JournalPhysical AI
Physical AI Cannot Retry
Software agents fail into a log file. Embodied ones fail into the world, where there is no exception handler and no undo.
Everything that makes language models forgiving disappears when the output is a torque command. A wrong token is a bad sentence. A wrong actuation is a damaged part, a stopped line, or a person in the wrong place at the wrong moment.
The three assumptions that stop holding
- Retries are free. In software, retry is the default recovery strategy. A robot that retries a failed grasp may have already knocked the object out of reach — the state it would retry from no longer exists.
- Latency is a UX concern. A 300ms pause is a spinner in a web app and a collision in a control loop. Physical systems have deadlines, not preferences.
- The distribution is stationary. Lighting changes, surfaces wear, a gripper accumulates dust. The world degrades your inputs continuously and without notification.
Sim-to-real is a distribution problem, not a graphics problem
The usual framing is that simulation must look more like reality. The more useful framing is that the policy must stop depending on the ways they differ. Domain randomisation works not because it makes simulation realistic but because it makes photorealism irrelevant to the policy.
You are not trying to close the reality gap. You are trying to make the policy indifferent to where it sits in that gap.
Layered autonomy
The architecture that survives contact with a real plant separates the learned part from the guaranteed part:
perception (learned) → scene estimate + uncertainty
planner (learned) → proposed trajectory
safety (analytic) → reject if outside envelope ← not learned
control (analytic) → execute, monitor, hard-stop ← not learnedThe safety and control layers are deliberately not learned. They are the part you can reason about, certify, and explain to a regulator. A learned system asking for permission from a verifiable one is the only pattern I have seen hold up in an industrial setting.