Be upfront about what's on the table: neither of today's two general-robotics headlines is a new humanoid launch. One is an IEEE Spectrum piece on rethinking robot safety in the age of AI, sponsored content from cybersecurity firm VicOne. The other is Robohub's roundup of keynote and plenary talks from ICRA 2026 in Vienna. Neither mentions a specific bipedal robot by name. But both bear directly on the question that actually decides whether a business puts a humanoid on its floor: can you trust the thing to behave the way you expect, even when someone -- or something -- is actively trying to make it do otherwise?
IEEE Spectrum's piece frames a shift that's easy to miss if you're only tracking hardware demos: robot safety used to be an engineering question -- does the machine fail gracefully when a motor jams or a sensor drops out? Physical AI adds a much uglier question -- does the machine stay safe when an attacker manipulates what it perceives, decides, or does, without anything visibly breaking? For a wheeled warehouse cart, that's a serious problem. For a humanoid working alongside people -- lifting, walking, gripping -- it's an existential one, because the failure mode isn't a stalled conveyor belt, it's a machine with human-scale strength misjudging what's in front of it. We've argued before that Digit 5's safety pitch is the real humanoid story, and this piece is the security-side companion to that argument: mechanical safety and adversarial-AI safety are now the same conversation, and vendors who only talk about the former are answering half the question buyers are actually asking.
My honest take: most humanoid marketing still leans on backflips and warehouse montages, and this article is a useful reminder that the boring stuff -- perception integrity, decision auditability, attack surface -- is what will actually gate enterprise adoption. A business evaluating a humanoid for a factory floor or a hospital corridor should be asking its vendor pointed questions about how the robot's AI pipeline is secured, not just how many kilograms it can carry. That's not a hypothetical concern for us either -- it's the same reasoning behind why we treat platform security as core infrastructure rather than an add-on, whether the software is running a CRM or, someday, a robot's decision loop.
The ICRA 2026 keynote and plenary recordings, now public via Robohub, are a genuinely useful resource -- Vienna's conference is one of the few venues where you get research-grade robotics thinking without a product pitch attached. I'd encourage any operations leader seriously evaluating robotics vendors to skim a talk or two rather than relying on press releases; it's a faster way to calibrate what's actually hard right now versus what's marketing gloss. But it's worth noting what a keynote roundup can't give you: a business case. Academic conferences are where the next five years of capability get seeded, not where this quarter's purchasing decisions get made. The gap between what a keynote demonstrates in a lab in Vienna and what a robot can reliably do on a loading dock in Ohio is still the whole ballgame, and that gap is exactly where security and reliability -- not raw capability -- decide who wins deployments.
Put the two stories together and you get a clearer picture than either gives alone: humanoid robotics is entering the phase where the interesting problems are no longer just 'can it walk' but 'can it be trusted with an adversary in the loop,' and the research community knows it even if the marketing hasn't fully caught up. That's a healthy sign, even if it makes for less exciting headlines than a robot climbing a wall.
If your business is weighing a humanoid pilot in the next year, what would it take for you to trust the robot's decisions as much as you'd trust its balance?
Sources