The Robot Safety Standard With Exactly One Author
Anthropic's new Model Hardware Standard is being sold as a safety spec for AI-controlled robots, but it launches closed, governed by one company, while the industry's actual functional-safety standard took fifteen years and a multi-stakeholder committee to write.

Thursday's announcement out of San Francisco read, on first pass, like a plumbing update. Anthropic released the Model Hardware Standard, a specification that lets an AI agent read a machine's capabilities and safety limits from one file instead of a custom integration, and called it a research preview open to sixteen partners across pharmaceutical labs, universities and industrial robot makers. Coverage treated it as the natural next step after the Model Context Protocol, the software-tool standard Anthropic shipped in 2024. That framing misses the more interesting story.
The Model Hardware Standard is not mainly a technical document. It is a bid to decide, by product decision rather than by committee, what an AI agent is allowed to command a robotic arm to do near a human hand. That distinction matters more than the demo footage suggests, because for as long as industrial robots have had safety rules, those rules have been written by exactly nobody who also sells the robot.
Consider the document MHS is quietly standing next to. ISO 10218, the core functional-safety standard for industrial robots, went through its first major revision in roughly fifteen years in January 2025, expanding from a combined 122 pages across its two parts to 318, folding in the previously separate collaborative-robot safety spec and adding cybersecurity requirements for the first time. That process ran through ISO's Technical Committee 299, a body of manufacturers, integrators, insurers and regulators who do not agree by default and had to reconcile a decade and a half of field experience before signing off. Nobody at that table sells a single robot brand. Anthropic's answer to the same category of question, what a machine may safely be told to do by an AI system, shipped as a company blog post and a closed partner list, with the company stating plainly that it is building "safety evaluations and best practices" with those partners ahead of open-sourcing the spec, not alongside a governance body that could outvote it.
Fifteen Years Versus One Blog Post
Anthropic has run this playbook once already, and the comparison is instructive precisely because MCP is the good version of the story. The Model Context Protocol launched open source from day one in November 2024. Within six months, Microsoft and GitHub had joined its steering committee, and OpenAI and Google had shipped their own support for it, none of which Anthropic could have compelled, all of which happened because the code and the governance were public from the start. That is the mechanism that turned MCP from one lab's convenience into shared infrastructure: competitors could see exactly what they were adopting, and could eventually help decide what it became.
MHS skips that step, at least for now. It launches closed, tested by a partner list Anthropic itself selected, with the open-source release deferred to an unspecified point after the preview generates the safety evaluations that will presumably justify it. A specification that only its author can currently amend is not yet infrastructure. It is a product with an infrastructure story attached, and the difference is not academic: infrastructure survives its creator changing course; a vendor spec does not.
A Partner List Bought Before the Rules Exist
None of this makes the sixteen partners naive. Genentech is piloting the standard on a protein-concentration assay that would otherwise need a specialist integrator to wire together a liquid handler, a robotic arm and a plate reader. Carnegie Mellon, the University of Washington's Baker and Pinglay labs and the HHMI Janelia Research Campus are running it against lab hardware they already own. On the industrial side, Universal Robots and Doosan Robotics, two of the cobot makers whose arms actually work assembly and quality-assurance lines today, are testing MHS support alongside Amazon Web Services' Strands Robots framework and Hugging Face's open-source LeRobot project, which lets the same interface reach down to hobbyist-grade arms as easily as a six-figure lab rig.
That range, from a university microscopy bench to a cobot shipping onto factory floors by the thousand, is the actual achievement here. Getting one specification to describe both without either category over-building for the other is a real design problem, solved well. But a coalition assembled before the governance exists is not a standards body. It is a beta cohort, and the distinction resolves itself the moment any partner disagrees with a decision Anthropic makes about the spec and discovers there is no vote to call.
A safety standard that only one company can currently amend is a product decision wearing a standard's clothing.
The Company Grading Its Own Sandbox
The timing compounds the trust question rather than resolving it. One month before the MHS preview, security researchers publicly documented a sandbox escape in Claude Cowork, Anthropic's software-agent product, that let a locally running session break out of its virtual machine and reach the host Mac's filesystem, including SSH keys and cloud credentials, on machines running the tool locally. Anthropic's own response was to make cloud execution the default going forward rather than patch the local escape path directly, leaving users who opt into local execution to harden their own configuration.
That episode predates MHS and involves a different product, so it is not evidence that the hardware standard itself is unsafe. It is evidence of something narrower and still relevant: a company whose most recent adjacent sandboxing effort failed against determined researchers is now asking labs and factories to trust the same company's internal judgment on what an AI agent may safely command a robotic arm to do, before any external body has reviewed that judgment. "We will build additional safety evaluations during the preview" is a reasonable research posture. It is a much weaker claim than a functional-safety certification, and buyers should not let one substitute for the other.
What This Actually Changes for a Buyer
None of this argues against testing MHS. For a facility already running Universal Robots or Doosan Robotics equipment, an integration format that turns weeks of specialist wiring into a task a line supervisor can complete is worth piloting on a low-stakes cell regardless of who governs the spec, because the integration-cost problem it targets is real and expensive today. What changes is what that pilot should be understood to prove. It shows whether MHS removes integration hours. It does not show that a machine described by an MHS file meets the bar the European Union will start enforcing on 20 January 2027, when its Machinery Regulation pulls AI-driven safety functions into third-party conformity assessment for the first time, rather than accepting a manufacturer's own declaration.
That deadline is the one to watch, not the preview's launch date. It will force the comparison this column is making now: whether an AI lab's internally authored safety file, produced on a preview timeline measured in months, satisfies a regulator built to expect the multi-year, multi-stakeholder process that produced ISO 10218:2025. Watching from a robotics data platform that spends its days reconciling what vendors announce against what the taxonomy can actually verify, the tell to track is not whether MHS gets adopted. Cobot makers will adopt useful integration formats regardless of who wrote them. The tell is whether Anthropic cedes control the way MCP eventually did, letting outside engineers sit on the committee that decides what the spec becomes next. Until that happens, every facility running an MHS-described robot is trusting one vendor's safety judgment on hardware that vendor does not build, sell or insure.
Hero image: Universal Robots' UR Series cobot family, courtesy of Universal Robots.
Disclaimer: This article is for general information purposes only and does not constitute investment, legal, or procurement advice. Readers should verify details with primary sources before making business decisions.












