Humanoid Robot Offboard Safety Buyer Guide
The Agility and FORT partnership puts external safety interfaces on the buying agenda. Use this guide to assess the evidence before a pilot.
Humanoid robot offboard safety is the part of a deployment that connects the machine to people, workcell equipment and facility safety systems. Agility Robotics and FORT Robotics announced an October 1 partnership for Digit 5 that includes a pendant, on-robot communications and off-robot interfaces. That is a useful architecture claim. It is not a ready-made approval for a warehouse task.[1]
The buying decision should stay narrow: can the supplier document how the exact robot, task, facility interface and fault response work together? If not, the sensible next step is a bounded pilot, not a wider rollout. This guide is a procurement checklist, not safety engineering or legal advice.
What is humanoid robot offboard safety?
Humanoid robot offboard safety is the connection between a robot's own controls and safety functions outside the robot, such as a pendant, guarded area, facility signal or external safety system. It matters because a dynamically stable machine can have different behavior when it loses power, a command path or its balance.
FORT and Agility say their planned Digit 5 arrangement has three parts: a safety pendant, on-robot communications and off-robot interfaces. They describe the off-robot interface as a bridge to external safety systems. The announcement does not publish task-specific test results, interface timing, coverage boundaries or an approval for a buyer's site.[1]
That absence should shape the questions, not be treated as evidence of a defect. A public partnership announcement cannot contain the complete integration file for every route, load, end effector and floor plan. The buyer needs to establish what the supplier will provide for the proposed setup.
| Evidence area | Ask the supplier | What a buyer should retain |
|---|---|---|
| Robot safety controls | Which stop functions, stability controls and operating modes apply to this configuration? | Dated configuration record and functional-safety documents. |
| External interface | Which facility systems can signal the robot, and what state follows each signal? | Interface map, signal list and failure response. |
| Manual intervention | Who can use the pendant or emergency stop, and who can restart work? | Access roles, restart procedure and training record. |
| Fault handling | What happens if an external signal or communication path is lost? | Planned fault-test results and recovery logs. |
*Buyer evidence checklist based on the FORT and Agility partnership announcement and Agility's public description of a controlled-stop and safety-controller approach. Sources checked October 7, 2026.[1][2]*
Why does an offboard interface need a site test?
An offboard safety interface needs a site test because its value depends on the completed system, not the name of the component. A facility signal may be correctly designed while the chosen route still has an untested blind area, an unclear restart process or a load that changes the stopping problem.
Agility's account of Digit's development says an earlier external safety controller created a new fall risk if communication with the robot failed. The company later added an onboard safety PLC, Category 1 controlled-stop behavior and a control pendant. It also says deployed humanoids operated behind physical workcell barriers when motion and stability risks remained.[2]
Those statements are vendor accounts of one platform, but they support a practical procurement rule: test the independent layers together. Do not infer the behavior of a whole installation from a product label or a single demonstration.
Which standards claims need careful reading?
ISO/CD 25785-1 is a committee draft for industrial mobile robots that require active control to remain stable. ISO says the scope includes legged, wheeled and other ground-traveling forms in industrial environments where public access is excluded or restricted. The record says Part 2, intended to cover application integration, will be developed separately.[3]
That split is important. A supplier may have useful robot-level evidence while the integration questions remain unresolved. The public ISO page also lists exclusions, including non-industrial environments and severe conditions such as freezer applications or explosive atmospheres. It cannot settle every task in a buyer's facility.[3]
In the United States, OSHA's machine-guarding regulation requires one or more guarding methods to protect workers from listed machine hazards where a point of operation exposes an employee to injury. It names examples including barrier guards and electronic safety devices.[4] The rule does not certify a specific humanoid, control pendant or external interface.
For a wider standards primer, read our legged robot safety standards guide. For the related question of changing a warehouse workcell around Digit 5, see our Digit 5 warehouse safety buyer guide.
What should the first acceptance test prove?
The first acceptance test should prove the behavior of the declared configuration in normal work and defined faults. Use a bounded job with a named route, stable load and clear handoff. A pilot that combines uncertain loads, open pedestrian traffic and frequent manual intervention produces weak evidence because too many variables move at once.
Set the acceptance criteria before equipment arrives. Include people entering the permitted route, a blocked path, a dropped load where relevant, each available stop control, loss of the external signal and loss of communications. Document the expected response, observed state, restart authority and any change made after the test.
| Test | Decision question | Pass record |
|---|---|---|
| Entry into the route | Does the system reach the documented safe state when a person enters the approved area? | Route map, test position, active mode and result. |
| External stop request | Does each facility or pendant signal produce the documented response? | Signal source, stop state, timing method and restart rule. |
| Communications loss | What happens when the offboard path is unavailable? | Fault injection method, robot state and recovery procedure. |
| Changed load or tool | Does the approved evidence still apply after a change? | Load, end effector, software version and re-test decision. |
This is a recommended test structure, not a claim that these tests alone establish compliance. ISO's public record describes a draft that addresses robot hazards and says application integration will be handled in a separate part. OSHA's rule similarly requires hazard protection in the actual operation.[3][4]
Is the new Agility and FORT partnership enough to change a purchase decision?
The partnership is enough to ask better questions. It is not enough to skip the buyer's task-specific review. The companies say their memorandum covers future hardware development, solutions engineering, regulatory compliance and deployment support as Digit 5 moves into more complex environments.[1] A memorandum and a public architecture description are not the same as a completed safety file for a given site.
Our view: buy a defined pilot when the supplier can identify the exact configuration, interfaces, operating limits, fault tests and accountable parties. Wait when the evidence remains at product or partnership level. The most useful offboard safety system is the one the facility can explain, test and govern after installation.
Humanoid robot offboard safety questions
What is an offboard safety interface for a humanoid robot?
It is the connection between the robot's own safety controls and systems outside the robot, such as a pendant, guarded area or facility safety signal. The interface must be assessed as part of the completed application.
Does an external safety system replace a robot's onboard controls?
No. The public Agility and FORT announcement describes a combined architecture with pendant, on-robot communications and off-robot interfaces. Buyers should ask how those layers work together in the proposed configuration.[1]
Is ISO/CD 25785-1 a published humanoid safety standard?
No. ISO lists ISO/CD 25785-1 as a committee draft under development. It covers actively stable industrial mobile robots in a defined industrial scope and says a later part will address application integration.[3]
Can a buyer remove a barrier after adding an offboard interface?
Do not remove a barrier based only on an architecture claim. OSHA's machine-guarding rule applies to hazards in the actual operation, and the employer's qualified process should assess the completed system before a safeguard changes.[4]
Sources
- https://www.fortrobotics.com/news/agility-and-fort-robotics-announce-strategic-partnership-to-advance-humanoid-robot-safety
- https://www.agilityrobotics.com/content/built-for-the-real-world
- https://www.iso.org/standard/91469.html
- https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.212