Every week another vendor tells a defense manufacturer that AI will transform the shop. Most of the time the shop does not have an AI problem at all. It has a value-stream constraint, a single bottleneck choking the flow of work, and pointing AI at it without seeing it first just automates the waste and makes it faster.
The right question is not "where do we add AI." It is "where is the work actually stuck, and which of those steps is safe to let a machine touch in an environment governed by export control and Controlled Unclassified Information." Those are two different investigations, and you run them in that order.
Why most shops have a constraint, not an AI problem
A constraint is the one step in your process that limits the throughput of the whole system, and adding capacity anywhere else just piles up inventory in front of it. This is the core insight of the Theory of Constraints, and it predates the current AI cycle by decades. If your bottleneck is a single inspection station, a slow quoting process, or one engineer who is the only person who can release a job, then automating the steps around it does nothing for your output. The work still waits at the constraint.
This is why the first move is never the technology. It is the map. Map the value stream, the full path work takes from order to cash, and the constraint becomes visible. Often the most valuable finding is that a step everyone wanted to automate should not exist at all. Automating a broken process only makes the waste faster, and in a regulated shop it can make a compliance gap faster too.
If you cannot draw the value stream on a whiteboard and point to the constraint, you are not ready to buy AI. You are ready to map.
Where AI safely helps in a regulated manufacturing operation
AI safely handles cognitive drudgery, the repetitive, high-volume work that consumes a skilled person's day without using their judgment. In a manufacturing operation that includes several real, low-risk applications:
- Documentation drafting. First drafts of work instructions, meeting notes, and routine reports that a human then reviews and approves.
- Anomaly flagging. Surfacing an out-of-pattern reading from machine or quality data so a person looks where they should look, without the machine making the call.
- Data entry and reconciliation. Moving structured data between systems and flagging mismatches, the rote work that breeds errors when humans do it tired.
- Search and retrieval. Helping an operator find the right revision of a procedure or the relevant clause in a standard quickly.
The pattern across all of these is the same: AI does the cognitive grunt work so a technician moves up into higher-judgment work, and a human stays accountable for the output. The goal is to augment the operator, never to replace the operator's judgment.
Where a human must stay in the loop
A verified human must own every decision that touches CUI, data integrity, or a compliance affirmation, with no exception for convenience. These are the decisions where an automated mistake is not a typo to fix later. It is a regulatory event.
That means a human reviews and signs:
- Any affirmation made to the government, including your SPRS self-assessment score and the attestations that ride on it under the False Claims Act (31 U.S.C. §§ 3729-3733).
- Any change to a record that establishes product conformity or traceability under AS9100.
- Any decision that determines whether information is or is not CUI, and therefore how it must be handled.
- Any release of a part, a document, or a design to a customer or supplier.
The principle is simple to state and hard to hold when a vendor is promising speed: in a regulated environment, automation proposes and a verified human disposes. The human-in-the-loop is not friction to be optimized away. It is the control that keeps an efficiency gain from becoming a compliance failure.
The data guardrails AI must respect: CUI and ITAR
The hard line is that Controlled Unclassified Information and export-controlled technical data must never enter a public AI model, because doing so can be an unauthorized disclosure or export. This is the guardrail that gets violated by accident, by a well-meaning engineer pasting a drawing or a process spec into a consumer chatbot to save ten minutes.
Two regimes govern this:
- CUI under DFARS 252.204-7012 and NIST SP 800-171. Covered defense information has to be protected on systems that meet the 110 NIST SP 800-171 controls. A public, consumer AI service is not such a system. Sending CUI to it puts the data outside your protected boundary and can create the same false-affirmation exposure as a wrong cybersecurity attestation.
- Technical data under ITAR (22 CFR 120-130). The International Traffic in Arms Regulations control the export of defense-related technical data. Transmitting that data to a model that processes or stores it outside controlled, US-person-only infrastructure can constitute an export, even if no part ever physically ships anywhere.
The practical guardrails follow directly:
- No CUI or ITAR-controlled data into public models, ever. Where AI touches regulated data, it runs inside your accredited boundary or a properly scoped enclave, not a public endpoint.
- Know your boundary before you deploy. If your MES, ERP, and SCADA environments are not mapped and access-controlled, you cannot say with confidence what an AI tool would be able to reach. The IT/OT environment has to be governed first.
- Log what the model touched. The same logging discipline NIST SP 800-171 requires for CUI applies to an AI tool operating inside that boundary.
CMMC raises the cost of getting this wrong. As of July 2026 the mandatory third-party phase is suspended, and the Level 2 self-assessment and annual affirmation are not. That puts your signature, rather than an assessor's finding, on the claim that data moves through your systems the way the 110 controls require. An ungoverned AI tool with a path to CUI is a finding waiting to happen, and you are the one attesting it is not there.
How to bring AI into the shop without creating risk
You bring it in by following the same order every time: map the stream, find the constraint, decide whether the step should exist, then choose the smallest safe automation that keeps a human on the judgment. The sequence is the protection.
I map the value stream first, because that is where the real constraint reveals itself and where most "AI projects" turn out to be process projects in disguise. Then I separate the work into what a machine can safely do, the drudgery, and what a verified human must own, anything touching data integrity or compliance. Then, and only then, the data-handling guardrails decide what can run where: public model for non-sensitive drafting, accredited boundary for anything near CUI or ITAR. Foundation before transformation. Clean, governed data and a documented process come before any new technology gets switched on.
The framework behind this discipline: Standard Work 2.0™
Everything above is the operating logic of Standard Work 2.0™, the proprietary methodology of Garrett Partridge LLC. Traditional Lean tools were built for the visible shop floor, the machines, the parts, the physical flow. The margin threat in advanced manufacturing now lives in the hidden factory: the manual tax of tribal knowledge and administrative friction. Standard Work 2.0™ closes that gap by treating AI subroutines the way a production line treats operations, as standard work with stations, checks, and owners. Four components carry it:
- The H.I.L. Subroutine Map. Complex AI tasks are deconstructed into verifiable operator steps with built-in quality gates. Just as a physical part is checked for accuracy at each station, an AI output is verified before it advances through the workflow. That is what earns zero-defect output from a probabilistic tool.
- The Risk-Based Tiering Model. A hard sort of which data belongs in a commercial LLM and which stays inside a compliant enclave, Microsoft GCC High or an on-premise system. The CUI and ITAR guardrails earlier in this article are exactly the boundary this model enforces, so a shop captures commercial LLM speed without surrendering data sovereignty.
- AI Maintenance & Manufacturing Engineering. New roles with a familiar shape: monitoring model drift and calibrating AI workflows the way a quality function monitors and calibrates instruments. A model that was accurate in March is an uncontrolled process by September unless someone owns its calibration.
- The 3-Step Training Guide. A practical method for training AI on a shop's unique operational logic without compromising security, so the model learns how your floor actually runs rather than how the internet assumes it does.
Garrett presents this framework in a conference session for lean manufacturing practitioners, "Standard Work 2.0™: Engineering the Human-in-the-Loop (H.I.L.) AI Strategy," a practitioner's roadmap for scaling responsible AI in high-consequence manufacturing, built around a tiered adoption model sized for the small-to-mid-size manufacturer.
The bottom line
In regulated defense manufacturing, AI earns its place on the cognitive drudgery, documentation drafts, anomaly flagging, data entry, while a verified human stays in the loop on any decision that touches CUI, data integrity, or a government affirmation. The first step is never the tool. It is mapping the value stream, because automating a broken or unnecessary process only makes the waste faster. And the one line you do not cross: no CUI and no ITAR-controlled technical data goes into a public model. Map the stream, keep the human, protect the data, in that order.
Sources
- 31 U.S.C. 3729, False claims. The statute behind the exposure that rides on an affirmation. Liability attaches to knowingly making or using a false record or statement material to a claim, and the statute defines "knowingly" to include acting in deliberate ignorance or in reckless disregard of the truth, expressly requiring no proof of specific intent to defraud. Damages are trebled. The False Claims Act runs from 3729 through 3733. This is the statutory location of the risk, not legal advice on your exposure, which is a question for government-contracts counsel.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. The clause requiring covered defense information to be safeguarded on systems meeting NIST SP 800-171. Its definition of a "covered contractor information system" is any unclassified system owned or operated by or for the contractor that processes, stores, or transmits that information, which is the test to apply to any AI tool you are considering.
- NIST SP 800-171, Revision 2. The controls for protecting CUI in nonfederal systems, including the logging discipline referenced above. Note that NIST withdrew Revision 2 in May 2024 in favor of Revision 3, while DoD still assesses CMMC Level 2 against Revision 2, and DFARS 252.204-7012 pins the revision to the one in effect when the solicitation is issued.
- DoD CIO, About CMMC. The source for the 110 security requirements, for the July 13, 2026 suspension of the mandatory third-party phase, and for the fact that the Level 2 self-assessment and annual affirmation remain in place. Retrieved July 16, 2026.
- 22 CFR 120.50, Export and 22 CFR 120.56, Release. Why sending technical data to a model can be an export with no part ever shipping. Releasing technical data to a foreign person inside the United States is a deemed export, and it is deemed an export to every country in which that person holds or has held citizenship or permanent residency. Under 120.56(a)(3), using access information to enable a foreign person to access unencrypted technical data is itself a release.
- 22 CFR 120.33, Technical data. The functional definition of what is controlled. Technical data is anything required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a defense article. No marking is required for it to be controlled, which is exactly why the engineer pasting a process spec into a chatbot does not think they are doing anything.
- AS9100D, Quality Management Systems, Requirements for Aviation, Space, and Defense Organizations. The current quality management standard for this industry, published by SAE International, incorporating ISO 9001:2015 and adding aviation, space, and defense requirements on top of it.
