A block diagram on a dark ground: three clients, a physicist through a GUI, an AI agent through MCP and a script through a CLI, each connect to one engine that checks every command against limits, role, attendance and a kill switch, which drives a virtual-instruments layer over four instruments: temperature, magnet, source meter, and camera and stage.

Instrument software · 2026–present

I2AS: Instrument to Agentic Station

Laboratory instruments that a physicist and an AI agent can operate side by side, with every command checked by the same safety rules.

The short version

A lab setup is a rack of instruments from different vendors, tied together by scripts that work only for the person who wrote them, with safety limits, monitoring and metadata rewritten or skipped for each setup. CryoSoft solved this for one cryostat but could not be reused elsewhere without a fork. An AI agent can only be allowed near a running instrument if every action it takes passes the same checks as a human's and is recorded.

Role
Solo developer
Period
2026–present
PythonPyQt6pyqtgraphPyVISApyserialh5pynumpyruamel.yamlMCPHDF5CI

The architecture of CryoSoft, made independent of any one station and opened to AI agents. It is the instrument strand of the lab's AI work, alongside the literature and wiki search.

A block diagram. Three clients at the top, Physicist through a GUI, AI agent through MCP and Script through a command-line interface, each connect with a two-way arrow to one wide engine block reading "One engine: every command checked", with "limits, role, attendance, kill switch" underneath and a red stop button at its right end. The engine connects below to a Virtual instruments layer, "each reading and action declared once", which connects to four instruments at the bottom: temperature, magnet, source meter, and camera and stage. Three kinds of client, one engine that checks every command, one declaration per instrument.

How

  • Declared each instrument once, in a Virtual Instrument layer: readings with units, actions with typed parameters, bounds and action classes. The PyQt6 and pyqtgraph GUI, the MCP tools, the Python gateway and the command-line client are rendered from it, and conformance tests keep the four surfaces identical.
  • Sent every command through one engine. A button click, an MCP call and a spooled JSON file become the same Command, checked against setup limits, session envelope, attendance, kill switch and run ownership, and answered by one Verdict on a stream every client sees.
  • Gave agents authority in steps: a role ladder from observer to human operator, where role ceilings, the kill switch and run ownership can only remove permissions. Remote agents connect over MCP with named access keys.
  • Placed code by trust: the tested engine on the instrument thread, user-written blocks in a killable helper process, agent-generated analysis in a container with no network.
  • Made every run a record and every layer testable. One HDF5 file per run with sample, parameters and declarations, an agent log inside the experiment folder, a checked YAML configuration, a simulated twin for every PyVISA and pyserial driver, and layer independence enforced in CI by import contracts.

A diagram of nested boxes around a block labelled Instrument. Tier 0, User/vendor, holds drivers, Virtual Instruments and procedures. Tier 1, Shipped tested, holds the engine, safety and gateway on the instrument thread. Tier 2, User blocks that could be vibe coded, holds lab-notebook connectors and renderers in a killable helper process. Tier 3, Agent code generated on the fly, holds analysis scripts in a container with no network. An arrow along the bottom reads "Less trust, further from the instrument". No user or agent code can affect a running experiment: the less trusted the code, the further it runs from the instrument.

Presented at AI4Sci 2026. The code is not public yet.