You’ve been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers and the cautious holdouts alike.
At some point AI stops being optional, and governing it becomes the job in front of you.
Governance starts with a position: a first policy that sorts AI use into three categories, each governed differently. There’s the general-purpose AI your teams have approved, the AI you’re deliberately building into products and processes, and the AI nobody decided on at all.
Writing that policy is the straightforward part. The wall comes when you try to enforce it, because you can’t govern what you can’t see, and you don’t yet know what AI is running across the business, where it lives, or which category it falls into.
The policy states your intent; the inventory is what turns that intent into governance you can enforce.
Without it, you can’t classify risk, apply the acceptable use rules you just wrote, or answer a customer’s due diligence questionnaire with anything better than a guess.
It’s the step most manufacturers skip, and a big part of why so many now use AI with no real oversight of it.
An inventory is a living record of every place AI is in use across the business: what each system does, what data it touches, who owns it, and what happens when it gets something wrong.
That’s a different list from the tools IT signed off on, and the distance between the two is where your exposure sits.
You build it by working through those three categories, starting with the AI you chose to use.
Start with the easy part, the AI you brought in consciously:
The general-purpose tools your teams use for research, drafting, summarizing meeting recordings into minutes, and the daily admin that used to eat hours.
This is the AI most companies think of first, because someone made a decision to adopt it.
These uses are usually governed by an Acceptable Use Policy (AUP): the rules for what staff can and can’t put into a tool.
For the inventory, write down:
Then note what the policy tends to miss.
With general-purpose AI, you rarely know exactly what data your people are feeding the model. A production schedule, a supplier contract, a customer list: once it goes in, you’ve lost sight of where it lives.
So the risk to log against every entry in this category is data exposure, as sensitive information leaves your control through a tool nobody is watching closely.
The next category is deliberate: the AI you’re developing into your products and processes. This is where AI does real work on the floor, and where most operations are putting their investment.
The common use cases in manufacturing include:
When you build AI into a product or a process on purpose, it should run through a Software Development Lifecycle (SDLC): the staged process your engineering teams use to approve a use case, develop it, test it, and monitor it once it’s live.
Capture each of these in the inventory as a governed project: what it does, what stage it’s at, who owns it, and what production decisions it drives.
Although you may be focused on getting the model to work initially, the harder test comes later, when a customer or an auditor asks you to explain how it reached a decision, and you need an answer on record.
This is the category that carries the most risk, and it’s the reason the inventory exists at all.
Some AI never went through a decision. It just arrived:
No one assessed any of it, and no one owns it. In the worst cases, a critical process is now running on AI that nobody is governing.
This is where governance becomes a resilience question. When an unmonitored model quietly becomes the thing that schedules production or approves orders, you’re depending on a system nobody chose and nobody is watching. When it drifts, no one will catch it in time.
It’s why we treat every AI program the same way we run a cyber program. Every AI capability we put into an engagement operates inside defined controls: what data it touches, where that data goes, who reviews the output, and who signs off before anything reaches you.
You can’t govern what you can’t see. On a manufacturing floor, this is the part of the operation you can see least.
Finding these takes real digging.
A list of AI systems isn’t governance yet. It becomes governance when each entry carries a risk rating and a name against it.
For every system, record:
With that in place, you can size controls to the risk. Light oversight is enough for a tool that drafts internal memos. A model that screens job applicants or makes a safety call on the line sits in a different category, the kind regulators are moving to treat as high-risk.
The EU AI Act, for instance, is built on classifying systems by risk. Its high-risk obligations are currently expected to apply from December 2027 for standalone systems, after the recent Digital Omnibus deferral pushed the original 2026 deadline back.
Whatever the final date, increased regulation is coming, and you can’t classify what you haven’t listed. The inventory is the input to every risk decision that follows.
Identifying every system, assessing the risk across data, tools, models, and vendors, and setting controls proportional to that risk is the first work we run in an AI governance program.
The policy sets the direction, and the inventory is what you govern from.
An inventory can feel like busywork until the moment you need it and don’t have it: the customer questionnaire you can’t answer, or the incident on a line running a model no one remembers approving.
Built ahead of that moment, it’s the foundation every other governance decision stands on.
If you don’t know what AI is running in your operation, that’s where to start.
Talk to us, and we’ll help you build the inventory and turn it into governance you can prove.
Risk is constant. Ready is a choice.
Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.
Because while risk is constant, ready is a choice.
You've been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers...
Read more
You passed the audit. The certificate went up on the wall. The consultant packed up, the engagement closed out,...
Read more
It's 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on:...
Read moreLet’s help Plan, Build and Run your cyber and AI programs to keep your business capable, compliant, and resilient. Because while risk is constant, ready is a choice.