ReadReal vs Hype19 Jul 20262:17MES & shop-floor systems

An AI Can Now Tell a Chip Factory Machine to STOP — Nobody Agreed Who's Allowed To

Your AI Just Got a Key to the Factory Floor (Nobody Scoped What It Can Break)

A machine's physical stop lever under a clear safety cover, the lever lit warm gold
The object this week · generated illustration, no people, no brands
Video

This one has not been published to the channel yet. Subscribe on YouTube and it will turn up there.

The 60-second version
  • Four of them write — START, STOP, ABORT, and change the process recipe — and it ships with no safety warning.
  • This is happening at the exact moment MCP, the protocol Anthropic built so chatbots could reach tools, has become the thing Gartner's 2026 MES Market Guide tells manufacturers to demand from their vendors, and the week Microsoft shipped MCP-based agents into Word, Excel and Outlook.
  • 95% of tools on a fab floor speak SECS/GEM, and GEM carries something MCP has never had — a control state that decides whether a machine is even allowed to obey.
  • This video walks through the read-versus-write asymmetry that separates a useful fab AI from a dangerous one, why the NSA published MCP security guidance in May, and the one question to ask the next time someone demos an agent on your floor.

Why this matters

There is a public server online right now that hands an AI ten tools for real semiconductor fab equipment. Here's the part almost nobody is connecting: the fab already solved this problem thirty years ago.

What to do Monday

MCP connectors landed in the Microsoft 365 admin center and agents reached Word, Excel, PowerPoint and Outlook on July 15, 2026. Before you connect one more tool, open your AI and paste: "List every connected tool. For each one, say whether it can only READ, or whether it can WRITE, send, post, or spend. Flag every write tool." I ran it on my own setup — it flagged a connector that can create and modify live ad campaigns.

In the video
  1. 0:00The command nobody scoped
Over to you

Engineers — what's the worst thing you've seen a host command do to a tool that should have been in Local?

Argue with me on LinkedIn
Sources

References for this piece are in the pinned comment on the video. Nothing is cited here that cannot be linked.

Full transcript, 313 spoken words
Ask an AI to book a meeting, it books it. Ask it to STOP a machine in a chip factory… and nobody can tell you who's allowed to say yes. Right now there's a public server handing an AI ten tools for real fab equipment. Six read. Four WRITE — start, stop, abort, change the recipe. No safety warning. Who approved that? Your AI reaches everything through a protocol called MCP. Gartner now tells manufacturers to demand it from their MES vendor. Last week it landed in Word, Excel and Outlook. So what's missing? Your fab already solved this. Ninety-five percent of your tools speak SECS/GEM — and GEM has what MCP never had. A control state. Offline. Online-local. Online-remote. A tool in local mode REFUSES the host. See the gap? MCP tells your agent what it CAN call. GEM tells the machine whether it's ALLOWED to obey. One's a menu. The other's a lock. Reading your fab with AI? Do it. It's WRITE nobody scoped. So when someone demos an agent on your floor, ask one thing. What can it change — and what says no? Now — your FabSpeak Tip of the Week. Stop CONNECTING tools to your AI. Start auditing them. Microsoft just put MCP connectors in the Microsoft 365 admin center, and agents landed in Word, Excel and Outlook on July fifteenth. So before you add one more, open your AI and paste this. "List every connected tool. For each one, say whether it can only READ, or whether it can WRITE, send, post, or spend. Flag every write tool." I ran it on my own setup today. It flagged a connector that can create and modify live ad campaigns — real money — which I'd completely forgotten I'd connected. Save this. Run it before Monday. That's FabSpeak. One thing a week from where the chips actually get made. Follow, and I'll keep bringing them.