Executive summary
Brian Comiskey, Vice President of Innovation & Trends at the Consumer Technology Association, expects CES 2027 to show AI moving from assistant to actor, across multi-agent software, specialized models and robots. His answer to the trust problem comes from cybersecurity rather than from AI, and it points to a practical discipline for any organization delegating work to machines.
Brian Comiskey has a compact way of describing what artificial intelligence does to a machine. Robots, he told me, used to be hardware with a single function: input A, output B.
“When you add artificial intelligence on board, you get input A, outputs B through infinity.”
Brian Comiskey, CTA
Comiskey is Vice President of Innovation & Trends at the Consumer Technology Association (CTA), the owner and producer of CES. We spoke in Paris on 16 September, shortly after his CES Tech Trends presentation at FDDay, France Digitale’s annual startup gathering and the first stop on the road to CES 2027. The shift he expects the show to make visible is AI moving “from assistant to actor,” or, in his other phrase, “digital delegation”: handing our day-to-day tasks to machines rather than asking them for suggestions.
The distinction sounds semantic until you look at what it changes. An assistant produces an answer that a person still has to act on. An actor turns that answer into a booking, a payment, a code change or a movement in the physical world. The underlying model may barely differ between the two. What changes is the range of things the system can do, and the number of steps at which nobody is checking.
Many agents, many models
Comiskey expects AI to appear in virtually every section of the CES 2027 show floor. The most explicit expression of the agentic shift will be at CES Foundry, the show’s AI and quantum area, which will include its own agentic AI section. In his view, the point of that section is not to showcase another chatbot, but the function and work an agent actually performs.
He also expects the architecture to become more crowded. “We’re quickly realizing, like the cloud, where we don’t just use one cloud, we use multi-cloud solutions,” he said. “We’re going to move to a multi-agent ecosystem.” Drug discovery and personalized medicine are among the fields where he expects that ecosystem to matter early, because they call for many agents running calculations at the same time.
The models underneath are diversifying as well. Comiskey’s second AI pathway for the show is vertical AI: systems designed for a specific industry or function, which may run on a small language model or a vision-language-action model rather than a general-purpose large language model. He expects the AI of the coming years to be a synthesis of several kinds of models, and he points to Caterpillar, which has built an AI-assisted tool around its own construction and industrial work.
Put the two trends together and the unit of trust changes. A single enterprise workflow may soon involve agents from several vendors, calling several models, reading data they did not produce and handing work to one another. The cloud comparison holds in a second sense. Multi-cloud turned security from a perimeter question into an orchestration question, and multi-agent systems will do the same, with one difference: their components do not simply store and compute. They decide what to do next.
When the action leaves the screen
Comiskey is glad the industry now speaks of physical AI rather than simply robotics, because the broader term covers what matters: robots, but also robotaxis, drones and “basically any sort of autonomous action.” In CTA’s framework, AI is a foundation technology. Physical AI is a transformation technology, the point at which foundations are combined to change something in society.
Humanoids will again draw crowds in Las Vegas, but Comiskey expects them to follow a specific path: industrial first, then enterprise, then consumer. Industrial deployments are already under way, with companies such as Agility Robotics operating in warehouses, and enterprise is the next pivot. The household humanoid is the long bet, “2029 at the earliest, 2030s most likely” in his estimate, largely because few companies are focused on the consumer market yet, and innovation accelerates only once more entrants arrive.
The more immediate story, in his view, is one that rarely makes headlines: dexterity, or simply how well a robot’s hand, arm or foot moves. It matters even if humanoids take years to reach mass adoption, because these components can be deployed on their own, and companies such as Sharpa have made them their focus. Comiskey pictured a hand that clears objects out of the path of a robotic vacuum, or a pair of hands that folds laundry. “You don’t actually need the whole robot,” he said. “You might just need this.”
What makes this possible, Comiskey argues, is multimodal AI: models that interpret “not just text and language, but images, movement,” fused together rather than handled separately. Language models help machines interpret instructions. Model fusion is what allows them to act in an environment that keeps moving.
This is where input A, outputs B through infinity stops being a figure of speech. A wrong recommendation costs a correction. A wrong turn, a wrong grasp or a wrong movement near a person can cost something no correction will undo.
Building in the absence of trust
When I asked how trust should evolve as AI becomes more autonomous, Comiskey reframed the question. “We think AI trust a lot,” he said. “I come from a cybersecurity side, so I think zero trust immediately.” The question that matters, in his words, is “how do you build in the absence of trust?”
In his view, cybersecurity’s biggest innovation was not only technological but architectural and behavioral: zero trust, which stops assuming that a request is legitimate because it appears to come from inside the organization. He expects that school of thought to enter AI, starting with AI-enabled cybersecurity. The principle is well established. NIST’s Zero Trust Architecture guidance, Special Publication 800-207, published in 2020, moves security away from trust inferred from network location and toward least-privilege access decisions made for each request.
The second layer he expects is provenance, a word he borrows from art history and applies to AI-generated images and text: how do you know whether something was produced by a human or a machine? Part of the answer will be technical, and AI itself will contribute through watermarking and authentication. His summary is the most practical formulation of the problem I have heard:
“Technology, whether that’s AI itself, blockchain or another, is going to play a critical role in affirming trust where we need it, and then operating in zero trust when we need to.”
Brian Comiskey, CTA
Zero trust, applied to action
Comiskey was speaking mainly about content and cybersecurity. I believe his framing extends directly to agents, and it complements an argument I made earlier this year: identity is not authority. A chain of authority defines what an agent is mandated to do, on whose behalf and within which limits. Zero trust governs everything the agent touches along the way: the tools it calls, the data it reads and the other agents it works with. Four working rules follow.
1. No trust by origin. An agent is not trustworthy because it runs inside your cloud, comes from a known vendor or is built on a leading model. Each consequential request should be evaluated on its own terms, as zero trust already requires for users and devices.
2. Provenance for instructions, not only for content. An agent that reads an email, a web page or another agent’s output can be steered by what it reads. Inputs should carry their origin, and nothing arriving from outside the trust boundary should be executed as a command.
3. Least capability by design. Vertical AI is usually presented as a performance choice. It is also a security choice: an agent built for one function should hold only the tools, data and actuators that function requires, and nothing it could be talked into using.
4. Assume the system will be wrong, and size the consequences before deployment. Ask what the agent can reach, how fast it can act and what can be undone. If the honest answers are “everything,” “instantly” and “nothing,” the design is not ready, however good the model.
Automated finance learned this lesson long before generative AI. In the first 45 minutes of trading on 1 August 2012, a software error in Knight Capital’s automated order router turned 212 customer orders into millions of orders sent to the market and more than four million executions, and the firm lost more than $460 million. In its 2013 order, the U.S. Securities and Exchange Commission found that an assessment of Knight’s controls had focused on confirming that they worked as intended, without considering what a malfunction in the routing system itself could cause. The order also notes that Knight’s primary risk-monitoring tool relied on people to spot trouble, with no automated alerts, and that the firm had no procedure to halt the router when its own activity turned aberrant. No AI was involved, yet it remains the clearest illustration I know of input A, outputs B through infinity.
What to watch at CES 2027
Comiskey’s test for the agentic section at CES Foundry is the work an agent actually does. I would add a second question for every demonstration: what is the agent prevented from doing, and how would anyone know? The companies with a convincing answer are building what enterprises will need next.
Zero trust never meant trusting nothing. It meant that trust is earned continuously, request by request, instead of being granted once at the perimeter. As AI moves from assistant to actor, in software and in the physical world, the same discipline will have to apply action by action. That, more than the next gain in model intelligence, will determine how much delegation organizations can safely accept.
