Updated September 2026.
AI has quietly entered engineering and estimating work, not through a formal company rollout, but through individual engineers and estimators pasting things into public AI tools to move faster: a customer's tolerance callouts, a snippet from a STEP file description, a cost breakdown, a supplier quote, a paragraph from a drawing's technical notes.
That is not experimentation. It is uncontrolled handling of exactly the data a manufacturing business exists to protect: customer intellectual property, defence- or medical-grade specifications, years of accumulated costing knowledge, and supplier relationships.
The problem is structural, not behavioral
Public AI tools are built for broad, general use. They are not built for the kind of data that moves through a manufacturing engineering or estimating desk:
No context-specific data handling rules. Nothing stops a tolerance-sensitive drawing from being treated the same as a marketing draft.
No integration with your access controls. A public tool does not know who is allowed to see which customer's part geometry.
No enterprise-grade security boundary. The data leaves your environment the moment it is pasted in.
No auditable trail. There is no record of what engineering data went where, or when.
These tools remain useful for general research and exploration. They are not suited to workflows touching drawings, STEP files, customer specifications, tolerances, costing data, production history, or machine information.
What engineering data actually needs
Data handling for engineering and manufacturing information needs to be enforced by architecture, not left to individual judgment. That means a system that sits inside your security boundary and integrates with the access controls, data classification and audit logging you already run.

Guardrails, not guidelines
Guardrails are system-level checks that run regardless of what a user intends. Before an AI system processes anything, it should be able to answer:
What data is being submitted, and is it a drawing, a customer specification, or costing data?
Is this use case permitted for this role, on this customer's data?
Does this comply with the customer's confidentiality terms and any export-control or IP obligations?
After the AI responds, the same system should check whether the output discloses something it should not, or implies a decision, such as a quoted price or a process choice, that needs documented human review before it goes further.
If a check fails, the system blocks it or routes it to a person. That decision is programmatic, not a matter of remembering the policy.
Why this matters in manufacturing specifically
Engineering: a drawing or STEP file pasted into a public tool for a quick geometry check can carry a customer's unreleased product design.
Estimating: historic costing data used to sanity-check a quote reveals your margin structure and a customer's volumes to a system outside your control.
Quality and production: inspection results and machine data can expose process know-how that took years to build.
Supplier and customer relationships: specifications and terms are often confidential by contract, not just by habit.
None of this requires bad intent. It is a structural gap: no system-level enforcement aligned with how the business already manages access, confidentiality and IP.
A governance requirement, not a tool choice
The same principles apply here as in any responsible AI deployment: process only the data a task needs, restrict AI usage to defined and authorized use cases, keep humans in the loop for decisions with real consequences, and log every interaction so it is traceable and auditable. None of that requires a specific vendor or model. It requires the same rigor already applied to any other system that touches sensitive engineering data.
Subduxion is building a world model for precision manufacturing. Our research focuses on how geometry, requirements, manufacturing processes and production outcomes can be represented and learned computationally, inside an architecture designed to keep engineering data where it belongs. Read more about how we approach this in security.
