Jensen Huang declared that “the ChatGPT moment for physical AI is here.”[1] For those of us in cybersecurity, that phrase means something very different than it does to most of his audience.

A city skyline with lights

AI-generated content may be incorrect.

Hundreds of synchronized drones paint abstract images and logos above the Las Vegas Strip during CES 2026

There’s a certain irony that only CES can deliver: standing in the world’s largest technology showcase, surrounded by autonomous robots, AI-embedded everything, and software-defined vehicles—while struggling to get consistent data throughput while seemingly enjoying FULL BARS of cellular signal. The meta-lesson is real: the edge isn’t a strategy slide. It’s what happens when the network taps out.

I’ve attended CES since 1996, when cellular failure meant you simply couldn’t make a voice call. Thirty years later, at CES 2026, I found myself in a remarkably similar situation—except now the stakes are exponentially higher. Back then, a dropped call was an inconvenience. Today, when every device is connected, intelligent, and making decisions at the edge, connectivity isn’t just convenience—it’s the foundation of trust.

Throngs of people entering CES 2026 Tuesday morning for Venetian Expo opening


The Shift: From Connected Devices to Software-Defined Everything

Across CES coverage, the dominant themes were consistent: AI everywhere—not as a feature, but as the substrate for consumer tech, enterprise platforms, and robotics. Robots and “physical AI” moved from novelty to near-term productization. Automotive doubled down on software-defined mobility. Edge intelligence became the default architecture.

That consensus matters because it changes the trust problem. We’re no longer securing “a device” or “an app.” We’re securing a living system—silicon + firmware + software + models + cloud APIs + suppliers—changing continuously.

One theme I saw repeated across countless booths was “Software-Defined Vehicles” (SDV). But that’s just the automotive slice. What I witnessed at CES 2026 was the emergence of Software-Defined Everything (SDE).

SDE used to mean OTA updates and feature flags. Now it means something sharper: continuous inference engines that adapt daily—or faster.

Consider: your mattress optimizes sleep cycles. Your CGM adjusts recommendations in real-time. Your vehicle’s autonomy stack makes split-second decisions. Robots navigate factory floors and hospital corridors. Each of these systems shares common characteristics: persistent cloud connections, contributions to massive data lakes, and AI models that learn, retrain, and deploy continuously. The device you interact with this morning may behave differently by this afternoon.

The “improvement” isn’t on a quarterly patch cycle anymore. It’s delivered through refreshed model weights, updated retrieval corpora, policy and safety tuning, and cloud-side behavior changes that instantly alter edge outcomes.

Trust implication: When behavior changes continuously, assurance can’t be periodic. You need continuous trust—identity, integrity, authorization, and evidence that keep pace with the update velocity.

Physical AI on the Floor: Three Exhibits That Made It Real

For those of us in cybersecurity, “physical AI” carries significant weight. Historically, I’d only heard “cyber-physical” in the context of threat scenarios—Stuxnet targeting Iranian centrifuges, BlackEnergy attacking Ukrainian power grids. These were warnings about what happens when digital systems control physical infrastructure without adequate security.

Now “physical AI” is consumer vocabulary. And that shift should make every product security team sit up and take notice.

Tensor: Personal Autonomy as an AI-First Platform

The Tensor Robocar: designed for autonomy from the ground up, not bolted on after

Tensor’s booth was a masterclass in the “software-defined vehicle” narrative becoming mainstream—framing the vehicle as an AI-first platform rather than a traditional EV with autonomy retrofitted. Their “Robocar” is a Level 4 autonomous vehicle designed for private ownership, powered by eight NVIDIA DRIVE AGX Thor chips delivering over 8,000 TOPS of computing power, with five LiDAR systems, 37 cameras, 11 radar units, and 22 microphones.[2]

The detail that stuck with me: Autoliv’s foldable/retractable steering wheel concept for autonomous mode—an interior designed around autonomy, not around a human driver at all times.

And candidly, this hit home. For an aging population—I’m navigating this with my own parents—”safe transport” isn’t a luxury feature. It’s independence. It’s access. It’s dignity. When that capability depends on an evolving AI stack, trust becomes the product.

Trust angle: SDV and autonomy need a trust fabric that spans device identity, OTA signing, in-vehicle and cloud service authentication, supplier boundaries, and forensic-grade evidence of what changed and when. Every one of those sensors, every model update, every over-the-air push requires authenticated, verified trust.

A car on display with people in the background

AI-generated content may be incorrect.

A modern SDV cockpit story: the user experience is software—and it’s updated as fast as the AI behind it

Kubota: AI-Driven Agriculture Where Sensing Becomes Control

Kubota showcased autonomous and smart solutions—including its M5 Narrow specialty tractor and a concept versatile platform robot (KVPR).[3]

What grabbed me wasn’t just “autonomy,” but the sensing-to-action loop: the idea that a system can interpret field conditions and deliver targeted inputs precisely. Treasury Wine Estates is already using Kubota technology in Napa Valley vineyards for mowing, under-vine cultivation, and precision operations.[3] That’s physical AI in the most practical form: less waste, better yields, and a tighter feedback loop between reality and control software.

When a robot can autonomously assess crop conditions and make treatment decisions in real-time, we’re well beyond traditional IoT. We’re in the realm of AI-driven cyber-physical systems that require continuous trust verification.

Trust angle: Sensors and models that drive physical actions need provable integrity (what code/model is running?) and strong authorization (who can command/override?), especially as these systems become remotely managed at scale.

Doosan Bobcat: AI Out of the Cloud and Onto the Jobsite

Doosan Bobcat leaned into a theme I expect to hear more in 2026: bringing AI directly to operators to make systems safer and easier—especially for less experienced users. Their CES messaging highlighted the RogueX3 autonomous concept loader, an AI-enabled “Jobsite Companion” that uses an onboard proprietary LLM to provide real-time voice and display support, a “Service.AI” support platform, and collision warning/avoidance systems.[4]

The Jobsite Companion automates over 50 functions without cloud connectivity. This is edge AI making safety-critical decisions.

Trust angle: Jobsite AI features are cyber-physical safety controls. If something can steer, lift, or warn—its integrity, provenance, and update chain matter like a safety-critical system. Because it is one. A compromised system isn’t just an IT incident—it’s a potential workplace injury.

What Happens at Supercompute Scale (and Why Quantum Shows Up)

NVIDIA’s CES messaging emphasized “physical AI” plus next-gen platforms aimed at reducing training and inference cost and time—making iteration cheaper and faster. Near term, “scale” means faster iteration and more automation on both sides: builders and attackers.

Longer term, quantum is the forcing function for crypto agility. The industry is actively standardizing post-quantum algorithms so we’re not stuck with brittle crypto when the environment changes. NIST finalized the first post-quantum cryptography FIPS standards (ML-DSA FIPS 204, SLH-DSA FIPS 205) in August 2024.[5]

You don’t need to be a doomer about quantum timelines to act: designing for algorithm agility and fleet-scale rotation is just good engineering in an SDE world. With devices shipping today that will operate well into the 2030s, crypto-agile architectures aren’t optional.

The Trust Stack for SDE and Continuous Inference

CES 2026 made it obvious: the hard problem isn’t adding AI. It’s operating it safely at scale.

Here’s the practical trust stack teams need:

  • Strong identity for every device/system component. Establish cryptographic identity for devices, subsystems, services, and operators—so “who/what is this?” is always answerable.

  • Sign what changes behavior. Firmware and software are obvious. Increasingly, so are model artifacts, policy bundles, and safety configurations. If it changes outcomes, it needs provenance.

  • Continuous assurance (not annual audits). Measured boot, attestation patterns, runtime posture signals, and evidence trails that let you prove what was running at a specific time—because incident response in SDE is a timeline problem.

  • Automation at fleet scale. If you can’t rotate keys/certs, manage lifecycle, and enforce policy at device-fleet velocity, you’ll fall behind your own update cadence.

  • Crypto agility + PQC readiness. Not because quantum is “tomorrow,” but because agility is the only sane posture when your environment evolves faster than your refresh cycles.

The Regulatory Forcing Function

The EU Cyber Resilience Act (CRA) is a real deadline-maker:[6]

  • Entered into force: December 10, 2024

  • Vulnerability reporting obligations: September 11, 2026

  • Full compliance required: December 11, 2027

Add FDA Section 524B for medical devices and the FCC’s Cyber Trust Mark program, and the message is clear: converging global requirements are making security-by-design non-negotiable.

Closing: If It’s Software-Defined, It Must Become Trust-Defined

CES 2026 wasn’t just an AI show. It was a preview of a world where AI-driven systems operate in the physical world, update continuously, and rely on sprawling ecosystems of suppliers and services.

The winners won’t just ship smarter products. They’ll ship products that can prove authenticity, integrity, authorization, and update safety continuously—at the speed those systems now evolve.

The ChatGPT moment for physical AI has arrived. The question for every manufacturer is whether their trust infrastructure is ready to meet it.

Want to discuss your Device Trust roadmap for 2026 and beyond? Connect with the DigiCert Device Trust team to map your compliance timeline and post-quantum readiness strategy.

Hundreds of synchronized drones paint CES devices above the Las Vegas Strip during CES 2026

Share


#CES #CES2026 #CyberPhysical #PhysicalAI #AI #SoftwareDefinedEverything #CyberPhysicalTrust #DigitalTrust #DigiCert #CyberResilienceAct #NVIDIA #JensenHuang #ChatGPT #Tensor #Kubota #Doosan #Bobcat #PQC #NIST #FDA524B

Sources and References

[1] Jensen Huang “ChatGPT moment for physical AI” quote: NVIDIA CES 2026 keynote, January 2026.

[2] Tensor Robocar specifications: Tensor press release, CES 2026. Level 4 autonomous, 8x NVIDIA DRIVE AGX Thor chips (8,000+ TOPS), partnerships with Lyft, Autoliv, ZF, Bosch. Deliveries targeted late 2026; Lyft-ready markets planned 2027.

[3] Kubota autonomous platforms and Treasury Wine Estates deployment: Kubota North America press release, CES 2026.

[4] Doosan Bobcat RogueX3 and Jobsite Companion: Doosan Bobcat press release, CES 2026. Proprietary onboard LLM, 50+ automated functions.

[5] NIST post-quantum cryptography standards (ML-DSA FIPS 204, SLH-DSA FIPS 205): Finalized August 2024 per NIST announcement.

[6] EU Cyber Resilience Act timeline: European Commission. Entered into force December 10, 2024; vulnerability reporting obligations September 11, 2026; full compliance December 11, 2027.