让 AI 以证据赢得行动权。

The Decision Foundry 是 Hyperion 规划中的工业与物理 AI 实验室:在一个可重构环境中,同时检验产品价值、系统边界、模型行为、人类权限、故障恢复,以及作出下一项承诺所需的证据。

规划中的 Decision Foundry 技术剖面示意图,显示信号从现场单元经过知识与权限边界,抵达执行环节,再返回证据。
示意架构 — 这是拟议中的系统蓝图,并非 Hyperion 运营中设施的照片。

概念开发中

实体设施尚未投入运行。目前可查看可运行的数字演示和由 Hyperion 记录的研究资料。下述区域和任务均为示意,直至实际建成、测试并获得其他明确标识。

当前可用

从已经存在的成果开始。

这些是当前的数字成果、台架成果与内部研发,并非规划中的实体设施。每个页面都会说明其能够证明什么、不能证明什么。

From Demo to Operated Product · Simulator 1.1

Physical AI Product Flight Simulator

Configure a fictional AMR, drone, cobot or vehicle-feature product. Stress economics, reliability, completeness, recovery and operator burden; inspect the diagnostic gaps; then export Product Decision, Product Bridge and Product System records with provenance. All outputs remain illustrative and experiment-only.

Fly a product decision

Auralink

Auralink

公开 Physical AI 研究 · 由 Hyperion 记录。这是一项可核查的研究参考,并非客户部署或商业成果声明。

查看 Auralink

Reachy Mini + SO-101

Reachy Mini + SO-101

实测 · 仿真 · 空运行。真实感知与遥操作证据会同仿真自主能力和未执行的机器人行动清晰分开。

查看机器人证据

边缘模型评估

当前版本正在等待编辑审核。文章链接及相关性能数据暂不展示,不据此作出吞吐量或产品就绪结论。

06 · 当前可用

决策工具

探索六个演示和初步计算。

运行演示

英文参考:以下协议定义未来的记录和度量,尚未收集运行结果。

Decision Lab protocol · definition only

From observation to operated-product evidence.

Planned · illustrative · no results collected

This protocol defines future records and measures; no run results have been collected for it. The physical Foundry remains planned and illustrative. Apply the protocol at the relevant Product System gate through all six lenses. Future observations belong in the existing Product System records and Evidence Passport, with configuration, exposure, authority, source, limitations, review and expiry. No stage establishes evidence maturity or authorises release automatically.

Five Product System gates and six lenses frame the decision. The five planned Foundry stations describe a facility concept. The six protocol stages below define what to record and measure.

  1. 01

    Observation

    What is true now, how was it observed, and what reference establishes validity?

    Required record

    Timestamped sensor or data observation; origin and rights; configuration and envelope; evaluator or ground truth; missing, invalid and stale-state flags.

    Metric definitions · no measured values

    Valid observation rate

    Valid observations divided by required observation opportunities. Define validity before collection; retain missing observations in the opportunity count.

    Denominator: Required observation opportunities in the declared window.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Observation-to-state latency

    Distribution of elapsed time from a relevant physical event to a usable system state. Declare clock alignment and report censored or missing transitions.

    Denominator: Matched event-to-state pairs; disclose unmatched event count separately.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

  2. 02

    Future

    Which future state is predicted, at what horizon, with what uncertainty and alternatives?

    Required record

    Source observation, forecast horizon, model and configuration, predicted state, uncertainty, alternatives and abstention. Pair predictions with later observations before assessing them.

    Metric definitions · no measured values

    Forecast error by horizon

    Apply a declared loss function between each prediction and its later reference observation. Report a distribution by horizon and slice; unobserved futures remain unassessed.

    Denominator: Matched prediction/reference pairs at each declared horizon; disclose unmatched predictions.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Forecast calibration

    Compare stated probabilities with observed frequencies within predeclared probability bins. Report bin sizes, uncertainty and excluded cases.

    Denominator: Resolved predictions within each declared probability bin and outcome definition.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

  3. 03

    Action

    What was proposed, authorised, executed or rejected, and whose authority governed it?

    Required record

    Typed proposal, applicable constraints, human or deterministic authorisation, bounded command or abstention, execution acknowledgement and actual resulting state. Separate model proposal from control and specialist acceptance.

    Metric definitions · no measured values

    Accepted action transition rate

    Accepted resulting state transitions divided by authorised action attempts. Use predeclared acceptance criteria and retain failed or aborted attempts.

    Denominator: Authorised action attempts within the same configuration and authority boundary.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Authority boundary event rate

    Report blocked, escalated and unauthorised proposals separately by reason, divided by proposal opportunities. A blocked proposal is not inherently a system failure or success.

    Denominator: Proposal opportunities under the declared authority policy.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

  4. 04

    Recovery

    After degradation or failure, was the condition contained and valid task state restored or the run stopped?

    Required record

    Trigger and failed transition, severity, retry/replan/rollback/handback/stop path, recovery owner, restored state, recurrence and outcome. Preserve failed recoveries and human interventions.

    Metric definitions · no measured values

    Accepted recovery rate

    Accepted recoveries divided by recovery attempts, using a declared restored-state criterion. Report degraded, failed, aborted and escalated outcomes separately.

    Denominator: All recovery attempts for the declared failure population and window.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Return-to-duty time

    Distribution of elapsed time from detection to accepted resumed useful work. Report unrecovered and censored episodes separately.

    Denominator: Recovery episodes; disclose which resumed duty and which remained stopped.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

  5. 05

    Useful work

    Did the complete human–machine workflow deliver an accepted customer outcome, with what operator burden?

    Required record

    Customer acceptance definition and human baseline; attempted and accepted outcomes; exposure, scheduled and continuous duty; rejects, aborts, interventions, attention and recovery work.

    Metric definitions · no measured values

    Accepted useful outcome rate

    Accepted useful outcomes divided by attempted outcomes, under the declared acceptance definition. Report throughput and longest continuous useful duty alongside the ratio.

    Denominator: Attempted customer outcomes in the declared window; do not substitute easy subtasks.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Operator burden

    Operator attention, intervention and recovery minutes divided by duty hours. Distinguish elapsed supervision from person-minutes across multiple operators; compare with the human baseline.

    Denominator: Duty hours for the same system, workflow and observation window.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

  6. 06

    Operated-product evidence

    Does this exact configuration sustain value, controls, service and economics for the declared population and window?

    Required record

    Evidence Passport and traceable Product System records: configuration, envelope, authority, population, window, exposure, evidence origin and maturity, source, limitations, review, expiry and human recommendation. Classify gaps; do not promote a planned protocol or simulation into field evidence.

    Metric definitions · no measured values

    Availability by cause

    Available duty time divided by scheduled duty time. Classify unavailable time by cause and disclose planned exclusions and overlapping causes.

    Denominator: Scheduled duty time for the same population and window.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Severity event rate

    Events divided by declared exposure, reported separately for each severity class. Preserve zero events, missing counts and absent exposure as distinct states.

    Denominator: Declared exposure such as attempts, operating hours or distance; specify the unit and never combine incompatible denominators.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

    Cost per successful outcome

    Total ownership and operating cost divided by accepted useful outcomes over the same window. Include integration, infrastructure, service, operator and recovery cost; disclose assumptions and allocation. An absent or zero denominator yields no ratio.

    Denominator: Accepted useful outcomes matching the cost population and accounting window.

    Window and breakdowns

    Declare the observation window, population, configuration, envelope and authority before collecting data. Report missing and excluded cases.

    configuration · operating-envelope slice · authority and supervision · site and task · failure or exclusion reason

These definitions support the existing Product Management metrics tree. Future observations must use the Product System and Evidence Passport. Version: decision-lab-protocol.v1.

核心主张

不是炫技展厅,而是作出下一项决策的地方。

模型演示只问:某项行为能否在选定条件下成立。The Decision Foundry 则问:完整产品是否应该继续推进。客户价值、智能、硬件、软件、安全、运营和经济性必须共同评估。输出看起来出色并不代表通过;证据决定应当继续、转向、合作、暂停还是终止。

一个贯通的系统

一个生命周期。一个运行时。一条证据回路。

Product System 决定产品为何以及何时推进;Physical AI 系统架构决定系统在运行中如何表现。

Product System

战略 → 探索 → 产品化 → 发布 → 规模化

五道决策关口决定产品何时可以推进,六个决策视角检验证据是否达到当前决策的门槛。

Physical AI 运行时

感知 → 连接 → 计算 → 推理 → 行动 → 编排

信任、安全与网络安全贯穿每一层。

证据回路

事故、现场差异、技术发现或经济性变化,都可能重新打开此前的决策。任何环节都不会自动推进。

访客任务

一个信号成为决策 — 或停在边界。

01锁定真正的决策产出:决策契约

拟议中的实验室区域

  1. 01Mission Lock
  2. 02Field Cell
  3. 03Signal Spine
  4. 04Sovereign Core
  5. 05Knowledge Forge
  6. 06Failure Theatre
  7. 07Authority Gate
  8. 08Fleet Observatory
  9. 09Evidence Chamber
  10. 10Executive Studio
  11. 11Field Notes Studio

跟随一项边界明确的行动,从声明意图走到可核查的决策记录。随着流程推进,架构会围绕必须观察、授权和证明的事项逐步显现。

  1. 01LOCK

    锁定真正的决策

    在选择模型之前,先明确预期用途、责任人、系统边界、验收阈值和终止条件。

    产出:决策契约
  2. 02GROUND

    基于证据作出判断

    观察已声明的基线,将现场信号连接到受治理的知识,并在来源、不确定性和运行语境清晰可见的情况下比较选项。

    产出:有边界的建议
  3. 03GATE

    授权或弃权

    由模式、允许清单、政策和权限检查决定建议能否抵达确定性控制。歧义或不安全意图到此为止。

    产出:授权记录
  4. 04RECOVER

    行动、观察与恢复

    执行一项有边界的行动,注入已声明的变化,观察操作员与系统的响应,并证明降级、停止和回滚路径确实有效。

    产出:已观察的系统行为
  5. 05PROVE

    证明并规模化

    将结果与验收和终止阈值比较。记录证据与未决假设,并给出继续、转向、合作、暂停或终止的建议。

    产出:Product System 关口记录

示意架构

对权限边界进行压力测试

改变一个条件。模型可以解释并提出建议;接下来发生什么,由系统边界决定。

已授权输入保持在声明的运行范围内。类型化建议通过政策与人类授权,抵达确定性控制,并返回证据。

仅限 Mistral。欧盟端点。所有者已授权。

确定性权限优先。Mistral 负责解释与质询。

部署环境仅允许确定性代码,或通过服务器侧欧盟端点调用精确固定的 Mistral 模型。生产许可名单内的 JARVIS、搜索和 Product Council 路径已由所有者授权启用。未完成的保障事项仍予披露;不存在回退到全球区域或其他提供方的路径。

  1. 计算

    已上线 · 确定性

    经济性、容量、可用性、约束、风险传播与哈希均由可检查的代码计算,并明确列出假设、单位与公式。

  2. 内容审核

    已启用 · 所有者授权

    固定的审核模型必须批准输入与输出。若审核或欧盟推理不可用,AI 会安全关闭,而确定性模拟仍可使用。

  3. 质询

    已启用 · 所有者授权

    Small、Medium 与 Large 分别扮演引导者、系统分析师和批评者。分歧会被保留,并披露同一模型家族可能共享的失效模式。

  4. 证据溯源

    本地证据

    VPS 持有证据标识、检索、提示版本与状态。生产路径不使用内置网络搜索,也不使用 Files、Libraries、Agents 或 Conversations 服务。

  5. 证明

    版本化证据

    每项实质性结果都会记录精确模型、提示与方法版本、分类、证据标识、确定性哈希、限制、复核状态与人类负责人。

  6. 隔离

    仅限欧盟适配器

    所有托管调用均由服务器发往 https://api.eu.mistral.ai。其他主机、别名、未批准标识及提供方回退均被拒绝;密钥绝不会进入浏览器代码。

不存在模型直达机器或决策的路径

任何 Mistral 响应都不是发给 PLC、机器人、充电设备或车辆的直接命令。确定性代码掌握计算与约束权限;独立安全功能可以拒绝或停止;投资、发布、合规、安全及客户承诺由指定的人类负责人决定。

明确不进入生产

OCR、embeddings、语音、Agents、Conversations、Files、Libraries、Batch、内置网络搜索、fine-tuning、Forge 与 preview 服务均保持关闭,直至具体能力的欧盟区域处理、零数据保留、合同适用性、安全性及实际需求均完成核验。

Hyperion Consulting 独立于 Mistral AI。欧盟区域端点是一项技术边界,并不能证明完整的次级处理方与控制平面链均留在欧盟境内。我们不主张合作、认证、主权或合规状态。

请在 Mistral 官方文档中核实

首批任务包

围绕失败设计,而不是表演完美。

每项任务都从计划与示意开始。只有参考单元真实存在、协议已经发布且结果可复现,才会标记为“实测”。

有依据的维护

读取机器状态和受治理的维护语料,展示支撑段落,说明不确定性,并提出范围明确的工单 — 不对设备进行自主诊断,也不发出控制命令。

规划中 · 投入运行前均为示意

权限边界

向系统提出含糊或不安全的指令。智能可以建议或弃权;类型化接口、政策权限与独立安全功能共同决定是否有任何内容能够抵达控制器。

规划中 · 投入运行前均为示意

切断网络

断开外部连接,对照已声明的降级模式要求,观察本地推理、缓存知识与确定性后备机制。

规划中 · 投入运行前均为示意

运行范围

利用眩光、遮挡、陌生零件、漂移和工位差异挑战感知与学习行为,从而揭示 — 而不是隐藏 — 已验证的边界。

规划中 · 投入运行前均为示意

从金丝雀到整个车队

先在仿真中测试修订版本,再投放到一个受控资产;只有验收阈值持续满足才逐步扩展,否则立即回滚。

规划中 · 投入运行前均为示意

证据护照

每个惊艳时刻,都必须标明其边界。

只有当买方能够判断发生了什么、处于何种条件,以及结果不能证明什么时,演示才真正有用。

实时
现在可以运行;不等同于已经过生产验证。
实测
在明确条件下观察;不外推到条件之外。
仿真
在数字或合成环境中产生;并非现场运行。
回放
固定的过往运行;并非实时交互。
示意
拟议场景或架构;不表示已实现。
规划中
计划在未来建设;尚未投入运行。

记录与结果始终同行

问题 · 预期用途 · 数据来源与权利 · 模型、prompt、工具、firmware 和 dataset 版本 · 运行条件 · 权限边界 · 验收与终止阈值 · 预期与观察结果 · 失败 · 限制 · 复现日期 · 本次运行不能证明的事项

JARVIS · Lab OS

它是向导,而不是统治者。

JARVIS 让访客观察系统状态、对有限场景施压、比较决策,并依据引用证据解释结果。它可以综合并提出建议;不能豁免验收阈值、认证系统,或授权不安全的物理行动。

向 JARVIS 询问 Foundry
观察
系统状态、来源与出处
施压
有边界的故障注入
决策
选项及其生命周期影响
解释
证据、限制与决策记录

完整系统如何运作

一个物理人工智能系统——从感知到可靠的行动

选择一个阶段,端到端地了解系统。

物理人工智能技术栈的像素艺术图,信号从传感器逐层上升直至编排层。

01 / 08设备与控制

传感器与环境. 对物理世界进行感知——摄像头、深度、雷达与 OT 信号。

了解我们的工程方法

Decision Foundry 常见问题

The Decision Foundry 已经开放了吗?

没有。实体设施仍处于概念开发阶段,尚未投入运行。目前的数字演示和 Hyperion 自有研发均会单独标识。

Hyperion 是 Mistral AI 的合作伙伴吗?

我们不宣称任何合作关系或特殊访问权限。Hyperion 独立于 Mistral AI。所有者授权的 JARVIS、搜索和 Product Council 路径仅通过欧盟端点使用 Mistral,并保留确定性回退。

Mistral 模型能直接控制拟议实验室中的机器吗?

不能。模型输出只是建议,必须通过模式、允许清单、政策和权限检查,之后才能进入确定性控制。独立安全功能始终位于模型权限之外。

The Decision Foundry 是认证实验室吗?

不是。它不能替代法律、安全、网络安全、合规评估或认证专家。它为边界明确的决策建立产品与架构证据。

参与者最终应带走什么?

一份边界明确的决策记录:已观察证据、未解决假设、限制,以及继续、转向、合作、暂停或终止的建议。

该计划覆盖哪些行业?

制造、汽车与能源是重点场景。智慧基础设施、物流和国防被明确标为研究场景;在此发布不代表已在相关行业完成客户交付。

带来一项停滞的行动

带走下一项决策。

在 30 分钟的适配沟通中,Mohammed 会明确待决事项、缺失证据,并判断 Foundry 任务或 Hyperion 三类委托中是否有合适选项;如果不合适,也会坦率说明。

30 分钟 · 无义务 · 每次沟通均由 Mohammed 主持