Imagine that stealing a frontier lab’s model weights were trivial. Not a years-long intelligence operation against a guarded data center, but a few scrappy computer science PhD students hacking away on weekends. The morning after OpenAI or Anthropic drops a new model, a rival Chinese lab has an exact copy and runs inference on its own compute, so the leader’s product advantage evaporates in a flash.1 The lab then puts the stolen model to work automating AI R&D, so the leader’s research advantage starts evaporating too.
In that world, there is no business case for spending billions on AI R&D and training runs, because there is no moat to profit from. And without a business case, there are no investors. And without investors, the compute buildout stops, killing any chance of continued exponential compute scaling.
Thankfully, we don’t live in that world, because stealing frontier LLM weights isn’t that easy. It requires hacking and infiltrating the data centers that serve OpenAI’s and Anthropic’s models, and doing so would be geopolitically costly. For frontier robotics, though, the story is much closer to what I described above.
Arguably, the most important part of a frontier robot2 is its policy weights. These AI model weights are the substrate of intelligence. The robot’s decisions, actions, balance, and reflexes flow from them. And often the thing that makes frontier robots so valuable (their policy weights) ships inside the product, and the product ships to whoever buys one. It’s almost like running a business-to-business SaaS company and handing every client your entire codebase. Well, if most of the value of your glorious business-to-business SaaS company comes from your codebase, then you have no moat, and Mr. Andreessen won’t fund you again!
Here’s what happened when three PhD students used a $600 voltage-glitching rig on a Tesla:
We were able to spawn a Root Shell on Autopilot, enabling us to dump the Autopilot Firmware, ML Weights, and all Sensor Data. Custom Modifications to the Autopilot can be made if it is glitched on every boot, requiring a more sophisticated setup. We also extracted various snapshots from our units, including those already marked as deleted. (Kühnapfel et al., 2025; emphasis mine)
Tesla is one of the more security-conscious hardware companies on earth, yet its model weights were leaked relatively easily. If China could do this to every robot the US deploys, American robotics companies would have no chance of maintaining IP moats. The robotics race would then be decided by something other than who has the best model.
In this post, I make the following argument:
Most of a robot’s “intelligence” may reside in model weights stored on edge devices.
Weights on mass-produced edge devices likely cannot be protected against a nation-state attacker.
From (1) and (2), rival states will be able to exfiltrate deployed robot model weights at low cost and low risk.
Stolen robot model weights are useful to the thief, even on different hardware, so weight theft lets a laggard fast-follow the leader.
From (4), the follower’s lag in deployed model quality is upper-bounded by theft-plus-integration time (the time to steal the weights and adapt them to your own hardware), not by frontier R&D time (the time to research and train a new robotics foundation model from scratch).
From (5), the relative advantage between the US and China in embodied AI will primarily depend on robotics component manufacturing capacity, edge compute supply, edge compute performance, energy, and willingness to deploy. The capabilities of the robotics foundation model might not be the deciding factor.
I don’t think this is a slam-dunk argument; it’s only my modal prediction, and I give this scenario less than a 25% chance. I’m uncertain about each premise, so the future may well look quite different.
Still, I am very confident that hardware security will be incredibly important for the robotics revolution, and more people should think carefully about its implications in a more automated world.
Thanks to Amelia Michael, Erich Grunewald, Emerson Alden, and Alex Wszolek for helpful discussions and feedback. All mistakes are my own. This is a rough research note, and I’m less confident in its conclusions than usual.
Most of a robot’s “intelligence” will reside in model weights stored on edge devices
There are two broad ways to design a frontier robot. In a fully onboard design, the robot’s entire brain runs on edge compute in the robot itself. In a hybrid design, a small model runs onboard for real-time control, while a larger model runs in a cloud data center for high-level reasoning and planning. The cloud model can be much bigger, since it runs on beefy data center chips rather than less performant edge compute. But the cloud model can have higher latency because it’s bottlenecked by inference time (forward passes on the data center chips) plus the round trip from robot to data center and back, though this isn’t always the case.
So far, most robots shipped to customers run fully onboard.
Will the industry converge on fully onboard or hybrid architectures? I think fully onboard architectures will win out, primarily because customers will keep demanding robots that work without an internet connection. For example, military robots and drones in enemy territory must operate without internet access because these regions are actively jammed. And more prosaically, many everyday places have patchy internet access, such as elevators, subways, dead zones in houses, and rural areas. Sunday’s cofounder has said that ordinary home Wi-Fi, even augmented with Starlink, wasn’t reliable enough for a robot that needed the cloud to function, which is why the company’s model now runs entirely onboard.
So even if you get extra juice from a cloud connection, there’s enormous value in a robot that is fully functional with nothing but onboard compute. That doesn’t preclude consulting a bigger model when a connection exists, but it does mean the weights that make the robot useful are sitting on the robot.
That said, hybrid architectures benefit from economies of scale. A shared data center GPU serving many robots uses hardware far more efficiently than a chip per robot. And benchmarking papers find that server-side inference, even on consumer GPUs, beats on-device inference on NVIDIA Jetson-class hardware, with remote servers sometimes winning on average latency at the cost of much higher variance. I still think fully onboard wins, or at least that the robotics-specific value stays onboard, so my all-things-considered take is that fully onboard architectures are more likely to remain state of the art.
Weights on mass-produced edge devices can’t be protected against a nation-state attacker
Reading the section header, you might think, “Why on earth would a nation-state be stealing robot model weights?” Well, I expect AI and robotics to be humanity’s greatest (and final) invention, and frontier robotics to be so central to economic growth and geopolitical power that China and others will be highly motivated to steal robotics IP, weights included. But you don’t even need to buy my nation-state framing, since three grad students with a $600 rig have already stolen Tesla’s weights.
Most robots will be deployed across the economy and around the world. Even if the US tries to use export controls to keep robots from going to China, China could trivially smuggle them. For example, Chinese actors could use shell companies in Europe to legally buy the robots and then smuggle them to China. Or they might not even need to smuggle the robot; they could just reverse-engineer it at the shell company’s premises. Either way, China can easily gain physical, unmonitored access to any widely deployed robot.
With unmonitored physical access, China can perform fully invasive attacks (decapping chips, probing buses, imaging memory, glitching power rails, freezing DRAM, etc.). And currently, there is no robust defense against a well-resourced attacker with unlimited physical access and time. Ross Anderson’s chapter on tamper resistance walks through decades of defeated protections, and a recent review catalogs the current state of model extraction from edge hardware.3
Might defense get easier in the future, especially once we have cognitive-only AGIs (AIs that can do any cognitive work, but not physical work)? Specifically, by the time we’re in the industrial explosion, will we have solved hardware security? In other words, will hardware security be defense-dominant by the time robotics becomes ubiquitous across the physical economy?
By solving hardware security, I mean that the hardware security community can cheaply protect hardware against fully invasive physical attacks. “Protected” is an overloaded term, so to be more concrete: a piece of hardware is “protected” if the blue team (the defenders) can guarantee that if the red team tries to extract the hardware’s data, the data gets automatically wiped. For example, when it detects tampering, the robot wipes its memory and, with it, the model weights.
I am uncertain whether we will get there. While it’s plausible that researchers will figure out how to reliably stop attackers from extracting model weights from edge devices, I think it is more likely than not that an attacker with full physical access will still be able to semi-trivially exfiltrate model weights. I expect this because testing hardware security takes too long in serial time. The feedback loops in cybersecurity are much faster because you can red-team code with fuzzers or a superintelligent AI coding agent. But you don’t get this tight feedback loop in hardware, so I expect hardware security to lag behind.
This is speculative, though. Once the market realizes hardware security is the main bottleneck to building robotics companies with massive moats, the invisible hand may reallocate the smartest minds towards solving it.
On balance, I think China and other rival states will probably be able to exfiltrate deployed robot model weights at low cost and low risk.
Laggards will be able to catch up quickly in robotics
I claim that stealing model weights sharply advances the thief’s robotics capabilities. For this to be true, stolen weights must be valuable even when trained for a different robot with different components. So can you adapt them to a robot with a different embodiment?
Prima facie, the answer is an easy yes, because nearly every academic robotics lab already does this with open checkpoints. They take OpenVLA, π0, or GR00T and fine-tune them to their own embodiment. But stolen weights differ from open checkpoints in two ways: they’re (a) often quantized, and (b) post-trained to a specific body.
Let’s start with quantization. Robot policies are trained at 16- or 32-bit precision and then, for deployment on a 40-130 W edge compute module, often compressed to 8 bits or 4 bits. This doesn’t matter much, since the quantized weights are what actually run, so they’re by construction good enough to control a robot. Moreover, the QLoRA paper showed you can fine-tune around a frozen 4-bit base with low-rank adapters and recover nearly all 16-bit fine-tuning performance, a technique applied directly to OpenVLA at 4 bits. So quantization shouldn’t be a problem.
The second difference is that stolen weights are post-trained to the exact embodiment and hardware. Deployed weights are often tuned to the robot’s joint limits and torque curves, the backlash in its gear reducers, the placement and intrinsics of its cameras, the geometry of its sensors, and so on. For example, Figure AI co-designs its models with its robot’s body, and Sunday collects data with a custom glove matched to the hand of its robot, Memo. Given all this, is retrofitting stolen model weights really that easy?
My guess is that it will be pretty easy because of generalization. Once robotics foundation models get good enough to automate a sizable share of the physical economy, the models will have generalized in some sense. That means they will have learned general representations of the world that aren’t hyper-tuned to a single embodiment. For example, the models might understand basic physics and cause and effect. Robotics companies may also train their robots to be both adversarially robust and adaptable.
Training models to be robust will be essential for commercial use, since models will often face out-of-distribution situations, and some groups will probably always try to make robots malfunction (e.g., nation-state actors). Robotics companies will also be heavily incentivized to train their robots to be adaptable. By adaptable, I mean that a robot can keep functioning despite physical damage, such as a broken sensor or an injured joint. To avoid returns and repairs, companies will work hard to make their robots resilient.
All of these factors suggest that retrofitting stolen model weights will be doable. I admit these are first-principles arguments, so I wouldn’t be surprised if I’m wrong for some subtle (or not so subtle!) reason. That said, I think stolen model weights will be easy to retrofit.
Thus, the follower’s lag in deployed model quality is upper-bounded by theft-plus-integration time (the time to steal the model weights and adapt them to China’s hardware and architecture), not by frontier R&D time (the time to research and train a new robotics foundation model from scratch).
How long might that lag be? Here is a super rough back-of-the-envelope calculation:
Acquiring a unit takes days if the robot is sold freely and weeks to months if it’s export-controlled; extracting the weights takes days to weeks for a prepared hardware lab; adapting them to your own body may take weeks to two months. So the steady-state lag for a prepared follower is roughly one to four months. Frontier robotics companies currently ship a major model version every three to six months, so continuous theft leaves the follower about one generation behind. Whether one generation is a decisive advantage depends on how steep the capability curve is at that point, but either way, the lag doesn’t compound. The leader can’t pull away.
Having the most capable robotics foundation model isn’t enough to win the robotics race
If laggards can catch up quickly at the model layer, then most of the economic (and military) value of robotics will come from robots deployed at scale, not from the single smartest robot. So the robotics race will probably come down to the following factors:
Robotics component manufacturing capacity (actuators, reducers, motors, magnets, batteries, sensors, and the factories that assemble them into robots)
Edge compute performance
Edge compute supply
Energy
Willingness to deploy (regulation, labor politics, and whether firms will actually put robots on the floor)
Here’s how I think the US and China stack up on each factor.
On robotics component manufacturing capacity, China leads but is not dominant. China shipped about 90% of the world’s humanoids in 2025 and controls 91% of rare-earth refining and 94% of permanent magnet production, which nearly every robot actuator depends on. The US and its allies hold the other chokepoints, including harmonic reducers, planetary roller screws, and six-axis force sensors, all of which are dominated by Japanese and European suppliers. These suppliers also hold about 85% of the industrial robot market. But Chinese firms are cheaper and already sampling these parts with humanoid robot makers, so I expect the allied chokepoints to erode within a few years, but not the magnet chokepoint.
On edge compute, there’s a big performance gap between NVIDIA Jetson modules and China’s alternatives, such as Horizon Robotics’ Journey 6P chip. But since Jetson-class chips are not currently export-controlled, Chinese companies can buy as many as they please. As the robotics race intensifies, the US may export-control frontier edge compute, which would hobble China’s ability to keep up.4
On energy, China is famously ahead. For every gigawatt of generating capacity the US added in 2025, China added about ten. China put up roughly 543 GW last year, compared with 53 GW in the US.
On willingness to deploy, China is probably in the lead. I expect the Chinese government will have an easier time deregulating the robotics industry and allowing widespread deployment. On the other hand, I suspect the US will have a difficult regulatory environment, which may make it much harder for robotics companies to deploy at scale. China has also made embodied AI a named priority in its 15th Five-Year Plan, and the government directs state-owned enterprises to deploy domestic robots. The US has no equivalent policy. Of course, this could all change if, for example, the US government realizes the strategic importance of the robotics economy.
Putting it all together, I would guess China is structurally favored in the robotics race. Most of all, I’m worried the US will have no way to scale up its rare-earth mining and refining in time for robotics crunch time.
Conclusion
To recap the argument: Most of the intelligence of future robots will live in weights stored on the device. Securing weights on hardware your adversary physically owns is somewhere between very hard and impossible, so adversaries can steal them semi-trivially. Stolen weights are useful, so laggards catch up quickly. Therefore, robotics companies will struggle to build moats around their models, and no country will “win” the robotics race simply by having the smartest robots. The winner will probably be whoever manufactures the most robots and deploys them at scale.
I don’t think this is definitely how the future goes, but it’s my modal prediction, with wide error bars. My argument has three main weaknesses. First, in response to competitors stealing model weights, robotics companies may move more of the “intelligence” into the cloud. Second, Tesla’s Full Self-Driving (FSD) weights have been easy to steal, so if weight theft were the dominant catch-up mechanism, Chinese driver-assistance progress should have looked like theft-driven fast-following. Instead, Huawei, XPeng, and Momenta built their own stacks. Third, theft-plus-integration might take long enough that it isn’t worth it. (For a more detailed discussion, see this footnote.5) To me, none of these weaknesses are fatal, though they make me less confident in my argument.
Zooming out, the main takeaway is that more people should take hardware security for edge devices seriously. I think it will be one of the most important security problems of the late 2020s and early to mid-2030s. And even if you don’t buy my weight-theft threat model, you definitely want hardware security solved so that North Korea can’t hack your household humanoid and strangle you in your sleep.
But Chinese labs have roughly one-twentieth the compute of the leading American labs, so they couldn’t run as much inference on the stolen models.
When I say “robot”, I mean a frontier robot (think a state-of-the-art humanoid or quadruped) rather than a fixed industrial arm.
You might object that hardware security modules (HSMs) already solve this, since they can wipe their secrets when they detect tampering. But HSMs protect a few kilobytes of keys inside sealed, attested hardware, whereas a robot has to stream tens of gigabytes of weights out of memory at hundreds of GB/s into a GPU that is actively computing on them. So the tamper-resistant envelope has to enclose the entire compute module and its DRAM while dissipating 100+ W. The best-certified HSMs are rated for narrow operating temperatures (+10 to +35 °C for IBM’s 4765) because their tamper sensors are fragile, and a robot may operate in warehouses, in kitchens, and on battlefields. Another option is confidential computing, but as of this writing, GPU confidential computing is only supported on H100/B200-class parts, not Jetson-class modules. And even if it’s extended to edge compute, there are still loads of hardware attacks that crack confidential computing!
To be clear, I’m not necessarily advocating that the US export-control frontier edge compute. In a future post, I may explore whether robots and their components should be export-controlled.
The first weakness is that the market might move the intelligence off the robot. If competitors start stealing onboard weights, the obvious response for robotics companies is to push more of the policy into the cloud. And there are independent economic reasons to do so (batched inference on a shared data center GPU is much more efficient than inference on a chip per robot). Still, I think keeping robots working in areas with spotty internet will be important enough that deployed robots will always have onboard model weights that can handle day-to-day activities.
The second weakness is that Tesla’s FSD weights can be trivially stolen, but no Chinese company seems to have done this. Tesla’s FSD computer runs a frontier on-device model and has been sold in China by the hundreds of thousands for years, physically accessible to every Chinese lab and to the state, and its weights have been publicly extracted. There are reasons the Tesla case might not carry over to robotics: overt theft from Tesla would have been costly at a time when China wanted Tesla’s investment; Chinese driver-assistance systems were already near parity with Tesla’s, trained on their own data; a policy tuned to Tesla’s camera-only rig is less useful on lidar-heavy Chinese stacks; and covert theft wouldn’t be public anyway. I suspect the main explanation is that overt theft would be too geopolitically costly.
The third weakness is that theft-plus-integration might take long enough that it isn’t worth it. If the process takes more than a few months while the leader ships new versions on a similar cadence, the follower may be better off investing in its own R&D. I think this is unlikely for a prepared attacker, but it’s plausible.


