A Closed-Loop Measurement Study of Runtime Governance in AI-Driven Smart Building Climate Control
Norkobil Saydirasulov Saydirasulovich, Dilmurod Abdujalilovich Davronbekov, Makhmudov Makhsum Mubashirovich, Young Im ChoWhich runtime governance mechanisms reduce physical risk when a learned controller drives a building’s climate, and under what conditions? We develop a closed-loop software-in-the-loop testbed in which a setpoint model trained on real occupancy data drives a physics-based thermal zone through a declarative governance plane, with outcomes scored by an independent safety oracle, and we run the same governance logic on a real MQTT stack with an in-process policy decision point and a hash-chained audit log. Under distribution shift, admission control reduces unsafe physical exposure by 19.4%, from 1185.3 to 954.8 °C·min, whereas adding checkpoint rollback reduces it by only a further 0.2% in the reference run (0.1–0.4% across sensor noise seeds): the governance decision takes 0.44 ms while physical recovery takes a median of 61 min. Prevention therefore outperforms recovery in the studied thermal system, and the remaining avoidable exposure is driven by the policy’s estimate of occupancy context. A deterministic single-rule thermostat incurs 50% more exposure under shift while the learned controller uses a 38% higher heating demand proxy: a safety–demand trade-off, not evidence that learned control is necessary. A plant sweep yields an operating envelope criterion for inertial plants: rollback contributes materially to safety only when the plant is restored before the next command arrives and sampled before it can leave the safe set; on slower plants it removes at most 14.7%, with a transition band in between. No physical hardware was operated.