Safety3 min read

Physical AI Robots Ship With Open Security Holes

July 22, 2026Synthesized from 1 source: Weforum

AI-powered robots are being deployed in warehouses, hospitals, and logistics operations with serious, largely unacknowledged security flaws built in, and most buyers have no idea.

Robots are arriving in warehouses, factories, hospitals, and logistics yards right now. BMW, Amazon, and Mercedes-Benz are already running pilot deployments. Humanoid robots range in price from roughly $16,000 for entry-level models to over $150,000 for advanced units, and costs have dropped by at least 40% since 2022. The capital is committed. The question is whether the security is.

The answer, in most cases, is no.

A Capgemini team in Cambridge bought a leading humanoid robot and spent a week pulling it apart. They found an internal computer they could not inspect, persistent outbound connections to servers in the robot's home country, a microphone feeding audio into closed software, and a Bluetooth flaw that was already catalogued in public security databases. To make it safe enough even for a controlled lab, they had to install separate hardware, physically disconnect the microphones, replace the cameras, build an isolated network, and write custom rules to block all outbound calls. That is not setup. That is reconstruction.

The software layer is no safer. Most modern robots run on a communication framework called ROS2, which handles the internal messaging between a robot's sensors, motors, and brain. Security researchers have documented roughly 15 dangerous flaws in that system, affecting over 650 devices across industry, hospitals, and military platforms. Those devices are not isolated: many are visible from the open internet, identifiable from any browser by anyone who knows where to look.

Then there is a compounding maths problem. An AI agent that is 95% reliable on each step of a task, running a 30-step task, has only about a 21% chance of completing the whole task without error. On a screen, a mistake means lost work. On a factory floor, it means a robot that drops, collides, or endangers someone. The longer the task chain, the worse the odds.

The human-in-the-loop is not the safety net it appears to be. Most physical AI systems rely on remote operators who intervene when the machine gets confused. These operators often work from facilities in other countries, may lack familiarity with local laws, and connect through workstations of unknown security. Waymo confirmed under US Senate questioning in February 2026 that some of its remote operators are based in the Philippines. The NTSB is investigating a case where one of those operators incorrectly cleared a robotaxi to pass a stopped school bus while children were boarding. The car followed that instruction.

If an attacker gains access to a remote operator's workstation, they get the live camera feed and, in some systems, the physical controls of whatever machine that operator is watching. A security robot in a hospital corridor, a warehouse picker near a loading dock, a delivery vehicle on a public road: each becomes a remote-controlled surveillance and manipulation tool. This is not an edge case. It is the standard architecture for a large portion of what is being sold and deployed today.

Three professional communities, security researchers, cybersecurity professionals, and robotics engineers, each hold part of the answer. None of them is talking to the others in any structured way. DARPA has publicly stated that operational security testing for physical AI used on the battlefield does not yet exist. If the US military is willing to say that out loud, any procurement committee buying the same class of hardware for a warehouse or hospital should take that seriously.

Regulatory pressure is building. The EU AI Act, with a compliance deadline in August 2026, classifies many physical AI deployments as high-risk systems. Non-compliance carries penalties of up to 35 million euros or 7% of global annual turnover, whichever is higher. The Act applies based on where the system is used, not where it was made. NIST in the US launched its AI Agent Standards Initiative in February 2026, but its current work does not yet cover robots, vehicles, or any physically embodied system.

For anyone signing a contract or sitting on a procurement committee that includes physical AI, there are three things that can be done now. Demand a documented list of every outbound connection the device makes, who it calls home to, and the right to have a neutral third party verify it. Treat remote operators as a regulated control point, with documented credentials, secure workstations, and clear accountability. And require that any security audit be repeatable, not a one-time sign-off done before deployment.

Physical AI is not coming. It is already here. The security posture is not.

Stay informed

Get AI intelligence like this delivered to your inbox.