The Case.
The industry pays to carry what it never uses. We drop the ballast — provably.
A structural failure of framing.
Physical AI programs fight over BOM cents and feature demos while five cost pools ride along unexamined: compute that waits, data that sleeps, updates that crawl, spares bought per box, capacity that parks. This is not an oversight by one company — it is a structural failure of how the industry frames value. The Case is the argument, lever by lever.
You have seen these two shapes before — the carriage and the Enterprise. Most fleets still ride the carriage.
Cut the tow line, lever by lever.
Today's L3-class programs ship a second computer that rides along as ballast. N:1 clusters make one standby carry many workloads.
Deep dive
A 1:1 standby is capital that waits for a failure that rarely comes. In a hyperconverged cluster, one spare node backs three or four live ones — and the failover itself leaves evidence. Shared redundancy is acceptable exactly because an evidence apparatus rides with it; that is why this lever and the assurance layer are one product. The zonal node →
Fleets pay transit and forever-storage for data that goes unread. Edge inference ships the needles.
Deep dive
Corporate reality: uploaded data is almost never deleted — you pay the cloud forever. Inference at ingress keeps the haystack local and forwards what matters; every disengagement arrives as a free, fleet-scale label. Real-world data, at the cost of the needles alone. The harvester →
Reported industry cases put over-the-air updates past ten hours. Cutover on the node takes a reboot.
Deep dive
Updates that crawl across ECUs on low-capacity links deplete batteries and have produced recall-class costs. On the node, the new version is pre-staged and shadow-tested; cutover is a boot-order change — under a minute by design — and rollback is the same move reversed. Rollback, not recall →
Spare capacity bought box-by-box is expensive. Bought once, in a consolidated node, it is marginal — and it powers levers 1 and 3.
Deep dive
The same headroom serves failover AND instant updates: one overprovision, two capabilities. Per-ECU, this economics never closes; consolidated, it is the cheapest insurance in the vehicle.
Household vehicles sit parked ~95% of the day (FHWA 2022). Aware, partitioned capacity can work — for the user, and on the roadmap, for the balance sheet.
Deep dive
The Anticipation Layer makes the endpoint aware of its network ahead — caching before dead zones, offering bookable coverage for a road trip leg, and (roadmap) renting partitioned idle compute as an OEM TCO offset. The product anticipates the user, the environment, the mission — what "AI-defined" should have meant all along. The Anticipation Layer →
Dropped ballast is not five savings — it is one flywheel. Evidence wins adoption; adoption feeds the data network; needles make the product better; a better product earns more missions; every mission leaves more evidence. Physical AI that gets better every day — provably.
The second lever: the ARR envelope.
Dropping ballast is only half the case. The other half is what an improving product is allowed to charge. Products frozen at start of production give customers no reason to subscribe — hardware margin, once, then silence. Products that visibly improve can carry recurring revenue: the best-known driver-assistance subscription sells at roughly $99 per month because it adds value to the owner's day, every month (as reported, Jul '26). That is the ARR envelope: the recurring revenue a physical product could carry if it kept getting better.
In regulated physical AI there is a gate in front of that envelope: improvements only ship if every release clears evidence an assessor will accept. The evidence layer is the license to iterate — the thing that converts continuous improvement from an engineering capability into a shippable, chargeable cadence. Our platform's levers feed the improvement (harvester, shadow, cut-over); our evidence layer makes shipping it routine. Illustrative scale: a 100,000-unit fleet at a $30–100/month feature attach is a $36–120M-per-year envelope for one product line — customer revenue, unlocked, not ours illustrative.
Dual use, same lever: in defense the envelope is capability sustainment — models that learn from contested operation, shipped as evidence-gated capability updates under sustainment contracts, raising mission success release over release.
One platform, two levers — cost out of the product, recurring revenue into it. Both compound through the same flywheel.
The market this unlocks.
We size this market the honest way: count the units we invoice, multiply by our price card. Machines-era: ~$2.2B per year across roughly 2,450 assurable programs and eight million nodes — bottom-up, methodology on request. The obtainable slice is deliberately the smallest number on the chart: $2.6M to $86M by year three (BASE to VENTURE case, named assumptions) — supply-limited by design, because audits are delivered by engineers, not downloaded. For calibration: that range brackets a top-decile year-three trajectory for enterprise deep tech; most eventual category leaders crossed year three below $10M. And when the cockpit era attaches — ~50 million cockpit controllers shipping annually by 2030 — the ceiling moves toward $40B per year: a ceiling, not a forecast — attach is the only variable that matters. Methodology on request.
Start where the evidence starts.
Evidence Readiness Assessment — $45,000 · one item, one program, one release