The Distance Between Systems Is Becoming the Bill (1)
Industrial AI triumphs not by data ownership but by seamlessly integrating evidence into actionable insights across systems, preventing delays that incur costs.
Michael Carroll | The One-Degree Dispatch | Industrial AI and Decision Architecture
The Distance Between Systems Is Becoming the Bill End-Users Refuse to Pay Industrial AI will not be won by the vendor that owns the record. It will be won by the architecture trusted to reconcile the Purdue stack and turn evidence into permitted action before delay becomes cost. By Michael Carroll Founder, The One-Degree Dispatch | Industrial Transformation Leader | Advocate for Agentic AI and Automated Reasoning
Lead image: The operating room is not failing because people lack data. It is failing because evidence, permission, and actio n still live in different places.
At 7:42 in the morning, the operating review has already stopped being a meeting and started becoming an autopsy. The plant leader has the quality exception queue open on one screen, a supplier report printed beside the laptop, and a schedule that no longe r agrees with either. The controller is working from a cost variance file that still has to be reconciled before close. The CIO has an access dashboard open, with API activity marked in red and a policy question sitting behind every technical one. The down stream cost has not waited for the architecture to explain itself. It has already arrived as premium freight, extra labor, inventory sitting longer than planned, rework nobody wanted to defend, and a customer call that will sound responsible because the organization cannot bear to call it delay. No one in the room is careless. That is what makes the pattern hard to confront. Each person is competent inside the boundary he or she has been given. Each system is doing something close to what it was bought to do. ERP has
the order. MES has the production record. Quality has the exception. Maintenance has the asset history. The historian has the process signal. Finance has the variance. The plant has the consequence. The failure is not inside the application. It is in the distance between them. The visible debate is about APIs, systems of record, agentic AI, vendor access, and the next control point in enterprise software. The deeper industrial issue is harder. For decades, the Purdue model gave manufacturers a disciplined way to separate enterprise systems from operations systems, supervisory control, control logic, and the physical process. That separation protected the plant. It also created handoffs, translations, waiting points, and human reconciliation work that became so familiar people stopped seeing it as work. Agentic AI is now pressing against that arrangement because the value is not sitting inside one layer. The value is in the seams where evidence, permission, timing, and authority must meet before action still matters. What would have to be true for this outcome to keep repeating. It would have to be true that separation remains the safest possible architecture even when delay becomes more costly than movement. It would have to be true that humans should continue serving as middleware between systems because software cannot be trusted to carry context. It would have to be true that ERP can remain the business spine, MES can remain the operating record, SCADA can remain the supervisory lens, historians can remain the memory, and the enterprise can still afford to assemble reality by m eeting. Those assumptions built much of the modern industrial firm. They were not foolish. They are becoming expensive.
The old stack protected the plant by creating distance
The Purdue model was never a mistake. That has to be said plainly because much of the current AI argument becomes unserious when it treats inherited industrial architecture as mere technical debt. The separation between enterprise systems and operational technology exists because physical consequence is different from administrative consequence. A bad field in an ERP system can damage money, trust, compliance, and service. A bad action near the process can damage equipment, people, product, safety, and the right to operate. That is why the industrial stack developed layers. The enterprise layer could plan, commit, cost, procure, forecast, and report. The operations layer could schedule, track, execute, record, maintain, and manage deviations. The supervisory layer could monitor and guide the process. The control layer could execute deterministic logic. The physical layer could obey physics rather than ambition. The industrial DMZ stood between worlds because the plant should not be treated like an office network with larger ma chines. This architecture made sense in a world where most intelligence was human, most software was procedural, and most integration happened through people. A planner saw a demand change, a supervisor knew the line constraint, a quality leader knew whether a hold was serious, a maintenance leader knew whether the asset could survive another run, and finance saw the margin pressure after the fact. The work crossed layers because people carried it. They carried context, memory, permission, history, risk, and accoun tability. The human being became the connector because the systems could not be trusted to be the connector. That arrangement created discipline. It also created latency. Each layer protected itself by forcing translation at its boundary. Each boundary made sense until the work needed to move through all of them at once. A supplier issue does not stay in procurement. It moves into production, quality, customer service, finance, inventory, maintenance, and sometimes regulatory exposure. A process signal does not stay in the historian. It can become scrap, customer risk, safety exposure, asset degradation, and margin loss. The record may be local. The consequence is not.
The old stack separated consequence. The new contest is over who can move through it with legitimacy
Supporting image: The boundary protected the plant, but it also made people carry the work between systems.
This is why the next industrial AI fight will not be settled by asking which vendor has the best assistant inside its own product. The local assistant may be useful. It may make a transaction easier, a report faster, or a workflow cleaner. But the enterprise does not experience constraint locally. It experiences constraint when the schedule says one thing, the equipment says another, the batch record is incomplete, the customer is waiting, and the system of authority is still gathering itself. The false certainty is that better visibility solves this. It is a reasonable belief because industry has spent years improving sensors, dashboards, historians, data lakes, and analytics. Better visibility has produced value. It has helped companies see conditions earlier, monitor assets better, understand variation, and reduce some forms of waste. The trouble is that sight is not conversion. A signal seen but not authorized into action is only a more current form of waiting. That was the lesson from 1940. The harder historical point was not that Germany had tanks and France did not. France had serious armor. The stronger ledger still lost because one system converted assets, doctrine, communication, authority, and movement into consequence faster than the other converted strength into response. The tank was not the decisive asset by itself. The action loop mattered more. The same mechanism is now returning inside industrial software, without the romance and with far more balanc e sheet exposure.
The seams are becoming the surface
The old application era trained companies to think of work by system. ERP work lived in ERP. MES work lived in MES. Quality work lived in QMS. Maintenance work lived in EAM. Product work lived in PLM. Control work lived near SCADA and PLCs. Each domain had a record, a permission model, a user interface, a workflow, and a budget owner. This was useful for buying software and assigning responsibility. It was less useful for governing consequence. Agentic AI attacks the seam because the seam is where value has been trapped. It can read across records, form a question, assemble context, test patterns, propose containment, draft action, request approval, and log what happened. That does not mean it should be allowed to act everywhere. It means the old boundary between reading and doing is no longer sufficient. The serious question is not whether agents get access. The serious question is what kind of authority follows the inference.
Level 4, the enterprise layer, is where the abstraction risk begins. ERP, planning, finance, procurement, and commercial systems know demand, cost, promises, inventory, orders, and commitments. They are essential because business has to be made official somewhere. But official is not the same as physically true. A production order can be valid while the asset is degraded. A customer promise can be real while the process is unstable. A material substitution can be economical while increasing quality risk. A planning run can optimize the ledger while borrowing from tomorrow’s reliability. An enterprise agent operating from Level 4 will be tempted to make the plan true. It may recommend moving an order forward, changing a promise date, pulling inventory, substituting material, expediting a job, or compressing a maintenance window. Each recommendation may be rational from the business record and dangerous from the operating record. This is not an argument against enterprise agents. It is an argument against enterprise agents that cannot hear the plant before they speak for the business. Level 3 is where the war gets serious. MES, MOM, quality systems, maintenance systems, historians, production records, and operating procedures sit close enough to the work to understand constraint, but far enough from deterministic control to influence broad operating decisions. This is where the organization spends much of its hidden effort. It reconciles the schedule against capacity. It reconciles quality holds against customer promises. It reconciles maintenance risk against production pressure. It reconciles process drift against yield, cost, safety, and service. That is why Level 3 becomes the most valuable decision surface in the industrial enterprise. A system that can govern reconciliation here does not need to replace the ERP to become strategically important. It only has to become the place where the business asks what is true enough, what is permissible, what must be contained, what can wait, and what should happen before delay becomes cost. The system of record remains necessary. The route to action changes.
The system of record says what has been made official. The action layer decides what should be made true next
Figure 1: The most valuable work sits between the layers, where records disagree and people still have to decide what is true enough to act on.
The industrial DMZ then becomes more than a network boundary. It becomes a permission boundary for cognition. Historically, the DMZ helped manage traffic between IT and OT. In the agentic era, the harder question is not only whether a connection is allowed. It is what the actor is trying to cause. The old firewall asks who is connecting, by what route, and under what credentials. The new boundary must ask what the agent inferred, what it intends to touch, what downstream systems will trust, what action chai n is being constructed, and where authority must stop. This is where many companies will learn that they have an access architecture but not a permission architecture. Access says who can enter. Permission says what consequence may be shaped. A credential can be valid while the action remains illegitimate. A workflow can be approved while the inference remains weak. A write can be logged while the causal path remains unexamined. That is how authorized mis -action enters the plant.
Authorized mis-action is the new failure mode
Industrial cyber risk has trained companies to look for unauthorized access. That remains necessary. It is not enough. Agentic systems introduce a more difficult failure class because the actor may be permitted, authenticated, logged, and apparently compliant while still producing the wrong action from poor context, weak evidence, flawed inference, or misplaced authority. The dangerous event may not look like an attack. It may look like a recommendation. It may look like a schedule adjustment, a material release, a maintenance deferral, a batch disposition, an alarm ranking, a parameter suggestion, or a procurement action. The risk is not simply that the agent gets into the system. The risk is that the organization starts treating the agent as an interpreter of reality before it has earned the right to shape consequence. At Level 2, that risk becomes visible in the control room. Operator copilots, alarm assistants, procedure guides, abnormal-situation advisors, and shift-handoff tools will help, and in many cases they will be needed. Operators are asked to manage noisy signals, aging assets, complex procedures, thinner staffing, and rising expectations. A well-governed assistant can reduce burden and improve attention. But advisory systems can gain authority through presentation. If the system frames the event, ranks the ev idence, compresses the uncertainty, and offers the next step, the human may remain formally in charge while the machine has already shaped judgment.
Supporting image: Near the process, advice can become authority by presentation long before it becomes authority by design.
This is why human-in-the-loop is too weak as a standard. It sounds reassuring because it preserves the appearance of accountability. Yet a human click does not mean human judgment governed the decision. If the system narrowed the evidence, selected the frame, hid the weak signal, or made disagreement costly in the moment, the human may be carrying accountability for a decision architecture he did not control. The better standard is judgment-in-the-loop. The question is whether the human had enough context, time, authority, and dissent path to exercise judgment rather than merely bless the recommendation. At Level 1, the answer has to be stricter. PLCs, RTUs, interlocks, control logic, and configuration should benefit from AI-assisted documentation, comparison, testing, simulation, and change impact analysis. They should not become a field for broad autonomous rewriting. The older disciplines still matter here. Version control matters. Peer review matters. Simulation matters. Rollback matters. Change authority matters. Safety review matters. The agent can shorten analysis, but it must not outrun engineering responsibility. At Level 0, the physical process reminds every model that measurement is not truth. Sensors drift. Instruments fail. Valves stick. Raw materials vary. Operators compensate. Mechanical wear hides inside acceptable limits until it does not. A historian may show data that appears clean while the process is telling a different story through heat, sound, vibration, fouling, or accumulated small corrections made by experienced people. An agent can reason cleanly from bad evidence and still be wrong.
Data is not evidence until there is a question. Measurement is not truth until the process confirms it
Figure 2: Agentic risk does not always enter as unauthorized access. It can enter as an approved action built on incomplete e vidence.
This is the hardest part of the Purdue argument because it resists both extremes. The answer is not to keep agents away from industrial systems. That would preserve too much manual burden and leave too much value trapped in old handoffs. The answer is not to let agents roam the stack because they can connect what people struggle to reconcile. That would trade latency for recklessness. The answer is a new layer of governed causality, where observation, inference, projection, permission, and action are kept d istinct enough to be audited before and after the fact.
A serious architecture would record what was observed, what was inferred, what was projected, what was missing, what permission existed, what action was recommended, who approved it, what happened after the action, and whether the result confirmed or weake ned the causal claim. That is not paperwork. It is the operating memory required when software begins to shape outcomes. Without that record, the organization will only know that the machine acted. It will not know whether the action was legitimate.
The wall may protect the vendor more than the customer
This is where the enterprise software wall enters the Purdue stack. Incumbents have strong reasons to limit uncontrolled agentic access to mission-critical systems. SAP’s current API policy does not eliminate APIs, but it does restrict API use involving semi-autonomous or generative AI systems that plan, select, or execute sequences of API calls unless the pathway is SAP-endorsed. That distinction matters. It is not a rejection of AI. It is a claim over the route by which AI may act. The fair case for the wall is safety. Customers should not want agents scraping, bypassing, extracting, replicating, or acting through undocumented routes. They should not want shadow orchestration touching ERP, MES, QMS, PLM, EAM, historians, and control-adjacent systems without clear authority. A plant is not a playground for a clever integration layer. A regulated record is not a staging table. The first companies that treat access as cleverness should lose the trust of serious buyers. But the wall becomes suspect when it prevents governed movement and calls that prevention protection. That is the line customers will feel in operating results. If the vendor allows intelligence only inside its approved house, the customer may gain local assistance while the end-to-end burden remains. ERP becomes smarter inside ERP. MES becomes smarter inside MES. PLM becomes smarter inside PLM. QMS becomes smarter inside QMS. The work still crosses the business, and the human still carries the gap. The customer is not asking for open chaos. The customer is asking for governed relief. A planner wants to know whether a constraint matters before the schedule freezes. A quality leader wants containment options before a deviation becomes a customer conversation. A maintenance leader wants to know whether deferral is safe or merely convenient. A controller wants variance drivers before the close turns into theater. A plant manager wants the next permissible action, not another dashboard proving the condition exists. This is why the phrase customer-owned context layer matters. The enterprise cannot allow every vendor to define context only inside its own product and then claim that governed agency has arrived. The customer needs a durable place to hold operating intent, decision rights, evidence definitions, risk classes, policy constraints, escalation rules, reversibility rules, and causal journals. That layer does not replace systems of record. It prevents systems of record from becoming walls around action.
The customer does not need a rebel integration layer. The customer needs a governed reasoning layer
The strongest incumbents will understand this. They will stop treating the wall as the strategy and start treating it as a temporary control while better permission architecture is built. They will expose richer audit hooks, event structures, permission pathways, semantic context, and customer-controlled means for governed agency. They will accept that some intelligence will sit above the application and that being trusted inside that higher -order architecture may be more valuable than forcing every future action through the old interface. The weaker incumbents will confuse restriction with strategy. They will tell customers the wall is safety, then use it to protect the route to work. That may work for a while because switching risk is real and industrial companies do not rip out critical systems casually. But the Go player does not have to assault the castle. The challenger only has to surround the work by solving the cross-system burden the castle was never built to carry.
The bill for delay will force the test
Decision latency sounds abstract until the bill arrives. It arrives as inventory held longer than necessary because the exception was not trusted soon enough. It arrives as premium freight because the supply constraint was visible before the decision was authorized. It arrives as scrap because the process signal was detected but not converted into action. It arrives as customer concessions because the company could describe the problem before it could contain it. It arrives as meetings where competent people translate system language into business consequence one more time. The ledger rarely names this as architecture. A CFO sees freight. A COO sees schedule disruption. A quality leader sees deviations. A CIO sees integration cost. A commercial leader sees customer pain. A plant leader sees labor and rework. Each sees a legitimate piece of the expense, and because each piece is legitimate, the common cause survives. The company is paying for distance between evidence and authorized action. This is the falsifiable claim. By the end of 2027, companies that rely primarily on application -native agents will show meaningful task productivity inside domains, but weaker improvement in cross -layer decision latency where ERP, MES, QMS, EAM, historian, supplier, customer, and control-adjacent evidence must meet before action. If that is wrong, the evidence will show up in cycle -time reduction across real workflows, not demo quality, adoption counts, prompt volume, or hours saved in isolated tasks. The e mbarrassing result would be clear: local intelligence would have been enough. My judgment is that it will not be. An executive team can test the claim without buying another platform. When a material operating exception appears, how long passes between the first trustworthy signal and the first authorized intervention? How many people touch the signal before action? Which system holds the record, which person holds the context, which meeting holds the authority, and which cost appears because those were not in the same place? If the answer requires someone to trace emails, screenshots, spreadsheets, system notes, and h allway memory, the company does not have control. It has witnesses. A second question is harder because it strips away the glamour of AI. If an agent had perfect access to relevant data but no authority, what would improve and what would stay exactly the same? If reports improve but action still waits, the constraint is not intelligence. It is permission. If action could occur but no one can explain the evidence threshold, audit trail, exception rule, or accountable owner, the constraint is trust. If no one knows which outcome the agent is allowed to shape, the constraint is leadership design, not software. The same test belongs inside the Purdue stack. When Level 4 wants to change the plan, what Level 3 evidence must be present before the change becomes legitimate? When Level 3 recommends a production move, what Level 2 conditions must be checked before the recommendation influences the control room? When Level 2 guidance suggests a parameter change, what Level 1 limits make the action permissible or forbidden? When Level 1 says the command executed, what Level 0 confirmation proves the physical process actua lly responded? A company that cannot answer those questions is not ready for broad agency. It is ready for more expensive latency or more dangerous speed. The older industrial disciplines do not disappear in this future. They become more important because AI compresses the time available to use them. Change control, management of change, process safety, cybersecurity, auditability, training, procedure discipline, and engineering review do not become obsolete because a model can reason. They become the guardrails that determine whether reasoning can be trusted near consequence. Speed without these disciplines is not modernization. It is gambling with better la nguage.
The new layer will decide who wins
The winner in this market will not be the vendor with the most impressive assistant. It will not automatically be the incumbent with the deepest system of record. It will not be the challenger with the most aggressive agentic demo. The winner will be the architecture that can reduce human reconciliation burden while increasing the legitimacy of action. That is a narrower claim and a harder one to prove. That architecture will have to know the difference between seeing, recommending, simulating, approving, and acting. It will have to separate read authority from write authority, local action from cross -layer action, reversible action from irreversible action, routine variance from safety-relevant abnormality, and confidence from permission. It will have to refuse action when the evidence is weak, when the risk class is too high, when the causal path is unclear, or when the accountable human has not granted authority. The ability not to act will become a mark of maturity.
It will also have to preserve the system of record without surrendering the route to the system of record. ERP still matters. MES still matters. QMS still matters. EAM still matters. PLM still matters. SCADA, historians, and control systems still matter. The physical process matters most. But the highest value layer moves toward the place where intent, evidence, authority, and action meet. That place will not be owned automatically by the company with the largest installed base.
Figure 3: The new layer must separate what was observed, what was inferred, what was projected, and what was allowed before action occurred.
This is where the Blitzkrieg analogy has to be handled with care. The point is not to admire speed, shock, or military conquest. The point is to understand conversion under pressure. France did not lack assets. Its weakness was revealed when a faster operating model made those assets late. Industrial incumbents may still look stronger on paper. They have installed base, contracts, records, integrations, relationships, switching fear, compliance comfort, and procurement gravity. Those are real assets. But if those assets cannot convert into authorized action fast enough, they become weight. The same caution applies to AI used as digital stimulant. Companies will be tempted to use it to produce more summaries, more reports, more emails, more meeting notes, more dashboards, more reconciliations, and more workflow updates. That may create short-run relief. It may even produce measurable savings in narrow tasks. But if the decision architecture remains unchanged, the company has not changed the system. It has made the old burden easier to perform.
AI used to run the old firm harder is not agency. It is delay with better tools
Supporting image: The winning architecture preserves the records but changes where evidence, permission, and action meet.
A real agent must be able to shape an outcome within authority. That sentence matters because it separates useful tools from agentic systems. A summary tool can help. A drafting tool can help. A search tool can help. A reporting tool can help. But if it cannot shape an outcome, it is not an agent. If it can shape an outcome but cannot prove its evidence, permission, and boundary conditions, it is not yet fit for serious industrial consequence. The market will learn this through operating pain, not conference language. Customers will accept governed access. They will not accept paying the bill for outcomes that vendor walls keep them from improving. They will accept caution around safety, security, intellectual property, performance, and regulated records. They will not accept a doctrine that says all legitimate intelligence must remain inside the vendor’s preferred route when the work itself crosses the enterprise. The difference between protection and control will be measured in cycle time, cost, risk, and burden. The companies that move first will not be reckless if they are serious. They will start where action can be bounded, reversibility is high, evidence is clear, and decision latency is measurable. They will use agents to reduce reconciliation before they grant them broader authority. They will build causal journals before they celebrate autonomy. They will map where human judgment is morally, operationally, or legally required and where humans are only being used because the architecture cannot carry context. That distinction will become one of the most important management questions of the next decade. The old firm could hide distance because no single ledger named it. Delay lived under respectable words. Alignment. Governance. Review. Escalation. Diligence. Risk control. Each word had a legitimate use, and that legitimacy gave the architecture cover. Time became free in the language of the meeting and expensive in the language of the customer, the plant, and the ledger. Agentic AI will make that distance visible because it will ask a plain question the old architecture cannot always answer. What is the system allowed to do now that it knows enough to act? If the answer is nothing, then the enterprise has bought narration. If the answer is everything, then the enterprise has bought danger. The mature answer sits between those failures. It defines which actions are permitted under which evidence, which risks require escalation, which records must be updated, which outcomes m ust be monitored, and which human remains accountable. This is why the Purdue stack is not becoming irrelevant. It is becoming the map of where agency must be governed. The layers still matter because consequence differs by layer. A recommendation in planning is not the same as a write to MES. A write to MES is not the same as a control room instruction. A control room instruction
is not the same as a PLC logic change. A command is not the same as physical response. The stack still teaches humility. What changes is that separation alone is no longer enough. The next industrial software war will be fought by companies that understand both truths. The plant must be protected from reckless cognition. The enterprise must be protected from permanent latency. The incumbent must not be allowed to define safety so broadly that it becomes a tax on customer outcome. The challenger must not be allowed to define speed so broadly that it becomes authorized mis -action. Trust will belong to the architecture that can hold both at once. In the operating review, the plant leader still needs the next permissible action. The controller still needs the variance explained before close. The CIO still has to know whether access is legitimate or merely convenient. The customer still will not wait for the systems map to become clean. The rework still will not introduce itself as architecture. It will arrive as cost, apology, expediting, inventory, labor, and lost option value. The Purdue model was built for an age when distance made the plant safer. Agentic AI belongs to an age when unmanaged distance makes the enterprise weaker. The winner will not be the company that collapses the stack fastest. It will be the one that knows where speed becomes consequence, where consequence requires permission, and where permission must be earned before the machine is allowed to act. The distance is the danger.
References
This article draws on NIST SP 800-82 Rev. 3 for operational technology as systems that monitor or directly change physical processes and for the safety, reliability, and performance duties of OT security; ISA/IEC 62443 for zones, conduits, and industrial c ontrol system security; SAP’s API Policy v.4.2026a for restrictions on semi -autonomous and generative AI systems that plan, select, or execute API sequences outside SAP-endorsed pathways; SAP’s Joule Studio materials for the incumbent move toward governed business agents; MITRE ATLAS for AI-system manipulation and downstream decision risks; CISA’s Cybersecurity Performance Goals for critical infrastructure security ballast; W. Edwards Deming’s Out of the Crisis for system responsibility; Herbert Simon’s bou nded rationality for the human limits that make reconciliation costly; Judea Pearl’s work on causality and intervention for the distinction be tween observed data and action-worthy evidence; and Michael Carroll’s supplied articles Blitzkrieg Was a Decision Architecture That Made Strength Late and Why Enterprise Software Is Building Walls Around AI for the motifs of decision latency, vendor walls, permi ssion architecture, governed reasoning, and the standard that if it cannot shape an outcome, it is not an ag ent.