
Manufacturing’s historically cautious approach to new technology is being tested by AI. Already, 46 percent of operations are using AI-powered tools like chatbots, and more than 80 percent expect to increase their AI use in the next two years, according to the National Institute of Standards and Technology.
But the same technology that’s helping manufacturers analyze data and automate work is also making attackers more capable. Social engineering is becoming more convincing, while AI systems are creating new entry points to compromise company data. CrowdStrike’s 2026 Global Threat Report found an 89 percent increase in AI-enabled attack methods.
AI can create meaningful value for manufacturers, and waiting too long to adopt it can erode competitive advantage. But moving too quickly without understanding how AI changes the security landscape can introduce risks organizations may not know to look for.
The challenge is defining how far AI’s access and authority should extend. If an AI agent can retrieve data, execute tasks, or influence decisions, securing it means setting clear boundaries around what it can access and act on.
A Different Kind of Attack Surface
In 2025, manufacturing was the most-targeted industry for cyberattacks for the fifth consecutive year, according to IBM’s X-Force Threat Intelligence Index. It makes sense when you consider manufacturers’ valuable operational and intellectual property data is frequently housed in process-control environments with immature IT security.
Now, AI adoption is adding another layer of exposure. Manufacturers are connecting models and agents to more data and systems, creating new dependencies and more places attackers can find a way in.
Once large language models (LLMs) have access to company data and the ability to execute tasks, attackers can attempt to manipulate those capabilities through techniques like various forms of prompt injection and jailbreaking. Manufacturers face a growing attack surface while attackers become more sophisticated.
To put that risk in practical terms, imagine a scenario in which a manufacturer deploys an AI agent to respond to vendors about purchase orders and invoice payments. If access boundaries aren’t properly configured, an attacker could manipulate the agent into revealing market information that is sensitive. Even natural-language guardrails may not be enough to prevent these types of breaches if more sophisticated prompting can work around them.
The more access and authority an AI system has, the greater the consequences if those boundaries are crossed — which is why manufacturers need to define what it should be able to access and do in the first place.
How Manufacturers Can Safely Scale AI
No organization can eliminate risk entirely. But manufacturers also shouldn’t add so many controls that the cost and constraints outweigh the value AI is meant to create.
Scaling AI safely means being deliberate about how much access and authority each application needs and whether the safeguards around it match the risk. The following steps can help you manage AI-related risks without slowing innovation or limiting the technology’s potential.
- Trace Your AI supply chain. An AI-enabled product may rely on models and infrastructure from providers beyond the company you bought it from. This is called an “AI supply chain,” where your data can move through technology service providers you don't directly manage. Leaders need to know which providers are involved, how their systems connect, where company data travels, and how it can be used or retained. Otherwise, you may understand your direct provider's security while missing other places your information could be exposed. Vendor evaluations should address both the technical and commercial sides of the relationship. SOC 2 audits can help assess core infrastructure, while ISO 42001 can provide insight into AI-specific management practices. Manufacturers should also review providers’ data-use and retention terms to understand where their information may be accessible and determine which AI applications justify that level of risk. Moreover, technology providers must be transparent to their customers about the third parties being used and the contractual obligations they hold them to.
- Set Identity and Access Boundaries. Identity management, a foundational aspect of cybersecurity of any institution, gets more complicated when AI agents can operate with different levels of authority or impersonation. An agent working directly with an employee may need to perform tasks on that person’s behalf, while an autonomous agent may need its own identity and boundaries. In either case, define which systems and data the agent can access, what actions it can take, and whether it does so under a user’s credentials or its own. Those permissions should be limited to what the agent needs to perform its job. Boundaries limit the damage if an agent is manipulated or behaves unexpectedly. The less unnecessary access it has, the less information and fewer systems it can expose.
- Evaluate if the Use Case is Ready for AI. Secure infrastructure and tightly controlled access still don't make every task appropriate for AI. You also need to consider what happens if the system gives the wrong answer or takes the wrong action. Think about an agent that provides employees with safety procedures. Without the right validation layers, it could recommend an action that isn't grounded in your operation’s safety protocols — resulting in a more serious consequence than an agent making a mistake on a routine administrative task. Start with the consequences, then work backward to the safeguards. Higher-risk applications may require stronger validation and human oversight, while lower-risk uses may not warrant the same controls. That keeps security proportionate to what the business could lose without adding so much friction that AI stops being useful.
Making Security Part of AI Adoption
AI can deliver meaningful efficiency gains and open new business opportunities. I’ve seen that firsthand. But like every major technological shift, it also introduces new risks.
As manufacturing leaders, we understand this tradeoff well. We operate complex facilities where failure can carry serious consequences, yet decades of better engineering, stronger safeguards, and continuous learning have made those operations safer.
AI needs to follow a similar path. As we give these systems greater access and authority, we need to be just as intentional about defining where that authority stops. That understanding helps us make better decisions about where and how to apply AI as both the technology and threats evolve.






















