Gemini Robotics 2: Google DeepMind Gives AI a Body, but the Attack Surface Expands

Google DeepMind's Gemini Robotics 2 controls full humanoid robots offline, but expanding AI autonomy increases the physical attack surface and cyber risks.

Gemini Robotics 2: Google DeepMind Gives AI a Body, but the Attack Surface Expands
AI

Illustrative image generated with AI

On July 30, 2026, Google DeepMind announced Gemini Robotics 2, an artificial intelligence model designed to control the entire body of a humanoid robot. Unlike its predecessors, which were limited to arms or hands, the new system also controls lower limbs, torso, and five-fingered hands. The robots can walk, crouch, stretch, and perform fine manipulation tasks: sealing envelopes, unscrewing light bulbs, grasping irregularly shaped objects.

A Model for Embodied Reasoning and Collaboration

Alongside Gemini Robotics 2, DeepMind also released Gemini Robotics ER 2, a vision-language model dedicated to “embodied reasoning”. ER 2 can recognize the start and end of multi-step activities and orchestrate collaboration among different types of robots. A mobile robot can transport a component and hand it over to a fixed robot with a gripper to complete an assembly.

The on-device model (Gemini Robotics On-Device Model) operates without connectivity and quickly adapts to different morphologies, from Google’s dual-arm robots to the Apptronik Apollo 2 humanoid. This broadens potential use cases: logistics, assistance, and offline environments.

More Autonomy, More Risk

Extending control to the entire body and offline operation increase human-machine proximity. Kaushik Subramanian, head of robotics safety at DeepMind, called Gemini Robotics ER 2 “the safest model ever built.” It includes a human presence detection system that triggers an emergency stop if a person gets too close.

On-device execution reduces exposure to network attacks but doesn’t eliminate the problem. A compromise of the firmware or the model could disable safety systems. And the ability to control a robot’s entire body in shared spaces turns a cyberattack into a real physical risk.

Collaboration among heterogeneous robots introduces operational interdependencies. A single compromised node could propagate incorrect instructions throughout the entire system. No CVEs have been disclosed, but the attack surface grows with each new degree of freedom.

Mitigations Are Just a Starting Point

DeepMind hasn’t described specific hardening measures beyond proximity detection and offline operation. General principles for autonomous systems still apply: network segmentation, strong authentication for firmware updates, continuous validation of model integrity. Deploying humanoids in production and assistance environments will require stricter standards. And a regulatory framework that currently doesn’t exist.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →