INTRO

Welcome to Level.UP, brought to you by UP.Labs.
This week’s two stories are on either side of the same shift.
The first: venture money has decided physical AI is the next leg of the boom, with $47.4B raised in the first six months of H1. The second: what happens when that software starts making decisions on its own?
Plus: $10M for Spirit Airlines’ internal business data, and robot safety is now a public company.
Think someone else needs this? Forward it to a friend or colleague navigating the same terrain.
MOVING THE WORLD AHEAD
Physical AI Funding is Booming
Physical AI startups raised $47.4B in the first half of 2026 across 521 deals, according to Crunchbase. Compare that to all of 2022, 2023, and 2024 combined, where the category took in $41.9B.
Four deals drove most of the jump. Waymo raised $16B in February at a $126B valuation, close to a third of the total so far. Anduril took $5B, autonomous defense company Shield AI raised $2B, and Saronic raised $1.75B to build autonomous sea vessels.
OUR TAKE
Ryan Ziegler, a general partner at Edison Partners, told Crunchbase the money has bunched into three buckets: robots and humanoids, defense, and foundation models.
But he thinks the real opportunity is much wider, with physical AI representing “the convergence of software, hardware, sensors and IoT, and services across a wide variety of real-world applications.”
Two key things have changed to make that possible. AI can now read the sensor data fast enough to tell an operator something useful. And the hardware got cheap.
That opens up industries that never went digital: manufacturing, supply chains, utilities, agriculture, transportation. Ziegler says the resulting companies look like vertical software businesses, with “attractive unit economics, large deal values, and multi-year deployments.”
In other words, there’s a major shift happening, similar to what cloud infrastructure did for SaaS. Founders now bundle hardware into subscription pricing, or charge by usage or outcome.
The hardware stops being the product and becomes the delivery truck. And companies like yours are perfectly positioned to capitalize on it.
Defending Against AI That Can Hack
Half of enterprise applications will be agentic by the end of this year, and the other half will be rushing to catch up in 2027.
Meanwhile, the average enterprise runs six to seven thousand distinct pieces of software. Almost none of it has been vetted for which models it calls, what it’s permitted to do once it starts reasoning, or whether the vendor installed guardrails at all. Most of it is arriving through procurement and employee sign-ups rather than anything security reviewed.
That’s the picture Nick Warner of Neo and Max Pollard of Cotool laid out on a recent a16z podcast. Both spend their days watching enterprises try to defend against this, and both described the same gap.
Security teams built their tooling for two things: people, and malware. Agentic software is neither. It holds valid credentials, it acts at machine speed, and it does whatever the prompt in front of it suggests. As thousands of software instances turn agentic over the next couple of years, many companies will have no visibility into what any of it can actually do.
OUR TAKE
Your security tools work by guessing intent from behavior. Agents break that.
Defenses have evolved over the years. First came signatures, which looked for known bad code. Then came behavior-based tools, which decided how a piece of software should act and flagged anything else. Agents don’t have a normal way to act. They do whatever the prompt tells them.
As Pollard put it, “signatures are dead, and the attack surface is now the total sum of human expression.”
The best example on the podcast had no attacker. A company had planted fake AWS keys on a developer’s laptop as a trap. Nothing legitimate should ever touch them. Then a sales rep asked an internal agent to deploy something. The agent went looking for a way into AWS, found the fake keys, and used them. A detection that had never been wrong started firing all night. The security team spent hours chasing an agent doing what an employee asked it to do.
Nothing bad happened, but the alarm went off anyway. Now put that agent somewhere with physical consequences: a maintenance system that can file a work order, a logistics platform that can reroute a truck, or a procurement tool that can place an order.
Those are the deployments getting built this year, and the failure mode isn’t a data breach. It’s an agent doing something in the real world that a person half-asked for.
SCALING UP
Ready to work smarter? Here are the tools we’re tracking this week:
Augury reads vibration and sensor data off plant equipment and tells your maintenance team what’s failing, how urgently, and what to do about it. It ranks by urgency and names a root cause, which is the difference between a dashboard and a decision.
Claroty inventories the cyber-physical gear on your plant floor and watches what each one talks to. It discovers passively, so mapping the network doesn’t require touching a live line.
Oasis Security inventories every login in your stack that isn’t a person (service accounts, API tokens, agent credentials) and records what each is for. It rotates those secrets and scopes access by intent rather than a fixed role, so permissions don’t quietly widen.
PRODUCTIVITY POLL
Which of these can an AI agent already do in your operation without a person signing off?
HOT TAKES
Robot Safety Is Now A Public Company. FORT Robotics is going public via SPAC at a $500M valuation. The Philadelphia company doesn’t build robots. It builds the safety layer that lets other people’s robots operate around humans, and it has over 600 customers including Google DeepMind, Zoox, Ocado, Textron, and DoorDash. Mark Cuban is a returning investor. The signal: the first physical AI company to reach public markets sells trust, not autonomy. Every robot deployment needs somebody to sign off that it won’t hurt anyone, and that turns out to be a business. → Read more
Seeing Machines Points Its Cameras At Robots. The Australian computer vision company launched a Physical AI Platform for humanoids and industrial automation, extending 25 years of driver-monitoring work into robotics. Its driver and occupant monitoring tech already runs in more than eight million vehicles. The new platform builds a live 3D map of people, objects, and space so a robot can read human behavior rather than just detect obstacles. Target markets are manufacturing, logistics, warehousing, mining, and aged care. The read: a company with a decade-old sensing business in cars just found a second market for the same core capability. That’s the physical AI playbook incumbents can actually run. → Read more
Google Is Buying A Dead Airline’s Operational Data For $10 Million. Google outbid Mercor for bankrupt Spirit Airlines’ internal business data, a trove that includes 500M Microsoft Teams messages, roughly 176K employee records, and nearly 100M passenger names. Google says the enterprise dataset will improve its products and AI models and that it won’t receive personal information. The flight attendants’ union objected, and a bankruptcy judge pushed the hearing to September 9. The signal for operators: someone just put a price on how an airline actually runs. Your Slack archives, ticket queues, and internal threads are a training asset with a market, and right now, the only companies discovering that may be the ones in Chapter 11. → Read more


