Humanoid robotics is evolving from isolated demonstrations into increasingly integrated cyber-physical systems. The decisive factor is less the human-like form than the ability to combine perception, AI-based planning, connectivity and physical action in real operating environments. For enterprises, the perspective is therefore shifting from robotics alone to an architectural question involving compute, connectivity, safety and cybersecurity.
Between industrial trials and production maturity
In 2026, humanoid robotics has reached a point where it is more than a laboratory demonstration. At the same time, it would be misleading to present today's systems as universally deployable workers. Real-world pilots show both sides: impressive progress and clearly defined limitations.
BMW demonstrated at its Spartanburg plant in 2025 that humanoid robotics can move from demonstration into a real production process. Over ten months, Figure 02 supported the production of more than 30,000 BMW X3 vehicles, moved more than 90,000 components and, according to BMW, completed around 1,250 operating hours.
In 2026, this development is continuing with the next generation of robots: at the Spartanburg plant, BMW and Figure AI are testing Figure 03 in a more complex logistics and sequencing process. The robot sorts delivered components into sequencing trolleys while combining manipulation with movement throughout the work area. Figure 03 also introduces tactile sensing, palm-mounted cameras, wireless charging and audio capabilities for speech-to-speech communication.
In parallel, BMW is deploying AEON by Hexagon Robotics at its Leipzig plant, marking the company's first use of a humanoid robot in production in Germany. The pilot includes material supply and assembly tasks related to battery production. Rather than a single robotics project, this creates a broader industrial test environment for Physical AI across different platforms and operating profiles.
Mobility
Walking, balancing and navigating environments designed for humans are becoming increasingly reliable.
Manipulation
Grasping and repeatable workflows are real capabilities – fine-motor and highly variable tasks remain significantly more demanding.
Autonomy
AI models improve perception and planning, but robust decision-making in unpredictable situations remains a core challenge.
Integration
Production use requires more than robotics: networks, production IT, safety, compute and operational processes must work together.
When artificial intelligence gains physical impact
The term Physical AI describes systems that perceive their environment through sensors, interpret information, plan actions and execute them physically through actuators. Humanoid robots are a particularly visible form, but the principle extends far beyond them.
The human form has a pragmatic advantage: our infrastructure was built for us. Doors, stairs, tools, shelves, vehicles and workplaces follow human dimensions and movement patterns. A humanoid system is intended to operate within this existing environment without requiring every space to be redesigned for robotics first.
From a security perspective, this chain is critical: every additional digital dependency can become part of the attack surface – and failures can ultimately produce real physical consequences.
Processing is also moving increasingly closer to the machine itself. In August 2026, NVIDIA demonstrated with Cosmos 3 Edge on Jetson Thor that robotics policies can run entirely on-device without relying on data-center GPUs for every inference step. For enterprise architectures, this makes edge compute a direct component of performance, availability and security.
The potential extends far beyond the factory floor
The potential fields of application are substantial. Humanoid systems can become particularly relevant where tasks are physically demanding, dangerous, highly repetitive or only partially accessible to humans. For enterprises, the value lies primarily in clearly defined task profiles, robust integration concepts and controlled interaction with existing processes.
Industry & Logistics
Repeatable tasks, material handling and work within existing production environments designed around humans.
Hazardous Environments
Deployment in environments where heat, radiation, contaminants or structural hazards would put people at risk.
Care Assistance
In the longer term, physical assistance, transport tasks and support with demanding routine activities.
Rehabilitation & Prosthetics
Related advances in sensors, actuators and neural interfaces are opening new possibilities for restoring functions.
Prosthetics and humanoid robotics are not the same field. They do, however, benefit in part from the same technological advances: more precise actuators, sensor fusion, adaptive control and improved human-machine interfaces.
The same capabilities always have a second side
Autonomous navigation, object recognition, force, manipulation and decision-making are initially neutral technical capabilities. Their value and risk depend on the application context and on the boundaries humans establish for these systems.
This is precisely why Physical AI is a classic dual-use technology. A system capable of opening doors, overcoming obstacles or moving heavy objects has capabilities that may be relevant in civilian as well as security-critical or military scenarios. Autonomous weapon systems are no longer a purely hypothetical debate; international organizations are already addressing their control and regulation.
For a technological assessment, however, the decisive question is less political than technical: How can a highly autonomous physical system remain controllable?
When cybersecurity no longer protects data alone
In a conventional IT security incident, confidentiality, integrity and availability of data and services are typically the primary concerns. A cyber-physical system adds another dimension: a compromised digital process can have an immediate effect on the real-world environment.
Identities & Permissions
Machines, services, operators and interfaces require unambiguous identities and only the minimum permissions necessary.
Firmware & Updates
Signed software, secure update paths and traceable version states become fundamental to system integrity.
Networks & Segmentation
Robotics, production and corporate networks must not be treated as a single trust zone.
Models & Sensors
Manipulated inputs, compromised models or faulty policies can influence system decisions.
Monitoring & Traceability
Telemetry and tamper-resistant logs are necessary to investigate behavior, anomalies and security incidents.
Fail-safe & Human Control
Cybersecurity and functional safety must work together so that failures cannot transition uncontrollably into physical actions.
Security by Design becomes a prerequisite for trust
The underlying principles are not new – their consequences are. Zero Trust, Least Privilege, Secure Boot, signed updates, segmentation, integrity controls and continuous monitoring already belong to professional security architectures. Physical AI, however, increases the impact when these principles are missing.
NIST already approaches Operational Technology on the premise that digital systems can directly affect physical processes. At the same time, the European Cyber Resilience Act is placing greater regulatory responsibility on security by design and vulnerability management throughout the product lifecycle. From 11 September 2026, CRA reporting obligations apply to actively exploited vulnerabilities and severe security incidents affecting products with digital elements; an early warning is generally required within 24 hours and a complete notification within 72 hours. In 2026, NVIDIA also introduced Halos for Robotics, its own full-stack safety architecture for Physical AI.
This illustrates a development that is critical for enterprise IT: compute, AI, connectivity, safety and cybersecurity are converging technically.
Dell Technologies & NVIDIA
Dell Technologies combines enterprise infrastructure with NVIDIA-accelerated compute for modern AI workloads.
For L::eS, this development is part of the infrastructure perspective – from the data center to the edge.
More about AI infrastructure and GPU systems →
ESET & L::eS Security
Endpoint security is not the same as robotics security. The underlying challenge, however, is familiar:
systems, identities, software and infrastructure must be protected against manipulation and misuse.
More about enterprise cybersecurity →
The new boundary between IT and the real world
Humanoid robotics should be viewed as a technology platform with substantial potential and, at the same time, new risk profiles. From a security perspective, the key issue is that software, identities, models and networks can increasingly produce direct physical effects.
This also changes the role of cybersecurity. Identities, networks, software integrity, update processes and monitoring then protect more than information and business processes. They become part of the safety and security of our physical environment.
For enterprise architectures, the performance of Physical AI alone will therefore not be decisive. What matters is whether security, safety, governance and operating models can keep pace with the technological development.
Frequently asked questions about Physical AI and cybersecurity
A technical perspective on key questions surrounding humanoid robotics, cyber-physical systems and their secure integration.
Physical AI refers to systems that perceive their environment through sensors, interpret information, plan actions and execute them physically through actuators. Humanoid robots are a particularly visible form, but the concept also includes other autonomous and cyber-physical systems.
With Physical AI, compromised digital processes can have an immediate effect on the real-world environment. In addition to data and services, identities, networks, sensors, software integrity, update processes and actuators must therefore be protected against manipulation and misuse.
Relevant attack surfaces include network connections, cloud and edge systems, machine identities, sensors, firmware, software updates and AI-based decision processes. The more directly a system can act in the physical world, the greater the potential impact of manipulation.
Safety addresses unintended malfunctions and protection against resulting harm. Security addresses deliberate manipulation, unauthorized access and cyberattacks. In Physical AI, both disciplines converge because a security incident can also cause physical consequences.
Physical AI systems require powerful compute resources for perception, planning and AI models. Depending on the application, these functions run locally at the edge, in centralized infrastructure, or across the device, data center and cloud. Compute, connectivity and cybersecurity therefore become interconnected parts of the system architecture.
Key requirements include clearly defined use cases, controlled permissions, network segmentation, secure update processes, monitoring, and robust safety and security concepts. Physical AI should therefore not be treated as isolated robotics technology, but integrated into the existing enterprise and security architecture.
Sources & Context
A selection of primary and specialist sources used to contextualize this Perspective. Manufacturer statements are treated as such and are not equated with independent evidence.