Tau Cleaning Robot Runs on FCC-Banned Hardware and Records Your Home Forever

On July 28, 2026 — the same day the Federal Communications Commission barred new Chinese-made humanoid robots from US markets over documented security vulnerabilities — San Francisco startup Tau Robotics launched what it calls the country’s first consumer humanoid home cleaning service, priced at $30 per hour. The robot it sends into your home runs on a Unitree G1 body, the exact hardware platform the FCC cited in its ban announcement. That platform carries two publicly confirmed, unpatched security exploits. Under Tau’s own service terms, it also films everything the robot sees inside your home and holds a perpetual, worldwide, royalty-free license to that footage — a license that survives account closure and cannot be retracted once footage has been used for model training.
The service is invite-only for now, with a public waitlist at tau-robotics.com. But its launch timing — arriving the morning of the FCC’s most sweeping action yet against Chinese robotics hardware — puts Tau in an unusual position: a US company building a consumer product on a supply chain the US government just moved to shut down, and inviting customers to sign a footage agreement before the security picture is fully understood.
What the FCC Ban Actually Covers — and What It Leaves in Place
The FCC’s July 28, 2026 Covered List designation bars new models of Chinese humanoid and quadruped robots from receiving the equipment authorization required for importation, marketing, or sale in the United States. It does not retroactively revoke authorizations for robot models already cleared before that date. Tau’s existing Unitree G1 units, already in-country and already authorized, can continue to operate legally under US law.
That legal distinction matters. But it is not the same as a security clearance. The FCC’s rationale for the ban rested on two independently confirmed vulnerabilities that affect the G1 specifically and remain unpatched as of this article’s publication.
The first, CVE-2025-2894, was disclosed in March 2025 by security researchers Andreas Makris and Kevin Finisterre and formally catalogued under CWE-912 (Hidden Functionality) in the National Vulnerability Database. It centered on a service called CloudSail — embedded in the firmware of Unitree’s Go1 quadruped and operated by Chinese firm Zhexi Technology — that auto-started on boot and established a persistent peer-to-peer tunnel through which anyone with the correct API key could take complete remote control of the robot. Researchers identified approximately 2,000 vulnerable robots on the CloudSail network at the time of disclosure, including units inside networks at MIT, Princeton, Carnegie Mellon, and the University of Waterloo. Unitree invalidated the API key used in the original exploit; the underlying service endpoint remains in the Go1’s firmware.
The second, dubbed UniPwn by researchers, is the more direct concern for Tau’s customers. Disclosed in September 2025 by the same research team, UniPwn targets the Bluetooth Low Energy WiFi configuration interface shared across Unitree’s G1 and H1 humanoids. It yields root-level access — full control over the robot’s operating system — and it is wormable: a compromised robot can scan for other Unitree units within Bluetooth range and compromise them automatically, without any user action. IEEE Spectrum characterized UniPwn as the first major public exploit of a commercial humanoid platform. Unitree acknowledged the vulnerabilities in September 2025 and stated it had begun addressing them. No confirmed firmware patch has been publicly released.
Separately, independent security researchers at Alias Robotics, publishing in September 2025, documented that the Unitree G1 transmitted audio, video, GPS location, and sensor data to servers hosted in China at regular intervals during normal operation, without user notification or opt-out mechanism. Unitree stated it does not collect private or sensitive data without user authorization. That claim is in direct conflict with the Alias Robotics findings.
What Tau’s $30 Service Actually Costs You
Tau’s price is real and its disclosure is more transparent than most. The service privacy policy, published on July 27, 2026, opens with language that is notably candid: “We record what those cameras see. We use that footage to run the cleaning and to train the AI models that we hope will eventually do the job without a human operator. This is not optional. It is how the service works, and it is why the service is priced the way it is.”
Cameras mounted on the robot’s head and wrists record the full visit. The footage — including unblurred faces of anyone present — along with depth and spatial data, telemetry, and every operator command, becomes training data for Tau’s vision-language-action models. There is no separate sanitized version. “The footage from your home, as recorded and including unblurred faces, is what our models learn from,” the policy states.
The retention policy is indefinite. Tau retains footage for “as long as we operate,” absent a customer deletion request. Customers can request deletion at any time, and Tau says it will honor that. But the policy adds an important caveat: “if footage from your home was already used to train a model, that training has already influenced the model’s parameters. Those parameters are not a database and individual visits cannot be extracted from them or subtracted out.” Deletion ends future use; it does not reverse past influence on model weights.
The service terms add a further structural commitment: “The license in §10 is perpetual and is not affected by your account closing or by your ending the service.” A customer who uses Tau once has granted a permanent, royalty-free right to footage of their home’s interior, regardless of whether they ever book again.
Tau provides several genuine protections. Microphones on the robot are disabled — audio travels only from operator to customer, never the reverse. Bedrooms and bathrooms are excluded from standard visits unless customers opt in. Operators are W-2 employees, background-checked, working on-site from Tau’s San Francisco facility — not remote workers or gig contractors. The data labeling vendor has view-only access and cannot download footage. Footage is stored on Google Cloud, encrypted in transit and at rest.
The customer must also remain present for the full visit. No key handoffs, no lock boxes. Someone must be home while the robot works.
How the Robot Actually Works
The model Tau has built is deliberately hybrid, and CEO Alex Koch was candid about why in his ABC7 News interview on July 30, 2026. “Current artificial intelligence technology cannot fully control a humanoid robot on its own” in an unstructured home environment, Koch said. So Tau pairs the robot with a human operator — a supervisory control architecture in which an AI policy governs the robot’s motors at all times while a human provides high-level task direction via live video feed from a centralized San Francisco facility.
The robot body is a Unitree G1: approximately 4.3 feet (1.3 m) tall, approximately 77 pounds (35 kg), with 23 to 43 degrees of freedom across its permanent-magnet synchronous motor joints. Tau builds its own camera systems, grippers, and onboard computing on top of that base platform. Three named robot configurations handle different tasks: Chelsea for kitchens and bathrooms using non-toxic products, Elon to learn item locations across repeat visits, and Tony for deeper cleans including baseboards and grout.
Tasks currently working reliably, by Koch’s own account: vacuuming hardwood floors and rugs, wiping kitchen counters, taking out trash, and picking up clutter. He described these as “pretty doable.” More complex manipulation — picking objects off the floor, cleaning under furniture, handling fragile items — remains difficult.
Ken Goldberg, a UC Berkeley engineering professor with four decades of experience in robotics, was more direct in his assessment: “I really think it is too early. I would be very surprised if these could do anything close to a useful job of cleaning a house. So, being able to pick up objects off the floor is even still a challenge for robots today. And being able to sweep and wipe out areas of counters and underneath things, that is very, very difficult.”
Goldberg also questioned the credibility of demonstration footage from Tau and similar companies. “You don’t know if it’s been speeded up, you don’t know if there’s a human behind-the-scenes, you don’t know if they’ve kind of very carefully constructed the environment just right,” he said. Tau has responded to this concern directly, publishing all its operational footage at 1× speed — a deliberate credibility signal in an industry known for flattering demo clips.
The Economic Math Behind the $30 Price Point
At $30 per hour, Tau sits well below the $150 to $300 range that human professional cleaners typically charge in San Francisco — and also well below Gatsby, the competing SF humanoid cleaning service that launched its first autonomous US consumer clean in May 2026 at a flat rate of $150 per visit. Internationally, Chinese startup X Square Robot has been reported running humanoid robots in residential homes alongside human cleaners at roughly $7 per visit.
The math at Tau’s current scale almost certainly does not pencil out per visit. One operator, one robot, one visit: operator labor, amortized hardware cost on a Unitree G1 base unit priced at approximately $13,500, plus Tau’s own camera and computing additions, vehicle transport, insurance. The cleaning revenue is not the product.
The training data is. Every teleoperated hour generates footage, telemetry, and operator commands that feed the vision-language-action model Tau is building toward eventual autonomous operation — the same teleoperation-as-data-collection model used by Physical Intelligence, Figure AI, and other physical AI labs. Koch acknowledged this directly: the long-term goal is a robot capable of cleaning an entire home autonomously. Consumer cleaning is, as one analysis put it, “socially acceptable data collection with a revenue line.”
The business challenge: this strategy works only until autonomy arrives, at which point the operator cost disappears and the unit economics flip. Until that happens, Tau’s cost structure is tied to headcount, not compute. The FCC ban compounds the supply problem: if Unitree cannot import new G1 models for existing US customers, Tau cannot scale its hardware fleet without switching to a different — almost certainly more expensive — platform.
What Readers Need to Know Before Signing Up
Tau’s transparency is genuine and its disclosures are, by consumer tech standards, unusually forthright. The company is not hiding the recording or the perpetual license — it states both plainly in documents accessible from its website. Customers who book knowing what they are signing are making an informed trade.
The security picture is less within Tau’s control. Tau is a US company; its operators are US-based; its footage goes to Google Cloud, not Chinese servers. But the G1 hardware Tau’s service depends on was manufactured by a company that China’s National Intelligence Law, Article 7, legally requires to “support, assist, and cooperate with national intelligence efforts” when formally demanded by Chinese authorities. That obligation applies regardless of where the data is stored or what Unitree’s stated privacy policy says. The Alias Robotics arXiv findings documented that the G1 transmitted sensor data to Chinese-hosted servers without user notification during normal operation — behavior that would occur below Tau’s infrastructure visibility if a similar undisclosed channel exists in the G1 units Tau has deployed.
Unitree G1 units in service at Tau are the same platform carrying the unpatched UniPwn wormable Bluetooth exploit. A Tau operator visiting a customer’s home brings a robot that can be compromised via Bluetooth Low Energy within approximately 10 meters (33 feet) — potentially from a neighboring apartment, a hallway, or a parked vehicle outside — and that, once compromised, can propagate to other Unitree devices in range. Tau cannot patch the G1’s firmware unilaterally; only Unitree can issue and distribute a firmware update, and no patch has been confirmed released.
For customers who book regardless: the Tau privacy policy gives meaningful controls. Request deletion immediately after each visit (email bookings@tau-robotics.com). Mark any room, closet, or object off-limits in advance — the operator is instructed not to bring the robot there. Opt in to bedroom and bathroom access only if comfortable with live operator viewing and indefinite footage retention of those spaces. Understand that deletion of raw footage cannot retract influence on model weights already trained before the deletion request.
How Tau Fits the Broader Consumer Humanoid Cleaning Market
Tau’s launch is the second confirmed entry in what is shaping up as a narrow but real market. Gatsby, the earlier SF competitor, went further on autonomy — its May 2026 first consumer clean involved no human inside the apartment — but charges five times as much. X Square Robot’s model in China relies on human escorts alongside the robots. Tau’s hybrid sits between: human always present remotely, robot doing the physical work, AI managing motor control.
The market is also, for now, a Unitree-dependent ecosystem. Both Tau and Gatsby are reported to use the Unitree G1 as their primary hardware platform. With new Unitree model imports now blocked by the FCC, both services face the same supply constraint: they can continue with hardware already in-country, but cannot expand their robot fleets with new Chinese-made humanoid models. The most likely alternatives — US-made humanoids from Agility Robotics or Boston Dynamics — start above $90,000 per unit, roughly six times the Unitree G1’s base price of $13,500.
For any consumer evaluating Tau’s waitlist, those supply-chain stakes are worth understanding: a service whose hardware is now import-restricted is a service whose scale-up path depends on either a regulatory change or a hardware pivot that substantially changes its unit economics.
Frequently Asked Questions
Does booking Tau’s cleaning service mean the company keeps video of my home permanently?
Unless you request deletion, yes. Tau’s service privacy policy states it retains footage “for as long as we operate” and is explicit that this is not a bureaucratic default but a deliberate business decision: the footage is the training data for the AI models Tau is building, and keeping it enables future model retraining as architectures evolve. You can request deletion at any time by emailing bookings@tau-robotics.com, and Tau says it will delete raw footage from its systems and remove it from training sets. The service terms confirm operators are W-2 employees working from Tau’s SF facility, microphones are disabled, and bedrooms and bathrooms are excluded unless you opt in.
What are the specific security vulnerabilities in the Unitree G1, and has Unitree fixed them?
Two publicly confirmed exploits affect the Unitree G1. UniPwn, disclosed in September 2025 by researchers Andreas Makris and Kevin Finisterre, is a wormable Bluetooth Low Energy vulnerability that grants root-level access to G1 and H1 humanoids and can propagate automatically to other nearby Unitree units. Separately, independent security researchers at Alias Robotics documented that the G1 transmitted sensor data — including audio, video, and GPS — to Chinese-hosted servers at regular intervals during normal operation without user notification. Unitree acknowledged the UniPwn vulnerabilities in September 2025 and said it had begun addressing them. No confirmed firmware patch has been publicly released. Tau cannot issue a unilateral patch for Unitree’s firmware; it depends on Unitree to close the vulnerability.
Can I delete my footage and fully undo my privacy exposure after a Tau visit?
Partially. Requesting deletion removes raw footage from Tau’s systems and from future training sets. What it cannot do is reverse the influence of footage that was already used to train a model before you made the deletion request. Tau’s own policy states this directly: “if footage from your home was already used to train a model, that training has already influenced the model’s parameters. Those parameters are not a database and individual visits cannot be extracted from them or subtracted out.” This reflects a documented gap in California’s Consumer Privacy Rights Act deletion right as applied to AI training data — the law grants a deletion right, but neural network model weights do not contain training data in a form that can be extracted or removed after training has occurred.
Does the FCC ban mean Tau has to stop its service or use different robots?
No — at least not immediately. The FCC’s Covered List designation bars new models of Chinese humanoid and quadruped robots from receiving equipment authorization for importation, marketing, or sale in the United States. It does not retroactively ban robot models already authorized before the July 28, 2026 action. Tau’s existing Unitree G1 units are legally authorized and can continue operating. The supply constraint is a scaling problem, not a legal shutdown: Tau cannot expand its fleet with new Unitree humanoid imports, and US-made alternatives cost roughly six times as much. The FCC ban means Tau’s current hardware is finite, not that its current service is prohibited.