Apple has reportedly pushed AI onto its factory floors for quality inspection. I have spent two decades in quality leadership across automotive and aerospace — greenfield plant builds, 900+ employee operations, safety-critical parts under EASA and IATF 16949 scrutiny. Every time a vendor pitches me a single-model AI inspection system, I ask the same question nobody in the room seems prepared for: when the model misses, what catches it? The silence that follows is not a pause for thought. It is a design flaw.
Apple put AI on the factory floor. So did your competitors
The machine vision and quality inspection market is scaling fast. On-prem AI infrastructure investments in manufacturing are accelerating — IT teams leaning into local deployment to control latency and data sovereignty. Training programmes for responsible industrial AI are appearing at polytechnics. Engineering software vendors are shipping AI agents. Gartner lists agentic AI as an emerging category. Shipbuilders are connecting entire production processes through autonomous systems.
The technology is genuinely useful. But every deployment I have reviewed, read about, or been asked to assess shares the same structural defect. One model. One decision. No cross-check. You bought a neural network and called it a quality system.
The redundancy you dismantled
Your old inspection chain was not elegant. But it had architecture. An operator inspected the part. A line checker verified the operator's call. A statistical audit sample — AQL-based or driven by PFMEA risk priorities — pulled parts downstream for independent review. Three layers. Three independent sets of eyes. Three opportunities to catch what the previous layer missed.
It was slow. It had human variability. But it had structural redundancy, and structural redundancy is what AS9100, EN9100, and IATF 16949 are built on.
Your AI system collapsed all three layers into one neural network. The operator is gone. The checker is gone. The audit sample is gone. In their place: a single model running inference on a camera feed, making the disposition call on every part that crosses the line, with no independent verification and no divergence detection. You optimised away the redundancy and called it digital transformation.
A single point of failure in a safety-critical path is not a risk to manage — it is a defect to eliminate.
Consensus is not ensemble averaging
Most vendors hear "redundancy" and reach for ensemble averaging — run five models, pool the confidence scores, ship the result. That is not a quality system. That is statistics wearing a hard hat.
I designed MultiPS to run 63+ models in parallel with consensus synthesis. Not because I needed a committee. I needed to know when models disagree. Consensus means independent models flagging divergence. When two models, trained on different data and built on different architectures, look at the same part and reach different conclusions, that disagreement is the most valuable signal your inspection system produces. That is the part you route to human review. That is the edge case that prevents the field failure.
In practice: Model A says pass. Model B says pass. Model C flags a geometric anomaly in the weld bead. You do not average A, B, and C and ship because two out of three said fine. You quarantine the part, because Model C just identified a failure mode the others were not trained to detect. The divergence is your audit trail. Under the EU's shift toward testing-based AI compliance, it is also your evidence that you monitored the system rather than trusted it.
The auditor's question you cannot answer
I reduced EASA audit findings by 50% in one cycle. Not by buying better cameras or faster models — by treating inspection architecture as a quality system. Redundancy, traceability, divergence detection. The things AS9100 demands. Designed in, not bolted on.
You are in a surveillance audit. EASA, your customer's SQE, or an IATF 16949 auditor asks you to walk through the inspection process for a safety-critical part. You explain that one unmonitored model — no consensus check, no divergence log, no independent review — made the pass/fail call on 10,000 parts last month. No ability to detect drift when the supplier changed material lots and the lighting on Line 3 shifted.
Try writing that into an 8D.
The auditor will ask how you detect degradation. The honest answer, for most current deployments, is that you do not. The model drifts silently. Your defect rate does not spike — it shifts. Parts that should have been caught start leaking through at 0.3% instead of 0.1%. You will not notice until the customer does. I have stood in QRQC rooms around exactly this kind of escape. The failure cost of catching a defect at the customer instead of at the line is typically a factor of ten — sometimes a hundred. Single-model architectures guarantee you find out late.
Key takeaways
- One model is a pilot. Two independent models with divergence detection is a quality system.
- When models disagree, the disagreement is your highest-value inspection signal — not noise to average out.
- EASA, IATF 16949, and the EU's emerging AI testing rules all demand proof that you monitored the system and could detect failure. Single-model architectures cannot produce that evidence.
- Inspection architecture is a quality system, not a technology purchase. Design redundancy in, or explain its absence to the auditor.
You would not certify an aircraft with a single hydraulic circuit. You would not sign off a PFMEA with no detection rating. Stop shipping parts inspected by one unmonitored AI model and calling it innovation. One model is a pilot. Two models that check each other is a quality system. You build redundancy into the architecture from the start, or you explain to the auditor — and eventually the court — why you thought a single neural network was sufficient for a safety-critical path. In aerospace, that is not a debate. It is a requirement.