Machine safeguarding was built on a simple premise: the dangerous thing stays where you put it, so you put a barrier around it. Fixed industrial robots fit that model perfectly. Fence the cell, interlock the gate, validate the stop, done.
Autonomous mobile robots broke that premise, and general-purpose humanoids are going to break it further. The hazard is no longer in a defined space. It moves, it shares the aisle with people, and increasingly it decides for itself what to do next.
Where autonomous warehouses are now
Mobile fleets are ordinary. Autonomous mobile robots and automated guided vehicles moving inventory alongside pedestrians, forklifts and manual carts are standard in modern distribution. The safety case usually rests on sensing and speed limiting rather than separation.
The failure modes are consistent. Sensor blind spots at specific heights and angles. Behavior in congestion that is technically correct and practically unpredictable. Interaction with manual forklifts whose operators cannot tell whether the robot has seen them. Maintenance and recovery work performed on a fleet that is still live elsewhere in the building.
Recovery is where people get hurt. A stuck or faulted unit needs a human to go to it, frequently in an aisle where other units are still running. Formal energy control and traffic management for recovery tasks is the gap I find most often.
What humanoids change
General purpose means unspecified. A traditional risk assessment starts from a defined task. A general-purpose machine is valuable precisely because its tasks are not fixed, which means the hazard analysis cannot be completed once and filed. It has to become a recurring process tied to whatever the machine is being asked to do this quarter.
Human form factor invites proximity. People keep more distance from something that looks like machinery. A machine that looks roughly like a person, moves like a person and occupies the space a person would occupy invites people to treat it as one — and it does not have a person judgment about what is about to happen.
Falls and dropped loads. A bipedal machine carrying a load has failure modes that a wheeled platform does not. Toppling onto a person is a different injury class than being bumped by an AMR.
Learned behavior resists validation. If behavior comes partly from training rather than entirely from specification, conventional validation gets harder. The question of what this machine will do in a situation nobody tested does not have a clean answer yet, and honest practitioners should say so.
There is no standard telling you what adequate looks like
There is guidance for industrial robot systems and for mobile platforms, and it continues to develop. For general-purpose mobile manipulators operating freely among people, the recognized-practice picture is still forming.
When the prescriptive answer does not exist, the defensible position is documented risk assessment. Identify the hazards, assess them with a method, select controls following the hierarchy, verify the controls achieve what was intended, and write down the reasoning. That is the standard a plaintiff attorney and a regulator will both apply, and it is what separates a considered decision from an assumption.
What to do now
Treat every new task as a new assessment. For flexible machines, assessment is a process rather than a document. Build a trigger into your management of change so a new task gets assessed before it runs.
Solve recovery and maintenance first. That is where the human enters the hazard zone deliberately, and it is consistently the least-documented activity around autonomous fleets.
Manage traffic, not just machines. Pedestrian routes, crossing points, blind corners, congestion behavior and interaction with manual equipment. The vehicle safety case and the facility traffic plan are separate things and both are required.
Train for the interaction, not the technology. Employees need to know what the machine can and cannot perceive, what it does when it faults, how to stop it, and what never to assume about it.
Demand evidence from vendors. Safety function performance levels, validation records, residual risks and the required conditions for the safety case to hold. A demonstration is not documentation, and the obligation to verify adequacy in your application is yours regardless of what the supplier claims.
The honest summary
This technology will reduce some injuries meaningfully — the lifting, the repetition, the entry into genuinely dangerous spaces. It will also create exposures we do not yet have good language for, in facilities where the safety function is already stretched.
The operations that handle it well will be the ones treating assessment as continuous rather than one-time, and documenting their reasoning while the standards catch up.
Key takeaways
- Fencing does not transfer to mobile hazards. The safety case shifts from separation to sensing, speed and traffic management.
- Recovery is the highest-risk task. Humans enter live aisles to retrieve faulted units, usually without formal energy control.
- General purpose defeats one-time assessment. If tasks are not fixed, hazard analysis has to become a recurring, change-triggered process.
- No prescriptive standard exists yet. Documented risk assessment against recognized practice is the defensible position.
- Vendor claims are not your verification. Adequacy in your application, under your conditions, remains your obligation.
Related reading: EHS for Robotics & Autonomous Vehicles · Machine Guarding Compliance · EHS for Warehousing & Distribution


