Silicon Wafer EngineeringFuture of AI & Visionary Thinking
Decentralised autonomy in silicon wafer engineering: which fab decisions can safely leave the centre
Decentralised autonomy in a wafer fab is the deliberate placement of decision authority at the smallest scope that holds every constraint the decision touches — a chamber, a tool, a bay — instead of at a central scheduler. It is a governance design before it is an AI design, and the physics of the process decides most of it.

Key takeaways
- Decentralised autonomy is a question about authority, not about intelligence. The interesting variable is not how clever the local model is but which decisions it is permitted to make alone, inside what bounds, and who finds out afterwards. A fab can buy every model on the market and change nothing about where decisions are made.
- A decision can only be devolved to a scope that holds all of its constraints. Chamber-level run-to-run correction is local physics and devolves cleanly. Reticle movement, Q-time rescue and hot-lot priority couple across bays, so devolving them without an arbitration layer does not distribute authority — it distributes conflict.
- The fab is already the most decentralised factory in manufacturing, and always was. Interlocks, equipment state machines, FDC holds and AMHS routing have executed without a central decision for decades. What has not moved in thirty years is the layer above them: the cross-fab production-control decisions that, as Flexciton puts it in its published material, no MES handles and no scheduler touches.
- The published record does not show negotiating agents running fabs. It shows centralised data architectures and control towers — Bosch’s Dresden fab describes fully connected systems within a centralised data architecture, GlobalFoundries publishes a global factory control tower — with autonomy at the execution layer beneath them. Multi-agent control is a mature research literature and a thin deployment record.
- Future-readiness here is almost entirely present-readiness. Nothing in a 2035 vision of a self-coordinating fab is reachable without three artefacts a fab can build this quarter: a written authority envelope per decision, a live constraint feed that tells the edge what it must respect, and a reconciliation trail good enough for a customer’s process-change audit.
Abbreviations used on this page
- MES
- Manufacturing execution system — the fab’s system of record for lots and steps
- APC
- Advanced process control
- R2R
- Run-to-run control — the per-run feedback loop on a tool
- FDC
- Fault detection and classification
- EDA
- Equipment Data Acquisition — the SEMI “Interface A” standards suite
- GEM
- Generic Equipment Model (SEMI E30, carried over SECS-II)
- AMHS
- Automated material handling system — the overhead carrier transport
- FOUP
- Front-opening unified pod — the 300 mm wafer carrier
- WIP
- Work in progress — lots currently on the line
- Q-time
- Queue time — the maximum permitted interval between two linked process steps
- SPC
- Statistical process control
- PCN
- Process change notification — the contractual notice a fab owes a customer before a qualified process changes
Free · 8 questions · ~3 minutes
Score where your fab’s decision authority actually sits
Eight questions, one at a time, about three minutes. Answer them and we build your personalised devolution report — your rung on the ladder, your score on each of the four dimensions, and the specific constraint holding authority at the centre — and send it to your inbox. Score one bay or one toolset rather than the whole fab; the answers are sharper.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised devolution report is ready
Tell us where to send it. Your rung appears on screen straight away, and the full report — dimension scores, the decisions in your area that are devolvable today, and a 90-day plan for the weakest dimension — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Central command
Every non-safety decision is made on the central plane’s cadence; the bay and the tool execute and report.
Your next moveEnumerate the fab’s recurring decisions and, for each, record who makes it today, on what cadence, and what it couples to. Do not automate anything yet.
Stage 2 · Sensing edge
Local intelligence can see but cannot act: tool and bay models raise signals that a human or the central plane must act on.
Your next movePick one existing local model and negotiate the narrowest possible authority envelope for it — one decision, one bay, a hard budget, and a one-switch revert.
Stage 3 · Bounded local authority
Named decisions execute locally inside a written envelope, with global constraints fed down live and every local action reconciled into the record.
Your next moveIdentify the shared resources your devolved decisions are already competing for, and give them an explicit arbitration primitive instead of a phone call.
Stage 4 · Negotiated autonomy
Local decision-makers hold rights over scarce shared resources and obtain them through an explicit arbitration protocol rather than a central plan.
Your next moveDefine degraded-mode behaviour explicitly — what each scope may decide when it cannot reach the arbiter, and for how long — and rehearse it.
Stage 5 · Federated line
Authority is federated across bays and sites under versioned policy, with defined and rehearsed behaviour when the central plane is unreachable.
Your next moveTreat envelopes, invariants and partition rules as one versioned, reviewable policy artefact, and rehearse the partition on a schedule.
0 / 24
Decision rights
— / 6
Constraint propagation
— / 6
Arbitration & contention
— / 6
Reconciliation & evidence
— / 6
Your score maps to a rung on the devolution ladder. Read the dimension breakdown before the total: the lowest dimension is the one actually capping you, and in most fabs it is constraint propagation rather than decision rights — the fab is willing to devolve and has nothing to devolve with. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a rung on the devolution ladder. Read the dimension breakdown before the total: the lowest dimension is the one actually capping you, and in most fabs it is constraint propagation rather than decision rights — the fab is willing to devolve and has nothing to devolve with.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want this run against your actual decision list?
We sit with your industrial engineering, production control and quality leads, walk your real recurring decisions through the authority map on this page, and leave you with a marked-up register: what is devolvable now, what needs a constraint feed first, and what should stay central permanently. You keep the register either way.
How the score maps to a stage
- 0–4 — Stage 1, Central command. Every non-safety decision is made on the central plane’s cadence; the bay and the tool execute and report.
- 5–10 — Stage 2, Sensing edge. Local intelligence can see but cannot act: tool and bay models raise signals that a human or the central plane must act on.
- 11–16 — Stage 3, Bounded local authority. Named decisions execute locally inside a written envelope, with global constraints fed down live and every local action reconciled into the record.
- 17–21 — Stage 4, Negotiated autonomy. Local decision-makers hold rights over scarce shared resources and obtain them through an explicit arbitration protocol rather than a central plan.
- 22–24 — Stage 5, Federated line. Authority is federated across bays and sites under versioned policy, with defined and rehearsed behaviour when the central plane is unreachable.
What decentralised autonomy in a fab actually means
A definition, the difference between devolving execution and devolving authority, and the three planes a fab decision can be made on.
Decentralised autonomy in a wafer fab means moving the authority to decide — not the ability to compute — down to the smallest scope that holds every constraint the decision touches. That is a deliberately narrow definition, and the narrowness is the point. A tool that runs a large model locally has decentralised computation. A tool that may place a hold without asking has decentralised authority. Only the second changes how the fab behaves, and only the second requires anyone to write anything down.
The distinction matters because fabs have been quietly decentralising execution for thirty years while centralising authority just as steadily. Interlocks abort a run without consulting anything. Equipment state machines transition on their own. Automated material handling routes carriers continuously without a person choosing a path — GlobalFoundries publishes (opens in a new tab) that its overhead transport delivers as many as 10,000 carrier moves a day in a single fab. Meanwhile the decisions above that layer — what to start, what to hold, what to expedite, what to measure — have concentrated into central planning and dispatch systems, and into the heads of the people who operate them.
So the vision usually described as “the decentralised fab” is not a break with fab history; it is the resumption of an old trend at a layer that has been stuck. It also has a hard ceiling that no amount of model capability moves, because a decision cannot be devolved to a scope that cannot see its own constraints. The diagram below is the whole argument in one picture: three planes, and the observation that what travels down from the centre in a devolved fab is a constraint, not an instruction.
Where a fab decision is actually made — the three planes
The vertical axis is authority, not time. At rung 1 the central plane sends instructions and the bay plane is empty. From rung 3 the central plane sends envelopes and constraints instead, the bay plane decides inside them, and the central plane’s remaining jobs are arbitration, invariants and the record. The tool plane has been autonomous since long before anyone called it that.
- Data & feeds
- Human in the loop
- AI / model
- System-of-record action
- Where value leaks
The process, in words
- The central plane holds the fab state of record — WIP, queue-time clocks, dedication rules, the reticle map — and, in a devolved fab, stops using it to write instructions. Instead it issues two things downward: a versioned authority envelope stating what each scope may decide and within what bounds, and a live constraint feed carrying the global facts a local decision must respect. It keeps three jobs for itself: arbitrating contended resources, enforcing invariants no local scope may cross, and reconciling every devolved action back into the record.
- The bay plane is where rungs 3 to 5 actually live, and at rungs 1 and 2 it is empty. A bay decision agent takes tool traces from below and constraints from above and decides in seconds rather than on the central re-plan cadence — sampling, holding, releasing, routing. When it needs something scarce it asks the arbiter for a bounded, expiring lease rather than escalating to a person. When a decision falls outside its envelope it escalates, and the escalation is the safety valve rather than a failure of the design.
- The tool plane has been autonomous since long before the word was fashionable. Equipment controllers execute moves and hold run-to-run offsets; interlocks and equipment safety systems can veto anything above them, locally and instantly, and are never part of a negotiation. Any architecture that proposes to make safety interlocks smart, remote or negotiable has misunderstood which decisions were already decentralised and why.
- Read across the diagram and the shape of the whole page appears: what moves down is constraints, what moves up is evidence, and the central plane trades the power to instruct for the power to bound. That trade is the entire content of decentralised autonomy in a fab.
Step-by-step insights
- Fab state of record — the thing you cannot devolve
- Every devolved decision is a bet that the local scope knows enough. The fab state of record is what makes that bet reasonable: one authoritative version of where lots are, which queue timers are running, which tools are qualified for which layers, and where each reticle physically is. Fabs that try to devolve before this exists end up with bays deciding confidently against divergent pictures of the same line, which is worse than a slow central plan because the disagreement is invisible. Nothing on the ladder above rung 2 is reachable without a single, current, authoritative state.
- The authority envelope — a delegation, written like one
- An envelope names the decision, the scope permitted to make it, the numeric bounds, the preconditions that suspend it, the budget it consumes and the revert. It reads like a delegation of authority in an organisation because it is one, and the useful test is whether a new shift supervisor could read it and know exactly what the bay may do at 3am without calling anyone. Envelopes are short — a page — and their value comes entirely from being versioned and reviewed, because the question a customer audit asks is not what the bound is now but what it was then.
- The constraint feed — where devolution usually fails
- Devolving a decision blinds the deciding scope to everything outside it, so the global facts it must respect have to be pushed down continuously with an explicit freshness guarantee. Queue timers are the canonical example and the canonical failure: a bay choosing what to run next cannot know a lot is forty minutes from a queue-timer breach unless the clock is fed to it. Flexciton has published technical material specifically on why queue timers defeat conventional schedulers, and the reason generalises — Q-time couples two steps that no single scope owns. Stale feed, suspended decision: that rule is cheap to implement and it is the difference between devolution and an unmonitored guess.
- The arbiter — small, boring and load-bearing
- The arbiter is deliberately not a planner. It does one thing: grants bounded, expiring leases on genuinely scarce shared resources, and refuses with a reason and an expiry so the refused scope can plan around it. Leases degrade well under failure — an expired lease returns the resource automatically, and a partitioned agent cannot hold one indefinitely. Keeping the arbiter small also keeps it auditable: its entire behaviour is a log of grants and refusals, which is a far easier artefact to defend than a full optimisation trace.
- Escalation as a designed output, not an exception
- The most common design error in devolved systems is treating escalation as failure and tuning it toward zero. The escalation rate is a signal: it measures how often the world falls outside the envelope, and a rising rate means conditions have moved beyond the envelope’s validity — a new product mix, a requalified toolset, a changed dedication map. Fabs that suppress escalations lose their early-warning system and discover the drift as an excursion instead. Budget for escalations, staff for them, and watch the trend rather than the count.
- Reconciliation — the audit trail as a by-product
- Every devolved action must land in the MES record with its inputs, its envelope version and, where relevant, the arbiter’s grant. At rung 3 this looks like engineering hygiene. By rung 5 it is the artefact a customer’s change-control audit examines, because in a qualified process the rule that decided is part of the process. Building reconciliation as a by-product of the action path — rather than as a reporting job that runs later — means the evidence accumulates for free and the audit becomes an export rather than a project.
One consequence follows immediately and it is worth stating before the ladder, because it reframes the whole topic. If what the centre sends down is a constraint rather than an instruction, then the quality of a fab’s decentralisation is bounded by the quality of its central state. Decentralised autonomy is not the opposite of a strong central plane — it is what a strong central plane buys you. That is why the fabs with the most publicly documented automation are also the ones describing, in their own material, a highly centralised data architecture.
The five rungs of the devolution ladder
For each rung: what it looks like on the floor, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps fabs there, and what leaving costs.
The ladder measures one thing only: how much decision authority has left the centre, safely. It is not a measure of how much AI a fab runs, and a fab can score highly on every other maturity model in this knowledge base while sitting at rung 2 here. Each rung below is written for a practitioner — the hallmarks are observable conditions, the diagnostic signals are checks you can run against your own systems this week, and the anti-pattern is the specific mistake most often made trying to leave that rung.
Decision authority safely devolved, against time on the ladder
The curve is flat through rungs 1 and 2 because sensing is not deciding: a fab can add local models for years and devolve nothing. It inflects at rung 3, when the first written envelope makes a bay’s decision real, and again at rung 4, when arbitration lets several devolved decisions coexist without a person resolving them. It also has an asymptote, which most visions of the autonomous fab omit — a permanent set of decisions that correctly stay central forever.
Decision authority safely devolved by stage
- Stage 1 · Central command — 31% of operators. Every non-safety decision is made on the central plane’s cadence; the bay and the tool execute and report.
- Stage 2 · Sensing edge — 42% of operators. Local intelligence can see but cannot act: tool and bay models raise signals that a human or the central plane must act on.
- Stage 3 · Bounded local authority — 19% of operators. Named decisions execute locally inside a written envelope, with global constraints fed down live and every local action reconciled into the record.
- Stage 4 · Negotiated autonomy — 7% of operators. Local decision-makers hold rights over scarce shared resources and obtain them through an explicit arbitration protocol rather than a central plan.
- Stage 5 · Federated line — 1% of operators. Authority is federated across bays and sites under versioned policy, with defined and rehearsed behaviour when the central plane is unreachable.
Curve shape: logistic, plotted from the stage data above. Distribution: Illustrative shape, consistent with published material on the path to fab autonomy.
Select a rung
Every rung’s full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Central command
31% of operators sit here
Every non-safety decision is made on the central plane’s cadence; the bay and the tool execute and report.
Rung 1 is not primitive. A great many high-yielding fabs run here deliberately, and the reasoning is sound: a central plane can see the whole line, so it can trade off Q-time links, bottleneck loading and customer commitments in one place, and one place is far easier to qualify than fifty. Centralisation is a legitimate architecture, not a failure state.
What makes rung 1 costly is not centralisation but cadence. The central plane re-decides on a fixed rhythm — every fifteen minutes, every half hour, every shift — while the fab throws up events on the timescale of seconds. A chamber goes down, a carrier arrives early, a metrology result comes back out of trend, and the fab spends the remainder of the interval executing a plan that was true when it was computed and is not true now. The gap between those two clocks is where every rung-1 fab loses time, and it is invisible on any dashboard because the plan was followed correctly.
The tell is not technological, it is documentary. Ask for the list of decisions a bay may make without asking. At rung 1 there is no such list — not because nobody has written it down, but because nobody has ever needed to: every answer is “ask production control”. That absence is the thing that has to change first, and it costs nothing but argument.
In practice
The twenty-minute-old dispatch list
A 200 mm fab issues a fab-wide dispatch list on a twenty-minute cycle. Nine minutes in, an etch chamber goes down on an FDC alarm. The list still shows four lots routed to it. The bay technician knows within a minute; production control learns when the next cycle recomputes; the lots sit. Nothing in the system is broken, no rule was violated, and the fab has just spent eleven minutes executing a plan built for a fab that no longer exists.
What it looks like
- The dispatch list is the decision — tools and operators execute it as issued
- Local models, where they exist at all, are reporting artefacts rather than actors
- The only decisions genuinely made at the edge are interlocks and equipment state transitions
- Nobody can produce a written statement of which decisions a bay is allowed to make
Diagnostic signals you can check this week
- Ask for the written list of decisions a bay may make alone. If there is none, you are here
- Measure the interval between central re-plans, then measure the mean time between events that invalidate a plan. Compare the two numbers
- Watch what happens on a tool-down: count the minutes before the plan reflects it
- Ask a shift supervisor how a priority conflict is resolved at 3am. If the answer names a person rather than a rule, authority is undocumented
Anti-pattern · Buying agents before writing the decision rights
The instinctive response to rung 1 is to procure something agentic — an edge platform, a multi-agent scheduler, an on-tool inference stack. It fails in a predictable way: the software arrives able to decide, and the organisation has no statement of what it is allowed to decide, so it is deployed in advisory mode “until we are comfortable”. Advisory mode is rung 2, and fabs stay there for years. Write the decision rights first. It is a document, it costs a fortnight of arguments between industrial engineering, process and quality, and it is the artefact every later rung depends on.
What holds you here
No decision has a written owner or a written bound, so nothing can be devolved without an argument that has to be had from scratch every time.
Highest-leverage next move
Enumerate the fab’s recurring decisions and, for each, record who makes it today, on what cadence, and what it couples to. Do not automate anything yet.
Cost of leaving
- Effort
- 4–8 weeks
- Team
- One industrial engineer, one production-control lead, one quality representative — part time
- Risk
- Very low — the output is a document, and nothing in production changes
- To next stage
- 3–6 months
If this is you, the next step is
A two-week working session: enumerate the decisions, agree the scopes, mark what is already devolved.
Stage 2
Sensing edge
42% of operators sit here
Local intelligence can see but cannot act: tool and bay models raise signals that a human or the central plane must act on.
Rung 2 is the mode of the industry and the most comfortable place on the ladder to get stuck. Local models exist, they are often genuinely good, and they produce a stream of signals nobody disputes. What they do not have is standing. The model can observe that chamber 4’s endpoint trace has shifted; it cannot hold chamber 4, because holding a chamber is a capacity decision and capacity decisions belong to production control.
The structural problem is that rung 2 optimises the wrong quantity. Every quarter of effort goes into raising the sensitivity and specificity of local detection, because that is the tractable engineering problem, and none goes into the question that determines whether detection matters: how long between the signal and the action, and who is in the loop. A fab can halve its false-alarm rate and change nothing about the time-to-action, because the time-to-action is set by shift handover and a ticket queue.
Time spent at rung 2 is not neutral. Engineers learn that local signals are advisory, so they stop reading them; production control learns that the models cry wolf, so it discounts them; and the next proposal for local authority is argued against that memory. The organisational antibodies are the real cost, and they are why a fab that has sat at rung 2 for five years is usually harder to move than one still at rung 1.
In practice
The alarm that everyone had already seen
A diffusion bay runs an FDC model that flags a slowly drifting temperature profile on one furnace tube. It fires on a Tuesday. The alarm goes to a queue reviewed at the Thursday process meeting, where an engineer confirms the drift and raises a work request; the tube is corrected the following Monday. Six days of wafers went through with a known, detected, unacted-upon deviation. Nobody behaved incorrectly. The model’s accuracy was never the constraint.
What it looks like
- FDC, health and quality models run at the tool or the bay and generate alarms
- Every model output terminates in a screen, a ticket or a chart
- Model quality is debated far more often than model authority
- The escalation path from a local signal to an action is human and undocumented
Diagnostic signals you can check this week
- Take one local alarm and time it end to end: signal raised, human aware, action taken. Do it for three alarms and take the worst
- Ask what the model is allowed to do if nobody responds. If the answer is “nothing”, authority is the gap, not accuracy
- Count how many local models write anything at all into the MES. At rung 2 the answer is usually zero
- Check whether alarm volume per shift exceeds what one engineer can triage. Above that line, the signals are decorative
Anti-pattern · Improving detection to earn authority
When local signals are ignored, the reflex is to make them better, on the theory that trust follows precision. It does not, because the bottleneck is not belief — it is standing. A model with an 80% precision that is permitted to place a two-hour engineering hold changes more wafers than a 97%-precision model that can only raise a ticket. Spend the next quarter negotiating a narrow, bounded, revertible authority for one existing model, and revisit detection quality once you can price a false alarm in lost tool hours rather than in reviewer irritation.
What holds you here
Local intelligence has no standing: every signal must pass through a human queue, so the fab’s response time is set by shift rhythm rather than by the physics.
Highest-leverage next move
Pick one existing local model and negotiate the narrowest possible authority envelope for it — one decision, one bay, a hard budget, and a one-switch revert.
Cost of leaving
- Effort
- 3–6 months
- Team
- One integration engineer, one process engineer, a named quality owner for the envelope
- Risk
- Medium — the first bounded local action needs a documented revert and a qualification review
- To next stage
- 6–12 months
If this is you, the next step is
We take a model you already run and design the narrowest envelope that makes it act.
Stage 3
Bounded local authority
19% of operators sit here
Named decisions execute locally inside a written envelope, with global constraints fed down live and every local action reconciled into the record.
Rung 3 is the first rung at which anything has genuinely been decentralised, and the artefact that makes it real is not the model — it is the envelope. An envelope is a short, versioned, reviewable document that says: this bay may place engineering holds on this toolset, up to four hours, up to two chambers concurrently, provided no lot in the bay has less than ninety minutes of Q-time remaining, and every hold is written to the MES within thirty seconds. That is the whole idea. It reads like a delegation of authority because that is exactly what it is.
The second artefact is the constraint feed, and it is the one fabs consistently underestimate. Devolving a decision means the deciding scope no longer sees the whole line, so anything global it must respect has to be pushed to it, live, with a freshness guarantee. Q-time remaining is the canonical case: a bay agent choosing what to run next cannot know that the lot in front of it is forty minutes from a queue-timer breach unless the clock is fed to it. A devolved decision made against a stale constraint is not autonomy, it is an unmonitored guess with a fast response time.
The character of the work at rung 3 is closer to operations engineering than to data science. What is the freshness SLA on the constraint feed? What happens if it goes stale — does the agent fail open, fail closed, or fail to the previous rule? Who is paged? These are boring, answerable questions with well-established answers, and answering them is what distinguishes a fab that devolves safely from one that devolves loudly.
In practice
The four-hour hold envelope
An etch bay is granted authority to hold a chamber for up to four hours on an FDC excursion, capped at two chambers at once, suspended automatically whenever the bay’s queue-time exposure exceeds a stated threshold. In the first quarter the bay used it forty-one times. Nine of those holds were later judged unnecessary by process engineering — and the argument that settled the review was not whether the model was right, but that the total capacity cost of the nine false holds was a fraction of the cost of one excursion caught six days late.
What it looks like
- A versioned envelope states which decisions a bay may make and within what numeric bounds
- The constraint feed pushes live Q-time remaining, dedication and budget state to the edge
- Every devolved action lands in the MES record with its inputs and its envelope version
- There is a tested revert to the previous decision source, and it has been exercised
Diagnostic signals you can check this week
- Ask to see the envelope. If it is a slide rather than a versioned document with an owner, it is not an envelope
- Check the constraint feed’s freshness alarm. If there is none, the devolved decision is running blind on its worst day
- Sample ten devolved actions from last month and try to reconstruct each from the MES record alone
- Ask when the revert was last exercised. “We have never needed to” means it is untested, not that it works
Anti-pattern · Widening the envelope by ticket
Envelopes creep. A hold cap of four hours becomes eight because a specific incident made eight seem sensible, and the change is made in a configuration screen by a person with the access to make it. Six months later nobody can say what the bound was in March, which is precisely the question a customer’s process-change audit asks. Treat the envelope as a controlled document: versioned, reviewed by the same forum that reviews a recipe change, with the version identifier stamped on every action taken under it.
What holds you here
Each devolved decision is negotiated, documented and monitored separately, so the fourth costs as much as the first and contention between them is still resolved by people.
Highest-leverage next move
Identify the shared resources your devolved decisions are already competing for, and give them an explicit arbitration primitive instead of a phone call.
Cost of leaving
- Effort
- 6–12 months
- Team
- Integration engineer, process engineer, industrial engineer, quality owner, plus a standing review forum
- Risk
- Medium — the exposure is qualification and change control, not model error
- To next stage
- 12–24 months
If this is you, the next step is
One decision, one bay: the bounds, the constraint feed, the revert and the audit record.
Stage 4
Negotiated autonomy
7% of operators sit here
Local decision-makers hold rights over scarce shared resources and obtain them through an explicit arbitration protocol rather than a central plan.
Rung 4 is where decentralisation stops being an efficiency argument and becomes an architecture. Once several bays hold real authority, they start wanting the same things at the same time: the same reticle, the same metrology slot, the same technician, the same batch furnace load, the same overhead vehicle on the same track segment. At rung 3 those collisions are resolved by escalation, which is a polite word for a person on a radio. At rung 4 they are resolved by a protocol.
The protocol does not have to be exotic. The useful primitive is a lease: a scope requests a contended resource, an arbiter grants it for a bounded period under stated conditions, and the lease expires whether or not it was used. Leases are attractive precisely because they degrade well — an expired lease returns the resource, a partitioned agent cannot hold one forever, and the arbiter’s decisions are a small, auditable log rather than a full plan. The academic lineage here is long: holonic manufacturing control has been formalising exactly this trade-off between local autonomy and global coherence for over two decades.
What is genuinely hard at rung 4 is not the protocol but the objective. Local scopes optimise what they can see, and what they can see is their own tool group. The published evidence that this is a real effect rather than a worry is unusually direct: recent work analysing joint versus modular learning for job-shop scheduling with transport resources measures the coordination gap between them explicitly. A fab arriving at rung 4 has to decide what the arbiter is protecting — line balance, Q-time integrity, on-time delivery — and encode that as invariants the local scopes cannot bid their way around.
In practice
The reticle nobody could book
Two litho bays in a fab with devolved lot selection both hold work needing the same reticle within the same hour. Under rung 3 the conflict surfaces as two engineers escalating simultaneously and a supervisor picking. Under rung 4 both bays request a lease; the arbiter grants ninety minutes to the bay whose lots carry the tighter Q-time exposure, refuses the other with a stated reason and an expiry it can plan around, and logs both. The second bay does not wait on a person; it schedules around a known return time.
What it looks like
- Contended resources — reticles, metrology capacity, AMHS segments, qual slots — are allocated by lease rather than by plan
- The central plane’s job has shifted from instructing to enforcing invariants and resolving conflict
- Priority is a negotiable, expiring claim rather than a static flag on a lot
- Contention itself is measured: wait time per resource, lease starvation, escalation rate
Diagnostic signals you can check this week
- List your genuinely scarce shared resources and ask, for each, what allocates it. If the answer is a human, you are below rung 4
- Check whether priority claims expire. Non-expiring priority is how a fab accumulates twelve simultaneous hot lots
- Measure lease wait time per resource and look for starvation — one scope repeatedly refused is a broken objective, not bad luck
- Ask what the arbiter protects. If nobody can name the invariants, local optimisation will eventually eat the line
Anti-pattern · Letting the agents set the objective
The seductive version of rung 4 is emergent: give every scope a reward, let them bid, and trust that good global behaviour appears. It does not, reliably, and the failure mode is quiet — the line balances worse, cycle time variance rises, and the cause is distributed across a hundred locally defensible choices. Global objectives belong in the arbiter as hard invariants, not in the agents as soft incentives. Bidding decides who gets a scarce resource; it must never decide whether a Q-time link may be broken.
What holds you here
Arbitration works inside one bay boundary and one shift, but nothing defines behaviour when the central plane is unreachable or when a second site is involved.
Highest-leverage next move
Define degraded-mode behaviour explicitly — what each scope may decide when it cannot reach the arbiter, and for how long — and rehearse it.
Cost of leaving
- Effort
- 18+ months
- Team
- Platform team, industrial engineering, production control, quality, plus a standing arbitration-policy forum
- Risk
- Higher — the exposure is systemic behaviour under contention, which is hard to test and easy to miss
- To next stage
- 24+ months
If this is you, the next step is
Which resources need leases, what the invariants are, and how contention is measured.
Stage 5
Federated line
1% of operators sit here
Authority is federated across bays and sites under versioned policy, with defined and rehearsed behaviour when the central plane is unreachable.
Rung 5 is narrower than the phrase “autonomous fab” suggests, and it is worth being precise about what it is not. It is not a fab without people, and it is not a fab in which everything is decided locally. It is a fab in which a specific, enumerated set of decisions executes under policy that is distributed rather than centrally instructed, in which the failure of the central plane degrades the fab gracefully instead of stopping it, and in which the whole arrangement can be explained to a customer’s auditor.
The distinguishing discipline is partition behaviour. Every distributed system eventually faces the question of what to do when the parts cannot talk to each other, and a fab’s answer must be per decision, not global. Interlocks keep working — they always did. A bay may keep placing holds under its existing envelope for a bounded period, because a hold is conservative. It may not keep granting itself reticle leases, because leases are the thing the arbiter exists to prevent double-issuing. Writing that table down, per decision, is most of the work of rung 5.
The second discipline is evidence, and it is the one that will actually gate a real fab. A qualified process serving automotive or medical customers carries change-control obligations: the rule that decided is part of the process, so the envelope version, the constraint values it saw and the arbiter’s grant are all part of the record. GlobalFoundries publishes its quality and certification frame openly, and every fab operating to comparable standards faces the same question — not “was the AI right?” but “can you reconstruct, eighteen months later, what it was permitted to do and why it did this?”. Rung 5 is sustainable only where the answer is yes by construction.
In practice
The forty-minute partition
A multi-site operator loses the link between one fab’s bay network and its central plane for forty minutes during a network change. Nothing stops. Interlocks are unaffected. Bays continue placing holds under envelopes cached with an explicit expiry, and stop issuing anything that consumes a shared resource. Two reticle requests queue rather than resolve. When the link returns, the reconciliation job replays forty minutes of local actions into the record and flags three that fell outside the cached envelope for human review. The event is a rehearsal, not an incident, because the behaviour was specified.
What it looks like
- Envelopes and invariants are distributed as versioned policy, not configured per site
- Degraded-mode behaviour is specified per decision and exercised on a schedule
- Cross-site decisions are federated by policy, with data-sharing constraints made explicit
- Any devolved action from any site is reconstructable to customer-audit standard
Diagnostic signals you can check this week
- Ask for the per-decision partition table. Its absence means degraded mode is whatever the code happens to do
- Check when the partition drill was last run. Annual is thin; quarterly is defensible
- Pick one devolved action from a year ago and reconstruct the envelope version and constraint values it ran under
- Ask how a policy change propagates to a second site, and how you would prove which version was live at a given time
Anti-pattern · Treating the policy as configuration
At rung 5 the policy — envelopes, invariants, partition rules — is the most consequential artefact in the system, and it is the one most likely to be edited in a settings screen with no review, no version history and no record of who changed what. The system works until someone has to explain an action taken eight months ago, at which point neither the bound nor the rule that produced it can be recovered. Policy is code. Review it like code, version it like code, and stamp its version on every action taken under it.
What holds you here
Sustaining federation is a governance and evidence problem — the constraint is customer change control and policy versioning, not engineering.
Highest-leverage next move
Treat envelopes, invariants and partition rules as one versioned, reviewable policy artefact, and rehearse the partition on a schedule.
Cost of leaving
- Effort
- Continuous
- Team
- Platform team, a standing policy forum, quality and customer-facing change control
- Risk
- Concentrated — low frequency, high consequence, and contractual rather than technical in nature
If this is you, the next step is
We run a partition scenario against your real envelopes and reconciliation trail.
Where wafer fabs actually sit on the ladder today
The distribution, why rung 2 is the plateau, and the one distributed system almost every fab already runs without noticing.
Most fabs are at rung 2 — local intelligence that can see and cannot act. The distribution below is weighted heavily toward the sensing edge, because adding a local model requires no delegation of authority and therefore no argument with quality, industrial engineering or a customer. Adding an envelope requires all three, which is why the drop from rung 2 to rung 3 is the largest single transition loss on the ladder and the one worth planning for explicitly.
Illustrative distribution of wafer fabs across the devolution ladder
An illustrative distribution, not a measurement. It synthesises what published fab smart-manufacturing material reports about adoption and its barriers, and it is used here only to show the shape of the plateau — treat the individual percentages as indicative rather than as a benchmark.
Share of fabs
- 31% — 1 · Central command
- 42% — 2 · Sensing edge (the plateau)
- 19% — 3 · Bounded local authority
- 7% — 4 · Negotiated autonomy
- 1% — 5 · Federated line
Source: Illustrative distribution, synthesised from published smart-manufacturing adoption reporting in fabs
10×
Faster troubleshooting from AI wafer-pattern classification, as published by GlobalFoundries
GlobalFoundries
~500k
3D objects in the plant digital twin at Bosch’s Dresden fab, mapping infrastructure and machines
Bosch
50+
Fab employees surveyed on smart-manufacturing adoption in fabs and the barriers to it
Flexciton
The barriers reported in that survey are worth reading against the ladder rather than against a technology roadmap. Flexciton’s 2025 front-end fab insights report (opens in a new tab), drawn from a survey of more than fifty fab employees worldwide, names integration with existing systems, data inadequacies and risk-averse leadership among the reasons advanced technologies move slowly into fabs. Every one of those is a rung-2-to-rung-3 blocker rather than a modelling one: integration is the constraint feed, data inadequacy is the fab state of record, and risk aversion is the entirely rational response to being asked to delegate authority without a written bound or a tested revert.
It is also worth being clear about what the plateau is not. It is not a shortage of algorithms. Learned dispatch and fab-scale scheduling have an active literature — self-supervised and reinforcement-learning approaches to semiconductor fab scheduling (opens in a new tab) and hybrid answer-set-programming formulations of the same problem (opens in a new tab) both address realistic fab constraints, and the latter is explicit that existing practice schedules locally with greedy heuristics or by optimising machine groups independently. The methods exist. What is missing in most fabs is the authority for anything to act on them without a person in the loop.
The authority map: which fab decisions can actually be devolved
Row per decision: the latency the physics demands, what the decision couples to, the smallest scope that holds those constraints — and therefore whether it can leave the centre at all.
A fab decision can be devolved to a scope if and only if that scope can see every constraint the decision touches, fast enough to matter. That single rule decides most of what follows, and it is a physics-and-coupling test rather than a technology test — which is why the map below does not change if the models get better. It is the page’s centrepiece: work down it with your own decision list, and the argument about what to automate stops being a matter of ambition and becomes a matter of arithmetic.
| Fab decision | Latency the physics demands | What it couples to | Smallest scope holding the constraints | Devolvable? |
|---|---|---|---|---|
| Abort or interlock trip on an out-of-spec chamber state | Milliseconds | The wafer in the chamber; personnel and equipment safety | The tool controller | Already devolved — hard-wired, and never negotiable |
| Run-to-run offset for the next run on this chamber | One run (minutes) | Metrology feedback for this layer on this chamber | The tool’s own control loop | Devolves cleanly — the classic bounded envelope |
| Hold a chamber out of service on an FDC excursion | Seconds to minutes | Downstream WIP, qualification status, the shift’s capacity | The bay, given a hold budget | Devolvable at rung 3 with a budget and a revert |
| Which wafers on this lot to send to measurement | Minutes — before the lot moves on | Metrology capacity, SPC power, product risk rules | The bay, inside a measurement budget | Devolvable at rung 3; the SPC rules must move with it |
| Next lot onto a non-bottleneck toolset | Seconds | Q-time links upstream and downstream, dedication, batch shape | The bay — but only if queue-time clocks are fed live | Rung 3–4, and only with a live constraint feed |
| Batch composition and release on a furnace or wet bench | Minutes | Batch efficiency, cycle time, every Q-time link in the batch | The toolset, with segment-level constraints pushed down | Rung 4 — the three objectives conflict and must be arbitrated |
| Reticle movement between litho tools | Minutes | Every lot needing that reticle, across bays | Fab-wide — a reticle is a physical singleton | Not devolvable; arbitrate by lease at rung 4 |
| Q-time rescue when a tool goes down mid-link | Minutes | Two or more process steps and the whole segment’s WIP | The segment, not the tool or the bay | Rung 4 — needs a negotiated priority, not a local one |
| Hot-lot priority and its expiry | Hours | Customer commitments, every queue the lot will pass through | Fab-wide, with expiry enforced centrally | Not devolvable; the claim expires, the authority does not move |
| Preventive-maintenance window placement across a toolset | Hours to days | The week’s capacity, spares, technician availability | Toolset plus maintenance planning | Partially devolvable at rung 4; the calendar stays central |
| Wafer starts and the week’s product mix | Days | Customer commitments, capacity, capital, revenue recognition | The fab and its planners | Correctly central, permanently |
Three patterns fall out of the map. First, everything at the millisecond and single-run end of the latency column is already devolved and has been for years — the industry solved local autonomy long ago and called it control, not AI. Second, the rows that resist devolution resist for one reason: the resource or the constraint is shared. A reticle is a singleton; a queue timer links two steps that no single scope owns; a hot lot passes through queues belonging to bays that will never meet. Third, the rows at the bottom are not failures of ambition. A fab that devolved its start plan to individual bays would not be more autonomous; it would have no commercial control over what it manufactures.
The queue-timer row deserves separate attention because it is where most well-intentioned devolution programmes come apart. Queue-time constraints link steps across tool groups: after a wet clean, wafers must reach the next furnace within a stated window or be reworked or scrapped. A bay agent optimising its own toolset’s utilisation will happily accept a lot whose downstream link it cannot see, and the cost of that acceptance appears somewhere else, later, as scrap that nobody attributes to a dispatch decision. Flexciton has published technical material specifically on why queue timers defeat conventional schedulers (opens in a new tab) and on the yield-versus-capacity trade-off they force (opens in a new tab). The engineering conclusion for a devolution programme is blunt: if you cannot feed queue-time remaining to the edge, do not devolve lot selection at all.
Where to devolve first — latency demand against constraint span
Plot a decision by how fast it decays and how far it couples. Only one quadrant is a good first move; one is a trap; and the bottom-right quadrant is a permanent, correct home for a large part of what a fab decides.
Devolve first
- Fast and locally contained — FDC holds, R2R correction, in-bay sampling
- The scope already sees everything the decision touches
- Move: write one envelope, feed the local constraints, ship it
Negotiate, don’t just devolve
- Fast and globally coupled — reticle contention, Q-time rescue, AMHS congestion
- Devolving without arbitration distributes conflict, not authority
- Move: build the lease primitive before moving the decision
Devolution buys nothing
- Slow and contained — routine consumable replacement, local calibration cadence
- A central plan is fast enough, and one place is cheaper to qualify
- Move: leave it alone and spend the effort elsewhere
Correctly central, permanently
- Slow and globally coupled — starts, mix, capital, PM calendar
- These are commercial decisions wearing operational clothes
- Move: improve the central plan; do not try to distribute it
The trap quadrant is the top right, and it is where visionary programmes reliably land, because those decisions are the ones that hurt most and therefore attract attention first. Reticle contention and queue-time rescue are genuinely fast, genuinely painful and genuinely global — which is exactly why they need an arbitration primitive before they need a local agent. A fab that devolves the top-right quadrant without the arbiter has not decentralised authority; it has replaced one queue at production control with several simultaneous ones and removed the person who used to resolve them.
Real today, published research, and speculation — kept apart
The discipline this topic demands: three columns, and a refusal to let a research claim borrow the credibility of a production one.
Most writing about the autonomous fab fails at one specific point: it moves between what is running in production, what a paper demonstrated in simulation, and what somebody hopes will be true in 2040, without ever signalling the change. The table below keeps those three apart deliberately, claim by claim. It is the most useful section of this page for anyone building an internal business case, because a capital committee will not fund a roadmap whose evidence classes are mixed — and it will fund one whose author separated them before being asked.
| Claim you will hear | What is genuinely in production | What published work actually shows | What remains speculation |
|---|---|---|---|
| “The fab runs itself” | Material handling moves carriers continuously without human dispatch — GlobalFoundries publishes up to 10,000 carrier moves a day in one fab | Learned dispatch and fab-scale scheduling are formulated against realistic fab constraints and evaluated largely in simulation | An end-to-end fab in which no human owns a decision class |
| “Agents will negotiate with each other” | No publicly documented fab-scale agent negotiation; contention is resolved by plan or by people | Holonic and multi-agent control architectures have a two-decade literature, including benchmarking frameworks for comparing them | Emergent negotiation replacing an explicit, auditable protocol |
| “Edge AI decides at the tool” | Run-to-run control, FDC and on-tool health models — decades old, and genuinely local | Multi-agent approaches to dynamic dispatching in material-handling systems are demonstrated on enterprise data | On-tool models altering a qualified recipe without change control |
| “The fab is one distributed brain” | Centralised data architectures and control towers — Bosch describes fully connected systems within a centralised data architecture at Dresden | Federated learning addresses sharing model updates without sharing data; it is about privacy and data locality, not decision authority | Cross-company federated control of production decisions |
| “Swarm behaviour will optimise the line” | Nothing in a production fab | Bio-inspired flocking has been proposed as an optimisation inspiration for production plants — an ideas paper, not a deployment report | Self-organising WIP flow with no arbiter and no invariants |
| “Autonomy removes the qualification burden” | Nothing — qualified processes still carry change-control and customer-notification obligations | No published work claims otherwise; the deciding rule is part of the process | Customers and auditors accepting an unversioned autonomous policy |
The multi-agent row is the one most often overstated, so it is worth being exact about what the literature does and does not say. Holonic manufacturing control architectures (opens in a new tab) have been formalising the trade-off between local autonomy and global coherence since well before the current AI cycle, and there is published work on how to benchmark holonic systems against each other (opens in a new tab) precisely because comparing them has been hard. That is a mature research programme, not a shipping product line. More recent work is sharper still about the cost of modularity: an analysis of the coordination gap between joint and modular learning for job-shop scheduling with transport resources (opens in a new tab) measures what is lost when decisions are learned separately rather than together, and separate work on graph-structured experience reuse for multi-agent adaptation in dynamic manufacturing (opens in a new tab) addresses how such agents adapt. Both are evidence that coordination is the hard part — which is the argument for an arbiter, not against decentralisation.
Physics is the first bound, and it does not move
Queue-time windows, thermal budgets, resist shelf life and chamber seasoning are chemistry and physics. No architecture makes a linked step less linked. Every claim about a self-coordinating fab has to survive the observation that some of its couplings are covalent.
Qualification is the second bound, and it is contractual
A qualified process is qualified as a whole, and the rule that decides is part of it. Fabs serving automotive and medical customers publish their certification frames openly — GlobalFoundries’ quality and certifications page (opens in a new tab) is a representative example — and the obligations behind them do not distinguish between a human decision and an automated one. A change in an autonomous decision rule is a process change, with everything that follows.
Interfaces are the third bound, and they are where the work is
Devolved decisions need equipment data and they need it in a normalised form. The SEMI standards suite — GEM for equipment communication, the EDA or “Interface A” standards for structured data collection — is what makes that possible, and the state of a fab’s conformance to it is usually the real schedule driver. SEMI’s standards programme (opens in a new tab) is the reference point; the fab-side work is normalisation, not procurement.
Evidence is the fourth bound, and it is the one that decides
Whatever a fab devolves, it must be able to reconstruct months later: the action, its inputs, the envelope version, the arbiter’s grant. The fabs that will devolve most in 2035 are the ones that made reconciliation a by-product of the action path in 2026, rather than a reporting project scheduled after the models.
These cross-fab and multi-step decisions sit between dispatching and planning. No MES handles them. No scheduler touches them. They live in the heads of experienced engineers — and the response depends on who is on shift.
That quotation is the honest starting point for any decentralisation programme, and it reframes the whole vision. The gap in a modern fab is not that decisions are made centrally; it is that a large class of consequential decisions is made by nobody in particular, at a scope nobody wrote down, with an answer that varies by shift. Decentralised autonomy is one legitimate response to that gap. Better central automation is another, and for the top-right quadrant of the matrix it is usually the correct one. What is not a response is leaving the decisions unassigned and adding models around them.
What the published record actually shows
Three publicly reported programmes, read against the ladder. None is an Atomic Loops engagement — each links to the material it is drawn from.
The public record on fab autonomy points somewhere slightly awkward for the decentralisation thesis, and it is more useful for that. The most documented programmes are not distributed at all: they are centralised data architectures, global control towers and enterprise AI functions, sitting above an execution layer that has been autonomous for decades. Read the three below for what leading fabs actually chose to build, not for a benchmark to apply to your own line.
Three programmes read against the devolution ladder
Outcomes as reported in the linked material; we have not independently audited the figures, and where a result comes from a vendor webinar rather than a peer-reviewed study it is stated. Card images are generated industry scenes from our library — none depicts the named operator’s facility, and none implies an endorsement.
GlobalFoundriesGlobal foundry · fabs in the US, Europe and Asia23
- Challenge
- Scaling AI-supported manufacturing decisions across a footprint of geographically separated fabs, where a per-site build never amortises and per-site divergence in data definitions makes any cross-site comparison meaningless.
- Approach
- GlobalFoundries publishes a digital-manufacturing programme built around centralised capability: a proprietary factory control tower described as a virtual fabric monitoring key production processes and performance metrics across all its global manufacturing with 24/7 support from manufacturing hubs, a global AI centre of excellence based in Singapore that pilots and scales solutions across sites, and heavy automation at the execution layer including robotics and an overhead material-handling system.
- Reported outcome
- GlobalFoundries publishes that its overhead transport delivers as many as 10,000 carrier moves a day in a single fab, that custom AI engines classifying wafer patterns speed troubleshooting time by up to 10× and reduce wafer scrap, and that in 2025 the World Economic Forum designated its 300 mm fab in Singapore part of the Global Lighthouse Network of advanced manufacturers.
- What it shows about the curveCoordination centralises as execution devolves, and that is not a contradiction. The material handling is autonomous; the decision layer above it is a control tower. This is rung 2 moving to rung 3 with an unusually strong central spine — which is exactly the spine any later devolution will need.
GlobalFoundries — digital manufacturing (opens in a new tab)
Bosch (Dresden)300 mm automotive and power semiconductor fab · greenfield13
- Challenge
- Bringing up a greenfield 300 mm fab for automotive ICs and power semiconductors — a product class with among the most demanding traceability and change-control obligations in the industry — with the opportunity to choose its data and decision architecture from scratch rather than inherit one.
- Approach
- Bosch describes the Dresden plant as data-centric from the start: systems fully connected within a centralised data architecture giving detailed data capture for each chip, AI applied to data-based process control, real-time monitoring and machine learning for early deviation detection, and a digital twin of the plant consisting of around half a million 3D objects mapping infrastructure and machines for planning, remote maintenance and simulating process changes.
- Reported outcome
- Bosch reports that this combination supports traceability and consistent quality control per chip, earlier deviation detection and higher manufacturing yields, alongside optimised planning and simulation of process changes through the digital twin.
- What it shows about the curveThe most interesting sentence in Bosch’s own description is “centralised data architecture”. Given a blank sheet and every reason to be radical, a modern greenfield fab built the central spine first. Devolution is what you can do once that spine exists — the ordering is not optional.
Unnamed production fab (reported by Flexciton)Front-end wafer fab · production control13
- Challenge
- A class of cross-fab, multi-step production-control decisions — when to start WIP, how to respond to a tool going down, how to balance competing priorities when capacity is tight, how to keep bottleneck tools fed, how to manage queue timers, whether to batch aggressively or protect cycle time — that no MES handled and no scheduler touched, and which in practice depended on which experienced engineer was on shift.
- Approach
- Rather than devolving these decisions to individual toolsets, the reported approach automates them across the whole fab in real time, every cycle, sitting above both rule-based dispatching and any toolset scheduler already in place — that is, assigning the unowned decisions an explicit owner rather than distributing them.
- Reported outcome
- Flexciton reports a cycle-time reduction of over 10% alongside a throughput improvement at a production fab, and describes more consistent performance across shifts with less reactive firefighting. This is published as a vendor webinar and case description rather than a peer-reviewed study, and should be read at that weight.
- What it shows about the curveThe largest reported win in this space came from assigning authority, not from decentralising it. Before asking which decisions should move to the edge, ask which decisions currently have no owner at all — that list is usually longer, cheaper to fix and worth more.
Flexciton — “The decisions that nobody owns” (opens in a new tab)
Read together, the three make one uncomfortable and useful point: nothing in the published record describes a fab in which authority has been genuinely distributed to negotiating local agents. What the record describes is strong central state, autonomous execution, and a slowly closing gap in between. That is not an argument against the decentralised vision — it is a statement about sequence. For wider context on where fab automation is heading, Semiconductor Engineering’s manufacturing coverage (opens in a new tab) tracks the field continuously, imec (opens in a new tab) publishes on advanced process and equipment research, and TSMC (opens in a new tab), Intel (opens in a new tab), Micron (opens in a new tab) and GlobalFoundries (opens in a new tab) all publish periodically on smart-manufacturing programmes.