On September 15, Agility Robotics introduced a 284-pound machine with a safety maneuver unusual for a product launch. If a person enters an unsafe distance, Digit 5 is designed to avoid the person, stop, or lower itself into a seated position.

Agility wants that response to remove a commercial barrier. Earlier versions of Digit have largely worked inside fenced cells. Digit 5 is intended to move through factories and warehouses close to the people who run them, without the fixed barriers used around much industrial automation.

Agility attached a large sales number to that promise. It said it had more than $300 million in multi-year orders for Digit 5 as of May 2026. The same September 15 release listed a 50-pound payload, a 90-minute battery runtime, a nine-minute charge, and more than 20 productive hours in a 24-hour day.

Those are specifications and forecasts for a product that has not entered general availability. Early access is expected in the first half of 2027. General availability is expected by the end of that year.

A footnote changes the order figure. An investor presentation filed with the Securities and Exchange Commission puts one purchaser behind the headline. The agreement covers 1,000 Digit 5 robots under a three-year Robots-as-a-Service contract. Revenue depends on contractual milestones. The purchaser also received warrants that vest in proportion to deployed robots.

It is a commercial commitment, not recognized sales.

Eleven days before the launch, Agility’s proposed public-market transaction produced a harder baseline. Its September 4 Form S-4 reported $1.782 million in 2025 net sales and an operating loss of about $140.2 million. The filing warns that existing orders may not convert to revenue on schedule if Digit 5 misses its planned timing, features, or specifications.

Agility therefore has two conversions to prove. One runs from a safety architecture to accepted work near people. The other runs from a concentrated, conditional order to deployed units and revenue.

Both conversions run through the same warehouse aisle.

September 15 moved the safety cage into the product roadmap

Digit 5 changes the physical terms of the product. The machine is 5 feet 11 inches tall, weighs 284 pounds, and can reach 7.2 feet. Its new leg design is intended to lift 50 pounds repeatedly, up from Digit 4’s 35-pound payload. A faster charge is meant to raise the run-to-charge ratio from 2:1 to 10:1.

Those numbers broaden the tasks Agility can propose. A robot that can reach human shelving and handle the upper limit of many single-person lifting policies can move more than empty totes. Agility lists depalletizing, machine tending, kitting, sequencing, quality inspection, and palletizing as future workflow stages.

These additional workflows remain roadmap items. Digit 4’s disclosed commercial record is narrower.

At GXO’s Flowery Branch facility near Atlanta, Digit 4 moved totes between mobile robots, conveyors, and floor positions. Agility says the deployment passed 100,000 cumulative tote moves with approximately 98% accuracy while on task. Other named Digit sites include Schaeffler, Amazon, and Toyota Motor Manufacturing Canada. The company reports more than 65,000 operating hours across the installed fleet.

Digit 5 has none of those field denominators yet. It inherits engineering lessons and software from the earlier generation, but it does not inherit completed customer acceptance. A new leg, heavier payload, different battery cycle, swappable grippers, and a new safety controller all widen the validation surface.

Proximity is the central change. Agility says multiple sensors and proprietary algorithms will monitor for people. A separate safety controller will oversee the response when someone gets too close. Visual and audible cues are meant to tell nearby workers what the robot intends to do.

Moving beyond a workcell pushes the boundary outward. A fence keeps most untrained people away from the hazard. An open workflow asks the robot, the site layout, and each worker to coordinate continuously. Its safety function has to work when a person crosses the route, a pallet blocks a sensor, a reflective vest changes the visual field, or a dropped object changes the floor.

Battery math creates another operating boundary. Ninety minutes of runtime and nine minutes of charging can add up to more than 20 working hours only if docking and task handoffs fit the schedule. Fault recovery, preventive maintenance, and software updates need space too. Productive time is a subset of powered-on time. A robot sitting safely after an unexpected stop protects people while material waits.

Agility Arc, the company’s fleet-management platform, is supposed to expose uptime, throughput, and mean time between incidents. It also connects with warehouse and manufacturing systems. That interface matters because a robot can be mechanically available while the upstream conveyor is stopped, the work queue is wrong, or a warehouse system has not released the next move.

According to the release, essential health and diagnostic data will travel to Arc, while camera and depth-sensor data will be processed locally. Encryption and customer separation address part of the data problem. Site buyers still need a record of what the robot observes and what leaves the facility. They also need access rules, retention periods, and a process for workers to challenge conclusions drawn from sensor data.

Removing the cage does not remove infrastructure. It replaces steel fencing with sensing, control logic, training, integration, maintenance, network security, and a documented safe response.

A $300 million order book depends on one thousand robots

The launch release describes more than $300 million in multi-year customer orders. The SEC presentation supplies the concentration that the headline leaves out. The amount relates to a single unnamed purchaser and a 1,000-robot, three-year RaaS contract.

Beside Agility’s recognized revenue, the contract is enormous. The $300 million headline is about 168 times its 2025 net sales. Different accounting periods prevent a direct revenue comparison, but the ratio locates the growth case: almost all of its stated value still depends on future conversion.

Dividing $300 million by 1,000 robots and three years would produce a rough $100,000 per robot-year. It would not produce a valid rate card. The agreement has milestones, a deployment schedule that is not public, and warrants that vest as robots are deployed. RaaS can also include hardware, software, maintenance, field service, and fleet management. The allocation among those elements has not been disclosed.

Agility has not identified the buyer, its facilities, or the task mix. Expected start dates, minimum acceptance criteria, cancellation rights, and remedies for missed specifications are also undisclosed. Those terms decide how many robots can enter service during a quarter.

In the S-4, Agility makes that dependency explicit. Existing orders require Digit 5 or a future product to launch with anticipated features and specifications. A delay could push out related revenue. The filing also says a limited number of customers account for a significant portion of potential revenue.

Concentration cuts both ways. One buyer can accelerate learning across many sites if its rollout proceeds. The same buyer can slow the revenue plan if integration, safety review, capital approval, or facility readiness slips.

Before that conversion is complete, Agility is financing a manufacturing ramp. The proposed merger with Churchill Capital Corp XI values the company at $2.5 billion. Associated Press reported in June that the transaction was intended to fund commercial deployments and Digit 5 production.

The company says its 70,000-square-foot RoboFab in Salem, Oregon, is designed for as many as 10,000 robots a year and more than 500 jobs at full capacity.

RoboFab’s nameplate capacity describes a future state. The SEC filing says Agility has no experience with high-volume manufacturing. Reaching that state requires trained production workers and repeatable quality controls, plus reliable supplies of actuators, sensors, batteries, and computing hardware. Yield problems or component shortages could delay delivery and raise unit cost.

Field service will absorb money too. A RaaS provider keeps exposure to maintenance, integration, excessive wear, and support. The filing warns that customer environments can create higher costs through product damage, safety incidents, and implementation changes. A robot that needs repeated engineer visits can satisfy a deployment count while weakening unit economics.

Recognized sales supply a useful starting point because the $1.782 million was earned under the earlier commercial model. The roughly $140.2 million operating loss captures research, manufacturing preparation, and organization before scale. These historical figures cannot predict Digit 5 demand, but they keep the order book separate from a finished business.

An order-to-revenue bridge would begin with accepted robots, not announced value. It would then track the date each unit enters billable service, the contract element recognized, service credits, downtime, field-support cost, warranty expense, and renewal. A purchaser warrant belongs in that bridge because it changes the economics of deployment even when it does not change the robot’s task.

The footnotes turn customer commitment into a list of work still due.

Digit 4 supplied the field record

Compared with many humanoid startups, Agility brings a substantial operating record. That advantage makes generation labels more important.

GXO began a proof of concept with Digit in 2023 at a facility serving Spanx. The customer’s announcement described a specific loop: Digit would take totes from autonomous mobile robots and place them on conveyors. GXO said the repetitive movement created strain and that automation could free employees for higher-value work.

In June 2024, the companies moved to a multi-year commercial agreement. By November 2025, Agility said Digit had moved more than 100,000 totes at Flowery Branch. Its milestone account says the robots also learned to stack totes at a different floor position.

One hundred thousand is a real cumulative output count. It is not a complete productivity record.

Missing from the public account are the number of robots behind the count and its exact measurement period. Scheduled hours, completed shifts, attempts, interventions, stopped minutes, and loaded operating cost are also absent. Approximately 98% on-task accuracy lacks a public denominator or an explanation of the other 2%. A corrected grasp, a human intervention, and a dropped tote carry different costs.

Agility, rather than an audited customer dataset, supplies the figure. GXO has described the deployment and its purpose without releasing a site-level before-and-after record. Injury, throughput, headcount, overtime, turnover, job transfer, promotion, and worker-experience measures remain unavailable.

The milestone still matters. It shows repeated work in a live facility. Its scope ends before the economics of open, multi-task Digit 5 workflows across one thousand robots.

Safety evidence needs the same generation and site labels. Agility says an earlier Digit passed a field evaluation at an ecommerce fulfillment site. Its detailed safety account describes an inspection by an OSHA-recognized Nationally Recognized Testing Laboratory. The audit examined mechanical, electrical, and interaction hazards at that customer site.

Agility also says the evaluation allowed the robot to expand from an automated putwall task into tote recycling. That is useful deployment evidence. The company itself notes that NRTL field evaluations are site-specific.

The assessment covered one site and an earlier robot generation. OSHA did not certify every Digit, and Digit 5 was not the machine under test. Future grippers, payloads, software policies, aisle layouts, and customer workflows require their own review.

Keeping generation labels visible separates three evidence layers in Agility’s release: an evaluated Digit 4 installation, aggregate Digit 4 hours, and a Digit 5 design. A previous generation can establish the manufacturer’s operating discipline. Safety for a new model and application remains a separate finding.

Historical pricing requires the same label. In 2024, Time reported that GXO paid Agility $30 an hour for each Digit. That figure described an earlier agreement and robot generation. Agility has not disclosed a comparable Digit 5 price. A current comparison would include integration, charging, maintenance, spare units, human oversight, service credits, and the cost of the alternative process.

A broader task map in a harder environment raises the proof burden.

A walking robot cannot simply power down

Industrial safety has mature methods for equipment that stops by removing energy. A biped introduces a different failure.

If a fixed arm loses power, a safety design can often brake it or bring it to a defined state. If a walking robot loses the active control that keeps it upright, it can fall. Digit 5 weighs 284 pounds before it picks up a 50-pound load.

An August 2026 functional-safety preprint calls this the fail-passive gap. Caiwu Ding, Tao Cui, Lingyun Wang, and Chengtao Wen built a test cell around a Unitree G1 EDU robot. Their external chain used a light curtain, emergency stop, fail-safe controller, and industrial communication. That chain could issue a stop command. The unresolved point was the robot-side transition into an actively balanced standstill.

Ding and his co-authors explicitly declined to claim end-to-end certification. Their test used a different robot in a semi-enclosed cell, so it cannot validate Digit 5. It does explain why a humanoid’s safe state depends on software, sensors, actuators, and power continuing to work together after a stop demand.

ISO’s standards record reflects that problem. ISO/CD 25785-1, the proposed standard for dynamically stable industrial mobile robots, remains a committee draft. ISO defines the category around machines that need active control to remain balanced and could become unstable without power. The draft covers the robot. A separate Part 2 for application integration is still to be developed.

Vendors are taking orders before the first dedicated international standard reaches publication. Existing standards still apply as a stack rather than a single humanoid approval.

The U.S. Occupational Safety and Health Administration says there are currently no OSHA standards specific to the robotics industry. Its guidance points employers toward machinery, electrical, industrial robot, and mobile robot requirements. OSHA can still enforce workplace duties, including the General Duty Clause. The absence of a robot-specific rule is not an exemption.

A September 11 guide published through the Association for Advancing Automation reaches a similar operational conclusion. No single standard covers every general-purpose robot. The applicable framework changes with the task, environment, mobility, human access, manipulation, and AI behavior.

SRES also separates a conventional fault from unsafe behavior without a fault. A perception model can miss a person while every component remains powered. A decision model can choose a bad path in unfamiliar lighting. A safe controller can receive the wrong description of the environment.

Agility’s response is a layered architecture. It names human detection, visual and audible cues, an independent safety controller, NVIDIA IGX Thor, and the Halos safety framework. The company is participating in the U.S. ANSI/A3 TR R15.108 work and ISO 25785-1.

Participation supplies practical experience to standards bodies. It does not let a vendor certify itself against a committee draft. The final customer still needs an application risk assessment, site acceptance, documented stop behavior, worker training, maintenance controls, and change management when software or hardware changes.

Europe adds another deadline. Agility expects Digit 5 to carry a CE mark and plans commercial availability in the European Union and United Kingdom in 2027. Expected marks are roadmap items until the relevant conformity work is complete. A CE mark also does not replace the employer’s responsibility for the deployed application.

Version history may become the most important safety record. A new manipulation policy can change stopping distance or body posture. A different gripper changes pinch and dropped-load hazards. Moving from totes to machine tending creates a new system around the robot. Each change should point to the risk assessment that remains valid.

General-purpose capability makes change control part of the product.

Warehouse teams inherit the integration

The labor case starts with shortages and repetitive work. Peggy Johnson, Agility’s chief executive, has argued that older workers are retiring while younger people are avoiding some warehouse and factory jobs. Jonathan Hurst, the co-founder and chief robot officer, has emphasized a machine that fits spaces built for people.

Some facilities may match that labor description. The public case still lacks a workforce result.

A warehouse can have vacancies and still use automation to reduce paid hours. It can move current employees to different tasks or remove positions through attrition. It can add robotics technicians while narrowing entry routes for material handlers. The same rollout can reduce lifting strain and increase monitoring pressure.

GXO’s original pilot language promised less repetitive work and more valuable assignments. Adrian Stoch, then the company’s chief automation officer, connected the test to safety, efficiency, productivity, and engagement. Senior operations director Christy Hillier said the technology could work with associates to improve the workplace.

Intent is documented; outcomes are not. A worker-level record would show where people went after the tote loop changed. Did they move to exception handling, quality, inventory, maintenance, packing, or another facility? Did pay and schedule stability improve? How much training happened on paid time? Did the new role carry a promotion path or only more responsibility?

Open-floor operation adds duties that a fenced deployment can hide. Workers need to understand the robot’s cues, safe distance, route, payload, and reset process. A shift lead needs authority to keep a unit offline after a near miss. Maintenance staff need lockout procedures and a clear line between routine service and vendor-only repair. Safety representatives need access to incident and stop logs.

Integration expands the team around the machine. Warehouse-control engineers must connect Digit to conveyors, mobile robots, and work queues. Network and security staff review data paths. Functional-safety engineers validate the whole application. Trainers prepare nearby workers, including temporary employees and people who do not work in English. Procurement staff reconcile the subscription with downtime and service credits.

Agility retains work on its side of the boundary. The SEC filing says it needs more manufacturing personnel, service capacity, field integration, quality control, and support. A thousand-robot customer will need a response model for failed actuators, batteries, sensors, software, and communications. If a field engineer must travel for each recurring fault, fleet growth can increase labor faster than revenue.

Buyers also need an alternative. A humanoid form can avoid rebuilding a human-designed aisle, but a fixed arm, conveyor change, lift-assist device, or wheeled robot may complete a stable task with fewer degrees of freedom. A fair comparison prices the full workflow against the safest and least expensive credible redesign, rather than comparing the robot with one hourly wage.

The strongest case for Digit is broader than one tote loop. An operations manager could accept lower speed on an individual task if the same fleet can move from tote handling to kitting or machine tending with less new infrastructure. Shared charging, fleet software, spares, and training could make the second and third workflows cheaper to add than the first.

That option value is testable. Record the engineering hours, site modifications, validation time, and productive use retained when a robot changes tasks.

Versatility can also become a source of downtime. Each additional task brings a different load, route, tool, interaction, and acceptance rule. A general-purpose platform earns its advantage only when reuse across accepted workflows outweighs the added change-control and support burden.

Worker observation belongs in that comparison. Digit uses cameras, depth sensors, and operational logs to navigate and report health. Agility says sensory data is processed locally and transmitted diagnostics are limited and encrypted. The customer should still tell employees what is collected, whether footage or derived records can evaluate their behavior, and which decisions can be made from those records.

Research summarized by the European Agency for Safety and Health at Work identifies benefits and risks from collaborative robots. The reported risks include higher work intensity, reduced autonomy, surveillance, and more isolated work in some settings. That evidence is not about Digit. It identifies outcomes a buyer should measure rather than assume away.

Headcount is a lagging and incomplete measure. A site can retain the same number of employees while making the shift harder through interruption and exception work. It can reduce injuries without changing headcount. It can add technical jobs that are inaccessible to the workers whose previous tasks disappeared.

“Higher-value work” should name a job and a paycheck. The site can test the phrase by recording the old task, the new task, the employee transition, paid training, wage band, schedule, injury exposure, and advancement route.

A worker representative would need those terms before expansion, not after the old process disappears. The agreement should cover paid training, access to near-miss records, protection for using stop authority, and a route to challenge monitoring or reassignment decisions.

It should also name what happens when a redesigned job carries more interruptions, vigilance, or responsibility without a higher wage. That turns consultation into an operating control rather than a launch-day survey.

Build a humanoid deployment evidence file

A buyer does not need to settle the future of humanoid labor before starting a pilot. It needs to define what must be true before a robot leaves the pilot.

Use one evidence row for each site, task, robot generation, hardware configuration, and software release. Aggregate fleet hours can sit above those rows without erasing application differences.

Decision recordDenominator to preserveEvidence before expansionWorker and operating ownerStop or revise signal
Unit acceptanceRobots delivered, installed, accepted, and billableSerial number, hardware version, site test, acceptance date, open defectsBuyer automation lead and Agility deployment leadDelivered unit fails acceptance or remains non-billable
Productive timeScheduled, powered-on, available, blocked, charging, maintained, and productive minutesShift log joined to work queue and upstream equipment stateOperations manager and fleet ownerProductive share misses the agreed threshold after ramp
Task qualityAttempts, accepted completions, corrections, dropped loads, and damaged goodsTask definition, result label, review rule, and sampled video or sensor recordProcess owner and quality leadError type creates safety, service, or rework cost above baseline
Safe responseDetection events, avoidance, controlled stops, seated responses, and reset timeTimestamped safety-controller log tied to robot and software versionFunctional-safety engineer and site safety leadStop distance, posture, or restart departs from the validated case
Human interventionRemote assists, local assists, recoveries, and engineer visitsReason code, minutes, person involved, and action takenShift lead and vendor supportIntervention labor erases expected throughput or cost benefit
Worker outcomeExposure, injury, near miss, reassignment, training, pay, schedule, and advancementPre-rollout baseline, worker feedback, incident file, and role transition recordEmployer safety, HR, worker representative, and line managerRisk moves to another task or job quality falls without remedy
Loaded economicsRaaS fee, deployment, integration, network, training, spares, downtime, and service creditInvoice, internal labor, capital change, and alternative-system estimateFinance owner and procurementCost per accepted task exceeds the best credible alternative
Change controlHardware, gripper, model, policy, map, sensor, and system-interface versionRelease note, changed hazard analysis, regression test, and approvalAgility product safety and customer change boardMaterial change enters production without renewed validation
Order conversionContracted, scheduled, deployed, accepted, billable, and recognized unitsContract milestone, acceptance certificate, invoice, and revenue policyAgility finance and customer procurementOrder headline grows while accepted and billable units stall

This vocabulary encodes different states. Operating time contains more than productive time; attempts still need an acceptance rule; safe stops and incident-free shifts measure different events. Delivery precedes billing, contract value precedes revenue, and reassignment says nothing about promotion.

Shared fields connect people who otherwise see different projects. The safety engineer sees stopping behavior. The operations manager sees throughput. Finance sees invoices and downtime. Workers see task and schedule changes. Agility sees fleet performance and service burden.

Procurement can set release gates around the record. A pilot might require a minimum sample of representative shifts, not a staged demonstration. Expansion could require task-quality parity with the existing process, a defined ceiling for interventions, a closed list of safety issues, worker training completion, and an agreed response time for critical faults.

Contract and insurance review should use the same evidence. A buyer needs to know who investigates a near miss, who preserves the controller and fleet logs, how quickly Agility must disclose a safety-relevant defect, and which party approves a changed configuration.

Warranty language, service credits, indemnities, and coverage exclusions will not prove that a deployment is safe. They will expose whether the vendor and customer have assigned the consequences of a failure they both helped configure.

Test adverse conditions too. A facility changes across day and night shifts. Lighting changes, temporary workers arrive, pallets protrude, Wi-Fi coverage drops, and floors become wet or damaged. The product’s valid operating domain should state which conditions it can handle and what it does outside them.

Worker stop authority needs its own test. A person who sees an unsafe pattern should know how to halt the robot without a penalty for slowing production. The site should record who can authorize restart. If the answer changes during peak season, the safety case has changed even when the robot software has not.

Cyber and data events belong beside physical incidents. An unavailable fleet-management service can block dispatch or hide health information. A compromised credential can change configuration. A sensor-data policy can change after a software update. Recovery plans should define local safe behavior when Arc, a warehouse system, or a network connection disappears.

Keep the counterfactual. If a lift-assist device and a conveyor adjustment could remove the same repetitive motion, compare them. If a wheeled mobile robot can move the load but needs new fixtures, price the fixtures. A humanoid earns the premium when versatility or lower site modification produces a better result across enough accepted tasks.

A recorded alternative protects the buyer from paying for form alone. It also protects Agility from a pilot chosen for a task that a simpler system will always perform better.

Public records cannot yet fill this file. They provide a product specification, fleet hours, one tote milestone, a site-specific field evaluation, transaction risk disclosures, and a concentrated order. Those are strong starting entries. Most site, worker, incident, intervention, and loaded-cost fields remain blank.

One open aisle will test more than a launch video

Early Digit 5 access is expected in the first half of 2027. That date starts a more useful clock than the September launch.

A useful first record will identify a production site, a robot version, a task, a validated operating domain, nearby workers, and an acceptance rule. It will show how often the robot worked, stopped, sat down, needed help, and returned to service.

Commercial conversion runs in parallel. One thousand contracted robots must become scheduled units, accepted installations, billable service, and recognized revenue. The warrants tied to deployment should remain visible in that sequence.

Digit 4 gives Agility a field history that many competitors lack. Digit 5 asks that history to support a heavier machine, broader tasks, faster charging, and closer human contact. The dedicated ISO standard for dynamically stable industrial robots is still in committee while the commercial timetable is already running.

The mismatch shifts more of the proof onto each site; it is not a finding that the robot is unsafe.

The revealing moment will be ordinary. A worker steps into the route. The robot detects the person and chooses a safe response. The shift continues, or it stops. Somewhere in the system, the event should leave a record detailed enough for a worker and safety engineer to agree on what happened. The customer, Agility, and an auditor should be able to reach the same conclusion later.

Until that record survives ordinary work at scale, $300 million remains an order claim tied to a 2027 safety test.