← All posts

Architecture · 28 September 2026 · 6 min read

Hybrid AI in manufacturing: what goes private, what goes managed

Not every AI task in a plant carries the same risk. A simple routing rule lets you use the strongest models where they help, without sending process knowledge anywhere it shouldn’t go.

Most manufacturers now face the same question from two directions. Engineers want the best AI models available, because they are genuinely useful. IT, OT security and quality teams want to know exactly where plant data goes, because a recipe, a drawing or a year of sensor history is the company’s edge. Treating this as a choice between “all private” and “all public” leaves value on the table either way.

Hybrid AI resolves it by deciding per task, not per company. Every request passes a policy check before any model sees it. The check asks one question: does this task involve confidential data? If yes, or if the answer is unclear, the request runs on private models in your own infrastructure. If the task only involves public information, it may use a managed model such as Claude, GPT or Grok.

Tasks that should always stay private

In manufacturing, the private list is long, and that is fine. It includes:

  • IoT and sensor streams. Vibration, temperature, pressure, energy and PLC data describe how your process really runs. Patterns in that data reveal throughput, yields and weak points.
  • Camera video. Footage shows your process, your layout and your people. It belongs on edge servers at the plant, not in a vendor’s cloud.
  • Process recipes and parameters. Setpoints, windows and material choices are often the result of years of tuning.
  • Drawings, BOMs and change requests. Design data may also fall under export-control rules.
  • Quality and supplier records. Non-conformances, 8D reports and audit findings carry both commercial and customer information.
  • SOPs and work instructions. Your procedures encode how your plant works; they are also what makes answers useful.

Tasks that can use a managed model

Some work involves only public information. Summarising supplier news, tracking commodity prices, reading public regulation such as the EU Machinery Regulation, or drafting generic product descriptions can go to a managed model. You pay per token for that share only, and you can cap it monthly or switch it off.

The useful pattern is to split mixed tasks in two. A buyer asking “what changed for our key suppliers this quarter?” gets a managed summary of public news, then a private step maps that summary against your supplier list and contracts. The managed model never sees who your suppliers are.

Right-sizing inside the private route

Private does not mean one large model for everything. Alarm triage and work-instruction lookup run well on small language models that answer in milliseconds and cost little. Vision models handle inspection, time-series models handle sensor data, and larger models are reserved for root-cause reasoning and complex drafting. This is what keeps the cost per answer low when volumes run around the clock.

When in doubt, it stays private. The default protects you; exceptions are explicit.

Making the rule auditable

A routing rule only builds trust if people can see it working. Every request should record which route handled it, which sources it used and who approved the output. Customers, certification auditors and your own quality team will ask. With a log per request, the answer takes minutes, not a project.

Where to start

Write your own “what goes where” table: list ten tasks your teams would like help with, and mark each one private or managed. Most plants find that eight or nine are private, and that the managed share is small but valuable. That table becomes the first configuration of your policy check.