The Sensor That Lies Is Worse Than the Sensor That Dies
A dead sensor is obvious. A lying sensor costs you everything.
I spent years building fault-tolerant automation for diagnostics production lines. The failure mode that keeps engineers awake is never the component that stops. It is the component that keeps going while reporting wrong numbers, confidently, consistently.
One part of the system sees one value. Another part sees something different. Everything downstream keeps running on data that looks perfectly reasonable and is not.
You see a flat line on a dead sensor. You replace it in ten minutes. The sensor that drifts, the one that tells the dispensing controller one thing and the quality system another, that one can run for weeks before anyone notices. By then, you have a product on the line that should not be there.
In 1982, three computer scientists named Lamport, Shostak, and Pease gave this problem a name. The Byzantine Generals Problem. Several generals surround a city. They communicate only by messenger. They must agree on one plan. Attack or retreat.
The problem is that some generals are traitors. A traitor does not stay silent. He sends an attack to one general and a retreat to another, working to make sure the loyal ones never reach agreement.
The question they answered is the one that matters in every system I have ever built. How many honest sources do you need before a few liars can no longer break the decision? The result is exact. You can only reach a reliable agreement if fewer than a third of your sources are corrupted. To survive a single traitor, you need at least four generals.
Below that line, no amount of cleverness saves you. The liars win. A lone trusted channel is not a safety feature. It is a single point of failure waiting to happen.
I have built against this my whole career. Fault-tolerant systems never trust a single sensor. You build redundancy. You make the sources independent. You let them vote. One channel that everyone trusts is the most dangerous architecture you can build.
I have seen this pattern in every production line I have worked on across 37 countries. The systems that survive are not the ones with the best sensors. They are the ones with enough independent sensors that no single fault, silent or lying, can form a majority.
Now take that out of the machine and put it inside a company. Every organization runs on inputs. Reports. Dashboards. The person who always sounds certain in the meeting.
The most expensive failures I have seen were never the input that went quiet. Silence gets noticed. The damage came from the confident, wrong report. The channel everyone trusted told slightly different stories to different people, while decisions were made on numbers that looked clean but were not.
A leader who relies on one trusted source has built a Byzantine system with no redundancy. Most do not even know what fraction of their signal is already corrupted, which means they have no idea whether they are above the line where reliable agreement is still possible.
You do not fix it by trusting harder. You fix it by building enough independent, honest sources that no liar can form a majority. The engineering answer is the same one I keep coming back to in every part of this job.
Never trust a single source. Not a sensor, not a report, not a person. Redundancy is not a waste. It is the minimum viable architecture for reliable decisions.
Make the sources independent. Three sensors reading from the same power supply are not three sources. Three reports built from the same dataset are not three opinions. Independence is structural, not numerical.
Go to the real place. Walk to the floor. Look at the machine. Read the raw data. The further you are from the source, the more you depend on the honesty of every messenger between you and the truth.
Know your threshold. If you cannot say how many of your inputs could be wrong before your decisions break, you do not have a system. You have hope.
The cost of getting this wrong in diagnostics manufacturing is not abstract. A production line dispensing at the nanoliter level, building tests that determine whether someone has sepsis in 30 minutes instead of 72 hours, cannot afford to run on a lying input.
The machine on the factory floor is the last thing standing between a researcher's breakthrough and a patient's outcome. If the data going into that machine is corrupted, the product coming out is compromised. No amount of downstream quality checks fully recovers what was lost at the source.
An AI model that is confidently, fluently wrong is the purest Byzantine fault built so far. It does not fail by going silent. It fails by sounding exactly as certain when it is wrong as when it is right.
The discipline that fault-tolerant engineering learned the hard way- never trust one source, always verify at the floor- is becoming one of the most important management skills of the next decade.
Pick the three most important inputs to your most critical decision this quarter. For each one, name how you would know if it were wrong. If you cannot answer that, you are running a Byzantine system with no redundancy. That does not end well.
The general who sounds most certain is not the one to trust. He is the one to check.
The companies that will build reliably in the next ten years are the ones that design their information architecture the way engineers design fault-tolerant systems. Not by finding one source they trust completely. By building enough honest, independent sources that no single liar, human or machine, can break the decision.
Kauko Väinämö is CEO of Ginolis