Humanoid Robots in the UK and Europe: Who Is Deploying Them, and the Security Questions Nobody Is Asking

- THE STATE OF PLAY: HUMANOIDS ARE NOW A UK AND EUROPEAN INDUSTRY
- WHERE HUMANOID ROBOTS WILL LAND IN THE UK: LONDON, MANCHESTER, NEWCASTLE AND TEESSIDE
- London: the commercial centre of UK humanoid robotics
- Manchester: robotics and AI research in the North West
- Newcastle and the North East: Britain's advanced manufacturing heartland
- Teesside: process industry, critical infrastructure and where we build
- HUMANOID ROBOT SECURITY RISKS: THE QUESTIONS NOBODY IS ASKING
- EU REGULATION OF HUMANOID ROBOTS IS ABOUT TO FORCE THE ISSUE
- WHAT UK FIRMS SHOULD ASK BEFORE DEPLOYING A HUMANOID ROBOT
- WHERE XIUM LABS FITS
- FREQUENTLY ASKED QUESTIONS
- How are humanoid robots being used in the UK today?
- Can humanoid robots really be hacked?
- What rules apply to deploying a humanoid robot in Europe?
- Do these EU rules affect UK companies?
- What should we do before deploying a humanoid robot?
By Endurance Idahosa, Xium Labs.
Humanoid robots moved from demonstration to commercial deployment in the UK and Europe during 2025 and 2026, backed by record investment. Every deployed humanoid is a networked computer with arms, and researchers have already demonstrated remote takeover, fleet-to-fleet compromise and covert data exfiltration on production platforms. From January 2027, EU rules make a cybersecurity risk assessment a condition of the CE mark itself. Firms adopting humanoids should be asking their vendors security questions now, before the machines arrive on site.
For years, humanoid robots were a demo category: impressive videos, no invoices. That changed. In 2026 the machines started turning up on European order books, and the money followed. Robotics companies have raised over 55 billion dollars globally so far this year, nearly double the previous record, and a meaningful share of it landed in the UK and Europe.
THE STATE OF PLAY: HUMANOIDS ARE NOW A UK AND EUROPEAN INDUSTRY
The clearest signal came from London. Humanoid, founded in 2024 by Artem Sokolov, closed a 152 million dollar Series A in July 2026 at a valuation of 1.35 billion dollars, making it Britain's first dedicated humanoid robotics unicorn. Bosch has signed on as its contract manufacturer, Schaeffler has placed a commercial order reported at 1,000 units, and the company plans to put beta robots into customer facilities across logistics, manufacturing and retail before the end of 2026.
Continental Europe is moving at least as fast. Germany's Neura Robotics raised a round of up to 1.4 billion dollars in June 2026, the largest ever for a European full-stack robotics company, with NVIDIA, Amazon, Qualcomm and the European Investment Bank among the backers. In Italy, Generative Bionics, a spin-off from the Italian Institute of Technology, unveiled its Gene.01 industrial humanoid in July 2026 with a first deployment planned in shipbuilding alongside Fincantieri. Barcelona's THEKER raised 85 million dollars the month before.
Established manufacturers are converting pilots into programmes. After an eleven-month trial in which two Figure humanoids contributed to production of more than 30,000 vehicles at a BMW plant in the United States, BMW confirmed it is extending its humanoid programme to Europe for the first time.
And the Chinese platforms have arrived. AGIBOT gave its A3 humanoid its European debut at a partner conference in London and launched a UK Robot-as-a-Service model, meaning British firms can now rent a humanoid rather than buy one. Unitree launched its H1 Pro commercially in Europe in July 2026. Robot-as-a-Service matters more than it sounds: it lowers the barrier to putting one of these machines inside your building from a capital decision to an operating expense.
WHERE HUMANOID ROBOTS WILL LAND IN THE UK: LONDON, MANCHESTER, NEWCASTLE AND TEESSIDE
National coverage of robotics tends to stop at the M25. The more useful question for UK businesses is where these machines will physically be deployed, and the answer maps onto the country's existing industrial geography.
London: the commercial centre of UK humanoid robotics
London is where Humanoid is headquartered, where AGIBOT chose to stage its European launch, and where the investors, insurers and enterprise buyers who will finance and underwrite humanoid fleets sit. Early UK deployments in logistics and retail will be signed here even when the warehouses are elsewhere.
Manchester: robotics and AI research in the North West
Manchester carries the research weight in the North West. The University of Manchester's Centre for Robotics and AI is among the UK's leading robotics research groups, with over a hundred academic and research staff and a project portfolio spanning nuclear decommissioning, flexible manufacturing and healthcare robotics, including the CRADLE partnership with engineering firm Jacobs on autonomous systems for demanding environments. The talent and spin-out pipeline for UK embodied AI runs substantially through this cluster, and Greater Manchester's industrial base gives it deployment sites on its doorstep.
Newcastle and the North East: Britain's advanced manufacturing heartland
Newcastle and the wider North East is arguably the most natural early home for industrial humanoids in Britain. Advanced manufacturing contributes around 8.4 billion pounds to the regional economy across nearly 4,000 businesses, anchored by Nissan's Sunderland plant, which accounts for roughly 30 per cent of UK car production, alongside Hitachi Rail, Komatsu and the robotics manufacturer Tharsus in Blyth. Newcastle University's work on electrification and sustainable advanced manufacturing, and the region's Centre of Excellence for Sustainable Advanced Manufacturing, give the North East both the factories that want humanoid labour and the institutions studying how to integrate it.
Teesside: process industry, critical infrastructure and where we build
Teesside rounds out the picture with process industry. The North East hosts the majority of the UK's chemical industry, much of it concentrated around Teesside's petrochemical and advanced manufacturing sites. These are precisely the environments where humanoid vendors pitch their machines: repetitive materials handling, inspection in conditions unpleasant for people, and round-the-clock operation. They are also, in many cases, adjacent to critical national infrastructure, which is exactly why the security questions below stop being theoretical the moment a networked robot walks through the gate. Xium Labs operates from London and Teesside, and the overlap between this region's industry and the direction of embodied AI is precisely where we have chosen to build.
HUMANOID ROBOT SECURITY RISKS: THE QUESTIONS NOBODY IS ASKING
Here is the uncomfortable part, and the reason we pay this market such close attention. A humanoid robot is not a machine in the traditional sense. It is a mobile, networked computer running an AI stack, fitted with cameras, microphones, radios and actuators strong enough to injure a person, with an over-the-air update channel back to its manufacturer. Every one of those properties is an attack surface, and the research community has already shown that the risks are practical, not hypothetical.
In 2025, security researchers at Alias Robotics published an assessment of one of the world's most widely distributed commercial humanoids, the Unitree G1, documenting a vulnerability chain that handed an attacker root access over Bluetooth, along with static cryptographic keys and continuous telemetry streaming to servers overseas. That research was cited in testimony before the United States Senate in early 2026, and it fed into a US national security determination on foreign-produced humanoids, which also described a case where a compromised robot could scan for and infect nearby robots, creating a self-propagating humanoid botnet. Separately, researchers at a public security competition demonstrated a compromised humanoid spreading its compromise to fleet peers, and academic work has documented dozens of covert data streams leaving a commercial humanoid platform.
The AI layer adds a newer class of problem. The vision-language-action models that let these robots understand instructions and environments have shown very poor resistance to adversarial attacks in physical settings, meaning a crafted visual pattern in the robot's environment can manipulate its behaviour. And in controlled experiments, researchers demonstrated that an AI agent running on a compromised robot could autonomously map the network it sat on, discover exposed credentials and generate attacks against the manufacturer's own cloud control systems. A robot on your factory network is, in the worst case, a pivot point into everything else on that network.
None of this is an argument against adopting humanoids. It is an argument for treating them the way a mature organisation treats any powerful connected system: assessed before deployment, segmented on the network, monitored in operation.
EU REGULATION OF HUMANOID ROBOTS IS ABOUT TO FORCE THE ISSUE
If the threat research does not move procurement teams, the law will. Three European instruments converge on this market over the next eighteen months.
The EU Machinery Regulation (2023/1230) applies in full from 20 January 2027 and explicitly covers machinery with digital and AI components. From that date, a cybersecurity risk assessment becomes part of the conformity assessment a robot needs to earn its CE mark. No assessment, no European market. In regulatory terms, a security flaw in a robot is now a safety defect.
The EU Cyber Resilience Act (2024/2847) imposes reporting duties from 11 September 2026: a manufacturer that learns its product carries an actively exploited vulnerability has 24 hours to make its first report, with penalties running to 15 million euros or 2.5 per cent of global turnover. Full application follows in December 2027.
The EU AI Act layers on top for robots whose AI performs functions like biometrics or acts as a safety component, with high-risk obligations phasing in through 2027 and 2028 following the May 2026 Digital Omnibus adjustments.
For UK firms, Brexit does not provide an exemption worth relying on. Any UK manufacturer or integrator selling into the EU meets these rules head-on, UK product security law is evolving in the same direction, and insurers and enterprise customers increasingly treat the EU baseline as the de facto standard regardless of jurisdiction. One independent analysis estimated that fewer than 15 per cent of commercial humanoids on the market in 2026 hold a complete industrial CE file. The gap between what is being sold and what will be lawful to deploy is, for the moment, wide, and it is the deployer who inherits much of that risk.
WHAT UK FIRMS SHOULD ASK BEFORE DEPLOYING A HUMANOID ROBOT
If your organisation is evaluating humanoid robots, whether purchased or rented through a Robot-as-a-Service arrangement, these are the questions we would put to any vendor before signature:
Where does the robot's telemetry go, what does it contain, and can you contractually restrict it? Cameras and microphones on a mobile platform inside your facility are a data protection matter, not just an IT one.
How are over-the-air updates signed, delivered and verified, and what happens if the update infrastructure is compromised?
What is the robot's Bluetooth, Wi-Fi and cellular footprint, and can each radio be disabled or restricted?
Has the platform undergone independent penetration testing, and will the vendor share the report or a summary of findings and fixes?
Can the robot be network-segmented from your operational and corporate systems without losing core function?
What is the vendor's vulnerability disclosure and patching commitment, and does it meet the Cyber Resilience Act's timelines?
Who completes the CE conformity file, including the cybersecurity risk assessment, for the machine as deployed in your environment, you or the vendor?
If a vendor cannot answer these fluently, that tells you something about the maturity of what you are buying.
WHERE XIUM LABS FITS
We sit on both sides of this shift. Xium Labs builds the software layer that this generation of robotics runs on, from AI products to intelligent automation, and our offensive security practice exists to break connected systems before criminals do. Embodied AI is the natural next step in that work, and it is a space we are actively building in ourselves, with more to share on that soon. That vantage point shapes how we assess these machines. The same discipline we apply in our LLM and AI security testing applies to a robot fleet: the AI models that drive decisions, the companion mobile apps that control these machines, the cloud APIs they report to, and the networks they join. If your organisation is planning a robotics or AI deployment and wants the security questions answered before the machines arrive rather than after an incident, talk to us.
FREQUENTLY ASKED QUESTIONS
How are humanoid robots being used in the UK today?
At early commercial stage. London-based Humanoid plans beta deployments at customer sites from late 2026 and holds a substantial pre-order book, while AGIBOT's UK Robot-as-a-Service model lets British firms rent humanoids for pilots. Widespread deployment is still ahead, but procurement is happening now.
Can humanoid robots really be hacked?
Published research has demonstrated remote takeover of a production commercial humanoid, including root access gained over Bluetooth, and controlled experiments have shown a compromised robot attacking other systems on its network. The risks are documented on real platforms, not speculative.
What rules apply to deploying a humanoid robot in Europe?
From January 2027 the EU Machinery Regulation makes a cybersecurity risk assessment part of the CE conformity process, the Cyber Resilience Act imposes vulnerability reporting duties on manufacturers from September 2026, and the EU AI Act adds obligations where the robot's AI is a safety component or performs high-risk functions.
Do these EU rules affect UK companies?
Directly, if you sell or deploy into the EU. Indirectly in almost every other case, because enterprise customers, insurers and UK regulation are converging on the same expectations. Treating the EU baseline as your standard is the pragmatic position.
What should we do before deploying a humanoid robot?
Segment it from critical networks, restrict and audit its telemetry, verify the vendor's update and patching process, confirm who owns the CE and cybersecurity conformity file for your deployment, and commission an independent security assessment of the robot, its companion applications and its cloud services before it goes live.
Keep reading
All articles →
Industry InsightsHow UK AI Policy Is Reshaping AI Adoption in the North East, Manchester and London
The AI Opportunities Action Plan and the new AI Growth Zones are redrawing the UK's tech map. What the North East's 30 billion pound zone, Manchester's surge and London's scale mean for business.
Read more→
Cyber SecurityHow Much Does Mobile App Penetration Testing Cost in the UK? (2026 Pricing Guide)
What does a mobile app pentest cost in the UK? Realistic 2026 price ranges, the factors that move the number, and how to scope a test without overpaying.
Read more→
AI SecurityLLM & AI Security Testing: A Technical Guide to the OWASP LLM Top 10
Traditional pentesting misses how LLM applications fail. A technical walkthrough of the OWASP LLM Top 10, with prompt-injection examples, testing code and a methodology mapped to NIST AI RMF and MITRE ATLAS.
Read more→