Keep Factory AI Advice Outside the Control Loop

Design useful manufacturing AI around approved information, controlled connections and clear human authority before considering any influence on plant operation.

By dotSuper Research DeskPublished Sep 15, 2026Updated Sep 15, 20265 min read
Applied systemsPrimary sources with dotSuper analysisUpdated Sep 15, 2026

/ THE SHORT ANSWER

Key takeaways
  • 01Separate advisory outputs from commands and setpoint changes.
  • 02Design document and data transfers before enabling connectors.
  • 03Test failure handling alongside answer quality.
  • 04Require engineering approval when the operating role changes.

/ dotSuper point of view

The valuable first boundary is between helping a person understand equipment and granting software authority over physical operations.
01Orient

Choose one useful answer, then draw its boundary

A supervisor may simply want to find the approved changeover document for a machine variant.

That bounded question creates a different project from automatically adjusting the line.

Write the permitted output in a sentence.

For example: retrieve the current approved changeover reference and show its machine applicability.

Then write the forbidden actions: change setpoints, bypass an interlock, publish an engineering revision or authorise a restart.

Make both statements visible in the implementation brief.

ACSC's OT principles place safety and business understanding at the centre of decisions, including protection of OT data.[

1] Our interpretation is to begin with the consequence of a wrong answer.

That consequence determines the evidence and review needed before anybody acts.

02Signal

Make the information path a design decision

Map where manuals, drawings, maintenance notes and live telemetry currently sit.

Distinguish a controlled document copy from a connection into an operational network.

Consider whether the question can be answered from a reviewed export.

A document library updated through an approved process may meet the need.

Live data should require a specific operational reason, a defined owner and engineering agreement on how the transfer behaves during faults.

The joint AI-in-OT guidance discusses risks including model drift and safety-process bypasses.[

2] This supports examining how the complete arrangement could fail.

It does not establish that a particular architecture is safe merely because the model only reads data or runs on a separate computer.

03Prove

Specify what the operator sees

If two manuals disagree, display that conflict and route the question to the document owner.

A fluent synthesis that hides the disagreement removes information the operator needs.

Avoid a generic confidence percentage as the main safety cue.

Confidence in generated text is different from evidence that a procedure applies to this serial number.

Ask for observable evidence instead: exact source, revision date, equipment match and missing prerequisites.

Separate navigation assistance from procedural instruction in the interface.

An assistant can help somebody locate a procedure without rewriting its critical steps.

Where a summary is allowed, label it and provide immediate access to the controlled document that governs the work.

04Resolve

An original boundary review for each proposed feature

A button that begins as 'create a draft work order' may later acquire approval or dispatch behaviour.

The release note should explain changes in operational consequence, not just improvements in convenience.

Use the table to decide which role must review the change.

The suggested outcomes are implementation recommendations.

They do not replace site procedures, engineering standards or a qualified assessment of the equipment and its operating environment.

Proposed feature boundary review
FeaturePotential consequenceRequired design decision
Find a manualWrong revision reaches a userMatch asset and approval status
Summarise a work orderImportant context disappearsRetain original and reviewer
Read current telemetryNew network dependencyApprove the transfer architecture
Draft a maintenance taskAdvice becomes planned workRequire authorised task approval
Change a setpointPhysical process changesSeparate engineering safety assessment
05Orient

Hypothetical scenario: a convincing wrong manual

One has a modified guarding arrangement.

The assistant retrieves the original manufacturer's manual because its title closely matches the operator's question, while the site modification is documented elsewhere.

The correct test is not whether the answer sounds technically plausible.

The team checks whether the system recognises the asset identifier and the existence of a site-specific controlled procedure.

If it cannot establish applicability, the answer should stop at identifying the unresolved documentation issue.

The plant adds equipment identifiers and links approved modifications to the document register.

Its acceptance exercise includes both sealers, an unknown identifier and an obsolete manual.

This tests the information boundary without deliberately creating a dangerous condition or experimenting on operating equipment.

06Signal

Define failure behaviour before increasing reliance

Write down the fallback for each.

A missing library should produce an unavailable state and the existing authorised information route, not a plausible answer from general model knowledge.

There is a tradeoff between limiting access and answering every question.

Accept some unanswered requests when broad access would expose control systems or restricted customer information.

Record those requests to discover whether a smaller approved information set can meet the recurring need.

Begin with a document retrieval demonstration using approved copies and representative questions.

Have an operator and engineer jointly evaluate applicability, clarity and refusal behaviour.

Expand the scope only after the business can describe the new consequences and show how its controls address them.

What this page cannot conclude

  • 01The cited OT guidance addresses critical infrastructure and is applied here as design guidance, not a universal SME legal mandate.
  • 02This article is not a machinery safety assessment.
  • 03No live plant connection or vendor product was tested.
  • 04This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.

Sources

  1. 01Principles of operational technology cyber securityAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026
  2. 02Principles for the secure integration of Artificial Intelligence in Operational TechnologyAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026

This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.

Our editorial standard · Found an error? Send a correction with its source.

/ CITE OR SHARE THIS GUIDE

Make the evidence easy to verify.

When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.

Suggested citation

dotSuper Research Desk. (September 15, 2026). Keep Factory AI Advice Outside the Control Loop. dotSuper. https://dotsuper.net/feeds/applied-systems/australia-factory-ai-operational-technology-boundaries

Share on LinkedIn
A focused implementation decisionKeep Factory AI Advice Outside the Control Loop

/ APPLY THE THINKING

Draw your factory AI boundary before connecting

Bring a maintenance or production information workflow to a dotSuper AI Readiness Sprint and define its data path, human decisions and engineering review points.

Question for the working sessionHow should an Australian manufacturer separate useful factory AI advice from authority over operational equipment?

/ Topic-led working session · Keep Factory AI Advice Outside the Control Loop

Turn this question\ninto a useful first move.

Bring how this question currently shows up in your business: “How should an Australian manufacturer separate useful factory AI advice from authority over operational equipment?” We’ll test the page’s evidence against your context and define the smallest useful next move.

Live availability from ceo@dotsuper.net Automatically converted · your local time
  1. 01Bring the contextWhere this issue shows up in the work.
  2. 02Test the relevanceUse the evidence against your reality.
  3. 03Choose the next moveOne accountable action, clearly owned.
Live availability
  1. Date
  2. Time
  3. Booked

Syncing live times