Skip to content

Leadership1 publisher3 min readPublished

EY's Farooque Munshi wants model provenance written into equipment contracts

A Forbes Tech Council column by EY partner Farooque Munshi says most manufacturers run two AI estates, and that the larger one arrived as capital equipment judged on price, delivery and warranty, with no survey behind the claim.

The Board Room · Leadership desk

Illustration accompanying EY's Farooque Munshi wants model provenance written into equipment contracts

What happened

  • Farooque Munshi, an EY partner leading Data/AI for advanced manufacturing across the Americas, wrote in Forbes that most manufacturers run two AI estates, one governed and shown to the board and one invisible.
  • His examples are a machining center that self-adjusts tool offsets with an embedded vision model, compressors on a vendor's anomaly detection, and a spectrometer classifying defects on other customers' data.
  • None of that equipment passed through model validation or the CDO's inventory; it entered through procurement and was evaluated on price, delivery and warranty.
  • Munshi sets four questions for anything bought this year: what the model trained on, when the vendor retrains it and whether they say so, what data it phones home, and whether a scrapped shift can be audited.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure Some AI Act duties land on deployers, including human oversight, monitoring and record-keeping, so the plant that cannot name the models inside its machines holds the obligation itself.
  • cost An undocumented embedded model is paid for twice: once when it makes bad calls after an overnight update with no baseline to check it against, and again when operators route around it for good and the plant runs a machine whose intelligence it bought and no longer uses.
  • constraint Vendor data pooling limits what a site can keep to itself, because process tuning absorbed into a vendor's model is available for the plant across town to buy.
  • decision Someone has to choose between putting embedded-AI screening in the RFP template and leaving it as an escalation, and Munshi's own reasoning is that the escalation does not survive a delivery deadline.

The gap Munshi describes sits between two functions that are both doing their jobs. Procurement runs an RFP template that predates embedded AI, and a contract playbook written to cover IP, liability and spare parts, with no clause for retraining cadence or data provenance [9]. Governance was built to catch models written in-house and software bought as software, while capital equipment moves through a different budget and a different approval chain [10]. Munshi wrote that "Nobody screwed up, and that's the problem" [8]. Both teams did their assigned job; the gap sits between the jobs themselves.

His answer is procedural. Put the identification question inside the purchasing process, on the argument that developers did not consistently involve security teams on their own and procurement teams working to a deadline will not consistently escalate AI questions either [11]. The cost of that is an extra evaluation step on every capital purchase, and answers that have to arrive before signature. For anything bought this year, Munshi wrote, the honest answer is usually "We don't know, and we signed nothing that lets us find out." [7] That gap is what the four questions are meant to close.

The calendar does not depend on his practice. The EU AI Act's high-risk obligations now take effect in December 2027 [14], about 15 months after the column ran [20]. Certain AI-enabled safety functions come into conformity assessment under the new Machinery Regulation from 2027 [16]. One of those dates is a month and the other is a year, so which obligation reaches a given plant first is not established in the column [21]. Munshi wrote that "'We didn't know the machine had a model in it' isn't a defense" [17]. That question sits underneath both deadlines, whichever lands first.

A skeptic will say this is an EY partner describing a diligence workstream he is positioned to sell, and the column leaves that skeptic room: the claim that the ungoverned estate is the bigger and faster-growing one arrives with no survey, no sample and no count [19]. Nothing in it tells a board how many adaptive models are already sitting in its own asset register. That is what makes Munshi's first step cheap to test: walk the register, flag anything with adaptive control, vision, anomaly detection or optimization, then ask the vendors directly [18].

This quarter the decision is administrative. Whose template changes, and who reviews the answers that come back. The version that costs money comes later, when a bid that answers the four questions is set against a cheaper one that does not, on the same price and delivery criteria the machine was being judged on before [5].

What to watch

  • Whether the December 2027 AI Act date moves again, or deployer duties get spelled out in detail before it.
  • Whether equipment vendors begin offering retraining notification and data-provenance terms as standard contract language.
  • Whether the Machinery Regulation's 2027 conformity assessment scope names which AI-enabled safety functions are in.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories