Trust and Safety Outlook 2026

Redefining governance in the age of physical AI

  • Report
  • July 17, 2026

Key takeaways:

  • Physical AI moves AI risk from the screen into shared physical environments. 
  • Organizations need to manage physical harm, shared human-machine accountability, and heightened data privacy and cybersecurity exposure.
  • Governance should address design, testing, fail-safes, handoffs, logs, and life cycle support.
  • Getting governance right is central to public confidence and sustainable market growth.

Physical AI refers to systems that combine GenAI with sensors and motors to perceive the physical world, apply reason to what they see, and take action. Think home robots and self-driving cars. Autonomous drones navigating overhead. Smart glasses that guide the wearer. Warehouse systems that pick, pack, and lift alongside human workers.

The physical AI industry is estimated to reach over half a trillion dollars by 2030, and recent funding rounds suggest the market is already operating at scale—Waymo raised $16 billion at a $126 billion valuation1, Shield AI raised $2 billion2, and Wayve raised $1.2 billion3 all in early 2026.

Existing governance frameworks weren’t built for this speed of enhancement or scale. A digital AI system, like a chatbot, that gets something wrong might produce a flawed answer—a harm that’s largely contained to a screen and can usually be corrected. A physical AI system that gets something wrong could run a red light, drop a heavy package on someone’s foot, or record a conversation it wasn’t meant to hear. These actions can’t be easily undone.

As physical AI scales, organizations should look to manage three critical risks:

  • Physical harm
  • Shared human-machine accountability
  • Heightened data privacy and cybersecurity exposure

These risks need immediate attention—before the technology outpaces the rules designed to govern it.  

Potential for physical harm

A self-driving car, surgical robot, or factory machine that malfunctions can instantly cause injury, property damage, or even loss of life. There’s little time for a human to step in, catch the error, and undo the damage.

For example, a major autonomous vehicle company was ordered to immediately remove all of its driverless cars from public roads after an incident in which one of the company’s vehicles struck a pedestrian.

The faster, stronger, and more independent these systems become, the greater the potential consequences when something goes wrong. This shifts AI risk from something abstract to something tangible—and urgent.

Governance priorities

Reducing the risk of immediate physical harm requires safeguards at both the design stage and after deployment.

For manufacturers and developers

  • Bound the operating environment: Define the specific environments and conditions— like terrain, weather, and proximity limits—in which a physical AI system is approved to operate.
  • Conduct real-world testing: Simulation alone can’t surface edge cases that appear in uncontrolled environments. Require staged physical testing before any public deployment.
  • Build in fail-safes: Require built-in safety features such as emergency stop functions and safe mode defaults when the system encounters something it doesn’t understand.

For regulators

  • Tier oversight by risk: Match the level of oversight to the level of risk so that, for example, a small delivery robot is not regulated the same way as a large autonomous vehicle.
  • Create safety certifications: Adapt premarket certification models from aviation, automotive, and medical devices to physical AI—accounting for software-driven behavior changes post-certification.
  • Require post-market monitoring: Mandate incident reporting timelines, define recall thresholds, and require manufacturers to publish safety performance data at regular intervals.  

Accountability challenges when humans and machines interact

Physical AI rarely operates alone. It works alongside drivers, doctors, factory workers, consumers, and others, often sharing control of a task. When something goes wrong, it can be challenging to determine who’s responsible. Was it the company that built the system, the software provider, the business that deployed it, the human working alongside the device, or some combination of them all? This question becomes especially complicated during handoffs, when control passes between the AI and a human. 

After a major medical device manufacturer added an AI-powered navigation feature to a surgical tool, the FDA received reports of over a hundred malfunctions and adverse events involving patients.4 The manufacturer, the original developer, and a subsequent corporate acquirer could each point to different parties as responsible—illustrating how physical AI fragments accountability across the value chain.

Governance priorities

Closing the accountability gap requires clearer rules, more detailed evidence, and updated liability models that reflect how humans and machines share control.

For manufacturers and deployers

  • Maintain tamper-proof logs: Require detailed, tamper-proof records of what the AI system did, what the human did, and when control passed between them.
  • Design safer handoffs: Set design standards for how machines and humans hand off control, including reasonable time for a person to respond and clear guidelines about who’s in charge.
  • Define meaningful oversight: Define what meaningful human oversight actually looks like, so people aren’t unfairly blamed for failures they had no realistic way to prevent.
  • Certify operators: Require formal operator training and certification, with rigor scaled to the system’s level of autonomy and potential for harm.

For regulators

  • Clarify the liability chain: Establish clear guidelines for who’s responsible when something goes wrong—manufacturers, software developers, businesses deploying the technology, or end users.
  • Modernize liability models: Consider new insurance and liability models for high-risk applications where it’s hard to pinpoint a single cause of harm.  

Greater risks to data privacy and cybersecurity

Physical AI systems are connected computers—and that makes them a target. If hackers break into a digital AI system, the result might be stolen data or manipulated information. If they hack a physical AI system, the result could be a hijacked vehicle, a compromised drone, undetected surveillance, or a fleet of robots turned into weapons. Attackers can also trick these systems by manipulating what their sensors see or hear—which can also result in physical harm. On top of that, physical AI constantly collects detailed information about its surroundings—images of people, layouts of private spaces, and patterns of daily life—creating privacy concerns that go beyond what many digital AI systems gather.

In 2024, cybersecurity researchers disclosed a vulnerability in a popular line of internet-connected robot vacuums that allowed attackers to remotely seize control of the devices from more than 100 meters away, accessing their cameras and microphones and commandeering their movements. Affected households reported robots shouting insults, chasing pets, and being maneuvered around private living spaces by unknown operators. The manufacturer initially downplayed the flaw as “extremely rare” before pledging a firmware update later that year.5

Governance priorities

Protecting physical AI from cyber and privacy threats requires action across the product life cycle—from initial design through end-of-life support.

  • Embed security at design: Treat every software update as a potential change to physical behavior. Change control is a safety function, not an administrative one.
  • Test against physical attacks: Test systems against attempts to fool their sensors, jam their signals, or otherwise manipulate them physically.
  • Commit to life cycle support: Require security updates and support for the full life of the product, and for companies to be transparent about when that support will end.
  • Minimize data collection: Limit the data these systems collect to what is truly necessary, with extra protections for sensitive information like images of people or location details.

For regulators

  • Standardize breach reporting: Establish clear processes for reporting vulnerabilities and notifying customers and regulators when a breach occurs.
  • Develop sector-specific standards: Develop industry-specific cybersecurity standards for areas like autonomous vehicles, healthcare robotics, and industrial systems.  

Governing a trillion-dollar market

Embedding AI in physical products fundamentally changes the risk profile, expanding risk beyond technical performance and into the full range of human experience. Addressing this shift requires proactive design paired with collaborative governance that can adapt as the technology evolves. This is what it will take to manage the risks responsibly, build trust, and realize the significant benefits physical AI can offer.

A market on pace to grow from billions to trillions of dollars within the next decade will touch virtually every sector of the economy. Getting governance right is a prerequisite for sustainable industry growth and public confidence in these technologies.  


1. “Big money is betting the self-driving future belongs to a small club.” Business Insider. May 4, 2026. (Accessed via Factiva, June 1, 2026).

2. “Defense technology startup Shield AI valued at $12.7 billion in latest funding round.” Reuters News. March 26, 2026. (Accessed via Factiva, June 1, 2026).

3. “Wayve rockets to €7.2 billion valuation with €1 billion Series D bet on AI-driven autonomy – backing from Uber and Microsoft.” EU Startups. February 25, 2026. (Accessed via Factiva, June 1, 2026).

4. “As AI enters the operating room, reports arise of botched surgeries and misidentified body parts.” Tuoi Tre Newspaper. February 10, 2026. (Accessed via Factiva, June 1, 2026).

5. “Robot vacuum cleaners hacked to spy on and insult humans in the home.” CE Noticias Financieras English. October 30, 2024. (Accessed via Factiva, June 1, 2026).  

Trust and Safety Outlook 2026

FAQs

Physical AI refers to systems that combine AI with sensors, motors, and physical action, such as robots, autonomous vehicles, drones, smart glasses, and warehouse systems.

Physical AI can create consequences that are immediate and difficult to undo, including physical harm, privacy exposure, cyber compromise, and unclear accountability between humans and machines.

Contact us

Daniel Hays

Principal, Consulting Solutions, PwC US

Kim David Greenwood

Principal, PwC US

Rahul Kapoor

Principal (Partner), PwC US

Follow us

Required fields are marked with an asterisk(*)

Your personal information will be handled in accordance with our Privacy Statement. You can update your communication preferences at any time by clicking the unsubscribe link in a PwC email or by submitting a request as outlined in our Privacy Statement.

Hide