Machine safety law protects the operator in part through instruments — the stop function, the emergency stop — whose operation presupposes that a human being can perceive a developing hazard, evaluate it, and act before harm occurs. That presupposition can be tested. It amounts to a comparison between the interval a hazard allows and the window that stopping it requires.
The available interval runs from the onset of a hazardous action to the point beyond which its effect can no longer be prevented. Against it stands the window human intervention requires. Where that window is longer than the interval available, a protective architecture whose last layer depends on human intervention provides no protection at all. The capacity to halt must instead reside in a mechanism whose own window fits the interval, and which does not share a failure path with what produced the hazard.
The comparison is established first from the mechanics of the hazard and the physiology of response, without reference to any legal system. European Union machinery law, Swiss product-safety law and United States occupational safety regulation are then shown already to require the result it produces, while none states the comparison itself. The same silence runs through the international standards on which those systems converge: the response time of a halting mechanism is standardised in detail, and so is the interval a hazard allows, while the window human intervention requires has never been consolidated as a reference value. The criterion of systemic arrestability names that comparison and puts it in a form that can be demonstrated for a particular configuration. It adds no obligation to existing law.
This version restates the argument in causal sequence. The comparison is derived first, without reference to any legal system; the European, Swiss and United States frameworks are then shown to impose its result. One interval and the windows that must fit inside it replace the earlier terminology. Independence is added as the condition under which a mechanism's response time is measurable at all. Where no admissible mechanism exists, the consequence is stated as a demonstration that cannot be produced, rather than left as an open question. The three negative clarifications of the earlier version are removed, as each follows from the steps. An illustrative example drawn from a close-in defensive system has been removed: the interval it described was that of the engagement sequence, not the interval this paper measures.
Supersedes Version 6.
operator safety · machine safety · stop function · emergency stop · human reaction time · legal effectiveness · systemic arrestability · Directive 2006/42/EC · Regulation (EU) 2023/1230 · LSPro RS 930.11 · OSHA 29 CFR § 1910.212
The temporal structure analysed in this paper is not unique to civil machine-safety law. For the parallel argument in the context of International Humanitarian Law and autonomous weapons systems, see: Lawful Operational Safeguards in AI Systems (Paper I, 2026). The convergence of the two analyses indicates that the effectiveness problem identified here is structural rather than regime-specific. A candidate machine-readable recognition protocol is specified in HF SIGNAL 01 (Paper III, 2026), and the temporal criterion is extended to the recognition of surrender in HFA Technical Note HFA-TN-02.