How to Build an AI Use Case Inventory for Your Manufacturing Operation

28th July 2026 | AI Governance How to Build an AI Use Case Inventory for Your Manufacturing Operation

You’ve been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers and the cautious holdouts alike

At some point AI stops being optional, and governing it becomes the job in front of you.

Governance starts with a position: a first policy that sorts AI use into three categories, each governed differently. There’s the general-purpose AI your teams have approved, the AI you’re deliberately building into products and processes, and the AI nobody decided on at all.

Writing that policy is the straightforward part. The wall comes when you try to enforce it, because you can’t govern what you can’t see, and you don’t yet know what AI is running across the business, where it lives, or which category it falls into.

That’s why you need an AI use case inventory

The policy states your intent; the inventory is what turns that intent into governance you can enforce. 

Without it, you can’t classify risk, apply the acceptable use rules you just wrote, or answer a customer’s due diligence questionnaire with anything better than a guess.

It’s the step most manufacturers skip, and a big part of why so many now use AI with no real oversight of it.

An inventory is a living record of every place AI is in use across the business: what each system does, what data it touches, who owns it, and what happens when it gets something wrong. 

That’s a different list from the tools IT signed off on, and the distance between the two is where your exposure sits.

You build it by working through those three categories, starting with the AI you chose to use.

Step one: capture the AI you chose to use

Start with the easy part, the AI you brought in consciously:

The general-purpose tools your teams use for research, drafting, summarizing meeting recordings into minutes, and the daily admin that used to eat hours. 

This is the AI most companies think of first, because someone made a decision to adopt it.

These uses are usually governed by an Acceptable Use Policy (AUP): the rules for what staff can and can’t put into a tool. 

For the inventory, write down:

  1. The name of each tool
  2. Who uses it
  3. What they use it for

Then note what the policy tends to miss.

With general-purpose AI, you rarely know exactly what data your people are feeding the model. A production schedule, a supplier contract, a customer list: once it goes in, you’ve lost sight of where it lives. 

So the risk to log against every entry in this category is data exposure, as sensitive information leaves your control through a tool nobody is watching closely.

Step two: map the AI you’re building into the operation

The next category is deliberate: the AI you’re developing into your products and processes. This is where AI does real work on the floor, and where most operations are putting their investment.

The common use cases in manufacturing include:

  • Predictive maintenance that flags a bearing or motor before it fails
  • Quality control using machine vision to catch defects on the line
  • Supply chain optimization for demand forecasting and inventory planning
  • Process automation across scheduling, procurement, and back-office work
  • Generative AI in design and engineering, from first concept to detailed design

When you build AI into a product or a process on purpose, it should run through a Software Development Lifecycle (SDLC): the staged process your engineering teams use to approve a use case, develop it, test it, and monitor it once it’s live. 

Capture each of these in the inventory as a governed project: what it does, what stage it’s at, who owns it, and what production decisions it drives.

Although you may be focused on getting the model to work initially, the harder test comes later, when a customer or an auditor asks you to explain how it reached a decision, and you need an answer on record.

Step three: hunt the AI nobody decided on

This is the category that carries the most risk, and it’s the reason the inventory exists at all.

Some AI never went through a decision. It just arrived:

  • Your ERP vendor (the enterprise software that runs finance, inventory, and orders) pushing AI features in a platform update. 
  • Your MES (the Manufacturing Execution System on the shop floor) adding anomaly detection you didn’t switch on deliberately. 
  • An engineer wiring a generative tool into a reporting workflow because it saved them a morning.
  • HR screening applicants with a model built into the hiring software.

No one assessed any of it, and no one owns it. In the worst cases, a critical process is now running on AI that nobody is governing.

This is where governance becomes a resilience question. When an unmonitored model quietly becomes the thing that schedules production or approves orders, you’re depending on a system nobody chose and nobody is watching. When it drifts, no one will catch it in time.

It’s why we treat every AI program the same way we run a cyber program. Every AI capability we put into an engagement operates inside defined controls: what data it touches, where that data goes, who reviews the output, and who signs off before anything reaches you.

You can’t govern what you can’t see. On a manufacturing floor, this is the part of the operation you can see least.

Finding these takes real digging. 

  1. Start with recent vendor release notes for the AI features you’ve been given without asking.
  2. Walk each department head through the tools their team opens day to day. 
  3. Focus on systems touching production, quality, or customer data, especially any that added a model in the last year.

Step four: classify each entry by risk and give it an owner

A list of AI systems isn’t governance yet. It becomes governance when each entry carries a risk rating and a name against it.

For every system, record:

  • What it does and what business decision it affects
  • What data it touches, and whether that includes customer, employee, or regulated data
  • How it entered the business: chosen, built, or embedded by a vendor
  • What happens if it produces a wrong or biased output
  • Who owns it, and who signs off on changes

With that in place, you can size controls to the risk. Light oversight is enough for a tool that drafts internal memos. A model that screens job applicants or makes a safety call on the line sits in a different category, the kind regulators are moving to treat as high-risk.

The EU AI Act, for instance, is built on classifying systems by risk. Its high-risk obligations are currently expected to apply from December 2027 for standalone systems, after the recent Digital Omnibus deferral pushed the original 2026 deadline back. 

Whatever the final date, increased regulation is coming, and you can’t classify what you haven’t listed. The inventory is the input to every risk decision that follows.

Identifying every system, assessing the risk across data, tools, models, and vendors, and setting controls proportional to that risk is the first work we run in an AI governance program

The policy sets the direction, and the inventory is what you govern from.

Build it before you need it

An inventory can feel like busywork until the moment you need it and don’t have it: the customer questionnaire you can’t answer, or the incident on a line running a model no one remembers approving. 

Built ahead of that moment, it’s the foundation every other governance decision stands on.

If you don’t know what AI is running in your operation, that’s where to start.

Talk to us, and we’ll help you build the inventory and turn it into governance you can prove.

Risk is constant. Ready is a choice.

Latest Cyber and AI Insights

Improve your readiness, combat disruption

Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.

Because while risk is constant, ready is a choice.

How to Build an AI Use Case Inventory for Your Manufacturing Operation

How to Build an AI Use Case Inventory for Your Manufacturing Operation

You've been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers...

Read more
Program, Not Project: Why Cybersecurity With a Start and End Date Doesn’t Work

Program, Not Project: Why Cybersecurity With a Start and End Date Doesn’t Work

You passed the audit. The certificate went up on the wall. The consultant packed up, the engagement closed out,...

Read more
The Four-Week Shutdown: What Happens When a Manufacturer Loses Every System

The Four-Week Shutdown: What Happens When a Manufacturer Loses Every System

It's 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on:...

Read more