Make money doing the work you believe in

The biggest AI risk for an industrial SME may not be choosing the wrong AI model.

It may be giving the right model the wrong permissions.

A recent incident involving an autonomous AI agent attempting to introduce malicious code into software should be a warning for every industrial company now experimenting with AI agents.

Because we are rapidly moving from AI that answers questions to AI that takes actions.

Reads the CRM.

Accesses technical documentation.

Writes code.

Contacts suppliers.

Changes records.

Creates quotations.

Sends emails.

Connects to ERP systems.

Executes workflows.

And that changes the risk completely.

I increasingly believe the competitive infrastructure of an industrial company will look something like this:

Proprietary knowledge → Processes → Permissions → CONTROL → Orchestration → Trusted agents → Measurable outcomes.

The word I would add is CONTROL.

Before giving an AI agent autonomy, an industrial SME should be able to answer seven questions:

1. What can this agent see?

Not every agent needs access to your entire knowledge base, CRM, engineering documentation or customer history.

2. What can it actually do?

Reading information and modifying information are two completely different levels of risk.

3. Which systems can it reach?

ERP, CRM, email, production systems and external internet access should never automatically belong to the same permission perimeter.

4. Which actions require human approval?

Sending a quotation, modifying code, changing a production parameter, deleting data or communicating externally may require a human checkpoint.

5. Can every action be traced?

You need to know what the agent accessed, what it decided, what tool it used and what it changed.

6. Can its permissions be revoked immediately?

Every autonomous system needs a practical kill switch.

7. What happens when the agent is wrong?

Rollback, backups and recovery procedures need to exist before autonomy is granted, not after the first incident.

This leads to an important distinction.

AI governance is no longer just about protecting company data from AI.

It is increasingly about protecting the company from what AI can do with the access we give it.

And there is another strategic consequence.

Models will continue to become more powerful — and increasingly interchangeable.

Your durable competitive advantage will therefore not be simply having access to the best model.

It will be the combination of:

**your proprietary industrial knowledge

* your processes

* your permissions architecture

* your governance

* your ability to orchestrate trusted agents safely.**

Industrial SMEs should not ask only:

“Where can we use AI?”

They should start asking:

“What infrastructure must exist before we allow AI to act?”

That may become one of the most important management questions of the agentic AI era.

Aug 23
at
3:58 AM
Relevant people

Log in or sign up

Join the most interesting and insightful discussions.