That is the most common sentence we hear about manufacturing AI pilots. It is not a model problem. AI on operational data fails twice — and the second failure is the one nobody is selling you a fix for.
We don't build AI models. We make AI work on the data that actually runs your plants.
Both failures produce a confident answer. Only one of them is a model problem. Read them side by side, because every vendor conversation you have had so far was about the card on the left.
Failure one · widely discussed
A model asked a question it lacks the context to answer does not stop. It interpolates. The gap in your data becomes a sentence in its answer, and the sentence is indistinguishable from the parts that are true.
Fixable by giving the model more context. This is the failure the market is working on.
Failure two · nobody's pitch deck
This one is worse, and it is worse in a specific way. The model did its job perfectly. It found the record, read the field, reported the number, and showed you the source. The number was wrong before the model ever touched it.
No hallucination guardrail catches this. The answer is sourced, cited, traceable — and false.
The first failure makes you distrust the AI. The second one makes you distrust the AI for the wrong reason, and then quietly ship a decision based on it. A cited wrong number travels further inside a company than an obvious hallucination ever will, because it survives review.
Fixing the model does nothing about the second failure. That one is a data problem, and it is the one we fix.
Point the sharpest model available at disconnected systems and week-old numbers, and what improves is the writing. The reasoning chain gets tighter. The caveats get more sophisticated. The conclusion is still built on a cost figure that was never true and an inventory count that expired on Tuesday.
Model quality stopped being the constraint a while ago. Every frontier model on the market can reason about a scheduling tradeoff better than it can find out what actually happened in your plant yesterday.
A smarter model
What it genuinely fixes
Better reasoning, cleaner prose, fewer obvious mistakes.
What it does nothing about
It reasons more rigorously over the same stale number and builds a more convincing case around it. The confidence goes up. The accuracy does not.
A bigger context window
What it genuinely fixes
More documents in the prompt at once.
What it does nothing about
The documents you can paste are the ones already exported. The downtime record still sits on a historian the model has never been introduced to.
Retrieval over your documents
What it genuinely fixes
Policies, manuals, SOPs, last quarter’s reports.
What it does nothing about
Documents describe how the plant is supposed to run. They do not tell you what happened on second shift. That lives in systems, not in files.
An agent that takes actions
What it genuinely fixes
Multi-step work without a human in every loop.
What it does nothing about
An agent acting on a wrong number does more damage per hour than a chatbot reporting one. Autonomy multiplies whatever the data foundation hands it.
The line that matters
Your AI is only as smart as the data it can see.
Which means the useful question is not “which model should we use.” It is “what can any model actually reach, how old is it when it gets there, and who said it was right.” That is a plumbing question, and it has plumbing answers.
You can check all four this quarter without buying a single model license. Each one has a question underneath it that your own team can answer honestly in about an hour.
ERP, MES, WMS, CRM, quality, maintenance, historians and the PLC layer reachable through one governed integration plane — not through four point-to-point scripts and a nightly CSV someone maintains by hand.
The test: Can a question touch three systems without a human exporting anything?
Numbers that reflect this shift, not last week’s batch post. Real-time where the decision is real-time: production counts, downtime events, consumption, scrap, machine state.
The test: If the answer is six hours old, is the decision still safe to make?
One agreed source of truth per field, and a named owner for it. When ERP and MES disagree about the same part, the tie-break is written down rather than argued about in a meeting.
The test: For any number the AI returns, can you name the system of record and the person who owns it?
Identity, scope and audit on every read. The AI gets named, permissioned operations — never a service account with blanket database rights and no log of what it looked at.
The test: Can you show an auditor exactly what the model was allowed to see, and what it saw?
The part most AI programs discover late
Cycle times, machine states, downtime reasons, scrap at the station, actual consumption against the recipe. The facts that explain why a job cost what it cost live on controllers, historians and HMIs behind the plant firewall — by design, and correctly so. A cloud AI platform cannot see any of it, and no amount of model tuning changes that. Somebody has to build the bridge, safely, from the physical layer up. That is engineering work, not a prompt.
Magic MCP is a model-agnostic governance layer. It sits between whatever AI you choose and the systems that hold the truth, and it turns your existing business processes into secure, callable tools that a model can actually use — with identity, scope, audit and freshness on every single request.
It overlays your existing systems. No data migration, no rewrite, no parallel copy of your ERP maintained for the benefit of a chatbot.
What governed access means in practice
Model-agnostic, and we mean it structurally
The hard, expensive, slow work is not picking a model. It is mapping your systems, agreeing on sources of truth, and building governed access to live operational data. That work should be an asset you keep, not something you redo the next time the leaderboard changes.
Magic MCP keeps the model interchangeable. Run a frontier model today, a different one next year, an open-weight model on-prem for the air-gapped plant, and more than one at the same time for different workloads. The connectors, permissions, flows and audit trail do not move.
A vendor whose AI only works with their AI has sold you a second lock-in problem on top of the one you already have in your ERP.
Three deployment modes, one governance model. The controls do not get weaker because the plant is stricter.
Mode 01
Magic MCP runs inside your tenant and your network boundary. Your identity provider, your logging stack, your key management. Data stays in accounts you own, under policies you already wrote.
Who picks this: Enterprise IT that has already standardized on a hyperscaler and a model provider, and needs governance rather than another perimeter.
Mode 02
Isolated networking, private endpoints, no traffic over the public internet. Model calls traverse a path your security team can diagram, and the governance layer sits on your side of it.
Who picks this: Regulated operations and multi-plant groups that will allow cloud AI, but only across a private path with no shared tenancy.
Mode 03
The full governance layer deployed inside the facility, running against an on-prem model. No egress. The AI gets live floor data because it is standing next to it.
Who picks this: The plant that will never send data out. Defense work, proprietary process IP, contractual data-residency terms, or a plant manager whose answer is simply no.
We are not going to promise you AI value before the foundation is in place. Everyone who did that is the reason you are reading this page. Here is the sequence that actually produces a trustworthy answer, and who does each part.
Magic Consulting
A structured conversation and an assessment, not a procurement event. We walk the questions from the four pillars with your IT and operations people in the same room: which systems hold which truth, how current each one is, where the contradictions are, and which decisions you actually want AI to inform. The output is a candid readiness picture — including the parts that are not ready.
Sometimes the recommendation is to fix two integrations and revisit AI in a quarter. We would rather say that than sell you a pilot that produces the sentence at the top of this page.
Magic Integration
Enterprise integration across ERP, CRM, WMS, MES, HR, finance, support, historians and the plant floor — built on 100+ pre-built and certified connectors and proprietary in-memory middleware. Once the systems talk, Magic MCP governs how AI is allowed to ask them questions.
This is the step that converts the second failure mode into a solved problem. It is also the step most AI projects skip.
Magic Engineering
You cannot integrate a number nobody is capturing. Thirty-plus years of controls engineering and 1,900+ automation projects across Ignition, Rockwell, AVEVA, Siemens, Omron and FANUC — instrumenting lines, standing up historians, and bringing downtime, scrap and machine state into existence as real, timestamped, trustworthy data.
On most floors some share of what the AI needs has simply never been recorded. That is an engineering job and we do it ourselves.
Then, and only then
Start with the questions whose answers are now verifiable end to end. Prove the chain from the prompt back to the controller. Expand once the operators stop double-checking it, because that is the only real measure of trust.
Trust is earned at the data layer and spent at the interface. Never the other way around.
One P&L. No handoffs.
Magic Consulting, Magic Integration and Magic Engineering are divisions of Magic Software Americas — one P&L, no subcontracting. The people who assess readiness, connect the systems and instrument the line answer to the same leadership and the same project plan.
Published industry surveys put adoption at 88% of companies using AI in at least one business function, while only about one third have scaled it across the enterprise. That gap is not a shortage of models, budget or enthusiasm. Every company in both groups has access to the same models.
The difference is what happens the first time an answer gets checked. Where the data underneath is connected, current and owned, the answer survives the check and the pilot expands. Where it is not, the answer fails once in front of the wrong person and the program quietly becomes a line item nobody defends.
Pilots are cheap because nothing depends on them. Scaling is where the data foundation presents the bill.
The adoption gap
88%
using AI in at least one business function
~1 in 3
have scaled it across the enterprise
Published market context from industry adoption surveys, not Magic research. We cite it because the shape of the gap matches what we see in every plant we walk: the pilot works, the second question breaks it.
Governed access is not a feature we describe. It is connectors, middleware, identity and audit, shipped in whichever of the three deployment modes your security posture allows.
3
deployment modes: your cloud, private VPC, air-gapped on-prem
Model-agnostic
no lock-in to a single AI vendor, by design
100+
pre-built and certified connectors underneath
In-memory
proprietary middleware for high availability

A question goes to the model. The model calls a named, permissioned tool. The tool runs an integration flow that already knows how to ask your ERP, your MES or your historian correctly. The answer comes back with its sources and its as-of time. Every hop is authenticated and logged.
That chain is why the answer is defensible. You can walk it backwards in front of an auditor, a customer or a plant manager who does not believe you.
Governance and compliance
The same controls your enterprise systems are held to, applied to the layer your AI reads through.
This is the one outcome on our site where the org chart is the argument. The readiness assessment, the integration work and the controls engineering are three different skills, and handing them to three different vendors is how the data foundation ends up everybody's problem and nobody's job.
Connects the estate and deploys Magic MCP.
Enterprise integration across ERP, CRM, WMS, MES, HR, finance, support, historians and the plant floor — then the governance layer that lets AI read it safely.
Visit the divisionEstablishes readiness before anything gets deployed.
A structured conversation and an assessment with IT and operations together: sources of truth, data currency, ownership, and which decisions are worth automating first.
Visit the divisionMakes the floor data exist where it doesn’t yet.
Controls, instrumentation and historians across Ignition, Rockwell, AVEVA, Siemens, Omron and FANUC. CSIA-certified since 2002. The physical layer, done by the people who own the outcome.
Visit the divisionThe product page: Enterprise MCP, native LLM steps inside integration flows, and agentic workflows constrained to a schema you can rely on.
Read moreWhere AI fits across everything we build, and the line we hold: we don’t build the models, we make them usable on your operational data.
Read moreThe delivery view — how AI gets wired into existing business processes instead of sitting beside them in a separate tool nobody opens twice.
Read moreThe prerequisite outcome. A connected estate is what makes trustworthy AI possible at all, and it is worth doing even if you never deploy a model.
Read moreThat one question usually settles whether you have a model problem or a data problem — and it is the right place to start a readiness conversation. No deck. No pricing theater. If the honest answer is “fix two integrations first,” we will say so.