A welding cell's interlock never failed. It had no opinion about who was inside. A worker died with two supervisors in the cell.
When Feedback Misses Its Window ended with a protection system that did everything it was designed to do, just after the moment when doing it would have mattered. That failure was about timing, and timing is arguable. Reasonable engineers disagree about how much margin is enough.
This one is not about timing. The mechanism was present, it worked, and it was available at the exact moment it was needed. Nobody had to react faster or predict anything. The question is narrower and harder. What makes a control binding?
Stress test. Claim under test (Articles 4 and 5): a supervisor governs by controlling which events are permitted. Permission is the first element of managed autonomy. Domain: industrial automation. The question: what happens when permission is required but not enforced?
The domain that should have been easy
I chose industrial automation because it is the mature case, and I expected it to push back hardest against the thesis.
Every idea this publication has spent five articles building has an older, more concrete cousin on a factory floor. Constraints are fences. Permission is a lockout. A supervisor that stops an action before it happens is an interlocked gate. There are standards, some of them decades old, written by people who watched what happens when a manipulator moves through a space a person is occupying. A robotic welding cell should be the safest place in this series.
Cusseta, Alabama
On 18 June 2016, at an auto parts plant that stamped and welded dashboard components for Hyundai and Kia, a machine stopped because of a sensor fault. The welding process throws dust, the dust settles on the sensors that detect whether a part has been set down, and a fouled sensor halts the line. Clearing one takes seconds. Someone goes in and wipes it with their hand.
Regina Elsea was twenty and had worked at the plant about three months. She entered the cell through the front gate. Several people were already inside, including two supervisors. While she was standing about a foot and a half from one of them, a robotic arm energised and pinned her against another piece of equipment. She died the next morning, two weeks before her wedding.
The plant had a procedure for this. Seven steps, illustrated with photographs of the specific panel and gate. Put the robots on hold, turn the control to manual, press two more buttons. Then step four. Open the safety plug on the rear gate, flip the strikeplate down, put your personal lock through it. A buzzer sounds as the handle comes out. Everyone entering hangs their own lock, however many are already there.
That gate is not a door. It is a switch. It connects to an electrical interlock that deactivates the cell's robots whenever it is open, and the locks exist to hold it open, which is to say they exist to hold the robots off. The company later admitted in a federal plea agreement that if the procedure had been followed, the machinery could not have energised while she was inside. Her supervisor conceded at trial that one lock, hung by any of the people who went in, would have been enough.
Nobody hung a lock. Not that time, and not, it turns out, most of the time.
Why didn't the interlock help?
The temptation is to say the safeguard was bypassed, and that would be wrong. Nothing was defeated. No wire was jumpered, no device disabled, no password shared. The interlock worked perfectly that morning.
What happened is more interesting than sabotage. The cell's safeguards were keyed to points of entry rather than to occupancy.
The rear gate interlock answered whether that gate was open. The light curtains at the front answered whether something had crossed a particular plane. Some sensors could be cleared by reaching through a curtain, and for those the curtain was doing real work. The sensor Regina Elsea was clearing sat deep enough that reaching it meant walking in, and no light curtain covered that path.
So the question nobody's equipment was asking was the only one that mattered. Is there a person in this cell right now?
Entering through the front gate did not circumvent the interlock. It went somewhere the interlock had no opinion about. The equipment could establish a safe state. What it could not establish was whether anyone who needed that state had invoked it. OSHA's own guidance catalogues the failure mode, listing among documented accident types a worker pinned during automatic operation because perimeter guarding was inadequate enough to let someone enter without triggering a protective stop.
Engineered or expected
Safety engineering already has the vocabulary, and it is worth using the existing term rather than inventing a parallel one.
Engineering controls act on the hazard. Administrative controls act on the person. A guard that physically prevents contact is the first kind. A procedure instructing someone not to make contact is the second. Both belong in a serious safety programme, but they are not interchangeable and they are not ranked equally. Engineering controls sit higher because they do not depend on anyone remembering anything.
Control engineering makes the same distinction from the other direction, and this is the version I keep returning to. A supervisor can only enforce conditions it can observe. Everything else it can only request.
Ajin's cell had an engineering control available. It also had an arrangement in which invoking that control was a voluntary act, performed by the person the control was meant to protect. Those two facts together are the whole article.
What the enforced version looks like
The discipline had worked this out long before 2016, and the guidance is not ambiguous.
For non-collaborative robot applications, the approach is to physically separate people from the machine during automatic operation, using guards and barriers, interlocked guards, and presence-sensing devices. That last category is the important one. Light curtains, safety mats, safety scanners, safety vision systems. Devices whose purpose is to answer the occupancy question rather than the entry-point question.
Then the line that reframes the incident, from OSHA's technical guidance on robot systems: in most circumstances, the robot application automatically achieves a safe state when a worker enters the safeguarded space.
Automatically. Not when a lock is hung. Not when step four of seven is performed correctly by a tired person under a quota.
There is also a defined answer for when somebody genuinely must be inside a live cell, which happens constantly during programming and troubleshooting. The answer is not to trust them. It is to reduce what the machine is allowed to do while they are there. Manual mode. Speed capped at 250 millimetres per second, slow enough to step away from. And an enabling device, typically a three-position switch held in the hand, where releasing it or gripping it too hard inhibits motion, and where interconnected equipment is inhibited along with it.
Read those together and the industry arrived somewhere without any help from this publication. There are two legitimate states. Either no person is inside while the machine holds full automatic authority, or a person is inside and that authority has been deliberately cut. What is not on the list is a third state where a person is inside, the machine still holds full authority, and the only thing between them is a padlock somebody was supposed to remember.
The arithmetic
By now a pattern should be visible. Nobody at that plant was confused about the hazard, and nobody lacked the equipment to control it. What the record shows is nineteen months of the safety function saying so. An email in October 2014 warning that employees were locking out improperly, not locking out, or bypassing the procedure, and that some managers were letting it happen. Another in November 2015 calling it an ongoing issue management had not addressed. A third six weeks before the accident, saying compliance was not being strictly enforced. Every response was aimed at the people rather than at the control. Meanwhile an operator testified to what compliance actually cost. Changing welding tips with lockout took three to four minutes. Without it, one to two. Several times a shift, against a quota the line rarely met. OSHA lists time pressure as a source of robot application hazards in its own right, so this is a documented mechanism rather than my inference. A safeguard whose cost is paid every cycle by the person it protects, and whose enforcement depends on that same person, is not an engineering control regardless of what the binder says.
What the record settled
The company pleaded guilty in 2020 to a wilful violation of the lockout standard and was sentenced to the statutory maximum fine of $500,000, a million dollars in restitution, and three years of probation under an externally audited compliance plan. The civil case ran longer. An administrative law judge affirmed most of the citations in February 2023 and assessed roughly $1.3 million, and the case was directed for full Commission review the following month, so that decision is not final. Not everything alleged survived. The claim that the company had failed to issue locks was vacated for insufficient evidence, and the guarding citations sometimes reported alongside this incident concerned press welders elsewhere in the plant.
None of which changes the engineering, and the case is easy to file under negligence and leave there. Negligence is the least useful reading available. A company with no procedure and no interlock would tell us nothing. A company that had both, connected only by a person's decision, tells us something specific about what supervision requires.
Ajin did not lack a rule. It did not lack a mechanism capable of enforcing that rule. What it lacked was a system in which entering the hazard necessarily invoked the mechanism.
Two supervisors were in that cell. One was standing a foot and a half away when the arm moved. Being present turned out to be a different thing from being answerable.
Sources
Secretary of Labor v. Joon, LLC d/b/a Ajin USA, OSHRC Docket No. 17-0053, Decision and Order (February 2023), directed for Commission review 23 March 2023
U.S. Department of Justice, "Auto-Parts Manufacturing Company Sentenced in Worker Death Case," 9 November 2020
U.S. Department of Labor / OSHA news releases, 14 December 2016 and 8 March 2023
OSHA Technical Manual, Section IV, Chapter 4, Industrial Robots and Robot System Safety
ISO 10218-1:2025 and ISO 10218-2:2025, Robotics — Safety requirements
ANSI/A3 R15.06-2025, Industrial Robots and Robot Systems — Safety Requirements