When the Interlock Had a Key That Made It Lie
On August 18, 2026, The Auto Wire published a piece with a headline most safety engineers will recognize as correct on the first read: a robot did not kill this Stellantis mechanic, a bypass key did. The underlying facts have been accumulating since April 7, 2025, when 63-year-old machine repairman Ronald Adams Sr. was crushed inside an industrial parts-washer cell at the Dundee Engine Complex in southeast Michigan. The wrongful-death suit his widow filed in Wayne County Circuit Court alleges the cell's safety interlock had been defeated with a special key. Sixteen months on, the MIOSHA fatality investigation opened the day he died is still listed as open. There is a machine-safety artifact that exists specifically to prevent this outcome, it has a clause number, and on the evidence in the public record nobody produced it.
This is not an automotive functional-safety story. There is no vehicle in it, no ASIL, no ISO 26262. It happened inside a manufacturing cell, which means the governing framework is machine safety: ISO 12100 for the risk assessment, ISO 14118 for prevention of unexpected start-up, ISO 14119 for interlocking devices associated with guards, ISO 10218-2 for the robot application, ISO 13849-1 for the performance level of the safety function, and 29 CFR 1910.147 for the American legal floor underneath all of it. Those are different standards with a shared premise, and the premise is the whole story: a person inside a machine's motion envelope is a state the machine has to know about and respect.
Below: the public record, the clauses that should have caught it, a worked defeat analysis and fault tree, and five derived requirements that any robot-cell integrator should be able to hand an auditor on demand.
1. The public record
April 7, 2025 — Dundee Engine Complex, Dundee, Michigan. Ronald Adams Sr., a machine repairman with 19 years at the plant, was performing maintenance on a large industrial chamber washer that cleans engine components. In the early morning hours, an overhead gantry activated without warning and crushed his upper torso. He was pronounced dead at hospital. The autopsy, obtained by the World Socialist Web Site through a FOIA request, records 18 of 24 ribs broken, a crushed sternum, spinal fractures, and roughly 20 percent of his blood volume in his lungs. Two coworkers had stepped away on break; one returned to find him pinned. (WSWS, April 6, 2026; WorkersCompensation.com, August 17, 2025.)
The alleged defeat. The suit filed by his widow, Shamenia Stewart-Adams, in Wayne County Circuit Court alleges the washer cell's safety interlock had been bypassed with a special key, defeating the work-safe mode that should have prevented the gantry from moving while a person was inside the cell. Adams's own attorney has stated there is no evidence Adams turned that key himself. (The Auto Wire, August 18, 2026.)
The precursor nobody actioned. According to the complaint, two days before the fatality a coworker reported that the same robotic system was moving unexpectedly while supposedly in a diagnostic dry-run mode. In machine-safety terms that is not a nuisance report. That is a witnessed unexpected start-up in a mode where operators are expected to be inside the safeguarded space, reported by an operator, forty-eight hours before the same mechanism killed someone.
The fleet-level condition. An independent rank-and-file investigation presented in Detroit on July 27, 2025 collected worker testimony that "cheater keys" — devices that trick a safety gate into registering as closed — were circulating in the plant. After the death, management ordered the keys returned and set out popcorn tins to collect them; one tin outside the union local office was reportedly half full. A former OSHA compliance officer who reviewed the findings characterized the plant as having virtually no functioning lockout/tagout system. Workers also reported that lockout placards were never updated after the gantry was physically relocated within the plant, so a worker could believe a machine was isolated when it was not. (WSWS, April 6, 2026.)
The evidence that may be gone. Fives Cinetic, which built, installed and programmed the washer and gantry, is a named defendant and has argued in filings that the accident would not have happened had Stellantis followed proper safe-work procedures. Per the same reporting, Fives Cinetic personnel — the only people positioned to pull the controller fault history and determine what signal actually commanded the gantry to move — were never contacted by Stellantis, the union, or MIOSHA, and the control boards holding that data have since been restarted.
The pattern around it. Seven months earlier, on the Jeep Gladiator line at Stellantis Toledo, 53-year-old Antonio Gaston was pulled under a chassis and killed after, per his family's suit, pinch-point guards were removed from a conveyor. Federal OSHA cited Stellantis in December 2024 under 29 CFR 1910.212 — the general machine-guarding standard, the most elementary rule in the book — with a proposed penalty of $16,131, later settled at $11,291.70 after contest. (WorkersCompensation.com, August 17, 2025; OSHA violation record 1770398.015.) On March 16, 2026, Gregory Knopf, a 64-year-old pipefitter at Ford's Sharonville Transmission Plant, was killed when a press activated during routine maintenance. Same operating mode, same class of failure, different company.
Where the investigation stands. MIOSHA opened inspection 1816147.015 at Dundee on April 7, 2025. Asked in April 2026 why it remained incomplete after a year, a MIOSHA spokesperson said the agency "must pursue additional legal or administrative steps to obtain information," which is regulator language for someone is not handing it over voluntarily. As of the August 2026 reporting, no findings, no citations. The plant is back to three shifts.
2. The standards lens
2.1 ISO 14118:2017 — the clause this fatality is named after
ISO 14118, Safety of machinery — Prevention of unexpected start-up, exists for exactly one scenario: a person is inside a machine's hazard zone during setting, maintenance, cleaning or fault-finding, and the machine starts. Clause 5 requires that energy supply be isolated and residual or stored energy dissipated before that person enters, and Clause 6 governs restart. The standard is explicit that measures relying purely on a control-system stop are not equivalent to isolation for maintenance tasks unless the stop function itself has been designed and validated to the required performance level.
The Dundee cell reportedly had a "work-safe mode" — a control-system state, not an isolation state. That distinction is the entire technical argument. A control-system mode can be commanded into or out of existence by whoever holds the right token. An isolated and dissipated energy supply cannot be, which is why ISO 14118 puts isolation at the top of its hierarchy and why 29 CFR 1910.147(c)(4) requires energy-control procedures rather than mode selection.
2.2 ISO 14119:2024 §7 — the defeat analysis that should exist and apparently does not
ISO 14119, Interlocking devices associated with guards — Principles for design and selection, Clause 7 is titled, in substance, measures to minimize defeat possibilities of interlocking devices in a reasonably foreseeable manner. It says two things that matter here.
First, the machine shall be designed so that it minimizes the motivation to defeat the interlock — the device must interfere as little as possible with legitimate activity during all life-cycle phases, maintenance included. Second, the design must include additional measures against defeat where defeat is reasonably foreseeable: coded actuators of high coding level, position and status monitoring, plausibility checks, mounting out of reach, and so on. The informative annex on defeat motivation is not a formality. It is a structured prompt to ask why would a competent person want this thing not to work today, and to design that answer out.
A "cheater key" is not an exotic attack. It is the canonical example the annex is written about. When a plant is being retooled to launch a new four-cylinder engine and a technician has to dry-run a gantry sequence to confirm the program, the legitimate work task and the interlock are in direct conflict — and if the safeguarded design does not provide a sanctioned way to do that task, someone will build an unsanctioned one. Circulating keys collected into popcorn tins is not a discipline problem discovered after the fact. It is the output of a Clause 7 analysis that was never run, made visible.
2.3 ISO 10218-2:2025 and ANSI/A3 R15.06-2025 — the mode that was supposed to exist
The 2025 revision of ISO 10218 splits robot safety between Part 1 (the robot, on the manufacturer) and Part 2 (the application and cell, on the integrator). Part 2 requires the integrator to define the safeguarded space, the span of control, and the permitted operating modes for the application, not just the arm. Manual reduced-speed mode caps tool-centre-point velocity at 250 mm/s — roughly 10 inches per second — precisely so a technician can be inside the space and still get out of the way. It is paired with a three-position enabling device and single-point-of-control requirements, because the whole safety case for a human inside the cell rests on that person holding the authority to move it.
OSHA's own robotics guidance in the Technical Manual splits the duty three ways — manufacturer, integrator, employing establishment. There is no tier in that split that owns a mechanism to strip the reduced-speed limit and keep full production speed available while someone is inside. That combination is not a sanctioned mode in any published framework. It is an unlisted mode, and unlisted modes have no risk assessment, no performance-level target, and no validation record behind them.
2.4 ISO 13849-1:2023 and ISO 11161:2007 — the numbers that were owed
For a guard interlock protecting against a crushing hazard from an overhead gantry, the required performance level lands at PL d with a Category 3 architecture at minimum, and for a hazard this severe with poor avoidance possibility many integrators would specify PL e / Cat 4. Category 3 means single-fault tolerance. A key that reports "guard closed" is not a fault the architecture is designed to tolerate — it is a defeat, which ISO 13849-2 handles through fault exclusion, and fault exclusions must be documented and justified. If the integrator excluded defeat of the guard-position signal, that exclusion is now falsified by field evidence.
ISO 11161, covering integrated manufacturing systems, adds the piece that the relocated-placard testimony implicates: when a subsystem is physically moved within an integrated system, the zone boundaries, span of control, and isolation points are part of the safety-related configuration and require re-validation. Moving a gantry and leaving the old lockout placards in place is a configuration-management failure with a body count.
2.5 The U.S. legal floor
29 CFR 1910.147 requires an energy-control program with machine-specific procedures, employee training, and periodic inspection. 29 CFR 1910.212 requires guarding of hazardous machine parts, full stop. ANSI/ASSP Z244.1-2016 (R2020) is the standard most integrators reach for when a task genuinely cannot be done under full lockout — it defines alternative methods with a documented risk assessment and control reliability, which is the sanctioned route the cheater key was substituting for.
3. A worked snippet: defeat analysis and fault tree
Here is what a Clause 7 defeat analysis for this cell should have looked like, filled in with what the public record now tells us.
3.1 Defeat-motivation analysis (ISO 14119 §7, informative annex method)
| ID | Life-cycle task | Why the interlock obstructs it | Foreseeable defeat method | Sanctioned alternative provided? | Additional measure required | |---|---|---|---|---|---| | DM-01 | Gantry program dry-run during retool | Cell must cycle with technician observing motion inside safeguarded space | Cheater key / coded actuator spare | No | Manual reduced-speed mode ≤250 mm/s + three-position enabling device, single point of control | | DM-02 | Washer nozzle / basket clearing | Guard must open repeatedly; full LOTO cycle costs minutes each time | Guard held open with actuator spare | No | Trapped-key isolation with guard-lock and controlled release, ISO 14119 §6 | | DM-03 | Fault-finding on gantry drive | Fault only reproduces with drive energized | Interlock bridged at terminal block | No | Z244.1 alternative-method procedure with documented risk assessment | | DM-04 | Cycle-time troubleshooting during launch | Reduced-speed mode too slow to reproduce timing defect | Key left in production-speed position | No | Time-limited mode with automatic reversion + supervisory logging | | DM-05 | Post-relocation commissioning | Isolation points changed; placards not updated | Worker locks the wrong point, believes cell is dead | No | ISO 11161 re-validation of zones and isolation points on physical change |
Five rows, zero sanctioned alternatives, one shared root: the design gave technicians no legitimate way to do legitimate work, so they built an illegitimate one and it circulated widely enough to fill a tin.
3.2 Fault tree — top event: unexpected gantry motion with person in cell
TOP: Gantry executes motion while person inside safeguarded space
|
OR
______________________|______________________
| | |
[G1] Guard-closed [G2] Motion command [G3] Person's presence
signal FALSE issued in a mode never detected by
(guard reports that permits full- any independent
closed while open) speed motion means
| | |
OR OR OR
___|________ ____|________ ____|________
| | | | | |
[B1] Coded [B2] [B3] Mode [B4] [B5] No area [B6] No
actuator Interlock selector Residual scanner / enabling
spare used bridged left in queued light device held
("cheater at production motion curtain by the
key") terminals speed from inside cell person in
aborted the cell
dry-run
^ ^ ^ ^ ^ ^
| | | | | |
ALLEGED plausible ALLEGED REPORTED absent per absent per
in suit per Clause in suit 2 days cell reduced-speed
7 analysis before description mode absence
Note the structure. G1, G2 and G3 are joined by OR, which means the top event needs only one of them. A cell designed to ISO 10218-2 and ISO 13849-1 would have made G3 an independent AND branch — presence sensing that does not share a signal path with the guard interlock — so that defeating the guard alone could not reach the top event. It did not, so a single key reached a fatality through a single branch. That is a single-point-of-failure finding, and single-point-of-failure findings are the kind a Category 3 architecture is specifically procured to eliminate.
3.3 The precursor, scored
| Item | Value | |---|---| | Event | Gantry system observed moving unexpectedly in diagnostic dry-run mode | | Date | Approx. April 5, 2025 (two days before fatality) | | Reported by | Coworker, per complaint | | Severity if realized | S2 — irreversible injury or death (ISO 13849-1 severity) | | Frequency of exposure | F2 — frequent to continuous; retool phase, technicians in cell daily | | Possibility of avoidance | P2 — scarcely possible; gantry drops vertically, no reaction time | | Resulting PLr | PL e | | Action taken before April 7 | None on record |
An S2/F2/P2 rating is the top of the ISO 13849-1 risk graph. A witnessed unexpected start-up in that band is a stop-work event, not a maintenance note.
4. Derived requirements (excerpt)
Stable IDs, written as they would appear in a cell-level safety requirements specification handed from integrator to end user.
CELL-SR-01 — Defeat resistance of the guard interlock. Each guard interlocking device on the washer and gantry cell shall use a coded actuator of high coding level per ISO 14119:2024 §5, with actuator spares controlled under a documented issue-and-return register. The safety-related control system shall detect and latch a fault when a guard-closed signal is asserted while the associated guard-position monitoring input indicates otherwise, and shall inhibit all hazardous motion until the fault is manually reset by an authorized person. Detection to inhibit shall complete within 100 ms.
CELL-SR-02 — Sanctioned in-cell work mode. The cell shall provide a manual reduced-speed mode in which all gantry and transfer axes are limited to 250 mm/s maximum, enforced by a safety-rated speed monitoring function of PL d / Cat 3 per ISO 13849-1:2023, available only while a three-position enabling device is held in its centre position by a person inside the safeguarded space, with single point of control enforced. Release or full compression of the enabling device shall command a Category 1 stop within 250 ms.
CELL-SR-03 — Independent presence detection. Presence of a person within the gantry motion envelope shall be detected by a means functionally and physically independent of the guard interlock signal path — area scanner, light curtain, or safety mat of PL d minimum — such that no single defeat, bridge, or actuator substitution can simultaneously falsify both the guard state and the presence state. Minimum distance shall be calculated per ISO 13855 using the measured gantry stopping performance, not the nominal figure.
CELL-SR-04 — Isolation and configuration management. Every energy-isolation point for the cell shall be identified on a machine-specific lockout procedure per 29 CFR 1910.147(c)(4) and ISO 14118:2017 §5, and that procedure and its physical placards shall be re-verified and re-issued within 5 working days of any physical relocation, addition, or removal of a cell subsystem, per ISO 11161:2007. Where a task cannot be performed under full isolation, an ANSI/ASSP Z244.1 alternative-method procedure with a documented risk assessment shall be issued before the task is authorized.
CELL-SR-05 — Precursor capture and controller forensics. Any reported instance of unexpected axis motion shall be logged as a safety-related anomaly, shall trigger cell shutdown pending investigation, and shall be closed only with a documented root cause. The safety controller and motion controller shall retain a non-volatile, timestamped fault and command history of not less than 30 days, and that history shall be preserved and imaged before any power cycle or board replacement following a reportable incident.
CELL-SR-05 exists because of the single most avoidable detail in this entire record. The controllers knew what commanded the gantry to move. They were restarted.
5. What the headline really tells us
The viral framing was worker killed by robot, and every safety engineer reading this knows why that framing is worse than useless. It puts the agency in the machine. It invites a conversation about whether robots are dangerous, which is a conversation with no work product at the end of it.
The gantry did what it was commanded to do. The interlock did what it was told the world looked like. The key did what keys do. What is actually missing from this record is a set of documents: a Clause 7 defeat analysis that asked why a competent technician would want the guard to lie during a retool, and answered it with a sanctioned reduced-speed mode instead of leaving the answer to the shop floor; an ISO 14118 isolation procedure that survived a physical relocation of the equipment it described; an ISO 11161 re-validation triggered by that relocation; a presence-detection branch independent enough that one defeat could not reach the top event; and an anomaly process that treated a witnessed unexpected start-up two days out as a stop-work condition rather than a shrug.
None of those are exotic. All five are ordinary integrator deliverables on a cell of this class, and all five are cheaper than an $11,291.70 settlement in the sense that matters, which is not the money.
There is a second, quieter finding. Sixteen months after a fatality, the investigation is open, the family has been told nothing, the regulator says it is pursuing compulsory disclosure, and the fault history is likely gone. Whatever else is true about this case, the evidence chain failed as completely as the safety chain did — and evidence preservation after a reportable incident is itself a requirement someone was supposed to write. That is why CELL-SR-05 is on the list. A safety case you cannot reconstruct is not a safety case. It is a story, and stories are what fill the space where the artifacts should have been.
Sources
- A Robot Didn't Kill This Stellantis Mechanic. A Bypass Key Did, and OSHA Predicted It Decades Ago — The Auto Wire, August 18, 2026
- One year since the death of Stellantis worker Ronald Adams Sr.: Family demands answers as MIOSHA investigation blocked — World Socialist Web Site, April 6, 2026
- Family Sues Stellantis after Death of Worker at Jeep Plant — WorkersCompensation.com, August 17, 2025
- MIOSHA fatality inspection 1816147.015, Stellantis Dundee, opened April 7, 2025 — OSHA establishment records
- OSHA violation detail 1770398.015 — Stellantis Toledo, 29 CFR 1910.212 serious violation, December 2024
- OSHA Technical Manual, Section IV, Chapter 4 — Industrial Robots and Robot System Safety
- 29 CFR 1910.212 — General requirements for all machines — OSHA
- 29 CFR 1910.147 — The control of hazardous energy (lockout/tagout) — OSHA
- ISO 14119:2024 — Safety of machinery — Interlocking devices associated with guards — ISO
- ISO 14118:2017 — Safety of machinery — Prevention of unexpected start-up — ISO
- ISO 10218-2:2025 — Robotics — Safety requirements — Part 2: Industrial robot applications and robot cells — ISO
- Updated ISO 10218 — Frequently Asked Questions — A3 / Association for Advancing Automation
- Stellantis workers killed at Toledo, Dundee and Center Line facilities — The Detroit News, August 17, 2026
— Jherrod Thomas, The Lion of Functional Safety™