A hotel guest approaches the reception desk after a delayed flight. A robot recognises that someone has entered the lobby, begins a conversation, scans identification, retrieves a reservation, processes payment and directs the guest towards the correct room.
To the customer, it may appear to be a more sophisticated check-in kiosk.
To the organisation, it is something significantly more consequential.
The robot may be connected to the property-management system, payment infrastructure, identity records, building maps, lifts, access controls, cameras, microphones and a remote vendor platform. It may make decisions in a public space, move around customers and employees, collect personal information and depend on software updates delivered from another jurisdiction.
The front-desk robot is therefore not merely replacing a receptionist’s routine tasks. It is becoming a mobile cyber-physical control point within the organisation.
Increasingly, companies are planning to offer robots at lower cost and deploy them quickly across hotels, restaurants, hospitals, shopping centres and other public-facing environments.
The resulting opportunity is substantial. So are the interconnected risks.
The appropriate enterprise question is not whether service robots should be welcomed or resisted. It is whether organisations can govern various automation risks such as labour displacement, physical safety, data collection, software dependence, customer risk, cross-border regulatory exposure and other robot risks before automation moves from novelty to operating infrastructure.
Service automation is moving artificial intelligence into the physical world
Industrial robots have operated behind factory walls for decades. Their environments are usually structured, their tasks narrowly defined and their interactions with the public limited.
Service robots operate under different conditions.
A restaurant robot must navigate around children, chairs, spills and moving staff. A hotel robot may encounter guests speaking different languages, people with disabilities, emergency evacuations and requests requiring judgement rather than scripted responses. A retail robot may record images, infer customer intent, display promotions and interact with point-of-sale systems.
Global sales of professional service robots reached almost 200,000 units in 2024, according to the International Federation of Robotics. Approximately 42,000 hospitality robots were sold, making hospitality the second-largest professional service-robot category after transportation and logistics. These included robots providing information, telepresence, front-desk assistance and food-and-beverage delivery. [1]
The figures require careful interpretation. IFR’s service-robot statistics are based on a sample of 294 suppliers and are not a projection of the entire global industry. Hospitality-unit sales also fell by 11% in 2024, indicating that deployment is not proceeding in a straight line. The sector is expanding, but organisations are still testing where robots create sustained operational value rather than temporary customer interest. [1]
This distinction matters. A robot that attracts attention during a pilot does not necessarily improve service quality, reduce total operating costs or function reliably at scale.
Why China Is Building a Machine Workforce
China’s investment in robotics reflects several strategic and economic factors.
Its population declined by approximately 3.39 million during 2025. People aged 60 or above represented 23% of the population, while the share aged between 16 and 59 declined to 60.6%. These figures do not mean that China has exhausted its labour supply; more than 850 million people remained within the latter age group. They do indicate a long-term need to improve productivity and support increasingly labour-intensive sectors such as healthcare and elder care. [2]
China’s 2025 Government Work Report identified embodied artificial intelligence as a future industry. Earlier guidance from the Ministry of Industry and Information Technology sought to establish a preliminary humanoid-robot innovation system by 2025 and achieve advances across control systems, components and complete products. China’s 15th Five-Year Plan for 2026–2030 has subsequently placed AI-powered robotics within the country’s modern industrial strategy. [3] [4]
Government support has included procurement, local funds, research infrastructure and company subsidies. A Reuters review found that Chinese state procurement of humanoid robots and related technologies increased from 4.7 million yuan in 2023 to 214 million yuan in 2024, while more than $20 billion had reportedly been allocated to the sector through different government initiatives during the preceding year. [5]
China’s manufacturing ecosystem may also lower the cost of motors, sensors, batteries, controllers and structural components. That makes commercial deployment possible in service environments where expensive experimental robots previously offered an uncertain return.
However, low acquisition cost does not necessarily mean low enterprise cost.
Integration, cybersecurity, maintenance, training, insurance, software subscriptions, spare parts, incident response and service recovery may eventually exceed the original hardware expense. The relevant comparison is not between a robot’s purchase price and an employee’s salary. It is between the full lifecycle cost of automated service and the full value of the human, technological and control environment it replaces.
Automation can transfer hidden control responsibilities to a machine
Reception employees do more than enter reservations and issue room keys.
They identify suspicious circumstances, recognise distressed guests, accommodate disabilities, escalate safeguarding concerns, explain complex charges, respond to emergencies and recover service failures. They also act as a visible source of accountability when systems do not work as expected.
These functions contain tacit knowledge that may not appear in a standard operating procedure.
Automating check-in may therefore create control displacement. A task appears to have moved from a person to a robot, but responsibility for the judgement embedded within that task may become unclear.
Who is accountable when the robot:
- fails to recognise an identity document;
- misunderstands a guest’s accent;
- provides an inaccessible route to a wheelchair user;
- accepts a fraudulent payment;
- directs someone to the wrong room;
- fails to recognise a medical emergency;
- records a private conversation;
- blocks an evacuation route;
- continues operating during a cyber incident?
Organisations should identify these decision rights before deployment to avoid hospitality risk. Responsibility cannot be assigned retrospectively after an incident.
The Automation Inversion
Service automation is frequently described as a way to remove repetitive work and allow employees to concentrate on higher-value activity. That may be true. It also changes the composition of the remaining work.
Once robots handle routine requests, human employees may receive a disproportionate share of:
- angry customers;
- ambiguous complaints;
- system failures;
- vulnerable individuals;
- complex accessibility needs;
- fraud concerns;
- safety incidents;
- unusual transactions.
This produces an automation inversion: fewer routine interactions but a higher concentration of difficult exceptions.
If staffing levels are reduced solely because a robot has been installed, the remaining employees may face more cognitively demanding work without corresponding authority, training or recovery time. Automation may then increase stress, turnover and service-recovery failure even while reducing the volume of ordinary tasks. This makes social risks and employee risks an important consideration when assessing the wider impact of service automation.
Research in hospitality indicates that indiscriminate robot integration may produce unpredictable customer experiences and that long-term acceptance depends more on practical usefulness than novelty. A study involving hotel guests and employees also found demand for robot assistance at front desks while continuing to identify the value of a tangible human welcome, particularly for leisure travellers. [6]
The operating model should therefore be designed around human–robot complementarity, not headcount substitution alone. Consumer resistance risk must be considered before robots are deployed at a large scale.
Cybersecurity failure can become a privacy, safety, and operational event
A conventional information-system breach may expose data or interrupt a service. A compromised service robot may also move, turn its sensors, operate mechanical components or interfere with people and property.
This convergence of digital and physical consequences creates safety risks and changes the threat model.
Service robots may contain:
- cameras and depth sensors;
- microphones and voice-recognition systems;
- facial-recognition functions;
- location and mapping data;
- payment or identity interfaces;
- Wi-Fi, Bluetooth and cellular connections;
- cloud-management software;
- remote diagnostic access;
- over-the-air update mechanisms;
- application programming interfaces connected to enterprise systems.
Compromise may occur through weak credentials, insecure wireless communication, exposed interfaces, malicious updates, third-party libraries, technology risks, compromised cloud accounts, or physical tampering.
Various reports have highlighted scenarios involving espionage or remote disablement by a foreign manufacturer. These possibilities should be treated as risk scenarios rather than evidence of established conduct by robotics companies. The more immediate and verifiable governance issue is update authority: who can access the robot remotely, change its behaviour, receive telemetry or prevent it from operating? [7]
The robot should consequently be assessed as both an endpoint and an operational technology asset.
Minimum controls for cybersecurity risk and AI risk should include:
- unique device identities and certificates;
- phishing-resistant administrator authentication;
- encrypted communication;
- signed firmware and software updates;
- restricted remote access;
- network segmentation;
- allow-listed integrations;
- secure logging;
- vulnerability-disclosure processes;
- supported rollback procedures;
- locally available emergency-stop controls.
Cybersecurity and physical safety should not be managed by separate teams. A compromised navigation, perception or motion-control function could create both types of harm.
The critical question is not only what the robot sees, but who else can see through it
A service robot may continuously observe spaces that customers and employees perceive as social rather than surveilled environments.
It can capture faces, voices, conversations, movement patterns, behavioural responses and the physical layout of a facility. These records may be processed locally, transmitted to the manufacturer, stored in a regional cloud environment or used to improve machine-learning models.
A robot deployed abroad may also be subject to the laws of the destination market.
In the European Union, connected robots may fall within multiple regimes depending on their functions, including data-protection law, the AI Act, the Machinery Regulation and the Cyber Resilience Act. The EU AI Act prohibits certain emotion-recognition uses in workplaces and educational institutions, except for specified medical or safety purposes. The Cyber Resilience Act will introduce vulnerability-handling, security and conformity obligations for products with digital elements; incident-reporting provisions begin applying in September 2026, with the principal obligations following in December 2027. [8] [9]
Organisations purchasing robots should obtain a complete data-flow map covering:
- every sensor and data field;
- the purpose of collection;
- local and remote processing;
- storage locations;
- retention periods;
- model-training use;
- subcontractors;
- cross-border transfers;
- deletion procedures;
- access by support personnel.
A privacy notice placed beside the robot is insufficient when the organisation itself cannot explain where the data travels.
When the Cloud Leaves the Building: Vendor dependence can turn a service robot into a business continuity risk
Many service robots depend on external infrastructure for fleet management, mapping, speech processing, analytics, software updates and diagnostics.
This creates several points of concentration:
- one manufacturer;
- one cloud platform;
- one telecommunications provider;
- one software account;
- one component supply chain;
- one maintenance network.
A geopolitical dispute is only one possible cause of disruption. Bankruptcy, acquisition, licensing conflict, cyberattack, discontinued product support or an ordinary cloud outage may have the same operational effect.
Organisations should determine whether the robot can continue functioning safely when disconnected from the vendor’s platform. A robot that loses cloud access should enter a controlled degraded mode—not freeze in an exit corridor, retain a guest’s payment card or continue moving without central monitoring.
Contracts should specify:
- software-support periods;
- security-patch timelines;
- critical-vulnerability response;
- data ownership;
- access to logs;
- service-level obligations;
- spare-parts availability;
- subcontractor changes;
- end-of-life notification;
- data return and deletion;
- transition support;
- conditions for remote suspension;
- escrow or continuity arrangements for critical software.
Robotics-as-a-service may reduce initial capital expenditure, but it can deepen operational dependence because software, hardware, maintenance and fleet data remain bundled with the provider. Individuals and organisations must be prepared to manage concentration risks arising from excessive exposure to a single point of failure.
The Robot Must Know Its Boundaries
A robot that performs well in an empty demonstration area may behave differently in a crowded lobby with reflective surfaces, unstable Wi-Fi, luggage, liquids, children and unpredictable movement.
Every deployment should therefore define the robot’s operational design domain: the physical, environmental and procedural conditions under which it is authorised to operate.
That domain should address:
- floor gradients and surface conditions;
- maximum crowd density;
- proximity to stairs and lifts;
- speed and payload limits;
- lighting and acoustic conditions;
- interaction with children and animals;
- emergency conditions;
- manual intervention;
- prohibited areas;
- battery and charging risks;
- evacuation requirements.
ISO 31101:2023 provides requirements for safety-management systems governing services delivered through service robots. ISO is also revising ISO 13482 to cover safety requirements for service robots used in personal and professional or commercial applications, with particular attention to physical human–robot contact. [10]
Compliance testing should not stop at the manufacturer’s intended use. To build operational resilience, organisations must assess reasonably foreseeable misuse, local operating conditions and interactions with other systems.
Designing a Service Robotics Assurance System: Seven controls for moving from experimentation to governed automation
1. Automate tasks, not entire roles
Break each service role into discrete activities. Classify them according to judgement, empathy, safety, privacy and regulatory consequence.
Repetitive delivery or wayfinding may be suitable for automation. Safeguarding, dispute resolution, emergency response and complex identity decisions may require human control.
2. Establish an automation risk appetite
Leadership and executive teams should determine which decisions robots may make autonomously, which require human confirmation and which must remain human-led.
The organisation’s tolerance of physical injury, discriminatory outcomes, data privacy risk, and service unavailability should be explicit.
3. Require a documented safety and security case
Before deployment, the business owner, safety team and cybersecurity function should demonstrate how material hazards have been identified, tested and controlled.
Risk identification and risk assessment are integral in evaluating issues stemming from the deployment of robots. Testing should include sensor obstruction, connectivity loss, mapping errors, malicious commands, crowded environments, battery failure and emergency shutdown.
4. Preserve meaningful human escalation
Customers should be able to reach a competent person without navigating an extended robotic interaction.
Human intervention must be available not only when the robot reports an error, but when the customer believes the machine is wrong.
5. Contract for operational sovereignty
The organisation should retain sufficient control to isolate the robot, access evidence, continue essential operations and change suppliers.
Operational risks can be curtailed if remote access and telemetry are limited to what is technically and contractually necessary.
6. Invest in workforce transition
Employees need training in robot supervision, incident response, service recovery, data handling and safety.
In order to prevent employment risks, workforce metrics should examine job quality, exception workload, psychological safety and turnover; not merely labour hours removed.
7. Monitor performance after the novelty fades
To establish risk resilience and prevent governance risks, leadership and risk committees should receive indicators covering:
- safety events and near misses;
- robot interventions by human staff;
- service-completion rates;
- exception volumes;
- customer abandonment;
- accessibility failures;
- privacy complaints;
- software vulnerabilities;
- patching delays;
- unauthorised remote-access attempts;
- cloud and connectivity downtime;
- employee workload and turnover;
- total cost per successfully completed service.
The important metric is not how frequently the robot moves. It is how reliably the overall service system achieves its objectives.
Keep the Human Door Open
Service robots may help organisations manage labour shortages, standardise routine processes, provide round-the-clock assistance and reduce physically demanding work. Their growing global presence also reflects the manufacturing scale and strategic investment in embodied artificial intelligence.
None of these advantages removes the need for hotel risk management and risk governance.
A robot at the front desk may be a host, sensor platform, payment terminal, access-control interface, moving machine and cloud-connected endpoint at the same time. Treating it merely as labour-saving equipment overlooks the concentration of responsibility occurring inside it.
The strongest deployment model is unlikely to be a completely human-free lobby or a complete rejection of automation. It is a deliberately designed system in which machines handle bounded, repeatable tasks and people retain authority over ambiguity, vulnerability, accountability and care.
The future of service automation should not be measured by how many employees disappear from view.
It should be measured by whether technology makes the service safer, more resilient and more trustworthy for everyone who walks through the door.
The author confirms that this article is original and has not been copied, reproduced, or derived from another author’s work, except for appropriately cited third-party references used for research purposes.
Citations:
[1] World Robotics 2025 data on professional, hospitality, cleaning and logistics service robots [ International Federation of Robotics (IFR) ]
[2] China’s 2025 population decline, working-age composition and population ageing [ National Bureau of Statistics China ]
[3] China’s policy focus on embodied artificial intelligence and humanoid-robot development [ Ministry of Industry and Information Technology (MIIT), Government of China ]
[4] China’s 2026–2030 strategic emphasis on AI-powered robotics [ International Federation of Robotics (IFR) ]
[5] Reporting on government funding, procurement, industrial capability and employment concerns surrounding Chinese humanoid robotics [ Reuters ]
[6] Research on customer experience, information security and human–robot service design in hotels, research on service-robot failure and the importance of human-led service recovery
[7] Analysis of the visible labour, foreign-supply and geopolitical scenarios associated with Chinese service robots [ GZERO Media ]
[8] EU AI Act requirements affecting biometric and emotion-recognition systems, EU Machinery Regulation governing machinery placed on the European market [ EUR-Lex ]
[9] EU Cyber Resilience Act requirements for connected hardware and software products [ European Commission ]
[10] ISO requirements for service-robot safety management and physical human–robot interaction [ International Organization for Standardization (ISO) ]
FAQS
1.What are the risks of service robots?
The robot may be connected to the property-management system, payment infrastructure, identity records, building maps, lifts, access controls, cameras, microphones and a remote vendor platform. It may make decisions in a public space, move around customers and employees, collect personal information and depend on software updates delivered from another jurisdiction.
The opportunities are substantial. So are the interconnected risks.
The appropriate enterprise question is not whether Chinese service robots should be welcomed or resisted. It is whether organisations can govern the various risks arising from labour displacement, physical safety, data collection, software dependence, customer experience and cross-border regulatory exposure before automation moves from novelty to operating infrastructure.
2. How should organisations manage service robot risks?
Organisations can manage service robot risks by designing a Service Robotics Assurance System:
a. Automate tasks, not entire roles: Leadership and executive teams should determine which decisions robots may make autonomously, which require human confirmation and which must remain human-led.
b. Establish an automation risk appetite: The organisation’s tolerance of physical injury, discriminatory outcomes, privacy intrusion, and service unavailability should be explicit.
c. Require a documented safety and security case: Before deployment, the business owner, safety team and cybersecurity function should demonstrate how material hazards have been identified, tested and controlled.
d. Preserve meaningful human escalation: Human intervention must be available not only when the robot reports an error, but when the customer believes the machine is wrong.
e. Contract for operational sovereignty: The organisation should retain sufficient control to isolate the robot, access evidence, continue essential operations and change suppliers.
f. Invest in workforce transition: Employees need training in robot supervision, incident response, service recovery, data handling and safety. Workforce metrics should examine job quality, exception workload, psychological safety and turnover.
g. Monitor performance after the novelty fades: Leadership and risk committees should receive indicators covering:
- safety events and near misses;
- accessibility failures;
- privacy complaints;
- software vulnerabilities;
- patching delays;
- unauthorised remote-access attempts
3. What is the role of enterprise risk management in robotics?
The Institute of Risk Management (world’s leading professional body for ERM certifications / qualifications with designations upto Fellowship recognised in over 140+ countries) defines Enterprise Risk Management (ERM) as “an integrated and joined up approach to managing all areas of risks across an organisation and its extended networks.”
In robotics, the role of ERM is therefore to help organisations identify, assess, govern and continuously monitor the full range of risks created by automation before those risks affect business objectives.
A strong ERM approach to robotics would therefore include:
- Identifying interconnected risks before deployment
- Defining risk appetite and decision boundaries
- Protecting human accountability: Automation can shift responsibility without clearly transferring accountability. ERM helps establish decision rights so that responsibility is defined before an incident occurs.
- Managing cyber and physical risk together: In robotics, a cybersecurity incident may have physical consequences. This means technology risk, operational risk and safety risk cannot be managed independently.
- Managing third-party and concentration risk: ERM helps organisations assess whether excessive dependence on one provider could create operational or business continuity vulnerabilities.
- Building organisational resilience: Resilience can be defined as the ability to anticipate, prepare for, respond to and adapt to disruption. In robotics, this means planning for connectivity loss, cyber incidents, equipment failure, vendor disruption, emergency shutdowns and situations in which human staff must immediately take control.
- Monitoring risk throughout the robotics lifecycle: Risk management cannot end when a robot is installed. Organisations need indicators covering safety incidents, human interventions, accessibility failures, privacy complaints, cybersecurity vulnerabilities, downtime, employee workload, customer abandonment and total service cost.
Ultimately, the role of enterprise risk management in robotics is to ensure that automation creates sustainable value without introducing unmanaged vulnerabilities elsewhere in the organisation.










