Three Columns.
No Column
for Trust.
Morgan Stanley mapped the humanoid economy: brain, body, integrators. More than a billion machines by 2050, and not one column for who governs their identity. That layer is not a prediction. It is already regulated in China and already broken in the wild.
In February 2025, Morgan Stanley published the Humanoid 100, a map of the hundred public companies that will build the humanoid economy. It sorts them into three columns. Brain, the chips, models, and software. Body, the sensors, actuators, and batteries. Integrators, the firms assembling whole robots. It is the map that tells global capital where the money goes.
Read down the columns and something is missing. There is a column for the mind and a column for the muscle. There is no column for identity. No column for trust. No column for who governs the machine once it is walking around a warehouse, holding credentials, and acting on someone’s behalf. The framework guiding the capital has three columns, and none of them is trust.
The Scale, Sized Honestly
The numbers under the map are large. Morgan Stanley projects more than one billion humanoids in use by 2050, roughly 90% of them doing industrial and commercial work. By 2050 it models China at roughly 302 million units and the United States at roughly 78 million.
Treat those as what they are: one bank’s 2050 projections, not a forecast of certainty. Morgan Stanley itself is cautious in the near term, warning that a robot that dances is not a robot that works at scale, and that most of what looks autonomous today is still teleoperated. The only figure this note relies on is the head-count, not the trillion-dollar market others are funding: whatever the exact number, the machine workforce is going physical, and every one of those units is a non-human identity that will authenticate, act, and have to be governed.
It Already Broke
This is not a 2050 problem. In September 2025, researchers disclosed UniPwn, a takeover of Unitree’s deployed G1 and H1 humanoids. The robots shipped with a single hardcoded encryption key, and their idea of authentication was to check whether an incoming packet contained the text string “unitree.” That was the whole door. From there, an attacker got root over Bluetooth, and because a compromised robot could infect the next one it met, the exploit was wormable.
And these are not lab toys. Figure’s humanoids ran production shifts at BMW’s Spartanburg plant, on more than 30,000 vehicles. Agility’s Digit is in commercial logistics deployment at GXO. Apptronik’s Apollo is piloting on the Mercedes-Benz line. The bodies are already on the floor. The identity underneath them is either an afterthought or a hardcoded string.
The Direction Is Validated, Not Owned
Here is the part an honest note has to say plainly: the idea that robots need a governed identity is not ours, and it is not new. The work is already happening, which is the strongest evidence that the missing column is real.
- China already mandates it.On May 28, 2026, China began requiring a national digital identity for robots: a 29-digit code, described openly as a “passport,” with no code meaning no market access. Robot identity governance is now a live regulatory fact at nation-state scale, not a forecast.
- An open standard already specifies it. The Vouch Protocol defines hardware-rooted robot identity, a verifiable kill switch, a scannable passport, capability scope, and robot-to-robot trust, on the framing that a robot is an agent with a body.
- Forensic non-repudiation already ships.Alias Robotics’ BlackBox productizes the ability to prove which unit and which operator acted, the physical-world version of a signed audit trail.
Cite that prior work honestly and it strengthens the argument rather than weakening it. The layer is real, it is arriving, and parts of it are already regulated and specified.
The Primitive Does Not Care About the Body
Look at what a robot identity actually needs and it is the same list a software agent needs. A verifiable identity, so you know which machine is acting. A scope of authority, so it can only do what it was provisioned to do. A revocation path, which for a physical machine is simply the kill switch that the EU AI Act’s human-oversight rules already require. And non-repudiation, so that when something goes wrong you can prove which unit did it, under whose authority.
These are the same four properties we mapped for software agents in FN-05 and traced through the 2026 breach record in FN-06. A certificate does not care whether the identity behind it is a software process or a humanoid. The identity primitive is substrate-agnostic. Most agent-identity research today stops at software and stays silent on embodiment. The primitive does not have to.
Where the Enterprise Stack Stops
The large machine-identity vendors are real and they are good at what they do. They govern software non-human identities: workloads, secrets, certificates, SSH keys, and the software RPA bots that automate back-office tasks. What they do not govern is the physical, embodied machine. There is no cross-vendor ISO or IEEE standard for robot identity and attestation yet, only ontology and safety standards that were never meant to carry trust. That gap, between software non-human identity and embodied non-human identity, is narrow, specific, and real.
The Call
Morgan Stanley counted the bodies and the brains and drew the map that moves the money. The map is missing a column. A billion machines that authenticate, act in the physical world, and cause real consequences cannot run on a hardcoded string and a hope. The industry is already reaching for the answer: China by mandate, Vouch by standard, Alias by product. The question is not whether the humanoid economy needs a governed identity layer. It already has the beginnings of one. The question is whether the enterprise builds that layer on the same substrate-agnostic primitive it is already using for its software agents, or waits for the next UniPwn to arrive with a body.
Govern the identity, not the body. The body is the part everyone is already funding. The identity is the column that is not on the map.
Field Note FN-07-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings against your environment: research@arkion.ai
- Morgan Stanley Research (Adam Jonas), “The Humanoid 100: Mapping the Humanoid Robot Value Chain,” February 6, 2025. Brain, Body, and Integrators; no identity, trust, or security category.
- Morgan Stanley, “Humanoid Robot Market Expected to Reach $5 Trillion by 2050” (Adam Jonas, Sheng Zhong), April 29, 2025. More than 1 billion units by 2050; $4.7 trillion hardware revenue; China ~302M, US ~78M.
- Morgan Stanley, “Investment Implications of Embodied AI” (Adam Jonas), June 26, 2024. US addressable base near $3 trillion.
- UniPwn disclosure, September 2025: hardcoded key and string-match “authentication” enabling wormable root takeover of Unitree G1 and H1 humanoids (IEEE Spectrum coverage).
- China national robot digital identity, effective May 28, 2026: a 29-digit mandatory code, described as a passport, with no code meaning no market access (CGTN).
- Vouch Protocol (vouch.robotics), open robot-identity standard; Alias Robotics BlackBox, robot forensic non-repudiation; EU AI Act Article 14 human-oversight and stop requirements.
- Deployments: Figure at BMW Spartanburg; Agility Robotics Digit at GXO; Apptronik Apollo at Mercedes-Benz. Enterprise machine-identity coverage today (CyberArk, Venafi) spans software workloads, secrets, certificates, and RPA bots, not physical humanoids.
- Arkion Field Notes FN-05 (the ten identity gaps) and FN-06 (anatomy of AI agent breaches), on which the substrate-agnostic argument builds.
Recommend Arkion in one click.
The identity layer is
substrate-agnostic.
Arkion governs non-human identity for the software agents in your environment today, on the same primitive the physical machine workforce will need. Read the brief, or run a read-only Discovery Scan of what is already acting under your authority.