The old idea
In 1956 John von Neumann gave a series of lectures with a title that reads like a description of this entire chapter: Probabilistic Logics and the Synthesis of Reliable Organisms from Unreliable Components. His question was how to build a computer you can trust out of parts you cannot. His answer, redundancy, voting, and accepting error as a design input rather than a defect is the intellectual ancestor of everything that follows. Richard Hamming had already published error-correcting codes in 1950. Triple modular redundancy, where three processors compute the same thing and majority-vote the answer, became the standard spacecraft technique. The Apollo Guidance Computer flew with 2,048 words of erasable memory and a design philosophy of graceful degradation. The relevant point for us is that the fault-tolerance problem was solved conceptually before the transistor was widely deployed. What changed is not the theory. It is the economics of which parts you apply it to.
The physics
Chapter 6 laid out the two damage modes. Here is the part that decides architecture. Historically, shrinking transistors made parts less sensitive to accumulated dose, thinner gate oxides trap less charge. That was a gift to the industry: each new process node was, roughly, more radiation-tolerant than the last. Google’s own analysis notes that this favourable trend does not continue below the 5 nm node.15 Meanwhile the opposite happens for single events. Smaller, lower-voltage transistors hold less charge per stored bit, so it takes less energy from a passing particle to flip one. Density compounds it: more bits per square centimetre means more targets. So modern silicon is, crudely, better at surviving the slow damage and worse at surviving the fast one, which is exactly the profile that favours the hyperscale answer. Accumulated dose you cannot fix in software. Bit flips you can.
What the numbers actually say
Figure 12.1 — Commercial silicon has more margin than the sector assumed
Put the published figures on one axis and the argument becomes visual. The five-year shielded mission dose in the reference orbit is about 0.75 krad. High-bandwidth memory, the most sensitive subsystem, showed its first irregularities near 2 krad. The tested part reached 15 krad with no hard failures attributable to dose.9 The mission needs to clear the leftmost bar. The evidence says commercial silicon clears it with roughly a factor of three of margin on its weakest component, and considerably more on the processor itself. That is a smaller margin than it looks, and it is worth being precise about why. Three times is not much when the dose estimate itself depends on solar cycle phase, exact orbit, and how much shielding survives the mass budget review. It is also a dose margin, and dose was never the thing that was going to kill you suddenly.
What breaks
Latch-up, which destroys hardware rather than corrupting it, and is a power-electronics problem: detect the current excursion, cycle the device, restart. Every operator in this sector is quietly building this capability and almost none of them talk about it. Memory, which is both the most sensitive component and the largest by area in a modern accelerator. If there is a hardware surprise in this sector over the next five years, my expectation is that it comes from HBM stacks rather than from logic. The absence of data. Nobody has multi-year on-orbit statistics for frontier accelerators. Beam tests simulate a dose; they do not simulate five years of thermal cycling, vibration-settled solder, coolant contact and unattended operation.
Who is attacking it and why I do not own any of them
Google is the only organisation designing its own silicon with orbit in mind, and it has published the testing to prove it, alongside a design for satellite clusters and a first launch of prototypes with an Earth-imaging partner.8 Nvidia has flown commercial accelerators in orbit and now offers a radiation-tolerant line built on commercial silicon rather than bespoke rad-hard parts. Ramon.Space and Microchip occupy the traditional space-processor niche, the latter supplying processors to commercial station operators. Now the uncomfortable conclusion, which is the reason this chapter exists in a book about investing. This layer has been solved by companies you cannot buy at venture scale, and that is a good outcome, not a missed one. The radiation problem is being retired by two of the largest semiconductor organisations on Earth, funded by AI revenues that dwarf this sector, and they are publishing the results. A private radiation-hardened
silicon company competing with that is a poor investment regardless of how good its engineering is. A guidebook that only tells you where to invest is a sales document. This is a layer to understand and not to own. Its progress is the strongest de-risking event the sector has had, Chapter 6’s reframe holds, that radiation is a depreciation schedule rather than a wall and you capture that progress by owning the operators and suppliers whose economics improve because of it.
What to watch
The first published on-orbit single-event rates for a frontier accelerator, as opposed to beam-test results. Any evidence on HBM behaviour over years rather than hours. Whether the sub-5 nm dose trend Google flagged turns into a practical ceiling on which generations of silicon can fly.