← Journal
EN 30 August 2026 · 8 min

BAYON — governing humanoid robots before they govern our elders

"IF plate.temperature > 40°C THEN require human validation." How a business-rules governance engine turns a humanoid into a declared, auditable, trustworthy agent in the room of an 87-year-old. An editorial note.


IF plate.temperature > 40 THEN require human validation.

This is not a line of code. It is a governance rule — and it decides what a humanoid robot is allowed to do in the kitchen of an 87-year-old person.

The gap nobody is filling

Humanoids are coming. OLI, LUNA, and an entire generation of platforms that can walk, grasp, climb stairs. What is not coming with them is the frame: none of these platforms capitalises human arbitrations, none is natively compliant with the EU AI Act and ISO 13482.

The vendor ships locomotion. Nobody ships governance — the thing that separates a technical demonstration from a service you can, in good conscience, install in the home of a frail person.

That is the missing link we are building: BAYON, a business-rules governance engine — an agentic MDM — that sits above the robot’s operating system. Our thesis fits in one sentence: govern humanoid robots before they govern our elders.

A rule is data, not code

BAYON’s founding principle is policy-as-data: every rule exists in two forms. A text a caregiver can read — “if the bag weighs more than 3 kg, refuse” — and its canonical, machine-executable form, hashed for audit and deduplicated.

The consequence runs deep: governance becomes consultable. By the operator, by the family caregiver, by the senior themselves or their legal representative. A rule you cannot read is a rule you cannot contest — and a robot whose policy is not readable does not start.

Three autonomy classes

Every declared task belongs to one of three classes:

  • AUTO — the robot acts alone. Reserved for the home environment: housekeeping, laundry, receiving groceries, preparing simple meals.
  • RECO — the robot proposes, the human decides.
  • OBLIG — a human validates, with a cryptographic signature. Everything that touches the person: getting up, washing, taking meals, accompaniment.

Governance card — what the robot does alone (AUTO class), LimX Oli platform

Governance card — what touches the person (human validation), LimX Luna platform

Applied to the eight services of the French home-care scheme (SAD), the same grid yields the summary card below: for each service, the competent robot — OLI for manipulation, LUNA for interaction — and its governance class.

Summary card — the 8 home-care (SAD) services mapped to OLI, LUNA and their BAYON governance class

The boundary is not technical, it is ethical: three categories are never delegated to the robot alone — the person’s safety, threshold crossings, conversations with medical implications.

The golden rule: governance is never in the real-time loop

One objection always comes up: “what if the governance server goes down while the robot is catching a fall?” It rests on a confusion our architecture rules out.

BAYON never intervenes below 10 milliseconds. Reflex safety stays in the robot — “closer than 30 cm to a human and faster than 0.3 m/s: stop” — as preloaded interlocks, signed, executed locally. BAYON operates in the cognitive loop (100 ms to 10 s) and asynchronously for governance. The robot never waits for a server to avoid an accident.

Every intervention is an episode

When the robot acts, it opens an episode: which robot, which task, on whose order, with which validation, with what outcome. Every episode is logged and hash-chained — tampering with an entry breaks the chain, and therefore shows.

And this is where GDPR meets audit: the senior’s personal data remains erasable — right to be forgotten — without breaking the audit chain, of which only the hashes are kept. Anonymisation is native: no nominative data in the robot database.

This is what makes a fleet accountable: in a control or an incident, the question “what happened?” has a verifiable answer.

The system learns — under human control

A repeated human arbitration is not lost: it becomes a candidate rule, submitted to human validation, then redeployed as an interlock. Today’s caregiver decisions become tomorrow’s robot prudence.

It is the same capitalisation mechanic our AGE applies to engineering: what is validated in production becomes a reusable asset — and the nth deployment costs a fraction of the first.

The ethical frame, translated into interlocks

Four commitments structure the system, not as an annex but as executable rules:

  1. Radical transparency — the log is consultable at any time by the senior or their representative; the robot announces any sensitive proposal out loud.
  2. Revocable opt-in — task-by-task granular consent, revocable by voice.
  3. The right to immediate shutdown — a physical emergency stop button and the voice command “Stop”; no restart without explicit human action.
  4. Human-in-the-loop governance — the three sensitive categories are never delegated to the robot alone.

January 2027

Our pilot starts in January 2027: two LimX Dynamics humanoids — OLI and LUNA — in our Paris RaaS lab, 16 declared assistance tasks, 4 demonstration scenarios, 2 volunteer seniors.

When governance applies to an object that moves around a room, it stops being a legal abstraction.

We are looking for a home-care or care-home partner (SAAD/EHPAD) to host the pilot, and health/impact investors for our seed round — get in touch or write directly to richard.yi@medicalcity.ai. For the business model behind this fleet, see our RaaS offering.

  • BAYON
  • Robotics
  • Governance
  • AI Act
  • RaaS