RobotAIGeek

A Quadruped Just Got a Building Badge. Access Control Has No File For It.

ANYbotics' quadruped ANYmal just passed through secured doors at a GE Vernova power plant on its own digital access credential, via a pilot with dormakaba and LEGIC. The mechanics are a genuine safety win, but physical security has no equivalent of cybersecurity's "non-person entity" governance category for a badge holder that isn't a person, and the industry adopting this fastest has the least room for that accountability gap.

martti
4 min readPosted: Sep 26, 2026
A Quadruped Just Got a Building Badge. Access Control Has No File For It.

A door at a power station in Cork, Ireland, opened this month for something that was not a person and was not, in the way the building's own systems understand things, an object either. The door belongs to GE Vernova's Whitegate plant. What opened it was ANYmal, the four-legged inspection robot built by the Swiss company ANYbotics, carrying a digital credential issued through a joint pilot with access-control group dormakaba and identification-technology firm LEGIC Identsystems. The robot walked its inspection route, reached a secured door, requested access the way the door's own management system expected a request to arrive, and passed through without a human opening it, badging it through, or standing nearby to vouch for it.

That is the part getting covered as a product story. The part that is not getting covered is the one that actually matters: access-control systems and their audit trails were built around a simple assumption, that whoever holds a credential is a person who can be identified, trained, disciplined, or fired. Cybersecurity ran into this same problem years ago, when service accounts and automated processes started needing digital identities too, and it built a formal category for it. Physical security just quietly acquired its first equivalent case, and it does not yet have the category to put it in.

What The Pilot Actually Did

The mechanics, per dormakaba's own account of the program, are unglamorous by design. ANYmal carries a secure digital credential and, on reaching a controlled door during an unmanned inspection round, requests passage through dormakaba's access-management and door-automation systems the same way the system is built to receive any access request. The pilot ran for several weeks at Whitegate, a live operating power plant, not a test rig, with ANYmal completing autonomous inspection rounds and clearing secured doors without a person present to intervene. Dormakaba, ANYbotics, and LEGIC presented the results together at LEGIC's own connect26 event in Zurich.

The people attached to the announcement described it in terms that are worth separating from the mechanics. LEGIC's general manager, Mehdi Elhaoussine, called it a major step into what he termed physical AI. That is his characterization, not an independently verifiable fact, and it is fair framing for a company selling credential technology into a robotics market it wants to expand into. Dormakaba's chief executive, Till Reuter, and ANYbotics' chief executive, Péter Fankhauser, are both named in the same joint release, which states a commercial rollout across the ANYmal fleet is planned later this year, with elevators, gates, and turnstiles named as the next targets for the same credential.

None of that is small. A patrol robot that can only open doors a person opens for it is a robot on a leash. A patrol robot that carries its own building credential is a robot that has been admitted, procedurally, into the same identity system a human employee is admitted into. The leash is what just came off.

The Category That Does Not Exist Yet

Here is the piece the "physical AI" framing skips past. Cybersecurity solved a narrower version of this exact problem more than a decade ago. NIST's own glossary defines a Non-Person Entity, a formal identity category for something acting in a digital system that is not a human: a service account, a device, an automated process. That category is not a footnote. It sits underneath NIST's access-control guidance for enterprise systems and its zero-trust architecture standard, both of which assume that some share of the identities requesting access to anything will not be people, and both of which were written specifically so that an automated audit trail can say what a non-human credential holder was authorized to do and when it did it.

I looked for a physical-security equivalent: a standard, a framework, a working group, anything that formally treats a robot's building credential the way NIST treats a service account's network credential. I did not find one. That does not mean nothing exists anywhere; it means there is no documented governance framework for it today, in an industry that is about to need one faster than it expects.

This is the sentence worth sitting with: the audit trail for "who opened this door" is about to start returning an answer that is not a name.

That gap is not hypothetical friction. A power-plant operator's door log exists for a reason that has nothing to do with convenience: when something goes wrong at 3 a.m., the log is supposed to tell an investigator who was where. A credential that identifies its holder as a robot rather than a person answers a different question than the log was designed to answer, and the industry that built the log has not yet decided what the right answer looks like. Was the robot behaving inside its authorized route? Did its credential get suspended when its last software update failed. Who is the accountable party when the door log says the robot opened it and something on the other side was disturbed? None of those questions are answered by "physical AI." They are answered, if at all, by whatever governance framework physical security eventually builds, and right now it is building the deployment faster than the framework.

What Gets Traded Away

The tradeoffs here are not abstract. An unmanned inspection round at a power plant is a genuine safety improvement: fewer people walking routes near industrial equipment at odd hours, in a facility where GE Vernova has every reason to want fewer avoidable human-injury incidents. That benefit is real and I am not arguing against the pilot. What I am arguing is that the industry adopting this fastest, energy and industrial infrastructure, is also the industry with the least tolerance for an unaccountable access-control gap, and it is adopting a robot-as-badge-holder model before anyone outside three companies and a standards body's glossary has worked out what accountability looks like when the credential holder cannot be interviewed.

There is also a quieter risk in the framing itself. Calling this physical AI invites comparison to a technology leap. The more accurate comparison is a governance regression: an industry re-learning, door by door, a lesson enterprise identity management already learned about service accounts, except this time the thing carrying the non-human credential can also fall down a stairwell, get physically tampered with, or be duplicated in a way a software service account cannot be.

What I Would Watch Next

The commercial rollout dormakaba and ANYbotics have signaled for later this year is the thing to track, not the Zurich announcement. Every additional door type they add, elevators, gates, turnstiles, is one more place where the current answer to "who is accountable for this robot's access decision" is a shrug dressed up as a keynote quote. The honest test of whether this industry has actually solved the problem, rather than shipped around it, is whether any of the three companies involved, or a body like the Security Industry Association, publishes something that reads like NIST's non-person entity guidance but for a badge that walks. I have not seen that document yet. Until it exists, every additional door this credential opens is a door where the audit trail already knows less than the building thinks it does.

This column reflects the author's own analysis of public company statements and standards documentation current as of September 26, 2026. It is for general information purposes only and does not constitute investment, financial, or legal advice.

Hero image: ANYbotics' ANYmal robot on an unmanned inspection round at an industrial facility, official pilot photography. Credit: dormakaba.

Access ControlANYboticsPhysical AIRobot GovernanceSecurity StandardsQuadruped RobotsIndustrial Robotics