When Cyber-Physical Systems Collide with Privacy and IP: Preparing Manufacturing for AI’s Next Chapter

Hillstrong Group Security ·

AI and LLMs are beginning to blur operational, privacy, and intellectual property boundaries – boards must set the guardrails now

Author: Roger Hill

A change that will catch leaders off guard

Factories were designed to optimize throughput and protect physical safety. The information they generated -sensor readings, control logic, maintenance logs- was treated as technical. It mattered to operators and engineers, but it never drew the attention of regulators, lawyers, or auditors.

That clean division is starting to disappear. As vendors fold AI features into their products and researchers test large language models (LLMs) on operational data, manufacturing executives face a new reality: information once considered harmless can now be classified as personal, regulated, or strategically sensitive.

This shift is not happening at scale yet. But it is emerging fast enough that boards who wait until adoption is widespread will find themselves reacting under duress rather than shaping terms of engagement.

When plant data stops being “just plant data”

One of the quiet surprises of early AI adoption is how ordinary operational data changes character once models begin to process it.

Take cameras. Vision systems installed for quality inspection do more than check product tolerances; they capture images of workers in the frame. Those images may qualify as biometric data.

Consider logs. An LLM trained to summarize maintenance reports doesn’t just highlight equipment conditions; it can also surface names, comments, and shift patterns. What was once a troubleshooting record suddenly looks like a labor file.

Even optimization algorithms can push boundaries. A scheduling tool may begin surfacing insights about team performance. Regulators could easily interpret that as a form of surveillance.

None of these examples are science fiction. They are plausible consequences of how AI changes the nature of data. The lesson for executives is simple: once AI enters the loop, operational information can no longer be assumed safe from privacy obligations.

The overlooked crown jewels

Privacy is only part of the story. Intellectual property – the formulas, tolerances, and configurations that define how plants actually run- may be even more exposed.

Many AI-driven services ask for access to detailed technical information. That can mean:

  • recipes and formulations developed over decades
  • PLC configuration files that encode sequencing and tolerances
  • OT network diagrams that show exactly how critical assets are connected

If this material is uploaded into a vendor’s AI system, the company has lost control over some of its most valuable assets. Vendors often retain the right to keep data for “model improvement.” Once that happens, your competitive advantage may be sitting in someone else’s pipeline.

It’s not hard to imagine how this unfolds. An engineer, under pressure to get a line back up, sends configuration files to an AI assistant for faster troubleshooting. The files help resolve the problem, but they also reveal how that process is tuned. Unless clear contractual protections are in place, that information may not stay contained.

For boards, this is not a technicality. It is a direct threat to shareholder value.

Data doesn’t always stay where you think

Almost every AI service in the industrial space is cloud-first. That means the data collected, whether logs, images, or configurations, often leaves the plant. Even in pilots, it may travel across jurisdictions, where different privacy, labor, or export laws apply.

Few manufacturers today have a clear line of sight on these flows. Questions that rarely get asked include:

  • Where is the data physically stored?
  • Which subcontractors are processing it?
  • What legal regimes govern access once it leaves the country?

The answers matter. A misstep here doesn’t just create a compliance problem, it can generate headlines, lawsuits, and a loss of trust with regulators who will expect you to have known better.

The problem isn’t just what AI collects – it’s what it infers

LLMs are particularly tricky because they don’t just store data; they generate new insights. Those insights can reveal more than the underlying records ever did.

Maintenance logs that once documented machine failures might, when analyzed, highlight absenteeism patterns or flag a labor dispute. A scheduling optimizer could suggest vulnerabilities in a supplier’s workforce. Quality models might tie defect rates to certain crews, effectively turning process monitoring into performance monitoring.

Executives should assume regulators will view inferences as carrying the same obligations as raw data. A profile created by a model can be just as sensitive as the identifiers it was built from.

Governance is already behind the curve

Most manufacturers do not yet have a board-level AI policy. That is understandable, adoption is limited, and much of what exists is experimental. The problem is that pilots are moving forward anyway. Without governance, early projects establish habits by default: sending logs to vendors, uploading configurations, streaming video feeds without restrictions.

Once those practices normalize, they are hard to undo. Culture and convenience set in. At that point, governance is playing catch-up.

The deeper issue is fragmentation. Vendors disclaim liability. IT leaders see it as an OT concern. OT leaders dismiss it as “just data.” Privacy and legal are consulted only when a regulator calls. This lack of ownership is itself a risk. AI doesn’t respect organizational silos, and neither will regulators when they assess accountability.

How it could play out in practice

To make this real, consider a few plausible scenarios:

  • Defect detection pilots. A food processor tests an AI vision system to flag flawed products. The system also records workers at their stations. If those images are retained, they may be treated as biometric data.
  • Shift log summaries. A manufacturer experiments with LLMs to speed up maintenance reporting. The model not only highlights equipment issues but also surfaces names and notes about individual employees. A tool built for efficiency now carries privacy implications.
  • Cloud-based anomaly detection. A plant streams OT traffic to a vendor’s AI platform. Months later, it becomes clear the data was routed offshore through subcontractors. That discovery creates compliance questions the board wasn’t prepared to answer.
  • AI-driven support tools. Engineers upload PLC configuration files into a vendor’s troubleshooting assistant. Those files encode process IP central to the company’s competitive advantage. If they are stored, the vendor has information competitors would pay dearly to see.

These examples aren’t predictions, they’re cautionary illustrations. They show how quickly operational experiments can bleed into privacy, compliance, and IP exposure.

What boards should do now

The point is not to stop experimentation with AI. The point is to shape it with guardrails. Boards can take several steps immediately:

  • Issue an AI governance policy. Even a short one makes clear what data can and cannot be used, how IP must be protected, and who approves exceptions.
  • Run impact assessments. Treat AI pilots the same way you would a new system handling customer data. Document risks before deployment.
  • Set vendor terms. Contracts should prohibit retention or reuse of your operational data and IP. Do not accept vague promises of “best practices.”
  • Use frameworks as scaffolding. The NIST AI Risk Management Framework and the EU AI Act offer useful benchmarks. They give boards a way to show regulators that standards were considered early.
  • Name a single accountable executive. Decide now who owns AI governance, CIO, CISO, or COO. Shared accountability often means no accountability.

What this means at the board table

The key issue isn’t whether AI is pervasive in your plants today. It isn’t. The issue is whether you are setting standards before adoption accelerates.

Operational data once treated as harmless is on a trajectory to become regulated or strategically sensitive. AI features, LLMs especially, are the catalyst. They collapse the boundaries between operational security, information security, privacy, and intellectual property protection.

Boards that move early can adopt AI responsibly and defend their competitive position. Boards that wait will face difficult questions about why sensitive data was allowed into vendor pipelines without safeguards.

The next part of this series will focus on accountability. If AI introduces new categories of risk, who owns them? Vendors rarely accept liability. Leaving responsibility undefined is an option no board can afford.

Want this as a playbook?

Every guide we publish has a companion eBook with templates you can use today.