Robotics and AI are converging on the security problem

Robotics and artificial intelligence are best understood as two halves of one system. One supplies the body that moves through the world; the other supplies the brain that decides what to do next. Organizations are pushing that pairing well beyond the rigid, single-purpose machinery of earlier decades, building machines that sense their surroundings, adapt to changing conditions and operate as agents rather than tools. The gains show up first as productivity and operational efficiency, but a second benefit is emerging alongside them: the ability to keep pace with a physical security landscape that is changing faster than conventional defenses can adapt.

Physical security is no longer a matter of fences, guards and standalone cameras. Critical infrastructure — data centers, manufacturing plants and the systems that connect them — faces risks that blend the digital and the physical, and those risks grow more complex by the year. The adaptive, scalable character of physical AI and robotics, deployed with care, offers a way to close a widening gap.

More than $23 billion is chasing the intersection

The scale of the bet is substantial. In 2026 alone, more than $23 billion has been invested in organizations focused on improving how robotics and AI work together, according to Charlie Burgess, a columnist writing for The Robot Report. A meaningful share of that money is directed at protecting people and property rather than at factory throughput alone — a signal that security has moved from a niche application to a central use case.

That capital matters because the threat environment has become harder to model. Understanding where physical AI fits requires first understanding what organizations are actually defending against.

Three categories of physical security risk

Nearly all of the leading risks and threats in 2026 fall into three broad categories: cyber-physical convergence, legacy constraints and global volatility. Each creates a distinct opening for attackers, and each limits what traditional security operations can accomplish on their own.

Cyber-physical convergence

Modern security systems are networks. Cameras, access control readers and environmental sensors are interlinked and report into shared platforms, which makes them easier to manage and far more fragile than the individual devices suggest. A malicious actor who compromises a central platform does not need to defeat every lock and lens in a facility; they need only reach the point where those devices are coordinated. From there, assets become vulnerable to theft, damage and outright disruption, and defenders can lose visibility at exactly the moment they need it most.

Legacy constraints

Much of the installed base of security equipment was never designed for the current threat model. Organizations running older hardware and software are largely limited to reacting to events after they occur, rather than intervening beforehand. In an environment where digital and physical attack paths are converging, a reactive posture is structurally insufficient — it all but guarantees that defenders stay one step behind.

Global volatility

Rising geopolitical and socioeconomic tensions compound both problems. The more contested the international environment becomes, the more attractive high-value facilities look as targets, and the more the security environment shifts in ways that static defenses cannot anticipate.

The Jaguar Land Rover breach as a case study

The clearest illustration of how these categories overlap comes from the disruption of Jaguar Land Rover. Attackers — allegedly state-sponsored — used stolen credentials and social engineering to gain access to the automaker's IT infrastructure. The intrusion did not stay digital. It halted physical production entirely, and the cost to the British economy has been estimated at $2.5 billion.

The episode demonstrates the mechanics of cyber-physical convergence at scale. An IT compromise became an industrial stoppage, and legacy systems and geopolitical volatility shaped both how the breach happened and how much damage it caused. For security leaders at data centers, plants and similar facilities, the lesson is that the boundary between an information security incident and a physical security incident is largely administrative rather than technical.

Where robotics and physical AI change the equation

Robotics and physical AI cannot eliminate these risks, but their adaptive and scalable nature maps onto the gaps that legacy approaches leave open. Areas where the technology is most relevant include:

  • Continuous presence: mobile platforms can maintain coverage across large or distributed sites where fixed cameras have blind spots and human patrols are constrained by shift length and headcount.
  • Adaptive sensing: AI-driven perception allows systems to separate routine activity from anomalies and to adjust as conditions change, rather than firing on fixed thresholds.
  • Scalable deployment: because much of the intelligence resides in software, additional capability can be extended across a facility or a portfolio of sites without a one-for-one increase in staffing.
  • Faster awareness: trained systems can surface events as they develop and route information to human operators, supporting prevention rather than after-the-fact investigation.
  • Human oversight: the most defensible deployments keep people in the decision loop, using automation to extend attention and judgment rather than replace them.

Responsibility is the deciding variable

The same connectivity that makes physical AI powerful also makes it a potential attack surface, which is why responsible implementation is not a secondary concern. Deployments that expand an organization's sensing and response capacity while adding new networked endpoints have to be designed with the same rigor as any other security-critical system. The technology's potential is real, but it is contingent: adaptation and scale only help if they are directed deliberately.

What makes this moment different is that robotics and AI are now capable of evolving alongside the threats they are meant to address. Static defenses lose ground by definition. Systems that can be updated, retrained and redeployed have a fighting chance of keeping up — provided organizations treat that capability as an ongoing commitment rather than a one-time purchase.

The road ahead for physical security

The direction of travel is clear. The convergence of cyber and physical threats, the drag of legacy infrastructure and the volatility of the wider world are not temporary conditions, and each one increases the value of systems that can perceive, decide and act. Robotics and physical AI will not solve physical security on their own, but applied responsibly, they give organizations a way to meet a moving threat with defenses that move too.

This article is based on reporting by The Robot Report. Read the original article.

Originally published on therobotreport.com