The Chips That Stop Robots From Being Hacked: Why FPGAs Matter for Physical AI Security

A veteran security engineer explains how a specialised type of programmable chip is becoming the first line of defence for AI-powered robots and machines.

AI2Day Newsdesk3 min read
AI-driven cyber operations visual, depicting autonomous systems in a digital landscape
Share

Key points

  • FPGAs, programmable chips used to lock down hardware before software even loads, are moving into a central security role in physical AI systems.
  • Eric Sivertson, VP of security at Lattice Semiconductor, a chipmaker based in Hillsboro, Oregon, made the case on episode 260 of The Robot Report Podcast.
  • Physical AI, meaning robots and machines that act on the real world using AI, face security risks that purely software fixes cannot fully address.
  • Sivertson brings more than 30 years of experience in embedded-systems security, the field of protecting the computing hardware inside physical devices.

What is an FPGA, and why should anyone care?

An FPGA, short for field-programmable gate array, is a chip that engineers can rewire after it leaves the factory. Unlike the fixed chips inside a typical phone, an FPGA's internal connections can be reprogrammed to do almost any task, which makes it useful for security because it can be updated as new threats appear.

In a robot or industrial machine, the FPGA often powers up before anything else does. That gives it a chance to check whether the rest of the hardware has been tampered with, before the main operating system or AI software even starts running. Think of it as a security guard who checks everyone's ID at the door before the building opens.

Lattice Semiconductor has built its security business around exactly this idea, positioning its FPGAs as a hardware root of trust, a verified starting point that the rest of the system can rely on.

Why do robots need this kind of protection?

A hacked chatbot is an embarrassment. A hacked robot operating a factory floor, a hospital ward, or a warehouse is a physical danger.

Physical AI systems, AI that controls arms, wheels, and tools in the real world, face attacks that pure software security cannot stop. An attacker who gets into the hardware layer, below the operating system, can override software defences entirely. The FPGA sits below that layer, which is exactly the point.

Sivertson spent more than 30 years working on security for embedded systems, the computing hardware inside everything from medical devices to industrial equipment. His argument, laid out on the podcast, is that as AI moves from screens into machines, hardware-level security needs to come with it.

What does this mean for ordinary people?

Most people will never see an FPGA. But if you are a patient in a hospital that uses robotic surgery equipment, an employee in a warehouse where robots sort packages, or a farmer using AI-assisted machinery, the security of those systems matters to you directly.

Getting this right at the hardware level means the robot working next to you is harder to hijack, whether by a remote attacker or by someone who has physically tampered with the machine. It is not a solved problem yet, but it is one engineers are actively working on.

Common questions

Do I need to know anything about this as a consumer?

Not right now. This is a concern for manufacturers and the companies deploying AI-powered machines, not individual users. The practical effect, if the industry gets it right, is that physical AI systems become safer and harder to tamper with.

Is Lattice the only company doing this?

No. Several chipmakers work on hardware security, and FPGAs are one approach among several. Lattice is positioning its products specifically for the physical AI market, but the broader field of hardware-rooted security includes many players and approaches.

© 2026 AI2Day