Robots are leaving isolated factory cages and entering work areas where people load parts, inspect products, recover faults, and change tasks. Better sensors and more capable software make that cooperation useful, but they do not make a robot application safe by themselves. Safety depends on the complete system: the arm, tool, workpiece, surrounding machines, control software, layout, and every task a person may perform.
That system view is central to the 2025 editions of the international ISO 10218 robot-safety standards. One part addresses the industrial robot as a partly completed machine. The other addresses the finished application and robot cell. The distinction sounds administrative, but it explains why buying a robot marketed as collaborative is only the beginning of the safety work.
The Robot Is Not the Whole Application
An industrial arm usually arrives without the final gripper, welding torch, sharp component, conveyor, fixture, or production program. ISO 10218-1:2025 focuses on the robot manufacturer’s responsibilities, including inherently safer design, protective measures, and information needed for integration. ISO 10218-2:2025 covers the integrator’s work across design, commissioning, operation, maintenance, decommissioning, and disposal of the completed application.
A slow arm carrying a blunt foam block presents a different risk from the same arm moving a sheet-metal panel or operating a cutting tool. A mobile base adds changing approach paths. A vision model may alter which object the machine selects. These details belong to the application-level assessment rather than to a generic claim that the robot is safe.
This is also why progress in robot foundation models and physical AI increases the importance of integration. More flexible behavior can reduce programming effort, but it creates more states, tool choices, and recovery cases that designers must consider.
Risk Assessment Starts With Tasks
A useful assessment follows what people and machines actually do. Normal production is only one state. Workers may teach a path, clear a jam, replace a tool, clean a sensor, retrieve a dropped part, or enter the area after an emergency stop. Maintenance personnel may need power for diagnosis even when ordinary lockout procedures would otherwise remove energy.
For each task, the team identifies hazards, estimates exposure and possible harm, then chooses risk-reduction measures. Those measures follow a hierarchy. Eliminate the hazard where possible, reduce it through design, add guards or safety-rated controls, and then support the remaining risk with procedures, training, and protective equipment. A warning label is not a substitute for a design change that prevents access to a crushing point.
OSHA’s industrial robot guidance similarly treats the end effector, controller, energy sources, interfaces, and surrounding equipment as one robot system. It recommends evaluating installation, testing, operation, and maintenance rather than judging only the manipulator.
“Collaborative” Describes an Application
The word cobot is often used as if it were a permanent safety category. In practice, collaboration is a way an application is designed and operated. Common approaches include a safety-rated monitored stop when a person enters; hand guiding through a controlled device; speed and separation monitoring that slows or stops motion as distance closes; and power-and-force limiting that constrains contact.
Each method has conditions. A power-and-force-limited arm can still become dangerous with a sharp tool, a heavy payload, a trapping point, or excessive speed. A separation system depends on the coverage, resolution, response time, and failure behavior of its scanners or cameras. Hand guiding requires a controlled mode and a deliberate interface. The relevant question is not whether the robot has a collaborative badge, but whether the complete task has been validated.
That distinction matters for the humanoid systems discussed in our article on what humanoid robots need before they scale. A human-shaped machine may fit an existing workspace, yet its mobility, reach, balance, carried objects, and learned behavior introduce risks beyond those of a fixed industrial arm.
AI and Vision Are Not Automatically Safety-Rated
Modern robots can use cameras, neural networks, and force sensing to recognize people and adapt motion. Those capabilities may improve awareness, but a normal perception system is not automatically a safety function. A safety-related control must meet defined reliability, diagnostic, response-time, and failure requirements. Designers should know what happens when a camera is blocked, lighting changes, a network connection drops, or a model produces an uncertain result.
NIST’s robotics program is developing measurement methods for perception, manipulation, mobility, and human-robot interaction. This work is important because repeatable performance evidence is needed before emerging capabilities can support dependable industrial decisions. A polished demonstration is not the same as validated coverage across foreseeable conditions.
Recovery and Maintenance Deserve Special Attention
Many incidents occur outside steady production. A machine stops in an unusual pose, a part is wedged in a fixture, or an operator reaches into a cell to restore flow. The safest recovery design gives people a clear state indication, controlled access, limited motion, and an unambiguous way to prevent unexpected restart.
Energy is not limited to electricity. Pneumatic pressure, hydraulics, gravity, springs, hot surfaces, and a suspended load may remain hazardous after the main drive stops. Software state matters too: a recovered network connection or queued command should not surprise a person inside the work area.
Good systems also preserve evidence. Safety events, bypasses, mode changes, faults, and maintenance actions should be recorded so recurring problems can be corrected. The goal is not to blame an operator for entering a hazardous state. It is to redesign the workflow so the predictable need to recover production can be handled safely.
What Buyers and Workers Can Ask
A robot buyer should ask who is responsible for the application risk assessment, which edition of the relevant standards was used, and how the finished cell will be validated. The documentation should identify payload and speed limits, approved tools, safeguarding assumptions, inspection intervals, training needs, and the procedure for changes.
Workers should be involved before the layout is frozen. They understand how parts arrive, where jams occur, and which shortcuts a difficult process is likely to encourage. Their input can reveal hazards that are invisible in a simulation. After commissioning, any meaningful change to tooling, payload, program, speed, layout, or human task should trigger a review rather than being treated as a harmless software update.
Limits of the Standards
ISO 10218 is aimed at industrial robots and applications. Its published scope excludes areas such as medical robots, consumer products, service robots accessible to the public, and robots that lift or transport people. Mobile manipulators and other emerging systems may also require additional standards and local regulatory requirements.
A standard is not a guarantee that no incident will occur. It provides a common engineering framework. Real safety still depends on competent integration, accurate assumptions, validation, maintenance, training, and a willingness to stop production when the system behaves unexpectedly.
What to Watch Next
Watch for updated national adoptions of the 2025 ISO documents, clearer rules for mobile manipulators, and better test methods for AI-enabled perception and contact. The most credible vendors will publish operating limits and validation evidence instead of relying on general claims about intelligence or collaboration.
Robotics is moving from carefully scripted cells toward the adaptable workflows described in our overview of robots entering real operations. That transition will succeed only when flexibility and safety are engineered together.


Leave a Reply