SAP + on-prem AI for A&D
AI on SAP for Aerospace and Defense Manufacturers, Without the ITAR Exposure
Short answer
Aerospace and defense manufacturers running SAP S/4HANA or ECC can add natural-language search, configuration control assistance, and quote drafting without sending ITAR-controlled technical data to a public model API. The pattern is a private or air-gapped LLM grounded on SAP tables through read-only OData or RFC connectors, with every generated answer traceable back to source records and every write action gated behind human approval.
- ERP
- SAP S/4HANA, SAP ECC 6.0
- Industries
- Aerospace, Defense, Electronics
- Written for
- VP Operations
If you run production for an aerospace or defense supplier on SAP S/4HANA or ECC 6.0, your operations team already spends a disproportionate amount of time chasing information that technically lives in the system: where a specific serial number has been, which open orders a pending engineering change touches, what the last three quotes for a similar assembly looked like. None of that is a data problem in the usual sense. SAP has the answer. Finding it takes a person who knows which transaction, which table, and which report variant to use.
The obvious fix, ask a chatbot, runs straight into the constraint that defines this industry: the technical data sitting in your material masters, routings, and drawings referenced from production orders is very often ITAR or export-controlled, and a growing share of it is Controlled Unclassified Information under a DoD or prime contract. Sending that data, even as context for a prompt, to a public model API operated outside your control is not a theoretical risk. It is the kind of thing an export compliance officer will stop a project over, and should.
That is the specific problem this page addresses: how a VP of Operations gets the productivity benefit of AI, natural language search over SAP, faster quote and RFQ drafting, configuration-control impact checks, without the technical data ever leaving a boundary you control. The architecture is not exotic. It is an open-weight model served on your own GPUs or in a sovereign private cloud, grounded on your SAP data through the same connectors and authorization model SAP already uses, with a human approving anything that writes back.
The rest of this page is deliberately specific about SAP objects, ITAR and CMMC mechanics, and what a pilot actually looks like, because generic AI vendor material will not survive contact with your export compliance team. Where we are not confident about a fact (partner status, a specific certification, a named customer) we say so rather than imply it.
What usually gets in the way
The problems we hear most from vp operations teams running SAP S/4HANA.
Serial and lot genealogy takes an analyst half a day
Tracing a single serial number's history across equipment records, production orders, and inspection results usually means pulling IE03 equipment master data, cross-referencing AFVC/AUFK production order history, and checking QM inspection lots by hand. For a supplier audit or a fleet-wide corrective action, that is a half-day task repeated across dozens of serials.
Configuration control change impact is manual and error-prone
When an engineering change hits a configured item, someone has to work out which open production orders, sales orders, and spares stock are affected by walking CS03 bills of material and CA03 routings by hand. Missing one open order means a nonconforming build slips through, which is exactly the failure mode configuration control exists to prevent.
RFQ and quote turnaround lags the customer's expectation
Drafting a technical and cost quote for a new RFQ means digging up the closest prior contract, the cost estimate in CK11N, and any special terms, then writing it up from scratch. On a program with a tight bid window, that lag alone can cost the business, independent of price competitiveness.
Export control screening is a bottleneck, not a safety net
Checking ECCN and USML classification fields, partner country codes, and end-use flags against a pending sales order or purchase order line is a manual lookup most teams only do at order entry, not continuously, which means a classification change or a new restricted party can go unnoticed on an order already in process.
Knowledge walks out the door with senior planners and quality engineers
The people who know why a particular configuration was approved, which supplier's parts need extra incoming inspection, or how a prior nonconformance was dispositioned are retiring faster than that judgment gets written down anywhere SAP or a document system can surface it to the next person.
Where AI earns its place in SAP S/4HANA
Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.
Serial and lot genealogy lookup
A quality engineer asks a plain-language question about where a given serial number has been and gets an answer assembled from equipment records, production order history, and inspection results, with each fact linked back to its source screen.
Touches: Equipment master (IE02/IE03), production orders (AFVC/AUFK), QM inspection lots (QA32), serial number profiles
Outcome: Cuts a genealogy trace from a half-day of manual lookups to a few minutes, with full source traceability for the audit file.
Configuration control impact assessment
Before an engineering change is dispositioned, the agent drafts a list of open production orders, sales orders, and on-hand spares affected by the BOM or routing change, for the change board to review rather than build from scratch.
Touches: Engineering change management (ECM), material BOM (CS03), routing (CA03), open production and sales orders
Outcome: Gives the change board a first-pass impact list in minutes instead of a day of manual order-by-order checking, reviewed and finalized by the board itself.
Program and WBS status rollup
A program manager asks for a natural-language status summary across the WBS elements on a contract, pulled from Project Systems milestone, cost, and commitment data.
Touches: Project Systems WBS elements, network activities, CJ20N, cost and commitment line items
Outcome: Replaces a manually compiled program status deck section with a grounded summary the PM edits rather than authors from scratch.
RFQ and quote drafting from contract history
Given a new RFQ, the agent finds the closest prior contract and cost estimate, and drafts a first-pass technical and pricing narrative referencing that history for the estimator to adjust.
Touches: SD quotations (VA21/VA23), cost estimates (CK11N), material and customer master data
Outcome: Shortens first-draft quote turnaround meaningfully on programs with strong precedent, without setting price, the estimator still owns the number.
Export control screening assist
As sales and purchase order lines are entered or changed, the agent flags lines where material classification, partner country, or end-use data suggests a compliance review is warranted, before the order is released.
Touches: Material master classification fields (ECCN/USML), business partner country and denied-party fields, sales and purchase order line items
Outcome: Surfaces borderline lines for a compliance officer's review before release rather than relying solely on a point-in-time check at order entry.
MRO work order triage
For sites running maintenance, repair, and overhaul work, the agent classifies incoming notifications by likely cause and urgency and drafts a first-pass work order scope for the planner to confirm.
Touches: PM/CS notifications (IW21/IW28), equipment master, failure and damage catalogs
Outcome: Reduces the time a planner spends reading and re-typing free-text notifications into structured work orders.
First article inspection report drafting
For a new or changed part number, the agent pre-populates an AS9102 first article inspection report from characteristic results already recorded in the inspection lot, drawing reference, and balloon numbers, for the quality engineer to complete and sign.
Touches: QM inspection lot characteristic results (QA32/QA33), document management links to drawings
Outcome: Cuts the mechanical data-entry portion of FAI paperwork, leaving the engineering judgment to the person who signs it.
Reference architecture
The pattern is the same one Netray uses across ERPs, tuned to the authorization and export-control posture an A&D program needs: an ERP connector layer that reads SAP through the same access controls a person would use, a semantic layer that maps raw tables to the vocabulary your engineers and planners actually use, a model serving layer that runs entirely inside your boundary, an agent and retrieval layer that answers questions and drafts documents, and a governance layer that logs everything and blocks unapproved writes.
- 1
ERP connectors
Read-only OData services and CDS views for S/4HANA, or RFC/BAPI calls for ECC 6.0, authenticated with a dedicated service user scoped to the same authorization objects a real person in that role would have, never SAP_ALL.
- 2
Data and semantic layer
SAP tables, IDocs, and CDS views are mapped to a glossary your team recognizes: serial genealogy, configuration baseline, WBS status, so a question in plain English resolves to the right transaction data rather than a literal table search.
- 3
Model serving
An open-weight model (from the Llama, Qwen, Mistral, or similar class) served with vLLM or Ollama on GPUs inside your facility or your sovereign private cloud tenant. No inference call ever leaves that boundary.
- 4
Retrieval and agents
Retrieval-augmented generation over structured SAP data plus linked documents (drawings, specs, prior quotes), with agent workflows for multi-step tasks like configuration impact assessment or quote drafting.
- 5
Governance and audit
Every generated answer is logged with the exact query and source records used. Role-based access mirrors your SAP authorization concept. No write-back (order changes, disposition updates, status changes) happens without a named person approving it, and export-sensitive fields can be excluded from the model's context entirely.
Integration notes for your ERP team
- S/4HANA connections use OData services or CDS views exposed through SAP Gateway with a scoped service user; ECC 6.0 connections use RFC/BAPI where OData is unavailable, both read-only by default.
- Authorization mirrors your existing SAP roles rather than introducing a separate permission model, so a planner sees only what their SAP role would already let them see.
- Configuration and BOM/routing changes are picked up via change pointers or IDoc events so the semantic layer stays current without constant polling.
- No write-back action (order changes, disposition updates, status changes) happens automatically. Every write goes through a BAPI call a named person triggers after reviewing the draft.
- Export-sensitive classification fields (ECCN, USML category, denied-party flags) can be explicitly excluded from what the model is allowed to reference in its answers, configured per field, not left to model judgment.
- Document management (drawings, specs, prior FAI reports) is linked in as retrieval context rather than duplicated, so the source of truth stays in SAP's DMS or your PLM system.
- The same connector pattern works whether S/4HANA or ECC is on-prem, in a private cloud, or (for non-ITAR data) in RISE with SAP.
Deployment options
Air-gapped on-prem
Programs with ITAR technical data, CUI under a DoD contract, or a classified-adjacent enclave.
Model, retrieval index, and connector all run on hardware inside your facility with no outbound internet path. This is the deployment most defense primes and their tier 1-2 suppliers will require for anything touching export-controlled technical data.
Private or sovereign cloud
Programs where the data is sensitive commercially but not export-controlled, or where a customer's own sovereign cloud (a GovCloud-class or in-country tenant) is acceptable.
A dedicated tenant, not shared multi-tenant infrastructure, still with no data sent to a third-party model provider's API. Useful where facility GPU capacity is not yet in place but public cloud AI services are off the table.
Hybrid by program
Businesses running both commercial and defense programs on the same SAP instance.
Commercial business units use a private cloud deployment while ITAR- or CUI-scoped programs are segregated onto an on-prem instance, with authorization objects and data scoping keeping the two from mixing.
Compliance and data control
How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.
ITAR (22 CFR 120-130)
Technical data never leaves a boundary you control and is never sent to a third-party model API, which avoids the deemed-export exposure that a public LLM service creates the moment ITAR technical data is included in a prompt.
CMMC 2.0 Level 2
The AI layer sits inside the same CUI enclave as SAP itself, inherits your existing access controls, and adds its own query and access logging so it is auditable as part of your assessment scope rather than a separate shadow system.
DFARS 252.204-7012 / NIST SP 800-171
Encryption at rest and in transit, access logging, and least-privilege service accounts are applied to the AI layer the same way they already apply to SAP, so the control mapping your compliance team maintains extends naturally rather than needing a parallel one.
AS9100D traceability
Because every AI-generated answer cites its source SAP record, genealogy and disposition answers remain auditable back to the original transaction, which is what an AS9100 auditor will actually ask to see.
Where Netray fits
ERPray
Grounded natural-language question answering over SAP genealogy, program status, and order data is exactly ERPray's use case, deployed on-prem or in a private tenant for ITAR/CUI scope.
Custom build
Quote drafting, FAI report pre-population, and multi-step configuration impact assessment are bespoke agent workflows built around your specific SAP configuration and document set.
How an engagement runs
Phase 1 . 2-3 weeks
Discovery
- -SAP landscape and authorization review (S/4HANA vs ECC, custom Z-objects, existing roles)
- -Data classification workshop with export compliance to scope what the AI layer may and may not touch
- -Prioritized use case list ranked by planner/engineer time saved and compliance risk
- -Target deployment model (air-gapped, private cloud, hybrid) sized against available GPU capacity
Phase 2 . 6-8 weeks
Pilot
- -Read-only natural-language Q&A live for one program or product line
- -Security and export-compliance review of the connector, logging, and model boundary
- -Baseline accuracy testing against known-answer questions from your own planners and engineers
- -Go/no-go criteria and cost-to-scale estimate for production rollout
Phase 3 . 8-12 weeks
Production
- -Rollout across the target program's full planner, quality, and program management user base
- -Human-approval write-back workflows for the use cases that require them
- -Deployment into the CUI/ITAR enclave with full audit logging integrated into your existing compliance tooling
- -Runbook and internal admin training so your team can own day-to-day operation
Phase 4 . Ongoing
Scale
- -Extension to additional programs, product lines, or sites
- -Deeper PLM and document management integration for configuration-heavy engineering change workflows
- -Periodic re-tuning of the semantic layer as SAP configuration and catalogs evolve
Questions to ask any vendor, including us
A short list that separates real SAP S/4HANA AI work from a chatbot demo.
- Does any part of your architecture ever send our SAP data, including as prompt context, to a model API operated outside our boundary?
- Can the entire stack, model included, run with no outbound internet connectivity, and has it actually been deployed that way before?
- How does the system respect our existing SAP authorization objects rather than introducing a separate access model to maintain?
- What is logged for every AI-generated answer, and can our export compliance and CMMC assessors review that log directly?
- Can specific fields (ECCN, USML category, denied-party data) be excluded from what the model can reference, and how is that configured?
- Does the system ever write back to SAP automatically, and if so, exactly what stops it from doing that without a named person's approval?
- What happens when SAP is upgraded or a Z-table changes, does the integration break silently or fail safe?
- Can you show a reference architecture diagram for an air-gapped deployment rather than describing it only in prose?
Frequently asked questions
Can we run AI on SAP without sending ITAR technical data outside our network?
Yes, that is the specific problem this architecture is built for. An open-weight model served on GPUs inside your facility, grounded on SAP through read-only connectors, never sends data to a third-party model API. The technical data stays inside the same boundary it already lives in today.
Does this work on ECC 6.0 or only S/4HANA?
Both. S/4HANA connections typically use OData services and CDS views; ECC 6.0 connections use RFC and BAPI calls where OData is not available. The semantic layer and model serving are the same regardless of which SAP version sits underneath.
Will the AI change data in SAP on its own?
No, by default it does not. Every use case here is read-only or draft-only: the agent proposes a configuration impact list, a quote draft, or an FAI pre-population, and a named person reviews and executes any actual change through the normal SAP transaction and approval path.
How does this affect our CMMC assessment scope?
The AI layer sits inside the same CUI enclave as SAP and inherits the access controls, encryption, and logging already in place for your CMMC Level 2 assessment. It should be scoped into your assessment as an additional system in the enclave, not treated as an exception.
What does a serial genealogy answer actually look like?
A plain-language summary, for example which production orders, inspection lots, and equipment records a serial number touched, each fact linked back to the exact SAP transaction it came from, so a quality engineer can verify it in seconds rather than trust it blindly.
Can this help with RFQ turnaround without setting our prices for us?
Yes. It drafts the technical narrative and pulls the closest prior contract and cost estimate for reference, but the estimator sets the actual price. The goal is to remove the manual document assembly, not the pricing judgment.
How long before we see value?
A focused pilot on one program's genealogy and status Q&A use cases typically shows measurable time savings within the 6-8 week pilot window. Configuration impact and quote drafting take longer to tune because they depend more heavily on your specific BOM and contract history.
Related guides
AI for SAP S/4HANA, Running On-Prem or in Your Private Cloud
Run AI on SAP S/4HANA without sending ERP data to a public API. On-prem and private-cloud architecture, CDS views, OData, and honest deployment trade-offs.
ITAR + on-prem AIITAR-Compliant AI for ERP Technical Data
How to add generative AI to your ERP without creating a deemed export under ITAR. On-prem architecture patterns an Empowered Official can sign off on.
AS9100D + on-prem AIAI for AS9100 Quality Management on Your ERP
AI on top of your ERP quality module for AS9100D suppliers: NCR/CAPA drafting, FAI support, counterfeit parts screening, with a full audit trail.
CMMC 2.0 + on-prem AICMMC Level 2 AI for ERP Without Blowing Up Your Scope
How to deploy AI inside your CMMC 2.0 Level 2 assessment boundary without expanding CUI scope. Enclave architecture a CISO can defend to a C3PAO.
On-prem AI, any ERP, A&DOn-Prem AI for ERP in Aerospace, Defense, and Electronics Manufacturing
A hub guide to on-prem AI across SAP, Infor LN, Costpoint, IFS, and Oracle EBS for aerospace, defense, and electronics manufacturers under ITAR, CMMC, and AS9100.
Defense contractor AIAI for ERP Across the US Defense Supply Chain
A CIO's guide to adding AI on top of the ERP defense primes and tier 2-3 suppliers already run, without adding a compliance risk the program cannot absorb.
Plan it with numbers
ITAR AI Workload Compliance Assessment
Score your AI deployments across eight dimensions of ITAR exposure, from technical data classification and US persons access control to technology control plan coverage.
Free ToolDefense Contractor AI Readiness Assessment
A 9-question assessment measuring whether your defense manufacturing business can adopt AI productively and compliantly - across governance, data, infrastructure, and skills.
Free ToolAS9100 Audit Readiness Checklist
A 30-point checklist for AS9100 Rev D certification and surveillance audits, weighted toward the aerospace-specific requirements where auditors write the most findings.
GuideDefense CIO AI Briefing: 2026 Edition
Defense CIO AI briefing for 2026: CMMC 2.0, ITAR, and DFARS constraints on AI, plus how defense contractors deploy LLMs without risking CUI exposure.
GuideAI-Powered Quoting for Aerospace & Defense Manufacturers
AI-powered quoting for aerospace and defense manufacturers: cut quote turnaround from weeks to days while handling ITAR data, DFARS clauses, and cost buildup.
GuideDoD AI Adoption in 2026: What It Means for Defense Manufacturers
DoD AI adoption in 2026: what CDAO programs, budget priorities, and new acquisition rules mean for defense manufacturers planning their own AI investments now.
Talk it through with an engineer who knows SAP S/4HANA
Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.