Robot Safety Used to Mean Fail-Safe. Now It Must Mean Attack-Proof
An IEEE Spectrum analysis by VicOne argues that AI-driven robots create a new category of risk — machines that can be steered into harm while every diagnostic reads normal.

A perspective piece published on IEEE Spectrum, sponsored by automotive cybersecurity firm VicOne, argues that the definition of robot safety needs a rewrite. Traditional safety engineering asks whether a machine stays safe when something fails — a dead sensor, a stalled motor, crashed code. Physical AI — robots that perceive their surroundings through multimodal sensor inputs and make their own decisions — raises a harder question: can a machine stay safe when an attacker changes what it sees, decides, or does, even when nothing appears to have failed? The piece signals a convergence of two disciplines that Malaysian manufacturers have kept separate: functional safety and cybersecurity. If your business runs robots, warehouse automation, or vision systems, this changes your risk register.
AI Summary
A perspective piece published on IEEE Spectrum, sponsored by automotive cybersecurity firm VicOne, argues that the definition of robot safety needs a rewrite. Traditional safety engineering asks whether a machine stays safe when something fails — a dead sensor, a stalled motor, crashed code. Physical AI — robots that perceive their surroundings through multimodal sensor inputs and make their own decisions — raises a harder question: can a machine stay safe when an attacker changes what it sees, decides, or does, even when nothing appears to have failed? The piece signals a convergence of two disciplines that Malaysian manufacturers have kept separate: functional safety and cybersecurity. If your business runs robots, warehouse automation, or vision systems, this changes your risk register.
Key Takeaways
- Safety used to assume failure; now it must assume deception. A traditional robot safety case covers components breaking. A Physical AI safety case must cover inputs being manipulated — with all systems reporting "normal."
- Multimodal perception is the new attack surface. Modern robots decide based on fused sensor inputs. Whoever alters those inputs influences the robot's behaviour without touching its hardware.
- "Nothing failed" no longer means "nothing is wrong." A manipulated robot can pass every diagnostic check. Monitoring must shift from component health to behaviour.
- Safety engineering and cybersecurity are merging into one discipline. Teams that report to different managers, with different standards, now share one risk.
- Malaysian robot adopters — Penang E&E plants, Klang Valley logistics, smart city pilots — should treat robots as connected cyber-physical systems, not just equipment on an asset list.
What Happened
The article, published on IEEE Spectrum under VicOne's sponsorship, is an argument rather than a news report of a specific incident. Its core claim: the safety playbook built over decades of industrial robotics no longer covers the risks that AI-driven robots create.
Classically, robot safety asked one question — can the machine remain safe when something goes wrong? The answer was engineered through physical measures: cages, interlocks, emergency stops, redundancy, and certification against failure modes. If a sensor died or a program hung, the system detected the fault and moved to a safe state. The entire framework assumes the robot's environment and inputs are honest, and that danger arrives as malfunction.
Physical AI breaks that assumption. As the piece describes, modern robots perceive through multimodal inputs — combinations of cameras, radar, lidar, and other sensors — and use AI models to interpret what they see and choose actions. This is what lets robots leave their cages: an autonomous mobile robot navigating a warehouse aisle, a vision-guided arm picking parts from an unstructured bin. But it also means the robot's behaviour is a function of its inputs. An attacker who can subtly alter what the machine perceives changes what it decides and does — while the machine's own diagnostics report that everything is working exactly as designed.
One disclosure worth stating plainly: VicOne sells automotive cybersecurity, so the company benefits from framing this risk as urgent. That does not invalidate
Sources & References
AIBlog summarises and analyses published information. We do not reproduce full source text. Analysis is editorial and not financial or legal advice.


