The Claim Under Test: A $50 Billion Number That Is an Advertisement
The statistic that anchors nearly every AI-for-manufacturing pitch traces to a paid advertisement placed by a company that sells the remedy. You have seen the number: unplanned downtime costs industrial manufacturers an estimated $50 billion a year. It appears in vendor decks, conference keynotes, analyst notes and the opening paragraph of almost every competing ranking. We followed it all the way down, and the bottom of the chain is not a study.
The trail begins with a genuinely respectable document. Deloitte University Press published Making maintenance smarter on 9 May 2017, and on page one it states that recent studies also show that unplanned downtime costs industrial manufacturers an estimated $50 billion each year, with a superscript pointing to endnote 2. In the PDF, endnote 2 resolves to: IndustryWeek and Emerson, “How manufacturers achieve top quartile performance,” WSJ Custom Studios, partners.wsj.com/emerson, accessed March 7, 2017. A second, independent Deloitte publication from the same year footnotes the identical source.
There is no source, no footnote, no sample, no population definition and no methodology anywhere in that chain, in any year. And here is the detail that turns an absence into a finding: the advertisement does cite sources for its other claims — a 2013 Solomon reliability-and-maintenance study, a DOE study. The one number with no citation is the one everybody quotes. That makes the omission conspicuous rather than accidental.
One practical warning for anyone re-checking this. The re-hosted HTML version of the Deloitte piece merges endnotes 1 through 4 into a single endnote, so on the live web page the $50 billion superscript appears to point at an unrelated 1994 item. That is a re-hosting artifact. The PDF numbering is authoritative, and the second Deloitte paper corroborates it.
There is a second, quieter reason to refuse it: scope drift. The advertisement says industrial manufacturers, in a document whose examples are refining, pulp and paper, and offshore oil — process industries. It is now routinely quoted as a fact about manufacturers generally, which includes the machine shop, the injection moulder and the fabricator this article is written for.
The credible primary source says something much more modest. NIST Advanced Manufacturing Series 100-34, by Douglas Thomas and Brian Weiss, published June 2020 with 2016 reference data, reports that the 2016 losses due to preventable maintenance issues amounted to $119.1 billion: $18.1 billion due to downtime, $0.8 billion due to defects, and $100.2 billion due to lost sales. The US government's own survey of discrete manufacturing puts downtime at $18.1 billion — roughly a third of the advertised figure — and only reaches the bigger headline by adding a far broader lost-sales construct. Carry NIST's own caveats when you use it: a total of 85 survey responses were returned, and the report's reactive-versus-preventive comparison is stated as association, not causation.
That is the shape of this entire market, and it is why this ranking exists in the form it does. If you want the cross-industry version of the same argument, we set it out in our 2026 survey of AI agents across every vertical we cover. The manufacturing edition is the one where the underlying numbers are worst.
How We Ranked, and What We Refused to Rank On
We scored only attributes you can re-check yourself in an afternoon, and we refused to score anything a vendor publishes about its own performance. Everything below was checked on 23 August 2026. Where a vendor does not publish something, the cell says “not publicly disclosed” in plain words rather than being filled with an estimate. We never estimate a price.
- Corporate status in 2026 — does the company still exist under that name, and who owns it, from public record: an SEC filing, a press release, a registry entry.
- Whether the product can write to the control layer, and through which protocol. This is the column that decides everything else, and almost nobody publishes it.
- Pricing transparency — published figures, a self-serve calculator, or contact-sales. Exactly one vendor in this roster publishes a price.
- Compliance and certification claims that appear on the vendor's own trust page, quoted as the vendor words them, with the difference between certified and supported preserved.
- Documented public integrations with a real documentation URL, not a logo wall.
- Deployment model — cloud, on-prem edge, or customer-hosted — and whether data residency or retention is committed anywhere.
- Whether any independent evaluation of the product exists. Across every vendor examined here, the answer was no.
- Honest category: is this an agent, a copilot, or classic machine learning with agentic branding applied retroactively?
What we never score: accuracy, downtime reduction, OEE improvement, ROI multiples, hours saved, or uptime percentages. Every published figure of that kind in this market is produced by the seller about itself, or by an analyst firm the seller pays. There is no independent benchmark of these commercial products in manufacturing — and unlike some adjacent fields, there is not even a model-level benchmark to fall back on. What exists instead is a peer-reviewed refusal, which we come to below.
There is also a general principle worth knowing, though it must be cited with care. The FTC's Operation AI Comply, announced 25 September 2024, was accompanied by the statement that using AI tools to trick, mislead or defraud people is illegal, and that the enforcement actions make clear there is no AI exemption from the laws on the books. That is consumer-protection enforcement against AI-hype schemes, not a finding about industrial AI performance claims. No such finding exists. Cite it for the substantiation principle — objective performance claims require substantiation, and calling something AI does not exempt it — and for nothing more.
How to re-check this article.Every claim in the table below resolves to a URL you can open: a vendor's own trust page, a documentation page, a pricing page, an SEC filing, a press release, a standards document or a Federal Register entry. If a cell disagrees with what you find in six months, the vendor changed, not the method. That is the point of scoring things that move slowly and publicly.
Four Numbers We Refuse to Print, and Exactly Why
Four statistics dominate manufacturing-AI content, and not one of them survives contact with its own source. We traced each to the earliest document that can be reached. Print none of them, and be sceptical of any vendor that does.
1. "$50 billion a year in unplanned downtime" — an Emerson advertisement
Covered above, and it is the strongest refusal available to anyone writing in this field. The terminal source is a WSJ Custom Studios Paid Programpage produced by IndustryWeek in collaboration with Emerson, a company that sells the predictive-maintenance products the number is used to justify. No methodology in any year. Against it stands NIST's measured $18.1 billion in downtime losses for US discrete manufacturing in 2016 — with 85 responses and an explicit association-not-causation caveat.
2. "Predictive maintenance cuts downtime 30–50% and extends machine life 20–40%"
The origin is McKinsey's Manufacturing: Analytics unleashes productivity and profitability, published 14 August 2017, which states that predictive maintenance typically reduces machine downtime by 30 to 50 percent and increases machine life by 20 to 40 percent. The article carries no endnotes or footnotes of any kind.There is no reference apparatus on the page at all — no sample, no period, no sector, no baseline, and no definition of “downtime” or “machine life.” It is a bare assertion. Its context is process manufacturing; the worked example is offshore oil and gas compressors. It is now quoted at discrete manufacturers daily.
And the attribution you will see most often is simply false: the claim is not in McKinsey's “Manufacturing's next act” (2015). We searched the full text. The phrase “predictive maintenance” does not appear in it at all, nor does “machine life,” “30 to 50” or “20 to 40.” Anyone citing that article for this number has not read it. That is a clean, checkable correction, and you can make it in a vendor meeting in thirty seconds.
3. The DOE savings table — five round numbers from unnamed surveys, at least 22 years old
The other authority routinely stapled to the same claim is the US DOE Federal Energy Management Program's O&M Best Practices Guide, Release 3.0 (August 2010), which at page 5.4 states that “independent surveys indicate” industrial average savings of a 10-times return on investment, a 25% to 30% reduction in maintenance costs, elimination of 70% to 75% of breakdowns, a 35% to 45% reduction in downtime, and a 20% to 25% increase in production.
The “independent surveys” are never named.Chapter 5's entire reference list contains two items — a NASA document from 2000 and a 2001 pump-industry web article — neither of which is a survey, and neither of which is attached to the list. It is not a study; it is a bullet list of round numbers. The identical paragraph with the identical five bullets appears in Release 2.0 from July 2004, carried forward verbatim without added sourcing, which makes the figures at least twenty-two years old. And the guide is about federal buildings and facilities, not discrete production lines. DOE's 35–45% and McKinsey's 30–50% are separate uncited assertions from different decades and different domains, now blended into a single “30–50%, per DOE and McKinsey” and attached to whichever authority sounds better. Neither authority published a method.
4. "2.1 million unfilled manufacturing jobs by 2030" — superseded, and using it in 2026 is an error of fact
The origin is a Deloitte and The Manufacturing Institutestudy published 4 May 2021 — note the partner is the Manufacturing Institute, the National Association of Manufacturers' workforce arm, not NAM itself, which is a common miscitation. The claim was explicitly conditional: left unabated, the skills gap could leave 2.1 million jobs unfilled by 2030. The method was two online surveys of 800-plus manufacturing leaders plus economic projections from Deloitte's economic team. That is a scenario model with an unpublished specification, not a measurement.
It was revised. Taking charge, published April 2024, states that the net need for new employees in manufacturing could be around 3.8 million between 2024 and 2033, and that around half of these open jobs — 1.9 million— could remain unfilled. The current figure is 1.9 million by 2033, not 2.1 million by 2030. Two things to carry with it: the 2024 sample of 200-plus manufacturers is roughly a quarter of the 2021 sample, so the revision rests on a smaller base; and Deloitte's own 2026 Manufacturing Industry Outlook repeats neither projection, discussing workforce qualitatively instead. The publisher has quietly stopped leading with the headline number, which is itself the story.
Two honest notes on OEE itself, because we would rather flag uncertainty than resolve it in our own favour. First, ISO 22400-2:2014 defines manufacturing KPIs and its ISO record shows stage 90.92, “International Standard to be revised” — but the KPI list itself sits behind a paywall, so we are not asserting from the free record what it does or does not define. Second, the famous “85% is world-class OEE” benchmark, universally attributed to Nakajima in 1988, is widely debunked in trade glossaries and practitioner posts on the grounds that it came from no empirical study. We could not verify that debunkagainst Nakajima's text or any peer-reviewed source. So we are not printing either side: it is currently practitioner folklore contradicting practitioner folklore, and saying that plainly is more honest than picking a winner.
The Comparison Table — Every Cell a Citation or “Not Publicly Disclosed”
Read the third column first. It is the one that decides how much autonomy is even available to you, and it is the one no competing ranking prints. Two facts in this table are worth more than any accuracy chart a vendor can produce, and you can verify both in under a minute: exactly one vendor here publishes a price, and exactly one publishes a documented control-layer write path.
| Vendor and 2026 ownership | What it actually is | Writes to the control layer? | Pricing | Compliance, in the vendor's own words | Independent evaluation |
|---|---|---|---|---|---|
| 1. Guidewheel — independent; no acquisition found | Classic monitoring and analytics. Not an agent, and does not claim to be | No — architecturally cannot. A clamp-on current sensor on the machine's power cord with no connection to the control system | PUBLISHED: starting at $15,000 per year, includes your first 10 machines. Pricing beyond 10 machines not publicly disclosed — guidewheel.com/pricing | Not publicly disclosed — no certification claims found on the vendor's own pages | None found |
| 2. Tulip Interfaces — independent; $120M Series D led by Mitsubishi Electric, 13 January 2026, $1.3bn valuation | A frontline app platform now marketed with AI. Operator-assist and digital work instructions, not an autonomous plant agent | YES — documented and narrowly scoped. Write Machine Attribute works only on OPC UA or MQTT datasources with Write explicitly enabled; Edge Devices, APIs, Celos and CelosX cannot be written to. Generic I/O driver sets digital output pins HIGH or LOW | Not publicly disclosed | Compliant with applicable SOC 2 controls and maintains a SOC 2 report (a 2022 press release names a SOC 2 Type 2 audit by MNP LLP); ISO 9001:2015; FedRAMP Moderate Equivalency per NIST 800-53 Rev.5; 21 CFR Part 11 features. ISO 27001 and IEC 62443 not listed — tulip.co/trust-center/compliance | None found |
| 3. MachineMetrics — independent; no acquisition found | Classic machine monitoring and OEE analytics for CNC machine tools | Not stated either way. The documentation describes data collection only, makes no read-only guarantee and no write claim. Several supported protocols are write-capable in principle — ask in writing | Not publicly disclosed | Not publicly disclosed to us — the vendor's Security & Compliance article returned HTTP 403 to automated fetch; a human should open it directly | None found. Peer-review sites carry user reviews, not benchmarks |
| 4. Augury — independent; $75M Series F led by Lightrock, 19 February 2025, $1bn+ valuation | Condition monitoring with an agent layer added on top. The vibration-analysis product long predates the word agentic | No claim of control-layer writes. The vendor's autonomous action language describes multi-step tasks across software systems; its pages do not specify writing to control systems | Not publicly disclosed | ISO 27001:2022, ISO 9001:2015, ISO 80079-34, GDPR, CCPA, EcoVadis rating. SOC 2 Type II is NOT published on the trust centre despite being widely repeated — augury.com/trust-center | None found. A commissioned Forrester TEI study is not independent |
| 5. Limble — independent CMMS | CMMS with AI helpers: AI-Powered PM Builder on all tiers, AI Duplicate Work Request Prevention and AI Scheduling Suggestions on Enterprise. Not an agent | No — a CMMS writes work orders, not setpoints | Not publicly disclosed, but a self-serve price calculator is provided rather than a contact-sales wall. Third-party per-user figures are not from Limble — limble.com/pricing | Enterprise tier lists 21 CFR compliance and SSO as features. No SOC 2 or ISO 27001 verified | None found |
| 6. Rockwell Automation Fiix — Rockwell-owned since December 2020 (agreement announced 17 Nov 2020; Form 10-Q records the acquisition in Dec 2020, terms not disclosed) | CMMS with AI features, marketed with a maintenance copilot. The agentic surface is work-order generation — a software write, not a control write | Not verified; a CMMS ordinarily does not write to controls | Not publicly disclosed | Not verified | None found. Vendor releases headline customer downtime-reduction targets, which are targets rather than measured results |
| 7. Sight Machine — independent | An analytics and data-unification platform now marketed as agentic: agents investigate production, find where it can improve, and propose how | No, and the vendor says so clearly: validated findings become live recommendations that operations teams act on directly. Agents propose, humans act | Not publicly disclosed | Not verified — the security URL is a vulnerability-reporting form rather than a trust page | None found. A Most Innovative Companies listing is a press award |
| 8. Siemens — Senseye Predictive Maintenance and Industrial Copilot (Senseye a 100% Siemens subsidiary since 1 June 2022) | Copilot, by Siemens' own framing. Variants across Design (NX), Planning, Engineering (TIA Portal), Operations (Insights Hub) and Services/Maintenance (Senseye) | Advisory and human-gated. Siemens' own sentence: users retain complete control, selecting which tasks they wish to delegate to AI agents. Engineering Copilot generates automation code for an engineer to review | Not publicly disclosed | Not verified | None found. The 2022 release's up-to-50% downtime claim is a vendor claim with no floor and no methodology |
| 9. Instrumental — independent; electronics and contract-manufacturing inspection | Computer-vision defect detection with AI-branded modules (Trace base platform plus Discover AI, Operate AI, Solve AI) | Not verified, and the language is genuinely ambiguous: the site offers to deploy production controls that intercept issues, which could mean a gating action or something narrower. Ask | Not publicly disclosed; volume tiers are described (from 10M signals, from 10K images) without figures — instrumental.com/pricing | No SOC 2 Type II or ISO 27001 published on the security page. But it is the only verified customer-hosted option in this roster: self-host in your own AWS environment, plus an ITAR-compliant GovCloud environment | None found |
| 10. Cognite — independent, majority-backed by Aker (Oslo) | An industrial data platform (Cognite Data Fusion) with an agent-building layer (Atlas AI). The agents are built by you, not shipped finished | Not verified — do not assume either way | Not publicly disclosed | The most precise disclosure in the roster, and the teaching example: audited and certified — ISO 27001, ISO 9001, ISO 27018, SOC Type 2 (Security), SOC Type 3 (Security); separately, supported industry frameworks — NIST CSF, IEC 62443.2-4, 3-2, 3-3, 4-1, CMMC, NERC CIP v.5. Not a 62443 certification claim — cognite.com/en/security | None found. Analyst quadrant placements are paid-access opinion |
All cells checked 23 August 2026 against the vendor's own pages, SEC filings and press releases. Where we could not reach a page — MachineMetrics' compliance article returns HTTP 403 to automated requests — we say so rather than guessing. Nothing in this table is derived, estimated or taken from an aggregator database.
The Ten, Entry by Entry
Before the entries, a cross-cutting finding that will save you a great deal of time: almost none of these are autonomous agents. Most are condition-monitoring, computer-vision or analytics products that predate the word “agentic” entirely and have had it applied retroactively to the marketing layer. That is not a scandal — a vibration-analysis model that catches a failing bearing is genuinely useful — but it changes what you should be buying and what you should be asking. Where a genuine agentic or write capability exists below, we name the documentation URL.
1. Guidewheel — the best fit for a small manufacturer, and the only published price
What it does:a clip-on current sensor, the PowerClamp, goes on the machine's power cord — no drilling, no wiring, no PLC access — and infers run, idle and down states from the current signature, with OEE and downtime analytics on top. It works on machines of any age, which for a shop running 1990s equipment alongside new cells is the whole argument.
What is verifiable: Guidewheel publishes “starting at $15,000 per year” including your first 10 machines. That is the only published price in this entire roster, and under our methodology it scores accordingly. It is also the cleanest read-only-by-construction case here: a clamp-on current sensor has no connection to the control system at all, so the question of whether it can write to your PLC is closed by physics rather than by policy.
What is not disclosed:pricing beyond ten machines. A third-party page computes roughly $1,500 per machine per year from the published tier — that figure is derived, not published, and we will not print it as a price. No certification claims were verifiable on the vendor's own pages, so we print none. Fits: a small plant that wants real utilisation data with zero OT risk. Does not fit: anyone who needs cycle-level detail, part counts by program, or anything the current signature cannot see.
2. Tulip Interfaces — the clearest documented write path in this roster, and therefore the one needing the most governance
Disambiguation first, because search results mix these constantly: tulip.co is Tulip Interfaces, the manufacturing company. tulip.com is Tulip Retail, an unrelated retail-software business. Compliance and security pages for the two get confused routinely. Cite tulip.co only.
What it does: a no-code app platform for frontline operators — digital work instructions, quality checks, traceability, e-signature records — plus edge hardware that connects to machines, scanners, torque tools and sensors. Honestly described, it is operator-assist and work instructions with an app builder, not an autonomous plant agent. It raised a $120M Series D led by Mitsubishi Electric on 13 January 2026 at a $1.3 billion valuation, alongside a strategic alliance agreement.
What is verifiable, and it is the most important vendor finding here: Tulip documents a Write Machine Attribute action and scopes it explicitly — you can only write to machine datasources that are OPC UA or MQTT, and the attribute must have the Write option explicitly enabled. The documentation also names what cannotbe written: Edge Devices, APIs, Celos and CelosX datasources, where the triggers will fail. Separately, the Generic I/O driver supports setting output pins to HIGH (24V) or LOW (0V) from an app, with 8 output pins on the I/O Gateway and 4 on Edge IO, each sourcing 500mA and under 1.5A total, described as meant for sending digital signals rather than power. On compliance, Tulip's own page states it is compliant with applicable SOC 2 controls and maintains a SOC 2 report, that it is certified to ISO 9001:2015, that it has achieved FedRAMP Moderate Equivalency per NIST 800-53 Rev. 5, and that it offers features allowing customers to comply with FDA 21 CFR Part 11.
What is not disclosed, and one observation about the documentation:ISO 27001 is not listed. IEC 62443 is not listed. Data residency specifics are absent. Note also the careful wording — the compliance page does not itself say “Type II”; a 2022 press release announced completion of a SOC 2 Type 2 audit by MNP LLP, and that release is where the Type II claim properly belongs. Finally, a checkable observation rather than an accusation: neither Tulip write-path document contains a safety warning about unintended machine actuation. You can open both pages and confirm that yourself. Fits: a midsize discrete manufacturer that wants to start without a systems integrator. Does not fit: a plant with no appetite for governing a real write path.
3. MachineMetrics — the best-documented protocol coverage, and an honest disclosure gap
What it does: automated machine-data collection from CNC machine tools, producing real-time utilisation, downtime reasons, part counts, OEE dashboards and operator downtime tagging. It is classic machine monitoring and OEE analytics, not an agent.
What is verifiable: the connectivity documentation is the strongest in this roster and it is public: FANUC FOCAS, MTConnect, OPC UA, Modbus/TCP, EtherNet/IP for Allen-Bradley CompactLogix, ControlLogix and GuardLogix, MQTT, Siemens S7, Mitsubishi M70/M700, Heidenhain, Brother HTTP/FTP, Haas serial and MTConnect, and digital I/O for older machines. For a machine shop, that list is the reason to look.
What is not disclosed: whether it writes. The documentation describes data collection only — it makes no read-only guarantee and no write claim. That is the honest answer, and we are printing it as such, because it is a good example of the disclosure gap this article exists to surface. Note that several supported protocols — OPC UA, Modbus/TCP, EtherNet/IP — are write-capable in principle, so the protocol list alone does not settle the question. Put it to the vendor in writing. Its Security & Compliance article returned HTTP 403 to us, so we print no certification claim for MachineMetrics at all.
4. Augury — condition monitoring that retrofits onto anything, with an agent layer bolted on
What it does:wireless vibration, temperature and magnetic sensors mount on rotating equipment — motors, pumps, fans, gearboxes, compressors — and stream to Augury's cloud, where ML models flag developing mechanical faults and produce a diagnosis and a recommended repair. Two product lines: Machine Health and Process Health. The non-invasiveness is the real selling point, and we will say it more plainly than the vendor does: sensors retrofit onto existing rotating assets without touching the PLC, which is why a midsize plant can actually deploy this.
What is verifiable: a $75M Series F led by Lightrock announced 19 February 2025, maintaining a $1 billion-plus valuation, with Insight Partners, Eclipse, Qumra, La Maison, SE Ventures and Qualcomm Ventures participating. Its trust centre publishes ISO 27001:2022, ISO 9001:2015, ISO 80079-34, GDPR, CCPA and an EcoVadis rating. The agent layer is real but new and additive: the company now markets role-based AI agents including a Reliability Agent, describing context-aware agents that act and autonomous multi-step tasks across systems — and its CEO framed the agentic capability in the 2025 funding release as new ground being broken, which is exactly the point about retrofitted branding.
Two corrections worth carrying. First, SOC 2 Type II is not published on Augury's trust centre, despite being widely repeated — print ISO 27001:2022, which is verified, and nothing more. Second, the autonomous-action language describes multi-step tasks across softwaresystems — work orders, tickets — and the vendor's pages do not specify writing to control systems. We record it as read-only and advisory with respect to the control layer, and note that the vendor does not claim otherwise. On ROI: the site cites a Forrester Total Economic Impact study and named customer figures. A commissioned TEI study is paid for by the vendor and is not an independent evaluation. We do not print those numbers.
5. Limble — the realistic CMMS for a small maintenance department, and a pricing correction
What it does: work orders, preventive maintenance schedules, asset history, parts inventory and a mobile technician app. Its own pricing page names an AI-Powered PM Builder available on all tiers, plus AI Duplicate Work Request Prevention Check and AI Scheduling Suggestions on the Enterprise tier. Tiers are Standard, Premium+ and Enterprise. Category honesty: this is a CMMS with AI helpers, not an agent.
The correction: Limble does not publish per-user prices. Its pricing page offers a self-serve price calculatorrather than listed figures. Third-party blogs quote a per-user-per-month range; that range is not from Limble and we will not print it. Under our methodology this cell reads “not publicly disclosed, self-serve calculator provided” — which is a genuine middle category, and better than a bare contact-sales wall. Enterprise lists 21 CFR compliance and SSO as features, which is a feature list, not a certification; no SOC 2 or ISO 27001 was verifiable. Fits: a small maintenance department on a real budget. Does not fit: anyone expecting machine-level data — a CMMS does not see the machine.
6. Rockwell Automation Fiix — the CMMS for a plant already standardised on Allen-Bradley
Ownership, from the strongest source in this article: Fiix Inc. of Toronto was acquired by Rockwell Automation, with the agreement announced 17 November 2020 and Rockwell's Form 10-Q recording the acquisition in December 2020, with goodwill assigned to the Software & Control segment and terms not disclosed. That is an SEC filing, not a press summary. It is still actively sold in 2026 as Rockwell Automation Fiix within the FactoryTalk Maintenance Suite.
What it is: a CMMS — asset registry, PM scheduling, work orders, parts inventory — with AI features and a maintenance copilot. The agentic surface is work-order generation, and that distinction matters for your boundary table: creating a work order is a software write, not a control-layer write. Compliance and pricing are not publicly disclosed. Note that Rockwell customer releases headline downtime-reduction figures framed as targets to drive rather than measured outcomes — which is a weaker claim than it first appears, and not one we print.
7. Sight Machine — unusually straight about what its agents do, and realistically enterprise-oriented
What it does: ingests and unifies plant data into a plant-wide data model, then analyses production for yield, waste and throughput. Its own site describes agent-powered manufacturing where agents continuously investigate production, find where it can improve, and propose how.
Credit where it is due. On the write question the vendor answers clearly in its own words: validated findings become live recommendations that your operations teams act on directly. Agents propose; humans act. In a market where most vendors leave the question open, that is worth noting. It also references an MCP server for integration with other agents — relevant later, because MCP widens what can reach the model and therefore widens the prompt-injection surface.
What is not disclosed, and who it is not for: we could not verify any certification — the security URL is a vulnerability-reporting form, not a trust page — so we print nothing. Pricing is not disclosed. Be clear-eyed about fit: data-unification platforms need data volume, historian infrastructure and an in-house analytics owner to pay off. This is realistically an enterprise tool. A 150-person job shop evaluating it is buying a project, not a product.
8. Siemens Senseye and Industrial Copilot — for plants already standardised on Siemens
Ownership: Senseye, formerly of Southampton, UK, has been a 100 percent subsidiary of Siemens holdings plc since 1 June 2022, per Siemens' own release of 8 June 2022. It is sold as Senseye Predictive Maintenance. It is another dead independent name still listed in competing rankings.
What it is:a copilot, by Siemens' own framing. A May 2025 release introduced AI agents across the Copilot portfolio: Design Copilot for NX CAD, Planning Copilot in pre-release, Engineering Copilot for TIA Portal, Operations Copilot for Insights Hub, and Services/Maintenance Copilot built on Senseye. Engineering Copilot generates automation code from natural-language input — the highest-consequence capability anywhere in this article, and it is gated behind engineer review by design.
Quote both sentences or neither. Siemens does speak of truly autonomous agents that proactively execute entire processes without human intervention — as a direction of travel, immediately qualified by the operative line: users retain complete control, selecting which tasks they wish to delegate to AI agents.Quoting only the first would be exactly the distortion this article exists to avoid. Compliance and pricing are not publicly disclosed. Note that the 2022 acquisition release's claim of a reduction in unplanned downtimes of up to 50 percent is a textbook “up to” vendor claim: no floor, no methodology.
9. Instrumental — narrow by design, and the only verified customer-hosted option
What it does: fixed cameras on the assembly line capture every unit at defined build stages; ML flags anomalies and defects; engineers inspect failures remotely instead of flying to the contract manufacturer. The product is the Manufacturing Acceleration Platform, with a Trace base layer for traceability plus annual-licence modules called Discover AI, Operate AI and Solve AI, sold on volume tiers described as starting from 10M signals and starting from 10K images. It is computer-vision defect detection — classic ML with AI branding on the modules.
A genuine differentiator, and an honest ambiguity. The differentiator: you can self-host Instrumental in your own AWS environment to maintain data sovereignty, and there is an ITAR-compliant GovCloud environment for aerospace and munitions data. That is the only customer-hosted option we verified in this roster, and it makes the product unusually viable for an ITAR-constrained supplier. The ambiguity: the site offers to deploy production controls that intercept issues, which could describe a gating or stop action, or something considerably narrower. We are not resolving that in the vendor's favour or against it — it is a good example of language a buyer should ask about directly. No SOC 2 Type II or ISO 27001 is published on the security page. Fits: electronics and contract-manufacturing supply chains, brands with overseas CMs. Does not fit: a general discrete manufacturer — saying so saves you a sales cycle.
10. Cognite — enterprise-only in practice, and the best compliance disclosure in this market
What it does: Cognite Data Fusion is industrial DataOps — it contextualises operational data into a knowledge graph — and Cognite Atlas AI is the agent-building layer on top. The agents are built by the customer, not shipped as finished plant agents. The company is Oslo-based and majority-backed by the industrial investor Aker.
Why it earns a place despite the fit problem: its security page is the most precise disclosure in this roster and is worth copying as a template for what you demand from every other vendor. It splits audited and certified — ISO 27001, ISO 9001, ISO 27018, SOC Type 2 (Security), SOC Type 3 (Security), with accreditation reports available — from a separate, explicitly weaker category of supported industry frameworks, under which NIST CSF, IEC 62443.2-4, 62443.3-2, 62443.3-3, 62443.4-1, CMMC, FIPS, NERC CIP v5, GxP and CSA STAR Level 1 appear. Cognite is not claiming IEC 62443 certification, and neither are we on its behalf. It is the only vendor in this roster that names IEC 62443 at all, and it names it in the honest column.
Who it is not for: you, probably. Its customer base is oil and gas, power and large process manufacturers. Data residency is not specified on the security page, pricing is not publicly disclosed, and no independent evaluation exists — analyst quadrant placements are paid-access analyst opinion, not benchmarks. A 150-person job shop should not be shortlisting this.
Four more we examined and did not rank, with the reason in each case. Elementary (Pasadena, founded 2017, with Rockwell Automation as a strategic investor) builds AI vision inspection cells for defect detection, sorting and classification; it is a plausible buy for a midsize manufacturer with a specific repeatable inspection problem, but we could not verify its write behaviour, compliance or pricing. Oden Technologies does production analytics and operator guidance well, but its home is continuous and process manufacturing — plastics, extrusion, converting, inks — which makes it a poorer fit for a purely discrete shop. LandingAI sells LandingLens, a data-centric platform for building custom visual-inspection models with limited labelled data; the important honest distinction is that it sells the toolkit, not the outcome— you get a vision model, and integrating it into a line is your project. One correction while we are here: do not describe LandingAI as Andrew Ng's company or call him CEO. Dan Maloney became CEO in August 2024 and Ng moved to Executive Chairman; the older description is everywhere and dates an article instantly. And Samsara (NYSE: IOT — not NASDAQ, a common error) is a real and substantial company, but it is yard, fleet and mobile-asset monitoring. A plant manager comparing it against MachineMetrics is comparing different categories.
Three Names You Will See Ranked in 2026 That Should Not Be There
A ranking article is a vendor roster, and a stale roster is the fastest way to be dismissed by the operator it was written for. Three companies that appear on current best-of lists cannot honestly be ranked as independent 2026 vendors. Each one is checkable from a primary source in under a minute, which tells you something about the diligence behind the lists they still appear on.
- Falkonry — acquired by IFS. The definitive agreement was announced 31 August 2023, with IFS stating it expected the acquisition to complete in Q4 2023. Terms were not disclosed; the release names no price. What it did — high-speed time-series anomaly detection for manufacturing and defence — was classic ML that predates the word agentic entirely. It is not an independent vendor, and it is still widely listed as one.
- Uptake Technologies — Bosch announced plans to acquire the Chicago company in a press release dated 19 March 2026, stating that the parties agreed not to disclose financial details and that upon closing the company's associates are intended to be integrated into Bosch. Status precision matters here: the release announces a planned acquisition and refers to upon closing, so the honest description is announced March 2026, not Bosch-owned as settled fact. Note the direction of travel too — Bosch framed the deal around commercial fleets and mobility services, not discrete plant assets, which signals where the industrial-plant story is heading.
- Nanotronics — the most tangled of the three, and the best illustration of why the roster check matters. The company rebranded to CubeFabs, whose business is modular AI-driven semiconductor fabrication plants, not factory inspection software. Separately, the nSpec inspection product line was transitioned to Nanotronics Inspection Systems, Inc., which states on its own site that it acquired nSpec in November 2025 and now sells the nSpec LS platform. Ranking Nanotronics as an AI inspection vendor in 2026 is wrong twice over: wrong company name, wrong owner. If the inspection product is what you want, the correct 2026 name is nSpec from Nanotronics Inspection Systems — a different company from CubeFabs.
- Two more that are alive but not independent: Senseye has been a Siemens subsidiary since June 2022 and Fiix has been Rockwell's since December 2020. Both are still actively sold and both belong in a comparison — but under their current owners, with the suite lock-in that implies, not as the standalone startups the older write-ups describe.
The Binding Constraint: Can It Write to Your Equipment, and Through Which Protocol?
The buyer question that decides everything is not how accurate the model is. It is whether the thing can write to your equipment, and through which protocol. In a discrete plant the answer is usually no — and often no by construction, because the protocol the vendor connected through has no write verb at all. That single fact reframes most of the autonomy conversation, and almost no vendor volunteers it.
MTConnect has no write verb — quoted from the standard itself, not from a vendor blog
The current published version is MTConnect Standard Part 1.0, Fundamentals, Version 2.5.0, prepared 5 January 2026. Section 5.1 says it plainly:
The REST API adheres to the architectural principles of a stateless service to retrieve information associated with pieces of equipment. Additionally, the API is read-only and does not produce any side effects on the agent or the equipment.
— MTConnect Standard Part 1.0 — Fundamentals, Version 2.5.0, §5.1, prepared 5 January 2026
Two further confirmations from the same document. It states that an agent MUST support the HTTP GET verb, all other verbs are optional. And it defines HTTP 405 Method Not Allowed, described as the request specified a method other than GET, as a mandatory response code for probe, current, sample and asset requests. So a conforming MTConnect agent answers GET and nothing else. There is no PUT, no state-changing POST, no setpoint write.
The nuance that keeps the claim honest. A careful reader will raise Part 5.0, the Interface Interaction Model, which is the one place the standard approaches bidirectionality: it defines a structured data model used to organize information required to coordinate inter-operations between pieces of equipment. But the coordination happens by publishing state the other party reads — the same document confirms Interfaces data is returned in the response documents returned from an agent in response to a probe, sample or current request. Part 5 is a request-and-response handshake expressed in read-only data, not a write channel. The no-write-verb claim survives intact.
A sourcing warning, because this exact error has shipped before. A great deal of content attributes read-only phrasing to MTConnect using wording that comes from monitoring-vendor marketing blogs rather than from the standards body. A vendor blog explaining the difference between MTConnect and OPC UA may be substantively correct and is fine to cite as a vendor's explanation, clearly labelled— but it is not the standard. When you want the read-only fact, quote Part 1.0 §5.1 above. MTConnect's registered trademark and the specification copyright sit with AMT, The Association For Manufacturing Technology; the standard is prepared for the MTConnect Institute.
OPC UA does write — and the permission lives on your side, not the vendor's
The contrast is the most useful thing in this article. OPC UA has a Write Service, defined in Part 4 Services §5.10.4 as being used to write values to one or more attributes of one or more nodes. The specification adds that the values are written to the data source, such as a device, and that the service does not return until it writes the values or determines that the value cannot be written. The OPC Foundation's own technology overview states that OPC UA can, on demand, read and write data/information based on access-permissions.
Here is the operator-grade takeaway: the write capability is real, it is permissioned, and the permission is set on the server — which is to say on the machine side, by the plant. Not by the AI vendor, and not by the vendor's roadmap. A plant that does not want an agent writing does not need to trust anyone's intentions; it withholds write permission on the OPC UA server and the question is closed. The same Foundation page describes the surrounding controls worth demanding: each UA client and server identified through X.509 certificates, message signing so the recipient can verify origin and integrity, user authentication by credentials, certificate or token, and logging of activities by user and system providing an access audit trail.
IEC 62443 asks you to partition and justify. It does not mandate a data diode.
IEC 62443-3-2:2020, Security risk assessment for system design, published 24 June 2020, establishes requirements for defining a system under consideration, partitioning it into zones and conduits, assessing risk for each zone and conduit, establishing target security levels, and documenting security requirements. That is the whole scope. It is a method, not a hardware mandate.
It does not mandate unidirectional gateways or data diodes, and it does not make a compliant plant physically incapable of carrying a write. ISA's own series overview describes requirements and processes for implementing and maintaining electronically secure industrial automation and control systems, noting that people, processes and technology all play critical roles — and makes no mention of diodes either. The correct sentence is this: IEC 62443 asks you to partition the plant into zones, define the conduits between them, and assign each a target security level based on assessed risk. Some operators choose to enforce a particular conduit with a unidirectional gateway; the standard does not require them to. A plant can be fully conformant and still carry writes across a conduit. What the standard governs is how you justify and control that conduit, not whether it may exist.
The compliance distinction to hold onto: “supports IEC 62443” and “is ISASecure-certified to IEC 62443-4-1” are completely different claims. ISASecure is the conformance assessment arm of the International Society of Automation, home of the ISA99 committee, and describes itself as the only global ISA/IEC 62443 certification program requiring its certification bodies to be accredited to ISO/IEC 17065. Its schemes map cleanly: CSA and ICSA to 62443-4-2, SSA to 62443-3-3, SDLA to 62443-4-1, ACSSA to 62443-2-1, 2-4, 3-2 and 3-3. Not one pure-play AI vendor in this roster publishes an ISASecure certificate, and we could not verify a single case.
Where these products actually live, and the one line that must never move
ISA-95 organises technology and business processes into layers: Level 0 the physical process, Level 1 sensing and manipulating, Level 2 monitoring and supervisory control, Level 3 manufacturing operations management, Level 4 business planning and logistics. Essentially every product in this article lives at Level 3 or above, reads from Levels 1 and 2, and touches Level 4 for work orders and ERP. The interesting question for a buyer is whether a vendor's write path reaches down to Level 1 or 2 — and for most of them it does not.
Below all of it sits the safety instrumented system, and it must never be in an agent's blast radius. IEC 61511-1:2016, Edition 2.0, published 24 February 2016, gives requirements for the specification, design, installation, operation and maintenance of a safety instrumented system so that it can be confidently entrusted to achieve or maintain a safe state of the process. The principle to apply — paraphrased rather than quoted, because the clause text is paywalled — is that the basic process control system must be sufficiently separate and independent from the safety instrumented system that a failure in the control system cannot compromise the safety system's ability to act.
Excessive Agency is the whole problem, and prompt injection is unsolved
The OWASP GenAI Security Project's LLM Top 10 for 2026, published 4 August 2026, numbers the two risks that matter most here as LLM01:2026 Prompt Injection and LLM03:2026 Excessive Agency, with LLM10:2026 Improper Output Handling at the bottom of the list. Always write the year. The 2025 list numbers different risks at those positions, and at least one widely-copied security-news page publishes a wrong 2026 ordering. Cite OWASP directly, never an aggregator.
Excessive Agency, in plain terms, is the agent was given more authority than the job required. In a plant that is not an abstraction: it is the difference between an agent that drafts a work order and an agent that holds an OPC UA write credential to a running line. The human-in-the-loop boundary table further down this page is, functionally, a mitigation for LLM03:2026.
And prompt injection is unsolved. Any agent that ingests supplier PDFs, emailed purchase orders, quality certificates, material certs or maintenance manuals is reading untrusted input, and any of those documents can carry instructions aimed at the model rather than at the reader. There is no reliable defence at the model layer, so treat this as blast-radius reduction, never as solved: separate identities per agent rather than a shared service account, least-privilege scopes bound to the specific operations a workflow needs, no write credential live in a session that is reading untrusted content, reversible writes wherever possible, per-action logging that names both the agent and the human it acted for, and a kill switch that revokes the credential rather than pausing the code.
What Actually Binds You in 2026 — and Two Dates Almost Everyone Gets Wrong
If you are a US discrete manufacturer with no defence contract and no critical-infrastructure designation, no federal rule imposes operational-technology cybersecurity requirements on you today. That is a verified absence, not an assumption, and it is worth stating plainly because a great deal of vendor material implies otherwise.
Every OT-cyber instrument finalised or proposed in 2025 and 2026 is sector-scoped. The CMMC program rule at 32 CFR 170 took effect 16 December 2024 and the DFARS CMMC clause on 10 November 2025 — both bind DoD contractors, and defence-industrial-base manufacturers are squarely inside. NERC CIP-015-1 and the supply-chain revisions bind the bulk electric system, as does FERC Order No. 919. The Coast Guard's Cybersecurity in the Marine Transportation System rule took effect 16 July 2025 for US-flag vessels and regulated facilities. The NRC's modernising-security proposal binds NRC licensees. TSA's surface cyber rule remains an NPRM whose Unified Agenda entry lists the final rule as “To Be Determined” under Long-Term Actions. Otherwise IEC 62443, NIST CSF 2.0 and NIST SP 800-82r3 are voluntary. One caveat on CMMC: it assesses NIST SP 800-171 controls over Controlled Unclassified Information in contractor information systems, and whether that reaches plant-floor OT is a scoping question that depends on where your CUI actually lives.
CIRCIA is not in force — and the claim that it landed in May 2026 is false
As of 23 August 2026 there is no CIRCIA final rule, and no manufacturer owes CIRCIA a report. CIRCIA was enacted in March 2022. 6 U.S.C. §681b(b) required CISA to publish a proposed rule within 24 months and to issue a final rule within 18 months of that publication. CISA published the NPRM on 4 April 2024 at 89 FR 23644. The statutory final-rule deadline of 4 October 2025 is recorded as missed in the agency's own Unified Agenda entry for RIN 1670-AA04, which now projects a final rule in September 2026. A Federal Register query on that RIN returns three documents, all typed “Proposed Rule.”
The trap: multiple secondary sources — law-firm and vendor blogs included — assert that a CIRCIA final rule arrived in May 2026 and describe live 72-hour incident and 24-hour ransom-payment reporting duties. That is false. What CISA published in May 2026 was a notice rescheduling town hall meetings to gather input on the 2024 proposal, explaining that a lapse in DHS appropriations from 14 February to 30 April 2026 had forced the postponement. Critical Manufacturing is named explicitly among the sectors in Grouping B of those rescheduled June 2026 sessions, so the sector is squarely inside the proposed scope. Plan against the proposed 72-hour and 24-hour timelines as a design input — and label them as proposed every time you say them out loud.
The EU deadline that is already on the clock: Cyber Resilience Act Article 14
If you build machines or ship products with digital elements into the EU, the date to have in your calendar is 11 September 2026. Regulation (EU) 2024/2847 entered into force on 10 December 2024. Article 71 provides that the regulation applies from 11 December 2027, however Article 14 applies from 11 September 2026 and Chapter IV (Articles 35 to 51) applies from 11 June 2026.
Article 14 requires a manufacturer, via the single reporting platform established under Article 16, to notify the coordinating CSIRT and ENISA simultaneously. For an actively exploited vulnerability: an early warning notification without undue delay and in any event within 24 hours of becoming aware of it; a vulnerability notification within 72 hours giving general information about the product, the nature of the exploit and any corrective or mitigating measures taken; and a final report no later than 14 days after a corrective or mitigating measure is available. The same 24-hour and 72-hour cadence applies to a severe incident having an impact on the security of the product.
The sting is Article 69(3), which provides that by way of derogation, the Article 14 obligations apply to all in-scope products with digital elements that have been placed on the market before 11 December 2027. Article 69(2) otherwise exempts pre-December-2027 products unless substantially modified — but Article 14 reporting reaches back to the installed base anyway. Scope is broad: Article 2(1) covers products with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, and Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions. The Article 2 carve-outs are medical devices, motor-vehicle type approval, certified civil aviation and marine equipment. Industrial machinery is not carved out.
Machinery Regulation: 20 January 2027, not 14 January — and the AI Act moved
This is a live date trap and most sources still get it wrong. The original Official Journal text of Regulation (EU) 2023/1230 said the regulation shall apply from 14 January 2027, with sub-dates of 14 January 2024, 14 October 2023, 13 July 2023 and 14 July 2024. A corrigendum changed all five. The consolidated Article 54 as corrected reads: applies from 20 January 2027; Articles 26 to 42 from 20 January 2024; Article 50(1) from 20 October 2026; Article 6(7) and Articles 48 and 52 from 19 July 2023; and Article 6(2) to (6), (8) and (11) and Articles 47 and 53(3) from 20 July 2024. If you print one Machinery Regulation date, print 20 January 2027.
And the AI Act no longer bites machinery directly. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, in force 27 July 2026, deleted point 1 from AI Act Annex I Section A — the old Machinery Directive entry — and added the Machinery Regulation to Section B as point 21. Amended AI Act Article 2(2) provides that for high-risk systems under Article 6(1) related to products covered by Section B legislation, only Article 6(1), Article 60a and Articles 102 to 112 apply. So AI Act Chapter III does not apply directly to machinery-embedded AI. The requirements arrive instead through delegated acts rewriting the Machinery Regulation's own Annex III: the amended Machinery Regulation Article 8 directs the Commission to add health and safety requirements for high-risk AI systems reflecting AI Act Chapter III Section 2 and Articles 17, 19, 72 and 73, and states that those delegated acts shall apply by 2 August 2028. The same Omnibus deferred Chapter III for Annex III systems to 2 December 2027 and for Annex I systems to 2 August 2028.
The narrower question that decides whether any of this reaches you: does the model perform a safety function? Machinery Regulation Annex I Part A lists, at points 5 and 6, safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions, and machinery with embedded systems of the same character. Part A categories must go through one of three conformity routes under Article 25(2) — EU type-examination, full quality assurance, or unit verification — all three of which involve a notified body, which in turn satisfies both limbs of AI Act Article 6(1) and makes the system high-risk. Machine learning that recommends a setpoint, schedules a work order or flags a defect does not. Plan in that order: machinery rules from 20 January 2027, AI-specific machinery requirements roughly eighteen months later.
OSHA: an agent that can stop a machine is not a lockout
Two standards are unchanged and current. 29 CFR 1910.212(a)(1) requires one or more methods of machine guarding to protect the operator and other employees from hazards such as point of operation, ingoing nip points, rotating parts, flying chips and sparks. 29 CFR 1910.147(a)(1)(i) covers servicing and maintenance where the unexpected energization or start up of machines or equipment, or release of stored energy, could cause injury. A Federal Register sweep finds no 2025 or 2026 rulemaking touching either.
The connection to draw is the strongest safety argument in this article. Lockout/tagout exists because of unexpectedstart-up. Software that can command a machine to start is, by definition, a potential source of unexpected energisation. So an agent with write access to a machine a technician may be servicing is not merely a cybersecurity question — it is a 1910.147 question. And OSHA's definition of energy isolating device expressly excludes push buttons, selector switches and other control-circuit-type devices, software commands included.
There is an open rulemaking aimed squarely at this, and almost nobody mentions it. RIN 1218-AD00, “Lock-Out/Tag-Out Update”, states in its abstract that recent technological advancements employing computer-based controls of hazardous energy conflict withOSHA's existing LOTO standard, and its Statement of Need notes that the definition of energy isolating device expressedly excludes push buttons, selector switches and other control-circuit-type devices. Status precision: it is at Proposed Rule Stage with an NPRM projected for November 2026; there has been a Request for Information from May 2019 and nothing since. Until a proposal exists and is finalised the standard is unchanged — physical energy isolation, verified, before anyone puts a hand in the danger zone. The right control is a hardware interlock, not a software guardrail.
Two closing notes on the voluntary side. NIST's own wording about CSF 2.0 is more careful than “voluntary”: the CSF is a foundational resource that may be adopted voluntarily and through governmental policies and mandates. It becomes binding only where a contract, a regulator or a customer incorporates it by reference. Two changes from version 1.1 are worth knowing: GOVERN is a new Core Function, and the title “Framework for Improving Critical Infrastructure Cybersecurity” was dropped — the Note to Readers states plainly that this title is not used for CSF 2.0 — which is why a 90-person job shop can use it. For a plant manager, though, NIST SP 800-82 Revision 3, Guide to Operational Technology Security (September 2023) is the more relevant document, and almost no competing article names it.
Meanwhile the products an agent would be reading from are themselves a steady advisory stream. In a single week in August 2026, CISA published ICS advisories against SCADA, HMI, PLC-adjacent and building-control products from Siemens, AVEVA, Johnson Controls, Hitachi Energy and ANDRITZ — fourteen in the 13 August batch alone, with the most recent in the feed on 23 August being ICSA-26-232-01, Johnson Controls Simplex Incident Manager, dated 20 August 2026. Adding an AI layer on top of that estate does not reduce the patching obligation underneath it.
A Worked Example, With Honest Arithmetic
The first number you need is not a vendor's. It is your own downtime, measured — and most plants cannot state it from measurement. The scenario below is exactly that: an illustrative worked scenario, not a client result. Every figure in it is either published by a named source or arithmetic we show our working for.
Now price the cheapest honest way to find out your real number. Guidewheel publishes $15,000 per year including the first ten machines. For 22 machines, pricing beyond the first ten is not published, so the correct budget line is “$15,000 plus an undisclosed increment — get it in writing before modelling payback.” We are not going to divide $15,000 by ten and multiply by 22 for you; that derivation is not a price, and a third party publishing one does not make it a price. What you can say with confidence is that a clamp-on current sensor gets a small plant real utilisation data on machines of any age without touching a PLC, which means the OT-risk conversation and the procurement conversation stay separate.
Only after that measurement does an agent conversation make sense — and it will run into the write question immediately, because whatever the agent proposes has to land somewhere: in a CMMS, in an ERP work order, in a scheduling system, or in the control layer itself. That integration problem is where most of the budget actually goes, and we work through it properly in our guide to connecting AI agents to legacy and closed systems of record. Skipping that step is how a six-week pilot becomes a nine-month project.
A design principle from a different industry that transfers exactly
We build verification-first architectures for clients in industries far from the plant floor, and one of them makes this article's argument better than a manufacturing anecdote would. Our GemHub gemstone marketplace build had a single organising constraint: in a market where transactions run from $10,000 to $500,000 between strangers, the seller's own claim about the goods is not evidence.So every listing connects to a third-party certification lab — GIA, AGS, IGI — and buyers verify certificate authenticity through the platform rather than taking the seller's word. And the money moves through an escrow that holds funds until the buyer confirms receipt and authenticity, with dispute resolution behind it.
That is a different industry, and we are not transferring its outcomes here. What transfers is the architecture, and it is exactly the shape of a defensible agent deployment: verify the claim against an independent certificate rather than the seller's marketing, and gate the irreversible action behind a human confirmation. Read that sentence again with a vendor's accuracy claim and an OPC UA write in mind. It is the same design.
What Breaks First
The characteristic failure of a plant-floor AI deployment is not a crash. It is a confident recommendation that is quietly wrong, arriving faster than anyone can check it. Here is what actually goes wrong first, what signal detects it, and what rollback looks like when it does.
- Alert fatigue, within about six weeks. A condition-monitoring model tuned to catch everything produces more flags than the maintenance team can triage, so the team starts closing them in batches. Detection: track the percentage of alerts closed without an action recorded, weekly. When that number climbs past a third, the system has stopped working regardless of what the dashboard says. Rollback is a threshold change, not a deployment.
- Prompt injection through supplier documents. Any agent that reads supplier PDFs, emailed purchase orders, quality certificates or maintenance manuals is reading untrusted input, and this is unsolved — LLM01:2026 in the OWASP list. Detection is hard by design, so the control is structural: no write credential live in a session that is reading untrusted content, separate identities per agent, and per-action logs naming both the agent and the human it acted for.
- Excessive agency creeping in through convenience. The agent that was scoped to draft work orders gets a wider credential during a busy month because someone needed it to close them too. That is LLM03:2026, and it happens through operations, not through architecture. Detection: quarterly review of every credential the agent holds against the workflow it was scoped for. If nobody owns that review, assume the scope has widened.
- Silent model drift after a process change. A model trained on last year's tool paths, materials or cycle times quietly degrades after an engineering change, and degrades toward plausible outputs rather than obvious errors. Detection: a fixed known-answer regression set re-run on a schedule and trended, not spot-checks by whoever is free that day.
- The connectivity assumption that was never true. A vendor's protocol list says OPC UA; your 2004 machine speaks something else, or speaks OPC UA through a gateway that changes the semantics. Detection: prove the connection on the oldest machine on the floor during evaluation, not the newest. The oldest machine is the one that decides the project.
- A vendor that disappears or changes hands. Three vendors in this category changed status between 2023 and 2026. Detection is contractual rather than technical: an exportability clause, a data-format commitment, and a written answer to what happens to our data on termination — obtained before signing, not after.
- The review that stops being a review. The real failure mode in every regulated environment is rubber-stamping: the queue gets long, outputs look right, and approval becomes a click. Detection: instrument review time per item and alert when the median falls below the time it physically takes to check the work.
Rollback should be a credential action, not a code change.The kill switch that works in a plant is one that revokes the agent's token and leaves the humans with the queue — and, where a control-layer write path exists at all, one that withdraws write permission on the OPC UA server rather than asking the vendor to disable a feature. If your rollback plan requires a deployment or a support ticket, you do not have a rollback plan.
The Human-in-the-Loop Boundary
Every line in this table comes from a rule or a standard that already existed, not from our judgement. That is what makes it defensible, and it is why no AI-specific regulation was needed to answer the question of what an agent may do alone in a plant.
| An agent may act alone | Needs documented human review | Must never touch |
|---|---|---|
| Reading machine state over MTConnect, or over OPC UA with a read-only account | Any change to a setpoint, recipe, tool offset or program that reaches Level 1 or 2 | Anything inside the safety instrumented system's function path |
| Tagging and classifying downtime events for an operator to confirm | Opening or closing a work order against a critical asset | Starting, stopping or energising physical equipment as a substitute for lockout/tagout |
| Drafting a maintenance recommendation with the evidence that produced it | Ordering parts, or committing spend against a purchase order | Bypassing, muting or reconfiguring a guard, interlock or light curtain |
| Summarising a shift, a scrap trend or an OEE movement for a human to read | Rescheduling production or changing a due date that a customer sees | Signing, releasing or approving a quality record on a human's behalf |
| Flagging an anomaly and paging the person on call | Any first write of a new type, for the first thirty days, every time | Holding a standing OPC UA write credential in a session that is reading untrusted documents |
Boundary derived from MTConnect Part 1.0 §5.1, OPC UA Part 4 §5.10.4, IEC 62443-3-2:2020, IEC 61511-1:2016, ISA-95, 29 CFR 1910.147 and 1910.212, and OWASP LLM03:2026. Checked 23 August 2026.
Cost and Timeline for a Custom Build
If the roster above does not contain what you need — and for a plant with unusual equipment, an old ERP or a specific quality workflow, it frequently does not — these are our bands. They are the same figures we quote in every vertical, and they do not move because a prospect sounds larger.
| Engagement | Range | Timeline |
|---|---|---|
| Discovery and workflow audit | $9,000 – $22,000 | 2–4 weeks |
| Single-workflow agent | $28,000 – $70,000 | 4–9 weeks |
| Multi-workflow platform with system integration | $70,000 – $180,000 | 9–16 weeks |
| Enterprise, multi-site or regulated build | $180,000 – $420,000+ | 14–24 weeks |
Senior-led engineering runs $150–$225 per hour, and ongoing retainers run $2,500–$9,500 per month. Every engagement carries a 30-day post-launch warranty, and full source-code and IP ownership transfers to you — a point worth checking against any vendor whose model keeps the trained artefacts on their side. We return a fixed-price phased proposal within 5 business days of the discovery call. We are a senior-led, Black-owned agency in Los Angeles, and you can reach us at +1 (424) 272-5601 or book directly at calendly.com/frenchydigital/discovery-call.
Honest advice for a small or midsize plant: spend the discovery money first. Most plants we talk to cannot state their own downtime percentage from measurement, and no agent is worth commissioning against a number nobody has. A workflow audit that produces a protocol inventory, a write-path map and a measured baseline is worth more at this stage than a pilot — and it is the input every one of the vendors above will ask you for anyway. If you want the wider view of when a build beats a licence, that is the question we work through in our AI agent creation practice.
Ready to Build Your Application?
Let's discuss your project. Our team will help you build solutions that transform your business.
Red Flags When Evaluating a Vendor
Each of these is something we actually encountered while researching this article, and each one is checkable in a first sales call.
- Any downtime or OEE improvement percentage presented as neutral fact. Ask for the study, the sample, the period and the comparator. NIST screened 465 papers over 22 years and found 42 evaluable studies that it declined to pool — a vendor with a single clean number has something better than the literature, and should be able to show it.
- A commissioned analyst study presented as independent evidence. A Total Economic Impact study is paid for by the vendor. So are most quadrant placements. Peer-review sites publish user reviews. Innovation awards are press. None of these is an independent evaluation, and this is the main way these markets simulate one.
- An investor quoted as an evaluator. A performance claim attributed to the partner at the fund that just led the round is the most conflicted source available, not an outside assessment. Attribute it to the person who said it and to their position in the cap table.
- An up-to number. Up-to claims have no floor and no methodology. Up to 50% downtime reduction is compatible with zero.
- A target reported as a result. Read customer press releases carefully for the difference between a figure a customer is aiming to drive and a figure that was measured after the fact. The first is weaker than it looks.
- Silence on the write question. If a vendor cannot tell you in writing whether the product can write to your control layer, through which protocol, and who controls that permission, the sales team does not know their own architecture. Get the answer in email.
- A protocol list offered as a write answer. OPC UA, Modbus/TCP and EtherNet/IP are all write-capable in principle. A list of supported protocols tells you what the product can reach, not what it does.
- Compliance language that belongs to somebody else. Learn the difference between we hold this certification, our hosting provider holds it, we are compliant with the controls, we support the framework, and here is what the framework is. All five appear in this market and only the first two are claims about anybody's audit.
- Any claim of IEC 62443 certification without a scheme and a part number. Ask which ISASecure scheme — CSA, ICSA, SSA, SDLA, ACSSA — and which part of the standard. Not one pure-play AI vendor in this roster publishes a certificate.
- A security page that is a vulnerability-reporting form, or that returns an error. Several vendors handling plant data have no reachable trust page. That is not a neutral absence for a product with a credential inside your network.
- A stale integration directory. If a vendor's own integration list names a company that was acquired or renamed years ago, assume the roadmap page is equally stale — and re-check every other claim on the site.
- An ownership answer that is not a public record. Ownership changed for several vendors in this category during 2023 to 2026, and aggregator databases had at least one of them wrong. Ask for the filing, the press release or the registry entry — not a profile page.
- Documentation for a write path that contains no safety warning. That is a checkable observation about the documentation, and it belongs in your risk assessment rather than in an argument.
Limitations — What We Could Not Verify
Every article should carry this section, and the fact that almost none in this category do is itself informative. Here is what we could not establish, stated plainly.
- We could not verify whether MachineMetrics writes to the control layer. Its documentation describes collection only, making neither a read-only guarantee nor a write claim, and its Security & Compliance article returns HTTP 403 to automated requests. We print no certification claim for it at all.
- We could not verify the write behaviour of Cognite, Instrumental, Elementary or Oden Technologies. Instrumental's deploy production controls that intercept issues language is genuinely ambiguous and we have not resolved it in either direction.
- We could not verify compliance certifications for Guidewheel, Sight Machine, Instrumental, Elementary, Oden, LandingAI, Rockwell Fiix or Siemens from their own pages, so none is printed. Absence of a printed claim here means we could not reach a source, not that a certification does not exist.
- We could not confirm that the Bosch acquisition of Uptake Technologies has closed. The March 2026 release announces a planned acquisition and refers to upon closing, so we describe it as announced rather than completed.
- We could not date the CubeFabs rebrand precisely — that announcement page carries no publication date. The November 2025 date for the nSpec transfer comes from Nanotronics Inspection Systems' own site and is solid.
- We could not read the IEC 61511-1 clause on BPCS and SIS independence, which is paywalled. We paraphrase the principle from the standard's published scope and do not put quotation marks around any clause text.
- We could not verify the KPI list in ISO 22400-2:2014 from the free ISO record, so we make no claim about what it does or does not define. Its record shows stage 90.92, International Standard to be revised.
- We could not verify the widely repeated debunk of the 85% world-class OEE benchmark attributed to Nakajima. The critique appears only in trade glossaries and practitioner posts, so we print neither the benchmark nor the debunk as sourced.
- We could not obtain a manufacturing-sector AI adoption rate from any government source. The Census Business Trends and Outlook Survey industry breakdown lives in an interactive visualisation that we could not extract, so we print no such figure.
- We could not produce a count of CISA ICS advisories issued in 2026; the advisory feed caps at 30 items. The named August 2026 advisories above are what the feed shows.
- The productivity and capacity-utilisation figures in our stat tiles are whole-sector macroeconomic aggregates. A single plant cannot reconcile its own OEE to them, and neither series attributes anything to automation, software or AI.
- Most importantly: no independent benchmark of any product in this article exists, in any form. Every performance number in this market is published by the seller about itself or by an analyst firm the seller pays. That is not a gap we could close with more research — it is the finding.
If any of the above changes, the honest response is to re-check the source rather than to re-run the search that produced the original claim. That is the difference between a ranking that ages and one that rots — and it is why the sibling article on AI agents in plant operations is worth reading alongside this one: same constraint, different starting question.
Want a Write-Path Audit Before You Sign Anything?
Book a free 60-minute discovery call. You leave with a protocol inventory, a map of every system a proposed agent would touch and whether it can write there, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1MTConnect Standard Part 1.0 — Fundamentals, Version 2.5.0, prepared 5 January 2026 (read-only REST API, §5.1)↗
- 2MTConnect Standard Part 5.0 — Interface Interaction Model, Version 2.5.0↗
- 3OPC Foundation — UA Part 4: Services, §5.10.4 Write Service↗
- 4OPC Foundation — OPC UA technology overview (read/write on access-permissions; certificates, signing, audit trail)↗
- 5IEC 62443-3-2:2020 — Security risk assessment for system design (zones and conduits), published 24 June 2020↗
- 6ISA — ISA/IEC 62443 series of standards overview↗
- 7ISASecure — certification schemes and their IEC 62443 mappings↗
- 8IEC 61511-1:2016 Edition 2.0 — Safety instrumented systems for the process industry sector, published 24 February 2016↗
- 9ISA — ISA-95 standard, enterprise/control system integration levels↗
- 10OWASP GenAI Security Project — LLM Top 10 for 2026 (repository of record)↗
- 11Thomas & Weiss, NIST Advanced Manufacturing Series 100-34 — Economics of Manufacturing Machinery Maintenance (June 2020)↗
- 12Dadfarnia, Sharp & Herrmann (NIST) — Comprehensive evaluations of condition monitoring-based technologies: a systematic review, J. Manufacturing Systems vol. 82 (9 July 2025)↗
- 13Deloitte University Press — Making maintenance smarter (9 May 2017), the source of the $50bn citation chain↗
- 14McKinsey — Manufacturing: Analytics unleashes productivity and profitability (14 August 2017), the origin of the 30–50% claim↗
- 15US DOE FEMP — Operations & Maintenance Best Practices Guide, Release 3.0 (August 2010), the uncited 35–45% table↗
- 16Deloitte & The Manufacturing Institute — Taking charge (April 2024): 1.9 million of 3.8 million jobs unfilled by 2033↗
- 17NIST CSWP 29 — The NIST Cybersecurity Framework (CSF) 2.0, published 26 February 2024↗
- 18NIST SP 800-82 Revision 3 — Guide to Operational Technology (OT) Security (September 2023)↗
- 19CISA CIRCIA rulemaking — NPRM, 89 FR 23644 (4 April 2024), RIN 1670-AA04, docket CISA-2022-0010↗
- 20Unified Agenda entry RIN 1670-AA04 — statutory final-rule deadline recorded as 10/04/2025, projected 09/2026↗
- 21Regulation (EU) 2024/2847 — Cyber Resilience Act (Article 14 applies 11 September 2026; Article 69(3) reach-back)↗
- 22Regulation (EU) 2023/1230 — Machinery Regulation, consolidated text as corrected (applies 20 January 2027)↗
- 23Regulation (EU) 2026/1744 — Digital Omnibus on AI (in force 27 July 2026; moves machinery to Annex I Section B)↗
- 2429 CFR 1910.147 — The control of hazardous energy (lockout/tagout), current eCFR text↗
- 2529 CFR 1910.212 — General requirements for all machines, current eCFR text↗
- 26Unified Agenda entry RIN 1218-AD00 — OSHA Lock-Out/Tag-Out Update, Proposed Rule Stage, NPRM projected November 2026↗
- 27Federal Reserve G.17 — Industrial Production and Capacity Utilization, released 18 August 2026↗
- 28BLS series PRS30006093 — manufacturing labour productivity, output per hour, index 2017 = 100↗
- 29SEC — In the Matter of Presto Automation Inc., Securities Act Rel. No. 11352 (14 January 2025)↗
- 30FTC — Operation AI Comply (25 September 2024), cited for the substantiation principle only↗
- 31CISA — Industrial Control Systems advisories index↗
- 32Tulip vendor documentation — Write to machine attributes using OPC UA / MQTT↗
- 33Guidewheel pricing — the only published price in this roster↗
- 34Cognite security page — audited-and-certified versus supported-frameworks split↗
- 35MachineMetrics connectivity documentation — protocol coverage↗
- 36Bosch — planned acquisition of Uptake Technologies, press release 19 March 2026↗
- 37IFS to acquire Falkonry AI, 31 August 2023↗
- 38CubeFabs — Nanotronics is now CubeFabs; nSpec transferred to Nanotronics Inspection Systems, Inc.↗
- 39Siemens acquires Senseye, press release 8 June 2022↗
- 40Rockwell Automation Form 10-Q (Fiix acquisition, December 2020) — SEC EDGAR↗

