Manufacturing has a division that few other sectors have. On one side is operational technology: control systems, sensors, predictive maintenance and quality control with image recognition. Those systems are often formally procured, built into machines or production lines, and subject to existing engineering and safety procedures. On the other side is the office and staff environment: purchasing, planning, engineering support, customer contact and administration. There, generative AI appears in the same way as in any other organisation — through a browser, a separate account, a separate subscription.
The balance between those two layers determines how a governance approach needs to be set up. Where operational technology is relatively well documented because it is part of capital investments and maintenance contracts, the office layer is often not recorded anywhere. Anyone who only looks at the production line sees a fraction of what is used in terms of AI across the organisation.
An overview of approved software rarely tells the whole story. An engineer having a drawing summarised, a planner using an AI tool to rearrange delivery schedules, a buyer having quotes compared by an external model — this often happens without a request being submitted or a licence being registered. That is not negligence; it is a practical consequence of time pressure and the availability of free or cheap tools.
For a director or risk manager, this shadow AI is the real point of attention. The question is not only what the organisation has procured, but what is used daily to get work done faster. Finding that out requires a different approach than a technical audit: it requires people to be willing to share what they use, without the conversation feeling like an obligation to account for themselves. Asking "who has used something here without permission" gets no answer. Asking "what do you use to do your work" does get an answer.
Not every use of AI in manufacturing carries the same weight. An AI application that contributes to design validation or quality control of an end product touches on safety and liability in a different way than a tool that drafts an email to a supplier. A system that influences production planning can have consequences for delivery times and contractual obligations; a tool that summarises internal notes usually does not.
This differentiation is the basis of classification: not all AI use needs the same level of oversight, but the distinction does need to be made, and based on what the system does and what it affects — not on where it was procured. A tool downloaded by an individual employee can have just as much influence on the output delivered to a customer as a system procured through a formal process.
Manufacturing rarely operates in isolation. Suppliers, subcontractors and customers are part of the same process, and AI use at one of those parties can affect what an organisation itself delivers. If a supplier uses AI to interpret specifications or generate quality reports, a dependency arises that is not visible in the organisation's own systems, but is nonetheless relevant to whoever bears responsibility for the end product.
This is a difference from sectors where the primary process largely takes place within the organisation's own walls. A governance approach for manufacturing must therefore not only map internal use, but also form a picture of where in the supply chain AI plays a role in decisions that ultimately concern the organisation.
Most manufacturing companies already have risk structures: for product safety, for quality management, for supplier assessment. AI governance works better when it connects to what already exists, rather than becoming a new, isolated process. A classification of AI applications by risk level can, for example, be linked to existing supplier assessment criteria or to the quality management system, so that reporting to the board or supervisory board is not set up as a separate track alongside existing lines of accountability, but is incorporated into them.
Exactly how that connection takes shape differs per organisation and depends on the existing governance setup. Other sectors face comparable issues from a different structure: in the transport sector a similar tension exists between operational systems and office use, in the agricultural sector supply chain dependency is often even more directly noticeable, and in professional services the operational layer is largely absent, which means shadow AI is virtually the only layer to map there.
An inventory of AI use and a classification by risk give an organisation insight into what is going on and where oversight is needed. That question is closely related to another question many manufacturing companies ask themselves: which part of the work itself, at the level of individual tasks, can actually be taken over by AI. Where governance maps out what is happening and who bears responsibility for it, the work scan from FTE TO AI calculates per task which part actually qualifies for takeover — a question that can only properly be answered once it is first clear what is already running.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.