> ## Content Index
> Fetch the complete content index at: https://gridsignals.de/llms.txt
> Use this file to discover other available public pages before exploring further.

# Designing the Stop Button
- URL: https://gridsignals.de/designing-the-stop-button/
- Published: 2026-08-28T06:15:07.000Z
- Updated: 2026-08-28T06:26:12.000Z
- Description: The AI Act asks for human oversight where automation can affect physical systems faster than operators can assess individual actions. Every industry that hit this wall solved it with architecture, not vigilance. The grid can too — and it has already built much of the foundation.
- Author: Sascha Janssen

*Grid Signal — Issue #011 · August 2026*

---

**50.2**

Fifty point two. A frequency threshold written into Germany’s low-voltage connection rules back when rooftop solar was a rounding error: if the grid hits 50.2 Hz, disconnect. Locally sensible. Individually approved — hundreds of thousands of times.

By the summer of 2011, more than 12 GW of PV sat behind versions of that same tripwire. One overfrequency event could have dropped much of it at once. No device was wrong. The fleet was.

Two details of that story carry everything below.

First: nobody could have caught it live. By the time 50.2 appeared on a control-room screen, the fleet would already have acted — that was the setting. It was caught the only way it could be caught: at study speed, on paper, before it ever fired.

Second: the fix wasn’t a faster operator. It was a portfolio-level design change. New systems reduced active power progressively as frequency rose. Existing systems were retrofitted so they no longer disconnected together at one shared threshold — more than 300,000 installations, through an ordinance and a multi-year programme.

The risk lived in a rule. The catch happened *before*. The fix was architecture. Hold that pattern — it’s what oversight looks like when the thing you’re overseeing is faster than you are.

**The ladder**

Grid control is a ladder of nested loops, and the rungs are orders of magnitude apart:

- **Protection and inverter inner controls — cycles to hundreds of milliseconds.** Current control, protection and the fastest stability functions act before a control-room signal could make the round trip. Deterministic and local, for a reason.
- **Grid-forming control and fast frequency response — sub-second to seconds.** As inverters displace spinning steel, parts of this rung are being rebuilt in firmware. The technologies and services differ, but both operate below the timescale of individual human approval.
- **Volt-var / volt-watt curves — seconds, by design.** The loops from Issue #010\. A device follows its pre-set curve from local voltage — no signal from anyone. The response is deliberately damped so that thousands of inverters don’t chase each other into oscillation. Its pace was chosen by engineering and certification years earlier, not by an operator in the moment.
- **Frequency containment reserve (FCR)— up to 30 seconds.** Automatic, synchronous-area-wide, fully activated within half a minute.
- **Supervisory operation — seconds to minutes (aFRR/mFRR).** Perceive, interpret, decide, act. Humans can change the operating mode, withdraw authority and reverse a durable command. They cannot approve every switching edge or inverter response.
- **Minute reserve, redispatch, §14a control — minutes to hours.** The horizons where people, forecasts and optimisation increasingly overlap.

Each fast rung buys time for the slower, more contextual one above it. Fast response arrests the excursion so reserves can catch it. Reserves hold the system so dispatchers can think.

The grid never removed the human. It built a cascade beneath her, one rung at a time, as physics demanded responses faster than biology delivers.

But notice the line in the middle of the ladder. Below it, no human decision fits inside every response window. Real-time approval down there isn’t a policy choice anyone rejected — it is physically unavailable. Oversight still exists *during* operation, but at a different level: the human supervises the authority, health and operating state of the automation, not each individual actuation.

That distinction matters. Human-in-every-loop is impossible. Human-on-the-loop is architecture.

**Where the AI actually sits**

Now be precise about what the AI Act regulates here, because this is where sloppy versions of the argument fall apart.

A volt-watt curve is not AI. Neither was the 50.2 Hz threshold. The ladder’s fast rungs are predominantly deterministic controls: fixed rules, certified per device type, same relevant input, same prescribed response. The AI Act has nothing to say about the curve itself.

The Act can attach one layer up: to an AI system intended to serve as a safety component in the management and operation of electricity supply. Depending on its intended purpose and operational role, that might include a VPP optimizer allocating flexibility across thousands of assets, a forecast feeding safety-relevant redispatch, or a dispatch engine selecting resources to curtail. Not every forecast or market optimizer is automatically high-risk. The classification follows the use case, not the label on the model.

That layer sends schedules, setpoints or policies into the deterministic rungs. The timescales remain different: a dispatch may be calculated over minutes while the physical response begins in seconds. The AI does not become inverter firmware merely because its output reaches an inverter. But once released, its command can start changing the physical system before a human has assessed that individual action.

The 50.2 story shows what fleet-scale automation risk looks like even when the rule is simple enough to print. One number, in a public rulebook — and it still took a commissioned study to see the systemic bet. Replace that printed number with interacting optimizers, changing topology and remotely updated policies across a fleet, and the case for oversight gets stronger, not weaker. The question is only *where that oversight can be effective*.

**Article 14, read as a requirements document**

Article 14 of the EU AI Act says high-risk systems must be “effectively overseen by natural persons.” It lists what the overseer must be able to do: monitor operation, interpret output, disregard or reverse it, intervene, or halt the system “through a ‘stop’ button or a similar procedure” that brings it to a safe state.

Read as a requirement for per-decision approval, against the ladder, the verbs strain. Legal scholarship hasn’t settled every boundary of real-time intervention. And the timeline reflects the wider implementation difficulty: the Digital Omnibus of July 2026 moved the application date for Annex III high-risk systems to 2 December 2027, citing delayed standards, common specifications, guidance and institutional readiness.

But read as an architect, Article 14 contains the beginning of an answer. Article 14(3) allows oversight measures to be identified and, where technically feasible, built into the system before it is placed on the market or put into service.

That does not move the human out of operation. Article 14(1) still requires oversight during use; Article 14(4) still gives the overseer powers to monitor, override, reverse and stop. What changes is the object of supervision. The human cannot veto every action. She can supervise the automation’s authority and state, withdraw that authority and move the system to a safe mode.

No regulator has blessed this architecture as the grid’s Article 14 answer. It is an engineering interpretation, not settled doctrine. But it is the interpretation the text invites: oversight that is *effective*, proportionate to risk and autonomy, and designed so a natural person can still act.

For anyone who builds systems for a living, that’s not a loophole. That’s the assignment.

**Envelope before, authority during, record after**

- **Aviation.** Some flight-control systems enforce a flight envelope faster than a pilot could calculate the correction. The crew supervises and can change modes; the recorder preserves the evidence.
- **Nuclear.** Protection systems trip a reactor faster than operators can move. Operators retain supervisory authority, and safety-significant events are recorded.
- **Finance.** Regulators answered rapid electronic trading with pre-set thresholds, kill functions and circuit breakers. Controls before, supervision during, audit trails after.
- **Process industries.** Safety functions get an integrity level, proven in advance and re-proven in periodic tests. Nobody validates an individual protective trip in real time.

Four domains. None depends on a person approving each fast protective action. The common pattern is stronger than that: an envelope someone approved before, human authority over the operating mode during, and a record someone can judge after.

Nobody in aviation or nuclear calls that the absence of human oversight. It *is* human oversight — engineered for the timescale the machine operates on. That’s the pattern Article 14 is waiting to receive.

**The reference architecture**

In my day job this pattern has a familiar shape: policy, control and execution. Nobody supervises an individual autoscaling decision. Humans approve the policy, guardrails bound it, operators watch fleet health and can withdraw it, and every action writes to a log.

A scale-out no one approved individually isn’t a governance failure. An unbounded, unobservable or unlogged one is.

Translate that to AI on the grid and you get four components. The grid has built important parts of each — but not yet a complete chain for model-driven fleet control.

**1\. The envelope — exists locally; incomplete systemically.** Certified curves, protection settings and connection limits already constrain devices. They are the first line of defence, and they matter precisely because they do not depend on the optimizer being right.

But a thousand individually compliant commands can still overload a transformer, synchronize a rebound or violate a constraint elsewhere. A device certificate is not a feeder study. Local protection is not a fleet safety case.

The missing extension is an independent system-level policy gate between optimizer and execution. It checks topology, network limits, ramp rates, command concentration, asset availability and the optimizer’s authority. The AI proposes; the gate disposes — because it is simpler, deterministic and independently testable.

**2\. The supervisor and fallback — the honest stop button.** At machine timescale, “stop” cannot mean intercepting every completed actuation. It means taking the policy out of service: revoke the optimizer’s authority, block new commands and move the fleet to a defined, conservative operating mode.

The grid knows versions of this move. For certain new German PV installations, feed-in is temporarily limited to 60% at the connection point until the required intelligent metering and control path has passed its test. Not a universal Redispatch fallback, but a useful precedent: richer control authority is withheld until the smarter path is proven.

For AI-controlled fleets, safe mode might hold the last validated schedule, return assets to local control, apply fixed limits or hand dispatch back to an operator. It has to be defined, tested under communications failure and rehearsed.

An automated fallback alone is not human oversight. It counts because named people understand it, can invoke it, reverse durable outputs and decide whether the optimizer returns. The interface, alerts, authority model and runbook are part of the stop button. Without them, the fallback is only redundancy.

**3\. The registry — a fragmented foundation, one layer short.** Certificates, parameter assignments and asset inventories preserve pieces of who approved deterministic behaviour. But they rarely give one signed, current answer to a simple question: which exact behaviour was active on this asset at this moment?

The AI layer needs a versioned registry of which model, feature pipeline, constraint set and policy were authorised for which assets — by whom, when, for what scope. A repository artefact is not enough. The registry must describe what was actually in command.

This is where Article 14’s natural person becomes visible. Not only watching a dashboard. Signing an authority boundary. The oversight decision becomes an artefact you can point to.

**4\. The record — the largest missing piece.** Per decision: the inputs, grid-state and topology snapshot, model and feature versions, admitting constraint policy, resulting command, acknowledgement and outcome. Signed, tamper-evident and replayable enough to reconstruct execution. The flight recorder for dispatch.

The grid isn’t starting from zero. SCADA historians and sequence-of-events recorders reconstruct much of what the observed grid did in control centres and substations. Coverage thins toward the low-voltage edge. Even where recording is strong, it cannot say which model saw which inputs, which gate admitted the command and why that version held authority.

Event recording exists. Decision provenance largely doesn’t.

An input-output log does not reveal intent or magically explain a neural network. But it can reconstruct the decision path: available information, authorised transformations, applied constraints and the command that left. That is the “why” an investigation can test.

The AI Act already requires logging. The system must enable it; providers and deployers retain logs under their control for at least six months, unless other law says otherwise. Useful — but largely written for product monitoring and supervision. Grid incidents and disputes follow their own retention horizons. Build to the stronger sector need, and minimum compliance follows.

Now map Article 14’s verbs onto the architecture:

- *monitor* → live fleet telemetry, health indicators and actionable alerts, supported by the record
- *understand, interpret* → operating limits, decision context and the registry of what is actually in command
- *disregard, override, reverse* → the policy gate and supervisory control path
- *intervene, stop* → tested withdrawal of authority and transition to a defined safe mode
- *decide not to use* → staged autonomy: shadow mode, then advisory, then bounded control — the same canary pattern mature platform teams use to earn trust in automation

None of the building blocks is speculative research. Combining them across legacy fleets, vendors, long asset lives and regulated responsibilities is still hard systems engineering. But it is an integration problem with known ingredients — not a reason to wait for new control theory.

**The clock is the opportunity**

The deadline moved to December 2027 because the implementation machinery wasn’t ready. The public CEN-CENELEC programme covers horizontal work on risk management, trustworthiness, quality management, logging, robustness and conformity assessment. What it does not yet provide is the grid-specific worked example: effective oversight for an AI system whose commands reach embedded control and physical assets faster than a human can assess each action.

Meanwhile, inverter, heat-pump controller and utility platform design cycles can run longer than the sixteen months just added.

Read defensively, that’s a gap. Read like the SA in the room: the requirements are knowable now, the architecture is assembled from proven patterns, and nothing prevents building and testing the four components before anyone is forced to.

Whoever ships a credible reference implementation first gets to shape the worked example the industry, auditors and eventual standards reach for. Someone will turn Article 14 into a grid architecture. There’s no reason to wait for another industry to do it first.

**Same system, different rulebooks**

One cross-check that this is architecture, not EU-compliance trivia.

Switzerland — inside the same synchronous grid, using the same classes of controls — has chosen no broad horizontal AI act for now. It plans targeted amendments, sector-specific where possible, to implement the Council of Europe’s AI Convention. Oversight lands more directly in sector law, grid codes and supervision.

The UAE has a third model: charter principles rather than one comprehensive statute, and since June 2026 a federal Artificial Intelligence and Data Authority. It does not mandate a dispatch recorder today, but it creates a central place from which requirements can be shaped. On a greenfield grid, the record can enter the first tender rather than the twentieth firmware release.

Three governance models: horizontal statute, sector-focused implementation, central authority. The same four-component architecture travels across all three because it answers the operational question beneath the rulebook: who authorised the automation, what bounded it, who could withdraw it, and what evidence remains?

That is the definition of an architecture worth building.

**Build the record**

The 50.2 Hz problem sat still — one number, printed in a rulebook — and it still took a commissioned study to catch, an ordinance to change and years to retrofit. The next fleet-scale surprise won’t sit still. It will be an interaction between optimizers, topology, curves and control signals, tuned per connection and updated remotely — reconstructable only from records of what each layer saw and did. If those records exist.

Human oversight at machine timescale was never going to be a person approving every action on a dashboard. It is a person governing the authority before, supervising the operating mode during and judging the evidence after. An envelope that limits what automation may do. A fallback that returns it to a safe state. A registry that says what was in command. A record that shows what happened.

The grid already has strong device-level envelopes, familiar fallback patterns, fragments of the registry and decades of event recording. What it lacks is the continuous chain across the model, the system-level policy gate and the physical action. The record is what makes that chain inspectable. It turns “the optimizer did it” from an excuse into a testable statement.

Build the record.

And a record is only as trustworthy as the identity of the device that signs it. Which is a problem, because the heat pump in your basement has no signing key and no way to get one. That’s Issue #012.

---

**Sources**

- EU AI Act, consolidated Regulation (EU) 2024/1689 — Art. 14 (human oversight); Arts. 12, 19(1), 26(6) (logging and retention) — [EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02024R1689-20240712&ref=gridsignals.de)
- Regulation (EU) 2026/1744 (Digital Omnibus), OJ 24 July 2026 — Annex III high-risk application moved to 2 Dec 2027 — [EUR-Lex](https://data.europa.eu/eli/reg/2026/1744/oj?ref=gridsignals.de)
- European Commission — high-risk AI classification guidance and implementation timeline — Digital Strategy
- Melanie Fink, “Human Oversight under Article 14 of the EU AI Act” (2025) — the unsettled real-time-intervention question
- BDEW — 50.2 Hz problem, SysStabV and retrofit of more than 300,000 PV installations — BDEW
- Federal Ministry for Economic Affairs — system security and the 50.2 Hz problem — BMWE
- NREL — grid-forming inverter controls; IEEE 1547-2018 volt-var/volt-watt settings and response times — [NREL](https://docs.nrel.gov/docs/fy24osti/88609.pdf?ref=gridsignals.de)
- VDE-AR-N 4105/4110; FNN reactive-power guidance; BSI TR-03109; §14a EnWG; §9 EEG — technical connection, control and fallback patterns carried from #010 research
- Clearingstelle EEG|KWKG — technical requirements under §9 EEG — Clearingstelle
- SEC Rule 15c3-5 adopting release; ICAO Annex 6; IEC 61508/61511 — pre-set controls, recording and safety lifecycle precedents
- IEEE C37.118 — synchrophasors; SCADA historians and sequence-of-events recording — existing operational evidence infrastructure
- CEN-CENELEC JTC 21 — public AI standardisation programme — CEN-CENELEC
- Switzerland: Federal Council decision, 12 Feb 2025 — sector-focused implementation of the Council of Europe AI Convention; consultation draft due end-2026 — [admin.ch](https://www.admin.ch/en/nsb?id=104110&ref=gridsignals.de)
- UAE: establishment of the federal Artificial Intelligence and Data Authority, 14 June 2026 — Emirates News Agency
- Talal Ashraf Butt, Muhammad Iqbal and Razi Iqbal, “Governing What the EU AI Act Excludes” (May 2026) — accountability architecture for interacting critical-infrastructure AI — [arXiv](https://arxiv.org/abs/2605.01091?ref=gridsignals.de)

---

*Grid Signal is written from the perspective of a cloud solutions architect working with the energy industry. It reflects engineering interpretations of public regulations rather than legal advice. Opinions are my own.*