1. Learn
  2. Align
  3. Perform
  4. Review

Learn7 min read

Physical AI Is the Next Platform Shift, and Physical Security Should Pay Attention

By J Damien Scott, Trusted Advisor

NVIDIA CEO Jensen Huang's bet on physical AI points to a genuine shift in what artificial intelligence is for: not generating text, but acting in the physical world. For security professionals, this means video analytics that detects threats in real time, autonomous patrol robots covering ground that human officers cannot, and a new category of technical and organizational risk that demands informed vendor scrutiny.

What Physical AI Actually Means

Generative AI, the technology behind tools like ChatGPT, works entirely inside a digital space. It reads text or images and produces text or images in return. It never has to account for gravity, friction, or the fact that a human being might be standing in its path.

Physical AI is different. NVIDIA defines it as AI that perceives, reasons about, and acts within the physical world. A physical AI system has to understand cause and effect the way a person does without thinking about it: how much force is needed to grip a glass without breaking it, where a rolling ball will stop, or the likelihood that a pedestrian is standing just out of view behind a parked car. Jensen Huang has described this as the 'ChatGPT moment' for embodied systems, the point at which machines move from generating answers to taking physical action.

Organizations evaluating these systems should ask vendors directly about adversarial testing, data retention practices, and where liability sits when the system is wrong — before, not after, the system is deployed.

The Technology Stack Behind the Shift

Building a system that can act safely in the real world requires more than a large language model. NVIDIA's own architecture rests on three layers: training, handled by data-center supercomputers that build the underlying models; simulation, where platforms such as NVIDIA Omniverse generate photorealistic, physically accurate synthetic environments where a robot can fail ten thousand times in simulation before it ever fails once in a warehouse; and edge inference, where compact hardware runs the trained model on board the robot itself.

This is why simulation has become central to the field. Robotics companies cannot generate enough real-world data to train a robot the way a large language model is trained on internet text, so they generate synthetic data instead, then transfer what the model learns into physical hardware.

Where the Money and the Machines Are Going

The scale of investment gives a sense of how seriously the industry takes this shift. The humanoid robotics segment alone was estimated at roughly $2.9 billion globally in 2025, with company counts roughly doubling since 2023 as venture capital moved into the sector. Figure AI reached a private valuation near $39 billion in late 2025, and its Figure 02 robots are now performing real tasks inside BMW manufacturing plants and Amazon warehouses. Counterpoint Research estimates that more than 50,000 humanoid robots will operate commercially in 2026.

Broader market research firms place the total physical AI market anywhere from roughly $81 billion in 2025 to more than $430 billion by 2030, depending on methodology. The wide spread across these estimates is itself informative: analysts agree on the direction of growth but disagree substantially on its pace.

The Application That Matters Most for Security Professionals

Physical security is one of the clearest early proving grounds for this technology, because the core job of security work — sensing an environment and deciding whether something requires a response — maps directly onto what physical AI systems are built to do.

Video analytics is the most mature application. Industry reporting describes a shift from passive recording toward proactive detection, where on-site processors run deep learning models capable of distinguishing well over a hundred object types, flagging weapons, unauthorized access, or PPE non-compliance as events unfold rather than after the fact. Analysts project the AI video analytics market specifically will reach roughly $6.2 billion in 2026, growing at more than 22 percent annually.

Autonomous patrol robots represent the physical extension of that same logic. Wheeled units and drones are now used to cover ground in warehouses, large campuses, parking structures, and critical infrastructure sites that would otherwise require multiple human officers walking a fixed route.

The Limits Worth Naming Honestly

None of this should be adopted uncritically, and the research literature is candid about why. Adversarial manipulation is a documented risk: researchers have described how GPS spoofing can redirect an autonomous system, how projected laser patterns can trick LiDAR sensors into registering obstacles that are not there, and how subtly altered visual patterns can cause a vision model to misclassify what it sees.

Privacy is a second, related concern. Security robots and cameras generate rich data about the people they observe, and that data becomes a target in its own right if not properly secured. Liability is a third open question. When an autonomous system makes a judgment call that causes harm or misses a genuine threat, responsibility has to be traced through the hardware manufacturer, the software vendor, the integrator, and the operating organization, and current legal frameworks do not yet offer a clean answer.

The Practical Takeaway

Physical AI is not a rebranding of existing camera systems or a marketing term attached to older robotics. It represents a genuine expansion of what AI systems can do, moving from generating information to acting on it in physical space. For physical security specifically, the technology offers real, documented value in continuous monitoring and rapid detection. It also introduces a new category of technical and organizational risk that security leaders will need to understand well enough to question their vendors, not just their guards.

Organizations evaluating these systems should ask vendors directly about adversarial testing, data retention practices, and where liability sits when the system is wrong — before, not after, the system is deployed.

AI & TechnologyPhysical AISecurity TechnologyRoboticsRisk Management

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles