
The Defect Lens: AI in Manufacturing Quality Vision
Computer vision systems are helping factories detect defects, explain process drift, and close the loop between inspection and production control.
Read MoreZharfAI Team

An industrial copilot is not an office chatbot placed on a rugged tablet. It operates around moving equipment, heat, dust, noise, gloves, weak connectivity, shift handovers, permits, and procedures where a plausible wrong answer can injure someone. The product must therefore be designed as part of the work system: worker, machine, procedure, supervisor, safety control, and software.
The strongest use cases are modest but valuable. A copilot can retrieve the correct procedure for a specific asset revision, show the next checklist step, interpret an alarm with sensor context, capture a hands-free report, translate approved instructions, and assemble a maintenance handover. It should not improvise a bypass, declare equipment safe, or substitute a generated answer for lockout/tagout, permit-to-work, engineering judgment, or emergency procedure.
A field request such as “Why is pump 204 vibrating?” is incomplete. A reliable system first resolves identity and state:
Only then should retrieval search approved manuals, drawings, work orders, lessons learned, and engineering notices. The response should cite the exact document, revision, section, and effective date. Sensor values need units, timestamp, freshness, and quality flags. If identity, isolation state, or documentation is ambiguous, the system should stop and escalate.
This architecture is closer to a controlled maintenance interface than a general assistant. It also depends on AI data-quality observability: stale telemetry or a mismatched asset tag can make an otherwise accurate explanation unsafe.
The NIOSH 2026 bulletin on managing workplace AI hazards argues that familiar occupational-health methods can be extended to algorithmic systems. It distinguishes software from the physical platform it influences, notes that algorithms can change the risk profile of machinery and work organization, and highlights both work-design and software-design controls. NIOSH presents this as an emerging framework, not a finished certification standard.
Apply the hierarchy of controls before adding AI. Eliminate a hazard where possible; substitute a safer process; use engineering and administrative controls; then use personal protective equipment. A copilot is usually an administrative aid, not an engineering safeguard. It must never be represented as replacing a guard, interlock, gas detector, relief system, or competent-person inspection.
The NIOSH occupational risk assessment frames risk through what can happen, how likely it is, and the consequences. Use that structure for each copilot function. Also assess psychosocial effects: workload intensification, constant monitoring, reduced autonomy, skill erosion, unfair performance evaluation, and pressure to follow a machine recommendation. EU-OSHA’s work on AI-based worker management emphasizes transparency, worker participation, stress, fatigue, and autonomy.
The ILO’s 2025 global report on AI, digitalization, and occupational safety and health likewise treats worker participation and preventive risk assessment as core controls. It is a global policy report rather than a plant-specific standard, so teams must still apply local safety law, collective agreements, competent-person requirements, and equipment procedures.
A technician scans a compressor tag after a high-discharge-temperature alarm. The copilot confirms the asset and displays the alarm timestamp, sensor quality, current shutdown state, and active work permit. It retrieves the approved troubleshooting procedure for that compressor revision.
The system asks the technician to confirm isolation before inspection. It does not infer isolation from a single digital flag. It shows three approved checks: verify cooling-water flow, inspect the relevant filter differential, and compare the temperature sensor with a redundant instrument. Each step includes a citation and a “cannot confirm” option. Voice input works, but critical confirmations require an intentional tap or physical control compatible with the site’s safety practice.
The technician reports a damaged hose and attaches a photo. Computer vision can suggest the component class, but the worker confirms it. The copilot creates a draft work order, lists the observed evidence, and routes it to the supervisor. It cannot restart the compressor, alter a setpoint, clear the alarm, or approve the repair.
If connectivity drops, the device continues only with a signed, cached procedure bundle whose revision and expiry are visible. Live telemetry is marked unavailable. If the cached procedure is expired or the asset identity does not match, the workflow stops. This is the kind of boundary described in our operational readiness checklist for AI.
Identity: Prefer scan-plus-confirm over free-text asset names. Prevent workers from carrying context accidentally from one asset to another.
Interaction: Test with actual gloves, hearing protection, lighting, vibration, languages, and connectivity. Voice recognition in a quiet lab says little about performance beside a turbine.
Attention: Keep critical instructions short and sequential. Do not cover alarms with a chat window. Use consistent severity, color, sound, and haptic patterns, and preserve established plant conventions.
Evidence: Show document citations and sensor provenance beside the recommendation. Let the worker open the source without losing the task state.
Stop state: “I do not know” must be a designed outcome. Uncertain asset identity, conflicting procedures, stale sensor data, or a safety-critical question should trigger a named escalation path.
Accessibility and language: Translate only from controlled source material, validate safety terminology with competent reviewers, and preserve numbers, units, warnings, and diagrams. Record which language version the worker saw.
Offline behavior: Define exactly what remains available. Never silently replace live context with cached values. Cache signed documents, enforce expiry, and synchronize annotations with conflict handling.
Observe technicians across shifts and sites. Document decision points, interruptions, workarounds, handoffs, environmental constraints, and existing controls. Include operators, maintenance, contractors, supervisors, safety professionals, engineering, labor representatives, accessibility specialists, and IT/OT security.
Good pilots include manual retrieval, report drafting, parts identification with confirmation, or a non-safety-critical checklist. Avoid autonomous control, diagnosis that directly triggers action, performance scoring, or emergency response as a first deployment.
Assign owners to procedures and drawings. Capture asset applicability, revision, effective date, superseded status, language, and approval. Retrieval should exclude drafts and expired material. Establish a rapid path to publish safety bulletins.
Use different technical permissions. Reading telemetry is not permission to write a setpoint. Drafting a work order is not approval to issue it. A copilot should have its own identity, least-privilege access, and complete tool logs.
Evaluate noisy speech, damaged labels, similar-looking assets, dirty camera lenses, poor lighting, unit conversions, stale sensors, contradictory documents, network loss, and rushed users. Include red-team scenarios where a QR code, note, or document contains malicious instructions.
Compare the copilot with the current process without changing authority. Record retrieval accuracy, task time, escalation, near misses, worker confusion, and supervisor corrections. Expand only after safety and worker representatives review evidence.
Hallucinated procedure: Require retrieval from approved sources, sentence-level citations, and refusal when sources do not support an answer.
Wrong asset or revision: Bind sessions to a verified asset, display identity persistently, and re-confirm after interruption or handoff.
Automation bias: Ask workers to confirm observable facts rather than accept conclusions. Train supervisors to treat overrides as information, not disobedience.
Skill atrophy: Preserve manual drills, mentoring, diagnostic reasoning, and competency checks. Use the copilot to teach why a step matters, not only what to tap.
Surveillance and labor harm: Do not repurpose assistance logs for individual productivity scoring without a separate lawful, transparent process and worker consultation. Minimize personal data and define retention.
OT cybersecurity: Isolate the assistant from control networks, authenticate devices, sign cached content, restrict tools, monitor access, and maintain a manual fallback. Treat documents and sensor fields as untrusted input.
Vendor dependency: Require offline and exit capabilities, exportable logs, model-change notice, incident response, data-use limits, and evidence of secure development. The organization remains responsible for site safety.
Measure safety and work quality before adoption:
Release gates should require zero unresolved catastrophic failure modes, approved hazard analysis, role and permission validation, worker training, a tested manual fallback, rollback, incident response, and named safety ownership. A small average time saving does not compensate for a rare high-consequence error.
Classify every feature:
This boundary keeps field-service AI useful without pretending a language model is a safety controller.
No. It can reinforce approved work and make knowledge easier to retrieve, but workers still need competency, supervision, and practice without the tool.
Read-only access may be appropriate after security and safety review. Write access sharply increases consequence and should be avoided unless it belongs to a separately engineered, validated control system.
No. The source may be outdated, inapplicable to the asset, or misunderstood. Applicability, state, role, and procedure hierarchy matter.
Investigate the pattern. Overrides may reveal poor retrieval, local conditions, an outdated procedure, missing training, or unsafe work pressure. Do not simply reduce worker discretion.
Operations, safety, engineering, workers, security, and IT each own part of it. One accountable business owner must coordinate the whole safety case and stop the system when evidence degrades.
The best frontline copilot makes approved knowledge easier to use while preserving the worker’s authority to stop, question, and escalate. It recognizes the asset, cites the procedure, exposes data freshness, operates safely offline, and cannot cross into control without explicit engineering. Design it around the real work system and safety case—not a demo conversation.
Sources reviewed and current as of July 30, 2026:

Computer vision systems are helping factories detect defects, explain process drift, and close the loop between inspection and production control.
Read More
AI helps field teams predict failures, schedule technicians, prepare parts, and capture repair knowledge from every visit.
Read More
A hazard-first guide to AI in exploration, ore sensing, equipment safety, maintenance, processing, and environmental monitoring with community oversight.
Read MoreSee the daily briefing and the operational guides. This page is an archive note, not an invitation to start a project.