PK h]oa«,mimetypeapplication/epub+zipPK h]mX[PûûMETA-INF/container.xml PK h]êîþ..EPUB/package.opf urn:tuhat:post:1821 Physical AI in 2026: who is liable when an AI agent moves a machine nigelone it 2026-08-27T06:30:24Z PK h]hh~%""EPUB/nav.xhtml Physical AI in 2026: who is liable when an AI agent moves a machine PK h]áʱ«33EPUB/post.xhtml Physical AI in 2026: who is liable when an AI agent moves a machine

Physical AI in 2026: who is liable when an AI agent moves a machine

Ten thousand bridges, a handful of motors

The bridges between AI and software have multiplied almost sevenfold in five months; the ones that reach a motor have not.

In March this piece counted about fourteen hundred company-run servers for the Model Context Protocol, the open standard that connects AI assistants to external tools.

Qualys was already counting more than ten thousand active public ones, and governance had passed to a Linux Foundation body, per a WorkOS overview of the same month.

Software integration is no longer a project. It is plumbing.

Point those pipes at anything that moves an object in real space and little changes.

A ChatForest review of robotics MCP servers in May 2026 found some fifty community projects, many on hobby hardware, and no official server from Universal Robots, Boston Dynamics, Fanuc, ABB or KUKA.

The rare public exceptions are academic. A January 2026 arXiv paper by Burke and colleagues demonstrated LLM-controlled UAV flight through the MAVLink protocol with MCP as the bridge, and it gets cited because it stands almost alone.

Physical AI, an agent whose command leaves the screen and moves a machine, is not a harder version of software AI: the intent stays human, the last metre of the decision becomes the machine's, and no one has yet agreed who answers for that metre.

What the money says physical AI is for

Capital has stopped waiting for the connection layer.

Robotics companies had raised 55.8 billion dollars in 2026 by early June, nearly double the previous record, according to Dealroom figures reported by CNBC on June 10, 2026.

Humanoid startups alone accounted for 8.7 billion through July, in the same data as cited by The AI Insider on August 21.

Deployment is shakier than funding. A Technology.org analysis of July 18, 2026 traced the most repeated figures, fifty thousand Optimus units among them, to no company source.

Tesla has never published a production count, and the strongest verified records, Figure's and Agility's, are far smaller than the headlines.

Unitree ships more humanoids than any Western rival at roughly a tenth of the price, the same report notes, and its first-quarter profit still halved.

So the machines exist and the money is real, while the layer that lets a language model command them is still built by hobbyists and a few firms working alone. I am one of them.

The interlock that refuses the last metre

The part of my system that matters most says no.

An operator types a sentence in Claude Desktop; the model picks tools from my MCP server, which turns them into authenticated calls to an IoT cloud platform that forwards them to the UAV's flight controller and to an automated hangar. Telemetry returns along that chain.

That server also talks to a MAVLink autopilot, a DJI platform through its cloud APIs and a BlueROV underwater vehicle; only the final adapter changes. Flight modes, gimbal control, waypoint missions and retry logic all sink beneath a conversational surface.

What stays out of its reach is what I refused to hand to inference.

The hangar roof will not open above three metres per second of wind, outside the operating temperature range or under precipitation, and no sentence can argue it open: the rule sits below the model, not inside it.

A debug mode redirects every call bound for a physical device to an inspection endpoint, so mission logic is tested without a vehicle moving. A wrong text can be corrected; a wrong command to hardware cannot.

Language gets the route. It does not get the last metre.

The first documented case of a machine choosing its target

The question I left open in March has since been settled once, in the worst possible place.

On July 6, 2026 a Russian Molniya drone struck a petrol station in Zaporizhzhia and three civilians died. The New York Times reconstructed the sequence in an investigation published on August 24, with Ukrainian air defence commanders and the forensic team that examined the wreckage.

Operators sent the aircraft towards the site; close to it, the onboard software chose the exact target by itself, most likely the propane tanks it had been trained to recognise.

It failed to clear an apartment building, hit a wall and detonated near people sheltering below.

The wreckage carried no antenna and an unencrypted Nvidia Jetson Orin, a consumer module costing a few hundred dollars; Ukrainian officials could read its terrain imagery and target-selection code.

Kateryna Bondar of the Center for Strategic and International Studies called it the first documented case of civilian deaths from a Russian drone with fully autonomous targeting, Tom's Hardware reported on August 25.

A warehouse robot and a weapon are not on the same moral plane. The shape of the event, though, is the shape of the question. The intent was human and coarse: go there. The final choice was the machine's. The outcome matched neither.

The hardware, in Nvidia's words to the Times, was consumer-grade, not sold in Russia and not designed for the purpose.

Liability arrives before the building rules

Europe has started to legislate, and the order is the interesting part.

Directive (EU) 2024/2853, the revised Product Liability Directive adopted on October 23, 2024, treats software and AI systems as products and applies strict liability to anything placed on the market after December 9, 2026, software essential to a robot's functioning included, as Timelex notes.

If the inferential layer of a device causes harm, nobody has to prove negligence any more.

The directive also names who can be held liable: the manufacturer of a product or of a component, software included, the importer, and whoever substantially modifies a product after it is sold.

The Digital Omnibus on AI, approved by the Council of the EU on June 29, 2026, defers the AI Act's high-risk obligations for AI embedded in machinery and similar regulated products to August 2, 2028, as Gibson Dunn and DLA Piper read the text.

Civil liability lands this December; the engineering duties, twenty months later. Anyone shipping physical AI in Europe will spend 2027 exposed on a decision layer that no requirement yet describes.

The lesson is to write down, now, which decisions the model may take and which ones a rule takes for it, and to put a name next to the list.

Where the metre gets decided

What the frontier still lacks is a signature on the last metre.

Before you connect a physical AI agent to anything that moves, find the person in your organisation who will sign for it. If no one comes forward, the machine has already been given the job.

PK h]<Ø®ÓììEPUB/styles.cssbody { font-family: serif; line-height: 1.55; margin: 0; padding: 0 1rem; } article { max-width: 42rem; margin: 0 auto; } h1, h2, h3 { line-height: 1.2; } img { display: block; max-width: 100%; height: auto; margin: 1rem auto; } blockquote { border-left: 0.2rem solid #999; margin-left: 0; padding-left: 1rem; font-style: italic; } pre { white-space: pre-wrap; padding: 0.75rem; background: #f3f3f3; } .byline { color: #666; font-size: 0.9rem; } PK= h]oa«,¤mimetypePK= h]mX[Pûû¤:META-INF/container.xmlPK= h]êîþ..¤iEPUB/package.opfPK= h]hh~%""¤ÅEPUB/nav.xhtmlPK= h]áʱ«33¤EPUB/post.xhtmlPK= h]<Ø®Óìì¤s$EPUB/styles.cssPKnŒ&