1. The Deployment Curve Is Already Steep
The previous article argued that every AI platform will eventually need a layer where authority travels inside the object rather than being granted by the host. Physical-world autonomy is where that argument stops being a forecast and becomes a present-tense liability, because in the physical domain the forcing function is sharper: an autonomous system that must decide on its own, in the moment, with no round-trip to a regulator or operator, commits energy into reality that does not regenerate. Carried authority is not an optimization here. It is the only way a credentialed observation taken in the field can later be admitted by anyone who was not present when it was taken.
The deployments are real today, and the figures below are as publicly reported by the named companies and their regulators. Waymo passenger-miles, as reported, exceed those accumulated by any single human driver. Tesla FSD Supervised is described as operating across millions of vehicles every day, capturing telemetry from billions of road-miles as publicly described. Aurora and Kodiak are reported to run commercial autonomous trucking on public corridors in Texas, Arizona, and the I-45 freight lane. Intuitive Surgical's da Vinci platform has been used in, as publicly reported, well over twelve million procedures worldwide. Anduril autonomous defense towers are described as running persistent surveillance along U.S. southern border installations and at allied perimeters. Saildrone is reported to run persistent maritime ISR for the U.S. Navy, NOAA, and partner navies. Skydio drones are described as supporting U.S. Army short-range reconnaissance under Blue UAS approval. CMR Surgical Versius is reported to operate internationally across NHS trusts and private hospital networks. Symbotic warehouses are described as operating at scale across Walmart, Target, Albertsons, and other major retailers, moving billions of cases as publicly reported through autonomous case-handling fleets. These companies are named for comparison and public-record illustration only; none is affiliated with, endorses, or has any relationship to Adaptive Query, and no claim is made about their internal architectures.
None of these are speculative, research prototypes, or limited to controlled tracks and fenced laboratory cells. They are operational, revenue-generating, and embedded in regulated supply chains, regulated transport corridors, regulated medical workflows, and regulated defense missions. The regulatory engagement is racing to catch up: EU AI Act, UNECE WP.29, FDA PCCP, ICAO Annex 19 amendments, and the UN CCW LAWS-doctrine track. The architectural question is not whether physical autonomy will deploy. It is whether the deployment substrate will carry governance with the object it acts on, or fight against it.
The cost of getting that question wrong is asymmetric. Cognitive-domain AI errors regenerate as new tokens and new turns. Physical-domain errors commit energy into reality. A misclassified pedestrian becomes a tort claim, a recall, and a regulatory shutdown of an entire fleet; a misexecuted incision, a malpractice action, a device-class re-evaluation, and an FDA enforcement letter; a misidentified target, a war-crimes inquiry. The deployment curve is steep precisely because the industries operating on it have demand pressure that exceeds the rate at which their governance retrofits can scale, and that mismatch is the architectural opening the substrate primitive addresses.
2. Why Cognitive-Domain Governance Doesn't Transfer
The opening article of this collection makes the general case: external governance fails because supervision is post hoc, policy is bolted on rather than built in, and behavior is not bounded by construction. The substrate primitives that answer those failures (admissibility evaluation, lineage retention, governance-chain credentialing) carry over to the physical domain unchanged. What physical autonomy adds is structural pressure that cognitive systems never face, and an honest architectural account has to name that pressure rather than gloss it.
A misclassified token can be regenerated. A misexecuted physical action commits energy that does not. Surgical incisions, vehicle collisions, weapon engagement, infrastructure operations, mining-equipment movements, and autonomous-shipping berthing all produce reversibility-asymmetric outcomes. The harm function is not symmetric across the decision boundary: refusing to act is recoverable, acting incorrectly frequently is not. For physical systems, stage-gated commitment, reversibility classification, and post-actuation verification are not conveniences. They are the architectural primitives that make autonomous physical action structurally bounded. A platform that cannot distinguish a reversible state transition (a cache write, a routing update) from an irreversible energy commitment (closing a valve, firing an effector, severing tissue) cannot govern physical autonomy at any scale.
Cognitive-domain output flows through screens and APIs, where the consumer is another software layer or a human reader who can re-prompt. Physical-domain output flows through actuators that contact reality, where the consumer is a body, a vehicle, a payload, an environment, or a weapon. This makes the audit reconstruction problem structurally different. Cognitive audit asks what tokens the model produced and whether the prompt was logged. Physical audit asks what observations supported what decision under what authority that committed what energy in what reversibility class against what operator-attested intent. Without substrate-level lineage, that reconstruction becomes a forensic engineering project rather than a structural query. Investigators reverse-engineer logs from disparate vendor systems, time-align them by hand, and rebuild decision chains months after the fact. That is how we reconstruct aviation incidents today, and the reason it works for aviation is forty years of mandated flight-data-recorder architecture. Physical-AI autonomy has no equivalent mandate yet, and the architectural debt is accumulating in real time.
A final structural difference frames the rest of this article. Cognitive systems mostly operate inside the platform vendor's trust boundary; physical systems operate inside operator and regulator trust boundaries. The cognitive system answers to the platform's terms of service. The physical system answers to the FAA, the FDA, the NHTSA, the EMA, the IDF, the operator's safety case, and the insurer's underwriting model. Governance that lives only inside the vendor's platform cannot speak to those external authorities, because none of them will accept a vendor's internal log as a credentialed primary record. This is the malicious-host problem in physical form: the host running the autonomy is exactly the party whose self-interested account no external authority is willing to trust, so authority has to be carried by the object and witnessed independently rather than asserted by the host after the fact.
3. The Single-Vendor Platform Pattern Will Not Survive Coalition Operations
Most physical-autonomy vendors build vertically-integrated platforms. As publicly described, Anduril Lattice integrates Anduril sensors with Anduril autonomy with Anduril command surfaces. Palantir Foundry is described as integrating intelligence sources within a Palantir-managed ontology. Waymo is described as integrating its own sensing, perception, planning, and actuation. Tesla is described as integrating its own FSD stack from camera silicon up through training infrastructure. Each platform produces operational coherence inside the vendor boundary because the vendor controls every interface and every internal contract. None produces coherent operations across vendor boundaries, because there is no shared substrate that survives the crossing.
Coalition defense operations require cross-vendor and cross-coalition composition by definition. A NATO mission may compose Anduril towers, French Thales radars, German Hensoldt EW, U.S. Army Skydio drones, and a coalition-shared targeting picture under a partner-nation command authority. Multi-jurisdiction transport requires cross-vendor and cross-jurisdiction operations: an autonomous truck crossing from California to Arizona to New Mexico changes regulator, changes road-authority data feed, and may change command-and-control vendor. Multi-hospital healthcare requires cross-OEM medical-device operations as patients move between facilities with different surgical platforms. Multi-utility critical infrastructure operates across vendors and across jurisdictional grid operators with different governance frames. The platform pattern does not survive these realities except through ad-hoc integration projects that grow superlinearly with participant count and decay every time any vendor updates its API.
The substrate alternative is a credentialed mesh in which every vendor's contributions enter as active data: credentialed observations that carry their own authority under a published authority taxonomy, present that authority to whatever host consumes them, and let cross-vendor composition operate through declared federation rather than bilateral integration. Coalition operations admit through composite admissibility that weighs each contribution by its credentialing authority and trust slope. The architectural question is whether the substrate exists. If it does, vendors compete on what they implement well, the best radar, the best perception stack, the best surgical effector, while the composition is structural and coalition-portable. If it does not, vendors compete on whose platform captures the most customer-coalition, and the operators most exposed to coalition operations (defense, transport, healthcare, infrastructure) pay the highest tax for that capture in integration fragility, vendor lock-in, and regulatory friction at every authority boundary.
4. The Regulatory Frame Is Already Architectural
A companion article in this collection treats the EU AI Act in full, so the point here is narrow. Across regimes the regulatory direction is the same and it is architectural: governance must be carried and demonstrable, not procedurally documented. EU AI Act Annex III classifies most physical-autonomy deployments as high-risk, requiring traceable lineage, structurally-supported human oversight, and demonstrable risk management throughout the lifecycle, with enforcement for high-risk systems beginning August 2026. FDA's Predetermined Change Control Plan framework, finalized in 2024, requires structurally-bounded modification scope and architectural impact assessment for AI-enabled medical devices that learn or update post-clearance. ICAO's emerging autonomous-aviation frameworks under the RPAS Panel and the AAM-related amendments require phase-decomposed certification with structural separation between sensing, decision, and actuation certified independently. ICRC and UN CCW LAWS-doctrine work increasingly requires structurally-recorded operator intent and meaningful-human-control architecture rather than procedural attestation. UNECE R155 mandates cybersecurity management systems for vehicle OEMs across most major markets, already in force across UNECE-1958 contracting parties including the EU, UK, Japan, and South Korea, and R156 mandates software-update management systems with architectural traceability of every over-the-air change.
The supporting regimes point the same way. NIS2 transposition is in force across EU member states. The SEC cyber-disclosure rules are operative. Compliance documentation describing what a system does is structurally weaker than architectural records demonstrating what it actually did. Operators that adopt carried governance ahead of mandate gain an implementation-cost advantage over operators retrofitting under enforcement pressure, because the architectural primitive scales linearly with deployment while retrofit cost scales superlinearly with deployment scope, vendor count, and jurisdiction count. The architectural shape that satisfies these regimes is converging on the same five properties: credentialed observation, evidential weighting, composite admissibility, governed actuation, and lineage-recorded provenance with recursive closure.
5. The Substrate Is Not Incidental
Spatial autonomy needs positioning, time, identity, and coordination, and it needs all of them as governance-credentialed primitives that compose. Mesh-derived coordinates that survive GNSS denial through cooperative ranging across credentialed peers. Mesh-derived time that survives master-broadcast compromise through distributed time consensus under authority taxonomy. Credentialed marker infrastructure dual-purposed for human and machine readers, so a sign a human reads as a stop sign and a machine reads as a credentialed observation share the same authority chain. Multi-modality cooperative ranging that survives single-modality jamming because the substrate composes radar, lidar, vision, RF, and acoustic observations under one weighting scheme. Stage-gated commitment for irreversible actuations, so the architecture distinguishes intent from execution and supports do, defer, refuse, or partially execute as first-class outcomes. Operator-intent substrate that makes meaningful-human-control architecturally real rather than a checkbox on a procurement form. Multi-party coordination supporting role-differentiated attestation, so a surgical team, a flight crew, or a fire-control crew each contributes credentialed observations under their respective roles. Federated cross-mesh reconciliation that respects national sovereignty while enabling coalition operations.
Each primitive composes with the others through the five-property governance chain disclosed under provisional 64/049,409: authority-credentialed observation, evidential weighting, composite admissibility, governed actuator execution, and lineage-recorded provenance. Recursive closure means every output re-enters the chain at property one as input to downstream evaluations, so actuation-state observations feed forward into the next decision, and lineage records are themselves credentialed observations that downstream consumers can admit, weight, and respond to. The architecture is not a set of disconnected features. It is a substrate that produces governance as a structural property of execution rather than as a layer above it, technology-neutral with respect to signature scheme, weighting algorithm, or storage, and composable hierarchically across unit, region, jurisdiction, and coalition levels of the same chain. This is object-as-authority applied to the physical world: the observation carries its own admissibility, so the host that consumes it does not get to define whether it counts.
This matters for physical autonomy specifically because physical-domain governance has nowhere else to go. Cognitive systems can hide behind platform terms of service and red-team reports because the consumer of cognitive output is usually another software layer or a human reader. Physical systems contact reality, and reality has regulators, courts, insurers, and treaty bodies whose acceptance criteria are not satisfied by procedural attestation. Carried governance, witnessed independently of the host, is the only architectural shape that produces records those external authorities will admit as primary evidence of governed behavior. The same property answers the malicious-host case: a trust-scoped, host-signed, quorum-witnessed fabric makes a hostile or compromised host's actions attributable, out-routable, and fail-closed, which is exactly what an insurer's underwriting model and a court's evidentiary standard require.
6. What This Means for the Next Decade of Physical Autonomy
The vendors and operators that adopt carried governance as substrate, not as a compliance bolt-on, will operate inside the regulatory direction rather than against it. Their deployment scaling will be supported by regulatory engagement rather than collide with it, because the records the substrate produces are exactly the records EU AI Act conformity assessment, FDA PCCP impact analysis, UNECE R155 incident response, and CCW LAWS-doctrine review require. Their cross-vendor and cross-coalition operations will compose structurally rather than through bilateral integration projects. Their incident reconstruction will read against architectural records rather than depend on forensic engineering. Their competitive position will not depend on platform-vendor capture, because the substrate is portable across vendors and survives platform migrations.
The vendors and operators that do not will face the same trajectory platform-policy AI governance is now facing in the cognitive domain: regulatory pressure that demands architectural support the platform was never built to provide, compliance retrofits that grow superlinearly with deployment scale, audit reconstruction that depends on engineering archaeology after every incident, and coalition operations that face friction at every authority boundary. That cost is not paid evenly. Early movers amortize substrate adoption across a smaller deployed base; late movers retrofit across the full deployed base under enforcement pressure, with operational continuity and recall exposure on the line.
This is the architectural reality of what physical-world autonomy at scale requires. The patent positions the substrate at exactly that layer: the credentialed mesh under positioning, time, identity, coordination, and actuation, composed through a five-property chain with recursive closure. The regulatory direction confirms it, and the deployment curve makes it urgent. The substrate does not replace the platforms vendors have already built; it gives them the structural floor they have always needed and never had. Once authority, identity, and admissibility travel inside the object even in an environment as unforgiving as the physical world, a class of systems becomes possible that could not have existed before, which is where the collection turns next.