The principle
AI may reason about a manufacturing situation. AI must not directly control physical machinery. The output of a language model is never a machine command: it is at most a recommendation that a person or a deterministic system evaluates.
A layered pipeline
A safe design separates the stages. AI reasoning produces a recommendation. A validated engineering algorithm computes any candidate adjustment. A simulation predicts its effect. A policy guardian checks it against authorised limits. Deterministic control close to the machine executes it. The result is then verified.
Each stage after the AI step is deterministic and testable, so its behaviour can be proven without relying on model behaviour.
Limits and approval
Authorised limits are set by qualified people. An adjustment within limits may be allowed; one outside them requires human approval; one outside absolute bounds is rejected and cannot be approved. The default is to deny.
Typical limits include absolute bounds for a parameter, the largest single step, the largest cumulative change within a time window, and whether autonomous execution is enabled at all for that parameter.
Interlocks and degraded conditions
Stale data, degraded connectivity or a machine that is not ready must cause an adjustment to be rejected rather than guessed. Safe behaviour must also survive loss of connectivity: control that runs near the machine must not depend on a cloud connection to stay safe.
Auditability
Every recommendation should cite its evidence and confidence, and every action should be attributable to a human, system, agent or integration in an immutable history. This makes behaviour reviewable after the fact, which matters in regulated manufacturing.
Standards and further reading
- IEC 61508 — Functional safety of electrical/electronic/programmable electronic safety-related systems
- ISO 13849-1 — Safety of machinery: safety-related parts of control systems