/ THE SHORT ANSWER
- 01Separate advisory outputs from commands and setpoint changes.
- 02Design document and data transfers before enabling connectors.
- 03Test failure handling alongside answer quality.
- 04Require engineering approval when the operating role changes.
/ dotSuper point of view
The valuable first boundary is between helping a person understand equipment and granting software authority over physical operations.
Choose one useful answer, then draw its boundary
A supervisor may simply want to find the approved changeover document for a machine variant.
That bounded question creates a different project from automatically adjusting the line.
Write the permitted output in a sentence.
For example: retrieve the current approved changeover reference and show its machine applicability.
Then write the forbidden actions: change setpoints, bypass an interlock, publish an engineering revision or authorise a restart.
Make both statements visible in the implementation brief.
ACSC's OT principles place safety and business understanding at the centre of decisions, including protection of OT data.[
1] Our interpretation is to begin with the consequence of a wrong answer.
That consequence determines the evidence and review needed before anybody acts.
Make the information path a design decision
Map where manuals, drawings, maintenance notes and live telemetry currently sit.
Distinguish a controlled document copy from a connection into an operational network.
Consider whether the question can be answered from a reviewed export.
A document library updated through an approved process may meet the need.
Live data should require a specific operational reason, a defined owner and engineering agreement on how the transfer behaves during faults.
The joint AI-in-OT guidance discusses risks including model drift and safety-process bypasses.[
2] This supports examining how the complete arrangement could fail.
It does not establish that a particular architecture is safe merely because the model only reads data or runs on a separate computer.
Specify what the operator sees
If two manuals disagree, display that conflict and route the question to the document owner.
A fluent synthesis that hides the disagreement removes information the operator needs.
Avoid a generic confidence percentage as the main safety cue.
Confidence in generated text is different from evidence that a procedure applies to this serial number.
Ask for observable evidence instead: exact source, revision date, equipment match and missing prerequisites.
Separate navigation assistance from procedural instruction in the interface.
An assistant can help somebody locate a procedure without rewriting its critical steps.
Where a summary is allowed, label it and provide immediate access to the controlled document that governs the work.
An original boundary review for each proposed feature
A button that begins as 'create a draft work order' may later acquire approval or dispatch behaviour.
The release note should explain changes in operational consequence, not just improvements in convenience.
Use the table to decide which role must review the change.
The suggested outcomes are implementation recommendations.
They do not replace site procedures, engineering standards or a qualified assessment of the equipment and its operating environment.
| Feature | Potential consequence | Required design decision |
|---|---|---|
| Find a manual | Wrong revision reaches a user | Match asset and approval status |
| Summarise a work order | Important context disappears | Retain original and reviewer |
| Read current telemetry | New network dependency | Approve the transfer architecture |
| Draft a maintenance task | Advice becomes planned work | Require authorised task approval |
| Change a setpoint | Physical process changes | Separate engineering safety assessment |
Hypothetical scenario: a convincing wrong manual
One has a modified guarding arrangement.
The assistant retrieves the original manufacturer's manual because its title closely matches the operator's question, while the site modification is documented elsewhere.
The correct test is not whether the answer sounds technically plausible.
The team checks whether the system recognises the asset identifier and the existence of a site-specific controlled procedure.
If it cannot establish applicability, the answer should stop at identifying the unresolved documentation issue.
The plant adds equipment identifiers and links approved modifications to the document register.
Its acceptance exercise includes both sealers, an unknown identifier and an obsolete manual.
This tests the information boundary without deliberately creating a dangerous condition or experimenting on operating equipment.
Define failure behaviour before increasing reliance
Write down the fallback for each.
A missing library should produce an unavailable state and the existing authorised information route, not a plausible answer from general model knowledge.
There is a tradeoff between limiting access and answering every question.
Accept some unanswered requests when broad access would expose control systems or restricted customer information.
Record those requests to discover whether a smaller approved information set can meet the recurring need.
Begin with a document retrieval demonstration using approved copies and representative questions.
Have an operator and engineer jointly evaluate applicability, clarity and refusal behaviour.
Expand the scope only after the business can describe the new consequences and show how its controls address them.
What this page cannot conclude
- 01The cited OT guidance addresses critical infrastructure and is applied here as design guidance, not a universal SME legal mandate.
- 02This article is not a machinery safety assessment.
- 03No live plant connection or vendor product was tested.
- 04This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01Principles of operational technology cyber securityAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026
- 02Principles for the secure integration of Artificial Intelligence in Operational TechnologyAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Keep Factory AI Advice Outside the Control Loop. dotSuper. https://dotsuper.net/feeds/applied-systems/australia-factory-ai-operational-technology-boundaries