Critical Risk Areas & Mitigation Plans
Duration: 50 min · Level: Foundational · Module: 10. G1 Development Roadmap · Focus: risk, mitigation, planning, G1
A roadmap that lists only what will go right is a wish, not a plan. The discipline that separates a credible program from an optimistic one is naming the things most likely to break it — early, specifically, and with a mitigation attached to each. For the G1, five technical risks stand out as the ones most capable of delaying the 2030 launch or capping the robot's value in the market. This lesson treats each as a first-class engineering object: what it is, why it is dangerous, and what concrete action reduces it.
Risk 1 — Dexterous hand reliability
The 22-DOF tendon-driven hands are the G1's defining capability and its most fragile subsystem. Tendon systems carry high maintenance requirements: cables stretch, fray, and slip, and the more degrees of freedom you route through them, the more failure points you accumulate. A hand that needs constant servicing is unusable in a hospital, no matter how dexterous it is on a good day.
The mitigation is mechanical and procedural. Redundant tendon routing so a single cable failure degrades rather than disables the hand; a rapid tendon-replacement design so a field swap takes minutes, not a return to the lab; and MTBF testing to 1000 hours by 2027 so reliability is measured against a target, not assumed. The 1000-hour figure is the contract: it turns "the hands should be reliable" into a number a test rig can chase.
Risk 2 — VLA policy failure modes
Foundation-model policies are powerful precisely because they generalize — and dangerous for the same reason. A VLA can fail silently on out-of-distribution inputs, confidently producing a wrong action with no error and no warning. In a robot working near people, a confident wrong action is worse than a refusal.
Three mitigations turn silence into something you can catch. Uncertainty quantification so the policy can report when it is operating outside what it knows; a human-in-the-loop override for high-stakes tasks so a person remains the final authority where the cost of error is high; and comprehensive failure-mode testing so the ways the model breaks are catalogued before deployment rather than discovered in the field. The throughline: make failure observable, then make it interruptible.
Risk 3 — Battery life versus performance
The 8-hour endurance target and the robot's performance ambitions pull in opposite directions — every watt spent on dynamic motion or active manipulation is a watt not available for runtime. Hit the performance numbers naively and the robot is tethered to a charger; protect runtime naively and it moves like it is conserving energy.
The mitigation is to stop treating power as a fixed budget and start treating it as a managed one. Duty-cycle profiling in target environments establishes where the energy actually goes during a real shift; regenerative actuators recover energy from braking and gravity-assisted motion; and task-based power modes let the robot spend aggressively during a demanding task and idle efficiently between them. You meet the 8-hour target not by a bigger battery alone but by spending the one you have intelligently.
Risk 4 — Regulatory approval for healthcare
For a healthcare deployment, the hardest gate may not be technical at all. The G1 is likely to fall under EU MDR Class IIa device classification, which means a regulator stands between a working robot and a paying customer — and regulatory timelines do not compress to meet engineering deadlines.
The mitigation is to start the clock immediately rather than at the end. Engage a notified body in 2026 so the certification relationship exists years before submission; track IEC 62061 compliance from day one so functional-safety evidence accumulates as the robot is built rather than being reconstructed afterward; and have a clinical trial plan by 2028 so the evidence the regulator will demand is being generated on schedule. Regulatory work is slow, so it must start early — that is the entire strategy.
Risk 5 — Sim-to-real gap for manipulation
Locomotion has largely crossed the sim-to-real chasm; manipulation has not. Household manipulation still fails in real-world conditions that simulation does not faithfully reproduce — varied lighting, deformable objects, unmodeled friction, clutter. A policy that looks flawless in Isaac Lab can stumble on the first real countertop.
The mitigation accepts that you cannot simulate your way across this gap and must instead collect real data at scale. Real-world data-collection infrastructure and a teleoperation harness let operators generate demonstrations directly on the robot, and a data-flywheel strategy turns every deployment into training data that improves the next policy — a theme Lesson 10.4 returns to as a strategic advantage. The gap closes through volume of real experience, deliberately captured.
Putting it into practice
Build the risk register that the program reviews on every milestone.
- Create one row per risk: hand reliability, VLA failure, battery-vs-performance, regulatory, sim-to-real.
- For each, write a one-sentence statement of what could go wrong and why it threatens the 2030 launch.
- List the mitigations verbatim from this lesson, and beside each name an owner — a mitigation without an owner is a wish.
- Attach a measurable checkpoint where one exists (MTBF to 1000 hours by 2027; notified body engaged in 2026; clinical trial plan by 2028), and define one where the data gives only a direction.
- Add a status column (red / amber / green) and commit to updating it at each milestone review.
- Make the register a standing agenda item — a risk you stop looking at is a risk you have decided to be surprised by.
Key takeaways
- The 22-DOF tendon hands are the top reliability risk; mitigate with redundant routing, rapid replacement, and MTBF testing to 1000 hours by 2027.
- VLA policies fail silently out of distribution; counter with uncertainty quantification, human-in-the-loop override for high-stakes tasks, and failure-mode testing.
- The 8-hour endurance target conflicts with performance; manage it via duty-cycle profiling, regenerative actuators, and task-based power modes.
- Healthcare deployment likely means EU MDR Class IIa; start early — engage a notified body in 2026, track IEC 62061 from day one, clinical trial plan by 2028.
- Manipulation's sim-to-real gap is real; close it with real-world data infrastructure, a teleop harness, and a data-flywheel strategy.
- Every risk gets a mitigation, an owner, and a measurable checkpoint — that is what turns a risk list into a plan.
← Previous: 10.1 G1 Architecture: Resolved Technology Decisions · Next: 10.3 2026–2030 Development Milestones →
Part of Module 10: G1 Development Roadmap.