Artificial intelligence is increasingly being used to interact with physical machines, creating new opportunities for automation but also raising questions about whether those machines can be trusted.
AI agents are moving beyond tasks such as generating text and analysing data. They can increasingly interact with physical equipment, including robotic arms, microscopes, liquid handlers and laser systems.
Standardised systems could make this easier by allowing AI agents to discover machines, understand their capabilities and send instructions without requiring a separate integration for every type of equipment.
However, connecting AI to physical machines creates an additional security problem. It is not enough to know that an AI agent is authorised to carry out an action. The system also needs to establish that the machine receiving the instruction is genuine and can be trusted.
A device could potentially be impersonated, replaced or compromised. If an AI agent cannot establish the identity and condition of the equipment it is controlling, there is a risk that an otherwise authorised instruction could be sent to the wrong machine. This becomes more significant when AI agents are allowed to operate with limited human intervention.
An incorrect action in a digital environment can result in lost data or financial costs. An incorrect command sent to physical equipment could have much more direct consequences, particularly where machinery operates in industrial, laboratory or other controlled environments. Machine identity therefore becomes an important part of AI security.
There is a difference between discovering a machine and establishing trust in that machine. An AI agent may be able to identify equipment and understand what it is capable of doing, but that does not necessarily confirm that the physical device is genuine or operating securely.
The information produced by the machine also needs to be considered.
An AI system may receive data from equipment, analyse that information and then decide what action to take. This creates a chain between the physical machine, the data it produces, the AI decision and the resulting action.
If the machine or the information it provides has been compromised, the AI could make a decision based on unreliable information. This means security needs to cover the entire process rather than focusing solely on the AI model.
Device authentication, machine identity and authorisation can help establish whether a particular piece of equipment is genuine and whether it should be allowed to carry out a specific action.
The level of security required is likely to depend on what the AI is controlling. A low-risk device may require relatively simple controls, while equipment capable of causing physical damage or affecting sensitive processes would require stronger safeguards.
Standardised communication between AI agents and machines could make physical AI easier to deploy. Instead of building individual systems for every machine, a common approach could allow AI agents to work with different types of equipment more easily.
But greater connectivity also means that trust needs to be built into the system from the beginning. The AI needs to be able to establish what a machine is, whether it is the correct machine and whether it is authorised to perform the requested operation.
Tern plc (LON:TERN) backs exciting, high growth IoT innovators in Europe. They provide support and create a genuinely collaborative environment for talented, well-motivated teams.




































