Machine Design #36: Power or Air Loss — Should the Mechanism Hold, Release, or Return?
When electrical power or compressed air disappears, should a mechanism stay where it is, return to its initial position, release the workpiece, or be allowed to drift? There is no universal answer. The correct state depends on the hazard, load, stored energy, access conditions, and recovery method.
Calling a valve or actuator “fail-safe” without defining the safe state can create false confidence. A spring-return valve may retract one cylinder safely but drop a suspended load on another axis. A clamp that remains closed may protect product quality while trapping a hand during intervention. A gripper that releases on air loss may avoid stored pressure but drop a heavy part.
The engineering task is to compare the consequences of holding, releasing, and drifting, then design a state that can be verified and recovered safely.
This article gives a conceptual decision framework. It does not replace a machine risk assessment, calculations, component specifications, applicable standards, or validation by competent safety and fluid-power engineers.
1. “Fail-safe” means nothing until the hazard is defined
A failure is not safe merely because power has been removed. Ask what can injure a person, damage equipment, release process material, or create an unexpected movement after the failure.
For a vertical axis, gravity may be the dominant energy and removing motor torque can cause a fall. For a clamp, releasing pressure may eject or drop the workpiece. For a guarded door, retained pressure may prevent escape or create a pinch point. For a press, elastic deformation may drive the ram backward even after pressure is vented.
Define the required condition in observable terms: the load does not descend beyond a specified distance; clamping force remains within a safe range for a defined time; stored pressure falls below a verified threshold; or access cannot occur until hazardous motion and energy have ended.
2. Build an energy map for each mechanism
Do not create one energy map for the whole machine and assume every actuator behaves the same. For each mechanism, identify electrical power, pneumatic or hydraulic pressure, vacuum, gravity, springs, elastic deformation, inertia, thermal energy, and forces transmitted from linked equipment.
Record the normal energy path and the failure path. Determine which valve position occurs on electrical loss, what happens when supply pressure decays slowly, whether a check valve traps pressure, how leakage changes the state over time, and what external load continues to act.
The map should distinguish commanded energy from retained energy. A solenoid may be de-energized while a cylinder chamber remains pressurized. A motor may be disabled while a brake stores spring force. “Output off” is not evidence that energy is absent.
3. Use a hold–release–drift matrix
Compare all three states instead of selecting the familiar one by habit.
| Candidate state | Possible benefit | Typical risk | Evidence required |
|---|
| Hold | Prevents falling, product loss, or uncontrolled travel | Traps a person or retains hazardous energy | Brake, lock, pressure, position, or force feedback |
| Release or return | Removes clamping or process force and may open access | Drops a load, creates return motion, or ejects a part | Controlled path, speed, end-position, and clear-zone confirmation |
| Drift | Avoids an abrupt commanded movement | Final position and timing are uncertain | Drift rate, stop limit, containment, and inspection criteria |
Hold
Holding is appropriate only when the retaining measure has defined capacity, failure behavior, diagnostic coverage, and maintenance requirements. A check valve alone may slow motion but cannot automatically be treated as a personnel-protection device.
Release or return
Returning to a home position requires a safe path. Spring return is still motion and can create crushing or impact hazards. The available spring force also changes across the stroke and may be insufficient under contamination, friction, or external load.
Drift
Drift is a real state even when nobody specifies it. Leakage, gravity, and compliance determine the motion. If drift is tolerated, define how far and how fast it may occur, what contains the load, and when the mechanism becomes unsafe.
4. A vertical axis must not fall simply because power is lost
Vertical axes deserve separate analysis. Consider motor brakes, counterbalance systems, rod locks, load-holding valves, mechanical pawls, and physical supports. Check both static holding and dynamic stopping capacity.
The brake sequence matters. During restart, motor torque should be established before the brake releases. During stopping, the control should reduce motion and apply the brake in the validated order. Feedback should detect a brake that fails to engage or release. Periodic proof testing may be necessary because a brake can degrade while ordinary production still appears normal.
For maintenance, a brake or pneumatic lock may not be sufficient isolation. A mechanical support may be required before a person enters beneath the load.
5. Workpiece clamps: holding may help the process but hinder intervention
Retaining the workpiece can prevent a drop, preserve datum, and make controlled recovery possible. However, retained clamping force may trap fingers, keep a sharp or hot part energized, or make jam clearing dangerous.
Define separate states for an operational interruption and human intervention. The machine may hold the part during a short controlled stop, then require isolation and verified pressure release before access. If controlled release is needed, specify its order, speed, support for the workpiece, and confirmation that the hazardous area is clear.
Do not infer clamping force only from a closed-position sensor. Position confirms geometry, not necessarily pressure, contact, or holding capacity.
6. Robot grippers: hold or drop after air loss?
Hold
A normally closed gripper, check valve, pressure reservoir, or mechanical self-locking mechanism may retain the part. Verify how long it can hold under leakage, vibration, maximum payload, surface variation, and hose failure. Retaining pressure must not hide a later release hazard during maintenance.
Drop
Releasing can remove gripping force, but the falling part creates another hazard. If release is the selected state, provide a receiving surface, containment, restricted access, or another means preventing injury and secondary damage.
The answer may differ between a lightweight plastic component and a sharp metal casting. State the payload envelope and test the worst credible part, not only a nominal sample.
7. Vacuum pick: residual vacuum does not hold forever
A vacuum cup may retain a part briefly after supply loss because of a check valve and trapped volume. Holding time depends on leakage through the cup, surface roughness, porosity, tubing, fittings, and acceleration.
If residual vacuum is part of the risk-reduction concept, calculate and test the minimum holding time under worst-case conditions. Monitor vacuum near the end effector when practical. Provide a controlled destination or catch for the part. An HMI bit showing that the vacuum command is on does not prove that sufficient vacuum remains.
8. Pressing cylinders and presses can return stored elastic energy
During pressing, the frame, tooling, workpiece, and cylinder components deform. Removing fluid pressure can allow that elastic energy to move the ram or eject the part. A pressurized chamber can also remain trapped by valves.
Model both pressure energy and structural spring-back. Define the venting path, rate, and final position. Check whether decompression itself creates rapid motion. Before access, verify pressure and position rather than relying on elapsed time alone.
9. Pneumatic doors and covers
A pneumatic cover may be heavy enough to fall when air is lost, or a spring-return cylinder may drive it toward a person. Determine whether the safe state is open, closed, mechanically held, or prevented from moving.
Account for hinges, center of gravity, counterbalance, hand access, and the possibility of somebody leaning on the cover. Where the cover is part of a guard, its position sensing and locking function must match the safety concept; ordinary pneumatic control cannot substitute for a required guard-locking function.
10. A spring-return valve does not automatically create a safe state
The valve symbol only describes the spool's preferred state under specified conditions. It does not prove the actuator state, load behavior, exhaust performance, or resistance to common-cause failures.
Check blocked ports, meter-out controls, pilot-operated check valves, trapped pressure, hose rupture, spool sticking, silencer restriction, and pressure supplied from the opposite side. Select valve architecture only after defining the intended mechanical state and required diagnostic coverage.
11. Hydraulic systems: high pressure and accumulators
Hydraulic systems can retain substantial energy in accumulators, hoses, cylinders, and suspended loads. A pressure gauge at one point may not reveal trapped pressure behind a closed valve.
Provide safe discharge paths, pressure indication at relevant volumes, measures against load descent, and maintenance instructions identifying every isolation point. Verify accumulator precharge and discharge behavior. Never assume a stationary cylinder is depressurized.
12. Compressed air has lower pressure but still stores hazardous energy
Compressed air can move large cylinders, eject parts, whip a hose, and keep an actuator loaded after the main supply is closed. Exhaust silencers and flow controls can make pressure decay slow and variable.
Dumping the main manifold does not guarantee every branch is vented. Pilot circuits, check valves, reservoirs, and vertical cylinders need individual consideration. Where zero pressure is required for intervention, provide a reliable means of verification.
13. Separate operational stop from maintenance isolation
Operational stop
The mechanism enters a controlled state that supports short interruptions and recovery without human exposure to the hazard. Some energy may remain intentionally retained and monitored.
Maintenance isolation
Energy sources are physically isolated, locked where required, and stored energy is discharged, restrained, or otherwise controlled before intervention.
Using one valve and one state for both purposes often produces a compromise that is good at neither. Document the boundary clearly in the HMI, operating procedure, and maintenance instructions.
14. Diagnostics: how do we know the safe state has been achieved?
Select feedback that measures the safety claim as directly as practical: position for travel, pressure for fluid energy, brake feedback for engagement, vacuum level for gripping capacity, and mechanical-lock feedback for restraint.
Use plausibility checks between command and response. A cylinder cannot be both extended and retracted; pressure should decay within an expected time after venting; a brake-release signal with unexpected axis motion should trigger a fault. Diagnostic timing must come from physical behavior and validated margins, not an arbitrary five-second timeout.
15. Design the re-energization sequence
Restoring power or pressure is an active transition. It can move valves, release brakes, refill accumulators, or shift a mechanism before the PLC has reconciled its state.
A robust sequence establishes control power, reads feedback, identifies unknown states, restores utility pressure in a managed way, enables only required devices, confirms holding conditions, and waits for an intentional operating command. Pressure recovery or network reconnection must not resume the previous cycle automatically.
16. The failure matrix must go beyond a total blackout
Test partial and asymmetric failures: one phase lost, control power retained while actuator power is lost, air pressure decaying slowly, a branch hose ruptured, one valve stuck, one sensor failed, network communication lost, or power restored before pressure.
Also test failures during different phases of motion and with maximum credible loads. A design that behaves safely only when all energy disappears instantaneously is not robust.
17. Proof testing and maintenance
Load-holding components can fail silently. Define inspections and proof tests for brakes, rod locks, check valves, accumulators, pressure switches, vacuum monitoring, and mechanical catches.
Record test load, position, holding time, allowable drift, measured pressure, acceptance criteria, and corrective action. Maintenance replacement must preserve component rating, valve function, orientation, and validated settings. A visually similar substitute can change the failure state.
18. A process for selecting the state after energy loss
Step 1 — Define the load and hazard
Identify mass, force, sharp edges, temperature, stored process material, human access, and credible failure phases.
Step 2 — Build the energy map
Include supply, retained, gravitational, elastic, and externally transmitted energy.
Step 3 — Compare the three states
Evaluate holding, releasing or returning, and drifting. Consider both immediate consequences and later intervention.
Step 4 — Select the designed state
Describe the state in measurable terms, including position, force, pressure, time, and permitted access.
Step 5 — Select the class of measures
Choose inherent mechanical behavior, control measures, monitoring, physical restraint, containment, and procedures in the appropriate hierarchy.
Step 6 — Define diagnostics
Specify feedback, plausibility, timeout, fault response, and proof-test coverage.
Step 7 — Define recovery and isolation
Separate automatic recovery, operator intervention, and maintenance requiring isolation.
Step 8 — Validate and proof-test
Test realistic loads, failure combinations, lifecycle degradation, and re-energization.
19. Review checklist
Hazard
- [ ] The safe state is defined for each mechanism and failure phase.
- [ ] Hazards of holding, releasing, and drifting have all been compared.
- [ ] Gravity, elasticity, inertia, and trapped pressure are included.
Architecture
- [ ] Valve, brake, lock, support, and containment functions match the intended state.
- [ ] Operational stopping and maintenance isolation are separate where needed.
- [ ] Partial and common-cause failures are considered.
Feedback
- [ ] Feedback measures the claimed state directly enough.
- [ ] Command/response plausibility and physical time limits are defined.
- [ ] Trapped pressure and retained load can be verified before access.
Recovery and maintenance
- [ ] Re-energization cannot create unexpected movement.
- [ ] Unknown state leads to controlled recovery, not automatic continuation.
- [ ] Inspection and proof-test intervals have acceptance criteria.
Validation
- [ ] Maximum credible loads and leakage are tested.
- [ ] Power loss, air loss, pressure decay, and energy restoration are tested.
- [ ] Documentation identifies residual risks and isolation points.
Conclusion
The right response to power or air loss is not always “return,” “release,” or “hold.” It is the state that minimizes the defined hazard, can be confirmed with evidence, and supports safe recovery and maintenance.
Map every energy source. Compare hold, release, and drift without assuming that de-energization is safe. Design load restraint, venting, diagnostics, re-energization, and proof testing as one system.
A mechanism is fail-safe only when its behavior under credible failures has been defined, implemented, tested, and maintained—not because a catalog labels one component “spring return.”
Public references
View all MINATA technical articles