Manufacturing (Non-Automotive)Regulations, Compliance & Governance
Manufacturing AI human rights governance: the worker-rights ladder for non-automotive plants
AI human rights governance is the discipline of identifying every AI system that watches, scores or schedules factory workers, assessing its impact on their rights before it goes live, consulting the people it affects, and providing a working route to remedy — the UN Guiding Principles' due-diligence cycle applied to the shop-floor AI estate.

Key takeaways
- AI human rights governance in manufacturing is not an ethics statement — it is the UNGPs' due-diligence cycle (know your estate, assess, consult, remedy) applied to every system that watches, scores or schedules workers, run through the same gates a plant already uses for quality and change management.
- The exposure is wider than surveillance: algorithmic shift scheduling, productivity scoring built on MES and OEE data, vision-based safety monitoring, biometric time-and-attendance and hiring screens each engage different rights and need different gates.
- The EU AI Act makes workplace AI a named high-risk category, obliges employers to inform workers and their representatives before deployment, and bans emotion recognition at work outright — with the prohibited-practice penalty band reaching €35m or 7% of global turnover.
- Most manufacturers sit at the 'Declared' stage: a published commitment with no enforcement point in the deployment path. The ladder out runs Declared → Assessed → Embedded → Accountable, and each rung is process design, not philosophy.
- Consultation before contract signature is the single highest-leverage move on the ladder — scope is still changeable, co-determination risk collapses, and workers routinely catch design errors that assessments miss. Remedy data then becomes the feedback loop that improves the systems themselves.
Abbreviations used on this page
- UNGPs
- UN Guiding Principles on Business and Human Rights
- HRDD
- Human-rights due diligence
- HRIA
- Human-rights impact assessment
- FRIA
- Fundamental-rights impact assessment (EU AI Act, Article 27)
- DPIA
- Data protection impact assessment (GDPR)
- CSDDD
- EU Corporate Sustainability Due Diligence Directive
- GDPR
- General Data Protection Regulation
- ILO
- International Labour Organization
- MES
- Manufacturing execution system (ISA-95 level 3)
- WFM
- Workforce management system (rostering, labour scheduling)
- T&A
- Time-and-attendance system
- OEE
- Overall equipment effectiveness
Free · 8 questions · ~3 minutes
Score your plant on the worker-rights ladder
Eight questions, one at a time, about three minutes. Answer them and we build your personalised rights-governance report — your stage on the ladder, your score on each of the four dimensions, and the specific gap standing between you and the next stage — and send it to your inbox. Your result doubles as the baseline for your first estate review.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised rights-governance report is ready
Tell us where to send it. Your stage appears on screen straight away, and the full report — dimension scores, how you compare with manufacturers of similar estate shape, and the 90-day plan for your weakest dimension — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Unexamined
Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
Your next moveBuild the worker-facing AI register: one afternoon per site, walking the floor with the vendor contracts, recording what each system captures about whom.
Stage 2 · Declared
A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
Your next moveDefine the gate: what counts as worker-facing, which assessment tier each class needs, and whose signature a go-live requires. Wire it into the purchase-order path.
Stage 3 · Assessed
Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
Your next moveConvert every assessment condition into a checkable control: a locked configuration, a vendor contract clause, or a telemetry alert — one of the three, for every condition.
Stage 4 · Embedded
Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
Your next moveClose the loop publicly: disclose the worker-facing estate and its governance, commission independent review, and report remedy outcomes in aggregate.
Stage 5 · Accountable
Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.
Your next moveMake register review change-triggered: procurement events, vendor release notes and M&A due diligence each fire a review, so the public disclosure stays true between reports.
0 / 24
Estate visibility
— / 6
Due diligence & vendors
— / 6
Worker voice & transparency
— / 6
Remedy & accountability
— / 6
Your score maps to a stage on the ladder. The dimension breakdown matters more than the total: the lowest dimension is what actually caps your position — a strong assessment process over an incomplete register is still an unexamined estate — and it is where the next investment belongs. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a stage on the ladder. The dimension breakdown matters more than the total: the lowest dimension is what actually caps your position — a strong assessment process over an incomplete register is still an unexamined estate — and it is where the next investment belongs.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want the gaps turned into a working deployment gate?
We will walk your operations, HR and IT leads through the dimension scores, compare them against manufacturers of similar estate shape, and leave you with a costed 90-day plan for the weakest dimension — usually the register or the gate. No obligation, and you keep the plan either way.
How the score maps to a stage
- 0–5 — Stage 1, Unexamined. Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
- 6–11 — Stage 2, Declared. A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
- 12–16 — Stage 3, Assessed. Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
- 17–21 — Stage 4, Embedded. Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
- 22–24 — Stage 5, Accountable. Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.
What AI human rights governance means on the factory floor
A definition, the instruments behind it, and the deployment path that decides whether a worker-facing system is defensible or a dispute waiting to surface.
AI human rights governance is the application of human-rights due diligence — the know-your-impacts, assess, consult and remediate cycle that the UN Guiding Principles on Business and Human Rights ask of every company — to the specific AI systems that watch, score or schedule the people working in a plant. In a non-automotive manufacturing operation that estate is wider than the word 'surveillance' suggests: the WFM module allocating shifts, the productivity analytics built on MES and OEE data, the vision system watching for missing PPE, the biometric T&A terminal at the gate, and the screening algorithm ranking applicants for the packing hall are all worker-facing AI, and each engages a different set of rights through a different mechanism.
The instruments are concrete, not aspirational. The UNGPs (opens in a new tab) — 31 principles endorsed unanimously by the UN Human Rights Council in 2011 — define the corporate responsibility to respect human rights and the due-diligence cycle this page builds on. The ILO's fundamental principles and rights at work (opens in a new tab) — five categories, ten fundamental conventions since a safe and healthy working environment was added in 2022 — define what the rights at stake actually are: freedom of association and collective bargaining, freedom from forced and child labour, non-discrimination, and occupational safety and health. And the EU AI Act (opens in a new tab) hardens part of this into product-style regulation: AI used in employment and worker management is a named high-risk category, employers must inform workers and their representatives before putting such systems into service, and emotion recognition in the workplace is prohibited outright. The OECD Guidelines for Multinational Enterprises and the EU's CSDDD extend the same due-diligence expectations through the supply chain — which is why customer audit questionnaires increasingly ask about the AI estate.
Business enterprises should respect human rights. This means that they should avoid infringing on the human rights of others and should address adverse human rights impacts with which they are involved.
How a vision-monitoring rollout reaches the floor, at each stage of the ladder
The same camera-analytics purchase travelling three paths. The stage is determined by what stands between the vendor's feature and the worker it watches: at stages 1–2 nothing does; at stages 3–4 a register, an assessment, consultation and conditioned configuration do; at stage 5 a remedy loop feeds what is learned back into the estate. Most manufacturers are in the top lane.
- Data & feeds
- System-of-record action
- Where value leaks
- Human in the loop
- AI / model
The process, in words
- In the procurement-led lane, monitoring capability arrives as a vendor feature inside a system bought for something else. Nothing stands between the feature and the worker: IT enables it, supervisors discover the dashboards, and the exposure runs silently until a grievance, a works-council standstill or a regulator's letter surfaces it — at which point the whole system, including its legitimate function, is usually switched off.
- In the rights-gated lane, the same purchase enters a register before signature, a tiered assessment sets the conditions proportionate to what the system watches and decides, worker representatives are consulted while scope can still change, and the system goes live with purpose limitation, retention and access rules configured — then monitored for drift, because conditions that live only in documents do not survive vendor updates.
- The accountable loop is what stage 5 adds: a contested decision travels a defined appeal route to a named human reviewer, remedies change the system rather than just the individual outcome, and outcomes are disclosed and independently checked — turning individual grievances into estate-level learning and the disclosure into something an auditor can verify rather than take on trust.
Step-by-step insights
- The feature flag is the real deployment event
- Manufacturing AI governance fails at procurement more often than at deployment, because in a bought estate the deployment event is invisible: it is a firmware update, a licence-tier change or a module activation, not a project with a kick-off. A governance process keyed to 'projects' misses most of the estate. The fix is to key the gate to capability, not procurement category — any change that adds capture of individual-level worker data or adds a decision about work allocation, evaluation or discipline is a deployment, whoever initiated it and however small the invoice.
- Why the ungoverned lane ends in switch-off
- The characteristic end-state of the top lane is not a fine — it is the total loss of the system, including its legitimate function. When the packaging-hall cameras bought for seal inspection are discovered doing idle-time analytics, the works council or the data protection authority does not surgically disable the analytics module; the plant switches the cameras off entirely while the dispute runs, and the quality function goes with them. Ungoverned monitoring places the whole investment at the mercy of its least defensible feature.
- Salience is what makes the gate proportionate
- The gated lane only works if the assessment tier matches the stakes. Salience — the human-rights term for where the most severe impacts on people are likely — is the sorting rule: aggregate flow analytics that never resolve an individual sit in the lightest tier (register entry and notice); anything feeding pay, discipline or employment decisions, or capturing biometric and continuous individual data, gets the full assessment with consultation. Tiering is what keeps the gate fast enough that plant teams use it rather than route around it.
- Consultation before signature is where scope is still real
- The placement of the consultation node — before contract signature — is the single most consequential design choice in the lane. Consulted after signature, worker representatives can only accept or obstruct; consulted before, they can shape zone coverage, aggregation level and retention while the vendor still has an incentive to configure flexibly. In co-determined environments this is also the difference between a works agreement negotiated once and an injunction discovered later; everywhere else it is simply the cheapest error-detection pass the project will ever get.
- The remedy loop is telemetry, not ceremony
- The stage-5 lane treats appeals as system telemetry. An appeal that finds micro-stops mis-attributed to an operator is a model-quality finding; a cluster of grievances about one line's scoring is a configuration signal; an access-log exception is a control failure. Plants that route this data back into system ownership get a feedback channel their quality processes cannot provide — and the aggregate statistics become the disclosure that separates verifiable accountability from published good intentions.
This page is deliberately not a management-system guide. Certifying the machinery that runs an AI programme — scope statements, controls, internal audits — is ISO/IEC 42001 territory, covered by the companion guide in this knowledge base cell. Rights governance answers the prior question: what that machinery must protect, for whom, and who can appeal when it fails. The rest of this page gives the answer an operating shape — a five-stage ladder from unexamined estate to external accountability, a decision map naming which shop-floor systems engage which rights, and the deployment gate that ties them together.
The five stages of the worker-rights governance ladder
For each stage: what it looks like on the ground, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps manufacturers there, and what leaving costs.
Each stage below is written for a practitioner rather than a buyer. The ladder runs from an estate nobody has examined, through declared commitments and assessed deployments, to controls embedded in procurement and configuration, and finally to external accountability. The hallmarks describe observable conditions, the diagnostic signals are checks you can run against your own plants this week, and the anti-pattern is the specific mistake most often made trying to leave that stage.
Defensible worker-facing AI released against position on the ladder
The curve is not linear. Almost nothing is defensibly deployable at stages 1–2 — every system runs at the mercy of its least defensible feature — and capability inflects at stage 3, when assessment and consultation start producing conditions a dispute can be answered with. This mirrors the UNGPs' own arc: commitment alone releases nothing; due diligence and remedy release everything.
Worker-facing AI you can defensibly run by stage
- Stage 1 · Unexamined — 34% of operators. Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
- Stage 2 · Declared — 31% of operators. A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
- Stage 3 · Assessed — 22% of operators. Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
- Stage 4 · Embedded — 10% of operators. Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
- Stage 5 · Accountable — 3% of operators. Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.
Curve shape: logistic, plotted from the stage data above. Distribution: Consistent with the UNGPs' commit–assess–remedy arc.
Select a stage
Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Unexamined
34% of operators sit here
Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
Stage 1 is rarely a decision anyone made. The worker-facing AI estate accretes: the vision system bought for quality inspection gains people-detection in a firmware update, the WFM suite's next release adds an absence-prediction module, the access-control vendor upsells facial recognition as a convenience feature. Each arrival is a procurement line item or a maintenance contract, not an AI deployment — so no deployment review ever fires. The plant is running algorithmic management without ever having chosen to.
The tell is to ask for a list. At stage 1 nobody can produce one, and the attempt exposes the ownership gap: HR believes plant IT reviews these systems, plant IT believes HR owns anything touching people, EHS assumes legal has looked at the cameras, and legal has never heard of half the estate. Meanwhile the systems accumulate exactly the data — individual cycle times, movement traces, biometric templates — that a works council, a data protection authority or a customer auditor will one day ask about.
This is a cheap stage to leave and an expensive stage to be caught in. The inventory is an afternoon per site: walk the floor, read the vendor contracts, ask supervisors what they can see about individual operators. Staying costs nothing until the first dispute — and the first dispute arrives with no register, no assessment, no notice and no paper trail, which converts a manageable governance question into a trust collapse.
In practice
The upgrade that became a monitoring system
A packaging plant ran ceiling cameras for seal-quality inspection. A vendor firmware upgrade added people-detection and idle-time analytics as a bundled feature; a shift supervisor discovered the new dashboard and began using screenshots in performance conversations. The works council found out from a printout left on a desk. Outcome: a formal grievance, the entire camera system switched off pending review — including the quality function it was actually bought for — and a year of rebuilding trust before any vision project could be proposed again.
What it looks like
- Monitoring-capable features arrive inside systems bought for other reasons
- No register of AI systems that touch workers exists anywhere
- Workers learn what a system does from the floor, not from a notice
- HR, IT and EHS each assume one of the others owns the question
Diagnostic signals you can check this week
- Ask for the register of AI systems that touch workers — at stage 1 there is none
- Ask procurement which live systems have monitoring-capable features in their current release; compare against what IT believes is enabled
- Look for a single published transparency notice describing any system's data capture — usually zero exist
- Ask a line supervisor to show you what they can see about an individual operator; note whether anyone approved that view
Anti-pattern · Writing the policy first
The instinctive first move is an AI ethics policy — principles, values, a commitment to human oversight. Written before the estate is known, the policy names no systems, binds no procurement decision and cannot be falsified, so it changes nothing and ages into evidence of a commitment the company knew about and did not operationalise. Inventory first: a one-page register of real systems generates more governance in a month than a principles document does in three years, and the policy written afterwards can name what it governs.
What holds you here
Nobody owns the question, so the estate stays invisible — HR, IT, EHS and legal each assume another function has reviewed it.
Highest-leverage next move
Build the worker-facing AI register: one afternoon per site, walking the floor with the vendor contracts, recording what each system captures about whom.
Cost of leaving
- Effort
- 1–3 months
- Team
- One HR-operations pair per site, part-time, with procurement contract access
- Risk
- Low — the work is a survey; nothing changes on the floor yet
- To next stage
- 1–3 months
If this is you, the next step is
A per-site walk-down and contract review; you get the register and the data-flow map.
Stage 2
Declared
31% of operators sit here
A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
Stage 2 is where most manufacturers with any governance ambition actually sit, and it feels like progress because the commitment is real. The board approved the principles, the sustainability report cites the UNGPs, and the intention is genuine. The gap is structural: deployment decisions are procurement and plant-IT decisions, and the policy has no seat at that table. A rostering module goes live because the operations director signed the purchase order; at no point does anything in the purchase path ask whether the policy applies.
Declared commitments are not neutral while they wait for process. They raise the standard against which the company is judged — by customer auditors working through their own CSDDD obligations, by works councils quoting the company's own principles back at it, and eventually by regulators reading the sustainability report next to the plant's practice. The delta between what is declared and what is enforced is precisely what an audit measures. A manufacturer with no policy and no estate review is careless; one with a published policy and an ungoverned estate is worse positioned in any dispute, because the knowledge standard has been set by its own hand.
Leaving stage 2 is process design, not philosophy. Three definitions do most of the work: what counts as worker-facing (any system that captures individual-level worker data or feeds decisions about work allocation, evaluation or discipline), which tier of assessment each class of system needs (a notice, a DPIA, or a full HRIA with consultation), and who signs the gate. Wire those three into the purchase-order path and the change-management process the plant already runs, and the policy acquires an enforcement point.
In practice
The principles and the pilot
A food manufacturer published AI principles committing to 'human oversight and fairness in all AI affecting our people'. The same quarter, a plant piloted its WFM vendor's AI rostering module. Nobody mapped the pilot to the principles — it was a module activation, not a project. The optimiser learned to weight absence history, quietly disadvantaging workers with caring responsibilities in shift allocation. The grievance, when it came, quoted the company's own published principles in its first paragraph.
What it looks like
- Responsible-AI principles are published and sincerely meant
- Deployment remains a procurement decision the policy never touches
- Assessments happen only when legal flags a GDPR question
- Worker consultation is an announcement, when it happens at all
Diagnostic signals you can check this week
- Read the purchase-order and change-management templates: does any field reference the AI policy? Usually not
- Count worker-facing deployments in the last year against completed assessments — the ratio at stage 2 is many to almost none
- Ask who can stop a deployment on rights grounds; if the honest answer is 'nobody, in practice', the policy has no gate
- Compare the sustainability report's AI language against any single plant's live estate — the delta is the stage-2 signature
Anti-pattern · Scaling the paperwork instead of the gate
Stung by the gap, the company mandates a forty-page ethics assessment for every system that touches a person. Plant teams — who have lines to run — route around it, classify systems as 'not AI', or batch approvals through whoever signs fastest, and the register decays into fiction. Proportionality is the design constraint, not a concession: a three-tier gate where the lowest tier is a one-page register entry and notice keeps the estate visible, while reserving the full HRIA for the systems that decide pay, discipline or employment.
What holds you here
The policy has no enforcement point in the deployment path — procurement and plant IT can put a system live without ever touching it.
Highest-leverage next move
Define the gate: what counts as worker-facing, which assessment tier each class needs, and whose signature a go-live requires. Wire it into the purchase-order path.
Cost of leaving
- Effort
- 3–6 months
- Team
- A named policy owner, one operations lead, procurement, employment counsel part-time
- Risk
- Low to medium — the gate must survive its first collision with a live purchase order
- To next stage
- 3–6 months
If this is you, the next step is
We turn your published principles into a tiered, signable gate wired into your purchase path.
Stage 3
Assessed
22% of operators sit here
Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
At stage 3 the character of the work changes from principle to caseload. There is a queue of systems, a tiering rule, and a growing folder of completed assessments, each ending in deployment conditions: the yard cameras keep footage 72 hours, the line-performance dashboard reports at crew level and never at individual level, the T&A system offers a non-biometric alternative. The organisation has learned to ask the right questions before go-live, which is genuinely most of the discipline. What it has not yet done is give the answers any enforcement mechanism beyond the document itself.
Consultation quality is what separates a stage 3 that works from one that decorates. Run as dialogue rather than announcement, consultation catches design errors that no assessment template finds, because workers know things about the plant that system owners do not: which camera angle incidentally covers the union noticeboard, which 'productivity' metric punishes the careful setter who absorbs the line's variability, which corner of the hall is where people take the phone call about a sick child. Every one of those is a rights exposure and a system-design improvement, and only the people on the floor can see them in advance.
The constraint that emerges is drift. Conditions agreed in an assessment are configured once, at go-live, by whoever does the install — and then the vendor ships a platform update, a migration resets a retention default, a new supervisor requests a dashboard permission, and the running system walks away from its assessment one setting at a time. Nothing detects the divergence because the assessment lives in a document repository and the configuration lives in the vendor's admin console, and no process compares them. Closing that loop is the move to stage 4.
In practice
The retention setting that came back
An HRIA on yard and loading-bay cameras set a 72-hour retention limit — long enough for incident review, short enough to prevent retrospective trawling. Eight months later, an unrelated audit found retention at the vendor's 30-day default: a platform migration had rebuilt the configuration from the vendor's baseline, and nobody's job was to notice. Every conclusion in the assessment was right, and for eight months none of it was true on the running system.
What it looks like
- The register is current and every entry has an assessment tier
- HRIAs and DPIAs run before go-live, not after complaints
- Worker representatives are consulted while scope is still changeable
- Assessments produce written deployment conditions — retention, aggregation, access
Diagnostic signals you can check this week
- Pick three closed assessments and check whether their conditions are still configured on the live system — the stage-3 estate usually fails at least one
- Measure consultation lead time: days between worker-representative briefing and contract signature. Negative numbers mean announcement, not consultation
- Check the tier distribution: if everything lands in the highest tier, proportionality has failed and the gate is being routed around
- Ask who reviews vendor release notes against deployment conditions before an update is applied — at stage 3, nobody
Anti-pattern · Treating the assessment as the control
The completed HRIA gets filed as if the document itself were the protection — the same mistake as treating a signed risk assessment as a machine guard. The assessment is the specification; the control is whatever enforces it while nobody is looking: the configuration that cannot be changed without review, the contract clause with audit rights, the alert that fires when retention exceeds its limit. A folder of excellent assessments over an unmonitored estate is stage 3's most comfortable failure mode.
What holds you here
Deployment conditions are documented but not enforced — nothing detects drift between what the assessment agreed and what the running system does.
Highest-leverage next move
Convert every assessment condition into a checkable control: a locked configuration, a vendor contract clause, or a telemetry alert — one of the three, for every condition.
Cost of leaving
- Effort
- 6–12 months
- Team
- The gate owner, plant IT, procurement counsel for vendor clauses, worker representatives as standing participants
- Risk
- Medium — vendor contract renegotiation and configuration lockdown compete with operational demands
- To next stage
- 6–12 months
If this is you, the next step is
We sample your closed assessments and verify each condition on the live system.
Stage 4
Embedded
10% of operators sit here
Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
At stage 4 the gate stops being a meeting and becomes infrastructure. The vendor contract template already contains the purpose-limitation, sub-processor and audit clauses, so procurement does not negotiate them from scratch. System configurations that implement deployment conditions are versioned and checked, the way the plant already versions PLC programs and quality parameters. The manufacturing organisation's existing muscle — management of change, deviation handling, layered process audits — turns out to be exactly the right machinery; rights governance stops feeling like an import from legal and starts running like any other plant discipline.
The interesting shift is that governance starts producing operational data. Appeal rates by system, override outcomes, access-log exceptions, grievance themes: this telemetry does two jobs at once. It is compliance evidence accumulating as a by-product — the artefact a CSDDD-obligated customer or a data protection authority actually asks for — and it is a feedback signal about the systems themselves, because a rising appeal rate on one line is as likely to be a mis-specified metric as a difficult crew. Plants that read the appeal log as system telemetry routinely find model and configuration errors that quality review missed.
Where co-determination applies — Germany's works-council consent requirement for technical monitoring systems being the sharpest case — stage 4 converts it from a blocker into an asset. Works agreements become the codified form of deployment conditions, negotiated once per system class rather than fought per install, and the works council becomes a co-owner of the register rather than an adversary discovering systems after the fact. The remaining gap is external: everything still rests on internal assertion. No one outside the company verifies the register, the conditions or the remedy outcomes, so trust does not compound and every customer audit starts from zero.
In practice
The appeal that changed the model
A filling line's performance system flagged an operator for repeated micro-stops. The operator appealed through the defined route; the named reviewer pulled the event data and found the stops were upstream starvation events being mis-attributed to the operator's station. The configuration was corrected to credit stops to the true source, the flag was withdrawn with an explanation, and appeal volume on that line fell by half the following quarter. The appeal loop had found a model bug that two rounds of system QA had not.
What it looks like
- Procurement templates carry rights clauses with audit and exit rights
- Purpose-limitation and retention configs are versioned and drift-monitored
- Adverse algorithmic decisions have a named human reviewer and an appeal route
- Works agreements codify conditions per system where co-determination applies
Diagnostic signals you can check this week
- Open the procurement template: are the rights clauses standard text with audit and exit rights, or bespoke each time?
- Ask for the config-drift report on any monitored system — at stage 4 it exists and someone reads it
- Trace one appeal end to end: named reviewer, decision, explanation to the worker, and whether the outcome fed a system change
- Where works councils exist, count systems covered by a works agreement against the register — the gap is the exposure
Anti-pattern · Building a parallel bureaucracy
The failure mode at stage 4 is standing up a dedicated rights team that reviews everything itself — a second quality department with its own forms, queues and vetoes. It becomes the bottleneck, plant teams learn to schedule around it, and governance quality degrades with distance from the floor. The plant already runs gates: management of change, deviation management, layered audits. Embed the rights controls into that machinery — one more check in an existing gate outperforms a new bureaucracy every time, and it inherits an audit habit that already works.
What holds you here
Everything rests on internal assertion — no external party verifies the register, the conditions or the remedy outcomes, so trust has to be rebuilt at every audit.
Highest-leverage next move
Close the loop publicly: disclose the worker-facing estate and its governance, commission independent review, and report remedy outcomes in aggregate.
Cost of leaving
- Effort
- 12–18 months
- Team
- Gate owner, plant IT and OT, HR, employment counsel, works-council counterparts; vendor management for clause rollout
- Risk
- Medium-high — contract renegotiations and works agreements have their own calendars, and legacy systems resist retrofitted controls
- To next stage
- 12–18 months
If this is you, the next step is
We trace live appeals through your systems and report where the loop breaks.
Stage 5
Accountable
3% of operators sit here
Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.
Stage 5 is narrower than it sounds. It is not moral perfection and it is not the absence of incidents; it is a defined set of claims the company makes in public and can have verified: we know our estate, we assess before deployment, we consult before signature, our appeal routes work and change our systems, and someone external checks all of this on a cycle. Each claim maps to an artefact — the register, the assessment log, the consultation records, the remedy statistics, the audit report — which is what makes the position defensible rather than aspirational.
Remedy is the pillar that proves the others. The UNGPs' third pillar is access to remedy, and Principle 31 sets effectiveness criteria for grievance mechanisms — legitimate, accessible, predictable, equitable, transparent, rights-compatible, a source of continuous learning, and built on engagement. A mechanism that visibly meets those criteria and demonstrably changes systems — configurations corrected, models retrained, deployments withdrawn — is the strongest single piece of evidence a manufacturer can hold, because it shows the whole cycle operating under load rather than on paper. Disclosure without remedy statistics reads as marketing to exactly the audiences it is meant to persuade.
The stage is also the most exposed to regression, because the estate changes faster than annual governance cycles. An acquisition arrives with an unregistered plant full of biometric T&A and camera analytics. A vendor's quarterly release adds an analytics module across every site at once. A reorganisation orphans the register. Sustaining stage 5 means making review change-triggered rather than calendar-triggered: procurement events, vendor release notes, and M&A due diligence each fire a register review, so the disclosure stays true between annual reports.
In practice
The acquisition that reset the clock
A consumer-goods group acquired a contract manufacturer with three plants. Day-one integration review found biometric time-and-attendance and camera analytics at all three sites, never assessed, with no notices and no worker consultation on record. Because the group ran a cascade playbook — register template, tiered assessment, works-agreement patterns, vendor clause library — the sites were brought into the governed estate in two quarters. Without the playbook, the same finding would have meant either quiet inheritance of the exposure or a costly standstill.
What it looks like
- The worker-facing AI estate and its governance are publicly disclosed
- Grievance and appeal outcomes are tracked and reported in aggregate
- Independent audits examine the register, the conditions and the remedy log
- Supplier and contract-manufacturer agreements cascade the same gate
Diagnostic signals you can check this week
- Read the public disclosure against the internal register — stage 5 means they match, including the uncomfortable systems
- Check whether reported remedy statistics include volumes and outcomes, not just the mechanism's existence
- Ask when the last independent review ran and what changed because of it — 'nothing' is the wrong answer
- Check whether M&A due diligence and vendor release notes trigger register reviews, or whether review waits for the annual cycle
Anti-pattern · Disclosure as public relations
The stage-5 counterfeit publishes commitments, governance diagrams and selected metrics chosen for comfort — mechanism descriptions without volumes, principles without the register, case studies without the appeal that failed. Auditors, works councils and experienced NGO readers all recognise the pattern instantly, and it prices every other claim the company makes. The test is simple: publish the numbers that could embarrass you — appeal volumes, overturn rates, grievances upheld — with context. That is what separates accountability from communications.
What holds you here
The estate changes faster than annual governance cycles — acquisitions, vendor updates and reorganisations decay the register unless review is change-triggered.
Highest-leverage next move
Make register review change-triggered: procurement events, vendor release notes and M&A due diligence each fire a review, so the public disclosure stays true between reports.
Cost of leaving
- Effort
- Continuous
- Team
- A standing governance forum with worker representation, external audit budget, disclosure ownership in the reporting team
- Risk
- Concentrated — low-frequency, high-consequence, regulatory and reputational in nature
If this is you, the next step is
Register, conditions and remedy log examined against what is published; findings you can act on before an auditor finds them.
Where manufacturers actually sit on the ladder
The distribution across the five stages, and why 'Declared' — policy without process — is the plateau the whole page argues against.
Most manufacturers sit on the first two rungs: a third have never inventoried the worker-facing estate at all, and another third have published commitments that no deployment ever passes through. The distribution below is illustrative — synthesised from cross-industry adoption research rather than measured from a single survey — but the shape is the consistent finding: AI adoption in manufacturing operations has run years ahead of the governance of its workforce-facing edge, and the gap concentrates exactly where vendor features meet shop-floor workers.
Distribution of manufacturers across the worker-rights governance ladder
Stages 1 and 2 hold roughly two-thirds of manufacturers between them. The drop from Declared to Assessed is the largest transition loss on the ladder — it is where a commitment has to become a gate with a signature.
Share of manufacturers
- 34% — 1 · Unexamined (exposure without a register)
- 31% — 2 · Declared (policy without process)
- 22% — 3 · Assessed
- 10% — 4 · Embedded
- 3% — 5 · Accountable
The adoption side of the gap is well documented. McKinsey's State of AI research (opens in a new tab) has tracked AI use climbing across operations functions for years, and the WEF's Global Lighthouse Network (opens in a new tab) showcases what the leading edge of factory digitalisation now looks like — sites where scheduling, quality and performance management are AI-assisted as a matter of course, which is precisely the workforce-facing estate this page governs. The governance side has its own research tradition: acatech (opens in a new tab), the German national academy of engineering that shaped the Industrie 4.0 agenda, has argued from the beginning that human-centred design and worker acceptance are load-bearing parts of factory digitalisation, not soft extras. The distribution above is what it looks like when adoption outruns that advice.
The worker-rights decision map: which systems engage which rights
Seven classes of shop-floor AI, the rights each one engages, the regulatory hook that applies, and the governance gate that makes it deployable — the page's centrepiece.
Every class of worker-facing AI in a plant engages a specific, nameable set of rights through a specific mechanism — and the gate each one needs follows from that mapping, not from how sophisticated the model is. The map below covers the seven classes that account for nearly all of a non-automotive manufacturer's exposure. Two navigation aids for the regulatory column: the European Commission's AI Act framework page (opens in a new tab) is the official summary, and the AI Act Explorer (opens in a new tab) makes the full text navigable — Annex III lists the employment and worker-management category; Article 5 carries the workplace emotion-recognition prohibition; Article 26(7) is the duty to inform workers and their representatives before putting a high-risk workplace system into service.
| Shop-floor system | What it watches or decides | Rights engaged | Regulatory hook | Governance gate |
|---|---|---|---|---|
| Algorithmic shift scheduling (WFM) | Who works when; overtime allocation; rest patterns | Just and favourable conditions; family life; non-discrimination | AI Act Annex III (worker management); GDPR | HRIA + consultation; fairness constraints in the optimiser; human sign-off on rosters |
| Productivity scoring on MES / OEE data | Individual performance flags feeding reviews and discipline | Non-discrimination; due process in discipline | AI Act Annex III; GDPR Art 22 (automated decisions) | Full HRIA; crew-level reporting by default; named human reviewer + appeal route |
| Vision-based safety monitoring | PPE compliance, exclusion zones, unsafe behaviour | Privacy; chilling effect on association; OSH (benefit) | AI Act Annex III; GDPR; national workplace-monitoring law | Purpose limitation bound in contract; short retention; event-based capture; no repurposing for discipline |
| Biometric access and T&A | Identity at the gate; hours worked; pay inputs | Privacy (special-category data); data protection | GDPR Art 9 (biometric data); co-determination where it applies | DPIA; a non-biometric alternative offered; template storage and deletion rules |
| Wearables and fatigue monitoring | Ergonomic load, fatigue signals, micro-break prompts | Bodily privacy; health-data protection; OSH (benefit) | GDPR Art 9 (health data); AI Act Annex III | Voluntary participation; aggregation before reporting; health data segregated from HR systems |
| Hiring and screening algorithms | Ranking and filtering applicants for plant roles | Non-discrimination; equal access to work | AI Act Annex III (recruitment); GDPR Art 22 | Bias testing pre-deployment and on retrain; human review of rejections; candidate notice |
| Emotion recognition / sentiment analytics | Inferring emotional state from face, voice or behaviour | Dignity; privacy; freedom of thought | AI Act Article 5 — prohibited in the workplace | Do not deploy. Narrow medical and safety exceptions only — get counsel before touching them |
Two features of this map do most of the governance work. First, the systems live at different levels of the plant stack — ISA-95 (opens in a new tab) level 3 for anything built on MES data, the HR and ERP layer for WFM and T&A, edge devices for vision and wearables — which means the data flows cross organisational boundaries, and the register must follow the data rather than the org chart. MESA's (opens in a new tab) operations-management vocabulary is useful here precisely because it names the systems a rights review has to walk through. Second, the same physical system can sit in two rows at once: a camera deployed for safety is also a productivity monitor the moment anyone opens its analytics on an individual. The gate therefore binds purpose, not hardware — which is why the purpose-limitation clause and the access rules matter more than the camera's specification sheet.
How hard to gate a worker-facing system
Plot any proposed system by what it decides and what it captures. The quadrant sets the assessment tier — and the top-right is where every contested case in this industry actually lives.
Consult and configure
- Vision safety monitoring, wearables, biometric T&A
- Gate: consultation, purpose limitation, retention, voluntariness
- Dual-use risk is the watch item — bind purpose in contract
Gate hard — or redesign
- Productivity scoring feeding discipline; biometric data tied to pay
- Full HRIA, works agreement, named reviewer, drift monitoring
- Emotion recognition sits beyond this quadrant: prohibited
Register and notice
- Aggregate OEE dashboards, anonymised flow analytics
- Lightest tier: register entry + published notice
- Re-check on any vendor update that adds resolution
Human decision, algorithmic input
- Scheduling from aggregate demand; screening shortlists
- Gate: bias testing, human review, appeal route
- The human must be able to disagree in practice, not just in the SOP
What public commitments look like in practice
Two manufacturers whose published human-rights and responsible-AI programmes can be read against the ladder. Neither is an Atomic Loops engagement — each links to the operator's own published material.
The clearest public evidence for the ladder is in what large manufacturers with mature human-rights programmes chose to build when AI arrived. In both cases below the pattern is the same: the companies did not invent AI ethics from scratch — they extended an existing due-diligence infrastructure to cover the AI estate, which is precisely the Declared-to-Embedded climb this page describes. Siemens publishes both its industrial AI approach (opens in a new tab) and its sustainability and human-rights reporting; Unilever's human-rights reporting has been public since 2015. Outcomes are as reported in the operators' own material; we have not independently audited them.
Two programmes read against the ladder
Images are illustrative generated scenes from this page's asset library, not operator photography. Outcomes as reported in the operators' own published material — verify against the linked sources before reusing figures.
UnileverGlobal consumer goods manufacturer · foods, home and personal care24
- Challenge
- Scaling AI across manufacturing, supply chain and workforce-adjacent processes while holding a long-standing, public human-rights commitment — with the reputational exposure that any gap between the two would carry.
- Approach
- Unilever has publicly described a responsible-AI assurance approach under which proposed AI applications are reviewed against criteria including fairness, privacy and transparency before deployment — extending the salience-based due-diligence discipline of its human-rights programme, publicly reported since its standalone human-rights report in 2015, to the AI estate.
- Reported outcome
- As reported in Unilever's own published material: a structured pre-deployment review process for new AI use cases, operating alongside one of the longest-running public corporate human-rights reporting programmes in manufacturing.
- What it shows about the curveA mature HRDD infrastructure makes AI governance an extension rather than a new build. Unilever's climb from commitment to embedded gate was fast precisely because salience mapping, assessment habits and reporting already existed — the AI estate was a new subject for an old discipline.
Unilever — human rights and responsible business reporting (opens in a new tab)
SiemensIndustrial technology group · electronics and digital-industries factories24
- Challenge
- Deploying industrial AI at scale — in its own electronics plants and in products sold to other manufacturers — inside the EU regulatory environment and under German co-determination, where worker representatives hold consent rights over monitoring-capable technical systems.
- Approach
- Company-wide responsible-AI principles embedded into the AI development and deployment lifecycle, with human-rights due diligence across its own operations and supply chain reported through its published sustainability reporting — and the consultation machinery of co-determination carrying worker voice into deployment decisions as standard practice.
- Reported outcome
- As reported in Siemens' own published material: company-wide principles governing responsible AI use, and human-rights due diligence reported annually across operations and the supply chain.
- What it shows about the curveIn co-determined environments the consultation machinery already exists — the ladder climb is wiring the AI estate into it rather than building parallel structures. Works agreements become the codified form of deployment conditions, negotiated once per system class instead of disputed per install.
Siemens — sustainability and human-rights reporting (opens in a new tab)
The four dimensions that set your stage
Rights governance is not one number. Four dimensions gate each other, and the lowest is the real stage.
Rights governance is scored on four dimensions — estate visibility, due diligence and vendors, worker voice and transparency, and remedy and accountability — and the lowest of the four is the real stage, because each one gates the others. A rigorous assessment process over an incomplete register is due diligence on a fiction; a working appeal route nobody can find is remedy in name only. The structure deliberately parallels the govern–map–measure–manage discipline of NIST's AI Risk Management Framework (opens in a new tab), so teams already using the RMF can slot the rights dimensions into an existing programme rather than running a second one.
Estate visibility
The register and the data-flow maps behind it. The binding question is whether you can name every system that captures individual-level worker data or feeds decisions about work — including the vendor features enabled since the last review. Until you can, every other dimension operates on a sample of the real exposure.
Due diligence and vendors
The tiered gate and the contract clauses that make its conditions survive vendor updates. In a manufacturing estate that is mostly bought rather than built, vendor governance is the dimension — a perfect internal process with unbound vendors re-opens every condition at every release.
Worker voice and transparency
Consultation timing and quality, plus what a worker can find out about the systems watching them. This is the dimension that predicts dispute risk, and it is overwhelmingly the cheapest to improve: notices and pre-signature consultation cost approximately nothing against the price of one works-council standstill.
Remedy and accountability
The appeal routes, the grievance mechanism measured against the UNGPs' effectiveness criteria, and who answers for the estate's performance. This is the dimension auditors test hardest, because a working remedy loop is evidence the entire cycle operates under load — and its telemetry is what continuous improvement of the estate actually runs on.
The dimensions also sequence the work. Visibility before due diligence, because you cannot gate what you cannot list. Due diligence before voice only in the narrow sense that consultation needs something concrete to consult on — in practice they run together, and consultation routinely improves the assessment. Remedy last to build but first to prove: when an auditor, a customer or a works council wants one piece of evidence that the programme is real, the appeal log with outcomes is what settles the question.