Nvidia's Big Bet on Physical AI: Halos Safety Stack Expands from Robotaxis to Humanoid Robots

Published · AI Daily — AI-assisted deep research, methodology & disclosure

Nvidia launched Halos, a full-stack safety system for self-driving cars, in 2025. In June 2026 it announced Halos for Robotics, which carries the same approach into warehouse robots, factory humanoids and even surgical machines. The design runs the functional system and the safety system on the same silicon. It combines an independent safety processor, an operating system that monitors every hardware block and software library, sensor-data integrity checks, simulation, and an inspection lab. Agility Robotics' Digit 5 is the first adopter. Boston Dynamics, KION Group and LG are also working with the platform. Jensen Huang has said physical AI already drives nearly $10 billion in annual revenue.

Investors bullish on AI data centers may be fueling Nvidia's multitrillion-dollar market capitalization. Yet the chipmaker has also bet billions of dollars on physical AI, meaning robotics and self-driving cars. According to Jeremy Hsu's report for Ars Technica on October 8, 2026, a key part of that bet is a full-stack safety system. Companies can build on it to reduce the risk that their machines harm people nearby. 1. What was announced Nvidia launched Halos in 2025. It offered hardware and software tools that help developers put guardrails into self-driving cars and other autonomous vehicles. In June 2026 the company announced Halos for Robotics. This extends the safety architecture to more physical AI uses: autonomous mobile robots in warehouses, humanoid robots walking inside a factory, and even surgical robots. Amit Goel, head of robotics ecosystem and edge computing at Nvidia, told Ars that AI models and robot hardware are now capable. In his view, the next bottleneck is safety, and that is why Nvidia built the offering. The business context matters too. CEO Jensen Huang said on the All-In Podcast in March 2026 that physical AI already drives nearly $10 billion in annual revenue. He had named physical AI Nvidia's second-most important growth category in 2025. Nvidia has also invested directly in several robotics companies. These include the humanoid startups Agility Robotics and Figure AI, plus firms that build robotics foundation models. It has partnered with the Chinese humanoid maker Unitree on an open humanoid robot reference design for researchers.

2. The architecture, from chip to simulation The system starts with hardware. The Nvidia IGX Thor module, built for robotics and industrial use, includes an independent processor dedicated to safety-related workloads. Goel said that in physical AI, the functional system and the safety system must run on the same silicon. On the software side, the Halos operating system is designed to monitor every hardware block and every software library at all times, so it can spot failures quickly. It also isolates safety-critical computing workloads to avoid interference. On the data side, the Nvidia Holoscan Sensor Bridge links sensor data to safety-related processing and makes corrupted data easy to identify. It can be embedded in individual hardware components, such as a microcontroller or a field-programmable gate array.

The package also includes simulations for testing robots in virtual environments. It adds an inspection lab program. Robotics companies and other partners can use it to get quick feedback on safety artifacts that arise during development. 3. Why moving from cars to robots is hard Adapting Halos from autonomous vehicles to robotics meant accepting many definitions of safety. Functional safety for driving is largely the same across automakers and countries. A robot vacuum in a hallway and a robotic forklift hauling heavy payloads on a loading dock face very different safety questions.

Goel said the team had to reimagine its approach and do a lot of foundational work. The goal was a programmable platform with enough hooks for developers to define custom safety functions, without breaking the underlying infrastructure. He added that flexibility can come at the cost of losing some control over the stack. That is the hardest balance in the design. Custom functions matter because robots work in complex, varied places. Goel gave an example. A robot moving down an aisle at about six miles per hour cannot see blind spots or what waits around the corner. So it almost halts before the turn. Factories, warehouses and hospitals are unstructured, and things can come from anywhere. 4. Real deployments Agility Robotics was first to build Halos into its latest Digit 5 humanoid. The robot is designed to work safely near people without isolated workstations or physical barriers. Nvidia's system helped Agility bring all relevant safety sensors and hardware inside the robot. Earlier Digit operations also relied on external sensors placed around the work cell. Goel said the robot is now literally unchained. Safety goes with it, so no new infrastructure is needed for each new task.

Boston Dynamics, based in Massachusetts, is an early partner in the Halos safety accreditation program. It is building a safety platform that covers its Spot robot dogs, the wheeled Stretch with its large arm, and the Atlas humanoid. Atlas could begin deploying in factories of parent company Hyundai by 2028. Other companies working to adopt Halos include KION Group of Germany, which deploys self-driving forklifts and other autonomous mobile robots, and LG of South Korea. 5. What it means for the industry For developers, the most direct change is that safety shifts from a custom build to a reusable platform capability. Each robotics company once had to assemble its own monitoring, fault detection and verification flow. Now teams can build on shared silicon, an operating system, a sensor bridge and simulation tools, and use the inspection lab for faster feedback. That may shorten certification cycles and free teams to focus on the application.

For enterprise buyers, safety that travels with the robot should cut deployment cost. A factory or warehouse need not install dedicated sensors or fences for every new task, and robots can work across a wider area. For the ecosystem, Nvidia strengthens its position across chips, models, simulation and safety. One question follows. If many vendors share one safety platform, could a flaw in that platform become a shared risk? The article gives no data on this, so readers should stay cautious. 6. Outlook and open challenges A safety program is worth only what it proves in the field. A programmable safety layer splits responsibility between Nvidia and each developer. Custom safety functions that are poorly designed cannot be fully rescued by the platform. Blind spots in unstructured spaces will ease only through better perception, prediction and cautious motion policies. Still, the direction is clear. Once models and hardware stop being the bottleneck, proof that robots are safe around people will decide whether physical AI leaves the demo stage and reaches large commercial deployment. By investing here, Nvidia signals that it sees safety itself as a strategic asset that builds platform loyalty.

Sources