This argument is always so silly because it’s just an argument about the correct way to build a safe control system (i.e. with guaranteed performance characteristics in a defined operational domain) versus the incorrect way to do it (just kinda work over an ambiguously defined set of conditions and hope you don’t kill too many innocent people to cripple your business).