What Figure Does Well
Figure AI operates Figure 02, the second-generation bipedal humanoid that succeeded the Figure 01 prototype, with a manufacturing deployment at BMW's Spartanburg, South Carolina plant. The publicly described BMW engagement centers on body-shop tasks such as sheet-metal part handling, and it is among the most visible production-oriented humanoid deployments among Western humanoid programs. Figure's commercial trajectory rests on Helix, a vision-language-action model: an end-to-end neural policy that maps natural-language instruction and onboard vision directly into bimanual manipulation, an approach that departs from the discrete skill-library architectures common in earlier humanoid programs.
The corporate context reinforces the trajectory. Figure's publicly reported backers include Microsoft, OpenAI, NVIDIA, Jeff Bezos, Intel Capital, and Parkway Venture Capital. Figure and OpenAI announced a collaboration in early 2024 that produced conversational-agent demonstrations on Figure 01; Figure announced in February 2025 that it was ending that collaboration to develop its behavior stack in-house, and it introduced Helix as that in-house policy. This is a genuine vertical-integration posture: Figure controls both the humanoid hardware and the on-robot policy.
None of this is in dispute, and none of it is the subject of the comparison here. Helix is a behavior policy. It accepts an instruction and produces a behavior. What it does not model, because that is not its job, is whose credentialed authority a given instruction carries, how instructions from several distinct authorities compose over one fleet, or how a governing party revokes an instruction after the fact with an auditable record. Those are the questions industrial humanoid deployment raises the moment it moves past a single site under a single customer's authority.
The Multi-Authority Deployment Problem
Industrial humanoid operations sit inside a layered oversight environment. OSHA general-duty obligations, the ANSI/RIA R15.06 and ISO 10218 industrial-robot standards, the ISO/TS 15066 collaborative-robot guidance, ongoing NIST work on robotics safety and measurement, and the EU AI Act's treatment of high-risk systems all point at the same practical premise: the party whose instruction governs a machine's behavior around people should be identifiable and accountable, and in a multi-party deployment that accountability has to span several governing authorities at once, the facility operator, the OEM customer, the fleet operator, the systems integrator, and the regulator, each of which holds a distinct slice of governance over the same deployed unit.
BMW Spartanburg is one site under one customer's authority. The commercial roadmap for humanoids generally points toward multiple customers, multiple sites, multiple shifts, and eventually multiple fleets: units running for one automotive customer, another manufacturer, a logistics operator, and a consumer setting, each under a different facility authority and a different regulatory regime. Helix is silent on that composition by design; it is a behavior policy, not an authority model. Operator Intent is a layer that supplies exactly that missing model: it makes an instruction a credentialed object, makes the authorizing operator identifiable, bounds what the instruction may cause, and composes authority across the parties that share a fleet.
How the Operator-Intent Layer Composes Authority
The provisional discloses operator intent as a first-class architectural primitive of a governed spatial mesh: intent observations are published, admitted, fused, and consumed across a plurality of fidelity tiers, each intent observation carrying an authority credential, a temporal scope with a time-to-live, a spatial reference, a payload, and a lineage field. In a humanoid deployment, each governing party emits its intent at the tier appropriate to its role rather than through implicit, un-credentialed instruction: a facility operator can declare a coarse work envelope and safety geometry, an OEM customer can declare a task-level objective, a shift supervisor can declare a per-unit dispatch instruction, and a regulator can declare a compliance constraint that gates the whole envelope.
The spec's graduated fidelity tiers carry this. It describes at least three configurable tiers, full cognitive-state sharing, structured partial-fidelity intent extracted from an integrated data bus (it enumerates robotic middleware such as ROS/ROS2 and DDS among the integration sources), and behavior-inferred intent produced from mesh observation of a legacy unit, with tier-weighted evidential factors feeding a cross-tier composite admissibility evaluator. A coarse envelope, a task objective, a dispatch instruction, and a compliance constraint each enter at their native tier, each bound to their issuer's credential, and compose into a single admissibility decision that gates actuation at execution time. Where two parties instruct one unit at once, the composite is resolved through this evaluator rather than through ad-hoc precedence rules hand-coded into a controller.
Bounded, Revocable, and Auditable
Two further properties from the provisional matter for humanoid deployment. First, intent is bounded: the spec composes operator intent with a capability envelope through intent-bounded capability derating, and it gates a proposed actuation through the composite admissibility evaluator, which can permit, gate, defer, or reject the action, with graduated-actuation modes that let a unit stage or de-escalate an action rather than commit it. A unit that would exceed the envelope its authorizing intent defines does not act on it; it defers or escalates. This is meaningful human control expressed as structure rather than as a policy statement.
Second, intent is revocable and auditable. The disclosure includes an intent-retraction and correction mechanism supporting governance-chain-preserving corrigibility, and an intent-lineage recorder that records every intent emission, admission, fusion, verification, retraction, and downstream consumption in the governance chain. A governing party can retract a standing instruction; retracted intent remains in the chain as retracted-and-superseded rather than being deleted, and consumers that acted on it are notified. Every governed action traces back to the intent and the operator that authorized it.
Treating operator authority instead as a per-site configuration file or an integrator's runbook scales to one site under one authority. It does not scale to a fleet under partially conflicting instruction from a facility operator, an OEM customer, a fleet operator, and a regulator at the same time. At that point the composition, bounding, and revocation of authority stop being configuration and become an architectural layer that sits above a behavior policy, not inside it.
Where This Sits Relative to Figure
The layer is complementary, not competitive with Helix. It sits above the behavior policy: the multi-authority instruction surface feeds credentialed, bounded intent into the layer, the layer produces a composite admissibility decision, and Helix continues to map an admitted instruction and onboard vision into behavior. A platform can adopt this kind of layer without rewriting its policy stack and without changing its manipulation approach; the layer governs which credentialed instruction reaches the policy and bounds what the policy is permitted to cause, and the policy's end-to-end advantage is preserved.
The broader Western and Chinese humanoid cohort, including Tesla Optimus, Agility Digit, Apptronik Apollo, 1X Neo, Boston Dynamics Atlas, and Unitree's humanoids, is converging on a similar industrial-deployment thesis under similar oversight. The architectural point is category-wide and not specific to Figure: an end-to-end behavior policy, whoever builds it, does not by itself carry a credentialed authority model, multi-party composition, a revocation mechanism, or per-action lineage. A platform with a strong vertically integrated policy is well positioned to add that governance layer above the policy rather than trying to fold multi-authority composition into the policy itself.
Disclosure Scope
This article is a public technical disclosure of the operator-intent subject matter of U.S. Provisional Application No. 64/049,409. The disclosed approach is enabling and reasonably broad. Operator intent is disclosed as a first-class primitive of a governed spatial mesh, published, admitted, fused, and consumed as credentialed observations carrying an authority credential, temporal scope and time-to-live, spatial reference, payload, and lineage. Embodiments include, without limitation: at least three configurable fidelity tiers (full cognitive-state sharing, structured partial-fidelity intent extracted from an integrated data bus such as ROS/ROS2, DDS, or other enumerated buses, and behavior-inferred intent from mesh observation), multiple tier-classification mechanisms (self-declared, credential-based, observation-based, capability-based, manufacturer-attested, dynamic, and hybrid), tier-weighted composite admissibility gating actuation with permit, gate, defer, or reject outcomes and graduated-actuation modes, intent-bounded capability derating, governance-chain-preserving intent retraction and correction, and per-action intent lineage. The primitive is disclosed as domain-general across civilian, commercial, industrial, emergency-response, and defense settings and is not limited to humanoid robotics.
Figure, Figure 02, Helix, BMW, OpenAI, Microsoft, NVIDIA, Tesla, Optimus, Agility, Apptronik, 1X, Boston Dynamics, Unitree, and all other named products and companies are referenced solely as external market and technical context to situate the disclosed subject matter. Their descriptions reflect publicly reported facts about independently developed systems, are not claims of the present filing, and imply no affiliation, endorsement, or comparison of unpublished internal behavior. The scope of what is claimed is set by U.S. Provisional Application No. 64/049,409.