Will China Win The Physical AI Race

physical ai featured

I have been watching what is happening in Chinese manufacturing, and I do not think most people have connected it to what will be sitting in their kitchen in a few years.

China’s manufacturing scale gives it a real advantage in this category. More industrial robots deployed, more infrastructure to deploy them into, more sustained investment than almost any other nation. That is not opinion. That is the environment we are all operating in. But the part that interests me is not who is ahead. It is what that manufacturing capacity produces next.

It does not stay in the factory

Industrial capability has a way of arriving in the home about a decade after it arrives on the production line. That is the pattern with almost every technology we now take for granted.

So it is worth thinking about what that looks like here. Coffee machines that adjust to how you actually drink it. Televisions that watch the room. Vacuums that map your floor plan and know which room is which. Ovens that decide when the food is done. And eventually — not soon, but eventually — machines with arms, moving through a house where children and

elderly parents live.

Each of these is a decision system with a physical output. Not a chatbot that gives you a wrong answer. A device that does something.

What physical AI actually means

Let me be precise about the term, because it gets used loosely. Physical AI is a system where an AI model’s output becomes a physical action in the world, without a human deciding each time. That is the distinguishing feature. Not the intelligence, and not the robotics. It is that the loop closes without a person in it. A model perceives something, decides something, and a motor moves, a valve opens, a vehicle brakes.

Once that is true, three things change:Failure stops being informational and becomes physical. A hallucinating language model produces a bad paragraph. A misclassifying safety function produces an injury.

Safety and security become the same discipline. In IT, these are separate teams with separate risk registers. In physical AI, a compromised control system is a safety incident. Most organizations are not structured for that.

The system boundary moves. Your AI system is no longer a model and its training data. It is the model, the sensors, the actuators, the network, the update mechanism, and the maintenance process keeping it calibrated.

So — are we ready?

Not organizationally, in my experience. But the more interesting question is the legal one, and this is where I keep hearing the same three assumptions, all of which are now out of date.

“Who would even be responsible?”

The answer is more settled than most people think, at least in the EU. Under the revised Product Liability Directive — Directive (EU) 2024/2853 — the definition of “product” now explicitly covers software, AI systems, and digital manufacturing files.

Standalone software is a product. An AI model is a product.

More pointedly: providers of AI systems within the meaning of the AI Act are treated as manufacturers. So the question “is the software company liable or the hardware company?” has an answer, and the answer is frequently both, along with importers, authorised representatives, distributors, fulfillment service providers, and in certain conditions online platforms.

Two features matter especially for something living in a home:

Liability can attach to defects that emerge after the product was sold — where the product remains under the manufacturer’s control through updates, upgrades, or a system that continues to learn. A device that was safe on the day you bought it and became unsafe through an update is not outside the regime.

Recoverable damage includes the destruction or corruption of data not used professionally. Your family photos are within scope.

The deadline for Member States to transpose this into national law is 9 December 2026. It applies to products placed on the market after that date. That is not a distant horizon — it is a few months away.

“Which law would apply?”

This is the part I find genuinely elegant, and it is worth understanding because it changes how compliance work should be scoped.

The Product Liability Directive does not itself define what “safe” means. It links defectiveness to compliance with product safety law. Which means the AI Act, the Machinery Regulation, the Cyber Resilience Act, the General Product Safety Regulation and sector-specific rules become the practical benchmarks against which a court assesses whether your product was defective.

Compliance and liability are no longer separate conversations. Your regulatory posture is your liability position.

For a connected home device, that likely means several instruments at once: product safety

rules, cybersecurity obligations for products with digital elements, AI Act obligations depending on classification, and liability sitting underneath all of it.

“Do we even have laws for this?”

Yes. More than people assume, and arriving faster than most product roadmaps. The Machinery Regulation (EU) 2023/1230 applies from 20 January 2027. It does things that will surprise anyone who has not read it: software performing a safety function can be a regulated safety component in its own right; safety components with self-evolving machine- learning behavior require third-party conformity assessment rather than self-certification; cybersecurity protection of safety functions becomes a binding requirement for the first time; and substantial modification — including digital modification, such as adding connectivity or changing a safety function — makes you the manufacturer of the modified machine.

That last point deserves a moment. An operator who retrains a deployed model may have just inherited manufacturer obligations. So may a company that adds a connected feature to a device it did not build.

Where the real gaps are

I do not want to overstate this. There are genuine unresolved questions, and they are not

the ones usually raised.

Attribution across a stack. When a household robot injures someone, the fault may lie in a perception model from one vendor, control software from another, hardware from a third,

and an update pushed by a fourth. The liability regime names the parties. Establishing which link failed is an evidentiary problem, not a legislative one, and it is hard.

Products that keep learning. Static conformity assessment against a system whose behaviour changes post-deployment is a structural tension. The regulations acknowledge it; nobody has fully solved it.

Jurisdiction. The EU has moved furthest here. A device manufactured in one jurisdiction, sold in another, and updated from a third does not respect those boundaries. If you sell into the EU, EU rules reach you — but coverage globally is uneven.

The date mismatch. These instruments are landing on different timelines, and the interaction between the AI Act and the Machinery Regulation has been actively reworked through 2026. The direction is settled; the precise sequencing is still moving. Check the current position before scoping a program against it.

What I take from this

The question I started with was whether we are ready for AI to move into physical space. I think the honest answer is that the law got there before most organizations did.

That is unusual. Normally technology outruns regulation and we spend a decade arguing about it. Here, the frameworks are drafted, dated, and coming into force — while a great many companies building connected products still believe they are operating in a gap that closed some time ago.

If you are building anything where a model’s output becomes a physical action, the useful question is not whether rules exist. It is which of them already name you, and in what role.

About the author:

Nabiha Sofia Herradi is an AI governance and compliance advisor with over 15 years in governance, risk and compliance. She holds an LL.B alongside CISM, CISA, CIPP/E, CIPP/US and CMMC-CCP — legal training and technical certification, which is the combination AI governance actually demands.

She works with regulated organizations worldwide on EU AI Act, ISO/IEC 42001 and NIST AI RMF programs. Defense contractors handling CUI: that work runs at cyberdsc.com.

Have questions about AI governance for your organization?