AI-Assisted Containment and 8D Drafting
It is 6:40 on a Tuesday morning and the quality engineer at a Tier 1 automotive stamping plant has not had coffee yet. The customer's supplier quality engineer just called: a sorting line at the assembly plant found three brackets with a hairline crack at the radius, all from the same supplier lot, and the line is about to go down. The customer wants an initial containment response in writing within twenty four hours and a full 8D, the eight discipline corrective action report the automotive world runs on, in ten working days. The quality engineer has done this before. The last time it ate two full days: pulling the traveler, reading the historian, interviewing two operators, building a fishbone from memory, writing a containment plan, drafting eight disciplines of narrative, and formatting it into the customer's template. This time he opens an AI assistant, pastes the defect description and the part history, and watches a complete 8D draft appear in ninety seconds. It looks professional. It cites a root cause. It proposes corrective actions. And here is the trap that this entire lesson is about: that beautiful draft is worth exactly nothing until a human verifies every cause and every action against the drawing, the standard, and the historian, because the customer audits the plant, not the model, and a confidently wrong root cause that ships to a customer is worse than no 8D at all.
What Containment and the 8D Actually Are
Before AI touches any of this, you have to be clear about what these documents do, because AI is only useful if you already know what good looks like. When a defect escapes, meaning it gets past your last inspection and reaches the customer or the next process, the clock starts. Two things must happen, and they happen in a specific order.
Containment comes first. Containment is the emergency response. It answers one question: where is all the suspect material right now, and how do we make sure no more of it reaches the customer? Containment is not root cause. It is a tourniquet. It includes identifying the suspect population (which lots, which date codes, which serial range), sorting or quarantining everything that might be affected at every location (your dock, in transit, the customer's dock, the customer's line, and finished goods downstream), and putting a temporary screen in place so that anything you ship from this moment forward is certified clean, often by adding a redundant 100 percent inspection. In the automotive and aerospace world this temporary screen is frequently a formal step called a controlled shipping level, where you add a separate inspection redundant to your normal process (CS1) or a third party inspection (CS2) until the customer is satisfied the problem is fixed.
The 8D comes second and runs longer. The 8D, short for Eight Disciplines, is a structured problem solving report that originated at Ford and is now the default corrective action format demanded under IATF 16949, the automotive quality management standard, and used widely in aerospace under AS9100. The eight disciplines are a checklist that forces discipline onto a panicked process:
- D1: Establish the team. Who owns this, with what cross functional members.
- D2: Describe the problem. Specific, measurable, in customer terms. What, where, when, how many, how big.
- D3: Interim containment action. The tourniquet above, with a verified effectiveness check.
- D4: Root cause analysis. The actual physics of why it happened, plus why it escaped detection. These are two separate root causes and both are required.
- D5: Permanent corrective actions chosen. The fix that addresses the root cause, with verification that it works.
- D6: Implement and validate the permanent corrective actions. Proof in production data.
- D7: Prevent recurrence. Update the control plan, the FMEA, the work instruction, the error proofing, so the same failure mode cannot return on this part or its siblings.
- D8: Recognize the team and close.
The reason this matters for AI is that each discipline is a place where a generative model can produce something that reads correctly and is factually wrong. D2 can invent a defect rate. D4 can confidently name a root cause that the historian flatly contradicts. D5 can propose a corrective action that violates the actual process capability. The skeptic reads the 8D not as prose to be admired but as a series of claims to be checked.
Where AI Genuinely Saves Time
The honest case for AI here is strong, and you should not pretend otherwise. Roughly 85 percent of manufacturers say staffing shortages are hurting product quality, and the quality engineer in the cold open is doing the work of what used to be two people. The 8D is a document that is roughly 70 percent structure and formatting and 30 percent genuine engineering judgment. AI is excellent at the 70 percent and dangerous at the 30 percent, and the entire skill is keeping those two halves separate.
Consider the worked numbers. A thorough 8D, done from scratch in a template the customer dictated, takes an experienced quality engineer somewhere between six and sixteen hours spread across the ten day window, and a green engineer longer. The structural drudgery inside that, the parts AI handles well, is real and large:
Assembling the narrative scaffold. Turning a pile of notes (a phone call, a sorting report, two operator statements, a historian export) into a clean D2 problem statement in the is and is not format that good problem solving demands. This alone can save two to three hours, because writing a tight, customer readable problem description is genuinely hard and AI does first drafts of it well.
Formatting into the customer template. Every customer has a different 8D form. AI maps your content into their structure in seconds, a task that otherwise eats forty five minutes of copy, paste, and reformat.
Drafting the containment communication. The twenty four hour initial response letter to the customer, written in calm, professional, non incriminating language, is something AI drafts in under a minute. For a stressed engineer at 6:40 in the morning, that draft removes the blank page problem entirely.
Generating candidate causes for the fishbone. Given a defect description, AI can enumerate plausible failure modes across the six classic fishbone branches (machine, method, material, measurement, man, environment), which is useful as a brainstorming prompt that keeps a tired team from anchoring on the first idea.
Add it up and AI can compress the six to sixteen hour task by roughly four to six hours of pure structural work. At a loaded quality engineering cost of around 75 dollars an hour, that is 300 to 450 dollars of labor per 8D, and a plant that runs forty 8Ds a year is looking at real five figure annual savings. That is the genuine, defensible upside, and it is worth having.
AI drafts the 8D. The engineer owns the 8D. The customer audits the engineer, never the model.
The Three Things AI Will Confidently Get Wrong
Now the dangerous 30 percent. There are three specific failure modes, and a quality engineer who internalizes these three has most of the skill. Each one is a place where the draft will look completely convincing and be completely false, because a generative model is built to produce fluent, plausible text, not to produce true text. It has no access to your historian, your drawing, or your gauge study unless you give it to it, and even then it will sometimes override what you gave it with what sounds right.
Failure mode one: the invented number
You ask the AI to write the D2 problem statement and it produces: "Three cracked brackets were found at the customer, representing a defect rate of 1,200 parts per million across the affected lot of 2,500 pieces." Read that again. Where did 1,200 PPM come from? Where did the lot size of 2,500 come from? You never told it the lot size. The model generated a number that is dimensionally plausible and entirely fabricated. If the real lot was 8,000 pieces, the real escape rate, the sorting result, and the entire severity assessment are wrong, and you just put a fabricated figure into a document the customer will hold you to. Every number in an AI drafted 8D is a fabrication until you trace it to a source: the traveler, the historian tag, the sorting report, the gauge study. The defect count, the lot size, the PPM, the date codes, the torque values, the dimensional readings, the cycle counts. All of them.
Failure mode two: the confidently wrong root cause
This is the most dangerous one. You describe a hairline crack at a stamping radius and the AI writes a fluent D4: "Root cause: insufficient die radius causing excessive strain at the bend, compounded by material outside specification for tensile strength." It sounds like a textbook. It might even be a real failure mode for this kind of defect in general. But it is a guess dressed as a conclusion. The actual root cause, which only your historian and your incoming inspection records can tell you, might be that a die wear condition crept in over the last 3,000 hits and the press tonnage trend in the historian shows it climbing, or that the coil supplier changed and the certs show a hardness shift, or that a heater on the line failed on a cold morning and the material was below forming temperature. The AI cannot know which. It will pick the most statistically common cause from its training and state it with total confidence. If you ship that as your root cause and it is wrong, you implement a corrective action that fixes nothing, the defect returns, your customer escalates you to controlled shipping level 2, and the cost of that escalation, third party sorting at the customer plus your reputation, runs into the tens of thousands of dollars. A wrong root cause is not a neutral error. It actively sends the corrective action in the wrong direction.
Failure mode three: the missing escape point
A proper D4 has two root causes, not one. The occurrence root cause (why was the defect made) and the escape root cause (why did our inspection not catch it). AI, asked for a root cause, almost always gives you only the occurrence side and silently drops the escape side. But the escape side is often where the real corrective action lives, and it is the part the customer scrutinizes hardest, because the customer's pain is that your screen let it through. If your final inspection should have caught a radius crack and did not, the escape root cause might be that the inspection is visual only and a hairline crack is below the threshold of reliable human detection on a cold afternoon when the inspector is short staffed. That points to a completely different and more valuable corrective action, possibly a dye penetrant check or a vision system, than the occurrence fix. An 8D with only an occurrence root cause is an incomplete 8D, and AI will hand you incomplete D4s by default unless you explicitly force both.
The Verification Workflow That Makes AI Safe Here
The discipline that turns a dangerous draft into a defensible document is a fixed workflow. It mirrors the principle from the rest of this program: the job shifted from producing the draft to verifying the draft against the drawing, the standard, and the historian. Here is the four stage version specific to containment and 8D.
Stage one: feed the model real evidence, not the blank page. The quality of the draft depends entirely on what you give it. Do not ask "write an 8D for a cracked bracket." Paste the actual sorting report, the relevant historian export (press tonnage, temperature, cycle count for the affected window), the traveler, the incoming material cert, and the two operator statements. The more real evidence in, the less the model has to invent. You are not asking it to know things; you are asking it to organize things you already know. Where the evidence does not exist yet, mark that gap explicitly so it shows up as an open item, not a fabricated fact.
Stage two: verify every claim against a source, line by line. Read the draft as a hostile auditor. For each number, write next to it the source: "1,200 PPM, confirmed against sorting report dated 6/20." If you cannot find the source, the number is deleted or flagged as to be confirmed. For each root cause, ask the killer question: what evidence in the historian or the records supports this, and what evidence contradicts it? A root cause that cannot point to a historian trend, a cert, a gauge result, or a physical examination is a hypothesis, and a hypothesis does not go in D4. This is the stage where the press tonnage trend either confirms die wear or kills the AI's tensile strength theory.
Stage three: force the second root cause and test the corrective action against capability. Explicitly check that D4 has both an occurrence and an escape root cause. Then take each proposed corrective action in D5 and ask whether it is physically and statistically achievable on your actual process. If the AI proposes "tighten the radius tolerance to plus or minus 0.05 millimeters" but your process capability study shows the line cannot hold tighter than plus or minus 0.12, that corrective action is fiction and will fail D6 validation. The corrective action must be verified against the drawing tolerance and the real process capability, not against what sounds rigorous.
Stage four: a named human signs it. The 8D goes out under a person's name and that person owns every word. The customer's auditor will ask, in the audit, "walk me through how you arrived at this root cause," and "the AI suggested it" is the one answer that fails the audit instantly. The signer must be able to narrate the evidence chain for every discipline as if they had written it by hand, because in the way that matters, they did: they verified it. Log that the draft was AI assisted and human verified, with the verifier named and dated, the same way you would log any controlled document. That log is your evidence, in any future audit, that a human took accountability before the document reached the customer.
A Worked Example, Start to Finish
Return to the cracked brackets and walk the whole loop so the abstract rules become concrete. The defect: three brackets, hairline crack at the forming radius, found at the customer's sorting line, all marked from lot code stamped on the part.
The AI first draft produces a clean D2 ("3 cracked brackets, 1,200 PPM across a 2,500 piece lot"), a confident D4 ("insufficient die radius and out of spec material tensile strength"), and a D5 ("redesign die radius and implement incoming tensile testing"). Ninety seconds. Looks great.
Stage two verification. The engineer pulls the actual records. The lot was 6,400 pieces, not 2,500, so the PPM figure is fabricated and the real escape rate is different; that number is corrected against the traveler. He pulls the incoming cert for the coil: tensile strength is well within spec, so the AI's material theory is dead on arrival. Then he opens the historian and trends press tonnage for the lot's production window. Tonnage climbed roughly 8 percent across the shift and a die maintenance record shows the trim die was last serviced 11,400 hits ago against a 10,000 hit PM interval. The real occurrence root cause is die wear that was overdue for service, fully supported by the tonnage trend and the maintenance log, and it has nothing to do with the radius design or the material the AI confidently blamed.
Stage three. The AI's draft had no escape root cause at all. The engineer adds it: final inspection is visual only, and a hairline crack at the radius is at the edge of reliable visual detection, especially with the line one inspector short on nights. Now D4 is complete with both causes. The corrective actions change completely as a result. The occurrence fix is a tightened die PM interval tied to a tonnage trend alarm in the historian, not a die redesign. The escape fix is adding a dye penetrant check at the radius during containment and evaluating a low cost vision check for permanent prevention. He checks the die PM change against the maintenance schedule and the tonnage alarm threshold against historian data: both are achievable, so they will survive D6 validation.
Stage four. The engineer signs it, and in the document control system the record notes AI assisted draft, human verified by name on date, with the historian export and the cert attached as evidence. When the customer's SQE reviews it three days later and asks how the root cause was determined, the engineer pulls up the tonnage trend and the PM log and walks it line by line. The audit passes. Total time: about three hours instead of two days, with a root cause that is actually correct. That is the entire promise of the skill: the speed of the draft plus the truth of the verification, and never one without the other.
Prompting the Model So It Lies Less
You can structure the request so the draft is less dangerous to begin with, which makes verification faster. None of this replaces verification; it just reduces the volume of fabrication you have to catch. A few floor tested moves:
- Forbid invented facts explicitly. Tell the model: use only the data I provide; where a value is unknown, write TO BE CONFIRMED rather than estimating. This single instruction kills most invented numbers, because you have given it permission to leave a blank instead of filling it with a plausible guess.
- Demand the evidence column. Ask for the 8D as a table where every claim has an adjacent cell naming the source record. Claims that the model cannot source will show up as blanks, which is exactly the visibility you want.
- Force both root causes. Require D4 to contain a separately labeled occurrence root cause and escape root cause, each with supporting evidence. If it cannot fill the escape side from your data, it must say so.
- Make it list what it does not know. End the prompt with: list every assumption you made and every piece of data you would need to confirm the root cause. This turns the model's guesses into a visible checklist of verification tasks instead of hiding them inside confident prose.
- Keep it advisory on the conclusion. Ask for candidate root causes ranked with the evidence each would require, not a single declared root cause. The declaration is the human's job after checking the historian.
The pattern across all of these is the same: configure the model to surface uncertainty instead of papering over it. A draft that says TO BE CONFIRMED in eight places is far safer than a draft that fills those eight places with confident fiction, because the first one tells you exactly where to look and the second one waits to embarrass you in front of the customer.
Key Takeaways
- Containment is the tourniquet and comes first: find and quarantine all suspect material everywhere it sits, and put a temporary 100 percent screen or controlled shipping level in place before you ever touch root cause. The 8D is the longer corrective action report that follows.
- An 8D is roughly 70 percent structure and 30 percent engineering judgment. AI is genuinely good at the structure (problem statement scaffolding, template formatting, the containment letter, candidate causes) and can compress a six to sixteen hour task by four to six hours, worth 300 to 450 dollars of labor per report. AI is dangerous at the judgment.
- Three failure modes recur: the invented number (lot sizes, PPM, torque values the model fabricates), the confidently wrong root cause (the most common cause from training, stated as fact, that your historian contradicts), and the missing escape root cause (AI gives only occurrence and silently drops the escape side that the customer scrutinizes hardest).
- Every number in an AI drafted 8D is a fabrication until traced to a source: the traveler, the historian tag, the sorting report, the cert, the gauge study. Verify each one, line by line, as a hostile auditor would.
- A complete D4 has two root causes: occurrence (why it was made) and escape (why inspection missed it). AI defaults to one. Force both, because the escape root cause often points to the highest value corrective action.
- Every corrective action must be verified against the drawing tolerance and the real process capability study. A fix that the line cannot physically hold will fail D6 validation and the defect will return.
- A wrong root cause is worse than no 8D: it sends corrective action in the wrong direction, the defect recurs, and the customer can escalate you to controlled shipping level 2, where third party sorting and lost trust run into the tens of thousands of dollars.
- A named human signs the 8D and must be able to narrate the evidence chain for every discipline in the customer audit. "The AI suggested it" fails the audit instantly. Log every AI assisted document as human verified, with the verifier named and dated, because the customer audits the plant, not the vendor.
Skill.re