1st IJCAI Workshop on Safe Physical AI

IJCAI/ECAI 2026

15-16 August 2026

University of Bremen, Room SFG-2030

About the Workshop

Recent progress in deep learning and robot learning has brought the vision of autonomous, embodied systems operating in real-world environments significantly closer to reality. Robots and other physically situated AI systems are now demonstrating strong generalization, contact-rich manipulation and long-horizon reasoning capabilities. As these increasingly operate in human environments, ensuring both physical and cognitive safety becomes an urgent research priority.

This workshop focuses on Safe Physical AI: the study and development of intelligent systems that can act safely and reliably in the real world. We seek to identify fundamental challenges in verification, interpretability, uncertainty quantification, human–robot interaction, and alignment for physical AI systems. The workshop will unite researchers from robotics, deep learning, AI safety, planning, and AI governance to develop a shared conceptual and methodological foundation for safe embodied intelligence. By fostering interdisciplinary dialogue and mapping concrete research directions, the workshop aims to advance the scientific and ethical foundations required for trustworthy physical AI.

Key Objectives

  • To foster cross-disciplinary exchange between researchers in robotics, AI safety, machine learning, planning, control, ethics, and AI governance, encouraging collaboration and shared methodologies for safety assurance in embodied systems.
  • To define challenges and opportunities in developing safe, reliable, and interpretable embodied agents by analysing concrete safety and alignment issues in real-world interaction, manipulation, and long-horizon autonomy.
  • To develop a shared understanding of fundamental concepts, risk taxonomies, and evaluation strategies for assessing the safety and trustworthiness of embodied AI.
  • To investigate how AI methods—including reinforcement learning, uncertainty-aware models, causal reasoning, and formal verification—can contribute to safe decision-making and control under uncertainty.
  • To identify gaps in current architectures and design methodologies for engineering embodied agents that meet rigorous safety, robustness, and ethical requirements.

Venue

The workshop takes place at the University of Bremen, Room SFG-2030, Enrique-Schmidt-Straße 7, 28359 Bremen, Germany.

Call for Papers

This workshop invites submissions that develop methods, theory, empirical insights, benchmarks, and conceptual frameworks for Safe Physical AI: real-world intelligent systems that act safely and reliably under uncertainty. We welcome technical, empirical, theoretical, and position papers.

We welcome submissions of work that has been previously published or is under review at other venues. Authors should indicate this at submission time. Such submissions will be evaluated based on their relevance to the workshop themes.

Submission Formats

We accept short papers (4 pages excl. references) as well as extended abstracts (1 page excl. references). All submissions must use the two-column IEEE template Review is single-blind. Authors of four-page papers will present their work in a seven-minute talk, with an additional seven minutes for questions and discussion. Authors of extended abstracts will present their work in two-minute lightning talks. Authors of short papers and extended abstracts are strongly encouraged to submit a poster and join the speaker office hours. We strongly encourage interdisciplinary submissions, early-stage research papers, and contributions from graduate students.

Important Dates

Submissions openMarch 26, 2026
Submission deadlineMay 7, 2026 May 14, 2026, 23:59 CET (extended)
Author notificationJune 7, 2026
Camera-ready deadlineJuly 20, 2026

Relevant Topics

  • Safe decision making and action selection for embodied agents
  • Uncertainty quantification, risk estimation, and probabilistic verification
  • Interpretability of policies and world models, including mechanistic and behavioral approaches
  • Task specification, alignment, and intent understanding for physical agents
  • Monitoring and evaluation of untrusted models or untrusted hardware
  • Runtime verification, safety shields, and control-theoretic safety mechanisms
  • Bridging classical robot safety and statistical learning: safety beyond toy domains
  • Safe operation in social, contextual, and multi-agent environments
  • Stress testing, benchmarking, and evaluation methodologies
  • Contributions from ethics, law, and philosophy to physical AI safety
  • Interdisciplinary perspectives on risk taxonomies, safety vocabularies, and conceptual foundations
  • Hardware and computational design choices for safety in physical AI
  • Safe autonomy in real-world cyberphysical systems, including aerial, mobile, and manipulation platforms

Invited Speakers

George J Pappas

George J Pappas

University of Pennsylvania

Talk: LLM-Enabled Robots: Jailbreaking Attacks and Defenses

Abstract

Large language models are rapidly being integrated into robotic systems, promising robots that can interpret natural-language commands, reason about open-world tasks, and plan actions with unprecedented flexibility. Yet this same flexibility introduces a new and underappreciated attack surface: the safety guardrails that prevent an LLM from producing harmful text do not prevent an LLM-controlled robot from taking harmful physical actions. In this talk, I will show that LLM-enabled robots are alarmingly easy to jailbreak. Building on adversarial prompting techniques, our RoboPAIR algorithm achieves the first successful jailbreaks of LLM-controlled robots, eliciting unsafe and physically dangerous behaviors across simulated, white-box, and real-world platforms—often with complete success. These results demonstrate that aligning the language model is not equivalent to ensuring the robot it controls is safe. I will then turn to defenses, presenting RoboGuard, a runtime guardrail that grounds high-level safety specifications in contextual reasoning and formal verification to constrain robot behavior. RoboGuard reduces the execution of unsafe plans from over 90% to under 3% while preserving the robot’s ability to complete legitimate tasks. I will close by arguing that the safety of physical AI demands context-aware, action-level guarantees that go beyond text-level alignment, and outline open challenges for building robots we can trust to act in the world.

Andrea Bajcsy

Andrea Bajcsy

Carnegie Mellon University

Talk: How to Control a Robot You Didn't Train

Abstract

Robot foundation models (FMs) are rapidly becoming accessible: with modest compute, anyone can download a pretrained model and deploy it on a robot in a home or business “zero-shot”. But deploying a robot FM today often feels like operating a black box: you inherit a model’s capabilities but also its biases and failure modes without fully understanding where they came from. This makes it difficult to predict what a robot can and cannot do and whether it will behave safely and reliably in novel situations. In this talk, I will discuss my group’s work on controlling robot foundation models that we did not train ourselves. Specifically, I will describe a spectrum of control mechanisms that operate on a model’s inputs (e.g., natural language), internals (e.g., the generative process), and outputs (e.g., safety filters) to steer behavior toward safe, aligned, and high-performing outcomes while preserving the broad capabilities acquired during pretraining. Throughout the talk, I will present examples spanning both visuomotor policies and world models, with applications in robotic manipulation.

Sao Mai Nguyen

Sao Mai Nguyen

IP Paris

Talk: Neurosymbolic Reinforcement Learning for Long-Horizon Reasoning

Abstract

While Deep RL tackles long-horizon tasks by representation learning, these latent spaces are not interpretable and are hard to use in a safe manner by robots. Cyber-physical systems on the other hand use formal verification to verify safety-critical physical systems controlled by software. Because RL relies on trial and error, it can cause catastrophic failures during training and deployment. Formal verification acts as a mathematical guardrail to prevent these failures. However, classical integration approaches do not enable the robot to learn representations that are both interpretable and verifiable.

In this talk, we will introduce two methods combining deep reinforcement learning and formal verification. STAR is a deep hierarchical reinforcement learning algorithm that uses reachability analysis to devise a latent space grounded in the environment, both useful for more efficient learning by reinforcement learning and interpretable for interaction with humans. Reversely, we also use deep reinforcement learning as a framework to learn temporal rules describing long-horizon activities. These neurosymbolic methods combine the trial-and-error paradigm in continuous settings with formal verification to devise an interpretable representation for human verification and to be used for safe decision-making.

Michael Beetz

Michael Beetz

University of Bremen

Talk: From Plausible Action to Warranted Commitment: A Cognitive Framework for Safe Physical AI

Abstract

Physical AI systems increasingly generate plausible actions from demonstrations, learned policies, and foundation models. Yet an action that is statistically likely or task-relevant is not necessarily safe in the physical situation at hand. This talk presents the AICOR framework for reason-warranted physical action, which conceptualizes robot manipulation as the closed-loop solution of body motion problems within coupled robot–world systems. Before acting, the robot evaluates candidate actions against an explicit, task-relative model of the current situation, including their grounds, predicted effects and side effects, validity conditions, uncertainty, and safety and recovery margins.

During execution, the robot compares predicted and observed body–world evolution and responds to deviations through regulation, repair, withdrawal, or renewed deliberation. Semantic digital twins, executable action models, and episodic records make these processes operational, inspectable, and empirically assessable. Examples from everyday manipulation illustrate why successful execution alone is insufficient evidence of safe competence. Safe Physical AI therefore requires an architectural transition: from systems that merely generate likely actions to systems that can warrant, bound, monitor, revise, and account for their physical commitments.

Judith Simon

Judith Simon

University of Hamburg

Talk: Trustworthy AI? Epistemological and Ethical Aspects

Abstract

AI in its various forms affects us on a daily basis. AI is used both in science and in everyday life for pattern recognition, classification, prediction and decision support, and the use of Generative AI for communication, information and the production of new content has skyrocketed since 2022. Moreover, these various AI systems are also increasing embedded in robotic systems with the aim to increase their performance.

Yet AI systems also pose various epistemic and ethical challenges, related to accuracy, bias and discrimination; a lack of transparency and accountability; sustainability and numerous other concerns. Thus, while we seem to rely on AI on a daily basis, the question remains whether we can trust it – and whether we should. I will argue that we can trust AI systems, if and only if we conceive them as socio-technical systems, but that we should trust it if and only if they are trustworthy. In my talk, I will delineate some epistemic and ethical requirements for trustworthy AI systems, focusing on particular on the role of deception, and end with some considerations on the implications for the design of AI systems.

Interactive Formats

The workshop prioritizes active participation and knowledge exchange through multiple interactive formats designed to engage attendees across career stages and disciplines.

Poster Session

Poster sessions provide dedicated venues for early-career researchers to present their work and receive feedback from the broader community. Authors will submit one-page extended abstracts describing their research, with each presenter delivering a two-minute lightning talk to preview key ideas and encourage focused discussions at their poster. Authors of four-page short papers will also be given the opportunity to present a poster. Poster sessions are strategically scheduled during coffee breaks and between invited talks and panel discussions to maximize attendance and foster informal interactions.

Speaker Office Hours

To support early-career researchers and enhance inclusivity, our invited speakers hold office hours during the poster and networking sessions. Attendees can drop in to discuss their posters, research challenges, career development, and potential collaborations directly with the speakers. The office hours run concurrently with the poster sessions on both days.

Panel Discussion

The panel discussion will convene invited speakers for a moderated conversation examining challenges and advancements in safe physical AI from multiple disciplinary perspectives. Attendees can submit questions through an online platform where others can vote to prioritize the most pressing topics.

Program Committee

  • Prof. Michael Fisher (University of Manchester) — Verification of Autonomous Systems; Trustworthy AI
  • Prof. Masoumeh Mansouri (University of Birmingham) — Hybrid Robot Intelligence; Social Robotics
  • Dr. Michaela Kümpel (University of Bremen) — Knowledge Systems and Human-Robot Interaction
  • Dr. Maciej Zajac (Polish Academy of Sciences) — Ethics of Autonomous Weapons Systems
  • Prof. Rania Rayyes (Karlsruhe Institute of Technology) — Developmental Robots, Dexterous Robots, Industrial Robotics
  • Prof. Darko Katic (Stuttgart Technical University of Applied Sciences) — Knowledge Representation and Reasoning; Surgical Robotics
  • Dr. Justin Shenk (Redwood Research) — Evaluations and risk assessments for frontier AI models
  • Prof. Barbara Hammer (University of Bielefeld) — Robust, Data-parsimonious, Fair Machine Learning
  • Prof. Daniel Neider (TU Dortmund) — Safety Verification of AI systems
  • Prof. Vera Schmitt (TU Berlin) — Trustworthy and Responsible NLP
  • Prof. Julius Schöning (Osnabrück UAS) — Intersections to Legal Issues
  • Dr. Tim Schrills (University of Lübeck) — Psychology, AI Act
  • Prof. Peter Fettke (DFKI) — Human-Centric AI, Economics
  • Prof. Hanna Drimalla (University of Bielefeld) — Multi-Modal Sensors, Human-Centric AI
  • Max Kroker (Independent Lawyer) — Law of AI
  • Dr. Daniel Winteler (Fraunhofer Society) — Law of AI

Organizers

Benjamin Alt

Benjamin Alt

University of Bremen, Germany / Robotics Institute Germany (RIG)

Technical Director at the AICOR Institute for Artificial Intelligence and co-founder of AICOR Solutions, a startup for safe robot intelligence.

Primary Contact: benjamin.alt@uni-bremen.de

Nico Hochgeschwender

Nico Hochgeschwender

University of Bremen, Germany / Robotics Institute Germany (RIG)

Professor of Software Engineering for Cognitive Robots and Systems, Co-Speaker of the Thematic Cluster Safety, Reliability, and Resilience of AI-enabled Robotics of the Robotics Institute Germany.

Benjamin Paaßen

Benjamin Paaßen

University of Bielefeld, Germany

Junior Professor for Knowledge Representation and Machine Learning.

Karinne Ramirez Amaro

Karinne Ramirez Amaro

Chalmers University of Technology, Gothenburg, Sweden

Associate Professor in the Electrical Engineering Department.

Alex Robey

Alex Robey

Carnegie Mellon University, Pittsburgh, USA

Postdoctoral fellow in the Machine Learning Department.

Nathan Wood

Nathan Wood

Hamburg University of Technology, Germany / Ethics + Emerging Sciences Group, California Polytechnic State University San Luis Obispo, USA

Junior Research Group Leader at the Institute for Air Transportation Systems, heading the interdisciplinary project "Military Defense Technologies and Ethics".

Schedule

All times CEST.

Day 1 — Saturday, August 15

09:30Opening remarks
09:45Contributed Talks 1
10:25Coffee break
10:40Contributed Talks 2 (incl. lightning talks)
11:45Poster session
13:00Lunch
14:00Invited Talk — Judith Simon
14:45Contributed Talks 3
15:10Plenary discussion / Q&A
15:45Coffee break
16:00Invited Talk — Andrea Bajcsy
16:45Panel introduction / networking
17:30Close

Day 2 — Sunday, August 16

09:30Invited Talk — Sao Mai Nguyen
10:15Contributed Talks 4
10:45Coffee break
11:00Invited Talk — George Pappas
11:45Contributed Talks 5
12:15Lunch
13:15Invited Talk — Michael Beetz
14:00Poster session & mentoring
15:15Panel discussion / Q&A
16:15Wrap-up

Contributed talks are 5 minutes plus 1 minute for handover, with no questions in the room. All accepted papers also present a poster, and discussion happens at the poster sessions.

Contact

For inquiries, please contact: benjamin.alt@uni-bremen.de