STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart

Open RFC · v0.2 → v0.3 · updated 27 June 2026

The Embodied AI Security Top 10 is a draft. This is the RFC.

The list is a community draft maintained in the open under CC BY-SA 4.0. This page is the part that asks for something: what the list is trying to be, what it deliberately is not, the questions its maintainer cannot answer alone, and what it takes to change an entry.

Scope

Risks specific to embodied AI systems: policies that take an instruction and an observation and emit an action that moves something physical. A risk earns a place by being one that a deploying team has to reason about and that a general LLM risk list does not already cover well.

Everything here is written so a defender can test for it, and the tool that tests them runs in a simulator. The list describes what to check for; it is not an operational guide to causing any of it.

Non-goals

  • Not a standard. No conformance claim attaches to it and none should be made against it.
  • Not a compliance checklist. Covering all ten proves nothing about a system's safety case.
  • Not a threat model for your system. It is a starting vocabulary; the risks that matter to a specific deployment depend on what it is allowed to touch.
  • Not exhaustive. Ten is a format constraint, not a finding about how many risks exist.

Open questions

Is the ranking defensible at all?
Should the two out-of-scope risks be in the list at all?
Where does the boundary between EAI03 and EAI07 actually fall?
Does a risk with no known real-world incident belong?

How a change lands

  1. Open a discussion, or an issue if you have a concrete edit. Both links are below and neither needs permission.
  2. A change to an entry’s definition or scope needs a stated reason; a change to its RANK needs evidence, because rank is the part with the least support behind it.
  3. Disputes are recorded even when they do not change the list. A taxonomy that shows no disagreement is either finished or unread, and this one is neither.
  4. Versions are dated and the list carries its own version (v0.2) on every page that renders it. A change bumps the version; it does not silently edit the current one.