Most systems still rely on a convenient assumption: if a valid credential appears on a screen, something real must stand behind it.

For a long time, that shortcut was useful. A password was likely typed by a person. A photograph suggested that a camera had been present. A signed message usually represented a deliberate human action. A familiar voice on the phone was probably attached to a familiar person.

Those assumptions are becoming weaker.

Generative AI can reproduce the surface of identity at very low cost. Software agents can act continuously using permissions originally designed for occasional human use. At the same time, the post-quantum transition is forcing institutions to reconsider how long digital trust assumptions can reasonably survive.

Digital security is not becoming less important. It is becoming insufficient on its own.

The next security boundary is the physical world.

I came to this question indirectly. My work moved through VR software, aerospace systems, AI and, eventually, verification. The technologies changed, but one question kept returning: what gives a digital instruction the right to cause a physical consequence?

That question matters when software stops merely recommending actions and starts taking them.

The old shortcut

A digital system can establish that a credential is valid, that a message has not changed or that an account has the correct permission.

Those are essential facts. They do not always establish that the person, object or condition described by the system is actually present.

A valid signature proves something about a digital key and a message. It does not, by itself, settle every question about the reality behind that message.

This distinction was easier to ignore when most digital activity remained digital. It becomes harder to ignore when the result is a machine changing state, a vehicle moving, a robot entering a restricted area or a critical object being accepted.

The greater the consequence, the less comfortable we should be with a chain of trust that never leaves the digital domain.

Verification is not identification

The obvious response is to demand more identity: more accounts, more personal data and more persistent records.

That can create its own failure mode. A system may become more intrusive without becoming meaningfully more certain.

Many real-world decisions do not require a complete identity. They require a narrow question to be answered at a particular moment.

Is an action authorized?

Is an expected condition present?

Is a claim sufficiently trustworthy for this consequence?

These are verification questions. They should not automatically become excuses for permanent observation.

This distinction matters because trust and privacy are often presented as opposites. They do not have to be. A well-framed decision asks only for the information necessary to decide whether an action should proceed.

The goal is not to know everything. The goal is to remove the specific ambiguity that matters.

The real issue is authority

Security conversations often focus on information: whether content is authentic, whether a message is genuine or whether an account has been compromised.

But autonomous systems turn information into authority.

A recommendation becomes a command. A digital permission becomes physical access. A software decision changes something outside the computer.

This is where the problem changes character.

The key question is no longer only whether a message is authentic. It is whether that message deserves to produce the requested consequence in the real world.

That is a broader question than identity, cybersecurity or physical security can answer independently.

It is also why AI safety cannot remain limited to model behavior. Alignment, evaluation and interpretability are essential, but an autonomous system still operates inside a world of permissions, objects and consequences. A system may understand a policy while lacking a reliable basis for determining whether the real-world condition described by the policy is true.

Safety eventually meets enforcement.

Automation moves the bottleneck

I am optimistic about automation. Used well, it can create extraordinary abundance. Intelligence, production and coordination can become cheaper, faster and more widely available.

But abundance does not eliminate the need for trust. It moves the bottleneck.

When useful actions were expensive, their cost limited how often they could be attempted. Autonomous systems change that equation. They can make and execute decisions continuously.

Even a small rate of false authorization or ambiguous input can therefore become a large physical problem.

The security model has to scale with the number of actions, not merely with the number of users.

This is easy to miss because capability is visible and trust is usually invisible. We notice what a system can do. We notice the trust assumptions only after one fails.

As AI becomes more capable, those assumptions deserve to be treated as infrastructure rather than background detail.

A category, not a blueprint

We already have mature categories for cybersecurity, identity, access management and physical security. The emerging gap sits between them.

I use the term physical trust for the ability to determine whether a consequential digital claim corresponds to the relevant physical reality.

The category is early. Its final boundaries will be shaped by many people and institutions. The useful contribution at this stage is not to declare a universal blueprint. It is to name the problem clearly enough that we can stop hiding it inside adjacent categories.

The internet taught machines how to exchange information.

The next challenge is deciding when information deserves to cause something in the real world.

That is the question guiding my work at 4SI.