Reviewing AI Assistants Connected to Lab and Industrial Systems
A review dossier for laboratory assistants that separates analysis, proposed changes, operator authority and physical system effects.
A laboratory assistant can change an operating decision without having a controller credential. If it marks a quarantined material as available in a planning summary, an operator may use the wrong input while every equipment interlock behaves as designed. The review therefore has to follow both physical authority and the records people rely on.
I would ask for a dossier built around one complete workflow: its source records, proposed decision, authorized reviewer, deterministic checks, resulting state and recovery procedure. A diagram showing the model connected to a historian leaves too much of that workflow unspecified.
My KevinBytes industrial AI article discusses the boundary between recommendations and actuation. I write KevinBytes and am affiliated with TKOResearch. This edition focuses on the materials and acceptance decisions for a hypothetical laboratory review. It describes no delivered industrial engagement, certified system or implemented TARE capability.
Assemble the workflow dossier
Consider an invented pilot assistant that helps prepare an equipment run. It reads approved procedure versions, maintenance status, inventory availability and a replica of prior run data. It produces a preparation checklist for a qualified operator. It may save a draft checklist, but cannot release quarantined inventory, change approved procedures or start equipment.
The pilot's value could be easier preparation and clearer source references. Whether it achieves that value needs evaluation with the site's staff and workflow. A fluent checklist is not a measured improvement in operational reliability.
| Dossier item | What the reviewer needs | Decision it supports |
|---|---|---|
| Data and authority map | Source systems, network paths, service identities, read/write operations | Whether the stated advisory boundary exists |
| Sample preparation packet | Source versions, timestamps, inventory status and generated checklist | Whether the operator can verify the proposal |
| Procedure ownership | Approvers, change workflow and superseded-version handling | Whether retrieved content is suitable for the current run |
| Equipment and process constraints | Applicable operating modes, approved checks and responsible engineers | Which proposals must be rejected or escalated |
| Recovery design | Draft removal, data correction, queue cancellation and state reconciliation | Whether stopping the assistant leaves a manageable process |
| Test plan | Offline fixtures, expected decisions, excluded physical tests | What the pilot can establish before expansion |
Choose documents with the responsible process and equipment owners. The reviewer does not need unrestricted access to every laboratory record. Representative approved and rejected cases usually provide a better starting point than a large unstructured export.
Separate the kinds of authority
Reading replicated measurements, analyzing a trend, proposing a checklist, reserving inventory and issuing an equipment command are distinct actions. Record the credential and enforcement point for each. “Human in the loop” does not explain which of these actions needs approval or what the approval authorizes.
In this example, the assistant can create a draft in a separate application store. Inventory reservation remains in the existing authorized workflow. Equipment operation remains with qualified personnel and the approved control system. The assistant's credential cannot rewrite either system's permissions or validation rules.
Verify the surrounding host as well as the nominal API. A read-only database role offers limited protection if the same runtime holds an administrative token, can call a writable stored procedure, or can reach a management interface through another connector.
NIST SP 800-82 Revision 3, final September 2023, addresses OT security while considering performance, reliability and safety. Its scope is useful for this system review; the dossier here is an engineering interpretation, not a completed assessment against the publication.
Work the quarantined-material case
Suppose lot CEDAR-LOT-17 was available when a summary was generated and quarantined before checklist approval. The stored summary remains grammatically convincing. The review must establish where current material status is checked and how the operator sees that the earlier statement has become stale.
The preparation packet should retain the lot identifier, source-system version or observation time, current status and the procedure version used. Immediately before the operator accepts a preparation step, the authorized application should validate the relevant current records. The applicable freshness limit comes from the actual process; there is no safe universal number for a blog to supply.
Run this case offline with invented records. The expected outcome is an invalidated or clearly blocked proposal, with the changed source identified. The assistant may explain the change, but it cannot override quarantine by generating a new rationale.
Next remove the source record, supply inconsistent units, and replace the procedure with a superseding version. Treat these as separate cases. They exercise availability, interpretation and change control. A test that merely checks whether the assistant mentions “stale data” does not verify that the application prevented acceptance of the outdated packet.
Keep protective functions outside the assistant's control
If a later design proposes physical actuation, require a separate review with the people responsible for process hazards, controls and operation. An approved change must bind to the specific equipment, operating mode and request. Deterministic checks should evaluate current conditions at execution, rather than trusting an earlier conversation approval.
IEC 61508-1:2010, edition 2, concerns general requirements for electrical, electronic and programmable electronic safety-related systems. The appropriate sector standards, safety functions and validation activities must be identified for the installation. Citing this standard does not assign a safety integrity level to the assistant or certify the proposed arrangement.
Independent protective functions must retain the independence required by the site's safety design. Review shared credentials, maintenance channels and configuration privileges that could let the integration change both an operating command and its protective limit. Software that calculates a sensible range is not automatically an independent protection layer.
The operator also needs a usable decision surface: current sources, clear uncertainty, exact proposed effects and time to review them. Measure the ability to detect an unsuitable proposal during an authorized exercise. A compulsory approval click is weak assurance when the underlying information is hidden.
Define recovery in terms of real state
Deleting a draft checklist is reversible. A physical process change may not be. A source-control rollback cannot restore consumed material or reverse a completed equipment action. For any future actuation path, the equipment owner must define the safe recovery or compensating procedure.
Even in this advisory pilot, stop conditions matter. Disable new proposals when required data is unavailable, cancel or invalidate pending drafts when relevant records change, and retain enough references to explain what operators already saw. Corrections should preserve the original record and its authorized amendment where the laboratory's record process requires that history.
I would accept the initial pilot only after reviewers can demonstrate the advisory boundary, stale-record rejection, source traceability and an orderly stop using offline fixtures and approved application checks. Expand to inventory writes or physical commands through separately scoped acceptance decisions. That keeps the review attached to the authority being requested and the process the laboratory actually operates.
