Nvidia Halos: An Open-Source Safety OS for Robots
At Automate 2026, Nvidia launched Halos for Robotics, a full-stack robot safety system that opens 18,600 engineering-years of autonomous-driving safety know-how to the embodied AI industry — the core safety framework is already open, with 43 companies on board.


Nvidia Halos: An Open-Source Safety OS for Robots
At Automate 2026, Nvidia launched Halos for Robotics, a full-stack robot safety system that opens 18,600 engineering-years of autonomous-driving safety know-how to the embodied AI industry — the core safety framework is already open, with 43 companies on board.
The problem robotics faces today looks a lot like autonomous driving a decade ago — the models keep getting smarter, but what actually determines deployment usually isn't the model itself; it's safety. Traditional industrial arms bolted to a workstation can get by with physical guarding, but once autonomous robots start sharing space with humans, safety becomes a system-level problem.
At Automate 2026 in Chicago, Nvidia unveiled Halos for Robotics: a full-stack robot safety system spanning chips, sensors, the operating system, and safety certification. It brings Nvidia's accumulated autonomous-driving work — more than 18,600 engineering-years and 7 million lines of verified code — into robotics, and the core safety framework has been open-sourced to the entire industry.
If Tesla is taking the iOS route (build the robot yourself, do safety yourself), Nvidia has chosen the Android route: open the safety platform to everyone. So far 43 companies have joined, including humanoid robot maker Agility, Boston Dynamics, lidar vendor Hesai, and safety robotics firm FORT Robotics.

Halos aims to give embodied AI companies a unified safety architecture — plug in and go, no reinventing the wheel.
What Halos Is
Think of it as a safety Android for robots: not a specific robot product, but a safety middleware layer running from low-level hardware up to certification. A robot company that adopts it effectively reuses a proven safety infrastructure.
Per the official architecture, Halos stacks four layers bottom-up, corresponding to the four sources of error when robots operate in the real world.
Core Capabilities
Layer 1: Platform Safety (Hardware Doesn't Fail)
The bottom layer is the IGX Thor compute platform plus a safety microcontroller, forming a hardware-level "safety island." If the AI layer above goes wrong, the hardware still guarantees minimal safe shutdown and basic control — no more "AI strikes and the whole machine dies."
Layer 2: Safety Operating System (The System Stays Orderly)
Halos OS runs on top of IGX Thor, with Halos Core underneath, supporting two modes:
- Pure Linux
- Linux + QNX hybrid architecture (recommended for safety-critical scenarios)
The latter uses a hypervisor to split the system into two fully isolated execution domains:
- Linux handles AI compute and applications
- QNX handles safety-critical tasks
Even if the AI application layer crashes abnormally, the safety control logic is unaffected — a "software isolation wall" stacked on top of the hardware safety island. Above this layer sit the safety application modules, the most notable being the Outside-In Safety system, currently open-sourced to developers.

Halos' four layers: platform safety, safety OS, algorithm safety, ecosystem safety.
Layer 3: Algorithm Safety (AI Doesn't Misjudge)
This layer governs the decision risk of the model itself. A VLA (vision-language-action) model or VLM (vision-language model) might misread a cardboard box as a person, or a person as an obstacle. Layer 3 evaluates and constrains the physical-world behavioral safety of models, stopping "misunderstandings" before they become "dangerous actions."
Layer 4: Ecosystem Safety (Who Certifies)
The top layer turns the whole system into an industry standard. Nvidia established the Halos AI Systems Inspection Lab and earned the world's first ISO/IEC 17020 inspection accreditation in physical AI; certification bodies including TÜV Rheinland, TÜV SÜD, UL Solutions, SGS, exida, and CertX recognize its inspection results.
Robot companies can run pre-inspection with Nvidia before formal certification, sharply cutting time and cost — previously sensors, controllers, and vision systems were each certified separately, and companies had to piece it together themselves.
Hands-On Take
Strengths
- Plug and play: no need to build a safety stack from scratch, especially fitting for early embodied-AI startups under 60 people
- Open-source core: the Outside-In Safety system can be forked straight into your own project for customization
- Ecosystem moat: 43 partners means sensors, controllers, and certification bodies all speak the same interface, avoiding later "swap a layer, redo validation" cycles
- Proven in the field: Agility has integrated Halos into its Digit robot, certified and working in Amazon, GXO, and Toyota facilities

Nvidia's robotics full stack: beyond training, simulation, models, and deployment inference, Halos completes the "safety and certification" piece.
Use Cases
Clear target users and scenarios:
- Embodied-AI robot companies: especially teams building humanoid, logistics, and inspection robots — treat Halos as a "pre-shipment safety compliance kit"
- Industrial automation integrators: use Halos to streamline the ISO/IEC 17020 certification process when deploying autonomous robots for customers
- Robot safety researchers: build on the open-source Outside-In modules and contribute improvements
- VLA / VLM teams: use the "algorithm safety" layer as an evaluation target to verify model behavioral reliability in the physical world
Worth flagging: Halos currently targets industrial settings (factories, warehouses, logistics) rather than consumer ones. For individual developers hoping to bolt it onto a home robot, there's little payoff — its value lies in the compliance chain, not any single feature.
💡 Tip: Halos comes with strong full-stack lock-in. Once you've walked the whole chain from training (Cosmos) and simulation (Isaac Sim) to deployment (Thor) and safety (Halos), swapping any layer means redoing validation. Evaluate it as a "long-term technology stack decision," not a "single-point tool."