Foxconn Technology Group began a pilot that runs a compact Nvidia GPU inference rack on-premises at a Hsinchu science-park campus so perimeter security supervisors can query shift logs and camera event summaries in Mandarin without routing metadata through public cloud LLM APIs, according to an internal operations memo and vendor acceptance checklist InfoHandle reviewed Monday. The system is not a replacement for human guards or licensed biometric databases—it summarizes tagged incidents from existing VMS archives under rules Foxconn's legal team frozen for the trial quarter.

What actually runs on the rack

The rack hosts a fine-tuned open-weights model Foxconn's information security office approved for on-site inference only; weights stay air-gapped from training pipelines that use supplier NDAs. Queries accept natural-language prompts about gate tailgating flags, forklift near-miss timestamps, and badge-swipe anomalies aggregated from the last seventy-two hours—no live facial recognition on the LLM path, which Foxconn's memo explicitly excludes from scope.

Nvidia's enterprise stack supplies tensor-RT optimized serving; Foxconn integrators added audit logs that hash every prompt and response for PDPA-aligned retention reviews.

Claims versus what auditors can verify

Independent reviewers can replay hashed logs and confirm responses cite only indexed event IDs present in the VMS export— not invent incidents. They cannot, from outside the campus, validate false-negative rates on rare events or whether shift supervisors over-trust fluent Mandarin summaries. Foxconn published threshold tables for when the UI must force human video review; those tables are the evaluable artifact, not marketing AUC slides.

Who has power in the pilot

Campus security chiefs approve prompt templates; Foxconn corporate infosec holds kill-switch authority if drift monitors exceed bounds. Nvidia supplies hardware and reference architecture but does not operate Foxconn's video estate. Taiwan PDPA guidance treats aggregated gate logs as personal data when badge IDs appear; the pilot redacts employee numbers in LLM context windows while keeping them in source VMS for HR investigations.

Limits the memo admits

The model is not licensed as a medical or safety-critical system; it does not control doors or alarms. Latency targets are seconds, not milliseconds—unsuitable for real-time intrusion blocking. Multi-campus rollout waits on Hsinchu humidity and dust tests in the rack's filtered closet; Foxconn declined to name expansion dates.

What would falsify usefulness

If supervisors skip video confirmation because summaries sound authoritative, false clearance rates could rise; the pilot mandates random spot audits. If prompt injection via corrupted log fields succeeds, infosec must revoke templates—a threat model Foxconn red-team scripts listed but did not publish.

Policy context in Taiwan

NSTC-funded smart-manufacturing grants encourage on-prem AI for trade-secret-heavy lines; security summarization rides the same procurement lane but with stricter PDPA review. Competitors offer cloud copilots; Foxconn's bet is that guard contractors and union reps accept Mandarin Q&A only when packets never leave the fence line.

Next for evaluators

Quarter-end reports will compare mean time to locate incident clips with and without LLM search—operational KPIs, not benchmark leaderboard scores. For Ya-Ting Tsai's desk, the narrow story is named hardware, frozen scope, hashed audits, and explicit exclusion of live face ID—not a generic "AI security revolution" press release.

2317.TW and Nvidia's U.S. listing moved independently Monday; this pilot is immaterial to Foxconn revenue but signals how contract manufacturers productize Nvidia racks for internal ops before reselling to cloud clients.

Training and union visibility

Security supervisors completed sixteen hours on prompt hygiene and mandatory video spot-checks; union reps received read-only dashboard access without prompt-edit rights. Foxconn's environmental health and safety office said the LLM does not rank worker safety incidents—those feeds stay on a separate incident system to avoid conflating guard tours with factory floor near-miss analytics.

Edge rack power draw stays below the campus demand-response cap; if summer heat spikes, inference may defer to off-peak hours without affecting live guards. Nvidia field engineers documented cable routing for EMI isolation from nearby SMT lines—a mundane detail auditors asked for because unshielded runs caused ghost alerts in an April dry run.

Competitors including cloud security copilots pitched Foxconn last quarter; procurement minutes show on-prem won on PDPA and trade-secret clauses, not per-token price alone. If quarter-end KPIs miss, Foxconn may shrink scope to day-shift only rather than expand campuses—a fail-small posture rare in AI press releases but common in factory compliance culture.