The review says existing safeguards reduce language-model errors but do not provide the bounded, verifiable behavior required by major safety standards.
A review of language models and safety certification finds a structural mismatch between the two. Certification regimes require behavior that can be bounded, traced and supported by evidence, while language models retain a nonzero error floor and can produce plausible but incorrect outputs.
The authors argue that common safeguards—including retrieval tools, guardrails, formal checks, uncertainty estimates and hybrid systems—can reduce risks but do not eliminate the gap. They identify two possible paths: set statistical acceptance criteria for narrowly bounded tasks, or place the language model in an untrusted proposer role inside a deterministic, independently verifiable control system.
What the review found
The review identifies a structural mismatch between large language models and certification regimes used in areas such as aviation, road vehicles, medicine and critical infrastructure. Standards including IEC 61508, DO-178C and ISO 26262 require system-level risk targets, traceability, controlled configurations and evidence of bounded behavior.
The authors report three main findings. First, under stated conditions, mathematical results imply a nonzero error floor for calibrated probabilistic generators. Second, benchmark results for legal, medical and agentic tasks cannot be directly converted into certification targets, and the reviewed deployments do not provide the hazard and exposure models needed for a compliance demonstration. Third, retrieval augmentation, guardrails, formal verification, uncertainty quantification and neurosymbolic hybrids are documented to narrow the gap but not close it.
The review also formalizes how errors can compound over an execution horizon. It identifies two possible ways forward: standards could define statistical acceptance criteria for bounded tasks, or system designers could confine the language model to an untrusted proposer role within a deterministic, independently verifiable execution envelope. On the evidence reviewed, the authors describe certifying that envelope rather than the model as the most defensible current approach.
// Source
American Impact Review · 2026 · DOI: 10.66308/air.e2026066
Authors: Akbar Sayakov
Institutions: American Institute of Architects