Sunday, October 4, 2026 Sign inSubscribe to The Brief →
Humanoid Threats

Security for the age of physical AI

Humanoid Robot Security Checklist

A practical 32-point security checklist for teams buying, deploying or operating humanoid and service robots. It turns the lessons from real robot vulnerabilities, like the Unitree G1 CVEs, into checks you can run before and after a robot joins your network.

Before you buy

  • Ask the vendor for a list of known CVEs and the firmware version that fixes each one.
  • Request a software bill of materials (SBOM) for the robot's main computer and controllers.
  • Ask whether the robot has had an independent security test, and when.
  • Confirm how long the vendor commits to security updates for this model.
  • Check whether the model or vendor is affected by import rules such as the FCC Covered List.
  • Ask what data the robot collects, where it is sent and whether it can run without the vendor cloud.

Network and connectivity

  • Put robots on their own network segment, separated from office and production systems.
  • Block all inbound connections to robots from the internet.
  • Allow outbound traffic only to the vendor endpoints the robot actually needs.
  • Disable or restrict remote-control and cloud features you don't use.
  • Monitor robot network traffic and alert on unusual destinations or volumes.
Free for subscribers

Get the full checklist and the PDF

Subscribe to The Humanoid Threats Brief (free, one email a week) to unlock the rest of this page and the printable PDF.

Check your inbox and click the link to unlock.

Something went wrong. Please try again.

The Humanoid Threats Brief

The weekly briefing on humanoid robot security.

New vulnerabilities, incidents, standards and defenses, with why each one matters. Built for security teams, robotics engineers and the people buying humanoids.

  • Every claim sourced. We link the CVE, the paper or the regulator, not rumors.
  • 5-minute read. One email a week, every Thursday.
  • Free. No spam, unsubscribe in one click.

Check your inbox to confirm your subscription.

Something went wrong. Please try again.

Read a recent storyUnitree G1 Vulnerabilities Explained: CVE-2026-76639 and CVE-2026-76640 →
100% primary-source linked 1 email a week