FIELD NOTE / LINKEDIN
Build OT test harnesses around faults.
The complete written thought and the evidence behind it. The video edition will follow its public release.
The written argument is here.
This approved LinkedIn edition is on the journal now. Its video player and original platform link will appear after each public release is verified.
Build OT test harnesses around faults.
Video caption
Build OT test harnesses around faults.
Generated code and generated simulation may agree incorrectly.
Requirement, build, model, bench and plant are distinct.
My rule: The acceptance packet needs independent physical claims.
#EricFieldNotes
Full written post / accessibility read
An AI-assisted PLC pipeline should be judged by how it discovers wrong physical assumptions, not by how many ladder branches it exercises. A jam-stop change needs a signed behavior contract, fault inputs, observed controller state and measured machine response under controlled commissioning.
If an agent writes the stop logic and a simulator that assumes the drive follows commands instantly, the suite can pass. The team may discover only at commissioning that motion decays differently. The harness must preserve independently written fault cases and a mismatch register.
A qualified owner signs expected normal and abnormal states. CI checks the exact vendor build. Offline models test injected faults with a deliberate negative control. An isolated bench measures controller/I-O timing. Site personnel later authorize and observe installed behavior.
Track which oracle supports each release claim and keep failures visible. Budget model fidelity, bench access and qualified commissioning when evaluating AI ROI. Do this because generated code speed matters only if the complete engineering process produces safer, accepted changes.
#EricFieldNotes
Four-beat scene transcript
1. Build OT test harnesses around faults.
An AI-assisted PLC pipeline should be judged by how it discovers wrong physical assumptions, not by how many ladder branches it exercises. A jam-stop change needs a signed behavior contract, fault inputs, observed controller state and measured machine response under controlled commissioning.
Visual: Logic-path coverage misses physical obligations.
2. A shared model can self-confirm.
If an agent writes the stop logic and a simulator that assumes the drive follows commands instantly, the suite can pass. The team may discover only at commissioning that motion decays differently. The harness must preserve independently written fault cases and a mismatch register.
Visual: Generated code and generated simulation may agree incorrectly.
3. Make each gate report its oracle.
A qualified owner signs expected normal and abnormal states. CI checks the exact vendor build. Offline models test injected faults with a deliberate negative control. An isolated bench measures controller/I-O timing. Site personnel later authorize and observe installed behavior.
Visual: Requirement, build, model, bench and plant are distinct.
4. Buy evidence, not only generated logic.
Track which oracle supports each release claim and keep failures visible. Budget model fidelity, bench access and qualified commissioning when evaluating AI ROI. Do this because generated code speed matters only if the complete engineering process produces safer, accepted changes.
Visual: The acceptance packet needs independent physical claims.
Research and claim limits
- PLCopen IEC 61131-3 (S138)
- Siemens Automation Framework documentation (S140)
- NIST: Credibility Consideration for Digital Twins in Manufacturing (S141)
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.