Humanoid Safety: What We Know, and What We Still Don't

What we already understand, what we are still learning, and why hardware design matters

I've been asked several times to talk and write about humanoid safety, but I have been waiting for a while before writing about it. The topic is tricky because, to properly understand safety in humanoids, I think you need more than a robot in a lab. You need several robots, preferably different types, deployed in the field, doing real work, failing in different ways, interacting with different people, and operating in environments that were not perfectly prepared for them. We simply do not have enough of that yet.

My own field is mainly hardware design and human-robot interaction, or HRI, and that is where most of my experience comes from. But humanoid safety is much broader than mechanics, elastic actuators, external body design, pinch points and robot behavior. It also includes perception, locomotion, functional safety, control, cybersecurity, human factors, learned policies, fault management, standards, and probably several things we have not properly identified yet.

There is already a significant body of research around industrial robot safety, collaborative robotics and physical human-robot interaction. What we have much less of is safety knowledge validated on full-size humanoids operating for thousands of hours around people. That particular combination is still relatively new, and I think we need a few more years before we properly understand it. We will probably need to break a few dozen humanoids along the way, and perhaps a few bones too, metaphorically and, unfortunately, maybe literally.

There are already some things we know. We know that an actuator powerful enough to support the body weight of a humanoid, accelerate its limbs and lift another 10 or 20 kg can also generate enough force and energy to seriously injure a person. We also know that an emergency stop is not as simple on a humanoid as it is on a conventional industrial machine. Cutting power to a standing or walking biped may turn a controlled robot into an uncontrolled falling object. Recent work has started framing this as a safe-stoppability problem: can the machine actually reach a minimum-risk state from its current dynamic condition? [1]

We also know something useful from our own bodies. The human body is surprisingly good at physical interaction. We have soft tissue, compliant joints, distributed sensing and a neuromuscular system that continuously changes joint impedance. We become stiff when required and compliant when contact demands it. Robots are still much worse at this, and despite everything we already understand, there is much more that we do not know. In fact, we do not know what we do not know, and that is probably the most interesting part of humanoid safety today.

A quick map of humanoid safety

Before going deeper into hardware and HRI, I would separate humanoid safety into roughly six areas.

Mechanical and contact safety covers collision, clamping, crushing, sharp geometry, actuator forces, impact energy and what physically happens when the robot touches a human. Balance and fall safety covers balance recovery, safe stopping, controlled falling and what happens when a 60, 80 or 120 kg machine can no longer remain upright. Fall prediction and controlled fall strategies are already their own research area. [2]

Perception safety asks whether the robot can reliably detect humans, obstacles, contact and uncertainty around itself. Importantly, "nothing detected" and "I cannot see this area" are not the same state. Control and autonomy safety includes hard constraints around learned controllers, joint limits, collision avoidance and runtime safety filters such as control barrier functions. Work such as SHIELD has demonstrated this type of architecture on Unitree G1. [3]

Functional safety and cybersecurity deal with failures underneath the behavior, including communication loss, encoder faults, software crashes, corrupted commands and ensuring that a failure in high-level intelligence does not automatically become unrestricted physical motion. Finally, human-robot interaction safety asks whether humans can understand what the machine is doing, anticipate what it will do next, and behave safely around it.

That last area overlaps heavily with hardware design, which is where I want to spend most of the rest of this article.

The hardware is part of the safety system

I have argued before that a humanoid should not be understood as a collection of isolated components. Complexity compounds. Legs affect manipulation, payload affects stability, perception affects movement, and mechanical design affects control. I discussed this more broadly in Robotics Complexity vs Versatility: Why Robots Are Converging. The same logic applies to safety. A safe actuator inside a dangerous mechanical geometry does not produce a safe robot. Neither does a soft cover over a rigid high-energy structure, nor excellent collision detection if the human's finger is already trapped somewhere from which it cannot escape. The complete physical system matters.

Start with the actuator, but don't stop there

The obvious starting point is actuation. High gear ratios can make an actuator difficult to backdrive. Large reflected inertia means that a relatively light-looking arm can behave like a much heavier object during impact. High stiffness improves positioning accuracy, but can also increase peak collision loads. This is why backdrivability, torque sensing, series elastic actuation and impedance control keep appearing in discussions around physical HRI.

But compliance is not binary. A knee supporting the robot's full body weight probably should not behave like a compliant finger. The required stiffness, torque bandwidth and backdrivability depend on where the actuator is in the body and what sort of contact we expect there. I made a similar argument in What Is a Humanoid, and at What Point Does It Stop Being One?: compliance is most valuable where interaction occurs, and the entire machine does not need identical mechanical behavior.

This is also where effective mass becomes important. What matters during a collision is not simply the total mass printed on the robot's datasheet. The configuration of the arm, inertia of the links, velocity, joint stiffness and controller all determine the energy transferred at the contact point. A 3 kg forearm connected to the wrong mechanical architecture can behave much worse than its 3 kg suggests.

Softness is not foam

I've already written an entire article, Humanoids Can't Get Too Far Without Softness, around one hypothesis: human environments are designed not only around human dimensions, but around bodies that deform. I think this becomes even more important when discussing safety.

When people hear "soft robot", they often imagine putting foam over the machine, but that is only one layer. There is surface softness, such as foam, silicone, fabric or elastomeric covers. There is structural compliance, where the mechanical structure itself can deflect. There is actuator compliance, through elastic transmission, backdrivability or variable stiffness. And there is control compliance, where impedance or force control lets the robot yield to contact. The best system probably combines several of these rather than relying on one.

A soft external layer can reduce peak pressure, increase the contact area and absorb some energy before the rigid structure underneath reaches the human, but softness creates its own engineering problems. Make the material too thick and it changes dimensions and kinematics. Make it too soft and it may interfere with tactile sensing or accurate manipulation. A soft shell can trap heat, tear, become dirty in industrial environments, catch on sharp objects, hide structural damage underneath, or deform into new pinch geometries.

Recent tactile-skin research is increasingly treating this as a trade-off between impact attenuation and sensing performance, rather than assuming that softer is automatically better. For example, SkinAxis combines dissipative elastomer layers with a force-sensing structure specifically to balance impact mitigation with useful touch sensitivity. [4]

This is the direction I expect humanoid skin to go. Not skin for realism, but skin as an engineered mechanical and sensing interface. That connects directly to another idea from The Wrong Way to Design a Humanoid: copy the useful interface, not necessarily the biological implementation underneath it. We do not need artificial human tissue. We need the useful mechanical properties human tissue gives us.

Finger traps are probably going to become a much bigger discussion

This is one of those boring design details that becomes very interesting once robots leave the lab. A humanoid has an enormous number of moving gaps: between elbow covers, around shoulders, between the torso and upper arm, at the neck, behind the knee, around fingers, between fingers, between an end effector and the object it is holding, and between the robot and the environment. Any of these can potentially become a pinch, shear or crush point.

The dangerous geometry is not always visible when the robot is standing in its neutral CAD pose. A completely acceptable gap at zero degrees can become a finger trap at 60 degrees of joint rotation. Two panels can move toward each other. A soft cover can fold inward. A cable can become exposed. A person's hand can enter a large opening that subsequently becomes a small opening.

This is why the correct design question is not simply whether the robot has gaps. Of course it does. The better question is: what can enter this gap, and what happens to that object over the complete range of motion?

This applies beyond fingers as well. Loose clothing, gloves, hair, necklaces, ID lanyards and cables create very different trapping scenarios. ISO guidance for collaborative contact explicitly treats pinching and crushing differently from free impacts, and identifies robot links, joints, housings, grippers, workpieces and environmental structures as potential contact locations. [5]

For humanoids, I think we eventually need something close to a whole-body trapping map. Run the robot through its full workspace and deliberately search for every converging gap, shear edge and geometry where a human body part could enter. Do it standing, crouching, carrying an object, working against a table, next to shelving, and during recovery from a stumble. CAD clearance alone is not enough.

The panels themselves matter

Humanoid companies understandably want clean external surfaces. You want to cover cables, actuators, gearboxes, sensors and ugly engineering. There are good reasons for this. Covers protect hardware, prevent contamination and can remove direct access to moving mechanisms.

But covering everything creates another design question: how much of the robot's mechanical state should remain visually readable?

Human beings understand bodies partly because we can see their geometry. I can usually tell where your elbow is, which direction your knee bends, and where your hand is pointing. A humanoid with continuous sculpted panels can hide some of this information. This is not an argument for exposed gearboxes. It is an argument for making articulation legible.

Panel seams can follow joint axes. Changes in material can indicate moving regions. Forms can make the bending direction understandable. High-risk interfaces should not visually disappear into one continuous volume. Even the location of a robot's front and back should be obvious.

This connects directly to an argument I made in A Humanoid Robot Is Judged Against a Human, Not a Machine: the body is already communicating before the robot performs any task. Appearance creates a mental model of capability. I would extend that idea here. Appearance also creates a mental model of motion. If the mechanical design makes that motion difficult to predict, then styling has become a safety problem.

Safety information also needs to be visible

There is another meaning of visibility. Imagine you approach a humanoid from behind. Can you immediately understand whether it is powered off, powered on but stationary, autonomous, waiting for you, about to move, faulted, being teleoperated, or executing an emergency behavior?

A single screen on the chest does not solve this if you cannot see the chest. Industrial machines traditionally use tower lights partly because machine state needs to be visible from many directions. Research on robot light skins has shown that moving the status indication onto the robot body can improve awareness and reaction time compared with conventional external signaling. [6] More recent work also suggests that anticipatory visual cues can improve people's ability to predict upcoming robot motion and can improve safety and collaboration. [7]

For humanoids, I think the interesting design opportunity is to combine this communication with the body itself. A light near the shoulder can communicate arm activation. A directional cue can show where the robot intends to move. A visible gaze direction can indicate the object the robot is about to manipulate. Distributed lighting can communicate global machine state regardless of where the observer is standing.

But we need to be careful. If every body part starts blinking different colors, we have built a Christmas tree, not a safety interface. The information hierarchy has to remain extremely simple.

Agility's Digit 5 is an interesting recent example

This is why I find Agility Robotics' newly announced Digit 5, sometimes referred to as V5, particularly interesting. Not because it has solved humanoid safety. It has not, and Agility itself states that certain Digit 5 safety features are still in development. What is interesting is the architecture.

Agility describes safe human detection using multiple sensor technologies, with the robot able to avoid a person, stop, or assume a seated position. Digit 5 also uses visual and auditory safety cues intended to communicate motion intent to nearby humans.

This builds on earlier work in Digit where Agility added an onboard safety PLC and a Category 1 stop. Rather than instantly removing actuator power, a Category 1 stop maintains power during controlled deceleration and then removes it. Agility has openly described how an earlier external safety controller could create a new hazard: communication loss could make the robot fall.

That is exactly the kind of engineering evolution I think we need to study. A safety mechanism created a new failure mode, deployment exposed it, and the architecture changed.

Digit 5 is also explicitly being developed around what Agility calls cooperative safety, with the ambition of reducing dependence on conventional physical barriers. Whether the complete system achieves that reliably at scale still needs evidence, but the direction is important because the robot is starting to treat safety as a whole-body behavior rather than an external button.

Hands are probably the highest-density safety problem on the robot

I spend a lot of time thinking about robotic hands because they concentrate almost every humanoid safety problem into a very small volume. They combine high forces, small radii, small contact areas, multiple actuators, many pinch points, frequent human contact, occluded interaction, object manipulation, and increasingly autonomous behavior.

A finger moving at modest speed may have relatively little kinetic energy, but trapping someone's skin or fingertip between two robotic fingers is a completely different contact mode. Then there is the object. A safe hand holding a screwdriver is no longer the same mechanical system. A safe hand carrying a sheet of glass is not the same system. A safe hand carrying a 10 kg metal component is not the same system.

This is why safety analysis based only on the naked robot is incomplete. The workpiece becomes part of the robot's effective geometry.

During a handover, there is another problem: when exactly should the robot release? Too late and you create a tug-of-war. Too early and you drop the object. Research has explored using both load transfer and pulling force rather than a single cue before release. [8]

This is also why I remain interested in tactile sensing. As I noted in my 2025 robotics review, tactile sensing attracted a large amount of development activity, but integration remains one of the major challenges. Vision becomes least reliable precisely when the hand is in close contact with something. That is where haptics becomes valuable.

Falling deserves mechanical design too

Fall safety is usually discussed as a control problem, but it is also a product-design problem. If a humanoid falls into another person, which part contacts them first? Is it the head, shoulder, elbow, hand, battery enclosure, or a sharp corner of the pelvis? The answer depends partly on control, but also on geometry.

Rounded shoulders, compliant external structures and controlled energy-absorbing regions can change the consequences of a fall. Potential contact zones can be treated differently from protected internal zones. This is similar to automotive crash design. You do not make the entire car soft. You decide where deformation is useful, where stiffness is necessary, and how energy should move through the structure.

Humanoid designers may eventually need a similar concept. Not simply impact resistant, but impact managed.

HRI safety is partly about prediction

The final layer is behavior. I do not think we should expect humans to constantly calculate where a humanoid's collision boundary is. Humans do not interact that way. We predict one another.

If somebody reaches toward a glass, you understand the motion before their fingers arrive. If somebody suddenly steps backward, your body reacts. If somebody turns their torso toward you, you know they may enter your space. Robots need some equivalent of this motion legibility.

Research suggests that explicit anticipatory cues can improve human prediction of robot actions. Other recent HRI work is directly comparing body motion, lights, text and audio as ways to communicate upcoming navigation intent.

This is where the distinction between appearance and behavior becomes important. I previously argued that every anthropomorphic feature is a promise. Eyes promise attention. Hands promise dexterity. A face promises social responsiveness. For safety, I would add that movement promises intention.

If the robot looks toward one place and reaches toward another, that is confusing. If its torso rotates without a visible pre-cue, that can surprise people. If the machine can move backward as quickly as forward, the human needs some way of understanding that. If a robot is about to stand up from a crouched position, perhaps the people around it should be able to anticipate that before 100 kg of machine starts moving vertically.

Sometimes the safest motion is not the slowest motion. It is the motion people can correctly predict.

Safety creates trade-offs

There is a temptation to think that every added safety feature makes the system safer, but it does not. A thicker cover increases impact compliance but may reduce cooling. A very soft fingertip can increase friction but reduce manipulation precision. A guard can eliminate one pinch point and create another. A high-visibility shell can become visually noisy. A slower robot can be easier to avoid but can also become frustrating enough that people start bypassing its safety systems. An E-stop can remove power and make the robot fall, while a highly conservative collision controller can make robot motion so hesitant and unpredictable that humans struggle to coordinate with it.

This is why humanoid safety is not a checklist of safety components. It is system design.

That should not surprise us. As I have argued elsewhere, humanoids are fundamentally integration problems. The value comes from multiple capabilities working together, but the dependencies between those capabilities are also where much of the engineering difficulty appears. Safety is another one of those dependencies.

Where we are today

The standards are also still catching up. Industrial robot standards such as ISO 10218 provide a great deal of useful knowledge, while ISO 13482 addresses service robots. Collaborative-robot work, including ISO/TS 15066 and ISO/PAS 5672, also gives us valuable methods for thinking about impact, pinching, crushing and biomechanical limits.

But the modern humanoid combines categories that were historically easier to separate. It is a manipulator, a mobile robot, a dynamically balancing machine, an increasingly autonomous system and, increasingly, a machine expected to handle tools and objects while sharing space directly with people.

I do not think we yet have enough field experience to say what the final safety architecture for that machine will look like. But I am increasingly convinced that the answer will not come from one breakthrough sensor, one AI safety layer, or one standard. It will come from many relatively boring decisions working together: a rounded edge, a compliant joint, a carefully designed 8 mm gap, a panel that makes an elbow axis visible, a tactile surface, a light that tells you the robot is about to move, a controller that knows when not to cut power, a hand that knows you have actually taken the object, and a shoulder designed to hit you less badly if everything else fails.

None of these is particularly impressive in isolation. Together, they might be what makes humanoids boring enough to safely work around us. And perhaps that should be the objective: not making the safest-looking humanoid, but making a humanoid that, after a few thousand hours around it, people stop thinking about safety at all.

A note on the overview

The introductory overview and literature references in this article were prepared with the help of AI for search and reference collection. I reviewed the technical direction, but this is deliberately not intended to be an exhaustive academic literature review.

This article was originally requested by some of my VC clients, so I have intentionally kept the broader safety taxonomy relatively shallow and focused more heavily on hardware design and HRI, where most of my practical experience sits.

Selected references

[1] Learning Safe-Stoppability Monitors for Humanoid Robots, 2026. Safe-stoppability monitoring for dynamic humanoids.

[2] Subburaman et al., A Survey on Control of Humanoid Fall Over, Robotics and Autonomous Systems, 2023.

[3] Yang et al., SHIELD: Safety on Humanoids via CBFs In Expectation on Learned Dynamics, 2025.

[4] SkinAxis: 3D force-sensing soft robotic skins balancing touch sensitivity and impact protection for safe pHRC, Frontiers in Robotics and AI, 2026.

[5] ISO/PAS 5672:2023, collaborative robot force and pressure measurement guidance, including pinch and crush contacts.

[6] The development and evaluation of Robot Light Skin, Robotics and Computer-Integrated Manufacturing.

[7] Psarakis, Nathanael & Marmaras, Communicating robots' intent through visual cues enhances human anticipatory behavior in human-dual robot collaboration, Robotics and Computer-Integrated Manufacturing, 2025.

[8] Handover Control for Human-Robot and Robot-Robot Collaboration, Frontiers in Robotics and AI, 2021.

Related writing

Humanoids Can't Get Too Far Without Softness, on softness as part of the human-compatible interface.

The Wrong Way to Design a Humanoid, on copying useful biological interfaces rather than biology itself.

A Humanoid Robot Is Judged Against a Human, Not a Machine, on appearance, expectations, capability signaling and functional human-likeness.

What Is a Humanoid, and at What Point Does It Stop Being One?, on morphology, compliance, tactile sensing and human-compatible design.

Robotics Complexity vs Versatility: Why Robots Are Converging, on the systems-engineering cost created when mobility, manipulation, perception and autonomy become one machine.

Next
Next

Are We Building Robotics Backwards?