Five announcements in one week. Hyundai Motor Group revealing enterprise-wide AI agent deployment across manufacturing and maintenance. SK hynix tying AI adoption to executive KPIs as agents spread to chip equipment. GlobalFoundries selecting real-time data infrastructure to power AI agents across its global footprint. LTTS launching AgenticIQ – an end-to-end agentic AI platform for engineering and manufacturing. Eyelit Technologies rolling out Agent EyeQ, a purpose-built agentic AI application suite delivering full-stack MOM.

The demos are impressive. The dashboards are beautiful. Not one of these announcements mentioned audit readiness – and your next VDA 6.3 is probably in eight weeks.

Here is an uncomfortable observation. Every process audit methodology in use – VDA 6.3, layered process audits, the IATF process approach – rests on a single assumption. A human runs the line. A human reads the control plan. A human follows the work instructions. A human signs the acceptance decision. When an autonomous agent makes that acceptance, routing, or dispatch call instead, your audit methodology scores compliance with a process no human is executing. The systematic failure mode that creates is invisible to every checklist you own.

What your process audit actually verifies

Two decades on both sides of the audit table – conducting and receiving VDA 6.3, IATF 16949, and AS9100 audits across automotive and aerospace plants. When I built the greenfield QA department at SNOP for over 900 employees, I designed the audit framework from scratch rather than inheriting someone else's. So I can tell you precisely what your auditor looks for when they walk the floor.

Is the person at the workstation following the documented procedure? Does what they actually do match what the control plan says? Is there a signature trail proving someone accepted, rejected, or escalated each decision? When something went wrong, did a human respond per the documented reaction plan? Every question assumes a human at the station.

Now replace that operator with an agent. No human to observe. No manual step to verify. The signature is a system log entry. The reaction plan is executed in milliseconds by code that may or may not match what your PFMEA says should happen. Your auditor walks the floor, finds no operator, checks the digital trail, sees clean compliance, and scores the process 98%.

The process is empty. The score is meaningless. Nobody has asked whether it works.

The audit that scores an empty process at 98% is not 98% confident the process works – it is 100% blind to whether it doesn't.

From process audit to agent audit

Quality auditing and penetration testing are the same discipline. I hold a CEH certification and thirty-plus security certifications, and the argument I have made in practice for years is straightforward. Both exist to find how a system fails before someone else finds it for you. The tools differ. The mindset does not.

When you audit a human-run process, you verify adherence. When you audit an agent-run process, you probe decision boundaries. You inject adversarial inputs – a sensor reading that is technically within specification but practically impossible. A batch record where one field contradicts another. A routing instruction that, if followed literally, sends nonconforming material to shipping. Then you verify that the acceptance criteria embedded in the agent's logic match the acceptance criteria in your control plan, character for character, and that the deviation path it takes matches the one your quality plan requires.

This is not theoretical. Consider QRQC – quick response quality control. At Witte Automotive, I used QRQC and A3 problem-solving to drive substantial failure-cost reduction. The methodology depends on a human recognising the problem, responding within minutes, and documenting the countermeasure. An agent does all three faster than a human can. But does it do them correctly? Does the agent's definition of "nonconforming" match your control plan? Does it route suspect material to the same hold area your reaction plan specifies? Or does it optimise for throughput and quietly reclassify marginal parts as acceptable?

Your 8D doesn't cover that.

Mapping agent behaviour onto existing clauses

The clauses already exist. IATF 16949 clause 8.5.1 covers control of production – process control, deviation authority, continuous improvement. AS9100 clause 8.5.1 covers the same territory for aerospace. The requirements are there. The audit questions are not.

When an agent holds deviation authority – when it decides whether a marginal part passes or fails – your audit must answer four things. Who authorised the agent to make that call? Under what conditions? With what escalation path? Where is the evidence? If the agent routes material, your audit must verify that routing logic against the control plan the same way you would verify a human operator's decision. If it dispatches work orders, your audit must confirm that dispatch logic cannot override a quality hold.

These are existing requirements applied to a new decision-maker. Write the audit questions before your registrar writes them for you – because the first registrar to issue a major nonconformance for "agent deviation authority not verified against control plan" will set a precedent that propagates across the industry overnight.

The plant that audits its agents

A human operator fails individually. One station, one shift. The layers of defence around that operator catch it. An agent fails systematically – across every line it controls, at the same time, with the same defect, and with a perfect compliance score glowing on every dashboard in the building.

The plant that audits its agents catches that error before it spans every shift simultaneously. The one that does not will explain to a customer why the same defect appeared on three lines at once – with a clean audit trail, a 98% score, and no human in the chain to ask.

That conversation will be brief. The consequences will not.

Key takeaways

  • VDA 6.3, layered process audits, and the IATF process approach verify human adherence to documented procedures – they have no methodology for verifying an autonomous agent's decision logic against the control plan
  • Agent auditing borrows from red-team methodology: probe decision boundaries, inject adversarial inputs, verify that acceptance and deviation logic in the agent matches what your PFMEA and control plan specify
  • IATF 16949 clause 8.5.1 and AS9100 clause 8.5.1 already cover deviation authority and process control – the requirements exist, but the specific audit questions for agent-held authority do not
  • An agent's characteristic failure mode is identical defects across all controlled lines simultaneously – the one failure your current audit methodology is structurally incapable of detecting, because it scores compliance, not decision correctness