EyeOn Automations
Back to blog
AI policyAI acceptable use policyconstruction operations

Your construction company needs an AI policy. Here's a starter template.

Employees are pasting bids and contracts into personal ChatGPT accounts every day. Here's a starter AI policy for construction companies to take to legal.

Kelly Stephens

Kelly Stephens

8 min read

I've sat across from leadership at billion-dollar construction companies this year and asked the same question: do you have an AI policy? Not one of them did. Not a page, not a paragraph, nothing.

Here's what that looks like in practice. At the homebuilder I worked at, I physically watched employees put internal company documents into ChatGPT, not caring or not knowing what they were actually doing. They don't use Microsoft Copilot. They default to ChatGPT, and none of that data is covered by anything, because the company doesn't even pay for AI. People are using their personal ChatGPT accounts and uploading company information into them.

That's happening multiple times in a day now, with or without a policy. The only question is whether the company has decided what's okay.

Before anything else: this is not legal advice. I help construction and real estate companies stand up their first AI policy as part of an AI readiness audit, and I've seen what works on the ground, but I am not an attorney. Take whatever you build from this to your legal counsel and your IT lead before it goes into an employee handbook.

Why this matters more in construction than most industries

Construction runs on other people's confidential information. Your subs' pricing. Your owners' contracts and budgets. Site photos with addresses, plates, and faces in them. Payroll and certified payroll. Safety incident reports. Bid packages you're competing on. A lot of that data is under NDA, and the rest is the kind of thing that ends a relationship if it leaks.

When an employee pastes any of that into a public AI tool, it may be stored, it may be used to train the model, and it may be visible to the vendor's staff, depending on the tool and the plan. Most people using these tools have no idea which one they're on.

The part nobody talks about: your customers are going to ask

People are wary of AI right now. That's not going away. More and more of the folks you build for, and the trade partners you build with, are tuning in to how AI actually works, and they're going to start asking a direct question: how are you using our information?

If you have a written policy, that conversation is easy. You can say, we don't put your contract terms, your pricing, or your personal information into AI tools, period, and here's the document that says so. That's a trust move. It's the same reason you keep your insurance certs current and your safety record posted. It backs you up.

If you don't have one, the honest answer is "we don't know," and that's a much harder conversation to have with an owner or a GC who is deciding whether to work with you again.

What a first policy actually needs to cover

You do not need a 30-page governance framework to start. You need something short enough that a superintendent reads it, specific enough that HR can enforce it, and reviewed often enough to keep up with the tools. Four things:

  1. Which tools are approved, and on what plan. A company-paid business or enterprise account with data protections turned on is a different thing than a free personal account. Name the approved tools.
  2. What data can never go into an AI tool. This is the heart of the policy. Be concrete.
  3. How AI output gets reviewed before it's used. A drafted RFI response, a summarized contract, a schedule suggestion. A human owns it before it goes out.
  4. Who owns the policy and how often it's reviewed. Quarterly, at minimum. Annual is too slow for this.

Starter template

Copy this, put it in a doc, fill in the brackets, and then get it in front of legal and IT. This is a starting point, not a finished policy.


[Company Name] AI Acceptable Use Policy

Effective date: [date]
Policy owner: [name, title]
Review cadence: Quarterly

1. Purpose

This policy sets the rules for how employees, subcontractors with company system access, and contractors use artificial intelligence tools in the course of work for [Company Name]. The goal is to let our people use these tools to work faster while protecting our clients, our trade partners, our employees, and the company.

2. Scope

Applies to any AI tool that generates, summarizes, analyzes, or transforms text, images, audio, code, or data, including but not limited to ChatGPT, Claude, Microsoft Copilot, Google Gemini, and AI features built into software we already use such as [Procore / Autodesk / Bluebeam / accounting system / other]. Applies on company devices, personal devices used for work, and any account used for company business.

3. Approved tools

Employees may use the following tools, on the following accounts, for work purposes:

  • [Tool name], [Business / Enterprise plan], provisioned by IT
  • [Tool name], [plan], provisioned by IT
  • [AI features inside approved company software]

Personal or free-tier accounts may not be used for company data. Any new tool must be reviewed and approved by [IT lead / policy owner] before use. When a vendor adds AI features to software we already use, [policy owner] reviews the vendor's data terms before the feature is turned on.

4. Information that must never be entered into any AI tool

Regardless of the tool or account type, the following may not be entered, uploaded, pasted, dictated, or photographed into an AI tool:

  • Client, owner, or developer contract terms, budgets, pricing, or financial information
  • Subcontractor and supplier bids, pricing, unit rates, or proposals
  • Any information covered by an NDA or confidentiality clause
  • Employee personal information including SSNs, payroll, medical, and HR records
  • Safety incident details that identify individuals
  • Site photos or video containing identifiable people, license plates, or client addresses, unless the tool is an approved company system
  • Bid packages, estimates, and pursuit strategy for projects we are competing on
  • Login credentials, API keys, or system access information
  • [Company-specific additions]

5. Information that may be entered into approved company tools only

  • Internal SOPs, checklists, and training materials
  • Project documents where the client has agreed in writing to AI use
  • [Company-specific additions]

6. Information that may be entered into any approved tool

  • Publicly available information
  • General industry questions with no project or client identifiers
  • Drafting help on documents that contain no confidential information

7. Review of AI-generated output

AI output is a draft, not a decision. Before any AI-generated content is sent externally, used in a contract, RFI, submittal, change order, schedule, estimate, or safety document, or acted on in the field, a qualified employee must review it for accuracy and take responsibility for it as their own work. AI does not replace a licensed professional's judgment on engineering, safety, legal, or financial matters.

8. Intellectual property

Do not upload drawings, specifications, or plans licensed from an architect, engineer, or client into an AI tool unless the license or the client permits it. AI-generated images, renderings, marketing copy, and proposal content are reviewed by [marketing / policy owner] before external use, and employees do not represent AI-generated work as produced by a licensed professional.

9. High-risk decisions

AI tools may assist with research and drafting but may not make or recommend the final decision on hiring, discipline, termination, compensation, or safety calls. A named person makes those decisions and documents the basis for them.

10. Disclosure

[Choose one:]

  • Employees must disclose AI use on client-facing deliverables when asked.
  • Employees must disclose AI use on client-facing deliverables proactively.

11. Client and trade partner questions

If a client, owner, or trade partner asks how we use AI with their information, refer them to [policy owner] and share this policy on request.

12. Violations

Violations of this policy may result in loss of tool access and disciplinary action up to and including termination, consistent with the employee handbook. If you're not sure whether something is allowed, ask [policy owner] before doing it.

13. Training

All employees with AI tool access complete [company AI training] before access is granted and annually thereafter.

14. Acknowledgment

I have read and understand the [Company Name] AI Acceptable Use Policy.

Name: __________________ Signature: __________________ Date: __________________


Where people get stuck

Section 4 is where the arguing happens, and that's fine. The whole point is to have the argument once, on paper, instead of a hundred times in a hundred inboxes. Estimating will push back on the bid data line. PMs will push back on contracts. Work it out with them and write down what you decided.

The other place people get stuck is section 3. If the answer to "which tools are we paying for" is "none," that's the real finding. A policy that says "don't use free tools" without giving people a paid alternative just pushes the usage underground.

If you'd rather not build this alone, an AI readiness audit is where I start with most companies, and the policy comes out of it. You can take our free readiness assessment in about two minutes, or book a free 30-minute audit and we'll talk it through.


Kelly Stephens is the CEO of EyeOn Automations, a custom software and AI company for construction and real estate operators. She spent 14 years in construction operations at PulteGroup before building software for the industry. Based in Southern California.

Want help applying this to your operation?

Book a free 30-minute audit and I’ll walk you through what’s actually possible.

Book your free audit

Ready to build your custom system?

Book a free 30-minute audit. I’ll review your current setup and show you exactly what’s possible.

Book Your Free 30-Min Audit

No commitment · 30 minutes · Get a custom roadmap