Cell Register

AI defect-detection model

A trained model, on a camera or an edge box, that classifies product or predicts a fault and can be retrained on new data.

How the register reads it

Also calledAI inspection, defect detection model, edge AI
FamilyInspection and vision
What a wrong action costsbatch. Drift that passes defects or rejects good product, without anyone noticing the rule has moved.
Zone class and SL-Tline SL-T 3 by default (2 for the class, raised one because the class is reached remotely by default). Serves a line from an edge box on the line network. Never above 3; the paste may state its own zone name and SL-T.
Networked by defaultYes. Models are deployed and updated over the network.
Remote access by defaultYes. Model suppliers push updates remotely as a rule; the paste decides.
Behaviour by defaultadaptive. It learns; the class is adaptive.
Machinery RegulationA controller, a server or a sensor that is not itself a machine or a safety component carries no Machinery Regulation row; the machine it controls does.
Vendor cloudThe fleet or the model is usually managed from a vendor cloud: ISO 27001 control 5.23 attaches where ISO 27001 is ticked, and the runtime attestation row asks what the vendor can send back.
Safety references
  • ISO 12100 risk assessment and risk reduction for machinery
Named, not held: the register does not say whether a machine was built to them.

What each regime attaches, and who it binds

65 clauses across 5 regimes, on the class defaults

Shown on a register for the regimes you tick; with none ticked, the IEC 62443 asset-owner rows are the default. The CRA row is informational on every connected asset. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

IEC 62443

Binds Part 2-1 binds the asset owner; Part 3-2 is the owner's zoning and risk assessment; Part 3-3 is what the owner specifies for the system. Part 2-4 binds the service provider and Parts 4-1 and 4-2 the product supplier, so those rows are rendered as what to ask. Source framework: IEC 62443.

Asset owner dutyOn every asset (Part 2-1)
IEC 62443 2-1 AC · 2-1 BCP · 2-1 CSMS · 2-1 IR · 2-1 MOC · 2-1 NSEG · 2-1 PHY · 2-1 PM · 2-1 RA · 2-1 TRN
Whatever the zone, these ten programme duties are the owner's for every asset in the system under consideration.
Asset owner dutySystem requirements to specify for a line zone (Part 3-3)
IEC 62443 3-3 SR 1.1 · 3-3 SR 1.2 · 3-3 SR 2.1 · 3-3 SR 2.8 · 3-3 SR 3.1 · 3-3 SR 3.4 · 3-3 SR 5.1 · 3-3 SR 5.2 · 3-3 SR 6.1 · 3-3 SR 7.3 · 3-3 SR 7.6
A line zone shares a network among controllers, drives and stations, so device authentication, auditable events, communication integrity, a protected zone boundary, accessible logs and backup join the cell requirements.
Asset owner dutyAdded where the asset is on a network
IEC 62443 3-3 SR 3.1 · 3-3 SR 5.2 · 3-3 SR 6.2
Communication integrity, a monitored zone boundary and continuous monitoring attach the moment the asset is reachable.
Asset owner dutyAdded where the asset is reached remotely
IEC 62443 2-1 AC · 3-3 SR 1.1 · 3-3 SR 6.1
The remote account, its authentication and the record of its sessions are the owner's.
Asset owner dutyAdded where the controller adapts at runtime
IEC 62443 3-3 SR 2.8 · 3-3 SR 3.4
A controller that changes its own behaviour needs the integrity of its model or program watched and its actions logged, so a change can be told from an attack.
Ask the integratorPart 2-4 binds the service provider, not the owner
IEC 62443 2-4 SP-01 · 2-4 SP-02 · 2-4 SP-03 · 2-4 SP-04 · 2-4 SP-05 · 2-4 SP-06
The owner owes none of these rows; the owner asks the integrator and the maintenance provider for the evidence of each before commissioning and at every substantial change.
Ask the supplierPart 4-1 binds the supplier, not the owner
IEC 62443 4-1 DM · 4-1 SG · 4-1 SUM
The owner asks the maker of the controller or the machine for the hardening guide, the vulnerability handling process and the signed update channel.
Ask the supplierPart 4-2 binds the supplier: a networked component
IEC 62443 4-2 CR-1-1 · 4-2 EDR-3-10
For a networked controller the owner also asks for signed firmware with rollback protection and user authentication on the component.

NIST SP 800-82 Rev 3

Binds guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against. Source framework: NIST SP 800-82 Rev 3.

Asset owner dutyThe OT overlay on every asset
SP 800-82 GOV-3 · HOST-4 · HOST-6 · IR-1 · MON-2
SP 800-82 is guidance for the operator of the OT environment: an inventory that holds firmware and location, safety and security run together, change and patch management, and an incident plan with OT scenarios.
Asset owner dutyNetwork architecture where the asset is on a network
SP 800-82 ARCH-1 · ARCH-2 · NET-1
Zones and conduits, an industrial DMZ between the plant and the office, and deny-by-default rules between zones.
Asset owner dutyRemote access where the asset is reached remotely
SP 800-82 RA-1 · RA-2
A brokered, authenticated, recorded, time-bounded path; vendor accounts named individually and enabled just in time.
Asset owner dutyField devices in a cell or line zone
SP 800-82 IAM-4 · PHYS-1
Where a controller has little or no logical authentication, the key switch, the locked cabinet and the seal are the control.

The EU AI Act

Binds Articles 26 and 4 bind the deployer, which is the asset owner using the system; Articles 12 to 15 bind the provider; a deployer that substantially modifies the system becomes its provider. Source framework: the EU AI Act.

Asset owner dutyAs the deployer of an adaptive controller
AI Act Art. 4 · Art. 6 · Art. 26
An AI system used as a safety component of a machine, or that is itself the product, under the Union harmonisation legislation in Annex I (the Machinery Regulation is listed there) falls under Article 6(1). The deployer uses it per the instructions, assigns oversight to competent persons, monitors it, keeps its logs and makes its people literate in it.
Ask the providerArticles 12 to 15 bind the provider, not the deployer
AI Act Art. 12 · Art. 13 · Art. 14 · Art. 15
Human oversight by design, accuracy, robustness and cybersecurity, instructions for use that carry the oversight measures, and event logging are the provider's duties; the deployer asks for the evidence of each.
Asset owner dutyIf the owner substantially modifies the system
AI Act Art. 25
A deployer that substantially modifies a high-risk system, or changes its intended purpose so that it becomes high-risk, takes on the provider's obligations.

The EU Cyber Resilience Act

Binds manufacturers, importers and distributors of products with digital elements; never the owner using them. Source framework: the EU Cyber Resilience Act.

Ask the supplierFrom the application date (the CRA binds manufacturers)
CRA Art. 13 and Annex I · Art. 69, 70, 71
A connected controller or machine with digital elements is a product with digital elements; the manufacturer owes the essential cybersecurity requirements, a support period with security updates and vulnerability handling. The owner asks for the support period and the update channel. Informational: the owner owes no CRA clause.

ISO/IEC 27001:2022

Binds the organisation that holds the certificate, through the Annex A controls it declared applicable. Source framework: ISO/IEC 27001:2022.

Asset owner dutySupplier and change controls on every asset
ISO 27001 5.19 · 5.20 · 5.22 · 8.32
The integrator and the maintenance provider are suppliers; the change to a machine is a change.
Asset owner dutyNetwork controls where the asset is on a network
ISO 27001 5.21 · 8.9 · 8.20 · 8.21 · 8.22
Network security, the services on it, segregation and a secure configuration baseline attach to any connected asset; the ICT supply chain control attaches to what the supplier delivers into it.
Asset owner dutyWhere a fleet or model is managed from a vendor cloud
ISO 27001 5.23
A fleet manager or a model service hosted by the vendor is a cloud service: acquisition, use and exit are governed.

Runtime attestation: what to ask the supplier for

Signed firmware and updates with rollback protection, an attested boot or integrity check the controller reports, and behaviour logs that can be read off the device. The register asks; it does not say the supplier provides any of it. AI Act Art. 12 · Art. 15 CRA Art. 13 and Annex I IEC 62443 3-3 SR 3.3 · 3-3 SR 3.4 · 4-1 SUM · 4-2 EDR-3-10

Ask the integrator

  1. Who retrains the model, on what data, and who approves a new version into production
  2. What the model can do without a person: reject, stop, or only flag
  3. What it logs, and for how long

Findings this class can raise

Do this for every asset on your floor

Paste the list and get this classification for every asset at once, with the zone and SL-T, the behaviour, the connectivity, the findings and the obligation rows per regime. Eight assets free, no account.

Build my cell register

Variable-speed drive · Barcode and RFID reader