DEV Community

Cover image for When the Robot Needs a Badge: Physical AI Meets Access Control
Andrii Slobodskyi
Andrii Slobodskyi

Posted on

When the Robot Needs a Badge: Physical AI Meets Access Control

An autonomous robot can plan an inspection route, but a route is not permission. When that route reaches a controlled electrical room, the robot needs more than a navigation instruction or a signal to open the door. The facility must recognize the requester, determine whether it is authorized to enter, and allow the physical passage to take place safely.

A recent collaboration between ANYbotics, dormakaba, and LEGIC demonstrates how those requirements can work together. At GE Vernova's Whitegate power station in Ireland, the companies tested a solution that allows the ANYmal inspection robot to pass through an access-controlled door using a digital credential. The pilot involved two automated doors, including a controlled entrance to an electrical room.

For engineers working with robotics, connected infrastructure, and physical security, this is an interesting example of an autonomous machine interacting with a system that was originally designed to control access for people. The robot can pursue its inspection mission, but the facility still decides whether it may enter a protected area.

Why navigation alone cannot complete an inspection route

Industrial inspection robots can follow planned routes, collect measurements, and revisit equipment without requiring a technician to walk through the facility for every inspection. Their usefulness depends partly on how much of the site those routes can cover. A robot may be capable of reaching an equipment room geographically while remaining unable to enter because the door is closed or access-controlled.

Those barriers serve legitimate operational purposes. Doors may protect electrical equipment, separate working areas, or preserve fire compartments. Making a route accessible to an autonomous machine should not require the facility to abandon the functions those doors provide.

ANYbotics describes three previous approaches to the problem: leaving doors open where permitted, deploying separate robots in different areas, or accepting gaps in inspection coverage. Each imposes an operational limitation, whether through restrictions on where doors can remain open, additional robot deployments, or incomplete inspection routes.

The Whitegate project takes a different approach. Instead of designing the inspection mission around an inaccessible doorway, it allows ANYmal to interact with the door infrastructure already installed in the facility. The robot can continue its work when the appropriate access conditions are satisfied, while the entrance remains subject to the site's established rules.

Door automation and access control are separate responsibilities

The collaboration addresses both ordinary automated doors and entrances protected by access control. Although the physical outcome may look identical, the two scenarios require different functions.

At a door without access control, the primary task is coordinating physical movement. The automated door needs to operate in response to the approaching robot, provide a safe passage, and close after the robot has moved through it. ANYbotics and dormakaba have developed this configuration for deployment without introducing an access-authorization requirement where one does not already exist.

A controlled entrance involves an additional layer. The system must establish which robot is requesting entry and determine whether that specific machine may use the door at that time. Simply detecting the robot would not provide the authorization required for entry into a restricted space.

The three partners contribute different parts of this interaction. ANYbotics supplies ANYmal and develops its interaction with the door. LEGIC supplies the digital credential carried by the robot, while dormakaba provides the access-management environment and automated door solution.

These responsibilities remain distinct even when the overall interaction appears seamless. A valid credential does not physically open a door, and an automatic door operator does not establish whether the approaching machine should be admitted. Both functions must be integrated with the robot's ability to recognize when passage is possible.

The implementation also depends on suitable door automation and integration. It should not be understood as a universal zero-touch feature that can be enabled on any existing doorway without additional work.

How the robot's access request is handled

At an equipped access-controlled entrance, ANYmal presents its LEGIC credential to the facility's access-management system. The system verifies the robot's identity and checks whether it is permitted to pass through that particular door at that time.

Once authorization is granted, the automated door confirms that it can operate safely and opens. ANYmal then verifies that the passage is physically open before moving through it. After the robot passes, the door closes and the inspection mission continues.

ANYbotics describes four checks within this interaction: identity, authorization, safe operation, and physical verification. They address related but different requirements, and none can simply be substituted for another.

Identity establishes which machine is requesting access. Authorization determines whether that machine has permission to enter the protected area. The door's safe operation and the robot's verification of the passage address the physical conditions required to complete the movement.

The distinction is particularly relevant to autonomous systems. A successful access decision does not, by itself, establish that the physical environment is ready for the robot to proceed. Likewise, an open doorway does not establish that the robot was authorized to enter.

The denied-access behavior preserves the same separation of responsibilities. According to ANYbotics, if the request is rejected, the door remains secured while the robot reports the issue and adapts its mission. The inspection route does not override the facility's access decision.

Access rights are administered centrally through the existing access-management environment. The partners describe the robot as operating under the facility's established access processes rather than under a separate permission system controlled solely by its navigation software.

There is an important documentation boundary here. The public announcements do not describe the credential transmission protocol, internal access-system data model, or detailed cryptographic implementation. The demonstrated integration supports an architectural explanation of the access process, but not a reconstruction of its undocumented internal mechanisms.

What the Whitegate pilot actually demonstrated

The pilot took place at GE Vernova's Whitegate power station in County Cork, Ireland. Two doors were automated, including an access-controlled entrance to an electrical room. The participating companies reported several weeks of live operation during which ANYmal repeatedly requested access, passed through the controlled entrance, and continued its inspection rounds without manual intervention.

The operational opportunity is easier to understand when considering the inspection work beyond that entrance. In ANYbotics' account of the project, a Whitegate engineer described a room containing approximately 400 readings that had normally been collected by a contractor once a year. With the door-opening solution, the stated intention is for ANYmal to collect those readings daily.

That difference in measurement frequency could provide maintenance teams with a more detailed picture of how equipment conditions develop over time. More frequent observations may also create additional opportunities to identify changes that would be difficult to recognize from infrequent manual inspections.

The distinction between the demonstrated result and the expected benefit is important. The reported live operation establishes that the robot repeatedly passed through the controlled entrance and continued its mission. The proposed daily collection of approximately 400 readings is an intended operational benefit, not a published record of completed daily inspection cycles.

The companies have not published an independent security assessment or quantified cost and defect-detection outcomes for the pilot. Its documented value is the successful integration of autonomous inspection with the facility's access-controlled infrastructure in a live industrial environment.

That result addresses a practical limitation. An inspection robot can reach equipment behind a controlled entrance without requiring the door to remain permanently open or bypassing the facility's authorization process.

Access management becomes part of robot deployment

Introducing an autonomous robot into a facility with protected areas expands the scope of deployment planning. Navigation, inspection sensors, mission configuration, and connectivity remain essential, but the inspection route must also account for the systems that control entry to restricted spaces.

A facility using this approach needs to consider how the robot receives its credential, which entrances it may use, and who administers those permissions. Door automation must also be integrated with the robot's interaction, while mission behavior needs to accommodate a denied access request.

These are engineering implications of the Whitegate integration, not claims about additional undocumented product capabilities.

The collaboration also brings several areas of professional responsibility together. Robot specialists work with navigation and inspection behavior, access-control specialists manage the credential and permission environment, and the door infrastructure must operate safely during the physical passage.

The facility's existing access-management processes provide a common basis for those responsibilities. Rather than giving the robot unrestricted movement to complete its route, the operator can administer its access rights through the same environment used to control entry to protected areas.

This matters as industrial inspection systems become more closely connected to building and security infrastructure. A robot's ability to perform useful work depends not only on its own sensors and navigation capabilities, but also on whether the surrounding facility can accommodate its authorized movements.

The Whitegate pilot shows one way of making that interaction operational. Physical security remains responsible for controlling access, while the autonomous system gains a means of requesting the access its mission requires.

What comes after the first controlled door

ANYbotics says the access-controlled configuration is available on request, with a full rollout planned for 2027. The partners are also exploring future applications involving elevators, gates, and turnstiles.

Those possible extensions should be distinguished from what was demonstrated at Whitegate. The pilot establishes the interaction with automated doors, including an access-controlled entrance. It does not establish completed integrations with every other type of controlled infrastructure, nor does it demonstrate a universal access protocol for autonomous machines.

Nevertheless, the underlying engineering problem is relevant beyond the particular installation. Autonomous equipment working inside real facilities must coexist with physical boundaries, permission rules, and operational processes that were established for legitimate reasons. Greater autonomy does not eliminate those requirements.

The Whitegate project illustrates how a machine can participate in an existing access-management environment while the facility retains the authority to determine where it may go. Digital identity, authorization, door automation, and physical verification work together to support the inspection mission without making movement unrestricted.

The significant development is not that ANYmal can pass through another doorway. It is that an autonomous machine can request entry as an identifiable, authorized participant in the facility's existing infrastructure.

Autonomy becomes more useful when a machine can work within the rules of its environment, rather than requiring those rules to be removed.

Sources and further reading


AI disclosure: This article was drafted with AI from a human-reviewed, primary-source-verified technical master.

Top comments (0)