Sunday, October 4, 2026 Sign inSubscribe to The Brief →
Humanoid Threats

Security for the age of physical AI

Glossary

What Is Physical AI? Definition, How It Works and Security Risks

Physical AI is AI that senses the real world and acts on it through a machine. Here's how it works, and why it creates a new class of security risks.

Physical AI is artificial intelligence that perceives the real world through sensors, reasons about it, and acts on it through a physical body, such as a humanoid robot, a robot arm, a drone or a self-driving car. Where a chatbot produces text, physical AI produces motion.

Last updated: October 4, 2026

Physical AI, defined

NVIDIA, which has done more than anyone to popularize the term, describes physical AI as technology that lets autonomous systems "perceive, understand, reason, and perform complex actions" in the physical world (NVIDIA glossary). In practice the label covers any system where an AI model's output ends up moving something real.

Humanoid robots are the most visible example, because they combine every part of the stack in one machine: cameras and microphones, an AI "brain", network connections and dozens of motors.

How physical AI works

Most physical AI systems follow the same loop:

  1. Sense. Cameras, lidar, microphones, force and touch sensors capture what's happening around the machine.
  2. Understand. AI models turn raw sensor data into a picture of the world: objects, people, distances and physics. Newer systems use world models that learn how the physical world behaves.
  3. Decide. A policy, increasingly a vision-language-action (VLA) model, chooses what to do next, often from a spoken or written instruction.
  4. Act. Commands go to motors and actuators, and the loop repeats many times per second.

Much of the training happens in simulation. Robots practise millions of attempts in virtual environments, often on synthetic data, before they touch the real world (NVIDIA).

Why physical AI matters for security

In traditional IT, a successful attack usually means stolen data or downtime. In physical AI, a compromised system can also move, see and hear, which changes the stakes:

Layer What can go wrong
Sensors Spoofed or blinded cameras and lidar; microphones used for eavesdropping
AI model Prompt injection or adversarial inputs that change what the robot decides to do
Connectivity Bluetooth, Wi-Fi and cloud links used as a way in
Updates Malicious or unsigned over-the-air (OTA) updates
Actuators Unsafe motion if safety limits can be switched off in software

These risks are already showing up in real products. Researchers have shown root-level takeover of the Unitree G1 humanoid over Bluetooth (our explainer), and a security assessment of the same robot reported that it regularly sent sensor and telemetry data to remote servers without the user being told (Mayoral-Vilches et al., arXiv). Governments are responding too: in 2026 the U.S. FCC added foreign-produced humanoid and quadruped robots to its Covered List (our analysis).

Example

A warehouse humanoid gets the instruction "move the boxes from aisle 3 to the loading dock." Its cameras locate the boxes, its model plans a path around workers, and its motors lift and carry. That is physical AI. If an attacker can alter the instruction, the camera feed or the model's output, the same robot can be steered into doing something unsafe. That is why physical AI security is becoming its own discipline.

  • Embodied AI: AI that learns and acts through a physical body; largely overlaps with physical AI.
  • Vision-language-action (VLA) model: a model that turns camera input plus a language instruction into robot actions.
  • Functional safety: engineering that keeps machines safe when components fail (for example IEC 61508 and ISO 10218).
  • OTA updates: remote software updates, a major attack surface for connected robots.

FAQ

What is the difference between physical AI and generative AI? Generative AI creates content such as text or images. Physical AI uses AI to perceive and act in the real world through a machine. Many physical AI systems now use generative models inside them.

Is physical AI the same as robotics? Not exactly. Robotics is the broader field of building machines. Physical AI refers specifically to robots and machines whose perception and decisions are driven by learned AI models.

Why is physical AI a security risk? Because a compromised system can affect the physical world: it can move, record video and audio, and interact with people. That raises the stakes from data loss to physical safety and privacy.


Get the weekly Humanoid Threats Brief → Subscribe

Get The Humanoid Threats Brief One email a week. New vulnerabilities, incidents and defenses. Subscribe free
The Humanoid Threats Brief

The weekly briefing on humanoid robot security.

New vulnerabilities, incidents, standards and defenses, with why each one matters. Built for security teams, robotics engineers and the people buying humanoids.

  • Every claim sourced. We link the CVE, the paper or the regulator, not rumors.
  • 5-minute read. One email a week, every Thursday.
  • Free. No spam, unsubscribe in one click.

Check your inbox to confirm your subscription.

Something went wrong. Please try again.

Read a recent storyUnitree G1 Vulnerabilities Explained: CVE-2026-76639 and CVE-2026-76640 →
4 articles & explainers 100% primary-source linked 1 email a week