The vast majority of construction HR teams are using AI every week, but few say it is standardized, according to Arcoro’s AI use in Construction HR report. Without an AI-usage plan, your company could be at risk of leaking personal data or worse. The first step to creating an AI adoption plan that will get real time-saving results is understanding exactly what your team is doing with AI today.
This is essential, considering six in 10 organizations said they came to AI through individual experimentation, not a company decision. It’s likely you have no idea who is doing what with AI. Auditing your team’s AI use is essential, and surprise, it can be done in a week.
Day 1: Build the audit team
HR can’t be the only team auditing AI use, especially when its use is widespread. Law firm Ogletree Deakins suggests creating a cross-functional team from all your stakeholders. For large firms with multiple departments, that could include HR, IT, legal, and anyone else with a stake in AI use. But for smaller firms, where workforce responsibilities are shared between one or two people, that might include only a couple of people and possibly some external advisors. The concept is to include everyone who uses AI to ensure no blind spots exist in your AI plan.
An audit team also keeps everyone in the company aligned on objectives. That alignment will help you build a strong foundation for developing a sound audit that leads to an AI usage plan.
Day 2: Ask the question in writing
Get the details about how everyone in the company is using AI in writing. Having responses in writing, rather than a verbal say-so, creates a record and reduces the chance people will underreport what they’re using, considering many employees likely use AI without permission. According to a study from Gartner, 75% of employees will use some form of shadow IT (where employees use software and other technologies brought through the back door of their organizations) by 2027, up from 41% in 2022.
How you ask matters as much as what you ask. Zach Giglio, CEO of GCM, who is currently running dozens of AI audits with construction companies, says employees tend to fall into two groups. Some suspect their AI use is on shaky ground and are less likely to share it. Others have no idea their use carries any risk, so they'll tell you everything. To get honest answers from both groups, Giglio recommends speaking plainly, addressing fears up front, and not sugarcoating. Explain the audit is part of a larger goal to make the company and its people more efficient, so people see it as a step toward better ways of working and not a hunt for who broke the rules.
Send these questions to the team.
-
Current Tools: Which specific AI platforms or built-in generative AI software features are you using right now? Is it a personal account or a work-only account
-
Purpose: What specific tasks, such as summarizing text, writing drafts, or analyzing data, do you rely on AI to complete?
-
Frequency: How often are you using these tools?
-
Data Types: What company data, client information, or employee information are you putting into these tools?
-
Human Review: How do you verify and edit AI-generated outputs before sharing them or finalizing decisions?
-
Error Tracking: Have you encountered any major errors, hallucinations, or biased recommendations from the tools?
Add questions that aren't about AI
Giglio also advises against making the audit only about AI. When every question focuses on AI, people answer based on what they think AI can and can't do, which narrows the conversation. Asking about their day-to-day work gives you a fuller picture of both the risks and the opportunities. Consider adding:
-
Sensitive Information: What types of sensitive information do you handle on a day-to-day basis?
-
Extra Help: If you had another person working for you tomorrow, what's the first thing you'd have them do?
Day 3: Build the inventory
Once your audit team receives all the answers to the questions above, compile them into an audit table. Columns should list: tool name, department/user, use case, data sensitivity (does it touch employee records, wage data, immigration status, client specs), owner.
| Tool | Department/User | Use Case | Data Sensitivity | Owner |
|---|---|---|---|---|
| ChatGPT (free tier) | Recruiting | Drafting job postings | Low, no employee data entered | [Name] |
Audit tables are useful to provide an at-a-glance look at who is using which AI tools and why. But what’s more, when you do decide which AI tools your company should invest in, the audit table gives you a good idea about the number of licenses needed, helping you to control costs.
Day 4: Flag the risk tier
Once you have a scannable list of AI use across the company, sort the inventory by data sensitivity. Anything that touches Social Security numbers, I-9s, certified payroll, or immigration status gets flagged as high-risk regardless of which tool it's running through. (This is the ideal opportunity to consult an appropriate legal advisor with questions or concerns about risk.)
The difference is usually clear once you see it side by side. A recruiter using AI to draft a job posting is low-risk: no personal data goes in, and a bad output just means a rewritten posting. An HR admin using the same tool to summarize an employee's benefits file is high-risk: personal and compliance-sensitive data goes into a system you don't control, and an error there can mean a real compliance problem, not just a redo.
Every flagged item needs an owner, not just a red flag. Decide who reviews it, whether the tool is paused while it's under review or allowed to continue with a workaround in the meantime, and how long that review should take. Without an owner and a timeline, "flagged" tools tend to just keep running unchanged.
The result puts you in the best position to create a great usage policy for your company.
According to ABC's AI Resource Guide, an AI usage policy should define, in plain language, what's fine to run through a general-purpose AI tool (drafting, brainstorming, non-sensitive communications) and what should stay inside the HRIS (Social Security numbers, I-9s, certified payroll, immigration status, anything tied to a compliance record). (More on this in a later article.)
Day 5: Review and decide what's next
Bring the cross-functional team back together to look at the completed inventory. Walk it risk tier by risk tier, starting with anything flagged high-risk on Day 4, since those decisions are the most time sensitive.
For each tool use, the team lands on one of three outcomes:
-
Stays as-is. Low-risk, already working well, no changes needed.
-
Moves to a paid or business tier. The use case is legitimate, but a free or personal-account version doesn't have the data protections the company needs.
-
Goes to the policy conversation. Anything still flagged as high-risk, or any use case the team isn't ready to make a call on yet.
Then look at the results through a second lens: opportunity. The answers to your non-AI questions show where people are stretched thin and where their time pays off most. According to Giglio, team members who have seen AI deliver value can review those answers and map where AI could help. That way, the audit surfaces opportunities as well as risks.
Write the decision down next to each tool in the inventory, along with any opportunities the team identifies. This becomes the record you use to build the actual usage policy, so that work starts from decisions already made instead of from scratch.
Before the team leaves the room, name an owner for the policy and a rough timeline for when it's expected. A week of audit work loses momentum fast if there's no clear next step waiting on the other side of it.
Ready to turn this audit into a policy?
In our next post, we'll walk through how to translate your inventory and risk tiers into a usage policy your whole company can actually follow.
In the meantime, if you want to see how Arcoro helps construction HR teams manage AI-assisted workflows without losing control of sensitive data, get a quick demo.