AI Has Learned To Move A Human-Shaped Body — The Hard Part Is Keeping It Under Control
AI Can Now Control Robots From Feet To Fingertips — That Creates A New Kind Of Risk
AI Steps Into The Physical World
The danger begins when an AI mistake can move something heavy.
Artificial intelligence has spent most of its modern boom behind a screen. A chatbot could invent a fact. An image model could draw the wrong object. An autonomous software agent might click the wrong button or access something it should not.
A humanoid robot changes the consequence.
Give an AI system cameras, motors, hands, legs and enough autonomy to interpret an instruction, and its decisions no longer end as pixels. They become physical actions. The machine can reach, lift, carry, push, walk, turn and interact with the same spaces as human beings.
That is why one of the most important questions in technology is shifting from what AI can think to what AI can safely be allowed to do.
Humanoid Robots Have Already Left The Demonstration Stage
The transition is no longer theoretical.
BMW says Figure 02 humanoid robots worked ten-hour shifts at its Spartanburg plant in the United States during a 2025 deployment, moving more than 90,000 components and contributing to production of more than 30,000 BMW X3 vehicles. The project accumulated about 1,250 hours of operation.
In 2026, BMW expanded its work with humanoids. Figure 03 returned to Spartanburg for a more complex logistics task, while the company also introduced a separate humanoid project at its Leipzig plant in Germany.
Those deployments matter because factories expose the difference between a spectacular demonstration and a useful machine. A robot has to perform the same task repeatedly, around equipment and workers, without turning a small perception or control error into an accident.
BMW's experience also showed how much surrounding infrastructure matters. Its Leipzig account says lessons from the earlier deployment included revised safety concepts with additional barriers and partitions, alongside improvements to connectivity inside the plant.
Humanoids are therefore not entering the world as independent mechanical people. They are entering carefully engineered systems in which the environment, software, sensors and safety controls all have to work together.
That distinction becomes even more important as the intelligence controlling the machines improves.
AI Is Starting To Control The Whole Body
The biggest shift in humanoid robotics is happening in software.
Traditional industrial robots usually perform tightly specified actions in controlled areas. They can be extremely capable, but the task, movement and environment are heavily constrained.
The new ambition is different. Robotics companies want machines that can see an unfamiliar situation, understand an ordinary instruction and work out the sequence of actions needed to complete it.
Google DeepMind's Gemini Robotics 2, announced in July 2026, was designed around what the company calls whole-body intelligence. The system links perception and reasoning with control from a robot's feet to its fingertips.
Figure's Helix 02 follows the same broad direction. Figure says the vision-language-action system coordinates the hands, arms, torso and feet of its humanoid machines so that a robot can manipulate objects while repositioning its body.
NVIDIA, meanwhile, is building general-purpose robot foundation models through its GR00T platform, while other developers are pursuing systems that can learn unfamiliar tasks from demonstrations.
This is the technological leap behind the race to give humanoids their own “ChatGPT moment”.
The goal is not merely a better walking machine. It is a machine that can interpret, reason and adapt.
That is also where the safety problem becomes much harder.
A Robot Can Be Wrong And Still Sound Completely Reasonable
Modern generative AI is probabilistic.
It does not work like a conventional emergency-stop circuit in which a fixed condition produces a fixed response every time. A model interprets context, predicts useful actions and can encounter situations that were not represented cleanly in training.
That flexibility is exactly what makes general-purpose robotics attractive. It is also what prevents safety from being reduced to a single instruction such as “never hurt a human”.
Consider a simple command: bring me that box.
A capable robot has to identify which box the person means, determine whether it can lift it, plan a path, avoid people and obstacles, choose a safe grip, maintain balance and know where to put the object.
Now change one detail. A child steps into its path. The box is heavier than expected. A liquid has spilled on the floor. The camera misidentifies an object. A sensor fails. The instruction conflicts with a safety rule. The robot is asked to use a tool in a way it has never seen.
The machine does not need to be hostile for any of those situations to become dangerous.
It only needs to be wrong.
That is the central difference between digital AI safety and physical AI safety. A hallucinated paragraph can mislead someone. A hallucinated physical action can create contact, momentum and force.
The Industry Is Building Safety Outside The AI Brain
The emerging answer is not to trust one model to police itself.
It is to surround the intelligence with independent layers.
In June 2026, NVIDIA introduced Halos for Robotics, a full-stack safety architecture intended for humanoids, industrial robots and other forms of physical AI. It combines specialised hardware, operating-system components, sensor infrastructure and safety applications.
Agility Robotics is using elements of that system in Digit, its humanoid worker. The company introduced Digit 5 in September as a machine designed for close-proximity work with people without the traditional physical barriers used around many industrial robots.
The significance is easy to miss.
If a general AI model decides what a robot should do, safety cannot depend entirely on that same model noticing that its own decision is dangerous. Separate systems need the power to constrain movement, detect people, monitor conditions and stop the machine.
Google DeepMind describes a similar layered approach. Its robotics safety framework separates semantic safety, physical safety and operational safeguards.
Semantic safety asks whether the action makes sense in context. A machine should understand, for example, that handing a boiling drink to a small child is unsafe.
Physical safety deals with movement itself: collision avoidance, force limits, balance and safe stopping.
Operational safety concerns how the system is deployed, supervised and controlled.
The principle is familiar from aviation, nuclear engineering and other safety-critical industries. Do not assume one component will never fail. Design the system so that one failure does not become a catastrophe.
The Hardest Failures Are The Ones Engineers Did Not Predict
Humanoid robots create an enormous testing problem because they are designed for environments built for humans.
A conventional robot arm might repeat one movement inside a fenced cell. A general-purpose humanoid could eventually walk through kitchens, warehouses, hospitals, shops and homes.
Those spaces contain effectively endless combinations of objects and human behaviour.
A worker can drop something. A door can open unexpectedly. A pet can run past. A tool can be left in the wrong place. A person can give an ambiguous command. Two instructions can conflict.
Researchers studying embodied AI increasingly focus on these long sequences because errors can accumulate. A robot may correctly complete the first five steps of a task and make a dangerous assumption at the sixth. A small navigation error can change the position from which the next action begins. One misidentified object can corrupt everything that follows.
The safety challenge is therefore not just preventing dramatic failures.
It is recognising uncertainty early enough that the robot stops, asks for help or hands control back to a person.
DeepMind's latest robotics work explicitly tests this behaviour. Its ASIMOV-Agentic benchmark measures whether a system can reject unsafe tool calls, recognise when a task may not be possible and request human intervention when uncertainty becomes too high.
That is a crucial ability. A useful robot needs intelligence.
A safe robot also needs to know when not to use it.
Cybersecurity Becomes Physical Security
There is another problem once intelligent robots are connected to networks, remote operators and software updates.
A compromised computer can leak information. A compromised robot can potentially alter the physical environment.
That does not mean hackers are about to seize armies of household androids. Current humanoid deployments remain limited, controlled and heavily supervised.
But the attack surface grows as robots gain connectivity, remote support, downloadable models and access to wider systems.
The industry is already confronting the same principle in autonomous AI software agents: permissions have to be restricted, behaviour monitored and critical controls separated from the agent itself.
For physical robots, those ideas become even more important.
A safety architecture must assume not only that the AI can make a mistake, but that software can fail, sensors can be spoofed, communications can be interrupted and malicious instructions can eventually be attempted.
Security is no longer separate from robot safety.
It becomes one layer of it.
Homes Will Be Harder Than Factories
Factories are the obvious starting point because they can be engineered around machines.
Homes are far less forgiving.
A humanoid operating in a kitchen may encounter heat, water, glass, knives, children and animals within a few metres. Objects move constantly. Lighting changes. Floors become wet. Humans issue vague instructions and assume common sense will fill the gaps.
That is why the push to turn humanoids into household cleaners is a much greater intelligence test than it first appears.
It is also a greater safety test.
A robot that folds towels badly is annoying. A robot that misunderstands an instruction beside a hot stove is a different problem.
The domestic market will therefore demand something robotics companies have historically struggled to demonstrate: safe performance across huge numbers of situations that nobody programmed individually.
This Is Not Yet A “Robot Uprising” Problem
It is tempting to frame all of this through science fiction.
That can obscure the immediate issue.
There is no evidence that today's humanoid robots are conscious, secretly developing motives or preparing to rebel against their owners. Nor does a system need anything resembling human intent to become dangerous.
The nearer-term risk is more ordinary.
A machine is given a goal. Its perception is imperfect. Its model encounters an unfamiliar situation. Its reasoning takes a path its designers did not anticipate. The resulting action is physically unsafe.
The same distinction applies to wider debates about AI becoming increasingly autonomous and difficult to constrain. Capability can outrun control without the machine becoming sentient.
This is why the humanoid safety race matters now rather than decades from now.
The machines are already entering real workplaces. Their AI is becoming more general. Developers are explicitly building systems that can reason, adapt and control more of the body.
Every one of those improvements makes humanoids more useful.
It also increases the number of decisions that have to be made correctly.
The Real Test Is Whether A Robot Can Fail Safely
The next era of robotics will not be decided by which humanoid can perform the most impressive demonstration.
Walking, lifting, sorting and manipulating objects are becoming expected.
The harder test is what happens at the edge of capability.
What happens when the instruction is unclear? When a sensor disagrees with the model? When the robot encounters something it has never seen? When a person enters its path? When communications fail? When software behaves unexpectedly?
A mature physical AI system needs safe answers to those questions before millions of machines are placed beside people.
That means independent emergency systems, constrained permissions, force and speed limits, redundant sensing, cybersecurity, audit trails, human override and models that recognise uncertainty instead of improvising through it.
Humanoid robots are acquiring something increasingly close to general-purpose machine intelligence for the physical world.
The most important engineering achievement may not be making them smarter.
It may be making sure that when the intelligence is wrong, the machine knows how to stop.
Sources
NVIDIA — NVIDIA Announces Halos for Robotics, the Industry’s First Full-Stack Safety System for Physical AI — Details NVIDIA's June 2026 robotics safety architecture and Agility Robotics integration.
Google DeepMind — Gemini Robotics 2 Brings Whole Body Intelligence To Robots — Supports the description of whole-body robot intelligence, human-proximity safeguards and agentic safety evaluation.
BMW Group — Leipzig Debut: BMW Group Introduces Humanoid Robots, A First In Germany — Provides deployment figures from Spartanburg and BMW's 2026 expansion of physical AI into Leipzig.
Next Reads
Humanoid Robots Are Moving Into The Home — And Cleaning Could Be Their First Real Job — How humanoids are moving from controlled industrial work towards messy domestic environments.
China Says Humanoid Robots Could Have Their ‘ChatGPT Moment’ By 2027 — And Everything Could Change After It — Why general-purpose embodied intelligence could become the breakthrough that transforms the robot industry.
The Seven Warning Signs AI Is Getting Too Powerful — Ranked — A wider look at autonomy, control and the growing gap between AI capability and safety assurance.