Summary
- An ANYmal inspection robot has used a digital identity to pass access-controlled doors autonomously at GE Vernova’s Whitegate power plant.
- LEGIC supplies the credential technology, while dormakaba’s access and door systems enforce permissions already used for authorised personnel.
- The partners plan commercial availability and are exploring the same model for lifts, gates, and turnstiles.
dormakaba, ANYbotics, and LEGIC have tested an autonomous inspection robot that can authenticate itself at secured doors inside an operational Irish power plant, addressing a surprisingly physical limitation on industrial robotics: a machine may be autonomous until it reaches a locked door.
The pilot at GE Vernova’s Whitegate power plant in County Cork gives an ANYmal quadruped robot a secure digital credential that it can use to request access electronically. dormakaba’s access-management and door-automation systems then determine whether the machine has permission to enter, applying predefined rules before opening the door without human intervention.
The robot has been operating inside the live plant for several weeks, repeatedly requesting access, passing through controlled doors, and continuing its inspection routes. LEGIC supplies the credential technology, ANYbotics provides the robot and robotics platform, and dormakaba provides the access-management and automated-door layer.
Although opening a door looks like a minor addition to an autonomous system, it exposes a wider integration problem as robots move from controlled demonstration spaces into industrial facilities. Plants are deliberately segmented by physical security, safety zones, operational permissions, and restricted areas, so a machine that cannot participate in those access systems remains dependent on a person whenever its route crosses one of those boundaries.
Machine identity enters physical access control
The Whitegate approach treats the robot more like an authenticated operational asset than an exceptional piece of machinery. Instead of giving it unrestricted movement or programming doors to open whenever the robot approaches, the system issues a credential and evaluates that credential against permissions held in the access-control environment.
That distinction creates a clearer governance model because access can be bounded by location and other rules established by the operator. It also creates an audit trail under the same broad access principles used for people, making it possible to record when the robot requested entry and whether that request was permitted.
Industrial organisations already manage machine identity extensively in their digital environments, where servers, applications, sensors, certificates, and service accounts require authenticated access to networks and data. Autonomous mobile robots bring a similar principle into the physical estate because software actions can now cause movement between real rooms, production areas, and controlled infrastructure.
Keeping the physical and digital layers aligned becomes particularly important when a robot’s role changes. An inspection machine may need permission to enter a turbine area but no access to a control room, while another robot could be authorised for a different route. If permissions can be managed centrally rather than hard-coded into the robot or individual door controllers, operators gain a more familiar way to modify or revoke access as requirements change.
Autonomy depends on ordinary infrastructure
Industrial robotics is often discussed through advances in perception, navigation, sensors, and AI, although commercial usefulness depends just as heavily on whether the machine can interact with ordinary infrastructure. Doors, lifts, turnstiles, radio dead zones, uneven surfaces, safety barriers, and site-specific procedures can all break an otherwise autonomous route.
The Whitegate pilot is therefore less about a clever door than about extending the operating envelope of an inspection robot. ANYmal systems are designed to move through industrial environments and gather inspection data in areas where sending people repeatedly may be inefficient or hazardous, but every access-controlled threshold previously restricted the amount of a site they could inspect without assistance.
dormakaba, ANYbotics, and LEGIC are now exploring the same approach for lifts, gates, and turnstiles, which would increase the number of physical barriers a robot could navigate using established permissions. ANYbotics also intends the capability to become an add-on across the wider ANYmal fleet rather than remain a one-off Whitegate integration.
Commercial deployment will still require site-specific engineering. Doors need suitable automation, credential systems must interoperate, access rules have to reflect operational and safety requirements, and the robot needs a safe response when permission is refused or a doorway fails to operate. Facilities also require procedures for lost credentials, software updates, compromised devices, and emergencies in which normal access rules change.
Physical AI creates another security boundary
Giving machines credentials also expands the security model around robotics, because the credential itself becomes an asset that has to be protected. A robot able to request physical access should not be treated as trusted simply because it is inside the facility; its identity needs to remain verifiable, permissions should be limited to the task, and credentials require a mechanism for revocation.
That is especially relevant in energy and industrial environments where physical access and cyber systems increasingly intersect. An autonomous robot may carry cameras, thermal sensors, microphones, network connectivity, and onboard compute while travelling between operational areas, creating useful inspection capability but also placing a connected device close to critical assets.
The architecture demonstrated at Whitegate retains the plant’s access-control system as the decision point rather than allowing the robot to decide that a door should open. That keeps the operator responsible for defining permission and gives the physical-security layer a way to reject requests independently of the robot’s navigation software.
The pilot does not establish a universal standard for machine credentials, nor does it remove the safety and cybersecurity work needed around autonomous systems. It does demonstrate how an existing industrial control — authenticated access — can be extended to machines without simply bypassing the restriction in the name of automation.
As autonomous inspection expands through power generation, manufacturing, chemicals, mining, and other industrial settings, practical limits on deployment are likely to include more of these ordinary interfaces. A robot that can navigate difficult terrain but stops at every secured threshold remains only partly autonomous; connecting machine identity to existing access infrastructure gives operators a way to remove that dependency without giving the machine unrestricted movement.












