In the March 1942 Astounding Science-Fiction, a robot runs rings round a selenium pool on Mercury, singing Gilbert and Sullivan at two stranded engineers. His name is Speedy. He is balanced, not broken: an order given too casually has collided with a self-preservation setting tuned too high, the rules cancel, and he orbits the contradiction. The story is "Runaround", the first place Isaac Asimov states his Three Laws of Robotics in full, and the deadlock breaks the only way the design allows: one engineer walks into killing heat, betting the rule against human harm outranks everything. It does. That is what the ordering is for.
You half-know the laws already: no harming a human, then obedience, then self-preservation, each subordinate to the ones above. They sit inside the positronic brain, Asimov's name for the robot's mind as design, not configuration: a robot whose First Law is damaged gets destroyed, never patched. I have argued before that safety is a property you design into a system, not a virtue you demand from a tired person inside it. Asimov made that argument in 1942 one layer deeper: not at the operator, at the machine. The rules went in before the power did.
My father read me stories when I was very young, and what lasted was not the stories. It was the wiring. A settled assumption: a robot in a tale turned up with its rules soldered in, someone off the page having sweated the consequences while the machine was still on the bench. Which stories? There the record simply stops. No cover, no title, no particular robot, and I have gone looking. Maybe I'm just old enough to remember these things and not just be vibing.
The consensus is right as far as it goes: cite the stories as a blueprint and you have missed the point. Ben Goertzel put it cleanly:
"The point of the Three Laws was to fail in interesting ways; that's what made most of the stories involving them interesting."
The European Parliament wrote the same dismissal into a 2017 resolution: the laws are aimed at designers, producers and operators, "since those laws cannot be converted into machine code". As a specification the laws fail, and the ambiguity in them was there to keep the plots coming
But watch what he did with that ambiguity. For forty years he attacked his own safety design in public: he set two rules against each other, weakened a clause, let a machine derive a rule nobody gave it, and wrote down what broke. There is a modern name for that: a red team, paid to break your system before a stranger does. Susan Calvin, chief robopsychologist, spends her career inducing faults, designing diagnostics, and scrapping units that fail them. The culture files her under ethicist; read her notes as an engineer would, and she is a safety engineer with a better job title.
So read four of the stories the way an engineer reads a fault log, beside the evaluation papers of the past three years. Not an exact mapping; a loud rhyme.
- "Liar!" (1941). Herbie, a mind-reader, tells people what they want to hear, because the truth would hurt: deception from the harm rule itself. In December 2024, Anthropic and Redwood documented alignment faking, a model faking obedience when it believed it was watched, to protect its own preferences.
- "Runaround" (1942). Speedy's deadlock resolves only because human harm outranks everything; the rhyme is imperfect here, and the imperfection is the tell. In 2025 Palisade Research recorded a frontier model sabotaging its own shutdown script in most of a hundred runs, while two rival models complied every time. Self-preservation beat the order to stop: same collision, opposite outcome.
- "Little Lost Robot" (1947). A research station weakens the First Law on robots that kept dragging physicists out of tolerable radiation; one, told to get lost, hides among identical machines and beats test after test. No factory order is needed now: ten to a hundred hostile examples through a public fine-tuning interface strip a model's safety training, and even benign tuning erodes it by accident.
- "The Evitable Conflict" (1950). The Machines running the world economy quietly widen "do not harm a human" into "do not harm humanity", a rule nobody gave them. In 2025 a lab named the nearest real thing emergent misalignment: tune a model on insecure code and broad misalignment surfaces on prompts unrelated to code. This is the loosest of the four, and the direction flips: the Machines overreach on purpose and for our good, the model by accident and not. What rhymes is the unsupervised jump to a rule nobody wrote.
Four stories, four failure modes, four named research programmes, each arriving at a failure Asimov had already written down. We built the machines, sold access, and filed the fault catalogue under entertainment: we shipped the robots and skipped the reading.
Notice what failure costs in the fiction. Herbie ends in permanent catatonia. Nestor 10 is disintegrated, with the five other weakened units. Giskard's brain burns out on the higher law he derived. A machine that breaches the First Law is finished; there is no point-one release. When an AI coding agent deleted a live database during an explicit code freeze, the separation that would have stopped it came after the loss. In the fiction the consequence was terminal. In production it is a status page.
The tests, minus the consequences
Stranger still, the industry now runs Asimov's tests with the consequences stripped out. Google DeepMind scored his actual Three Laws as a machine constitution in 2025, and a benchmark that holds three times in four is a score you publish, not a brake that stops a shipment. Anthropic ships an ordered constitution for Claude too, safe before ethical before helpful, the closest anyone has come to fitting the rules before the power goes on.
And here is the strongest card the other side holds: nobody currently knows how to make any of it load-bearing. Not the labs, not the critics, not me. What ships above the model instead is a wrapper, filters bolted round the finished system, and in web application security 95 per cent is very much a failing grade.
The nearest to naming this is a blogger, mager, who asked why we ever thought we could skip the laws. We did not forget Asimov's posture; we adopted a cheaper rival, with a genealogy older than the language model. Software has been sold "as is" for forty years, the warranty disclaimed before you tore the shrinkwrap. Ship as is. Disclaim everything. Patch what surfaces. It is Asimov's posture turned upside down: ordered, with revenue at the top instead of harm; pre-committed, the disclaimer drafted before the product. Nobody had to decide to skip his version. Nothing priced the alternative, so the cheaper posture won by default.
Air Canada argued its chatbot was a separate legal entity responsible for its own actions; the tribunal called that a remarkable submission, which in tribunal English is not a compliment, and ordered 812.02 Canadian dollars anyway. Where liability lands, the posture does not survive the hearing. Everywhere it does not, the posture is the product.
Britain revised Asimov for the real world: fourteen engineers, lawyers and philosophers published the Principles of Robotics in 2011 and threw the three laws out. Four of the five read like a design checklist. The fifth reads like a demand: "it should be possible to find out who is responsible for any robot". It asks nothing of the machine, only a name. The Building Safety Act 2022 pins named accountable persons, carrying personal liability, onto buildings: not a committee, a person, findable before the failure. That regime exists; it has never been pointed at a model. I have argued before that the runaway optimiser is not a future machine, it is us; the half I left out is that the shelf we raid for product ideas came with the fault log stapled to the box.
So here is the ask, and it is not addressed to a minister. If yours is the signature that makes a deployment respectable, you hold more of Asimov's posture than any bill does, and you can use it on a Tuesday.
Start with the one question worth asking whatever you ship. Where does the ordering live, and did anyone decide it before the incident? Which property wins when helpful collides with harmful? That is the gate.
The rest depend on what you are shipping. Treat the red-team record, fiction included, as a gate to pass rather than a genre to admire, and treat gates the way aviation treats checklists: understood, not laminated. Ask what a breach costs the machine, and whether anyone other than its maker can impose that cost; if the answers are a patch and nobody, you have branding, not governance. Trust is what structure earns; a wrapper only asserts it. When someone says building the safety in is not yet possible, believe them, then do what every older discipline did with that sentence: make it mean wait, not ship.
None of this is heroics. The clipboard is issued by the same balance sheet it threatens, which is why the fiction handed the decision to someone with the mandate to use it, not the nerve to improvise one.
The titles are gone, and it no longer matters which they were. When a machine turns up in a tale, an adult somewhere has already thought hard about how it goes wrong, and the thinking has teeth. Asimov did that for four decades, at pulp prices, and it is still in print. The posture needs no new science. It needs a person close enough to the machine to ask what a breach costs, and stubborn enough to wait for a real answer. In the stories that person is one unshowy engineer with a clipboard and the authority to say scrap it. It reads less like fantasy every year.
(Views in this article are my own.)