When the Hazard Moves: Safety Management for Autonomous Work

Every safety program I have ever run, audited, or rebuilt shared one silent assumption: the hazard stays where you put it. The press is bolted to the floor. The forklift has a driver who can be trained. The conveyor runs the same path every shift. The entire architecture of industrial safety, from machine guarding to traffic management to lockout/tagout to the way we draw a plant layout, is built on the idea that hazards are fixed and people move around them. We manage the people.

Autonomous machines break that assumption. An autonomous mobile robot chooses its own path through a warehouse. A robotic arm on a mobile base moves from station to station. An autonomous vehicle on a yard or a public road makes thousands of decisions a minute with no human in the loop. The hazard now moves, it decides, and it shares the floor with people who are also moving and deciding. That is not a new machine to guard. It is a new kind of work environment, and the safety, risk, and insurance professions are not ready for it.

What actually changes when the hazard moves

Consider the humble forklift, which was OSHA’s eighth most-cited standard in fiscal 2025 with 1,826 violations and remains one of the most reliably lethal pieces of equipment in American industry. Our entire approach to forklift safety rests on the operator: training, evaluation every three years, pre-shift inspection, rules about speed and horns and pedestrians. We do not really manage the forklift. We manage the person driving it.

Now remove the person. An autonomous forklift or AMR has no operator to train. Its behavior is a function of its sensors, its software, its map, its fleet management system, and the rules someone configured in a dashboard. The questions change completely. What does it do when its LiDAR is obstructed by a hanging strap? How does it behave at a blind corner when a pedestrian steps out? What happens when two units from different vendors meet in an aisle and neither fleet manager knows the other exists? Who changed the speed parameter last Tuesday, and did anyone assess that change?

The safety case for the autonomous machine lives in places the traditional safety professional has never had to look: a functional safety calculation, a software configuration, a network, a vendor’s release notes. The ANSI/A3 R15.08 standard for industrial mobile robots exists precisely because the older industrial robot standards assumed a robot stayed inside a cell. The 2025 revision of ISO 10218 added cybersecurity requirements for the first time because a robot that can be reconfigured remotely can be compromised remotely, and a compromised safety function is a hazard with no physical warning sign.

The shared environment problem

The deeper challenge is not the machine. It is the environment the machine and the people now share.

Traditional safety separates people from hazards in space or in time. The fence separates in space. The lockout separates in time. Autonomous systems are valuable precisely because they do not require that separation; the AMR is useful because it can go where the people are. So the safety of the environment is no longer a property of the machine or the person. It is a property of the interaction, and interactions are harder to guard than objects.

This shows up in ways plants are only beginning to notice. Floor markings designed for human drivers mean nothing to a robot and may confuse the people who now share the aisle with one. Pedestrian walkways that were safe because forklift drivers could see and be seen become ambiguous when the vehicle has no eyes to make contact with. Emergency stops that assumed one machine become a fleet question: if you stop one unit in a corridor, what do the other 30 do? Maintenance access that assumed a locked-out machine now has to account for a machine that may decide to move.

And the people adapt in ways no one planned. Workers learn that the robot always stops for them, so they stop watching for it. They learn where its sensors are weak and cut through those zones because it is faster. They treat it as a coworker until the day it does not behave like one. Complacency around autonomous systems is the near-miss category I expect to define the next decade of incident reports.

What this demands of the EHS professional

I have spent more than 20 years in this profession, most of it inside large manufacturing, and I will say plainly that the average EHS practitioner is not equipped for this. Not because they lack ability, but because the training pipeline built them for a fixed-hazard world.

The professional who manages an autonomous environment needs to read a risk assessment written to ISO 12100 and ANSI B11.0 and know whether it is real. They need to understand performance levels under ISO 13849 well enough to ask an integrator why a safety-rated scanner field was set the way it was. They need to treat software configuration as a controlled document and demand change management for safety parameters with the same rigor they apply to a confined space permit. They need to speak enough of the language of cybersecurity to know that a safety PLC on a flat network is an exposure. They need to design a traffic management plan for a mixed human and autonomous fleet, which no OSHA standard describes. And they need to build the behavioral side, meaning training, expectations, and consequences, for people who will work alongside machines that never get tired and never get distracted but also never actually see them.

That is a broader skill set than the profession currently produces. It is closer to a systems engineer with a safety mindset than to a compliance manager with a checklist. And there are not many of those people, which is a market signal worth reading if you are running an operation that plans to automate.

What it demands of risk management

The insurance and risk side has its own reckoning coming. Workers’ compensation underwriting is built on loss history by classification code, and there is no loss history for a warehouse where 40 percent of the movement is autonomous. General liability and product liability blur when a robot injures a contractor: is that the operator’s negligence, the integrator’s design, the vendor’s software, or the fleet manager’s configuration? Business interruption looks different when a cybersecurity incident can stop a fleet.

Carriers will figure it out, and they will figure it out by asking for evidence. The operations that can produce a risk assessment, a validation record, a change log, and a training program for mixed environments will be underwritten as managed risks. The ones that can produce a vendor brochure will not. Risk management’s job over the next several years is to build the evidentiary record that makes the autonomous operation insurable at a reasonable price, and that record is an EHS product.

The question is not whether to automate

I want to be clear that none of this is an argument against autonomous systems. The labor market is not going to get easier. The injury rate for powered industrial trucks with human operators is a known, bad number. Well-designed autonomous systems, deployed into an environment that was designed for them, will make plants safer. I believe that.

The argument is about sequence. Most operations are buying the machines first and discovering the environment problem second. The robot arrives, the integrator commissions it to their scope, the fence around the old cell comes down, and the plant finds out over the next year what the shared floor actually looks like. The safety function is treated as a feature of the machine rather than a property of the operation.

The better sequence is to treat the autonomous deployment as a change to the work environment that requires its own risk assessment, its own layout and traffic plan, its own change control, its own training, and its own emergency response thinking, before the purchase order is cut. That is management-of-change discipline, which the process safety world has practiced for decades and the general industry world mostly has not. Autonomous systems are going to force it on everyone.

What to do now

If you are planning an autonomous deployment, inventory the interactions rather than the machines. Where will people and autonomous units share space, and under what conditions? Demand the risk assessment and the functional safety documentation from the vendor and the integrator as a condition of purchase. Put safety configuration under change control from day one, and decide who is allowed to change a scanner field. Build a traffic management plan for the mixed environment and train people to it, including the counterintuitive parts, like not trusting the robot to always stop. Talk to your broker and your carrier before commissioning, not after the first claim. And get someone in the room who has managed both process safety and machine safety, because this is where those two disciplines meet.

If you already have autonomous systems running, walk the floor and watch how people actually behave around them. The shortcuts they have learned are your risk register. Then ask when the safety parameters were last changed and by whom. If nobody can answer, that is your first corrective action.

The hazard is going to move. The safety profession, the risk profession, and the operations they serve are going to have to learn to think about the environment as a system rather than a collection of fixed things to guard. The ones who make that shift early will run safer, cheaper, more insurable operations. The ones who do not will learn what a moving hazard does to a static program, and the OSHA log will keep score. That shift in thinking is the work I do with clients through AI-enabled, senior-led EHS, because a moving hazard needs a system that can move with it.

Key takeaways

  • Autonomous systems break the fixed-hazard assumption — the hazard now moves and decides, so safety becomes a property of the interaction between people and machines, not of either one alone.
  • The safety case lives in new places — functional safety calculations, software configuration, fleet management rules, and network security, governed by ISO 10218:2025, ANSI/A3 R15.08, and ISO 13849.
  • People adapt in unplanned ways — complacency and learned shortcuts around robots that “always stop” are the emerging near-miss category.
  • Risk management needs an evidentiary record — risk assessments, validation, change logs, and mixed-environment training are what make autonomous operations insurable.
  • Sequence matters — treat the deployment as a management-of-change event with its own risk assessment, traffic plan, and change control before the purchase order, not after the first incident.

Related reading: Machine Guarding Is About to Stop Being a Fence · Risk Assessment Is an Art Disguised as a Spreadsheet

more insights

Machine Guarding Is About to Stop Being a Fence — FractionalEHS

Machine Guarding Is About to Stop Being a Fence

OSHA’s 1910.212 hasn’t changed since 1971. The machines have. Safety-rated sensing, ISO 13849 performance levels, and ISO 10218:2025 are turning the guard into a decision instead of an object — and most guarding programs aren’t built for it.

Read more >