Architectures/Model · typed tools · deterministic HMI
Public reference architecture

Governed AI Cockpit

Natural conversation with deterministic automotive authority.

A model proposes a bounded plan; the orchestrator owns credentials; policy decides; the native app renders typed state that generated wording cannot advance.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
APP-04 / device

Invocation and local fallback

OwnsCapture state and allowlisted local intents

Must not inferWake or transcript cannot invoke a tool

02
Isolated model gateway

Model proposal

OwnsSchema-bound language proposal only

Must not inferNo credentials, entitlement or state authority

03
SAAS-09

Orchestration and policy

OwnsTyped tools, credentials, risk, moving policy and result validation

Must not inferCannot claim downstream vehicle/partner completion

04
AAOS / IVI / projections

Deterministic HMI

OwnsConversation phase, exact confirmation and sourced cards

Must not inferGenerated text cannot advance lifecycle

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Invoke

    Start approved capture with visible/audible state and interruption.

    method · capture policy · session
  2. 02

    Propose

    Return a schema-valid plan with no direct tool access.

    prompt/model route · output schema · plan revision
  3. 03

    Decide

    Resolve tool registry, entitlement, occupant, moving state, risk and freshness.

    tool/policy revisions · decision
  4. 04

    Confirm

    Bind protected target, consequence, evidence, expiry and exact revisions.

    method · turn/plan/context/policy · idempotency
  5. 05

    Present

    Render typed terminal or uncertain result with source-bearing cards.

    operation state · result source · trace/evaluator

Interfaces that a production program must own.

01

Session context

Occupant, surface, moving state, capabilities and versions.

02

Typed plan

Model isolation, operations, risk, permission and policy.

03

Confirmation

Target, consequence, evidence, expiry and revision binding.

04

Trace/evaluation

Redacted context, tool/result, latency and release evidence.

Failure states stay truthful and useful.

Cloud/model unavailable

Use exact signed local grammar for supported intents or show unavailable.

Stale vehicle context

Block protected confirmation and require refreshed evidence.

Prohibited moving request

Reject before tool invocation and avoid attackable policy detail.

Downstream acknowledgement missing

Expose uncertain/not-dispatched; never narrate success.

Privilege follows the narrowest useful boundary.

  • Model gateway isolated from tool and vehicle credentials
  • Generated text validated before presentation/read-aloud
  • Microphone, transcript and personalization purpose controls
  • Replay-resistant confirmation and vehicle IPC adapters
  • Prompt/tool injection and owner-manual poisoning release cases

A green demo is not a production acceptance case.

  • 01No-direct-tool-access and registry tamper tests
  • 02Noisy cabin, language, false invocation and interruption
  • 03Moving HMI, source cards and confirmation expiry
  • 04Injection/red-team and privacy/retention evidence
  • 05Target vehicle adapter, uncertain outcome and rollback validation

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the Governed AI Cockpit reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.