Redefining Technology

Manufacturing (Non-Automotive)Regulations, Compliance & Governance

Manufacturing AI human rights governance: the worker-rights ladder for non-automotive plants

AI human rights governance is the discipline of identifying every AI system that watches, scores or schedules factory workers, assessing its impact on their rights before it goes live, consulting the people it affects, and providing a working route to remedy — the UN Guiding Principles' due-diligence cycle applied to the shop-floor AI estate.

Illustrative generated scene: a non-automotive factory floor where camera analytics, scheduling screens and operator workstations overlap — the worker-facing AI estate this page governs
Manufacturing (Non-Automotive) · Regulations, Compliance & Governance

Key takeaways

  1. AI human rights governance in manufacturing is not an ethics statement — it is the UNGPs' due-diligence cycle (know your estate, assess, consult, remedy) applied to every system that watches, scores or schedules workers, run through the same gates a plant already uses for quality and change management.
  2. The exposure is wider than surveillance: algorithmic shift scheduling, productivity scoring built on MES and OEE data, vision-based safety monitoring, biometric time-and-attendance and hiring screens each engage different rights and need different gates.
  3. The EU AI Act makes workplace AI a named high-risk category, obliges employers to inform workers and their representatives before deployment, and bans emotion recognition at work outright — with the prohibited-practice penalty band reaching €35m or 7% of global turnover.
  4. Most manufacturers sit at the 'Declared' stage: a published commitment with no enforcement point in the deployment path. The ladder out runs Declared → Assessed → Embedded → Accountable, and each rung is process design, not philosophy.
  5. Consultation before contract signature is the single highest-leverage move on the ladder — scope is still changeable, co-determination risk collapses, and workers routinely catch design errors that assessments miss. Remedy data then becomes the feedback loop that improves the systems themselves.

Abbreviations used on this page

UNGPs
UN Guiding Principles on Business and Human Rights
HRDD
Human-rights due diligence
HRIA
Human-rights impact assessment
FRIA
Fundamental-rights impact assessment (EU AI Act, Article 27)
DPIA
Data protection impact assessment (GDPR)
CSDDD
EU Corporate Sustainability Due Diligence Directive
GDPR
General Data Protection Regulation
ILO
International Labour Organization
MES
Manufacturing execution system (ISA-95 level 3)
WFM
Workforce management system (rostering, labour scheduling)
T&A
Time-and-attendance system
OEE
Overall equipment effectiveness

Free · 8 questions · ~3 minutes

Score your plant on the worker-rights ladder

Eight questions, one at a time, about three minutes. Answer them and we build your personalised rights-governance report — your stage on the ladder, your score on each of the four dimensions, and the specific gap standing between you and the next stage — and send it to your inbox. Your result doubles as the baseline for your first estate review.

0 of 8 answered

Question 1 of 8Estate visibility

How complete is your inventory of AI systems that watch, score or schedule workers?

Everything else gates on this. You cannot assess, consult on or remedy a system nobody has listed.

How the score maps to a stage
  • 05 — Stage 1, Unexamined. Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
  • 611 — Stage 2, Declared. A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
  • 1216 — Stage 3, Assessed. Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
  • 1721 — Stage 4, Embedded. Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
  • 2224 — Stage 5, Accountable. Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.

What AI human rights governance means on the factory floor

A definition, the instruments behind it, and the deployment path that decides whether a worker-facing system is defensible or a dispute waiting to surface.

AI human rights governance is the application of human-rights due diligence — the know-your-impacts, assess, consult and remediate cycle that the UN Guiding Principles on Business and Human Rights ask of every company — to the specific AI systems that watch, score or schedule the people working in a plant. In a non-automotive manufacturing operation that estate is wider than the word 'surveillance' suggests: the WFM module allocating shifts, the productivity analytics built on MES and OEE data, the vision system watching for missing PPE, the biometric T&A terminal at the gate, and the screening algorithm ranking applicants for the packing hall are all worker-facing AI, and each engages a different set of rights through a different mechanism.

The instruments are concrete, not aspirational. The UNGPs (opens in a new tab) — 31 principles endorsed unanimously by the UN Human Rights Council in 2011 — define the corporate responsibility to respect human rights and the due-diligence cycle this page builds on. The ILO's fundamental principles and rights at work (opens in a new tab) — five categories, ten fundamental conventions since a safe and healthy working environment was added in 2022 — define what the rights at stake actually are: freedom of association and collective bargaining, freedom from forced and child labour, non-discrimination, and occupational safety and health. And the EU AI Act (opens in a new tab) hardens part of this into product-style regulation: AI used in employment and worker management is a named high-risk category, employers must inform workers and their representatives before putting such systems into service, and emotion recognition in the workplace is prohibited outright. The OECD Guidelines for Multinational Enterprises and the EU's CSDDD extend the same due-diligence expectations through the supply chain — which is why customer audit questionnaires increasingly ask about the AI estate.

Business enterprises should respect human rights. This means that they should avoid infringing on the human rights of others and should address adverse human rights impacts with which they are involved.

How a vision-monitoring rollout reaches the floor, at each stage of the ladder

The same camera-analytics purchase travelling three paths. The stage is determined by what stands between the vendor's feature and the worker it watches: at stages 1–2 nothing does; at stages 3–4 a register, an assessment, consultation and conditioned configuration do; at stage 5 a remedy loop feeds what is learned back into the estate. Most manufacturers are in the top lane.

  • Data & feeds
  • System-of-record action
  • Where value leaks
  • Human in the loop
  • AI / model

The process, in words

  • In the procurement-led lane, monitoring capability arrives as a vendor feature inside a system bought for something else. Nothing stands between the feature and the worker: IT enables it, supervisors discover the dashboards, and the exposure runs silently until a grievance, a works-council standstill or a regulator's letter surfaces it — at which point the whole system, including its legitimate function, is usually switched off.
  • In the rights-gated lane, the same purchase enters a register before signature, a tiered assessment sets the conditions proportionate to what the system watches and decides, worker representatives are consulted while scope can still change, and the system goes live with purpose limitation, retention and access rules configured — then monitored for drift, because conditions that live only in documents do not survive vendor updates.
  • The accountable loop is what stage 5 adds: a contested decision travels a defined appeal route to a named human reviewer, remedies change the system rather than just the individual outcome, and outcomes are disclosed and independently checked — turning individual grievances into estate-level learning and the disclosure into something an auditor can verify rather than take on trust.
Step-by-step insights
The feature flag is the real deployment event
Manufacturing AI governance fails at procurement more often than at deployment, because in a bought estate the deployment event is invisible: it is a firmware update, a licence-tier change or a module activation, not a project with a kick-off. A governance process keyed to 'projects' misses most of the estate. The fix is to key the gate to capability, not procurement category — any change that adds capture of individual-level worker data or adds a decision about work allocation, evaluation or discipline is a deployment, whoever initiated it and however small the invoice.
Why the ungoverned lane ends in switch-off
The characteristic end-state of the top lane is not a fine — it is the total loss of the system, including its legitimate function. When the packaging-hall cameras bought for seal inspection are discovered doing idle-time analytics, the works council or the data protection authority does not surgically disable the analytics module; the plant switches the cameras off entirely while the dispute runs, and the quality function goes with them. Ungoverned monitoring places the whole investment at the mercy of its least defensible feature.
Salience is what makes the gate proportionate
The gated lane only works if the assessment tier matches the stakes. Salience — the human-rights term for where the most severe impacts on people are likely — is the sorting rule: aggregate flow analytics that never resolve an individual sit in the lightest tier (register entry and notice); anything feeding pay, discipline or employment decisions, or capturing biometric and continuous individual data, gets the full assessment with consultation. Tiering is what keeps the gate fast enough that plant teams use it rather than route around it.
Consultation before signature is where scope is still real
The placement of the consultation node — before contract signature — is the single most consequential design choice in the lane. Consulted after signature, worker representatives can only accept or obstruct; consulted before, they can shape zone coverage, aggregation level and retention while the vendor still has an incentive to configure flexibly. In co-determined environments this is also the difference between a works agreement negotiated once and an injunction discovered later; everywhere else it is simply the cheapest error-detection pass the project will ever get.
The remedy loop is telemetry, not ceremony
The stage-5 lane treats appeals as system telemetry. An appeal that finds micro-stops mis-attributed to an operator is a model-quality finding; a cluster of grievances about one line's scoring is a configuration signal; an access-log exception is a control failure. Plants that route this data back into system ownership get a feedback channel their quality processes cannot provide — and the aggregate statistics become the disclosure that separates verifiable accountability from published good intentions.

This page is deliberately not a management-system guide. Certifying the machinery that runs an AI programme — scope statements, controls, internal audits — is ISO/IEC 42001 territory, covered by the companion guide in this knowledge base cell. Rights governance answers the prior question: what that machinery must protect, for whom, and who can appeal when it fails. The rest of this page gives the answer an operating shape — a five-stage ladder from unexamined estate to external accountability, a decision map naming which shop-floor systems engage which rights, and the deployment gate that ties them together.

The five stages of the worker-rights governance ladder

For each stage: what it looks like on the ground, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps manufacturers there, and what leaving costs.

Each stage below is written for a practitioner rather than a buyer. The ladder runs from an estate nobody has examined, through declared commitments and assessed deployments, to controls embedded in procurement and configuration, and finally to external accountability. The hallmarks describe observable conditions, the diagnostic signals are checks you can run against your own plants this week, and the anti-pattern is the specific mistake most often made trying to leave that stage.

Defensible worker-facing AI released against position on the ladder

The curve is not linear. Almost nothing is defensibly deployable at stages 1–2 — every system runs at the mercy of its least defensible feature — and capability inflects at stage 3, when assessment and consultation start producing conditions a dispute can be answered with. This mirrors the UNGPs' own arc: commitment alone releases nothing; due diligence and remedy release everything.

Worker-facing AI you can defensibly run by stage

  • Stage 1 · Unexamined — 34% of operators. Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.
  • Stage 2 · Declared — 31% of operators. A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.
  • Stage 3 · Assessed — 22% of operators. Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.
  • Stage 4 · Embedded — 10% of operators. Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.
  • Stage 5 · Accountable — 3% of operators. Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.

Curve shape: logistic, plotted from the stage data above. Distribution: Consistent with the UNGPs' commit–assess–remedy arc.

Select a stage

Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Unexamined

34% of operators sit here

Worker-facing AI is already running — in the WFM module, the camera system, the T&A terminal — but nobody has listed it, so the rights exposure is invisible.

Stage 1 is rarely a decision anyone made. The worker-facing AI estate accretes: the vision system bought for quality inspection gains people-detection in a firmware update, the WFM suite's next release adds an absence-prediction module, the access-control vendor upsells facial recognition as a convenience feature. Each arrival is a procurement line item or a maintenance contract, not an AI deployment — so no deployment review ever fires. The plant is running algorithmic management without ever having chosen to.

The tell is to ask for a list. At stage 1 nobody can produce one, and the attempt exposes the ownership gap: HR believes plant IT reviews these systems, plant IT believes HR owns anything touching people, EHS assumes legal has looked at the cameras, and legal has never heard of half the estate. Meanwhile the systems accumulate exactly the data — individual cycle times, movement traces, biometric templates — that a works council, a data protection authority or a customer auditor will one day ask about.

This is a cheap stage to leave and an expensive stage to be caught in. The inventory is an afternoon per site: walk the floor, read the vendor contracts, ask supervisors what they can see about individual operators. Staying costs nothing until the first dispute — and the first dispute arrives with no register, no assessment, no notice and no paper trail, which converts a manageable governance question into a trust collapse.

In practice

The upgrade that became a monitoring system

A packaging plant ran ceiling cameras for seal-quality inspection. A vendor firmware upgrade added people-detection and idle-time analytics as a bundled feature; a shift supervisor discovered the new dashboard and began using screenshots in performance conversations. The works council found out from a printout left on a desk. Outcome: a formal grievance, the entire camera system switched off pending review — including the quality function it was actually bought for — and a year of rebuilding trust before any vision project could be proposed again.

What it looks like

  • Monitoring-capable features arrive inside systems bought for other reasons
  • No register of AI systems that touch workers exists anywhere
  • Workers learn what a system does from the floor, not from a notice
  • HR, IT and EHS each assume one of the others owns the question

Diagnostic signals you can check this week

  • Ask for the register of AI systems that touch workers — at stage 1 there is none
  • Ask procurement which live systems have monitoring-capable features in their current release; compare against what IT believes is enabled
  • Look for a single published transparency notice describing any system's data capture — usually zero exist
  • Ask a line supervisor to show you what they can see about an individual operator; note whether anyone approved that view

Anti-pattern · Writing the policy first

The instinctive first move is an AI ethics policy — principles, values, a commitment to human oversight. Written before the estate is known, the policy names no systems, binds no procurement decision and cannot be falsified, so it changes nothing and ages into evidence of a commitment the company knew about and did not operationalise. Inventory first: a one-page register of real systems generates more governance in a month than a principles document does in three years, and the policy written afterwards can name what it governs.

What holds you here

Nobody owns the question, so the estate stays invisible — HR, IT, EHS and legal each assume another function has reviewed it.

Highest-leverage next move

Build the worker-facing AI register: one afternoon per site, walking the floor with the vendor contracts, recording what each system captures about whom.

Cost of leaving

Effort
1–3 months
Team
One HR-operations pair per site, part-time, with procurement contract access
Risk
Low — the work is a survey; nothing changes on the floor yet
To next stage
1–3 months

If this is you, the next step is

A per-site walk-down and contract review; you get the register and the data-flow map.

Get your estate inventoried

Stage 2

Declared

31% of operators sit here

A public commitment exists — an AI principles statement or a human-rights policy that names technology — but no process connects it to what actually ships to the floor.

Stage 2 is where most manufacturers with any governance ambition actually sit, and it feels like progress because the commitment is real. The board approved the principles, the sustainability report cites the UNGPs, and the intention is genuine. The gap is structural: deployment decisions are procurement and plant-IT decisions, and the policy has no seat at that table. A rostering module goes live because the operations director signed the purchase order; at no point does anything in the purchase path ask whether the policy applies.

Declared commitments are not neutral while they wait for process. They raise the standard against which the company is judged — by customer auditors working through their own CSDDD obligations, by works councils quoting the company's own principles back at it, and eventually by regulators reading the sustainability report next to the plant's practice. The delta between what is declared and what is enforced is precisely what an audit measures. A manufacturer with no policy and no estate review is careless; one with a published policy and an ungoverned estate is worse positioned in any dispute, because the knowledge standard has been set by its own hand.

Leaving stage 2 is process design, not philosophy. Three definitions do most of the work: what counts as worker-facing (any system that captures individual-level worker data or feeds decisions about work allocation, evaluation or discipline), which tier of assessment each class of system needs (a notice, a DPIA, or a full HRIA with consultation), and who signs the gate. Wire those three into the purchase-order path and the change-management process the plant already runs, and the policy acquires an enforcement point.

In practice

The principles and the pilot

A food manufacturer published AI principles committing to 'human oversight and fairness in all AI affecting our people'. The same quarter, a plant piloted its WFM vendor's AI rostering module. Nobody mapped the pilot to the principles — it was a module activation, not a project. The optimiser learned to weight absence history, quietly disadvantaging workers with caring responsibilities in shift allocation. The grievance, when it came, quoted the company's own published principles in its first paragraph.

What it looks like

  • Responsible-AI principles are published and sincerely meant
  • Deployment remains a procurement decision the policy never touches
  • Assessments happen only when legal flags a GDPR question
  • Worker consultation is an announcement, when it happens at all

Diagnostic signals you can check this week

  • Read the purchase-order and change-management templates: does any field reference the AI policy? Usually not
  • Count worker-facing deployments in the last year against completed assessments — the ratio at stage 2 is many to almost none
  • Ask who can stop a deployment on rights grounds; if the honest answer is 'nobody, in practice', the policy has no gate
  • Compare the sustainability report's AI language against any single plant's live estate — the delta is the stage-2 signature

Anti-pattern · Scaling the paperwork instead of the gate

Stung by the gap, the company mandates a forty-page ethics assessment for every system that touches a person. Plant teams — who have lines to run — route around it, classify systems as 'not AI', or batch approvals through whoever signs fastest, and the register decays into fiction. Proportionality is the design constraint, not a concession: a three-tier gate where the lowest tier is a one-page register entry and notice keeps the estate visible, while reserving the full HRIA for the systems that decide pay, discipline or employment.

What holds you here

The policy has no enforcement point in the deployment path — procurement and plant IT can put a system live without ever touching it.

Highest-leverage next move

Define the gate: what counts as worker-facing, which assessment tier each class needs, and whose signature a go-live requires. Wire it into the purchase-order path.

Cost of leaving

Effort
3–6 months
Team
A named policy owner, one operations lead, procurement, employment counsel part-time
Risk
Low to medium — the gate must survive its first collision with a live purchase order
To next stage
3–6 months

If this is you, the next step is

We turn your published principles into a tiered, signable gate wired into your purchase path.

Design the deployment gate

Stage 3

Assessed

22% of operators sit here

Every worker-facing deployment passes a proportionate rights assessment before go-live and workers are consulted — but the resulting controls live in documents, not in systems.

At stage 3 the character of the work changes from principle to caseload. There is a queue of systems, a tiering rule, and a growing folder of completed assessments, each ending in deployment conditions: the yard cameras keep footage 72 hours, the line-performance dashboard reports at crew level and never at individual level, the T&A system offers a non-biometric alternative. The organisation has learned to ask the right questions before go-live, which is genuinely most of the discipline. What it has not yet done is give the answers any enforcement mechanism beyond the document itself.

Consultation quality is what separates a stage 3 that works from one that decorates. Run as dialogue rather than announcement, consultation catches design errors that no assessment template finds, because workers know things about the plant that system owners do not: which camera angle incidentally covers the union noticeboard, which 'productivity' metric punishes the careful setter who absorbs the line's variability, which corner of the hall is where people take the phone call about a sick child. Every one of those is a rights exposure and a system-design improvement, and only the people on the floor can see them in advance.

The constraint that emerges is drift. Conditions agreed in an assessment are configured once, at go-live, by whoever does the install — and then the vendor ships a platform update, a migration resets a retention default, a new supervisor requests a dashboard permission, and the running system walks away from its assessment one setting at a time. Nothing detects the divergence because the assessment lives in a document repository and the configuration lives in the vendor's admin console, and no process compares them. Closing that loop is the move to stage 4.

In practice

The retention setting that came back

An HRIA on yard and loading-bay cameras set a 72-hour retention limit — long enough for incident review, short enough to prevent retrospective trawling. Eight months later, an unrelated audit found retention at the vendor's 30-day default: a platform migration had rebuilt the configuration from the vendor's baseline, and nobody's job was to notice. Every conclusion in the assessment was right, and for eight months none of it was true on the running system.

What it looks like

  • The register is current and every entry has an assessment tier
  • HRIAs and DPIAs run before go-live, not after complaints
  • Worker representatives are consulted while scope is still changeable
  • Assessments produce written deployment conditions — retention, aggregation, access

Diagnostic signals you can check this week

  • Pick three closed assessments and check whether their conditions are still configured on the live system — the stage-3 estate usually fails at least one
  • Measure consultation lead time: days between worker-representative briefing and contract signature. Negative numbers mean announcement, not consultation
  • Check the tier distribution: if everything lands in the highest tier, proportionality has failed and the gate is being routed around
  • Ask who reviews vendor release notes against deployment conditions before an update is applied — at stage 3, nobody

Anti-pattern · Treating the assessment as the control

The completed HRIA gets filed as if the document itself were the protection — the same mistake as treating a signed risk assessment as a machine guard. The assessment is the specification; the control is whatever enforces it while nobody is looking: the configuration that cannot be changed without review, the contract clause with audit rights, the alert that fires when retention exceeds its limit. A folder of excellent assessments over an unmonitored estate is stage 3's most comfortable failure mode.

What holds you here

Deployment conditions are documented but not enforced — nothing detects drift between what the assessment agreed and what the running system does.

Highest-leverage next move

Convert every assessment condition into a checkable control: a locked configuration, a vendor contract clause, or a telemetry alert — one of the three, for every condition.

Cost of leaving

Effort
6–12 months
Team
The gate owner, plant IT, procurement counsel for vendor clauses, worker representatives as standing participants
Risk
Medium — vendor contract renegotiation and configuration lockdown compete with operational demands
To next stage
6–12 months

If this is you, the next step is

We sample your closed assessments and verify each condition on the live system.

Audit your conditions against your configs

Stage 4

Embedded

10% of operators sit here

Rights controls are wired into procurement, configuration and monitoring — a worker-facing system cannot reach the floor without its conditions travelling with it, and appeals work.

At stage 4 the gate stops being a meeting and becomes infrastructure. The vendor contract template already contains the purpose-limitation, sub-processor and audit clauses, so procurement does not negotiate them from scratch. System configurations that implement deployment conditions are versioned and checked, the way the plant already versions PLC programs and quality parameters. The manufacturing organisation's existing muscle — management of change, deviation handling, layered process audits — turns out to be exactly the right machinery; rights governance stops feeling like an import from legal and starts running like any other plant discipline.

The interesting shift is that governance starts producing operational data. Appeal rates by system, override outcomes, access-log exceptions, grievance themes: this telemetry does two jobs at once. It is compliance evidence accumulating as a by-product — the artefact a CSDDD-obligated customer or a data protection authority actually asks for — and it is a feedback signal about the systems themselves, because a rising appeal rate on one line is as likely to be a mis-specified metric as a difficult crew. Plants that read the appeal log as system telemetry routinely find model and configuration errors that quality review missed.

Where co-determination applies — Germany's works-council consent requirement for technical monitoring systems being the sharpest case — stage 4 converts it from a blocker into an asset. Works agreements become the codified form of deployment conditions, negotiated once per system class rather than fought per install, and the works council becomes a co-owner of the register rather than an adversary discovering systems after the fact. The remaining gap is external: everything still rests on internal assertion. No one outside the company verifies the register, the conditions or the remedy outcomes, so trust does not compound and every customer audit starts from zero.

In practice

The appeal that changed the model

A filling line's performance system flagged an operator for repeated micro-stops. The operator appealed through the defined route; the named reviewer pulled the event data and found the stops were upstream starvation events being mis-attributed to the operator's station. The configuration was corrected to credit stops to the true source, the flag was withdrawn with an explanation, and appeal volume on that line fell by half the following quarter. The appeal loop had found a model bug that two rounds of system QA had not.

What it looks like

  • Procurement templates carry rights clauses with audit and exit rights
  • Purpose-limitation and retention configs are versioned and drift-monitored
  • Adverse algorithmic decisions have a named human reviewer and an appeal route
  • Works agreements codify conditions per system where co-determination applies

Diagnostic signals you can check this week

  • Open the procurement template: are the rights clauses standard text with audit and exit rights, or bespoke each time?
  • Ask for the config-drift report on any monitored system — at stage 4 it exists and someone reads it
  • Trace one appeal end to end: named reviewer, decision, explanation to the worker, and whether the outcome fed a system change
  • Where works councils exist, count systems covered by a works agreement against the register — the gap is the exposure

Anti-pattern · Building a parallel bureaucracy

The failure mode at stage 4 is standing up a dedicated rights team that reviews everything itself — a second quality department with its own forms, queues and vetoes. It becomes the bottleneck, plant teams learn to schedule around it, and governance quality degrades with distance from the floor. The plant already runs gates: management of change, deviation management, layered audits. Embed the rights controls into that machinery — one more check in an existing gate outperforms a new bureaucracy every time, and it inherits an audit habit that already works.

What holds you here

Everything rests on internal assertion — no external party verifies the register, the conditions or the remedy outcomes, so trust has to be rebuilt at every audit.

Highest-leverage next move

Close the loop publicly: disclose the worker-facing estate and its governance, commission independent review, and report remedy outcomes in aggregate.

Cost of leaving

Effort
12–18 months
Team
Gate owner, plant IT and OT, HR, employment counsel, works-council counterparts; vendor management for clause rollout
Risk
Medium-high — contract renegotiations and works agreements have their own calendars, and legacy systems resist retrofitted controls
To next stage
12–18 months

If this is you, the next step is

We trace live appeals through your systems and report where the loop breaks.

Pressure-test your appeal route

Stage 5

Accountable

3% of operators sit here

Governance is externally accountable: the estate is disclosed, remedy outcomes are tracked and reported, independent reviews run, and supplier contracts cascade the same discipline.

Stage 5 is narrower than it sounds. It is not moral perfection and it is not the absence of incidents; it is a defined set of claims the company makes in public and can have verified: we know our estate, we assess before deployment, we consult before signature, our appeal routes work and change our systems, and someone external checks all of this on a cycle. Each claim maps to an artefact — the register, the assessment log, the consultation records, the remedy statistics, the audit report — which is what makes the position defensible rather than aspirational.

Remedy is the pillar that proves the others. The UNGPs' third pillar is access to remedy, and Principle 31 sets effectiveness criteria for grievance mechanisms — legitimate, accessible, predictable, equitable, transparent, rights-compatible, a source of continuous learning, and built on engagement. A mechanism that visibly meets those criteria and demonstrably changes systems — configurations corrected, models retrained, deployments withdrawn — is the strongest single piece of evidence a manufacturer can hold, because it shows the whole cycle operating under load rather than on paper. Disclosure without remedy statistics reads as marketing to exactly the audiences it is meant to persuade.

The stage is also the most exposed to regression, because the estate changes faster than annual governance cycles. An acquisition arrives with an unregistered plant full of biometric T&A and camera analytics. A vendor's quarterly release adds an analytics module across every site at once. A reorganisation orphans the register. Sustaining stage 5 means making review change-triggered rather than calendar-triggered: procurement events, vendor release notes, and M&A due diligence each fire a register review, so the disclosure stays true between annual reports.

In practice

The acquisition that reset the clock

A consumer-goods group acquired a contract manufacturer with three plants. Day-one integration review found biometric time-and-attendance and camera analytics at all three sites, never assessed, with no notices and no worker consultation on record. Because the group ran a cascade playbook — register template, tiered assessment, works-agreement patterns, vendor clause library — the sites were brought into the governed estate in two quarters. Without the playbook, the same finding would have meant either quiet inheritance of the exposure or a costly standstill.

What it looks like

  • The worker-facing AI estate and its governance are publicly disclosed
  • Grievance and appeal outcomes are tracked and reported in aggregate
  • Independent audits examine the register, the conditions and the remedy log
  • Supplier and contract-manufacturer agreements cascade the same gate

Diagnostic signals you can check this week

  • Read the public disclosure against the internal register — stage 5 means they match, including the uncomfortable systems
  • Check whether reported remedy statistics include volumes and outcomes, not just the mechanism's existence
  • Ask when the last independent review ran and what changed because of it — 'nothing' is the wrong answer
  • Check whether M&A due diligence and vendor release notes trigger register reviews, or whether review waits for the annual cycle

Anti-pattern · Disclosure as public relations

The stage-5 counterfeit publishes commitments, governance diagrams and selected metrics chosen for comfort — mechanism descriptions without volumes, principles without the register, case studies without the appeal that failed. Auditors, works councils and experienced NGO readers all recognise the pattern instantly, and it prices every other claim the company makes. The test is simple: publish the numbers that could embarrass you — appeal volumes, overturn rates, grievances upheld — with context. That is what separates accountability from communications.

What holds you here

The estate changes faster than annual governance cycles — acquisitions, vendor updates and reorganisations decay the register unless review is change-triggered.

Highest-leverage next move

Make register review change-triggered: procurement events, vendor release notes and M&A due diligence each fire a review, so the public disclosure stays true between reports.

Cost of leaving

Effort
Continuous
Team
A standing governance forum with worker representation, external audit budget, disclosure ownership in the reporting team
Risk
Concentrated — low-frequency, high-consequence, regulatory and reputational in nature

If this is you, the next step is

Register, conditions and remedy log examined against what is published; findings you can act on before an auditor finds them.

Scope an independent estate review

Where manufacturers actually sit on the ladder

The distribution across the five stages, and why 'Declared' — policy without process — is the plateau the whole page argues against.

Most manufacturers sit on the first two rungs: a third have never inventoried the worker-facing estate at all, and another third have published commitments that no deployment ever passes through. The distribution below is illustrative — synthesised from cross-industry adoption research rather than measured from a single survey — but the shape is the consistent finding: AI adoption in manufacturing operations has run years ahead of the governance of its workforce-facing edge, and the gap concentrates exactly where vendor features meet shop-floor workers.

Distribution of manufacturers across the worker-rights governance ladder

Stages 1 and 2 hold roughly two-thirds of manufacturers between them. The drop from Declared to Assessed is the largest transition loss on the ladder — it is where a commitment has to become a gate with a signature.

Share of manufacturers

  • 34% — 1 · Unexamined (exposure without a register)
  • 31% — 2 · Declared (policy without process)
  • 22% — 3 · Assessed
  • 10% — 4 · Embedded
  • 3% — 5 · Accountable

Source: Illustrative distribution, synthesised from McKinsey State of AI and WEF Global Lighthouse Network adoption reporting

The adoption side of the gap is well documented. McKinsey's State of AI research (opens in a new tab) has tracked AI use climbing across operations functions for years, and the WEF's Global Lighthouse Network (opens in a new tab) showcases what the leading edge of factory digitalisation now looks like — sites where scheduling, quality and performance management are AI-assisted as a matter of course, which is precisely the workforce-facing estate this page governs. The governance side has its own research tradition: acatech (opens in a new tab), the German national academy of engineering that shaped the Industrie 4.0 agenda, has argued from the beginning that human-centred design and worker acceptance are load-bearing parts of factory digitalisation, not soft extras. The distribution above is what it looks like when adoption outruns that advice.

The worker-rights decision map: which systems engage which rights

Seven classes of shop-floor AI, the rights each one engages, the regulatory hook that applies, and the governance gate that makes it deployable — the page's centrepiece.

Every class of worker-facing AI in a plant engages a specific, nameable set of rights through a specific mechanism — and the gate each one needs follows from that mapping, not from how sophisticated the model is. The map below covers the seven classes that account for nearly all of a non-automotive manufacturer's exposure. Two navigation aids for the regulatory column: the European Commission's AI Act framework page (opens in a new tab) is the official summary, and the AI Act Explorer (opens in a new tab) makes the full text navigable — Annex III lists the employment and worker-management category; Article 5 carries the workplace emotion-recognition prohibition; Article 26(7) is the duty to inform workers and their representatives before putting a high-risk workplace system into service.

Shop-floor systemWhat it watches or decidesRights engagedRegulatory hookGovernance gate
Algorithmic shift scheduling (WFM)Who works when; overtime allocation; rest patternsJust and favourable conditions; family life; non-discriminationAI Act Annex III (worker management); GDPRHRIA + consultation; fairness constraints in the optimiser; human sign-off on rosters
Productivity scoring on MES / OEE dataIndividual performance flags feeding reviews and disciplineNon-discrimination; due process in disciplineAI Act Annex III; GDPR Art 22 (automated decisions)Full HRIA; crew-level reporting by default; named human reviewer + appeal route
Vision-based safety monitoringPPE compliance, exclusion zones, unsafe behaviourPrivacy; chilling effect on association; OSH (benefit)AI Act Annex III; GDPR; national workplace-monitoring lawPurpose limitation bound in contract; short retention; event-based capture; no repurposing for discipline
Biometric access and T&AIdentity at the gate; hours worked; pay inputsPrivacy (special-category data); data protectionGDPR Art 9 (biometric data); co-determination where it appliesDPIA; a non-biometric alternative offered; template storage and deletion rules
Wearables and fatigue monitoringErgonomic load, fatigue signals, micro-break promptsBodily privacy; health-data protection; OSH (benefit)GDPR Art 9 (health data); AI Act Annex IIIVoluntary participation; aggregation before reporting; health data segregated from HR systems
Hiring and screening algorithmsRanking and filtering applicants for plant rolesNon-discrimination; equal access to workAI Act Annex III (recruitment); GDPR Art 22Bias testing pre-deployment and on retrain; human review of rejections; candidate notice
Emotion recognition / sentiment analyticsInferring emotional state from face, voice or behaviourDignity; privacy; freedom of thoughtAI Act Article 5 — prohibited in the workplaceDo not deploy. Narrow medical and safety exceptions only — get counsel before touching them
The worker-rights decision map for a non-automotive manufacturing estate. 'Governance gate' is the minimum for defensible deployment, assuming a current register and published notices as the floor for everything.

Two features of this map do most of the governance work. First, the systems live at different levels of the plant stack — ISA-95 (opens in a new tab) level 3 for anything built on MES data, the HR and ERP layer for WFM and T&A, edge devices for vision and wearables — which means the data flows cross organisational boundaries, and the register must follow the data rather than the org chart. MESA's (opens in a new tab) operations-management vocabulary is useful here precisely because it names the systems a rights review has to walk through. Second, the same physical system can sit in two rows at once: a camera deployed for safety is also a productivity monitor the moment anyone opens its analytics on an individual. The gate therefore binds purpose, not hardware — which is why the purpose-limitation clause and the access rules matter more than the camera's specification sheet.

How hard to gate a worker-facing system

Plot any proposed system by what it decides and what it captures. The quadrant sets the assessment tier — and the top-right is where every contested case in this industry actually lives.

Consult and configure

  • Vision safety monitoring, wearables, biometric T&A
  • Gate: consultation, purpose limitation, retention, voluntariness
  • Dual-use risk is the watch item — bind purpose in contract

Gate hard — or redesign

  • Productivity scoring feeding discipline; biometric data tied to pay
  • Full HRIA, works agreement, named reviewer, drift monitoring
  • Emotion recognition sits beyond this quadrant: prohibited

Register and notice

  • Aggregate OEE dashboards, anonymised flow analytics
  • Lightest tier: register entry + published notice
  • Re-check on any vendor update that adds resolution

Human decision, algorithmic input

  • Scheduling from aggregate demand; screening shortlists
  • Gate: bias testing, human review, appeal route
  • The human must be able to disagree in practice, not just in the SOP
Data intrusiveness — top: Continuous, individual, biometric, bottom: Aggregate or anonymised
Consequence for the worker — left: Information and aggregate reporting, right: Pay, discipline and employment decisions

What public commitments look like in practice

Two manufacturers whose published human-rights and responsible-AI programmes can be read against the ladder. Neither is an Atomic Loops engagement — each links to the operator's own published material.

The clearest public evidence for the ladder is in what large manufacturers with mature human-rights programmes chose to build when AI arrived. In both cases below the pattern is the same: the companies did not invent AI ethics from scratch — they extended an existing due-diligence infrastructure to cover the AI estate, which is precisely the Declared-to-Embedded climb this page describes. Siemens publishes both its industrial AI approach (opens in a new tab) and its sustainability and human-rights reporting; Unilever's human-rights reporting has been public since 2015. Outcomes are as reported in the operators' own material; we have not independently audited them.

Two programmes read against the ladder

Images are illustrative generated scenes from this page's asset library, not operator photography. Outcomes as reported in the operators' own published material — verify against the linked sources before reusing figures.

Illustrative generated scene: a consumer-goods production hall of the kind Unilever's responsible-AI assurance process would governUnileverGlobal consumer goods manufacturer · foods, home and personal care24
Challenge
Scaling AI across manufacturing, supply chain and workforce-adjacent processes while holding a long-standing, public human-rights commitment — with the reputational exposure that any gap between the two would carry.
Approach
Unilever has publicly described a responsible-AI assurance approach under which proposed AI applications are reviewed against criteria including fairness, privacy and transparency before deployment — extending the salience-based due-diligence discipline of its human-rights programme, publicly reported since its standalone human-rights report in 2015, to the AI estate.
Reported outcome
As reported in Unilever's own published material: a structured pre-deployment review process for new AI use cases, operating alongside one of the longest-running public corporate human-rights reporting programmes in manufacturing.
What it shows about the curveA mature HRDD infrastructure makes AI governance an extension rather than a new build. Unilever's climb from commitment to embedded gate was fast precisely because salience mapping, assessment habits and reporting already existed — the AI estate was a new subject for an old discipline.

Unilever — human rights and responsible business reporting (opens in a new tab)

Illustrative generated scene: an electronics manufacturing line of the kind covered by Siemens' responsible-AI principles and co-determined governanceSiemensIndustrial technology group · electronics and digital-industries factories24
Challenge
Deploying industrial AI at scale — in its own electronics plants and in products sold to other manufacturers — inside the EU regulatory environment and under German co-determination, where worker representatives hold consent rights over monitoring-capable technical systems.
Approach
Company-wide responsible-AI principles embedded into the AI development and deployment lifecycle, with human-rights due diligence across its own operations and supply chain reported through its published sustainability reporting — and the consultation machinery of co-determination carrying worker voice into deployment decisions as standard practice.
Reported outcome
As reported in Siemens' own published material: company-wide principles governing responsible AI use, and human-rights due diligence reported annually across operations and the supply chain.
What it shows about the curveIn co-determined environments the consultation machinery already exists — the ladder climb is wiring the AI estate into it rather than building parallel structures. Works agreements become the codified form of deployment conditions, negotiated once per system class instead of disputed per install.

Siemens — sustainability and human-rights reporting (opens in a new tab)

The four dimensions that set your stage

Rights governance is not one number. Four dimensions gate each other, and the lowest is the real stage.

Rights governance is scored on four dimensions — estate visibility, due diligence and vendors, worker voice and transparency, and remedy and accountability — and the lowest of the four is the real stage, because each one gates the others. A rigorous assessment process over an incomplete register is due diligence on a fiction; a working appeal route nobody can find is remedy in name only. The structure deliberately parallels the govern–map–measure–manage discipline of NIST's AI Risk Management Framework (opens in a new tab), so teams already using the RMF can slot the rights dimensions into an existing programme rather than running a second one.

  • Estate visibility

    The register and the data-flow maps behind it. The binding question is whether you can name every system that captures individual-level worker data or feeds decisions about work — including the vendor features enabled since the last review. Until you can, every other dimension operates on a sample of the real exposure.

  • Due diligence and vendors

    The tiered gate and the contract clauses that make its conditions survive vendor updates. In a manufacturing estate that is mostly bought rather than built, vendor governance is the dimension — a perfect internal process with unbound vendors re-opens every condition at every release.

  • Worker voice and transparency

    Consultation timing and quality, plus what a worker can find out about the systems watching them. This is the dimension that predicts dispute risk, and it is overwhelmingly the cheapest to improve: notices and pre-signature consultation cost approximately nothing against the price of one works-council standstill.

  • Remedy and accountability

    The appeal routes, the grievance mechanism measured against the UNGPs' effectiveness criteria, and who answers for the estate's performance. This is the dimension auditors test hardest, because a working remedy loop is evidence the entire cycle operates under load — and its telemetry is what continuous improvement of the estate actually runs on.

The dimensions also sequence the work. Visibility before due diligence, because you cannot gate what you cannot list. Due diligence before voice only in the narrow sense that consultation needs something concrete to consult on — in practice they run together, and consultation routinely improves the assessment. Remedy last to build but first to prove: when an auditor, a customer or a works council wants one piece of evidence that the programme is real, the appeal log with outcomes is what settles the question.

The rights-governance operating layer, stage by stage

What actually has to exist at each rung of the ladder — five layers, each defined by what it must guarantee rather than by any product.

A defensible worker-facing AI estate needs five layers, and the order in which you build them determines whether the programme compounds or stalls. Nothing in the architecture below is a product recommendation; each layer is defined by the guarantee it must provide, and most of it can be assembled from systems a plant already runs — the register in the same asset-management discipline that tracks calibrated instruments, the gate inside the existing management-of-change process, the telemetry from access logs the IT estate already produces.

Layers required by stage

Each layer is annotated with the stage that first requires it. A programme attempting embedded controls without the register underneath is enforcing conditions on a sample of the real estate.

  1. Worker-facing AI register

    Stage 1+

    • System inventoryEvery system capturing individual worker data or feeding work decisions
    • Data-flow mapsWhat is captured, where it goes, who can see it
    • Vendor and feature trackerWhich monitoring capabilities each release enables
  2. Impact assessment layer

    Stage 3+

    • Salience mapWhich rights, for which worker groups, how severely
    • Tiered HRIA / DPIA templatesProportionate to consequence and intrusiveness
    • Conditions registerEvery assessment's binding output, in checkable form
  3. Worker voice layer

    Stage 3+

    • Consultation路径 forumsWorker representatives engaged before contract signature
    • Transparency noticesPer system: what is captured, what is decided, who to contact
    • Pilot feedback channelsStructured floor input during trials, with responses
  4. Deployment controls

    Stage 4+

    • Purpose-limitation configsVersioned, locked, drift-monitored
    • Vendor contract clausesPurpose, retention, audit rights, update review, exit
    • Human review pointsNamed reviewers on adverse decisions, logged
  5. Remedy & accountability

    Stage 4+

    • Appeal and grievance routesPer system, meeting the UNGP 31 effectiveness criteria
    • Remedy telemetryAppeal rates, overturn rates, themes — fed back to system owners
    • Disclosure and independent auditPublished estate and outcomes, externally checked (stage 5)

Pipeline described

  1. Worker-facing AI register (stage 1+) — System inventory: Every system capturing individual worker data or feeding work decisions; Data-flow maps: What is captured, where it goes, who can see it; Vendor and feature tracker: Which monitoring capabilities each release enables
  2. Impact assessment layer (stage 3+) — Salience map: Which rights, for which worker groups, how severely; Tiered HRIA / DPIA templates: Proportionate to consequence and intrusiveness; Conditions register: Every assessment's binding output, in checkable form
  3. Worker voice layer (stage 3+) — Consultation路径 forums: Worker representatives engaged before contract signature; Transparency notices: Per system: what is captured, what is decided, who to contact; Pilot feedback channels: Structured floor input during trials, with responses
  4. Deployment controls (stage 4+) — Purpose-limitation configs: Versioned, locked, drift-monitored; Vendor contract clauses: Purpose, retention, audit rights, update review, exit; Human review points: Named reviewers on adverse decisions, logged
  5. Remedy & accountability (stage 4+) — Appeal and grievance routes: Per system, meeting the UNGP 31 effectiveness criteria; Remedy telemetry: Appeal rates, overturn rates, themes — fed back to system owners; Disclosure and independent audit: Published estate and outcomes, externally checked (stage 5)
Step-by-step insights
The register — follow the data, not the org chart
The register fails when it is built from the project portfolio, because most of the worker-facing estate never was a project. Build it from three sources triangulated: a floor walk-down (what screens and cameras exist), the vendor contract review (what capabilities are licensed), and the IT access audit (who can see individual-level data today). The three lists never match, and the deltas are the register's most valuable entries — they are the systems running outside anyone's mental model of the estate.
Assessment layer — salience is the sorting rule
The layer's core artefact is not the HRIA template but the salience map: which rights are most severely at stake, for which groups, through which systems. Salience is what lets a plant run a proportionate gate — full assessment with consultation for the productivity-scoring rollout, a register entry and notice for the anonymised flow counter — without either drowning in paperwork or waving the dangerous cases through. Revisit it when the estate changes shape, not on a calendar.
Worker voice — the layer that pays for itself first
Notices and pre-signature consultation are the cheapest components in the whole architecture and the fastest to show a return. Consultation catches design errors while they are configuration choices rather than installed facts; notices pre-empt the discovery dynamic — a workforce that learns about a system from a notice trusts the next system more, and one that learns from the floor trusts nothing afterwards. Where works councils exist this layer is also a legal requirement with an injunction behind it; treat that as a floor, not the target.
Deployment controls — conditions must live in three places
Every assessment condition needs a home in configuration (the retention setting, locked and versioned), in contract (the clause that survives the vendor's platform migration) or in telemetry (the alert when an access pattern breaks the rules). A condition living only in the assessment document is a stage-3 condition: true at go-live, unverifiable afterwards. The discipline is mechanical — walk the conditions register quarterly and name the enforcing control for each line; any line without one is drift waiting to be discovered by someone else.
Remedy — the loop that makes the estate self-correcting
Built properly, remedy is not a complaints desk bolted onto the estate; it is the estate's error-reporting channel. Appeals surface mis-attributed events, mis-weighted metrics and mis-configured zones that no amount of pre-deployment testing finds, because they only appear under real production variation. Route every upheld appeal to the system owner as a defect, aggregate the themes quarterly, and publish the statistics — the same log then serves workers, engineers and auditors, which is the architecture working as one system rather than three.

The layer most often skipped is the vendor and feature tracker inside the register, and it is the one that determines whether the whole structure stays true. A manufacturing estate is mostly bought: the analytics that create tomorrow's exposure will arrive in a release note, not a project proposal. A one-line process — vendor release notes are reviewed against the register before updates are applied — is the cheapest control in this architecture and the one that catches function creep before it reaches the floor.

A 90-day plan: gating a vision-monitoring rollout

The Declared-to-Assessed transition made concrete on one common manufacturing problem — camera-based PPE and exclusion-zone monitoring across a 14-line packaging hall. Contains no model development.

Moving one rung takes about 90 days when it is scoped to a single deployment, and multiple years when it is scoped to a policy programme. To make that concrete, the plan below runs the transition on a specific, common problem: a packaging hall wants camera-based PPE and exclusion-zone monitoring across its 14 lines — a genuine safety benefit carrying a genuine rights exposure, and exactly the dual-use case that goes wrong when it ships ungoverned. The vendor system already exists; the quarter contains governance work only.

Declared → Assessed on one vision deployment, in one quarter

One hall, one deployment, one owner. If any phase needs more than its window, narrow the scope — fewer lines, fewer capabilities — rather than extending the plan.

  1. Days 1–15

    Inventory the hall and map the salience

    Register the hall's existing and proposed worker-facing systems — current cameras, the proposed analytics, the WFM and T&A estate they will sit alongside. Map the data flows: what the analytics captures, at what resolution, retained where, visible to whom. Draft the salience map: privacy and chilling-effect exposure against the OSH benefit, by worker group including agency staff. Name the plant HR–operations pair as joint owners.

    Register entries, data-flow map, salience draft, named owners

  2. Days 16–40

    Assess, consult, and bind the conditions

    Run the tiered assessment — HRIA with the DPIA nested inside it. Consult worker representatives before contract signature, presenting the genuinely configurable scope: zones covered, event-based versus continuous capture, aggregation level, retention. Convert the agreed position into vendor contract clauses and a configuration specification: PPE and exclusion-zone events only, no idle-time analytics, 72-hour retention, no individual dashboards, update review before any feature activation.

    Signed consultation record and a conditioned contract

  3. Days 41–70

    Pilot two lines with the loop live

    Go live on lines 1–2 only. Transparency notices at the lines and in onboarding: what is captured, what is decided, who to contact. Appeal route live from day one with a named reviewer. Weekly configuration check against the conditions spec; access log reviewed for who viewed what. Structured floor feedback in weeks two and four, with responses published to the hall.

    A governed pilot: zero unreviewed accesses, feedback answered

  4. Days 71–90

    Review, attribute, decide

    Review the safety delta — PPE-compliance and near-miss events against the hall's baseline — honestly separated from the Hawthorne bump. Review the appeal log, access audit and feedback themes with worker representatives in the same session. Document the scale, adjust or stop decision with its evidence, and publish the decision record internally. If scaling: the remaining 12 lines inherit the conditions spec, not a new negotiation.

    A documented, consulted scale-up decision with evidence

The order matters

  1. Consultation before signature

    Consulted after the contract is signed, worker representatives can only accept or obstruct; consulted before, they shape zone coverage and retention while the vendor still has an incentive to configure flexibly. This single sequencing choice removes most of the dispute risk and all of the 'announcement dressed as consultation' pattern — and in co-determined plants it is the difference between a works agreement and an injunction.

  2. Conditions as configuration, not memos

    Every condition agreed in phase 2 must exist as a locked configuration, a contract clause or a telemetry alert before go-live in phase 3. A condition that lives only in the assessment document is true for exactly as long as nobody updates the platform. The weekly config check in the pilot is the habit that carries into production.

  3. Attribute the safety benefit honestly

    The system was justified on safety, so the review must measure safety — PPE compliance and near-miss events against baseline — and resist laundering surveillance value into the case. If the safety benefit does not survive honest attribution, the system shrinks or stops; holding that line once is what makes every future consultation in the plant credible.

Instrumenting rights governance: metrics and the deployment gate

Where each governance metric actually comes from — formula, source system, cadence — and the checklist a deployment must clear before go-live.

A governance claim you cannot name a source system for is an opinion. Every metric below reduces to counts and timestamps that the register, the assessment log, the grievance system or the IT access logs already record — the instrumentation work is joining them, not creating them. 'Honest from' is the ladder stage at which the metric first measures something real: an appeal rate means nothing before appeal routes exist, and disclosure currency only exists once there is a disclosure.

MetricFormula / readSourceCadenceHonest from
Register coverageSystems registered ÷ systems found in walk-downs and contract reviewRegister + procurement auditQuarterlyStage 1
Assessment coverageLive worker-facing deployments with an in-date assessment ÷ all liveRegister + assessment logMonthlyStage 3
Consultation lead timeDays between worker-rep briefing and contract signature (negative = briefed after)Project recordsPer deploymentStage 3
Condition driftAssessment conditions verified in configuration ÷ conditions writtenConfig audits + vendor attestationsMonthlyStage 4
Appeal and overturn rateAppeals ÷ algorithmic decisions; overturned ÷ appealsAppeal logMonthlyStage 4
Grievance closure timeMedian days from AI-related grievance to closed remedyGrievance systemQuarterlyStage 4
Access exceptionsViews of individual-level monitoring data outside approved rolesSystem access logsWeeklyStage 4
Disclosure currencyDays since the published estate disclosure last matched the registerRegister + published reportAnnualStage 5
Instrumentation build sheet for worker-rights governance in a manufacturing estate. Every metric is readable from systems the plant already runs.

Two of these deserve standing attention. Consultation lead time is the strongest leading indicator on the sheet — it predicts dispute risk before any dispute exists, and a drift toward zero or negative numbers means the gate is being bypassed under schedule pressure. Access exceptions is the metric that catches function creep in the act: the safety camera's individual-level data being viewed from a supervisor role that was never approved is exactly how a compliant deployment becomes a contested one, and the access log records it in real time if anyone is reading.

The deployment-gate checklist

Before any worker-facing AI system goes live. If you cannot tick all six, the deployment is not gated — whatever the policy says. Tick as you go; this list works without JavaScript.

0 of 6 ticked

Tick honestly — the blank list is data too

Zero ticks does not mean zero systems; it means the estate is running ungated. Don't start with policy: pick the single most contested system — usually the cameras or the scoring — and run the 90-day plan above on it. Every item on this list falls out of doing that once.

Failure modes that quietly undo the programme

Rights governance regresses silently — the systems keep running and the documents keep existing. Four failure modes account for most of it.

Governance regression is silent by definition: the cameras keep watching, the optimiser keeps scheduling, and the assessments keep sitting in their repository while the conditions they set quietly stop being true. Four failure modes account for almost all of the ground manufacturers lose, and each has a cheap preventive measure that is easier to install than to retrofit after the incident.

Likelihood: highImpact: high

Function creep — the safety system becomes a discipline system

Data collected for one accepted purpose drifts into another: the PPE camera's footage appears in a performance conversation, the fatigue wearable's data reaches a shift-allocation decision. Each individual step feels reasonable to whoever takes it, and the accumulated drift converts a consulted, conditioned deployment into exactly the surveillance the consultation promised it was not.

PreventionPurpose limitation bound in contract and configuration, role-based access to individual-level data, and access-log review — the creep is visible in the logs long before it is visible in a grievance.

Likelihood: highImpact: medium

Consultation collapses into announcement

Under schedule pressure, the pre-signature consultation slides to a pilot-stage briefing, then to a rollout announcement. Each slide feels minor; collectively they convert the strongest trust instrument the programme has into evidence against it — and where co-determination applies, they convert a negotiable deployment into an enforceable standstill.

PreventionTrack consultation lead time as a standing metric with a floor; a deployment that cannot show positive lead time does not pass the gate.

Likelihood: highImpact: high

The vendor update nobody reviewed

A platform migration resets retention to default, a release enables new analytics across every site at once, a licence-tier change activates individual dashboards. The estate's rights posture is now set by the vendor's roadmap rather than the company's assessments, and the divergence is discovered by an auditor or a works council rather than by the owner.

PreventionRelease notes reviewed against the register before updates are applied, plus contract clauses requiring notification of monitoring-relevant changes — one line in the update procedure.

Likelihood: mediumImpact: medium

The remedy route exists and nobody uses it

An appeal route with zero volume is usually not evidence of a perfect estate — it is evidence workers do not know the route, do not trust it, or fear using it. The programme reads the silence as success while the actual feedback accumulates as disengagement, quiet non-compliance and eventually an external complaint that bypasses the mechanism entirely.

PreventionTreat near-zero appeal volume as an alarm, not a KPI win: check awareness on the floor, publish outcomes of the appeals that do run, and test the route yourself annually.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

Worker-facing AI
Any system that captures individual-level data about workers or feeds decisions about work allocation, evaluation, discipline or employment — whether bought or built, and whether or not anyone calls it AI. The register's inclusion rule.
Salient human rights
The rights at risk of the most severe negative impact through a company's activities — the UNGP-derived prioritisation rule that decides which systems get the full assessment and which get a register entry and notice.
Algorithmic management
The use of algorithmic systems to allocate, direct, monitor or evaluate work — in manufacturing, typically shift scheduling, task allocation and performance scoring built on WFM and MES data.
HRIA
Human-rights impact assessment: a structured pre-deployment review of a system's effects on the rights of the people it touches, producing binding deployment conditions. Wider than a DPIA, which covers data protection specifically.
FRIA
Fundamental-rights impact assessment under Article 27 of the EU AI Act. Legally required only of certain deployers — public bodies and some financial-services cases — but the template is freely borrowable, and manufacturers increasingly run FRIA-style assessments voluntarily as their HRIA format.
Chilling effect
Behaviour change caused by the awareness of being monitored rather than by any use of the data — workers avoiding the union noticeboard in camera view, or under-reporting near-misses to keep metrics clean. A rights impact that occurs even if the data is never misused.
Co-determination
Statutory worker-participation rights in corporate decisions, strongest in Germany, where works councils hold consent rights over technical systems capable of monitoring performance or behaviour — which covers most of the worker-facing AI estate.
Operational-level grievance mechanism
A company-run channel through which affected people can raise and resolve concerns. UNGP Principle 31 sets eight effectiveness criteria, including legitimacy, accessibility, predictability and being a source of continuous learning.
Function creep
The gradual repurposing of data or a system beyond the purpose it was assessed and accepted for — the safety camera drifting into productivity monitoring. The most common way a compliant deployment becomes a contested one.
Purpose limitation
The rule that data is collected for a stated purpose and not reused beyond it. In a worker-facing estate it must live in three places at once: the vendor contract, the system configuration, and the access rules.
Deployment conditions
The binding output of an assessment — retention limits, aggregation levels, access restrictions, review points — that a system must satisfy to go live and keep satisfying in operation. Conditions without an enforcing control are stage-3 paper.

Frequently asked questions

The questions manufacturers ask most often when they start governing the worker-facing AI estate.

What is AI human rights governance in manufacturing?

It is the application of human-rights due diligence — inventory, impact assessment, worker consultation and remedy — to the AI systems that watch, score or schedule factory workers. In practice it means a register of worker-facing systems, a tiered assessment gate before deployment, consultation before contracts are signed, binding conditions on purpose and retention, and a working appeal route. The framework comes from the UN Guiding Principles; the enforcement increasingly comes from the EU AI Act, the GDPR and supply-chain due-diligence laws.

Which AI systems on a factory floor affect worker rights?

Seven classes cover nearly all of the exposure: algorithmic shift scheduling, productivity scoring built on MES and OEE data, vision-based safety monitoring, biometric access and time-and-attendance, wearables and fatigue monitoring, hiring and screening algorithms, and emotion recognition — the last of which is prohibited in workplaces under the EU AI Act. The common thread is individual-level data or decisions about work; a system needs only one of the two to belong on the register.

Is workplace emotion recognition really banned in the EU?

Yes. Article 5 of the EU AI Act prohibits AI systems that infer emotions in the workplace, with narrow exceptions for medical and safety purposes, and the prohibition has applied since February 2025. It sits in the Act's most severe penalty band — up to €35 million or 7% of global annual turnover. Sentiment-analysis features bundled into workforce or camera-analytics products are the practical trap: a vendor module can put a manufacturer in prohibited territory through a feature activation nobody reviewed.

What does the EU AI Act classify workplace AI as?

AI used in employment and worker management is a named high-risk category under Annex III — covering recruitment, task allocation, and monitoring or evaluating performance and behaviour. High-risk classification brings obligations for providers and deployers, including risk management, human oversight, logging and, for employers specifically, the Article 26(7) duty to inform workers and their representatives before putting such a system into service. The bulk of these obligations applies from August 2026.

What is the difference between a DPIA and an HRIA?

A DPIA assesses risks to personal data under the GDPR — lawful basis, minimisation, retention, security. An HRIA assesses impacts on the full span of rights: non-discrimination in a scoring system, chilling effects of camera coverage, freedom of association, due process in discipline. A vision system can pass a DPIA on clean data-handling and still fail an HRIA on its chilling effect. In practice manufacturers nest the DPIA inside the HRIA for high-tier systems, so one gate produces both artefacts.

Do the UN Guiding Principles legally bind a manufacturer?

Not directly — the UNGPs are soft law, endorsed by the UN Human Rights Council in 2011 but not themselves enforceable. Their content, however, is being hardened into binding law: the EU's CSDDD writes UNGP-style due-diligence duties into statute for large companies, national laws such as Germany's supply-chain act already impose similar duties, and customer contracts cascade the expectations to suppliers of every size. Building the discipline now on the UNGP structure means the binding versions arrive as reporting exercises rather than programmes.

How is this different from ISO/IEC 42001?

ISO/IEC 42001 specifies the management system — the machinery of policies, roles, controls and audits an organisation runs around its AI. Rights governance defines part of what that machinery must protect: which systems touch workers, which rights are at stake, what consultation and remedy must exist. The two compose naturally — the register, gate and remedy loop described here slot into a 42001 management system as its worker-facing content. The companion ISO/IEC 42001 guide in this knowledge base covers the management-system side in depth.

Do works councils have a veto over AI monitoring in Germany?

Effectively yes, for monitoring-capable systems. Under the Works Constitution Act, technical systems capable of monitoring employee performance or behaviour require works-council consent — and capability is enough, whether or not monitoring is the intent. That covers most camera analytics, scoring and workforce systems. The practical consequence is that consultation before contract signature is not just good practice in German plants; it is the difference between a negotiated works agreement and an enforceable standstill discovered mid-rollout.

Does PPE detection violate workers' privacy?

Not inherently — it depends on configuration and discipline. A defensible deployment captures events rather than continuous footage, reports compliance at line or crew level, retains data briefly, restricts individual-level access to defined safety roles, and binds the purpose in the vendor contract so the analytics cannot drift into productivity monitoring. The same hardware configured for continuous individual tracking with open supervisor access is a different system with a different answer. The assessment's job is to hold the deployment on the right side of that line.

How do you consult workers without stalling every deployment?

By tiering and by timing. Tiering keeps consultation proportionate: aggregate, anonymised systems need a notice, not a negotiation; the full consultation is reserved for systems that decide pay, discipline or employment, or capture intrusive data. Timing makes consultation cheap: engaged before contract signature, worker representatives shape configurable scope in days; engaged after rollout, the same conversation becomes a dispute over installed facts. Manufacturers who run the gate report that consultation adds a fortnight and removes the standstill risk that used to cost quarters.

What makes a grievance mechanism for algorithmic decisions effective?

UNGP Principle 31 sets the criteria: legitimate, accessible, predictable, equitable, transparent, rights-compatible, a source of continuous learning, and based on engagement. For algorithmic decisions the practical tests are: workers know the route exists, appeals reach a named human who can access the event data and can actually overturn the decision, outcomes are explained, and upheld appeals feed system changes — a mis-attributed micro-stop should fix the configuration, not just the individual record. Near-zero appeal volume is usually an awareness failure, not evidence of a perfect estate.

Where should a manufacturer start if nothing exists yet?

With the register, not the policy. One afternoon per site: walk the floor, read the vendor contracts, ask supervisors what they can see about individual operators, and list every system that captures worker data or feeds work decisions. The register makes the exposure concrete, which makes the rest sequenceable — the salience map says which systems matter most, the tiered gate covers new deployments, and the first HRIA on the most contested system builds the artefacts everything else reuses. Policy written after the register can name what it governs.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for manufacturing, logistics and energy operators — vision inspection, scheduling, forecasting and decision support integrated into the MES and planning layer rather than delivered as dashboards. Deployment gates, worker consultation artefacts and audit trails are part of the build, not an afterthought.

  • · Production AI deployed into MES, WFM and quality systems at operating plants
  • · Deployment-gate and governance reviews run jointly with plant HR, IT and worker representatives
  • · Audit-trail-first delivery: every automated decision reconstructable months later
  • · 13 cited sources on this page

Sources

  1. UN OHCHRBusiness and human rights — the UN Guiding Principles (opens in a new tab)
  2. International Labour OrganizationInternational labour standards (opens in a new tab)
  3. European CommissionAI regulatory framework (EU AI Act) (opens in a new tab)
  4. Future of Life InstituteAI Act Explorer (opens in a new tab)
  5. NISTAI Risk Management Framework (opens in a new tab)
  6. World Economic ForumGlobal Lighthouse Network (opens in a new tab)
  7. acatechHuman-centred Industrie 4.0 research (opens in a new tab)
  8. MESA InternationalManufacturing operations management resources (opens in a new tab)
  9. International Society of AutomationAutomation standards (ISA-95) (opens in a new tab)
  10. McKinsey & CompanyThe state of AI (opens in a new tab)
  11. UnileverHuman rights and responsible business reporting (opens in a new tab)
  12. SiemensSustainability and human-rights reporting (opens in a new tab)
  13. SiemensArtificial intelligence at Siemens (opens in a new tab)

Know exactly what your estate is doing — and be able to prove it

We run the assessment with your operations, HR and IT leads, benchmark the result against manufacturers of similar estate shape, and leave you with a costed 90-day plan for your weakest dimension — usually the register or the gate. You keep the plan whether or not we build it.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.