I found the name for that concept: https://en.wikipedia.org/wiki/Subsumption_architecture - subsumption architecture puts some of the intelligence in the lower level systems. While the higher level controls can tell the lower level systems what it wants, it can't do things that the lower system determines is dangerous.