The packaging twin recommended a speed increase after a simulated jam clear. On the floor, the line had already changed film lot and slowed two hours earlier. The optimizer did not know. The shift lead trusted the twin because the dashboard looked live.
Line commissioning twins and marketing digital twins are not this problem. This is staleness as a silent feature: ML or rules that read twin state as truth while SCADA has moved on.
Failure modes that look like intelligence
Clock honesty. Twin last-sync age must be visible next to every recommendation—not buried in an admin page.
Partial sync. Geometry updates while recipe tags lag; the model “optimizes” a line that does not exist.
Advice without authority. Even read-only twins drive humans to write setpoints. Bad advice still moves OT through people.
| Check | Pass looks like | Fail looks like | |-------|-----------------|-----------------| | Sync age | Seconds to low minutes, tagged | Hours old, still “LIVE” badge | | Tag coverage | Recipe, speed, scrap, mode | Geometry only | | MoC on twin | Version locked to line MoC | Twin drifts free of plant change | | Human gate | Advise-only until sync green | Auto-apply or soft pressure to apply |

Practices that keep advice honest
Publish twin freshness as a hard gate: if sync age exceeds the process time constant, recommendations disable—not gray out politely while still clickable. Tie twin model version to recipe MoC the same way you freeze inference models.
Do not train or tune controllers on twin trajectories without a sync-quality column in the training set. You will teach the plant to chase ghosts.
The twin is a mirror. A late mirror is a liar that still looks expensive.
