Governance as the operating foundation for industrial AI

As agents, digital twins and Physical AI take on greater operational responsibility, manufacturers need governance that aligns autonomy with risk, accountability and trust
Abonnieren
6 min 50 sec Lesen
Kanishka Bhargava
Kanishka Bhargava
Vice President, HCLTech
6 min 50 sec Lesen
microphone microphone Artikel anhören
30 s zurück
0:00 0:00
30 s vor
Governance as the operating foundation for industrial AI

Industrial AI is moving closer to the physical processes that determine output, quality, safety and cost. Digital twins can help teams evaluate operational scenarios, intelligent agents can coordinate decisions across systems and Physical AI can perceive conditions and act within factories, warehouses and other industrial environments.

HCLTech’s  report found that 90% of respondents expect to be an important technology evolution for their organization to master over the next three years. At the same time, HCLTech’s  research found that only 17% of organizations show high confidence in actions initiated by AI agents. Together, these findings point to a gap between the ambition to create more autonomous operations and confidence in allowing AI to act.

The challenge extends beyond industrial AI. An  found that while 87% of business executives believe principles are critical to adopt, 85% say they are not well prepared to implement them. This readiness gap reinforces the need to develop governance capabilities alongside AI adoption rather than after systems have already scaled.

That gap has particular significance in industrial environments. An incorrect recommendation in an office application may create rework, while the same failure on a production line could damage equipment, waste materials, interrupt output or expose workers to risk. Governance needs to develop alongside the technology so manufacturers can define how AI systems are introduced, monitored and given authority.

Small errors become enterprise risks at scale

One AI-enabled system operating within a controlled pilot is relatively easy to observe. A manufacturer can review its recommendations, compare them with operator judgment and intervene when performance falls below expectations. The challenge changes when hundreds of models, agents and connected machines are distributed across assembly lines, warehouses, maintenance processes and quality functions.

At that scale, no individual or central team can monitor every decision in real time. A small error that appears manageable in one plant can become a material problem when repeated across multiple sites, while unclear ownership can leave teams uncertain about who is responsible for a recommendation affecting safety, quality or production.

Governance provides the shared operating rules needed to manage that expansion. It should establish:

  • Who can deploy, activate or change an AI system
  • What data the system can access and learn from
  • Which machines, applications and workflows it can influence
  • Who is accountable for its recommendations and actions
  • How performance, exceptions and incidents will be reviewed
  • What happens when the system produces an incorrect or unsafe result

Making those decisions early reduces ambiguity as AI moves into wider production. It also helps manufacturers avoid replicating unresolved weaknesses across their networks, where a failure in trust can be as damaging as a failure in technology.

Match autonomy to risk and reversibility

Manufacturers should avoid treating autonomy as a single decision applied equally across every use case. The appropriate level of human oversight depends on the potential impact of an error and how easily an action can be reversed.

A low-risk adjustment within a defined operating range may eventually be suitable for autonomous execution. Changing warehouse heating or cooling settings and completing routine inventory actions within approved thresholds are examples of decisions that can be monitored, logged and corrected without placing production or safety at significant risk.

The model changes when AI begins influencing operational performance. Adjusting assembly-line pacing, changing process temperatures or recommending chemical feed rates can affect throughput, scrap, equipment effectiveness and product quality. In these situations, AI may prepare an action plan, while an experienced operator approves the recommendation before it reaches the control system.

Higher-risk decisions require stronger boundaries. Restarting a plant after a blackout, changing a core formulation or overriding a safety setting can be costly or difficult to reverse. Digital twins and AI models may support analysis and simulation, but accountable human leaders should retain control over execution.

A practical governance model can divide autonomy into three levels:

  1. Autonomous within limits: Low-risk, reversible decisions within predefined thresholds
  2. AI recommendation with human approval: Decisions that can materially affect production, quality or cost
  3. Human-controlled execution: Safety-critical, regulated or difficult-to-reverse actions

Emergency shutdowns, fire suppression, toxic-gas controls, personnel decisions and formal regulatory actions should remain clear boundaries for autonomous action. Autonomy can increase as a system demonstrates reliability in production, but manufacturers should expect an initial period of training, validation and human supervision. Trust needs to be earned through evidence rather than assumed from performance in a test environment.

Build controls into the operating architecture

Governance works best when embedded in the architecture and workflow from the outset, just like security. This allows controls to develop with the use case, reducing the risk that questions about data, access, accountability or recovery emerge only after the system has moved into production.

The National Institute of Standards and Technology’s (NIST) AI Risk Management Framework provides a useful reference point for integrating trustworthiness considerations into the design, development, use and evaluation of AI systems. In industrial settings, manufacturers can translate that approach into practical controls covering data access, model monitoring, decision traceability, human approval, security boundaries and recovery.

Several capabilities should form part of that foundation:

  • Data controls define what information the system can access, retain and use
  • Model and agent monitoring identifies drift, deteriorating performance and unexpected behavior
  • Decision traceability records the information, models, tools and rules behind an action
  • Approval controls introduce maker-checker processes where independent review is required
  • Security boundaries restrict the machines, applications and operational technology systems an agent can access
  • Recovery controls provide a tested route to reverse an action, restore a previous state or stop a system

Controls should be proportionate to the potential impact of each use case, meaning a low-risk application does not need to follow the same approval process as an AI system capable of changing a safety-critical production setting. Shared risk categories, reusable control patterns and clear approval routes can then help teams move faster without rebuilding the governance model for every deployment.

At HCLTech, our  is designed to help clients operationalize these principles across the AI lifecycle. Through our Office of Responsible AI and Governance, we support areas including AI maturity assessment, governance policy implementation, technical assessment and red teaming, AI management systems readiness and Responsible AI engineering. The framework is built around five core tenets: Accountability, Fairness, Security, Privacy and Transparency.

Extend security and accountability to the plant floor

As AI systems connect with enterprise applications and operational technology, their permissions become a direct security concern. An agent that can retrieve maintenance records, communicate with a production system and initiate workflow changes has a wider operational reach than a conventional analytical model.

Manufacturers need to define each agent’s identity and scope, restrict its permissions to the minimum required and monitor the actions it takes. Operational technology security must be built into the same governance model because scaling AI can create new connections into protected plant environments. As a result, architecture teams need to preserve network segmentation, tightly control inbound access and ensure AI services do not create unmanaged routes into production systems.

Decision ownership also needs to remain visible. A system may recommend an action, but the organization must still determine who is accountable for accepting the risk, approving execution and responding when something goes wrong. Greater autonomy makes a complete record of the decision chain and a clear route for escalation increasingly important.

Make operators part of the governance system

Policies and technical controls cannot capture every condition that influences plant performance. Experienced operators understand equipment behavior, process exceptions and local operating practices that may not be fully represented in maintenance records, data platforms or digital models.

Their involvement helps teams identify missing context, challenge weak recommendations and determine when a technically valid action may be operationally inappropriate. It also supports adoption because employees are more likely to trust a system when they understand how it reaches decisions and can see that their expertise has shaped its design.

That involvement should continue after deployment. Feedback from operators can reveal whether a model is producing too many false positives, recommending impractical actions or failing to account for changing plant conditions. Feeding that evidence into monitoring, retraining and governance reviews strengthens the link between technical performance and operational reality.

Measure whether governance is enabling scale

A governance framework should be judged by how well it supports safe deployment and sustained business value. Counting policies, committees or completed reviews provides little insight into whether the approach is working in practice.

More useful measures include:

  • Scale rate: The percentage of successful pilots that progress into production and expand across plants
  • Approval speed: The time required to review and clear a new use case at each risk level
  • AI incident rate: The frequency and severity of incorrect recommendations, unauthorized actions and operational exceptions
  • Trust and adoption: Whether operators and plant managers use the systems consistently or bypass them
  • Business performance: Whether governed deployments improve quality, throughput, cost, uptime or other outcomes at scale

These measures make governance part of the performance conversation. A mature framework should allow more approved use cases to move into production while reducing incidents, strengthening employee confidence and maintaining clear accountability.

will continue to take on more responsibility across production and operations. Manufacturers that define decision rights early, match autonomy to operational risk and integrate monitoring, security and recovery into the design will be better positioned to scale those capabilities safely.

Governance gives people and AI systems a common operating framework, helping manufacturers move beyond promising pilots while retaining the confidence of the teams responsible for keeping plants productive, secure and safe.

Fertigung und EUNR Fertigung Artikel Governance as the operating foundation for industrial AI