Magic Software Americas
For IT Leadership · the CEO · whoever signed off on the pilot

The answers sounded great. Some of them were wrong.

That is the most common sentence we hear about manufacturing AI pilots. It is not a model problem. AI on operational data fails twice — and the second failure is the one nobody is selling you a fix for.

We don't build AI models. We make AI work on the data that actually runs your plants.

The Two Failures

AI on manufacturing data fails twice. You only ever hear about the first one.

Both failures produce a confident answer. Only one of them is a model problem. Read them side by side, because every vendor conversation you have had so far was about the card on the left.

Failure one · widely discussed

The model invents what it cannot see.

A model asked a question it lacks the context to answer does not stop. It interpolates. The gap in your data becomes a sentence in its answer, and the sentence is indistinguishable from the parts that are true.

  • You ask why Line 3 missed schedule. The model can reach the order header and the shipping record, but not the downtime log, the changeover notes, or the quality hold.
  • It has no way to say “I cannot see that.” So it writes the most plausible sentence that fits the shape of the question.
  • The output reads like an analyst wrote it. There is no footnote where the missing data used to be.

Fixable by giving the model more context. This is the failure the market is working on.

Failure two · nobody's pitch deck

The facts it does cite are already wrong.

This one is worse, and it is worse in a specific way. The model did its job perfectly. It found the record, read the field, reported the number, and showed you the source. The number was wrong before the model ever touched it.

  • Standard cost is not actual cost. The model cites the costed BOM to the cent, and the real job ran a different routing on a different machine with a different scrap rate.
  • The ERP has not heard from the floor since last Tuesday. Quantities were back-flushed in a batch, so on-hand is a snapshot of a shift that already ended.
  • Two systems disagree about the same part number, and nobody told the model which one the plant trusts.

No hallucination guardrail catches this. The answer is sourced, cited, traceable — and false.

The first failure makes you distrust the AI. The second one makes you distrust the AI for the wrong reason, and then quietly ship a decision based on it. A cited wrong number travels further inside a company than an obvious hallucination ever will, because it survives review.

Fixing the model does nothing about the second failure. That one is a data problem, and it is the one we fix.

The Bottleneck

A better model doesn't give you a better answer. It gives you a more persuasive one.

Point the sharpest model available at disconnected systems and week-old numbers, and what improves is the writing. The reasoning chain gets tighter. The caveats get more sophisticated. The conclusion is still built on a cost figure that was never true and an inventory count that expired on Tuesday.

Model quality stopped being the constraint a while ago. Every frontier model on the market can reason about a scheduling tradeoff better than it can find out what actually happened in your plant yesterday.

A smarter model

What it genuinely fixes

Better reasoning, cleaner prose, fewer obvious mistakes.

What it does nothing about

It reasons more rigorously over the same stale number and builds a more convincing case around it. The confidence goes up. The accuracy does not.

A bigger context window

What it genuinely fixes

More documents in the prompt at once.

What it does nothing about

The documents you can paste are the ones already exported. The downtime record still sits on a historian the model has never been introduced to.

Retrieval over your documents

What it genuinely fixes

Policies, manuals, SOPs, last quarter’s reports.

What it does nothing about

Documents describe how the plant is supposed to run. They do not tell you what happened on second shift. That lives in systems, not in files.

An agent that takes actions

What it genuinely fixes

Multi-step work without a human in every loop.

What it does nothing about

An agent acting on a wrong number does more damage per hour than a chatbot reporting one. Autonomy multiplies whatever the data foundation hands it.

The line that matters

Your AI is only as smart as the data it can see.

Which means the useful question is not “which model should we use.” It is “what can any model actually reach, how old is it when it gets there, and who said it was right.” That is a plumbing question, and it has plumbing answers.

AI-Ready, Defined

“AI-ready” is not a posture. It is four testable things.

You can check all four this quarter without buying a single model license. Each one has a question underneath it that your own team can answer honestly in about an hour.

01

Connected systems

ERP, MES, WMS, CRM, quality, maintenance, historians and the PLC layer reachable through one governed integration plane — not through four point-to-point scripts and a nightly CSV someone maintains by hand.

The test: Can a question touch three systems without a human exporting anything?

02

Current data

Numbers that reflect this shift, not last week’s batch post. Real-time where the decision is real-time: production counts, downtime events, consumption, scrap, machine state.

The test: If the answer is six hours old, is the decision still safe to make?

03

Clear ownership

One agreed source of truth per field, and a named owner for it. When ERP and MES disagree about the same part, the tie-break is written down rather than argued about in a meeting.

The test: For any number the AI returns, can you name the system of record and the person who owns it?

04

Governed access

Identity, scope and audit on every read. The AI gets named, permissioned operations — never a service account with blanket database rights and no log of what it looked at.

The test: Can you show an auditor exactly what the model was allowed to see, and what it saw?

The part most AI programs discover late

Roughly half the most valuable operational data never leaves the OT network.

Cycle times, machine states, downtime reasons, scrap at the station, actual consumption against the recipe. The facts that explain why a job cost what it cost live on controllers, historians and HMIs behind the plant firewall — by design, and correctly so. A cloud AI platform cannot see any of it, and no amount of model tuning changes that. Somebody has to build the bridge, safely, from the physical layer up. That is engineering work, not a prompt.

Magic MCP

We don't build AI. We make AI work.

Magic MCP is a model-agnostic governance layer. It sits between whatever AI you choose and the systems that hold the truth, and it turns your existing business processes into secure, callable tools that a model can actually use — with identity, scope, audit and freshness on every single request.

It overlays your existing systems. No data migration, no rewrite, no parallel copy of your ERP maintained for the benefit of a chatbot.

What governed access means in practice

Not a connection. A permissioned, auditable interface.

  • The AI never gets a database credential. It gets a catalog of named operations — get job cost, get current on-hand, get downtime for a line and shift — each one backed by an integration flow that already knows how to ask correctly.
  • Every call carries an identity. Scope is enforced per user and per role, so a plant supervisor and a controller see different answers to the same prompt because they are entitled to different data.
  • Every call is logged: who asked, what was returned, which systems were touched, when. Reconstructable after the fact, which is what makes an AI answer defensible.
  • Freshness is explicit. A response can carry the as-of timestamp of the underlying read, so a stale number announces itself instead of hiding inside a confident paragraph.

Model-agnostic, and we mean it structurally

Your governance layer should outlive your model choice.

The hard, expensive, slow work is not picking a model. It is mapping your systems, agreeing on sources of truth, and building governed access to live operational data. That work should be an asset you keep, not something you redo the next time the leaderboard changes.

Magic MCP keeps the model interchangeable. Run a frontier model today, a different one next year, an open-weight model on-prem for the air-gapped plant, and more than one at the same time for different workloads. The connectors, permissions, flows and audit trail do not move.

A vendor whose AI only works with their AI has sold you a second lock-in problem on top of the one you already have in your ERP.

Three deployment modes, one governance model. The controls do not get weaker because the plant is stricter.

Mode 01

Your cloud, with controls

Magic MCP runs inside your tenant and your network boundary. Your identity provider, your logging stack, your key management. Data stays in accounts you own, under policies you already wrote.

Who picks this: Enterprise IT that has already standardized on a hyperscaler and a model provider, and needs governance rather than another perimeter.

Mode 02

Private VPC

Isolated networking, private endpoints, no traffic over the public internet. Model calls traverse a path your security team can diagram, and the governance layer sits on your side of it.

Who picks this: Regulated operations and multi-plant groups that will allow cloud AI, but only across a private path with no shared tenancy.

Mode 03

Air-gapped on-prem

The full governance layer deployed inside the facility, running against an on-prem model. No egress. The AI gets live floor data because it is standing next to it.

Who picks this: The plant that will never send data out. Defense work, proprietary process IP, contractual data-residency terms, or a plant manager whose answer is simply no.

The Honest Sequence

Assess. Connect. Then AI. In that order, every time.

We are not going to promise you AI value before the foundation is in place. Everyone who did that is the reason you are reading this page. Here is the sequence that actually produces a trustworthy answer, and who does each part.

01

Magic Consulting

Assess readiness before anyone deploys anything.

A structured conversation and an assessment, not a procurement event. We walk the questions from the four pillars with your IT and operations people in the same room: which systems hold which truth, how current each one is, where the contradictions are, and which decisions you actually want AI to inform. The output is a candid readiness picture — including the parts that are not ready.

Sometimes the recommendation is to fix two integrations and revisit AI in a quarter. We would rather say that than sell you a pilot that produces the sentence at the top of this page.

02

Magic Integration

Connect the estate, then deploy Magic MCP on top of it.

Enterprise integration across ERP, CRM, WMS, MES, HR, finance, support, historians and the plant floor — built on 100+ pre-built and certified connectors and proprietary in-memory middleware. Once the systems talk, Magic MCP governs how AI is allowed to ask them questions.

This is the step that converts the second failure mode into a solved problem. It is also the step most AI projects skip.

03

Magic Engineering

Make the floor data exist where it doesn’t yet.

You cannot integrate a number nobody is capturing. Thirty-plus years of controls engineering and 1,900+ automation projects across Ignition, Rockwell, AVEVA, Siemens, Omron and FANUC — instrumenting lines, standing up historians, and bringing downtime, scrap and machine state into existence as real, timestamped, trustworthy data.

On most floors some share of what the AI needs has simply never been recorded. That is an engineering job and we do it ourselves.

04

Then, and only then

Put AI in front of people who have to act on it.

Start with the questions whose answers are now verifiable end to end. Prove the chain from the prompt back to the controller. Expand once the operators stop double-checking it, because that is the only real measure of trust.

Trust is earned at the data layer and spent at the interface. Never the other way around.

One P&L. No handoffs.

Magic Consulting, Magic Integration and Magic Engineering are divisions of Magic Software Americas — one P&L, no subcontracting. The people who assess readiness, connect the systems and instrument the line answer to the same leadership and the same project plan.

Start with the Assessment
Market Context

Almost everyone is using AI somewhere. Almost nobody has scaled it.

Published industry surveys put adoption at 88% of companies using AI in at least one business function, while only about one third have scaled it across the enterprise. That gap is not a shortage of models, budget or enthusiasm. Every company in both groups has access to the same models.

The difference is what happens the first time an answer gets checked. Where the data underneath is connected, current and owned, the answer survives the check and the pilot expands. Where it is not, the answer fails once in front of the wrong person and the program quietly becomes a line item nobody defends.

Pilots are cheap because nothing depends on them. Scaling is where the data foundation presents the bill.

The adoption gap

88%

using AI in at least one business function

~1 in 3

have scaled it across the enterprise

Published market context from industry adoption surveys, not Magic research. We cite it because the shape of the gap matches what we see in every plant we walk: the pilot works, the second question breaks it.

  • Pilots live in one system. Production questions cross four.
  • Demos use a curated extract. Operations use whatever posted last night.
  • A pilot is judged on whether the answer sounds right. Production is judged on whether it is right.
What's Actually Behind It

Every AI claim on this page is really a data-plumbing claim.

Governed access is not a feature we describe. It is connectors, middleware, identity and audit, shipped in whichever of the three deployment modes your security posture allows.

3

deployment modes: your cloud, private VPC, air-gapped on-prem

Model-agnostic

no lock-in to a single AI vendor, by design

100+

pre-built and certified connectors underneath

In-memory

proprietary middleware for high availability

Magic MCP governing LLM access to ERP, MES and plant-floor systems

The path from a prompt back to a controller, and every hop in between.

A question goes to the model. The model calls a named, permissioned tool. The tool runs an integration flow that already knows how to ask your ERP, your MES or your historian correctly. The answer comes back with its sources and its as-of time. Every hop is authenticated and logged.

That chain is why the answer is defensible. You can walk it backwards in front of an auditor, a customer or a plant manager who does not believe you.

Governance and compliance

SOC 2 Type IIISO 9001ISO 27001GDPR

The same controls your enterprise systems are held to, applied to the layer your AI reads through.

Who Delivers It

Trustworthy AI crosses three disciplines. All three report to the same P&L.

This is the one outcome on our site where the org chart is the argument. The readiness assessment, the integration work and the controls engineering are three different skills, and handing them to three different vendors is how the data foundation ends up everybody's problem and nobody's job.

Go Deeper

Four places to keep reading. Start with the prerequisite.

Tell us which answer was wrong. We'll tell you which failure it was.

That one question usually settles whether you have a model problem or a data problem — and it is the right place to start a readiness conversation. No deck. No pricing theater. If the honest answer is “fix two integrations first,” we will say so.