AI is starting to operate in the physical world and security is struggling to keep pace.

Artificial intelligence has spent the last few years proving what it can think. Now it's proving what it can touch, break into, and physically control — and the security world is scrambling to keep up.

Three stories from the past few days capture just how fast the ground is shifting: AI agents are being handed real access to robots inside labs, hackers pulled off a massive breach affecting millions of airport customers in the UK, and a shipped humanoid robot turned out to have a gaping wireless security hole.

For years, AI agents mostly lived inside software — writing code, answering questions, managing calendars. That's changing. Reports indicate AI agents are increasingly being granted direct access to physical lab robots, letting them run experiments, move equipment, and execute tasks without a human physically operating the machine at every step.

The appeal is obvious. Autonomous lab robotics could dramatically speed up scientific research, letting AI systems test hypotheses around the clock without waiting on human schedules. But handing an AI system control over a physical machine changes the risk calculus entirely. A software bug in a chatbot produces a bad response. A bug — or a manipulated instruction — in a robot with hands can produce a real-world accident.

Security researchers have long warned that as AI models move from advisory roles into direct actuation, the attack surface expands with them. An agent that can be tricked through a cleverly worded prompt is one problem. An agent that can be tricked into physically damaging equipment, mishandling hazardous materials, or overriding safety protocols is a different order of concern altogether.

Meanwhile, the more familiar kind of cyberattack is still very much alive. Hackers reportedly compromised systems tied to UK airports, exposing personal data belonging to roughly 8.7 million customers.

Airport systems are an especially attractive target because they sit at the intersection of high-value personal data, tight operational schedules, and critical infrastructure. A breach doesn't just risk identity theft for travelers — it can ripple into flight delays, security bottlenecks, and erosion of public trust in systems people assume are locked down.

The scale of this incident, affecting millions of people in a single event, underscores a pattern seen across the industry all year: attackers are increasingly going after infrastructure operators and travel systems, not just banks and retailers, because the payoff — both in stolen data and in disruption leverage — is larger.

Perhaps the most unsettling story is the smallest in scale but the biggest in symbolism: a humanoid robot reportedly shipped to customers with a Bluetooth vulnerability that could allow root-level access to the machine.

Root access means more than reading data — it means potentially controlling the robot's movements and behavior entirely. For a device designed to operate around people, in homes or workplaces, that's not a hypothetical risk. It's a direct line from a wireless exploit to physical control of a machine with actuators, motors, and — increasingly — some degree of autonomous decision-making.

This isn't the first time consumer robotics has shipped with security as an afterthought. But as humanoid robots move from research demos to actual commercial products, the stakes of a shipped vulnerability rise sharply. A flaw in a smart speaker is an inconvenience. A flaw in a machine that can walk, lift, and manipulate objects is something else entirely.

Taken together, these three stories point to the same underlying shift: AI is no longer confined to screens. It's operating lab equipment, sitting inside critical infrastructure, and walking around in humanoid form — often faster than the security practices meant to contain it can catch up.

The lab-robot story shows AI gaining physical agency. The airport breach shows how much personal data now flows through systems that increasingly rely on AI-driven infrastructure. And the humanoid robot flaw shows what happens when that physical agency meets a basic security oversight.

None of this means the technology should slow down — but it does mean the conversation around AI safety can no longer stop at model behavior and data privacy. Increasingly, it has to include the physical world: who — or what — has the keys to a robot, a lab, or a piece of critical infrastructure, and what happens when that access falls into the wrong hands.

As AI systems keep gaining bodies, hands, and autonomy, security can't be the layer that gets bolted on after the fact. It has to be built in from the first line of code to the first bolt on the chassis.

NEVER MISS A THING!

Subscribe and get freshly baked articles. Join the community!

Join the newsletter to receive the latest updates in your inbox.