Almost every Physical AI enquiry we receive opens with the machine. Which arm, which AMR, which drone. It is the wrong end of the problem, and the plants that get autonomy working in production are the ones that started a layer below it.
What a machine actually knows
A robot arm knows its own joint positions and whatever its cell controller was told at commissioning. An AMR knows a map and a set of waypoints. An inspection drone knows a flight path. None of them knows what the asset in front of it is called in SAP, which zone is currently under a permit to work, what the P&ID says that valve should be doing, or who on this shift is authorised to approve the next action.
That gap is not a perception problem. Perception is the part that already works. It is a grounding problem, and it is where the money and the schedule go.
The five stages, in the order they have to be built
- Perceive — turn the floor into structured events rather than video nobody watches.
- Ground — resolve every event to a real, named asset, zone, batch, and shift.
- Decide — bring the context the machine cannot sense: permit status, work order, maintenance history, regulation.
- Act — issue the instruction through the same permissions that govern a person doing it.
- Govern — write the plan, the call, and the result to an audit trail that survives an EHS review.
The order matters. Stages one and two pay for themselves on safety, quality, and uptime before any machine is given authority to act, which is what makes stages three to five fundable.
The gate nobody budgets for
The pilots we see stall rarely stall on accuracy. They stall when EHS or legal asks why the system did what it did, and the answer is a model output nobody can reconstruct. Attribution — to a policy, a model version, and a named person — is not a compliance afterthought on an autonomous system. It is the thing that decides whether it is allowed to run at all.
What we would do on a first site
- Start on the cameras and signals already installed. New hardware is a procurement cycle you do not need yet.
- Resolve identity early — one asset, one record, across SCADA, ERP, CMMS, and the drawing set.
- Run inference at the edge from day one, so data residency never becomes the reason the rollout stops.
- Define the escalation path and the named reviewer before the first autonomous action, not after the first incident.
- Keep functional safety where it belongs: in the safety-rated controller, not in a model.
Plants that buy the robot first usually spend the following year building this layer anyway, under schedule pressure, with a machine already sitting on the floor. It is the same work either way. Only the order changes, and the order is what decides whether it lands.
Written from deployment experience across multiple sites. Patterns are described without identifying any customer — we are under confidentiality with the operators involved.
Talk to an engineer about this