Only 12% of Manufacturers Think They Could Pass an AI Audit. Your Customers Are Starting to Ask.
Executive Summary
- Only 12 percent of manufacturing leaders say they are confident their organization could pass an independent AI governance audit, compared with 22 percent across all industries, according to Grant Thornton’s 2026 AI Impact Survey. Just 7 percent have a defined and tested AI incident response playbook, the lowest rate of any sector surveyed.
- Many Tier 1 customers are beginning to translate AI governance concerns into supplier questionnaires, contractual representations, diligence requests, and audit provisions, much as they did with cybersecurity and supply chain security. This is a growing procurement trend rather than a universal requirement, but it is moving faster than legislation.
- The EU Machinery Regulation applies on a mandatory basis from January 20, 2027. For the specific Annex I Part A categories covering machine learning safety components, internal production control alone is no longer available. This affects products placed on the EU market, not ordinary internal factory AI, and it arrives well before the EU AI Act’s deferred rules for embedded products.
- CISA and its G7 partners published minimum elements for an AI bill of materials on May 12, 2026, followed by updated general SBOM minimum elements on July 29, 2026. Both are explicitly voluntary, but they give procurement teams a recognized vocabulary for asking suppliers about AI components and dependencies.
- A small manufacturer does not need certification to answer well. It needs an AI inventory, a named owner, a written policy, and evidence that a human reviews AI output before it touches a safety, quality, or pricing decision.
In this article
- Why is your biggest customer suddenly asking about your AI?
- What is actually driving AI flow down demands in manufacturing?
- What does the EU Machinery Regulation require by January 20, 2027?
- Did the EU AI Act delay let small manufacturers off the hook?
- What is an AI bill of materials and why is it in your questionnaire?
- What does a Tier 1 AI questionnaire actually ask for?
- NIST AI RMF or ISO/IEC 42001: which does your customer actually want?
- Which AI flow down contract clauses should a small supplier negotiate?
- What federal supply chain security teaches small manufacturers
- A 90 day plan to become answerable
1. Why is your biggest customer suddenly asking about your AI?
Your biggest customer is asking because their own compliance and product obligations can depend on what you do, and they have no way to answer their regulators, their auditors, or their insurers without answering for you first. This is the same mechanism that pushed cybersecurity questionnaires down the supply chain a decade ago. AI governance appears to be following a similar path, and the customer risk is not theoretical. It is a product that ships with a defect nobody can explain.
A caveat worth stating plainly: this is an emerging procurement trend, not a universal event. Not every manufacturer will receive an AI questionnaire this year, and the depth of what customers ask varies enormously by sector and by whether your parts touch a safety function. The argument of this article is that the direction of travel is clear enough to prepare for, not that every Tier 1 has already sent one.
A Tier 1 AI questionnaire is a supplier due diligence document that asks a manufacturer to disclose where artificial intelligence touches its products, processes, and quality decisions, who governs that use, and what evidence exists to prove it. It arrives from a customer, not a regulator. It is enforced through purchase orders and audit rights rather than fines, which is precisely why it moves faster than legislation.
The readiness gap here is measurable and it is bad. Grant Thornton’s 2026 AI Impact Survey, fielded between February 23 and March 18, 2026 across 950 business leaders including 100 manufacturing respondents, found that only 12 percent of manufacturing leaders felt confident their organization could pass an independent AI governance audit. Across all industries the figure was 22 percent. Only 14 percent felt extremely prepared for AI privacy and security challenges, against 40 percent overall.
Meanwhile adoption keeps climbing. The same survey found 48 percent of manufacturers piloting AI, well above the 34 percent all industry average, and 64 percent reporting increased operational efficiency. Manufacturers are deploying faster than they are governing. Half of the manufacturing leaders surveyed said formalizing an AI strategy or governance framework was the single most important change their organization needed to make within six months.
2. What is actually driving AI flow down demands in manufacturing?
Four separate pressures converged in 2026, and each one gives a Tier 1 customer an independent reason to send you a questionnaire. Understanding which pressure produced your questionnaire tells you what the customer actually needs, and that determines how much work your answer requires.
The first is product regulation in Europe. Where a supplier’s component or system is incorporated into machinery placed on the EU market, and particularly where machine learning performs a covered safety function, the manufacturer may need technical evidence from suppliers to complete its conformity assessment. The second is the EU AI Act, whose timeline shifted in July 2026 but whose transparency and prohibited practice provisions did not. The third is supply chain transparency guidance from CISA and its international partners, which gave procurement teams a ready made vocabulary for AI disclosure. The fourth is plain contract risk: general counsel at large manufacturers are rewriting supplier agreements to push AI liability outward.
None of these four is a law that applies to a 60 person machine shop in Ohio directly. All four apply to that shop through its customers. That distinction matters because it changes what a good answer looks like. You are not proving compliance to a regulator. You are giving a customer enough documented substance to satisfy someone else’s auditor.
GOVERNANCE INSIGHT
The questionnaire is a contract document, not a compliance filing.
Treat it the way you treat a quality clause or a first article inspection requirement. It is negotiable, it is scopeable, and a thoughtful partial answer with a remediation date beats silence or an overclaim. An inaccurate yes on a supplier questionnaire can become a warranty breach later. An honest not yet, with a plan attached, rarely loses a contract on its own.
3. What does the EU Machinery Regulation require by January 20, 2027?
Regulation (EU) 2023/1230 applies on a mandatory basis from January 20, 2027, and for a specific set of machine learning safety components it removes internal production control as a standalone route to conformity. The European Commission describes the regulation as one that integrates provisions for machinery with safety functions that are AI powered. For a small supplier whose parts go into EU bound machinery, that sentence has teeth.
Scope matters enormously here, and it is easy to overstate. The Machinery Regulation governs machinery and related products placed on the EU market or put into service. It is not a general rule about using AI in a factory. Internal uses such as email drafting, production scheduling, predictive maintenance, or office analytics do not by themselves trigger a notified body assessment. What triggers it is machine learning performing a covered safety function in a product within the listed categories.
Here is the specific mechanism. Annex I of the regulation lists categories of machinery and related products that must follow a heightened conformity assessment procedure. Part A of that Annex includes, in the regulation’s own words, “Safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions,” and separately covers machinery with such systems embedded where those systems were not placed independently on the market. The full text is available on EUR-Lex.
Under Article 25, products in Annex I Part A must use one of three procedures: EU type examination under module B followed by conformity to type under module C, full quality assurance under module H, or unit verification under module G. What is absent from that list is module A, internal production control. Module A remains available for the lower risk Part B categories. For the Annex I Part A machine learning safety categories, internal production control alone is unavailable, and the applicable conformity assessment routes involve a notified body.
One drafting detail is worth flagging because it trips people up. The originally published text of Article 54 said the regulation would apply from January 14, 2027. A corrigendum published in the Official Journal on July 4, 2023 moved that date and thirteen others, shifting general application to January 20, 2027. If you are working from an early printout, check the date you have.
4. Did the EU AI Act delay let small manufacturers off the hook?
No. The delay moved the expensive obligations and left the immediate ones exactly where they were. The AI Omnibus entered into force on July 27, 2026, and the European Commission confirmed two new dates: high risk AI systems listed in Annex III now apply from December 2, 2027, and high risk AI embedded in physical products under Annex I, which the Commission specifically identifies as machinery, toys, and lifts, now applies from August 2, 2028.
That is a genuine reprieve on conformity assessment, technical documentation, and database registration under the AI Act. It is not a reprieve on everything. The Omnibus also extended simplified obligations previously reserved for small and medium enterprises to small mid cap companies, expanded regulatory sandbox access, and gave the AI Office broader oversight of systems built on general purpose models. Transparency duties and the prohibited practices list were not pushed back.
Two clarifications keep this from being over read. First, transparency duties are use specific rather than universal. They attach to particular situations such as systems that interact directly with people, systems generating certain synthetic content, emotion recognition, and deepfake scenarios. A manufacturer running a vision inspection model on its own line does not automatically acquire them. Second, the Machinery Regulation and the AI Act are complementary but distinct frameworks with different scopes, risk classifications, and documentation requirements. Compliance with one does not automatically establish compliance with the other.
Read the two European deadlines together and the sequencing becomes clear. The Machinery Regulation bites on January 20, 2027. The AI Act’s embedded product rules bite on August 2, 2028. A manufacturer that treats August 2028 as the planning horizon will miss the earlier and more concrete requirement by nineteen months. We covered the broader shape of the Omnibus and what survived it in our analysis of what the Digital Omnibus delayed and what it did not.
| Date | What applies | Who it reaches |
|---|---|---|
| July 27, 2026 | AI Omnibus entered into force, revising AI Act timelines | All AI Act obligated parties |
| January 20, 2027 | EU Machinery Regulation applies. Notified body assessment required for machine learning safety components | Anyone placing covered machinery on the EU market |
| December 2, 2027 | AI Act high risk rules for standalone Annex III systems | Providers and deployers of listed high risk systems |
| August 2, 2028 | AI Act high risk rules for AI embedded in regulated products including machinery | Product manufacturers with embedded AI |
5. What is an AI bill of materials and why is it in your questionnaire?
An AI bill of materials is a structured record of an AI system’s components and dependencies, potentially including models, datasets, software, infrastructure, system level properties, performance information, and security relevant details. CISA and its Group of Seven partners, comprising Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union, published Software Bill of Materials for AI: Minimum Elements on May 12, 2026. CISA is explicit that the guidance is neither exhaustive nor mandatory.
That voluntary status is precisely why it matters commercially. The guidance gives procurement teams a defensible vocabulary for asking suppliers about AI system components and dependencies, which is something they previously lacked. As Morgan Lewis observed in its analysis, the guidance is nonbinding but may harden into contractual expectations and vendor diligence standards. Expect it to surface as a reference point in supplier diligence rather than as a legal obligation.
The AI guidance sits on top of general SBOM practice, which also moved this year. On July 29, 2026, CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released 2026 Minimum Elements for a Software Bill of Materials, which updates and replaces the NTIA minimum elements published on July 12, 2021 under Executive Order 14028. CISA notes that AI software and software as a service may require elements beyond the general baseline, and lists small and medium businesses among the intended audience.
For a small manufacturer the practical translation is narrow. You are rarely being asked to produce a full AI bill of materials for a model you did not build. You are being asked to identify which of your suppliers’ AI you depend on, which models or vendors sit behind the tools in your plant, and whether you can name them when your customer asks.
6. What does a Tier 1 AI questionnaire actually ask for?
Many AI supplier questionnaires reduce to five recurring themes, however many pages they run to. There is no universal standard document, and the page count is usually inherited from a cybersecurity template. The substance is often narrower than it looks, and once you recognize the pattern, a long questionnaire stops being intimidating.
The first theme is inventory. Where does AI touch your operation? This includes the obvious systems, such as computer vision quality inspection and predictive maintenance, and the ones nobody logs, such as a scheduler using a vendor’s optimization model or an engineer pasting a drawing tolerance into a chatbot. The second is provenance. Whose model is it, and what can you establish about it? The third is human oversight. Who reviews AI output before it affects a safety, quality, or pricing decision, and how is that review recorded?
Be realistic about provenance, because this is where small suppliers get pushed into answers they cannot support. You will often not be able to describe the training data behind a vendor’s proprietary foundation model, and no amount of diligence will change that. A defensible answer identifies the vendor and tool, names any known underlying model, describes what data you yourself put into it, states the contractual and data use restrictions you operate under, and records that you requested available model or system documentation from the vendor. Documented diligence is the deliverable, not omniscience.
The fourth is failure. What happens when the AI is wrong, who finds out, and how fast? This is where manufacturing is weakest. Only 7 percent of manufacturers in the Grant Thornton survey had a defined and tested AI incident response playbook, the lowest of any sector measured. The fifth is governance. Who owns this, what policy governs it, and what evidence proves the policy is followed rather than filed?
Answering those five honestly, with dates and named owners, will satisfy most customers. Answering them vaguely invites a follow up audit, and answering them optimistically creates a contractual exposure you will not enjoy explaining eighteen months later.
7. NIST AI RMF or ISO/IEC 42001: which does your customer actually want?
If the questionnaire asks whether you follow a framework, the NIST AI Risk Management Framework is usually a credible answer, and if it asks for a certificate, it means ISO/IEC 42001. The two are not competitors and the distinction is straightforward: one is a free voluntary framework you can adopt unilaterally, the other is a certifiable management system standard. Certification under ISO/IEC 42001 is itself voluntary. You can implement the standard without ever being certified, and many organizations do. What requires an external audit is the certificate, not the standard.
NIST released the AI Risk Management Framework 1.0, catalogued as NIST AI 100-1, on January 26, 2023. It is voluntary, sector agnostic, and built around four core functions: GOVERN, MAP, MEASURE, and MANAGE. NIST followed it with the Generative AI Profile, NIST AI 600-1, on July 26, 2024, which maps those functions to twelve generative AI risk categories.
ISO/IEC 42001:2023 was published in December 2023 as the artificial intelligence management system standard. Its Annex A contains 38 controls organized under 9 control objectives. Organizations that choose to seek accredited certification typically follow the two stage route used across ISO management system standards: a Stage 1 audit reviewing documentation and system design, a Stage 2 audit testing operational effectiveness, and periodic surveillance audits afterward, performed by a certification body accredited by a recognized accreditation body.
| Consideration | NIST AI RMF 1.0 | ISO/IEC 42001:2023 |
|---|---|---|
| Type | Voluntary risk framework | Certifiable management system standard |
| Cost to obtain the document | Free from NIST | Purchased from ISO or a national body |
| External audit required | No | Only if you seek the certificate. Stage 1 and Stage 2 plus surveillance |
| Structure | Four functions: GOVERN, MAP, MEASURE, MANAGE | Annex A with 38 controls across 9 objectives |
| Produces a certificate | No | Yes |
| Best first move for a small supplier | Start here. Adopt without permission or budget approval | Pursue when a named customer requires the certificate |
The practical sequence for a supplier under 200 employees is to build against the AI RMF first, because it costs nothing to adopt and it produces most of the evidence an ISO/IEC 42001 audit would later ask for. Pursue certification when a specific customer conditions specific revenue on it, not before. Manufacturers already running ISO 9001 will recognize the management system pattern immediately, which shortens the path considerably.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
8. Which AI flow down contract clauses should a small supplier negotiate?
Negotiate scope, audit burden, and unbounded indemnity, in that order, and accept disclosure obligations readily because they cost you almost nothing. The mistake small suppliers make is fighting the wrong clause. Disclosure is cheap and builds trust. Uncapped liability for a model you neither built nor control is what can end your business.
On scope, insist that AI obligations attach to the AI actually used in producing the customer’s parts, not to every system in your company. A clause drafted for a software vendor will otherwise sweep in your payroll tool. On audit rights, push for reasonable notice, business hours, and a cap on frequency. On indemnity, resist accepting liability for defects originating in a third party model when your customer specified that tool, and try to align any AI liability cap with the commercial cap already in the agreement.
You do not have to draft from a blank page. The Community of Practice on Public Procurement of AI published an updated set of EU AI Model Contractual Clauses on March 5, 2025, in a full version for high risk AI, a lighter version for AI that is not high risk, and a commentary explaining when to use each. The clauses are non binding and were drafted for public sector procurement, so they are not automatically appropriate for a private manufacturing supply agreement and should not be dropped in wholesale. They are still a legitimate reference point when a customer’s draft looks unreasonable, and pointing to a published model reads as informed rather than obstructive.
GOVERNANCE INSIGHT
Be careful about warranting a model you did not build.
If a customer asks you to warrant that an AI system is free from bias or defect, and that system is a licensed vendor model, the warranty you can most easily support is about your process: how you selected the tool, how you validate its output, and how you escalate when it fails. This is a commercial risk judgment rather than an absolute rule. A supplier may reasonably give a broader warranty where it has verified the claim, can operationally support it, has negotiated matching protection upstream from its vendor, and has agreed a liability cap that makes the risk survivable. What you should avoid is an unbounded model level warranty with nothing behind it.
9. What federal supply chain security teaches small manufacturers
Federal supply chain security has already run this exact experiment, and the lesson is that flow down requirements always arrive faster than the compliance capacity of the smallest suppliers. Anyone who watched Section 889 or the Cybersecurity Maturity Model Certification move through the defense industrial base has seen the pattern that commercial AI questionnaires are now repeating.
Section 889 of the 2019 National Defense Authorization Act addressed covered telecommunications and video surveillance equipment from five named companies. The flow down mechanics are specific and worth reading precisely. The implementing clause, FAR 52.204-25, requires at paragraph (e) that the contractor insert the substance of the clause in all subcontracts and other contractual instruments, including those for commercial products and services, while expressly excluding paragraph (b)(2). Paragraph (b)(2) is the Section 889(a)(1)(B) prohibition, the one directed at entities that use covered equipment. So the procurement prohibition travels down the tiers and the use prohibition does not flow down in the same way, though it still shapes what a prime will ask you. The compliance work was never really about the five companies. It was about whether a supplier could produce an accurate inventory of its own equipment on demand. Many could not.
CMMC repeated the lesson with cybersecurity. The Defense Federal Acquisition Regulation Supplement final rule was published in the Federal Register on September 10, 2025 with an effective date of November 10, 2025. The underlying CMMC Program rule sets out a four phase rollout, beginning with self assessments in Phase 1 and reaching full implementation in Phase 4, and states that Phase 2 begins one calendar year after the start of Phase 1 and is where Level 2 certification requirements come in. The practical point for a supplier is that there is no single uniform deadline: whether a given solicitation or renewal carries a CMMC requirement depends on the contract, so track the solicitation rather than a date. Suppliers who had maintained a real asset inventory and a written system security plan adapted quickly. Suppliers who had not spent a long time catching up. We mapped that terrain in detail in our guide to the 2026 federal AI procurement rules.
The transferable insight is that inventory is the bottleneck every time. Not policy, not certification, not tooling. The suppliers who survive flow down waves are the ones who already know what they have. For manufacturers who want structured help, NIST’s Manufacturing Extension Partnership operates centers serving small and medium sized manufacturers nationwide, and NIST also publishes a manufacturing specific security profile, NISTIR 8183 Revision 1, released October 7, 2020, which adapts Cybersecurity Framework version 1.1 to the plant floor.
10. A 90 day plan to become answerable
Ninety days is enough time for a small manufacturer to move from unanswerable to credible, provided the work is sequenced so that inventory comes first and documentation follows. The goal is not certification. The goal is that when the next questionnaire lands, someone in your building can answer it accurately in an afternoon.
Days 1 through 30: find the AI. Walk the plant and the back office and list every system that uses AI, including features your existing vendors switched on without a new contract. ERP, MES, quality inspection, maintenance scheduling, CAD tooling, and customer service software have all been adding AI capabilities into existing license agreements. Record for each one what it decides, who uses it, what data goes into it, and which vendor stands behind it. Name one owner for the inventory. This step is unglamorous and it is the entire game.
Days 31 through 60: write the short policy. A usable AI policy for a company under 200 people runs a handful of pages, not forty. It should state which tools are approved, what data may never be entered into a general purpose AI tool, where human review is mandatory before an AI output affects a safety, quality, or pricing decision, and who to tell when something goes wrong. Map each section loosely to the GOVERN, MAP, MEASURE, and MANAGE functions of the NIST AI RMF so that a customer can see the alignment without you claiming certification.
Days 61 through 90: build the evidence and the incident path. A policy nobody can prove is being followed will fail the first audit. Set up a review log for AI assisted quality and safety decisions, run a short tabletop exercise on an AI failure scenario, and write down the escalation path. Given that only 7 percent of manufacturers have a tested incident playbook, a genuinely tested one is a differentiator you can put in a bid.
Assemble the output into a short supplier response pack: the inventory summary, the policy, the review evidence, the incident procedure, and a one page statement of your governance approach. That pack answers most of what arrives, and updating it beats reconstructing your position from scratch for every customer.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Does my customer have the legal right to audit my AI use?
In an ordinary commercial relationship it usually depends on the contract, purchase order, supplier manual, or incorporated quality and security requirements. Read those before responding, and negotiate reasonable notice, business hours, and frequency limits when a customer proposes new AI language. Government contracting, product safety, certification, and regulatory arrangements can create additional inspection or information rights beyond the four corners of your supply agreement.
Do I need ISO/IEC 42001 certification to keep my Tier 1 customers?
Often not yet. For many questionnaires, mapping your program to the free NIST AI RMF provides a credible answer, though it does not substitute for a certificate where one is expressly demanded or where a customer requires specific controls, evidence, or a maturity score. Pursue ISO/IEC 42001 certification when a specific customer conditions specific revenue on it. The standard was published in December 2023 and its Annex A contains 38 controls across 9 objectives, so the work is real and worth scoping deliberately.
The EU delayed its AI rules. Can I wait until 2028?
Not if your products go into EU bound machinery, because the Machinery Regulation is the earlier deadline and it was not delayed. It applies from January 20, 2027, and for the Annex I Part A machine learning safety categories it removes internal production control as a standalone route, requiring a conformity assessment involving a notified body. The AI Act’s embedded product obligations moved to August 2, 2028, but that later date does not extend the machinery deadline, and the two frameworks are distinct.
What is an AI bill of materials and do I have to produce one?
An AI bill of materials is a structured record of an AI system’s components and dependencies, potentially covering models, datasets, software, infrastructure, system level properties, performance information, and security details. CISA and its G7 partners published minimum elements for one on May 12, 2026, and CISA states the guidance is neither exhaustive nor mandatory. Small manufacturers are rarely asked to produce a full AI bill of materials for models they did not build. You are normally asked to identify which vendor AI you depend on.
We only use AI for scheduling and email. Does any of this apply?
Yes, at the inventory level, though your answer will be short. Questionnaires ask where AI touches the products you supply, so low risk administrative use is a legitimate and easy answer. The risk is not having looked. Vendors have been enabling AI features inside existing ERP, MES, and quality licenses without new contracts, so confirm what is switched on before you certify anything.
What happens if I answer a questionnaire inaccurately?
An inaccurate answer can become a warranty or representation breach, because supplier questionnaires are frequently incorporated into the agreement by reference. Overstating your governance maturity is materially riskier than admitting a gap with a remediation date. Given that only 12 percent of manufacturers say they could pass an independent AI governance audit, customers expect gaps. They do not expect surprises.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.