Humanoid robots are increasingly being positioned as a solution to labour shortages, repetitive work and operational inefficiency in warehouses, factories, data centres and other enterprise settings.
But the technology is raising a more consequential question for buyers: can they safely deploy machines that move through sensitive sites, collect rich environmental data, connect to cloud platforms and receive remote software and AI-model updates?
The concern is no longer theoretical.
Security researchers have disclosed flaws in commercial robot platforms that could enable unauthorised access or expose sensitive data. Separately, a high-profile data-governance failure involving development versions of iRobot’s Roomba robot vacuum showed how imagery gathered by a sensor-equipped robot can travel beyond the setting in which it was collected.
Meanwhile, the Trump administration’s recent restrictions on new foreign-made humanoid robots have intensified the debate over whether the origin of an advanced robot presents a national-security or enterprise-risk issue.
For business buyers, however, the security challenge is broader than the country in which a robot was assembled. A modern humanoid is a mobile cyber-physical platform: it may contain cameras, microphones, LiDAR, thermal sensors, wireless connectivity, AI inference tools, cloud links, third-party software components and over-the-air update mechanisms.
That combination creates a potential path to surveillance, operational disruption, data theft or movement between corporate IT and operational tech (OT) environments. It also introduces a newer form of dependency: a robot’s most valuable capabilities may rely on an external AI model whose availability could be affected by a vendor decision, export control or regulation.
The practical takeaway is obvious. Enterprises must secure the entire robotic stack – the machine, its data, its networks, its remote-access arrangements, its update path and its AI-model dependencies – before it is allowed to move through a sensitive workplace.
From Fixed Machinery to Mobile Data Collection
Traditional industrial robots are already a cybersecurity concern.
Robot controllers, remote-access systems and legacy industrial networks can contain vulnerabilities. An attacker who gains control of a fixed robotic arm or related OT system could disrupt production, damage equipment or create safety risks.
However, most traditional robots have a relatively constrained operating model. They are installed in a known location, perform a defined task and are often isolated within a fenced production cell or a dedicated industrial network.
Humanoid robots and other autonomous mobile systems are designed to work differently. They can travel through environments built for people, including warehouse aisles, factory floors, loading bays, offices, corridors, stockrooms and potentially server or data-storage areas.
To move safely, they need to understand their surroundings. That can involve cameras, microphones, LiDAR, depth sensors, thermal imaging, mapping tools and environmental telemetry. Those capabilities are commercially useful. They can also create a substantially richer data-collection footprint.
“Humanoid robots add mobility to the data-gathering process,” said Stanislav Kazanov, Head of GRC, Cybersecurity & Sustainability and Head of Data at digital engineering company Innowise.
“The takeaway for those in charge of operational technology risk is a shift from worrying about fixed machine failure to planning for active data capture via multiple sensors.”
Kazanov said that, unlike fixed robotic arms “confined to obsolete factory sub-networks,” humanoids may move through corporate buildings, logistics centres and data-storage sites while collecting high-resolution LiDAR, thermal imagery and audio that can build a picture of physical layouts and operations.
That information can be highly sensitive. Mapping data may reveal restricted areas, access routes, security controls, high-value inventory locations, equipment configurations or operational bottlenecks. Cameras can capture screens, documents, whiteboards, ID badges and visitor details. Audio may record conversations. Thermal data can reveal occupancy patterns or machinery use.
The issue is not that every robot will automatically collect and export every available form of data. Responsible deployments should minimise what is captured and tightly control where it goes. The risk is that a compromised platform, an overly permissive fleet-management system or a poorly governed data pipeline can turn legitimate sensors into tools for reconnaissance.
“If a robot is compromised, it does not only present a danger of physical collision or damage but rather act as a rogue insider,” Kazanov said.
That is the central shift for security leaders. A compromised device does not necessarily need to defeat an external perimeter. It may already be inside the facility, trusted by staff, connected to a fleet-management service and physically able to observe areas that an external attacker cannot reach.
With weak network controls, the robot could become a route for unauthorised wireless activity, credential capture through visual data, site mapping or data exfiltration through connected cloud systems. Robust segmentation can prevent a mobile robot from reaching sensitive OT assets. But mobility makes poor segmentation and unmanaged sensor data far more consequential.
The Real-World Warning Signs
The robot-security risk has already moved beyond academic theory.
In 2025, security researchers disclosed issues involving Unitree’s G1, a commercially available humanoid platform. Research around the device identified security and privacy concerns that included Bluetooth-related weaknesses and questions around telemetry.
The significance of the case is not that every Unitree robot has been compromised in the wild, nor that humanoid robots are inherently unsafe. It is that a commercial humanoid platform has already been subject to public security scrutiny over the precise areas that enterprise buyers must assess: remote access, wireless communications, telemetry, data exposure and fleet-level risk.
The risk posed by robot-generated data has also been demonstrated outside industrial settings.
In 2022, MIT Technology Review reported that images captured by development versions of iRobot’s Roomba J7 robot vacuum had been sent to data-labelling contractors and subsequently shared online. The images included sensitive household scenes. iRobot said the units involved were development devices and were not intended for retail sale.
It was not a conventional hacking incident. But it is an important example of a related failure: data from a camera-equipped robot passing into a third-party AI-development and labelling ecosystem without sufficient protection.
For enterprise buyers, the lesson is direct. Whether a data leak arises from a cyberattack, weak vendor governance, excessive collection, poorly controlled training data or human error at a subcontractor, the operational outcome may be similar. Sensitive imagery, audio, maps or telemetry may leave the environment in which the robot was deployed.
Fixed industrial robots have also shown why robotics cannot be treated as a simple hardware-security problem. Security research involving industrial robot controllers, including ABB systems, has found vulnerabilities capable of exposing controller functions or enabling unauthorised manipulation under certain conditions.
The difference with humanoids and other mobile autonomous robots is the combination of those established OT security risks with a roaming physical presence, more extensive sensing and cloud-connected AI capabilities.
Not Just a Humanoid Issue
Elvis Nava, co-founder and CTO at Mimic Robotics, cautioned against isolating humanoids as a uniquely risky category.
“I wouldn’t single out humanoids, but any kind of ‘smart’ or AI-driven robot,” he said.
That includes autonomous mobile robots, quadrupeds, warehouse platforms, inspection machines, drones and other connected devices that merge movement, perception, artificial intelligence and remote management.
Nava said the newer generation of robots has more extensive telemetry by default. “So ‘hacked’ robots could indeed allow attackers for more access to sensitive information,” he said.
Their attack surface is also greater than that of older automation, Nava added, because their software stacks include more components: cloud integration, AI inference systems, over-the-air software updates and model updates.
Every one of those elements is useful. Cloud platforms allow enterprises to monitor fleet performance, diagnose faults and manage large deployments. Remote support can reduce downtime. Over-the-air updates can fix vulnerabilities and improve performance. Model updates can improve navigation, perception and task handling.
But each element creates dependencies that require governance.




