A reported fatality during setup of a stationary industrial robot demonstrates the central cell-entry hazard: a person can be trapped between robot motion and fixed structure. The available account supports a practical review of hazardous energy, operating modes, access control, end-of-arm tooling, software, and verification, but it does not establish the final legal or technical cause.
Separate the Reported Facts from the Preliminary Cause
A 22-year-old contractor was part of a team setting up a stationary robot at a Volkswagen plant in Baunatal, Germany. The robot reportedly grabbed him and crushed him against a metal plate. The equipment normally operated inside a confined area while handling and manipulating automotive parts.
A company spokesperson reported that initial conclusions pointed to human error rather than a robot fault. Treat that statement as preliminary: the evidence contains no completed investigation, validated event sequence, controller logs, safeguard status, operating-mode record, or judicial finding. It therefore does not prove that an interlock was bypassed, that automatic mode was active, or that a specific component failed.
Define the Crushing Hazard Before Cell Entry
The immediate hazard is not robot motion alone. It is motion combined with a trapping point between the robot, its payload or tooling, and a fixed object such as a plate, floor, machine, pallet, or fence. A safe review must consider the complete motion envelope and every location where a person could be pinned, struck, or trapped.
| Hazard source | Failure or exposure to evaluate | Required decision |
|---|---|---|
| Programmed robot motion | Unexpected path, mode change, or command during setup | Determine whether work can occur with motion disabled |
| Fixed structures | Crushing point between the robot and surrounding equipment | Remove personnel from the trapping zone or prevent hazardous motion |
| Payload and end-of-arm tooling | Dropped or unintentionally released part | Prevent release until the payload reaches an approved deposit position |
| Stored energy | Spring, gravity, kinetic, pneumatic, or hydraulic movement | Isolate, dissipate, restrain, or block each source |
| Safeguarding | Defeated, worn, disconnected, or jumpered interlock | Restore and validate the safeguard before operation |
| Software | Unusual state sequence exposes an untested command path | Analyze state transitions and verify the revised sequence |
Distinguish De-Energized Work from Powered Work
“Live” is ambiguous unless the team defines it. Equipment may be powered and operable without running automatically. Before entry, document whether the task requires automatic operation, teach or manual motion, control power only, or complete energy isolation.
For work that does not require motion, lock out and tag the equipment and control every hazardous energy source. Removing servo power alone does not address gravity, springs, retained pneumatic or hydraulic pressure, suspended payloads, or other stored energy. Disable, dissipate, restrain, or mechanically block those hazards as the task requires.
If diagnosis or teaching genuinely requires powered motion, the evidence describes teach or manual control, restricted speed, an enabling device such as a teach pendant or separate dead-man device, and an observer outside the hazard area with access to an emergency-stop device. These are inputs to the task-specific safety plan, not proof of compliance with an unnamed standard. The evidence supplies no validated speed limit, force limit, stopping distance, or robot-specific mode configuration.
Use a Controlled Cell-Entry Decision Path
- Define the task and identify every location a person must occupy, including possible crushing points throughout the commanded and residual motion envelopes.
- Determine whether cameras, remote diagnostics, wireless observation, or relocated test points can eliminate entry. The evidence describes robot-mounted cameras and wireless equipment as an engineered alternative to riding or closely observing moving machinery.
- If motion is unnecessary, isolate and tag all energy sources, release retained energy, secure gravity-loaded elements, block motion where required, and verify the safe state before entry.
- If powered motion is essential, prohibit automatic operation during occupancy and use the approved manual or teach procedure, enabling device, restricted-motion settings, and defined outside supervision required by the site assessment.
- Remove personnel, restore guards and interlocks, clear tools and temporary blocks, and apply the specified reset criteria before returning the cell to production.
- Run a controlled verification from outside the hazard area. Confirm the intended path, tooling behavior, safeguard response, reset behavior, and absence of unintended release or motion.
Design Safeguards Against Single Defeats and Latent Faults
The evidence describes properly applied industrial safety systems as using at least two channels, separate evaluation, agreement between processors, timing checks, pulse checking for sensor continuity, and controlled reset criteria. It also states that servo power is admitted through a dual-channel arrangement and that robot axes may use spring-set brakes when power is removed. These statements are practitioner descriptions, not model-specific specifications; verify the actual robot, safety controller, drives, brakes, and risk-reduction functions from their approved documentation.
A safety function provides no protection after it is jumpered, disconnected, worn out, or mechanically defeated. Inspection must therefore test the complete chain: sensor or access device, both input paths where provided, safety logic, output devices, final power-control elements, reset behavior, and fault detection. Do not infer safety integrity merely because an emergency stop halts normal motion.
Control Software, Payload, and End-of-Arm Tooling Risks
One cited automation event involved a robot moving a raw casting weighing more than 650 lb. An unusual sequence exposed a software bug that commanded the gripper to release while the casting was moving near the top of its arc. The response was to stop the automation work, review the code and part motion, revise the path to reduce malfunction consequences, and redesign the gripper so release could occur only when the part was positioned over its pallet.
This case supports two independent controls: prevent an unsafe command in software and prevent the mechanism from releasing the payload at an unsafe location. Software review alone does not eliminate a tooling failure, and robust tooling alone does not validate the state sequence. Test normal production, setup, recovery, interruption, reset, and abnormal transitions before personnel depend on the behavior.
Verify the Cell Before Returning It to Service
Record the evidence needed to reconstruct the safety state: task authorization, operating mode, energy-isolation status, safeguard condition, temporary overrides, controller and safety-system diagnostics, tooling state, payload position, reset sequence, and the results of functional tests. The supplied evidence provides no robot model, safety-system model, firmware, program listing, interlock schematic, or event log for the Baunatal incident, so no product-specific root cause can be assigned.
Close the work only after confirming that temporary bypasses are removed, access panels and fences are restored, interlocks detect access correctly, hazardous motion remains inhibited during access, resets do not initiate unexpected motion, and the robot and tooling complete the approved sequence with personnel outside the hazard area. Escalate any unexplained motion, coordinate deviation, release command, or inconsistent safeguard response instead of normalizing it as unusual robot behavior.
Frequently Asked Questions
Can I enter a robot cell if the servos are turned off?
Not on that fact alone. Isolate and verify all relevant energy, including gravity, springs, retained pneumatic or hydraulic pressure, kinetic energy, and suspended payloads.
What controls are needed when a robot must move during setup?
The evidence supports an approved manual or teach procedure, restricted motion, an enabling device, defined outside supervision, and personnel kept clear of crushing points. It provides no universal numeric speed or force limit, so obtain those settings from the applicable risk assessment and approved equipment documentation.
Does a human-error finding prove the robot safety system worked?
No. The reported human-error conclusion was preliminary, and the evidence contains no logs or completed investigation. Verify operating mode, interlocks, overrides, safety outputs, stored-energy controls, tooling state, and the actual motion sequence before assigning root cause.