jaz_online - stock.adobe.com
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them
ESET has blocked more than 3,000 artificial intelligence (AI) skills it identified as malicious and flagged a further 25,000 as suspicious since March 2026, offering an early indication of how quickly the software infrastructure around AI agents is becoming a target in its own right.
The security supplier said it had scanned nearly 800,000 unique AI skills, which tell an agent how to perform tasks, use tools and interact with external systems, over the period – roughly 13 times the number publicly available at the start of the year.
The figures relate to the broader AI environment rather than embodied AI systems specifically, said Juraj Janosik, vice-president of artificial intelligence at ESET, but the pattern remains the same: once AI becomes part of operations, the attack surface grows fast.
“Embodied AI changes the risk profile because software can now influence physical action, and in some environments, human safety,” he added.
Most organisations deploying embodied AI systems need to protect the right assets. The machine itself is rarely the point of entry. What sits around it is softer: stolen credentials, the fleet management console, the cloud services the machines report to, the channel that pushes updates to every device on a site.
An attacker who compromises those systems may be able to influence many devices at once, offering a far greater return than targeting a single robot, according to Janosik.
Securing embodied AI therefore means protecting the full technology stack that shapes a machine's behaviour, including AI models, cloud services, software updates, application programming interfaces (APIs), sensors, third-party software and the platforms used to manage them.
“Each dependency extends the chain of trust, and attackers consistently look for the weakest point in that chain rather than the most visible device,” said Janosik.
Unpatched vulnerabilities, weak identity controls and poorly governed software dependencies remain among the easiest routes into embodied AI deployments, he added.
This creates an uncomfortable trade-off for organisations that have built the operational tools needed to manage fleets of machines. Centralised device visibility, staged model roll-outs and over-the-air updates make continuous improvement possible across thousands of devices in the field. From an attacker’s perspective, however, they also provide leverage over every device at once.
Putting guardrails around a guess
A harder engineering question is how to impose deterministic, hard-coded limits on a probabilistic model, ensuring that a system based on predictions cannot violate a physical safety protocol.
Janosik’s answer is to keep the two firmly separate. Safety-critical functions, such as emergency stops, collision avoidance and operational limits, should remain under deterministic control, with AI used to optimise operations within those boundaries.
“The AI can decide how to complete a task, but it should never decide whether fundamental safety rules apply,” he said.
This is less a new principle than one imported from other safety-critical fields. Aviation, industrial control systems and medical devices have spent decades establishing that safety depends on multiple independent controls rather than trust in a single decision-making system. Embodied AI inherits the same logic.
That discipline must be maintained throughout the life of the system as models evolve, software dependencies change and updates introduce new behaviours.
Janosik said every deployment should include staged roll-outs, adversarial testing, rollback procedures and continuous monitoring to keep behaviour predictable as the underlying system changes.
Fooling the sensors
Perception brings another attack surface. Researchers have shown that a sticker placed on a stop sign can be enough to mislead an autonomous vehicle’s computer-vision system. The same principle applies to any machine that acts on what it believes it can see.
“Secure embodied AI starts with the assumption that no individual sensor should ever determine a physical action on its own,” said Janosik.
Camera data should be checked against light detection and ranging (Lidar), radar and telemetry information, as well as environmental context and expected behaviour. When those signals conflict, the system should recognise the uncertainty and move into a safer operating state rather than act.
Spoofed inputs, manipulated visual cues and poisoned training data all exploit the same weakness: the assumption that plausible-looking data is automatically safe.
Janosik argued that adversarial conditions must therefore be treated as part of the threat model rather than as an edge case. Sensors, models and environmental assumptions should be deliberately tested before systems are deployed.
Operators, meanwhile, are working with the tools available. At the Hyundai Motor Group Innovation Centre Singapore, the group’s robotics smart factory in Jurong, cyber security “is embedded across our manufacturing environment”, the company said.
A dedicated team continuously monitors evolving risks, while safety measures are designed into its automation and robotics systems to protect people and equipment.
A broader definition of endpoint security
For suppliers, these developments broaden the definition of what security software must cover.
Endpoint protection remains essential, said Janosik. But autonomous systems are increasingly shaped by AI models, cloud services, software supply chains, update mechanisms and machine-to-machine communications.
Security teams therefore need visibility across the entire chain of interactions rather than viewing each device in isolation.
In environments running specialised robotics or non-standard communication protocols, that visibility must be achieved without disrupting operations – a familiar constraint for anyone who has tried to instrument operational technology.
At its user conference in Berlin in May 2026, where it announced a €40m investment in AI security, ESET outlined plans for a Secure AI Relay that would sit between users, AI agents, business applications and models. This gives investigators more context when something looks unusual, whether originated from software, infrastructure, AI services or user interactions.
“The same approach applies to embodied AI,” Janosik said. “The objective is no longer simply securing individual devices, but to understand and secure the entire decision chain that surrounds autonomous systems before attackers find opportunities to exploit it.”
Read more about cyber security in APAC
- Unauthorised access to a development and testing environment managed by IBM has exposed the names, NRIC numbers and property addresses of about 70,000 people held by the Singapore Land Authority.
- Japan’s Nikkei has confirmed a major data breach that potentially exposed the personal information of more than 17,000 employees and business partners after hackers infiltrated its internal Slack messaging platform.
- Australian privacy commissioner warns that the human factor is a growing threat as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high.
- Philippine bank BDO is shoring up its cyber security capabilities to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago.
