Artificial intelligence

Why Does Physical AI Need Trust from Silicon to Software?

A sponsored opinion article argues that securing artificial intelligence systems that interact with the physical world cannot be limited to protecting networks or testing models; it must cover data, sensors, hardware, software, and system behavior during operation. This approach is becoming increasingly important with agentic systems that make decisions and adapt in real time to changing environments.

2026-09-03
4 min read
10 views
فريق تحرير certi.news
Why Does Physical AI Need Trust from Silicon to Software?

Artificial intelligence is gradually moving from producing answers and content to operating systems that interact directly with the physical world, such as autonomous vehicles, industrial robots, drones, surgical systems, and smart infrastructure. In these applications, the impact of an error is not limited to an inaccurate result or poor recommendation; it could lead to overlooking an obstacle, operating a mechanism incorrectly, sudden braking, or exposing people and operations to real risks.

This is the central idea in an opinion article sponsored by Semiconductor Engineering on September 3, 2026, written by Dana Neustadter and Ilya Tolchinsky. Tolchinsky serves as Synopsys’s principal product manager for artificial intelligence, while Neustadter serves as the company’s senior director of product management for security solutions. By its nature, the article presents the authors’ perspective and editorial recommendations, not a product announcement or independent test results.

The Risk Begins Before the Model Runs

The authors emphasize that threats to physical AI do not begin at the inference stage, nor do they end at the software layer. The data used for training may be incomplete, biased, altered, or low quality, whether it is real-world or synthetic data. The system may learn incorrect patterns from the outset that do not appear clearly during testing, then become exposed when it encounters different operating conditions.

Sensors constitute another point of exposure because cameras, LiDAR, radar, microphones, and positioning systems are what build the system’s picture of the environment. If these inputs are blocked, corrupted, or manipulated, the picture on which the model relies to make decisions may change.

The problem is not limited to each individual component. A robotic platform, for example, may combine a perception component, a motion-planning component, and a control-execution component. Temporal delays, differing inputs, model drift, or the compromise of one component can lead to a loss of synchronization and the emergence of behavior that is difficult to predict.

From Roots of Trust to Behavior During Operation

The attack surface also extends to hardware, including silicon, embedded intellectual-property units, accelerators, and interconnects. The article notes that a weak hardware root of trust, an insecure firmware-update path, or the reuse of a vulnerable intellectual-property unit across multiple products could undermine the protection present in higher layers.

Agentic artificial intelligence systems add another layer of complexity because they navigate dynamic environments, make decisions, and change their behavior in real time. Therefore, the authors do not consider verifying the model once before deployment sufficient. Instead, they call for continuous assurance during operation to monitor whether outputs remain within safe operating limits as conditions change.

What Changes in Practice?

The article’s practical conclusion is that trust must be built at the level of the entire system, from silicon to software, rather than confined to the application layer. This requires examining the source of data, verifying model integrity, securing hardware and software supply chains, authenticating updates, and monitoring how the system behaves when inputs are uncertain or conflicting.

The importance of this argument lies in its connection between security and operational safety: protecting the network alone does not guarantee that sensors measure the environment reliably, and model accuracy alone does not guarantee that a decision will be executed within safe limits. However, the article does not provide a quantitative standard or a specific implementation mechanism for measuring these assurances, nor does it present experimental data comparing different approaches. Its call to build trust across the life cycle therefore remains a general framework that must be converted, for each application, into measurable tests and controls.

News source
Semiconductor Engineering
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news