Dr. Greg Ombach, CEO-Level Deep-Tech Operator & Board Member, Senior Vice President at Airbus.gettyArtificial intelligence (AI) is moving from advising people to acting on their behalf. Agentic AI can plan tasks, access tools and execute decisions across digital systems. Physical AI connects intelligence to robots, vehicles and industrial operations.Both can enable greater autonomy, but they describe different dimensions of it. Agentic AI concerns how a system pursues an objective across tools and workflows. Embodied AI concerns how intelligence is connected to machines and the physical world. They can overlap, but their consequences require different controls.They share foundations such as trusted data, security, ownership and human accountability. Yet a digital agent may create, for example, financial, informational or operational harm, while physical AI can translate a decision directly into movement or operational change. The decisive question is not how intelligent the system is, but what it is allowed to do and what happens when it is wrong.Two Forms Of AutonomyAgentic AI changes how digital work is performed. Instead of asking a system to produce an answer, a company can give it an objective and allow it to determine the steps. The human role shifts from performing every task to setting the objective, defining limits and supervising the outcome. This transfers selected decision rights from people to software.Physical AI combines sensing, reasoning and physical action. Compared with conventional rule-based automation in tightly structured conditions, it can respond to greater variation and act in more dynamic and less predictable environments.My experience in aerospace has shaped how I think about this distinction. In safety-critical operations, one successful demonstration does not create permission to operate. Confidence is built through repeated evidence, defined conditions, certification and clear authority to intervene.I have seen the same challenge in robotics and industrial automation, where a system that performs well in a test may still struggle with latency, connectivity, conditions not encountered during testing, maintenance or integration. Proof-of-concept work with increasingly autonomous humanoids and other robotic systems has helped identify the conditions required for deployment in aircraft manufacturing, particularly around task suitability, human-machine interaction, safety, security, integration and operational reliability.Why Consequences Determine ControlAn agentic system may access the wrong information, approve an inappropriate transaction or pass flawed output into another workflow. It can repeat an error at scale, and when several agents depend on the same data, models or infrastructure, one weakness can spread rapidly.Physical AI can make consequences more immediate and less reversible. An incorrect action may affect a worker, a vehicle, a production line or critical infrastructure. Some digital actions can be reversed. Physical actions may require containment or shutdown, while some consequences cannot be undone.Leaders should consider how quickly harm can occur, whether an action is reversible, whether failure can be detected in time and how much opportunity a person has to intervene. AI risk should reflect the authority given to the system and the credible consequence of failure, rather than the model type. A system recommending an action, one executing a financial transaction and a machine moving in a shared environment should not pass through the same approval process.Different Security BoundariesBoth forms of AI need controlled access, trusted data, auditability, clear ownership and configuration control. Leaders should know what an autonomous system can access, what authority it has, which versions are approved, how changes are controlled and how quickly it can be contained.For agentic AI, the central issue is delegated digital authority. Organizations need visibility into the systems an agent can access, the tools it can use, the transactions it can initiate and the other agents it can communicate with. Permissions should reflect the consequence of the task.Embodied AI inherits these risks but adds a cyber-physical attack surface. Sensors, actuators, edge devices, connectivity and command channels become part of the security architecture. A compromised physical system may change how a machine moves or how an industrial process operates. Security and safety must therefore be engineered together, including safe degradation where appropriate, a safe stop when required and operational recovery.Different Operating ModelsAgentic AI can scale through digital workflows, platforms and reusable agents, but scale still requires ownership, monitoring and records sufficient to reconstruct material actions and decisions. Organizations must understand what an agent did and intervene when its behavior exceeds defined limits. Central teams can establish standards, but business functions must remain responsible for outcomes.Embodied AI requires an integrated operational system. Hardware, sensors, edge computing, energy, maintenance and operational workflows must work together. A technically capable robot may still fail to create value if it cannot operate reliably or integrate with existing processes.The business case must include integration, safety systems, training, maintenance, supervision, energy and upgrades. Comparing the price of a machine with the cost of human labor is not enough.Physical autonomy also needs a defined operating envelope. Leaders must specify which tasks a machine may perform, where and when it may operate, what uncertainty is acceptable and when it must slow down, escalate or stop. Autonomy should expand because operational evidence shows the system is ready, not because a roadmap promised it.One Foundation, Different ControlsOrganizations do not need separate governance frameworks, but the controls must reflect how the system acts and the consequences of its actions. Agentic AI requires clear permissions, decision rights, workflow limits and rollback. Physical AI also requires defined safety and security boundaries, intervention mechanisms, safe shutdown and operational recovery.“Human in the loop” is not enough. Leaders must know whether people can understand the system, intervene in time where intervention is feasible and rely on automated safeguards where it is not. Before approving autonomy, boards and executive teams should assess the authority being delegated, the worst credible failure scenario and the organization’s ability to reconstruct events, contain the failure and recover.The challenge is to apply autonomy where it adds value, set the right limits and retain human control where the consequences demand it.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Governing Physical AI: When Digital Governance Is Not Enough
A compromised physical system may change how a machine moves or how an industrial process operates.









