Blog

When AI meets IoT: machines will be able to act

For much of its history, the Internet of Things has essentially served to make the physical world observable by computer systems. A sensor measures a temperature, a camera transmits an image, a vehicle communicates its position, and an industrial machine reports its operating status. That data is then routed to a platform where software, analysts, or operators can review it and determine what action to take.

Artificial intelligence is beginning to transform this architecture profoundly. Systems can now interpret images, detect anomalies, establish relationships between different data points, and recognize situations that would have been difficult to identify with simple predefined rules. AI agents add a further capability: they can use this information to pursue an objective, query other systems, select an action, and potentially trigger its execution. We are thus moving gradually from an Internet of Things that lets us know what is happening to an infrastructure capable of taking part directly in what should happen next.

This convergence between IoT, Edge Computing, and artificial intelligence opens up considerable possibilities in industry, energy, transportation, logistics, agriculture, smart buildings, and several other sectors. At the same time, it introduces a fundamental governance question: when a machine can observe its environment, interpret a situation, and act, how far are we prepared to delegate the decision to it?

The traditional model of many IoT systems rests on a relatively clear separation between observation and action. The device measures a physical condition, turns that observation into data, and transmits it to a central system. An alert, an indicator, or a dashboard then allows a person to interpret the information and decide on the next step.

A sensor may, for example, detect an abnormal temperature in a cold room. The system generates an alert and an employee checks the situation before deciding whether to intervene. An industrial machine may report an unusual vibration, and a technician analyzes the information before determining whether an inspection or a shutdown is necessary.

In this architecture, the computer system informs and the human decides.

This approach works particularly well when the volume of information to monitor remains reasonable. The challenge changes considerably when an organization operates thousands or tens of thousands of devices. The quantity of data and alerts can then exceed human capacity to interpret everything effectively.

Artificial intelligence brings a first transformation by making it possible to bring interpretation closer to observation. A traditional camera produces an image. A camera using a vision model can also recognize the presence of a vehicle, detect that a normally clear area is obstructed, or identify an event requiring particular attention.

In an industrial environment, a model can simultaneously analyze the temperature, vibrations, pressure, and operating history of a piece of equipment. A combination of values that would trigger no individual rule may nevertheless correspond to an unusual situation when the full context is taken into account.

Raw data then acquires operational meaning. This capability is particularly important in environments where value comes not from accumulating data but from the speed with which a significant situation can be recognized. An organization does not necessarily need to observe thousands of measurements continuously. Above all, it wants to know when a situation deserves its attention. Artificial intelligence can thus help turn a constant stream of data into actionable events.

Edge Computing brings this capability even closer to the physical world. When analysis has to be performed quickly, systematically transmitting all the data to a cloud infrastructure is not always necessary. Part of the processing can be carried out directly on the device or on an Edge infrastructure located nearby.

This approach can reduce latency, limit certain volumes of transmitted data, and maintain certain functions when the connection to the cloud becomes temporarily unavailable. It can also considerably change how information circulates.

A camera does not necessarily need to transmit all of its video continuously when the operational need is to recognize a few specific events. Local analysis can identify those events and transmit only the relevant metadata or sequences. An industrial machine can likewise analyze its operating data locally in order to distinguish normal variations from situations requiring intervention.

Edge AI therefore brings intelligence closer to the source of the information. And the closer that intelligence comes to the physical world, the more the distance between observation and action can shrink. It is with AI agents that this evolution takes on an even greater dimension. Detecting an anomaly is a first step. Determining what to do next is another.

Suppose a system detects an unusual variation on a piece of industrial equipment. An agent can consult the maintenance history, review previous interventions, compare the data with that of similar equipment, and check technician availability. It can then prepare a recommendation, open a service request, and pass on the necessary information to the person responsible. With a higher level of autonomy, it could also temporarily modify certain parameters when clearly defined conditions are met. The chain then becomes: observe → interpret → decide → act.

This loop represents a major evolution because it directly connects the physical world and the digital world. Information coming from a piece of equipment can lead to a digital decision that then produces a physical consequence. Automation becomes more contextual and can adapt to situations that cannot always be reduced to a simple rule.

This evolution does not, however, make traditional automation any less relevant. Organizations have been automating equipment for several decades. Programmable logic controllers, industrial control systems, and management software already execute rules that automatically trigger actions.

When a condition is known and deterministic, a traditional rule often remains the best solution. If a temperature exceeds a clearly established critical threshold, shutting down a piece of equipment immediately can be infinitely more appropriate than asking an artificial intelligence model to interpret the situation.

AI delivers more value when several pieces of information have to be interpreted together, when a context has to be recognized, or when several possibilities have to be considered. An agent can be given a general objective and determine some of the steps needed to reach it. This flexibility increases the scope for automation while simultaneously introducing variability that has to be governed. Intelligent architecture is therefore not about putting AI everywhere. It is about using each technology where its characteristics genuinely create value.

From the moment a system can act, the central question becomes one of authority. An agent that recommends inspecting a machine does not exercise the same level of autonomy as an agent able to shut it down. A system that prepares a purchase order does not present the same risk as a system authorized to send it directly to the supplier.

Organizations will therefore have to define levels of autonomy according to the nature of the action, its reversibility, the context, and the potential consequences of an error.

Some decisions can be fully automated when risks are low and limits clearly defined. Others can be prepared by AI and then validated by a person. Decisions likely to entail significant consequences can continue to explicitly require human authorization.

Maturity will not consist of maximizing autonomy. It will consist of assigning the appropriate level of autonomy to each situation.

This distinction is essential because the phrase “human in the loop” can give a false impression of control. Adding human validation does not automatically guarantee better governance. If an operator receives several hundred recommendations each day and simply has to click “approve,” their presence can quickly become symbolic.

Human judgment must be placed where it brings real value. A system can automatically handle routine situations and pass exceptions to a person with the necessary expertise. It can also provide the context that led to its recommendation so that the human decision is genuinely informed.

The objective is to combine machines’ ability to process large quantities of information quickly with humans’ ability to understand unusual situations, broader consequences, and elements that are difficult to reduce to data. The human then remains an active component of the decision-making system.

Identity also becomes fundamental as soon as a machine can act. It is no longer enough to know that a piece of information comes from a sensor. We must be able to determine which identity produced it, which system interpreted it, which agent requested an action, and which device ultimately carried it out. This chain of trust must be traceable.

When an agent communicates with a machine, the equipment must be able to verify that it is an authorized entity. The agent must hold only the permissions necessary for its function. A compromise of its identity should not allow it to extend its reach across the entire infrastructure.

Least privilege, Zero Trust, and Continuous Trust thus become directly operational principles. The greater a machine’s capacity to act, the more its identity, its permissions, and its context matter. Cybersecurity must then protect more than devices and communications. It must also protect the decision-making process.

An attacker does not necessarily need to take full control of a piece of equipment if they can influence the information the system uses to decide. Falsified data, a compromised source, or a change in context can potentially lead a technically functional system to make a bad decision.

Trust must therefore be established across the entire chain: data provenance, device identity, communication integrity, model behavior, agent permissions, and the legitimacy of the commands transmitted.

The cybersecurity question then broadens. We must continue to protect information against theft, alteration, or destruction, while also protecting the organization’s ability to make and carry out good decisions.

This perspective connects directly to Hypersecurity. In an environment made up of intelligent, distributed systems, security lies in the ability to protect the interactions between data, identities, models, agents, and physical systems. A compromise at a single step can influence the entire decision chain.

Increasing autonomy must therefore be accompanied by a proportional ability to take back control. An autonomous system must be designed with the possibility in mind that it will behave in an unexpected way. Mechanisms must make it possible to reduce its permissions, disable a function, isolate a device, or require fresh validation when certain conditions are met.

These mechanisms are not a weakness of automation. They are a property of its resilience.

Organizations already apply comparable principles to people. Certain transactions require multiple approvals, responsibilities are separated, and employees have limits of authority. Emergency procedures also make it possible to halt a piece of equipment or a process when conditions become dangerous.

Autonomous systems must be subject to the same governance logic. The greater their capacity to act, the more important the ability to limit or quickly take back that action becomes.

The real potential appears, however, when several systems begin to collaborate. A smart building can combine information on temperature, occupancy, air quality, and energy consumption in order to adapt its operations to the actual situation. A supply chain can bring together vehicle positions, the condition of goods, weather conditions, lead times, and resource availability in order to detect a disruption and prepare an adjustment.

A plant can combine production data, equipment status, quality, inventory, and orders in order to identify that a technical problem is likely to affect a delivery soon.

Value then no longer comes solely from a smart sensor or a particularly high-performing model. It comes from the ability of the system as a whole to understand a situation well enough to coordinate a response.

Architecture thus becomes as important as artificial intelligence itself.

This reality takes on particular importance when digital decisions produce consequences in the physical world. An error in a text generated by an AI can be embarrassing or costly. A bad decision applied to an industrial machine, a vehicle, an energy system, or a critical infrastructure can have far greater consequences. The shift from informational AI to operational AI therefore changes the nature of the risk.

The performance of an autonomous system cannot be measured solely by the number of decisions it makes without human intervention. Its reliability, its predictability, its safety, the quality of its decisions, its ability to detect unusual situations, and above all its ability to recognize the circumstances in which it should not act become just as important.

That last capability could in fact become one of the most important signs of an autonomous system’s maturity: knowing when to act and knowing when to stop. The convergence between AI and IoT thus gives rise to a new organizational responsibility: the governance of machine autonomy.

Companies will have to determine which information systems may observe, which sources they may use, which decisions may be made automatically, and which actions may be carried out without human intervention. They will also have to define who is accountable for these systems, the audit mechanisms, the limits of authority, and the procedures for taking back control.

This governance cannot belong exclusively to artificial intelligence teams or IT teams. It must bring together those responsible for operations, cybersecurity, technology, compliance, and risk management, along with the specialists who genuinely understand the equipment and processes involved.

A decision made by a machine remains a decision embedded in a business process. Its governance must therefore be integrated into that of the organization.

The convergence between the Internet of Things, Edge Computing, and artificial intelligence represents much more than an improvement in sensors or IoT platforms. It is gradually transforming the relationship between digital systems and the physical world.

Connected objects have allowed us to observe remotely what is happening in our machines, our vehicles, our buildings, and our infrastructures. Artificial intelligence now makes it possible to interpret those observations further. Agents are progressively adding the ability to select and trigger certain actions.

The loop closes: observe, interpret, decide, and act.

For organizations, this capability opens up considerable possibilities in terms of productivity, maintenance, quality, logistics, energy management, and operational resilience. At the same time, it demands a far more rigorous architecture around identities, permissions, traceability, data provenance, cybersecurity, and the levels of autonomy granted to systems.

This evolution also represents a new dimension of Hypersecurity. When machines begin to act, protecting the infrastructure also means protecting the chain that turns an observation into a decision and then a decision into an action. Identity, Zero Trust, Continuous Trust, least privilege, AI governance, and resilience must then function as components of a single architecture.

At Quantum Beyond, this convergence connects directly to our work on Edge infrastructures, Qb OS Edge, Q-Carbon Security Systems, digital identity, Hypersecurity, and artificial intelligence governance. Our experts work alongside technology and operations teams to design environments where intelligence can be distributed while preserving clear limits of authority, traceability of actions, and the human ability to take back control when the situation demands it.

In the past, the essential question in IoT was how to connect machines and retrieve their data. The next stage is far deeper. We will have to determine which decisions we are prepared to delegate to machines, under what circumstances, with what level of authority, and with what ability to take back control. Because as artificial intelligence gradually leaves our screens to act in the physical world, the question is no longer only what the machine is capable of doing. We must also decide what it has the right to do.