"Fail-safe" by definition means that the system fails into a safe state. Stopping the trains on comms failure _is_ safe.