Edge inference silicon lands on the floor. PLC copilots draft logic. Agentic tools propose actions. Soft sensors close quality loops. Vision and TSFMs watch assets. What still fails under audit is the model itself: shadow notebooks, unversioned weights, and silent swaps that change control behavior without a signed change record.
OT-aware model change control—ownership, promote gates, rollback, and evidence packs—is becoming mandatory for plants that let AI touch production decisions.
The industrial point is reversible, attributable model state. A better AUC model deployed by Slack message is still a process deviation.
What OT model control changes
- Promote and rollback gates — Versioned artifacts with approvers and windows.
- Runtime ownership — Which team answers when the model drifts.
- Evidence for change boards — What trained, what validated, what limits remain.
What still fails
IT MLOps clones that ignore LOTO, interlocks, and qualified procedures. “Shadow A/B” on live lines without safety review. This is not edge accelerator procurement, not PLC code copilots, not agentic ticket bots, not maintenance RAG, and not soft-sensor tuning itself.
What to watch next
- Sites that cut unauthorized model edits without freezing all innovation.
- Whether insurers and PSM treat model promote logs as living controls.
- Integration with MOC systems that already govern PLC and loop changes.
Hardware runs the inference. Change control decides which inference is allowed to steer the plant.
