# Why Can't Humanoid Robots Get Safety-Certified for Factory Work?
The barrier to industrial humanoid deployment is not locomotion, not [dexterous manipulation](https://humanoidintel.ai/glossary/dexterous-manipulation), and not AI capability — it is a single unresolved collision between bipedal physics and a foundational assumption baked into every major machinery safety standard on Earth. A paper published today on arXiv by Caiwu Ding, Tao Cui, Lingyun Wang, and Chengtao Wen gives that collision a precise name — the **fail-passive gap** — and uses a real [Unitree Robotics](https://humanoidintel.ai/companies/unitree-robotics) G1 EDU robot in a pick-and-place cell to demonstrate exactly where certified safety chains break down and why.
The core problem, stated plainly: ISO 13849-1 and EN 60204-1 — the standards that govern machinery safety in virtually every industrial jurisdiction — assume that removing power from a machine puts it into a safe state. For a conveyor belt or an industrial arm, that is true. For a walking biped, cutting power causes an uncontrolled fall. **De-energization is itself the hazard.** No amount of excellent balancing policy closes this gap, because the safe state of a legged robot is an actively-controlled state, and active control requires power.
Until this gap is formally addressed by standards bodies, no humanoid robot can achieve end-to-end certified Performance Level e (PL e) or SIL 3 — the ratings required for collaborative industrial operation near humans. Every company pushing humanoids into factory environments is navigating around this, whether or not they are acknowledging it publicly.
---
## What ISO 13849 Actually Requires — and Where Bipeds Fail
The authors' analytical approach is worth understanding in detail, because it is more rigorous than most industry commentary on this topic.
They construct a complete external safety chain using established, certifiable components: a light curtain, emergency stop, fail-safe input module, fail-safe PLC, and wireless PROFIsafe communication. Each of these elements can be independently quantified using standard methods — Probability of dangerous Failure per Hour (PFHD), Diagnostic Coverage (DC), Common Cause Failure (CCF) — and the chain as a whole can be assigned a certified Performance Level or Safety Integrity Level.
The analytical value of this exercise is in what it isolates. Because the external chain is fully certifiable, the residual uncertifiable element is precisely located: the **robot-side reaction chain**. When you follow the Siemens fail-safe S7-1500 emergency-stop reference that the authors use as a benchmark, the certifiable reaction in a conventional machine is Stop Category 0 — contactor-based power removal. That is exactly the action that a balancing humanoid cannot execute without falling.
This is not a paperwork problem or a regulatory lag. It is a genuine technical incompatibility between the physics of bipedal balance and the logical foundation of existing safety standards.
---
## The Unitree G1 Testbed: What Was Validated and What Was Not
The authors validate their framework on a [Unitree Robotics](https://humanoidintel.ai/companies/unitree-robotics) G1 EDU operating in a semi-enclosed workspace measuring 3 meters by 1.5 meters, performing pick-and-place tasks. This is a practically meaningful testbed — compact enough to be representative of real industrial cells, with a commercially available platform that other researchers and engineers can replicate.
The paper contributes several concrete analytical artifacts:
- A humanoid-specific hazard analysis addressing fall-as-hazard, single-support stop bounds, and balancing-policy residual risk
- ISO 13855 separation distance analysis adapted for a robot that cannot guarantee a controlled stop
- A provenance-labeled timing budget for the safety chain
Critically, the authors also explore hosting an industrial software-defined automation (SDA) controller on the robot, co-located with the balancing policy, connecting to PROFINET/PROFIsafe via a standardized IEC 61131-3 interface. This is an architecturally interesting approach — it moves the safety communication endpoint onto a known industrial protocol stack. However, the authors are explicit about its limits: the G1's onboard compute is not safety-rated hardware, so this endpoint is not a certified safety runtime. The conclusion is important — this design choice **reinforces rather than resolves** the fail-passive gap and localizes it more precisely to the interface between the SDA controller and the balancing policy.
To their credit, the authors state directly that they do not claim end-to-end certified PL e / SIL 3. This intellectual honesty is worth noting in a field where marketing language frequently outpaces verifiable claims.
---
## Why This Matters for the Entire Humanoid Industry
Every humanoid company with industrial ambitions — [Figure AI](https://humanoidintel.ai/companies/figure-ai), [Agility Robotics](https://humanoidintel.ai/companies/agility-robotics), [Apptronik](https://humanoidintel.ai/companies/apptronik), and others deploying or planning to deploy in factory settings — faces this same gap. Current industrial deployments are operating under risk-acceptance frameworks negotiated with individual customers and insurers, not under certified safety standards. That is workable for pilots and limited deployments, but it is not scalable to the broad industrial penetration that the industry's financial projections require.
The path to resolution runs through standards bodies — specifically, IEC and ISO technical committees need to develop a new safe-state definition for legged machines that accommodates active-control safe states. The authors' framework, by precisely locating the gap and characterizing it in the language of existing standards (PFHD, DC, CCF, PL, SIL), provides exactly the kind of structured problem statement that standards bodies can act on.
From an investment and deployment strategy perspective, the implications are direct. Any humanoid company claiming certified PL e or SIL 3 compliance for a walking biped today should be pressed hard on exactly which standards they are citing and which elements of the safety chain they are excluding from that certification claim. The fail-passive gap described in this paper is not a niche technical footnote — it is the central regulatory obstacle between current humanoid capability and certified industrial deployment at scale.
[Whole-body control](https://humanoidintel.ai/glossary/whole-body-control) researchers should also take note: the paper implies that balancing policy residual risk must be characterized as part of any safety case, even if the policy itself cannot be formally certified under current standards. That creates demand for interpretable, bounded balancing controllers with quantifiable failure modes — a design constraint that pure performance-optimized whole-body control approaches do not currently satisfy.
---
## Key Takeaways
- **The fail-passive gap** is the fundamental incompatibility between ISO 13849-1/EN 60204-1's de-energization assumption and the physics of bipedal balance — identified and named in today's arXiv paper by Ding et al.
- **De-energization is the hazard**, not the remedy, for a walking humanoid: cutting power causes an uncontrolled fall.
- The authors used a complete, certifiable external safety chain (light curtain, e-stop, fail-safe PLC, wireless PROFIsafe) to isolate the uncertifiable element: the robot-side reaction chain.
- Validation was conducted on a **Unitree G1 EDU** in a **3m × 1.5m** semi-enclosed pick-and-place cell.
- The paper explicitly does **not** claim end-to-end PL e / SIL 3 certification — a notable departure from typical industry communications.
- Co-locating an IEC 61131-3 SDA controller on the robot localizes but does not resolve the gap, because the G1's onboard compute is not safety-rated hardware.
- Resolving this industry-wide will require standards bodies to define active safe states for legged machines — the paper provides the structured problem statement to enable that work.
---
## Frequently Asked Questions
**What is the fail-passive gap in humanoid robot safety?**
The fail-passive gap is the incompatibility between existing machinery safety standards (ISO 13849-1, EN 60204-1) — which assume that removing power puts a machine into a safe state — and bipedal robots, for which cutting power causes an uncontrolled fall. The safe state of a walking robot requires active control, which requires power, which the standards prohibit in an emergency stop scenario.
**Can humanoid robots achieve SIL 3 or PL e certification today?**
Not end-to-end, according to this analysis. The robot-side reaction chain — specifically the requirement for Stop Category 0 (contactor-based power removal) — cannot be satisfied by a balancing humanoid without causing a fall hazard. Current industrial deployments operate under negotiated risk-acceptance frameworks, not certified safety standards.
**What is PROFIsafe and why does it matter for humanoid robots?**
PROFIsafe is a safety communication protocol layered over PROFINET, widely used in industrial automation. The paper explores using wireless PROFIsafe as part of the external safety chain and hosting a PROFIsafe endpoint on the robot via an IEC 61131-3 interface. While this standardizes the communication layer, it does not resolve the fail-passive gap because the robot's onboard compute is not safety-rated hardware.
**Which humanoid robot was used in this study?**
The authors validated their framework using a Unitree G1 EDU performing pick-and-place tasks in a semi-enclosed workspace measuring 3 meters by 1.5 meters.
**What would it take to close the fail-passive gap?**
Standards bodies — particularly IEC and ISO technical committees — would need to develop revised or supplementary standards that define valid safe states for legged machines which require active control to remain safe. This paper's contribution is providing the precise technical characterization of the gap, in the formal language of existing standards, that could ground such a standards development effort.
RESEARCH
The Fail-Passive Gap Blocking Humanoids from Factory Floors
Published: August 5, 2026 at 24:00 EDTLast updated: August 5, 2026 at 07:43 EDTBy Alex Reiner, Senior EditorLast reviewed by Alex Reiner on August 5, 20268 min read
A new arXiv paper names the exact regulatory gap preventing humanoid robots from certified industrial deployment: the fail-passive assumption.
functional-safetyiso-13849unitreecertificationindustrial-deploymentprofisafefail-passive