Building the foundations of Physical AI through Execution Integrity
There is a gap in current autonomous AI: the gap between the data an autonomous AI acts on and whether the state it describes is physically and logically possible. We call this the Execution Integrity Gap. Our PILOT solution fills this gap by providing the integrity layer that means autonomous AI always makes decisions on data that is trustworthy.
The biggest risks are no longer predictable by looking back
AI-accelerated cyber and hybrid warfare: adversaries can now attack digital, physical, and operational systems at unprecedented speed, combining cyber attacks with disruption and physical consequences.
Critical infrastructure fragility: water, energy, transport, communications, data centres and other essential systems are increasingly interconnected, so a failure in one can rapidly cascade into others.
Protect What Matters Now.
Aequus is the integrity layer for critical infrastructure. Every other tool asks whether something looks unusual, Aequus tests whether the state your systems are reporting is physically and logically possible at all, catches the manipulation built to look normal, and tells you what is actually worth acting on, before disruption becomes damage.
From critical infrastructure and water to data centres, buildings and defence, Aequus turns a flood of data into a clear verdict, what is possible, what is not, and what to do about it, for stronger resilience and the confidence to act.
We have set out a formal argument that adding PILOT to an AI pipeline cannot make it less reliable, and we will publish it once the patents are public.
-
Physical AI is artificial intelligence that doesn't just process or analyse, it acts autonomously, in the real world. These are the systems where a wrong decision is not an error on a screen but a physical consequence.
Physical AI includes:
Autonomous vehicles and self-driving systems
Industrial and surgical robots
AI-managed power grids and energy infrastructure
AI-controlled water treatment and utilities
Data centres and AI factories managed by autonomous systems
Drones and unmanned aerial vehicles
Oil, gas and high-energy industrial systems controlled by AI
AI-directed defence systems
As Physical AI scales, one question becomes the load-bearing constraint for every system in this list: is the operational state the AI is acting on physically and logically possible? This is the Execution Integrity question. PILOT answers it.
-
Without Execution Integrity, an autonomous system can be working perfectly and still cause catastrophic harm, because it trusts the data it receives, and data can be wrong.
Execution Integrity seeks to overcome three failure classes:
Cyber manipulation and attack: a malicious actor alters the data the AI receives, causing it to act on a false operational state. Traditional security tools detect threats, but they cannot guarantee the integrity of the data the AI is already acting on.
Sensor error or drift: a sensor malfunctions, degrades, or drifts out of calibration. The AI receives readings that are physically impossible or inconsistent. It acts on them anyway, because nothing tells it not to.
Degraded data: telemetry is incomplete, delayed, or corrupted in transit. The AI’s picture of operational state is partial or wrong. It makes decisions based on that partial picture.
In all three cases, the cause is different. The consequence is the same: the AI acts on a lie. PILOT addresses all three. Before the AI acts, PILOT checks whether it is physically and logically possible for the system to be in the state the data describes. If the answer is no, or even uncertain, the AI does not act on that data. This is not a probabilistic check. It is deterministic. Valid, Violation, or Uncertain. Every time, before every action.
Independent, EU-funded research published in 2025 applied causal models to cyber-physical attack detection on the three public water and industrial testbeds and reported large gains over correlation-based methods. It post-dates our patent priority dates, uses a different method, and does not test our product. We cite it as evidence of the direction of travel, not as validation of PILOT.
Independently Validated
74%
Reduction in false alarms vs correlation-based methods
84
Attack scenarios tested across three independent OT testbeds
83.3%
Stealth threat detection
3.2ms
Latency
Firesapien: Winner, Best Innovation
UK Public Sector Transformation Awards 2024
Whole-State Verification (Physics, Not Logs)
-
Aequus runs an independent, deterministic check that flags when the state your systems are reporting is physically or logically impossible, not just when it looks unusual. It runs read-only alongside the tools you already have and returns a clear verdict with the engineering evidence behind it, in real time. How we do it is ours; what you get is a verdict you can act on and audit.
Why it matters:
Attackers can fake signals. They cannot fake causal reality.
Invariant-Based Validation (How Real Systems Behave)
-
Rather than looking only for known attacks or anomalies, PILOT independently determines whether the system state described by available telemetry is physically and logically possible.
It evaluates how the system is operating, not whether its behaviour resembles a known threat. When reported conditions are inconsistent with what is possible, PILOT identifies the state as implausible even when every individual signal appears normal.
This is Execution Integrity: confirming that the state a system reports is physically and logically possible before anything acts on it.
Why it matters:
This enables PILOT to identify stealthy, credential-based and low-noise threats, as well as benign or data-led failures, that may evade correlation, signatures and anomaly detection.
Parallel Validation Layer (Works With Your Stack)
-
PILOT runs alongside existing security, IT, and OT tools as a non-intrusive validation layer. It does not sit in the data path, replace detection systems, or act as a new alert engine.
Instead, PILOT treats all incoming data as signals, not ground truth, and validates whether the story those tools are telling is coherent before decisions, automation, or AI inference occur.
Why it matters:
Existing tools become more trustworthy, false alarms drop, and root cause analysis starts where reality first broke, not at downstream symptoms.
Use case:
IT Threat (Cyber-Digital)
-
An attacker compromises valid user credentials and accesses a sensitive media or IP asset through an approved application. The file is opened or copied, but no editing, processing, or downstream workflow follows. The asset is placed into an approved sync or sharing service and later retrieved outside the organisation via a trusted partner or cloud link.
-
Access was authorised.
The application used was approved.
Data moved through sanctioned services.
No signatures, policy violations, or anomalies are triggered.
Correlation-based tools observe events but do not encode expectations about what should happen next.
-
PILOT enforces the invariant “use follows access.”
Access to a high-value asset without a credible downstream workflow is causally implausible. The absence of expected use is itself a signal. PILOT identifies the global inconsistency between access, execution, and resource usage.
-
Instead of investigating hundreds of benign access events, RCA immediately narrows to who accessed the asset, why no workflow followed, and how it exited the system.
-
Traditional tools: Never (no policy violated)
PILOT: Immediate (causal violation identified)
Use case:
OT Threat (Cyber-Physical)
-
An attacker manipulates sensor readings to show normal pressure and flow while physical actuators drive a process outside safe limits.
-
Sensor values remain within expected ranges.
Network traffic appears normal.
No alarms are triggered at the sensor layer.
-
PILOT enforces physical invariants such as conservation of mass and energy.
Sensor readings that do not match actuator behaviour and downstream physical effects are causally impossible. -
RCA immediately identifies which sensor or control loop broke physical coherence, avoiding lengthy fault isolation.
-
Traditional tools: When physical damage occurs
PILOT: Before physics violation causes harm
Beyond Cyber
-
Firesapien™ is the physics-based threat-modelling engine within Aequus’s unified cyber-physical architecture, working alongside PILOT.
Where PILOT verifies the state a system is in now, Firesapien reasons about the physics of what must follow from it. It encodes the physics of real-world threats, fire, pressure, thermal propagation and other domain-specific processes, and computes the consequences a given state must lead to, so those consequences can be seen and acted on before they arrive. This is deterministic, physics-based reasoning, not a probabilistic forecast. It supports scenario and consequence analysis for infrastructure resilience.
Fire is the universal threat present in every critical-infrastructure environment. It is the domain Firesapien addresses first, and the clearest illustration of the broader physics-based capability, which rests on granted (UK) and allowed (US) patents.
-
The security industry has spent decades asking one question: is this behaviour unusual? Aequus asks a different question: is this system state actually possible?
Most security tools sit on the same axis: they watch individual signals and ask whether behaviour looks unusual. Adding more of them is an incremental gain on the same question, and in practice, more to triage. PILOT works on a different axis. Instead of examining each signal for anomalies, it takes the whole system state and tests whether it holds together against the physics and operating limits of what is being protected. Where the reported state is physically or logically impossible, PILOT says so, and identifies why, turning an overwhelming stream of alerts into a short list of what is real and worth acting on. It does this through a patent-pending integrity layer.
The failures Execution Integrity addresses are not only malicious. They can also be benign or data-led. A sensor spoofed by an attacker, a software update that disrupts a physical process, and a poorly calibrated AI model driving a system beyond safe parameters are all Execution Integrity failures. Conventional cybersecurity tools are primarily designed to detect malicious activity and may not reliably identify the second or third.
Aequus provides an independent layer of verification between what a system reports and what can physically and logically be possible. Operating read-only alongside existing infrastructure, it produces a clear, actionable verdict in real time without requiring existing systems to be replaced.
Aequus is not just a cybersecurity company. It provides the integrity layer needed to support trustworthy autonomous AI deployment in critical infrastructure.
Why Now?
AI is moving from inference into autonomous execution in power grids, water treatment plants, autonomous vehicles, robotics, data centres and AI factories, oil and gas and high-energy industrial systems, and defence. As it does, one capability becomes the load-bearing constraint: can we be certain that the operational state the AI is acting on is admissible? Existing tools typically assess how unusual a state appears or rely on fixed, pre-coded rules; this is the Execution Integrity Gap.
PILOT fills this gap. The Physical AI and autonomous industrial control market is projected to reach $1.7 trillion by 2035 (Kaiso Research, Goldman Sachs). Aequus filed IP addressing this emerging market before the category had a widely recognised name.
Everyone is racing to see more. Aequus tells you what is actually worth acting on.
Commercial Momentum
We are preparing our first lighthouse deployments with critical-facility operators and are in active discussions across data centres, water and process industries.
Aequus is a member of NVIDIA Inception, a programme designed to support startups. Our approach is platform-agnostic: we design to work with NVIDIA technologies but are not dependent on them. Our solutions can integrate with technologies including:
-
Trusted Out-of-Band Cyber Telemetry
-
GPU-accelerated Cybersecurity Framework
-
Digital Twin & Simulation Platform
-
GPU Programming Framework
Shaping the Future of Cyber Defence
We are at pre-seed stage and in active discussions with investors. The hardest technical question is settled: a formal, mathematical proof shows that PILOT is always at least as reliable as AI alone for Execution Integrity. Independent validation of an architecture matching our designs has also been peer reviewed. If you are interested in the investment opportunity, please get in touch.
