Autonomous systems that act on goods need a root of trust for the object.
The International Federation of Robotics (IFR) estimates that about 4.7 million industrial robots were in service worldwide in 2024—only 177 for every 10,000 manufacturing workers. Annual installations climbed through the 2010s and jumped during the pandemic-era rush to automate, then levelled off, with 542,000 units installed in 2024.
The moment AI agents and robots execute on goods, a machine-verifiable, hard-to-clone physical-to-digital binding stops being a marketing feature and becomes a control problem.
The factory is having its ChatGPT moment.
Jensen Huang said the quiet part in January: the same for robotics. The Economist mapped what that looks like on the floor — robots that can be retasked instead of frozen in one product generation, digital twins that replace 2D drawings, software taking a third of industrial-automation revenue at Siemens, plants that can anticipate a shortage and move material without a human walking the aisle.
That is physical AI arriving through the door that software already opened.
Agentic systems learned to sense, interpret, decide, orchestrate, and learn on files, tickets, and markets. That stack is the on-ramp. Physical AI is what happens when the same loop closes on a battery, a wafer, a fastener, a pack, a spare that will go into a vehicle. The agent is no longer drafting a memo. It is releasing, picking, welding, shipping, recalling, or sending a cell to a second life.
A human inspector can still smell a wrong solvent or notice a reprint. An agent and a robot cannot. They act on whatever identity the system hands them. If that identity is a printable code, the control system is supervising a forgery surface.
The on-ramp is already live. The object is not.
Most firms are standing up agent stacks on the workflows they already understand: RFQs, quality packs, planning exceptions, customer files. That is the correct first move. Coordination costs have fallen. The firm-twin can run beside the core and force a decision in ninety days.
Those stacks still treat the physical good as a row in ERP.
That was tolerable when a person stood between the record and the act. It is not tolerable when the act is machine-executed. An autonomous trolley that delivers the wrong cell, a release agent that clears a cloned serial, a recycler that trusts a QR that never touched the chemistry — these are not data-quality incidents. They are physical events with a legal person attached.
The control problem is simple to state:
- The agent needs to know it is acting on this object, not a plausible substitute.
- The proof must be machine-verifiable at the stack’s tempo.
- The binding must be hard to clone, or the verification is theatre.
- No check is a stop, not a low-confidence score.
Brand protection used to own this sentence. Safety, release, customs, circularity, and now autonomy own it instead.
A passport is not a root of trust
Europe is about to make the gap visible.
From 18 February 2027, electric-vehicle batteries, light means of transport batteries, and industrial batteries above 2 kWh placed on the EU market must carry a battery passport under Regulation (EU) 2023/1542. The passport is accessed through the QR code required by the same regulation. It is an individual electronic record — model data plus unit data, including information that results from use — maintained by the economic operator who places the finished battery on the market.
The common Digital Product Passport technical system under the Ecodesign Regulation is the rail it rides on. The registry is scheduled to be operational from 20 July 2026. Other categories follow: iron and steel, then textiles, tires, and aluminum.
This is the right instrument for transparency, repair, reuse, and recycling. It is not, by itself, a root of trust for an autonomous system.
A QR code is a label, and labels can be photocopied. A unique identifier attributed by an operator is a claim. Claims travel without the object. A landing page that satisfies Annex XIII can be perfect while the cell in the fixture is not the cell in the record. When a human scans for compliance, that gap is an audit finding. When an agent or a robot scans to execute, that gap is an unauthorized act.
Digital Product Passports, serialization, and track-and-trace close the documentary half of the loop. They fail if:
- the identifier can be cloned,
- the document can be copied,
- or the scan never touches a property of the object itself.
Regulators can require the passport. They cannot, from Brussels, make the pack unclonable. That is an engineering and control choice the firm still has to make — before it lets the stack orchestrate goods.
What a root of trust for the object actually is
Root of trust, in this setting, is not a slogan and it is not a wallet app. It is a fail-closed chain from matter to permission.
1. A property of the object that is hard to separate and hard to copy.
Ink, a microscopic transponder, a physical unclonable function, a surface fingerprint that does not survive reprinting. A serial printed on a label is not this. A crypto-anchor that lives in the material or the pack can be.
2. A digital twin derived from that property, not pointed at it later.
The direction of travel is physical → digital. A collision-resistant hash from the anchor, optionally mixed with time, place, and process context, becomes the twin. Resolving it returns verification methods, not a marketing page. Decentralized identifiers and verifiable credentials are useful here because two machines that do not share a boss still need to share a fact.
3. A reader that is part of the trust system.
An anchor that cannot be interrogated on the line, at goods-in, at install, or at end-of-life is a lab curiosity. Verification is a first-class act: scan, check, green or not. The device is in the architecture, not in a pilot cupboard.
4. A signed event, not a screenshot.
The scan becomes a credential or a ledger update that the next party — a different plant, a customs node, a recycler, an agent — can check without trusting the last operator’s spreadsheet. A PDF of a green tick is not a control.
5. Lockstep through state change.
Tested, released, shipped, installed, recalled, repurposed. Article 77 already requires a new battery passport to link back to the original when a cell is remanufactured. The binding has to survive that lineage, or the second life is a second chance to launder identity.
6. The stack may not learn around a missing check.
If the reader is down, the workflow stops. A model that “infers” authenticity from a complete passport is inferring a story. Stories are how counterfeits clear gates.
None of this replaces the passport. The passport is the shared schema. The root of trust is what makes the schema about the object in the room.
Physical AI makes the join load-bearing
The manufacturing story now circulating is mostly about capability. Robots on six axes. Generative models closing the sim-to-real gap. Smaller plants closer to demand because flexible machines no longer need a kilometer of dedicated line. SoftBank buying a robotics business. Incumbents talking about AI as the brains of the factory and machines as the muscles, with humans still in oversight.
Oversight is the right word only if the object can answer.
A firm-twin that senses only from internal systems is a hall of mirrors. It will learn the warehouse, not the world. A product-twin that lives in a compliance drawer will sit there while agents act on fields anyone could have typed.
Safety — and now autonomy — is the join: the firm-twin may act only on object-twins whose binding to matter has been proven.
That join changes the Evolut stack the moment a workflow touches goods.
- Sense is not a database read. It is an observation of the object.
- Decide may not outrun the last fresh verification.
- Orchestrate may not move matter on a cached status bit.
- Learn may accept training data only from anchored events.
Humans stay above the loop. The loop, in a physical plant, includes the gripper. A human who clicks yes on an unanchored record is not exercising judgment. They are decorating a failure mode.
First workflows that deserve agents — and a binding
If you are scoring the 70% question on a line that ships physical goods, add one test the software-only version does not need:
Could two people and an agent stack-copy the line’s paperwork in 60–90 days, or would they also have to copy the object?
If they can only copy the paperwork, the exposed margin is documentary. The extinction risk is still sitting in the goods.
Pick the first two workflows at a physical gate:
- incoming identity and custody
- in-process hold and release
- finished-goods release
- install or put-into-service
- return, remanufacture, recycle
Those gates already have inspectors. They are the right place to replace heroic inspection with a machine-verifiable check plus a human yes or no. Put the object-twin in the system of record. Let the firm-twin orchestrate. Do not let it invent identity.
Batteries are the rehearsal. The date is not a strategy. It is a deadline that will expose every firm that treated the QR as the work. The work is the binding. Textiles, steel, furniture, and electronics will inherit the same argument, with less time to pretend otherwise.
Build the binding. Then let the agents touch the world.
Agentic AI is how a company learns to run an intelligence stack under a mandate, with guardrails, logs, rollback, and a human on every material gate. That is necessary. It is the on-ramp.
Physical AI is the same stack with consequences measured in kilograms, amperes, sterility, and torque. It does not get a free pass on identity because the model is fluent.
Autonomous systems that act on physical goods need a root of trust for the object. Not a nicer label. Not a richer passport page. A machine-verifiable, hard-to-clone physical-to-digital binding that fails closed.
The digital twin of the firm will evolut_ing into the core only if the twins of the objects it handles can survive contact with a robot – and we’re not even talking about organic, or humanoid robots yet….

