Reference resource

This page covers the essential concepts and links to more specialised resources. Capabilities, constraints and rules must always be checked against the relevant site and use case.

The short answer: security assistant, yes; autonomous guard, no

The human form has a theoretical advantage. Buildings are designed around legs, arms and hands. A humanoid may climb stairs, open a door, press a button, move an object or use equipment designed for people.

That advantage is not enough to create a security officer. Security requires high availability, repeatable navigation, reliable perception at night, environmental resilience, secure communications and prepared response procedures. Most importantly, it requires judgement. A guard must distinguish a lost visitor from an intruder, assess conflict and know when to call a person or the police. For verification, see CISA · secure AI integration into operational technology.

In 2026, leading humanoids mainly demonstrate narrow capabilities in factories, warehouses, laboratories and selected homes. Those results matter. They do not demonstrate general security autonomy. For verification, see Figure · BMW production results.

The NIST Humanoid Robot Baseline Performance Benchmark also highlights the need for rigorous, comparable measurement. A polished video or public demonstration is not a substitute for repeated testing at the intended site. For verification, see NIST · humanoid robot baseline performance benchmark.

For most current security missions, a wheeled robot, quadruped or automated drone remains simpler, more mature and easier to secure. For verification, see Unitree H2 · official page.

Explore this topic

What 2026 deployments actually prove

The strongest evidence comes from logistics and manufacturing. Agility Robotics reports that Digit moved more than 100,000 totes in a commercial GXO deployment. Figure reports that Figure 02 accumulated more than 1,250 operating hours and loaded more than 90,000 parts on a BMW production line. For verification, see Agility Robotics Digit · 100,000 totes.

Boston Dynamics introduced the product version of Atlas in 2026, with initial industrial deployments announced. UBTECH presents Walker S2 as a mass-produced industrial humanoid used for handling and assembly. For verification, see UBTECH Walker S2 · official page and Boston Dynamics Atlas · official page.

These results show progress in walking, grasping, balance and workflow integration. They still concern prepared tasks, known objects, mapped areas and controlled procedures. Security introduces rare, ambiguous and potentially adversarial events. That is a different problem.

In China, EngineAI PM01 and SE01 walked beside police officers during a Shenzhen event in 2025. The public source documents their presence and movement. It does not document autonomous incident assessment or police powers. This was an accompanied demonstration, not an operational guard. For verification, see Shenzhen · PM01 and SE01 demonstration.

In the United States, RAD announced development of HERO as a security-focused humanoid. The announcement sets out patrol and interaction ambitions. It does not prove that a commercial fleet has completed sustained, measured security operations. For verification, see RAD HERO · official announcement.

Humanoids worth monitoring for security

This list does not rank robots by spectacle. It separates industrial evidence, security-themed demonstrations and ambitions that remain unverified. None should currently be presented as a proven replacement for a security officer.

Publicly verifiable status on 9 August 2026
PlatformRegionVerifiable statusSecurity relevanceWhat it does not prove
EngineAI PM01 and SE01ChinaAppeared beside police during a Shenzhen eventPublic-space walking and symbolic participation in a human patrolNo evidence of autonomous duties or intervention
Unitree H2, H1 and G1ChinaDeveloper and commercial platformsPotential bases for research, teleoperation and sensor integrationNo manufacturer-documented security deployment
UBTECH Walker S2ChinaMass production, delivery and industrial tasksEnergy management, manipulation and factory operationNo proven security patrol
XPENG IRONChinaAdvanced development and announced scenariosInteraction, walking and proposed inspectionNo documented operational security service
Agility Robotics DigitUnited StatesCommercial logistics deployment and over 100,000 totes moved according to the companyEvidence of repeatability in a physical taskNo patrol or incident response
Figure 03United StatesNew generation informed by Figure 02 industrial workCoordinated locomotion and manipulationNo documented security mission
Boston Dynamics AtlasUnited StatesProduct version introduced in 2026Fleet integration, manipulation and battery exchangeNo demonstrated security offering
Apptronik Apollo 2United StatesIndustrial platform and announced pilotsModular mobility and manipulationNo demonstrated availability as a guard
1X NEONorway and United StatesHome humanoid with remote human assistanceShows the importance of human recoveryDesigned for homes, not security
RAD HEROUnited StatesAnnounced in development as a security humanoidDirectly security-focused positioningInsufficient evidence of sustained deployment
Tesla OptimusUnited StatesGeneral-purpose programme for repetitive or unsafe workPotential manufacturing scaleNo documented security-guard deployment

For a deeper analysis, read Security robots. Platforms currently best suited to patrols.

Tasks that may be plausible in a controlled pilot

Indoor patrol on a stable route

A humanoid may follow a defined corridor, stop at checkpoints, transmit images and return to its station. Doors, reflections, moved objects, people and network loss must be included in the test. Human recovery remains necessary.

Remote alarm assessment

After an alarm, an operator may send the robot to observe an area, transmit thermal or visible imagery and establish communication. The robot acts as a mobile sensor. It should not decide that a person is dangerous.

Telepresence and information

A remote operator may speak through the robot, provide directions or ask a visitor to wait. Messages should be prepared. An open-ended language model should not improvise threats, accusations or legal instructions.

Simple manipulation

A robot may press an approved button, present a reader, move a light object, open a compatible door or carry a sensor. Every action must be validated in the exact configuration. A hand shown in a video is not proof that the robot can operate every lock.

Combined technical inspection

A humanoid may read a display, observe an indicator or carry a sensor before or after a security round. Sharing the platform with maintenance may improve utilisation, provided purposes and data access remain separate. For verification, see Apptronik Apollo 2 · official page.

Tasks that should not be delegated

In 2026, a humanoid should not autonomously decide that a person is suspicious or dangerous, chase, block, restrain or search someone, use a weapon, intervene alone in a confrontation or patrol an uncontrolled crowd.

It should not make consequential access decisions without human review, replace human judgement during a fire, record ambient audio continuously, use facial recognition without a specific assessment or continue when localisation, sensors or communications are unreliable.

A responsible architecture stops safely, preserves distance and escalates to people. It should not attempt to make the robot intimidating. For verification, see 1X NEO · official page.

Humanoid, wheeled robot, quadruped or drone?

If the mission only requires video and alerts on a flat surface, the humanoid form adds little. It becomes relevant when stairs or manipulation of human equipment are the actual problem.

Match robot form to mission
CriterionHumanoidWheeled robotQuadrupedAutomated drone
Flat, structured groundPossible, often unnecessarily complexExcellentGoodNot relevant on the ground
Stairs and human infrastructureHigh potential, still route-dependentPoorVery good depending on platformAvoids some ground obstacles
Door and object manipulationMain theoretical advantageLimited without an armLimited without an armVery limited
Rapid view of a large perimeterLow to mediumMediumMediumExcellent
Endurance and simplicityCurrently disadvantagedGenerally strongestMediumLimited by flight and charging
Outdoor resilienceLittle proven evidenceModel-dependentOften strongest on the groundWeather and regulation dependent
Physical risk near peopleHigh if the robot falls or moves an armEasier to contain at low speedDepends on mass and gaitSpecific aerial risk
Security maturityVery lowHigh for several productsMedium for inspection and assessmentHigh for selected industrial sites
Best current useExperimental manipulation in controlled facilitiesRegular patrol on prepared groundComplex terrain and inspectionRapid assessment of large areas
Explore this topic

For a deeper analysis, read Quadruped comparison. X30, B2, ANYmal and Spot for industrial needs.

Physical safety must remain independent from robot intelligence

A humanoid combines mobile mass, powerful joints, hands and sometimes an AI model that interprets instructions. A software failure can therefore create physical motion.

Emergency stopping, speed limits, exclusion zones, person detection and force limits should not depend solely on the AI model. They need an independent, testable control layer.

ISO 10218-1:2025 covers industrial robot safety. ISO 13482 addresses certain service robots operating near people. Work continues for dynamically stable industrial mobile robots, including legged systems. A generic certification claim is not enough for a mobile humanoid in a shared space. For verification, see ISO 10218-1:2025 · industrial robot safety.

The pilot should record falls, stops, contacts, localisation loss, human interventions and post-update behaviour. Emergency-stop access and safe recovery after power or network failure must be tested.

Cybersecurity: remote compromise can become physical harm

The attack surface includes the robot, docking station, operator console, cloud accounts, APIs, maps, video, microphones, software updates and access-control integrations.

AI should be a supervised system function, not the only safety barrier. An AI API should never be able to bypass physical safety limits.

Minimum controls before a pilot

The device must remain controllable after a cloud or network loss.

  • Dedicated network segmentation.
  • Named accounts, strong authentication and least privilege.
  • Encrypted communications and logged remote commands.
  • Time-limited supplier access.
  • Signed updates and tested rollback.
  • A vulnerability-response policy and software bill of materials.
  • A safe mode that does not require an AI response.
  • Tested recovery, access revocation and supplier exit.

For a deeper analysis, read Swiss framework. Data protection, employment, liability and cybersecurity.

In Switzerland, the robot remains a tool, not a licensed officer

Swiss law gives humanoids no special status. When a person can be identified, the Federal Act on Data Protection applies. A mobile robot must comply with purpose limitation, proportionality, transparency, security and privacy by design. For verification, see Swiss Federal Act on Data Protection.

The FDPIC states that private video surveillance should remain on the controller’s property and avoid unnecessary recording of public space or neighbours. In the workplace, systems intended to monitor employee behaviour are prohibited. A route that is proportionate at night may become excessive while staff are present. For verification, see FDPIC · video surveillance in the workplace.

If AI identifies, classifies or tracks people, purpose, data sources and errors must be documented. A data protection impact assessment may be required for high-risk processing. A fully automated consequential decision also creates rights to information and human review.

In several French-speaking cantons, the Concordat on security companies defines a security officer as a natural person and subjects security activities to authorisation. A robot does not become a licensed officer by wearing a uniform or speaking to the public. It may be a technical tool used under the responsibility of authorised companies and people. For verification, see Concordat on security companies.

The manufacturer, integrator, operator, monitoring provider and remote operator must allocate responsibilities. This section provides general information, not legal advice.

Explore this topic

For a deeper analysis, read AI and surveillance. Design explainable and supervised functions.

A realistic horizon and criteria before a pilot

A tightly controlled pilot may be reasonable now when the mission genuinely requires arms, hands or movement through human infrastructure, the supplier can repeat the exact task and a person retains authority, remote control and intervention.

Between 2027 and 2029, some industrial humanoids may become security assistants in controlled facilities. They may combine inspection, manipulation and alarm assessment. Progress will depend on measured availability, standards, local service, insurance and cybersecurity.

There is no credible date for a humanoid that completely replaces a security officer. The horizon should be defined by evidence, not a promised year.

Twelve criteria before approving a pilot

A successful demonstration starts the assessment. It does not complete it.

  • Real need: why a humanoid rather than a simpler platform?
  • Bounded task: which route, object and decisions are allowed?
  • Repeated proof: how many full cycles without hidden assistance?
  • Declared autonomy: which actions are autonomous or teleoperated?
  • Physical safety: mass, speed, force, fall and emergency stop.
  • Availability: mission completion and interventions per shift.
  • Environment: lighting, doors, stairs, floors, weather, people and network.
  • Cybersecurity: accounts, segmentation, updates and logs.
  • Privacy: field of view, audio, biometrics, retention and transfers.
  • Human governance: responsible operator, escalation and no autonomous force.
  • Support: parts, technicians, service levels, insurance and end of service.
  • Stop criteria: events that immediately suspend the pilot.

Frequently asked questions

Can a humanoid robot replace a security guard?

Not in 2026. It can perform a limited task, transmit observations and provide telepresence. People still need to assess, decide and intervene.

Are humanoid police robots already deployed?

Humanoids have accompanied police during demonstrations and events, including in Shenzhen. This is not evidence that they independently perform police or security powers.

Which humanoid is closest to a security use case?

No platform has enough public evidence to recommend it as an autonomous guard. Walker S2, Digit, Figure 03 and Atlas provide industrial evidence. HERO directly targets security, but sustained deployment remains unproven.

Can a humanoid open doors or use a lift?

Some systems manipulate objects or press controls in trials. Each handle, badge reader and lift must be integrated and tested. The capability should not be inferred from a video.

Why not use a quadruped instead?

Quadrupeds are generally more mature for stairs, uneven ground and inspection. A humanoid becomes relevant when two-arm manipulation or use of human equipment is essential.

Is a humanoid security robot legal in Switzerland?

It may be used as a tool if physical safety, data protection, employment law and security-company rules are respected. The robot is not itself a licensed security officer.

Can it use facial recognition?

Facial recognition creates significant legal and ethical risks. Presence detection without identification is usually more proportionate. Any biometric project requires a specific assessment.

When will humanoids become common in security?

There is no reliable timetable. Targeted industrial pilots may emerge. General replacement of human guards is neither demonstrated nor predictably dated.