
Key takeaways
- AI is already in use for the vast majority of manufacturing organizations, with a scarce minority reported to not be using AI tools at all.
- Uses include modeling for preventative maintenance and third-party risk assessment. Without proper guardrails, users may inadvertently expose the manufacturer to risk.
- The regulatory landscape is rapidly expanding and evolving for AI, but a foundation of effective governance can simplify compliance when new rules go into effect.
AI deployment is speeding ahead. Is governance keeping pace?
Like other industries, manufacturing has been quick to implement artificial intelligence in its operations. Only 6% of industry risk and compliance leaders told NAVEX there was no AI use anywhere in the organization in our 2026 Risk & Compliance Report survey, and only 3% said there was no usage planned in the next 12 months.
However, as these technologies quickly and profoundly transform operations for manufacturing, is governance keeping pace? Manufacturing organizations appear to be aware of the need – in our survey, a combined 79% of industry respondents said Compliance was either “very” or “somewhat” involved in decision-making regarding AI use. This is a strongly positive signal, but as AI’s role for manufacturing evolves, compliance teams must continue to possess the knowledge and resources to inform rules around its use – and ensure the spread-out business units common for the industry are all following suit.
What AI governance actually means on the shop floor
Effective AI governance for manufacturing is more than just a set of policies that sit on a shelf. Like all effective policies, AI governance must live and breathe in the way the organization conducts its operations – something practiced and known by each person on the factory floor.
The accessibility of AI models is a great strength driving innovation in their use. Looking for efficiencies, workers are, and increasingly will be, discovering ways to more quickly complete routine tasks and find innovative solutions to problems. Yet that accessibility is also a source of risk, giving rise to “shadow AI” use throughout the organization. Without proper guardrails, users may inadvertently cause issues like the exposure of future product plans, proprietary designs and other trade secrets, or creation of output errors. Proper governance is critical to ensure these risks don’t outweigh the very real benefits that continue to reveal themselves through AI innovation.
The use cases for AI in manufacturing continue to mature. Today, firms are reported to be using AI to parse extensive operational data to prioritize where preventive repairs can reduce costly production downtime in the future. In 2026, 14% are using the technology for third-party risk screening and due diligence, with that share expected to double in the coming year, according to NAVEX survey data. And worker safety stands to benefit from stronger, more proactive assessment of leading risk indicators and the expedited investigation of reported issues.
These are just some emerging examples where model ownership, documentation that outlines acceptable uses and ongoing monitoring of outputs will be important. Through it all, Compliance needs a seat at the table.
AI’s new challenge for supplier risk
Manufacturers have a long history of managing operational risks such as production downtime, equipment failure and worker safety. Connected compliance strategies and systems helped address the expansion of those challenges across increasingly complex supply chains. Now, these approaches face a new frontier in risk management with AI.
Third-party suppliers – be they for back-office software, assembly-line services, physical materials or some other function – are themselves now exploring their own ways to leverage AI. As part of a holistic approach to risk management, manufacturers must now incorporate the AI practices of their third parties. Are those third parties implementing AI in a way that ensures the manufacturer’s sensitive data is protected? Could a malicious actor at the third-party level leverage AI to discover or create some vulnerability in the manufacturer’s process?
Like other elements of third-party risk management, a connected compliance approach enabling continuous monitoring and effective risk assessments is increasingly critical as the web of these supply chain relationships expands.
The regulatory clock is running
Regulatory jurisdictions around the globe are developing their frameworks for AI compliance. Given the often global nature of manufacturing, this introduces a new and potentially urgent realm for Risk and Compliance to act.
Perhaps the first major example of comprehensive regulation around AI is the EU Artificial Intelligence Act. This continues the European Union Parliament’s appetite for comprehensive regulation around emerging technology, akin to the General Data Protection Regulation, and touches many elements of operations for manufacturers based in, or doing business with, the EU. Yet the EU AI Act is far from alone – a global matrix of rules is rapidly emerging and subject to reinterpretation, from anti-bias hiring screening rules in New York City to a host of sector-specific guidelines. In short, regulations around AI are widespread and moving fast.
Organizations should not wait for regulations to become mandatory before establishing governance, documentation and accountability processes around how AI is used. Connected compliance systems and practices can make sure those tools and controls are getting out to the front line and supply chain before it’s too late. Existing compliance frameworks – including those in effect for jurisdictions that may not ever impact the manufacturer – can serve as a foundational starting point.
The commercial cost of the governance gap
The business costs of weak AI governance are only going to compound for organizations, including manufacturers, into the future.
For one, there is the pure regulatory risk. The EU AI Act, for example, threatens penalties for some noncompliance that can include fines of up to 35 million Euros or 7% of annual turnover the prior year – whichever is greater. Other commercial costs could include operational disruptions, misinformed decision-making, reputational damage and loss of customer trust.
With strong governance, each of these areas can be addressed. This makes strong AI governance a competitive advantage for manufacturers, improving resilience and laying the groundwork for thoughtful adoption of AI in the future.

Things to do now
Manufacturing organization have opportunities now to quickly advance their maturity in AI governance:
- Take an inventory to improve visibility: Where is AI currently being used across operations? This includes ad hoc uses that individual employees may implement, as well as practices within key third-party suppliers.
- Develop governance policies: At a high level, establish rules around AI that define acceptable use, responsibilities, oversight and risk assessment, and address any immediate regulatory pressures.
- Put governance into action: Equip individuals throughout the business with the training and tools to act in accordance with newly developed governance policies. Deploy training where needed and at scale, and ensure tools and practices are widely implemented to assist in risk assessments while providing information back to decision makers at the highest levels of the organization.
With this foundation, the organization can adapt as regulatory expectations continue to evolve. At all points in decision-making regarding policies around AI use, ensure Compliance has a voice in the discussion.
Create a strong foundation for AI governance
Risk and Compliance has a major role to play in building a future-proof foundation for AI governance practices in manufacturing. This will only become more important, and more of an opportunity, as the use of AI continues to grow.
Discover how a unified approach to AI governance and compliance management can help your organization navigate new risks while achieving benefits that help it speed ahead.


