It’s a seductive vision: a sleek humanoid robot, as sophisticated and engineered as a high-end Jaguar, gliding through our factories, homes, and hospitals. But the stark reality is that we are essentially building powerful computers with limbs—and we’ve forgotten to lock the front door. As internet-connected robots emerge as the next great leap in tech, they bring a chilling truth: a compromised robot isn’t just a data breach; it’s a physical liability that can spy, sabotage, and cause genuine harm.
Experts have been sounding the alarm for years: today’s smart robots are vulnerable to the same cyber risks as any laptop or smartphone, but with the terrifying addition of autonomous physical agency. An attacker doesn’t just steal your files; they weaponise the machine itself. This isn’t some far-off Black Mirror script; it’s the new frontier of cyber-physical threats, and we are caught flat-footed. This is a deep dive into the security and safety minefield of modern robotics—from hair-raising real-world hacks to the global regulatory scramble trying to keep pace.
When Good Robots Go Rogue: The Technical Risks
Modern service robots are masterpieces of engineering, bristling with sensors, cameras, high-torque motors, and sophisticated AI. Unfortunately, every one of these features is a potential entry point for a hacker.
Hijacking and Unauthorised Control
Like any networked device, a robot’s software is only as strong as its weakest line of code. Security researchers have repeatedly proved that popular robots often ship with laughably weak authentication, allowing them to be commandeered with frightening ease. In one infamous demonstration, researchers at the cybersecurity firm IOActive bypassed the safety protocols on a UBTech Alpha 2 home robot and reprogrammed it to aggressively stab a tomato with a screwdriver. It was a visceral, chilling proof-of-concept for how a friendly-looking android could be turned into a kitchen-counter menace.
“Even running at slow speeds, their force is more than sufficient to cause a skull fracture,” the IOActive researchers noted regarding collaborative factory robots. They highlighted a grim reality: once a hacker is at the helm, built-in safety features are effectively deleted.
The “kill switch”—a physical emergency shutdown—is often touted as the ultimate safeguard. European lawmakers have even mooted making them mandatory. However, if an attacker can disable that switch via a remote exploit, your only remaining safety protocol is to run.
Surveillance and the Death of Privacy
With high-definition cameras and sensitive microphones acting as their eyes and ears, hacked robots become mobile surveillance platforms inside our most private sanctuaries. This hit home in 2024 when owners of the premium Ecovacs Deebot X2 robot vacuum found their devices had been hijacked. Attackers gained remote access to the live camera feeds and began shouting obscenities through the built-in speakers—in one instance, even chasing the family dog around the living room.
“It’s like having a webcam that can roll around your house and watch your family,” one shaken owner remarked. Researchers later demonstrated that the same model could be compromised via Bluetooth from 140 metres away, allowing an intruder to silently watch, listen, and even harvest the home’s Wi-Fi credentials. This isn’t just a glitch; it’s a profound violation of the home.
Data Leaks and Subtle Sabotage
Beyond overt spying, a compromised robot can leak sensitive data or, more insidiously, manipulate its tasks in ways you won’t notice until it’s too late. In 2017, researchers from Politecnico di Milano and Trend Micro remotely altered an industrial robotic arm’s calibration by a mere 2mm. This tiny, undetectable shift caused the robot to produce faulty parts. “If that was an aeroplane… it could be a catastrophic event,” the researchers warned. Their scan of the web found over 80,000 industrial devices, many of them robots, exposed online without so much as a password.
Autonomous Misbehaviour and Physical Harm
Humanoid robots are built for physical interaction. If their AI logic fails or is tricked, they become heavy, moving hazards. We’ve already seen a chess-playing robot break a child’s finger in 2022 because the boy moved too quickly for its sensors. Now, imagine a malicious actor instructing a hotel concierge robot to ram a guest, or a kitchen assistant to misuse a blade. The potential for injury is visceral, transforming a helpful companion into an unpredictable threat.

The Automotive Parallel: Lessons Not Yet Learned
The most accurate parallel for the risks of mobile, autonomous robots is the modern car. Today’s vehicles are essentially supercomputers on wheels, and the motor industry learned about cybersecurity the hard way.
A landmark 2015 hack of a Jeep Cherokee, where researchers remotely killed the engine while it was on a motorway, triggered a recall of 1.4 million vehicles and forced a total industry rethink. Today, new cars sold in the UK and EU must comply with stringent UN regulations like UNECE R155, which mandates certified Cybersecurity Management Systems. Manufacturers are now legally on the hook for protecting vehicles from hackers.
The robotics industry, by contrast, has no such binding mandate. A humanoid costing tens of thousands of pounds might ship with a default password and no clear way to push security patches—lapses that would be unthinkable in the automotive world today. Cars and robots share a nearly identical risk profile, yet vehicle security is light-years ahead in terms of regulation and rigour.
The Regulatory Scramble: A Global Patchwork
As the incidents pile up, governments are finally waking up to the threat. However, the current regulatory landscape is a messy, inconsistent patchwork.
United States
The US currently lacks a dedicated “Robot Law.” Instead, agencies like the FTC and CPSC try to stretch existing consumer protection and product safety laws to fit. While NIST has released a voluntary AI Risk Management Framework, it lacks teeth. More recently, citing national security concerns, the FCC has moved to block imports of certain foreign-made humanoid and quadruped robots—a move aimed squarely at Chinese manufacturers. It’s a sign of growing awareness regarding espionage, but it’s a reactive geopolitical move, not a comprehensive safety standard.
European Union
True to form, the EU is taking a more structured, proactive path. The landmark EU AI Act, adopted in 2024, employs a risk-based model. Robots used in sensitive sectors like healthcare could be classified as “high-risk,” forcing manufacturers to meet strict requirements for safety, transparency, and human oversight. Furthermore, the updated Machinery Regulation forces firms to address cybersecurity risks that could lead to physical accidents. Combined with the GDPR, Europe is building a multi-layered fortress for the robotic age.
China
With a national goal of mass-producing humanoids by 2025, China is also moving to tighten the reins. In 2023, Shanghai introduced the country’s first governance guidelines for humanoids, stressing the “protection of human dignity” and “assurance of human security.” While these are currently guidelines rather than hard law, they signal Beijing’s intent to bake safety and ethics into the manufacturing process. China’s existing, draconian cybersecurity and data privacy laws will also apply, creating a powerful, state-led governance model.
The Way Forward: Security Is Not an Optional Extra
Experts are unanimous: we are in a critical window to build a foundation of trust for robotics. The global service robotics market is set to explode, potentially surpassing $200 billion by 2031. Millions of these machines are about to enter our workplaces and homes.
The path forward requires a shift in mindset:
- Security by Design: Manufacturers must stop treating security as a “nice-to-have” afterthought. Encrypted comms, secure boot processes, and robust authentication must be the baseline.
- Standards and Certification: We need a clear “Kitemark” for robotics—a signal to consumers that a robot meets rigorous cybersecurity standards.
- Regulatory Accountability: Laws must hold manufacturers liable for shipping products with glaring vulnerabilities.
- User Hygiene: Consumers need to be aware of the basics—changing default passwords and ensuring firmware is always up to date.
The warnings from the frontline of cybersecurity have been clear for a decade. In 2017, IOActive identified nearly 50 vulnerabilities across a range of popular robots. In a 2024 follow-up, they noted with frustration that the same classes of bugs persist, but now the tools to exploit them are being supercharged by AI, lowering the barrier for entry for bad actors.
We are building a future where robots will care for our elderly, deliver our shopping, and work alongside us in the office. If we fail to secure them, we aren’t just risking our data; we are risking our physical safety. The dystopian future where the machines turn on us won’t be because of a “sentient” AI uprising; it’ll be because of a dodgy bit of code found on a public GitHub repo. It is up to the engineers, the politicians, and the public to ensure our robotic helpers stay exactly that: helpful.
