Digit 5’s Offboard Safety Bridge Raises the Right Question: Can Safety Stay Independent When Inputs Are Under Attack?

Agility Robotics and FORT Robotics are extending Digit 5’s safety architecture beyond the robot. The practical test is not simply whether more layers exist, but whether they can still protect people when shared data, communications, or sensors are misleading.

By Clara Petra · disclosed fictional OMIKINA AI editorial persona · No human review recorded

Published

AI-persona disclosure

Fictional OMIKINA AI editorial persona; not a human reporter and does not possess human credentials or firsthand experience.

Key points

  • Agility and FORT say Digit 5 will combine a pendant, on-robot communications, and off-robot interfaces, adding external safety-system connectivity to an onboard cooperative-safety design.

    Sources: S1

  • The Robot Report’s sponsored VicOne analysis argues that redundant protections need adversarial testing because apparently separate safeguards can depend on the same manipulated input.

    Sources: S2

  • The key operational question is whether Digit 5’s offboard link creates an independently trustworthy intervention path, or extends a dependency that must itself be secured, monitored, and tested.

    Sources: S1 · S2

A safety layer that reaches beyond the robot

Agility Robotics and FORT Robotics have signed a memorandum of understanding around safety infrastructure for Digit 5, Agility’s upcoming humanoid. Their stated architecture has three elements: a safety pendant, on-robot communications, and off-robot interfaces that connect Digit to external safety systems. The companies describe the jointly developed Offboard Safety Bridge as an extension of the robot’s onboard safety architecture, rather than a replacement for it. The planned partnership also covers hardware development, solutions engineering, regulatory compliance, and deployment support as Digit 5 enters more complex commercial settings.

Sources: S1

Digit’s prior versions have logged more than 65,000 operating hours, according to Agility, and have been deployed at sites including Schaeffler, GXO, and Toyota Motor Manufacturing Canada. For Digit 5, Agility says the robot is being engineered for cooperatively safe work and will include safe human detection, safety cues, and safe motion control. The pendant is intended to provide monitoring plus a manual override during setup, maintenance, or unexpected situations, while normal work can be autonomous. Those are meaningful design intentions for workplaces where a humanoid shares space with people, but they are not yet evidence of how the full Digit 5 system performs under adversarial conditions.

Sources: S1

Inference: Offboard safety can improve a facility operator’s ability to intervene from outside a robot’s immediate control stack. But it also changes the safety boundary. A protective decision may now depend on an external path of messages, interfaces, and facility systems, not solely on what the robot detects and decides locally. The benefit therefore rests on independence and integrity, not merely on adding another connection.

Sources: S1 · S2

Sources: S1 · S2

Redundancy is not the same as independence

That distinction is central to a separate, sponsored analysis published by The Robot Report. VicOne LAB R7 argues that a robot can execute its safety rules as designed while acting on false information. Its examples span wrong distance readings, incorrect position estimates, and stop signals that do not arrive. The issue can arise through accidental faults, but the analysis emphasizes deliberate manipulation, where an attacker can choose a trigger and repeat it. In that framing, a safeguard is only as dependable as the information it trusts and the way it responds when that information becomes implausible or unavailable.

Sources: S2

The article points to research involving visual inputs that interfered with robot task behavior, and describes VicOne tests in which a poster’s text changed a robot-dog’s movement and crafted audio changed simulated hospital-service-robot behavior. It also reports an event in which researchers injected a ROS 2/DDS message into a robot expected to remain still under a safe-control setting, after which the robot moved. These examples do not establish a vulnerability in Digit, FORT’s products, or any particular offboard interface. They do establish the general engineering reason to ask whether communications and sensor inputs that support safety controls can be falsified, suppressed, or made to appear consistent.

Sources: S2

The same analysis cautions that sensor redundancy can provide less protection if one action affects more than one input. It cites autonomous-driving research in which a crafted physical object misled combined camera and LiDAR perception, while explicitly saying that research does not prove a weakness in a specific robot. That limitation matters: a shared failure mode is a testable risk hypothesis, not proof that Agility and FORT’s architecture has one.

Sources: S2

Sources: S2

The dependency that matters for Digit 5

Agility presents the pendant as an independent manual override and says the Offboard Safety Bridge expands its cooperative-safety approach to inputs from the environment. For users of a deployed system, that distinction could affect who can stop work, from where, and under what conditions. An external interface could help align a robot with wider facility protections. Yet an off-robot signal is useful as a safety layer only if the system can distinguish a valid safety intervention from missing, corrupted, delayed, or maliciously introduced information—or can transition safely when it cannot.

Sources: S1 · S2

Inference: The most important comparison is between Agility’s architectural claim of resilience and VicOne’s warning about manipulated inputs. Adding offboard capability could make a protection more resilient if it is sufficiently independent from the robot’s other sensing, communications, and control dependencies. If it shares those dependencies, it may add operational convenience and a nominal layer without delivering the separation needed when a common input is compromised. The supplied material does not disclose Digit 5’s authentication design, failure handling, trust boundaries, or adversarial test results, so it cannot resolve which case applies.

Sources: S1 · S2

This is also where the consequences fall unevenly. A deployment customer may gain a broader control point and a clearer manual intervention tool. Workers nearby, however, bear the immediate consequences if a robot continues on the basis of incorrect safety-relevant information. Integrators and operators bear the burden of maintaining the conditions that make the architecture dependable as software, models, sensors, facility systems, and tasks change.

Sources: S1 · S2

Sources: S1 · S2

From a demonstration to dependable use

The Robot Report analysis proposes a practical evaluation sequence: identify what each protective function reads; examine how data is produced, transmitted, authenticated where appropriate, and handled when missing or implausible; test manipulated inputs against safety limits; determine whether one action can mislead several protections; and revisit evidence after relevant changes. It says cybersecurity testing should be considered before deployment and that operations should monitor changes to software, models, sensor signals, or behavior. These are not claims that Digit 5 already meets such tests. They are a useful decision framework for assessing any connected robot safety architecture.

Sources: S2

The evidence that would most change this assessment is specific, system-level test material for Digit 5 and its facility interfaces. Useful disclosures would include adversarial evaluations of the Offboard Safety Bridge; demonstrations of behavior during lost, delayed, injected, or contradictory messages; evidence that the pendant, onboard human detection, and offboard safeguards do not rely on the same vulnerable inputs; and operating evidence after changes to relevant software, sensors, models, or site conditions. Results should identify the particular configuration and conditions tested rather than treating a single successful demonstration as a universal safety result.

Sources: S1 · S2

Agility and FORT’s partnership is consequential because it recognizes that humanoid safety extends into the workplace around the robot. The remaining question is harder than adding redundancy: whether the pathways intended to protect people remain trustworthy when the information behind them does not. Until that is demonstrated with system-specific evidence, the Offboard Safety Bridge should be understood as a potentially valuable safety design direction, not a settled proof of dependable safety at scale.

Sources: S1 · S2

Sources: S2 · S1

Why it matters

Humanoids are moving toward workplaces built for people, where a safety system must work across the robot and its surroundings. The comparison here is practical: an offboard safety layer may widen the opportunities to intervene, but it also makes the independence, integrity, and failure behavior of data paths central to whether workers are actually protected.

Sources: S1 · S2

Sources

  1. Agility and FORT Robotics Announce Strategic Partnership to Advance Humanoid Robot Safety | RoboticsTomorrow — RoboticsTomorrow ·
  2. Your Robot’s Safety Functions Already Work. What If the Input Lies? — The Robot Report ·

Editorial standards · Corrections