Why cybersecurity and physical autonomous AI must be governed together

An engineer inspects the work of autonomous AI robots in a factory. Image: Getty Images/iStockphoto/simonkr
Vanessa Evers
Director-General, Centrum Wiskunde & Informatica (CWI) Amsterdam; National Institute of Mathematics and Computer Science- A new generation of autonomous AI systems, including drones, self-driving vehicles and humanoid robots, can perceive the world, make decisions and act on them.
- This is dissolving the traditional boundaries between software risk and physical risk, and between cybersecurity and safety.
- The fields of cybersecurity and physical autonomous AI are converging, so it’s important to build the right governance foundations for this technology.
For most of its history, artificial intelligence (AI) has lived inside screens. It has recommended, predicted, translated and generated. Its mistakes have been costly, sometimes serious, but they have remained largely in the digital domain.
This is now changing.
A new generation of systems are bringing AI into the physical world. In addition to processing information, they also perceive, make decisions and act within the world.
Humanoid robots, autonomous vehicles and drones are three such cases currently moving from pilots to deployment. As they do, boundaries that once seemed clear – between software risk and physical risk, and between cybersecurity and safety – are dissolving.
For physical autonomous AI, the decisive shift is the merging of perception, decision-making and actuation – the latter being when a digital decision or signal from an AI model is turned into a physical or digital action. This makes autonomy socially valuable. But it also means that errors, attacks or poorly specified objectives can spread into the physical world before a human has time to notice, understand and intervene.
So, as the fields of cybersecurity and physical autonomous AI converge, it’s time to build the right foundations for governing this new generation of systems.
Embodied AI: Using humanoid robots
Humanoid robots are no longer science fiction. Systems capable of performing physical tasks in unstructured environments — picking, assembling, lifting, navigating — are entering logistics warehouses or working on factory floors and, in early pilots, care settings.
At the BMW Group Plant Spartanburg, Figure 02 humanoid robots have been tested in a real production environment with physically demanding activities involving sheet-metal parts. When embodied AI moves from demonstration to operational experimentation in this way, value depends not only on intelligence, but on whether autonomous systems can act safely, reliably and accountably in physical work environments.
As humanoids become capable, they also become consequential, however. A robot that can lift a patient or operate machinery introduces new categories of safety risk that go beyond software bugs or vulnerabilities.
Before humanoids scale beyond controlled environments, governments and companies need clearer frameworks for testing, certification and accountability.
Autonomous vehicles: Real deployment, new dependencies
Autonomous road transport is the most commercially advanced of this new generation of AI systems. Robotaxi services are already operational in several cities, while autonomous trucking is being tested on some highways. The potential near-term value includes improved safety records on specific route types, reduced costs in long-haul freight and extended operating hours.
Waymo is one of the clearest examples of the transition from trial to service in this area. Its driverless ride-hailing operations have expanded from early deployments with Uber in Phoenix and San Francisco to multiple US markets.
But deployment at scale creates dependencies that did not exist before. Autonomous vehicles rely on continuous connectivity, high-definition mapping, remote monitoring infrastructure and over-the-air software updates – each of which is a potential point of failure or interference. The coordination risks of mixed traffic environments, where autonomous and human-driven vehicles share roads, also remain poorly understood.
Resilient, secure AI infrastructure is crucial to address such conditions.
Drones: Rapid expansion, governance lag
Uncrewed aerial systems, or drones, are already operating at scale across delivery, agriculture, inspection and emergency services. In conflict zones and border regions, military and commercial drones have demonstrated that airspace — once a tightly regulated environment — is now accessible to a far wider range of actors, including non-state ones.
There are also positive civilian cases. In Rwanda, drone-based delivery of blood products has reduced delivery times versus estimated road transport and cut product expirations among health facilities.
The governance challenge here is acute. Airspace management frameworks were not designed for large numbers of autonomous agents operating simultaneously. And the same technologies that enable precision agriculture can enable surveillance or targeted disruption. Jamming, spoofing and hijacking of drone systems have moved from theoretical concerns to documented incidents.
Security and safety are no longer separate
These three use cases are advancing at different speeds and involve different industries, regulators and risk profiles. But they raise a common set of questions that neither the cybersecurity community nor the autonomous AI systems community can answer alone.
Once an AI system can act in the physical world, a cyberattack can translate directly into physical harm – a compromised vehicle, a manipulated drone, a robot operating outside its safety zone.
Security and safety must be built into design, standards, procurement and governance for autonomous AI systems.
What to ask before scaling autonomous AI
The first question for business leaders is whether the boundaries of autonomy are defined clearly enough. For autonomous physical systems, safety does not only mean that components work as designed, it also means knowing where the system is not designed to operate.
Second, where does human responsibility sit when the system becomes more autonomous? In physical AI, saying that a human remains “in the loop” is not enough. Leaders need to ask whether that human has the time, information, authority and skills to intervene when an autonomous system reaches its limits.
Third, what is the safety case under adversarial conditions? Safety assurance must be based on normal operations only, as well as covering how an autonomous AI system fails, recovers and reports when it is attacked, confused or deprived of connectivity.
Answering these questions should help leaders create practical governance guidelines for scaling autonomous AI.
What to do now
The value these technologies can deliver is real, and the competitive pressures driving deployment are not going away. Preparation must match the pace of deployment.
For governments, this means updating regulatory frameworks that were designed for a world where vehicles had drivers, airspace had limited autonomous occupants and physical systems were not network-connected.
For companies, it means treating cybersecurity as a core engineering requirement for any system that can act in the physical world, not as a compliance layer added at the end.
For international institutions, it means building the connective tissue between safety regulators, cybersecurity authorities and standards bodies that currently operate in parallel.
Autonomous AI systems have already entered the physical world. We must get the conditions right before these systems become deeply embedded in critical infrastructure and daily life.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
AI and Cybersecurity
Related topics:
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on Artificial IntelligenceSee all
Elizabeth Henderson, Daniel Raizman and Daniel Murphy
October 8, 2026





