When planning an autonomous factory implementation, the first question should not be “How many people can we remove?” The first decisions are which judgments machines and AI may make, when human approval is mandatory, who may stop production, and who may authorize recovery. An autonomous factory is not a plan to eliminate people. It is a plan to define, in advance, where people must intervene. This guide gives manufacturing owners in Thailand and ASEAN a practical path from a 90-day proof of concept to an RFP, FAT/SAT, cybersecurity responsibilities, and operational handover.
An autonomous factory is managed autonomy, not a people-free factory
The popular image of an autonomous factory is a dark building in which robots run for 24 hours without supervision. Real production is different. Material variation, changeovers, gauge drift, worn tooling, communication loss, operator access, revised customer specifications, and quality holds create exceptions every day. It is rarely practical to program every exception in advance, and it is not responsible to give an AI model unlimited authority over production equipment.
A useful working definition is: a factory in which equipment, control systems, and software can perceive conditions and make adjustments inside a defined operating domain, then degrade or stop safely and hand the right information and authority to people when conditions leave that domain. This definition creates value without waiting for complete unmanned operation. The system may recalculate dispatch sequences, raise maintenance requests, or recommend increased inspection while recipe limits, interlock bypasses, and final release remain under human approval.
Rockwell Automation’s article on AI-driven autonomous factories and Siemens’ Industrial AI article, both published on 18 September 2026, describe a direction in which connected equipment data and AI support manufacturing decisions. FANUC America’s IMTS 2026 announcement also highlights robotics, CNC, automation, and physical AI. These are vendor perspectives and product announcements. They are not proof that every factory will achieve the same outcome. Each investment must be judged against the site’s baseline and agreed acceptance evidence.
Three questions that separate automation from autonomy
- When conditions change, who or what selects the next action?
- Where does authority to execute that action reside?
- If execution fails, to which state does the process return, and who approves restart?
Automation follows a predetermined sequence under predetermined conditions. Autonomy selects among allowed actions according to current conditions. Without explicit options, constraints, stop conditions, and approvers, however, autonomy becomes loss of control. Replace the sentence “AI will optimize production” with a specification of decision target, inputs, outputs, prohibited operations, monitoring interval, timeout, and fallback.
Assess factory automation maturity in five stages
An autonomous factory roadmap should be assessed by the scope of closed-loop decisions and its ability to handle exceptions, not by the number of machines or AI models. The following five-stage model is a practical alignment tool, not a certification scheme.
| Stage | Operating characteristic | Human role | Gate to the next stage |
|---|---|---|---|
| 0 — Before visibility | Paper, stand-alone panels, manual reports | Experienced people reconstruct conditions and decide | Define signals, asset IDs, and stop reasons |
| 1 — Visibility | Shared view of production, quality, and energy | Detect an issue and issue a manual instruction | Time sync, missing-data monitoring, data ownership |
| 2 — Recommendation | Rules or AI suggest causes and next actions | Approve or reject a recommendation | Classify the consequence of a wrong action |
| 3 — Bounded autonomy | Sequence, speed, or allocation changes inside limits | Supervise, handle exceptions, approve restart | Test stop authority, degraded mode, and recovery |
| 4 — Coordinated autonomy | Multiple processes share constraints and replan | Own goals, constraints, and change control | Site-wide governance and recurring audit |
Skipping a stage usually exposes a data or accountability problem rather than an AI problem. If MES and maintenance use different asset names, PLC and server clocks disagree, defect causes are free text, or recovery actions leave no record, even an advanced model is difficult to validate. Start with a factory automation diagnosis and place investments on a phased factory automation roadmap so that a PoC does not become an isolated demonstration.
Do not hide weak interfaces behind an average maturity score
Machining may be at stage 3 while inspection is at stage 1 and material feeding at stage 0. A site average hides the weak interfaces. Assess the end-to-end value stream, then inspect equipment, conveyance, inspection, maintenance, and planning handoffs separately. Ask what downstream equipment does when an upstream unit stops, how quickly a quality hold blocks a transport order, and whether a cell can operate locally during communication loss.
The maturity result is not a score used to justify a purchase. It is a map of the next boundary to test. A low stage is not a failure; an unclear and untestable boundary is.
Define stop authority before connecting AI, PLCs, and enterprise systems
One of the most important design artifacts for an AI-enabled autonomous factory is a stop-authority matrix. It states not only who can stop but why, what scope is stopped, and into which condition. A safety stop, quality hold, equipment-protection stop, and schedule stop serve different purposes. Treating every event as the same “STOP” encourages either unnecessary plant-wide shutdowns or unsafe continuation.
| Event | Automatic action allowed | Human approval required | Evidence to retain |
|---|---|---|---|
| Safety input activated | Move the affected cell to its validated safe state | Restart, bypass, or operation with unresolved cause | Input, timestamp, state transition, approver |
| Quality trend outside limit | Hold the lot and request added inspection | Release, off-spec operation, rule change | Measurements, model version, lot, rationale |
| Equipment degradation | Reduce speed inside an approved range and notify maintenance | Raise limits, defer a stop, restart after repair | Sensor values, thresholds, work history |
| Communication loss or missing data | Enter local degraded control and block new remote commands | Resynchronization and restart | Missing interval, held commands, sync result |
| Schedule change | Resequence unstarted jobs within constraints | Override customer priority or quality holds | Old/new plan, constraint, approval ID |
Safety PLCs and emergency-stop functions must not be replaced by a supervisory AI. AI can identify a precursor or propose a bounded adjustment, while safety functions retain the independence, determinism, and verification required by the applicable risk assessment and standards. ISO 10218-2:2025 covers safety requirements for industrial robot applications and cells, but it does not certify an entire autonomous factory. Other machinery, conveyance, electrical or chemical hazards, work procedures, Thai law, and customer rules still require specific assessment.

Use ISA-95 to draw the boundary between data and executable commands
ISA-95 provides models, terminology, and interfaces for integrating enterprise and manufacturing-control activities. In an autonomous factory project, use it to ask when information from one level is allowed to become an executable instruction at another.
An ERP due-date change should not directly rewrite a PLC speed. Enterprise demand passes to MES/MOM as a production request. MES/MOM checks equipment capability, quality holds, material status, and safety constraints, then issues an approved dispatch or recipe reference to control. In the opposite direction, raw values should become contextualized events or results with timestamp, unit, quality flag, and asset ID.
Every boundary needs, at minimum:
- the data owner and system of record;
- read, propose, approve, and write permissions;
- command expiry, idempotency ID, and retry behavior;
- values retained and commands discarded during loss of communication;
- allowed ranges and unit conversion;
- change history, model version, and operator identity;
- rollback conditions and procedure.
This turns manufacturing AI automation from a “collect all data” exercise into a controlled closed loop. ISA-95 alignment is valuable, but does not by itself satisfy machinery safety or cybersecurity requirements.
Engineer exception recovery from NORMAL to RECOVERY
Testing only a normal production demonstration is a poor measure of autonomy. A PoC should deliberately create exceptions: missing material, an unreadable barcode, a stuck sensor, failed robot grasp, slow MES response, low model confidence, and duplicate commands. The aim is to verify that equipment enters a predictable state.

NORMAL — automatic operation inside the validated domain
Signals are available and the process remains inside safety, quality, and equipment constraints. NORMAL is more than “no alarm.” Material identity, recipe match, calibration validity, communication health, and approved model version are part of the run permission.
DEGRADED — continue with bounded capability
One function is unavailable, but the process can continue at a risk-assessed speed, product mix, route, or decision mode. If vision AI is unavailable, automatic reject logic may be disabled and every item routed to human inspection. If planning is disconnected, only a short approved queue may run. Specify both the degraded scope and maximum duration.
SAFE STOP — stop while controlling energy and work in process
The process moves to a state that does not increase risk and supports recovery. The final state is process-specific. A furnace or chemical process may not be safe after a simple power cut. A robot cell must account for held workpieces and peripheral axes. Define the end condition and residual risks, not merely the label “safe stop.”
RECOVERY — inspect, synchronize, prove, and restart
Do not return to full automatic operation immediately after removing the initiating cause. Check work in process, incomplete transactions, MES/PLC counters, quality holds, and input freshness. Require a dry cycle or first-piece verification where appropriate, record the restart approver, and retain evidence that the system returned to NORMAL.
The transition table must state initiation conditions, permitted actions, prohibited actions, timeout, notification, and return criteria. Production, maintenance, quality, EHS, IT/OT, and shift supervision should approve it together. For periods without operators at the line, combine this design with our night unattended operation guide to define alarm escalation, response time, remote-control limits, and recovery that requires physical inspection.
What to put in an autonomous factory RFP
An RFP that says only “use AI for autonomy” or “build a dashboard” will produce incomparable proposals. Interfaces, logs, maintenance, and training then appear as variations or extra cost. Write operating boundaries and accountability before listing features.
1. Included process and explicit exclusions
List products, assets, operating modes, shifts, materials, and connected systems. Define start and end points using asset tags, transfer positions, and data handshakes. State what the PoC does not cover.
2. Decision use cases
For every use case state inputs, decision cycle, outputs, allowed range, prohibited operation, and human-approval condition. Separate a wrong recommendation from a wrong execution. A person can reject a recommendation; an automated write needs an engineered guard.
3. Non-functional requirements
Specify response time, availability, recovery objective, clock synchronization, retention, audit logging, backup, language, terminals, and network bandwidth. Derive figures from the process’s tolerable delay and stoppage rather than copying a vendor default.
4. Safety, quality, and cybersecurity
Require risk assessment, interlocks, change control, access control, vulnerability handling, remote-maintenance governance, restoration, and revalidation after replacement. IEC 62443-2-4:2023 addresses security-program requirements for IACS integration and maintenance service providers. It is a useful reference when examining a supplier’s maintenance process, not a substitute for site-wide controls.
5. AI lifecycle conditions
Define training-data rights, data location, model version, update procedure, performance-degradation monitoring, explanatory information, manual fallback, and stop conditions. The NIST AI RMF is a voluntary framework whose Govern, Map, Measure, and Manage functions provide a useful checklist. It does not replace applicable law or safety certification.
6. Deliverables and handover
List editable backups, I/O lists, network drawings, state-transition tables, alarm lists, user roles, test records, training materials, spares, licences, and escalation contacts. State the editable format and the party who receives administrative access.
7. Responsibility matrix
Allocate work among the factory, machine builder, system integrator, AI supplier, IT operations, and telecom provider. Explicitly assign revalidation after a model update, consistency after PLC changes, security patches, remote-access approval, and first response to night incidents.
Turn FAT and SAT into acceptance gates
Factory Acceptance Test and Site Acceptance Test are decision gates, not ceremonies for ticking boxes. FAT tests logic, interfaces, fault injection, logging, and backup restoration at the supplier. SAT uses real equipment, network, material, operators, and shift conditions to expose site-specific behavior.
| Gate | Main verification | Acceptance evidence | If the gate fails |
|---|---|---|---|
| Design review | Boundaries, states, authority, risks, I/O | Approved specification and responsibility matrix | Hold implementation |
| FAT | Normal/fault scenarios, simulated I/O, logs, recovery | Results, screens/logs, issue list | Conditional shipment or retest |
| Installation | Wiring, tags, clocks, network, backup | As-built documents and deviation record | Hold SAT |
| SAT | Real material, speed, work instruction, degradation, recovery | Signed results and training record | Restricted run or correction |
| Operational acceptance | Stability period, maintenance handover, KPI definition | Run records and handover package | Do not expand autonomous scope |
Do not compress acceptance into one figure such as “95% AI accuracy.” Define the population, cost of false positive and false negative, low-confidence behavior, workload sent to people, and time to stop. Target values come from the process baseline and risk, not from an unrelated case study.
A 90-day PoC validates the operating model, not just the technology
Ninety days is a planning example, not a performance promise. It is long enough in some projects to complete design, connection, testing, and handover once. Machinery modification or certification may require more time; a read-only recommendation use case may require less.

Days 1–15: Confirm boundary and baseline
- Limit SKUs, equipment, shifts, and operating modes.
- Confirm existing stop categories, quality decisions, and recovery measurement.
- Put decision use cases and prohibited operations on one page.
- Name reviewers for safety, quality, cyber, privacy, and contract issues.
- Agree success and termination conditions.
Do not promise an improvement percentage in this phase. Align data definitions and measurement. Record missing data and inconsistent labels as PoC findings.
Days 16–35: Build data and control connections
Align tags, clocks, quality flags, asset IDs, and user access. Validate quality with read-only access first, then add recommendations, and only then consider bounded writes. Remove development access before production and record approval for every remote session.
Days 36–55: Implement scenarios and run FAT
Inject communication loss, sensor faults, wrong material, low confidence, duplicate commands, and slow upstream responses. Confirm transitions among NORMAL, DEGRADED, SAFE STOP, and RECOVERY and check that alerts and logs agree. Delay site deployment when a critical issue remains unresolved.
Days 56–75: Site SAT and restricted operation
Run with real material and operators. Validate Thai and English terminology, shift handover, maintenance callout, and network behavior. Train operators not only to use the system but also to reject AI advice, restore manual control, and report the evidence needed for diagnosis.
Days 76–90: Evaluate, hand over, and decide the next gate
Compare results using the agreed method and separate achieved, not achieved, and not measurable. “Not measurable” is not success; correct the measurement design. The owner decides whether to continue, reduce scope, hold, or stop.
A useful PoC can end without production rollout
Discovering an unsafe boundary or an unfit dataset and deciding not to deploy is a valid result. Agreeing failure conditions in advance lets operators expose difficult exceptions instead of hiding them. Separate evaluation of supplier performance from the capital decision. The purpose of a PoC is evidence for the next decision, not a polished demonstration.
Implementation in Thailand: people, maintenance, and BOI
Thai and ASEAN plants often combine multinational management, Thai-speaking operations, overseas OEMs, and local system integrators. Translating responsibilities matters as much as translating screens. If alarm procedures, training, escalation, or change approval exist in only one language, night-shift recovery will fail. Maintain a shared glossary and map Thai, English, and Japanese terms to the same state and event code.
A maintenance contract must define who may see and change what, not merely response time. Avoid a situation in which the machine supplier sees the PLC, the AI vendor sees the model, and IT sees the server, but no party can reconstruct the event end to end. Use shared event IDs, synchronized clocks, and change tickets. Refer to IEC 62443-2-4:2023 when assessing how an IACS service provider handles personnel, access, configuration, and incidents.
Thailand BOI’s current Smart and Sustainable Industry information, as cited for this article, describes a minimum investment of THB 1 million. It describes a three-year corporate income tax exemption normally capped at 50% of qualifying investment, with a cap of 100% where eligible machinery/equipment connected with Thailand’s automation industry accounts for at least 30% of total value. Eligibility depends on activity, cost classification, improvement scope, application timing, and sourcing. The incentive is not automatic; confirm each project directly with BOI or a qualified adviser. Keep the technical scope and incentive-application scope under separate control.
Manufacturing AI automation KPIs: outcome, risk, and learning
Productivity alone creates pressure to avoid safe stops and quality holds. Balance three groups of measures.
| KPI group | Examples | Interpretation caution |
|---|---|---|
| Outcome | Schedule attainment, good-unit lead time, changeover time | Normalize for mix and demand |
| Quality | Holds, escapes, reinspections, decision agreement | Separate AI judgment from final release |
| Availability | Stop duration, degraded time, successful recovery | Separate planned stops from failures |
| Safety/control | Interlock events, prohibited-operation attempts, unapproved changes | Zero reports may indicate poor reporting culture |
| AI operations | Low confidence, rejection reason, model version, missing data | Measure out-of-domain rate, not accuracy alone |
| Human capability | Recovery drills, handover completion, time to manual control | Do not turn this into a headcount-reduction metric |
Every KPI needs an owner, formula, source, frequency, and exclusion rule. If the baseline was not measured before the PoC, do not claim an improvement. Treat measurement capability as the first deliverable and establish a separate evaluation period.
Common failure patterns and countermeasures
Starting with the model and postponing authority design
A model can perform well in a demo but remain unused because no one knows what happens after a wrong recommendation. Design propose, approve, execute, stop, and recover authority first.
Training and testing only on normal data
Production brings missing signals, replaced parts, new SKUs, contamination, and lighting changes. Include fault injection and out-of-domain data in FAT and SAT.
Turning a PoC connection into a production connection
Shared accounts, fixed passwords, open ports, and manual CSV files remain. Add authentication, audit logs, backup, configuration documents, and removal of unnecessary access to PoC exit criteria.
Calling operators “resistant to change”
Operators may be identifying a system that they cannot recover. Capture their exception knowledge and allow rejection reasons. Human interventions are learning evidence for a better boundary, not automatically a failure.
Using vendor announcements as the business case
Announcements are useful for understanding direction, but site benefits require site data. Put the comparable baseline, acceptance condition, and stop condition in the contract.
Pre-order checklist for autonomous factory AI
- Included and excluded scope is defined by equipment, product, and mode.
- AI proposals and executable operations are separate.
- Stop authority across people, PLC, safety system, MES, and ERP is explicit.
- Degraded behavior during communication loss and missing data is defined.
- NORMAL, DEGRADED, SAFE STOP, and RECOVERY transitions are documented.
- Data and command boundaries are drawn with ISA-95 as a reference.
- FAT/SAT includes fault injection, restoration, and permission testing.
- Model updates and PLC changes have named revalidation owners.
- Thai-language training, night escalation, and handover are ready.
- BOI eligibility is checked per project, not assumed.
- PoC termination and access-removal conditions are agreed.
- KPI formulas, data sources, and baseline periods are approved.
FAQ about autonomous factory implementation
Does an autonomous factory mean a fully unmanned factory?
No. It means that systems may decide and adjust within a defined operating domain, then degrade or stop safely and hand control to people outside it. People still own objectives, constraints, exceptions, and change approval.
How should factory automation maturity be measured?
Measure the scope of visibility, recommendation, bounded autonomy, coordinated decisions, and safe exception recovery. Assess each process and its handoffs; do not rely only on a site average.
What is the most important item in an autonomous factory RFP?
Define scope, allowed decisions, prohibited operations, stop and recovery authority, acceptance evidence, and responsibility. This makes proposals comparable and FAT/SAT enforceable.
Can a 90-day PoC prove all production benefits?
Not necessarily. It may validate technical feasibility, operating boundaries, data quality, and exception recovery, but seasonal variation, every SKU, and full equipment life can require longer observation.
Is Thailand BOI support guaranteed for automation investment?
No. The published program has investment and sourcing conditions, while eligibility varies by project, activity, cost, and timing. Confirm the specific case with BOI or a qualified adviser.
Conclusion: the intervention boundary determines success
The value of an autonomous factory is not removing people. It is assigning repeatable decisions to equipment and software so people can focus on goals, exceptions, improvement, and controlled change. Assess maturity by process, define data and command boundaries, allocate stop authority, engineer degradation and recovery, and assign maintenance accountability. Align bidders through the RFP, test faults in FAT/SAT, and use a 90-day PoC to gather evidence before expanding scope.
TOMAS TECH can support Thailand factories from initial diagnosis and RFP definition through PLC/MES/AI responsibility mapping and FAT/SAT scenarios. Even if equipment specifications are not final, you can discuss how to isolate a safe first scope through our contact page.
References
- Rockwell Automation, AI-driven autonomous factories (18 Sep 2026)
- Siemens, How industrial AI is transforming manufacturing with intelligent solutions (18 Sep 2026)
- FANUC America, Robotics, Automation, Physical AI and CNC Innovation at IMTS 2026 (3 Sep 2026)
- ISA, ISA-95 Standard
- IEC, IEC 62443-2-4:2023
- ISO, ISO 10218-2:2025
- Thailand Board of Investment, Smart and Sustainable Industry
- NIST, AI Risk Management Framework resources