> ## Content Index
> Fetch the complete content index at: https://www.humanoidthreats.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Is Physical AI? Definition, How It Works and Security Risks
- URL: https://www.humanoidthreats.com/what-is-physical-ai/
- Published: 2026-10-04T08:58:50.000Z
- Updated: 2026-10-04T08:58:50.000Z
- Description: Physical AI is AI that senses the real world and acts on it through a machine. Here's how it works, and why it creates a new class of security risks.
- Author: Jonas Weber
- Tags: Glossary

**Physical AI is artificial intelligence that perceives the real world through sensors, reasons about it, and acts on it through a physical body**, such as a humanoid robot, a robot arm, a drone or a self-driving car. Where a chatbot produces text, physical AI produces motion.

*Last updated: October 4, 2026*

## Physical AI, defined

NVIDIA, which has done more than anyone to popularize the term, describes physical AI as technology that lets autonomous systems "perceive, understand, reason, and perform complex actions" in the physical world ([NVIDIA glossary](https://www.nvidia.com/en-us/glossary/generative-physical-ai/?ref=humanoidthreats.com)). In practice the label covers any system where an AI model's output ends up moving something real.

Humanoid robots are the most visible example, because they combine every part of the stack in one machine: cameras and microphones, an AI "brain", network connections and dozens of motors.

## How physical AI works

Most physical AI systems follow the same loop:

1. **Sense.** Cameras, lidar, microphones, force and touch sensors capture what's happening around the machine.
2. **Understand.** AI models turn raw sensor data into a picture of the world: objects, people, distances and physics. Newer systems use *world models* that learn how the physical world behaves.
3. **Decide.** A policy, increasingly a vision-language-action (VLA) model, chooses what to do next, often from a spoken or written instruction.
4. **Act.** Commands go to motors and actuators, and the loop repeats many times per second.

Much of the training happens in simulation. Robots practise millions of attempts in virtual environments, often on synthetic data, before they touch the real world ([NVIDIA](https://www.nvidia.com/en-us/glossary/generative-physical-ai/?ref=humanoidthreats.com)).

## Why physical AI matters for security

In traditional IT, a successful attack usually means stolen data or downtime. In physical AI, a compromised system can also **move, see and hear**, which changes the stakes:

| Layer        | What can go wrong                                                               |
| ------------ | ------------------------------------------------------------------------------- |
| Sensors      | Spoofed or blinded cameras and lidar; microphones used for eavesdropping        |
| AI model     | Prompt injection or adversarial inputs that change what the robot decides to do |
| Connectivity | Bluetooth, Wi-Fi and cloud links used as a way in                               |
| Updates      | Malicious or unsigned over-the-air (OTA) updates                                |
| Actuators    | Unsafe motion if safety limits can be switched off in software                  |

These risks are already showing up in real products. Researchers have shown root-level takeover of the Unitree G1 humanoid over Bluetooth ([our explainer](https://www.humanoidthreats.com/unitree-g1-vulnerabilities-cve-2026-76639-76640/)), and a security assessment of the same robot reported that it regularly sent sensor and telemetry data to remote servers without the user being told ([Mayoral-Vilches et al., arXiv](https://arxiv.org/abs/2509.14139?ref=humanoidthreats.com)). Governments are responding too: in 2026 the U.S. FCC added foreign-produced humanoid and quadruped robots to its Covered List ([our analysis](https://www.humanoidthreats.com/fcc-robot-ban-covered-list-humanoid-robots/)).

## Example

A warehouse humanoid gets the instruction "move the boxes from aisle 3 to the loading dock." Its cameras locate the boxes, its model plans a path around workers, and its motors lift and carry. That is physical AI. If an attacker can alter the instruction, the camera feed or the model's output, the same robot can be steered into doing something unsafe. That is why physical AI security is becoming its own discipline.

## Related terms

- **Embodied AI:** AI that learns and acts through a physical body; largely overlaps with physical AI.
- **Vision-language-action (VLA) model:** a model that turns camera input plus a language instruction into robot actions.
- **Functional safety:** engineering that keeps machines safe when components fail (for example IEC 61508 and ISO 10218).
- **OTA updates:** remote software updates, a major attack surface for connected robots.

## FAQ

**What is the difference between physical AI and generative AI?** Generative AI creates content such as text or images. Physical AI uses AI to perceive and act in the real world through a machine. Many physical AI systems now use generative models inside them.

**Is physical AI the same as robotics?** Not exactly. Robotics is the broader field of building machines. Physical AI refers specifically to robots and machines whose perception and decisions are driven by learned AI models.

**Why is physical AI a security risk?** Because a compromised system can affect the physical world: it can move, record video and audio, and interact with people. That raises the stakes from data loss to physical safety and privacy.

---

Get the weekly Humanoid Threats Brief → [Subscribe](#/portal/signup)