Skip to content
Back

What Goes into a Construction AI Usage Policy?

Image of Arcoro's 6 minute drill to learn how to build an AI usage policy for construction HR

You’ve audited your company’s AI use. You understand who is using what, why, and the risks involved. Now it’s time to make an AI usage policy so everyone in the company is aligned with how AI should be used.

Construction companies are no strangers to risk, and AI use should be thought of in the same way. An AI policy should protect your company while guiding its use.

An AI usage policy should include:

  • A purpose or mission statement

  • An AI definition section

  • An explanation of who the policy applies to

  • A policy that allows for open use or prohibits or limits AI use

Let’s dig in.

Your purpose or mission statement

You want to establish clear guidelines that balance the use of AI (and all the wonders it can bring to business processes) with protecting your construction company’s precious data, and ensuring humans are the final decision makers.

Zach Giglio, CEO of GCM and an AI expert, suggests asking these questions to help define your purpose:

How are we using this as an organization?

  • Do we have a real policy or governance plan?

  • Do people understand what that is and how it relates to them?

The policy’s mission statement should complement your company’s existing values and mission. Aligning your mission and purpose with your company’s core values, can serve as a guiding principle for all AI-related decisions, according to JCA Law.

Here’s an example of an AI policy mission statement:


At [Company Name], we build with integrity, safety, and craftsmanship, and we expect our tools to support those same values. This policy exists to help every member of our team, from the jobsite to the office, use artificial intelligence in ways that make our work safer, more efficient, and more accurate.

We encourage employees to use approved AI tools to reduce administrative work, improve communication, and support better planning, so we can spend more time on the work that matters most: delivering quality projects for our customers. At the same time, we are committed to protecting the confidential information entrusted to us by our customers, partners, and employees, including project documents, bid data, and personal information.

AI supports our people. It does not replace their judgment. Every estimate, schedule, safety decision, and communication that leaves our company remains the responsibility of the person who approves it. By following this policy, we can embrace new technology with confidence while protecting the trust we’ve earned on every project.


An AI definition section

Your AI definition section needs to cover all software that uses machine learning and large language models to generate content, analyze data, automate tasks, or make recommendations.

According to the National Artificial Intelligence Initiative, “artificial intelligence” means a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments. Artificial intelligence systems use machine and human-based inputs to:

  • perceive real and virtual environments;

  • abstract such perceptions into models through analysis in an automated manner; and

  • use model inference to formulate options for information or action.

Name the standalone tools, like ChatGPT, Claude, Copilot, and Gemini, your employees may use, embedded tools like grammar tools, analytics platforms, and chatbots, as well as integrated tools in the software you already use.

Add who the reader should go to when in doubt about using a certain tool not listed.

Here’s an example of an AI definition:


For this policy, "artificial intelligence" (AI) means any software or feature that uses machine learning or large language models to generate content, analyze data, automate tasks, or make recommendations. This includes:

  • Standalone tools such as ChatGPT, Claude, Microsoft Copilot, and Google Gemini

  • Embedded features such as writing assistants, meeting transcription, and chatbots

  • AI within the software we already use, such as estimating, scheduling, and project management systems

Jobsite technology: Equipment or devices that use AI to capture or interpret information, such as drone mapping, camera-based safety monitoring, and site progress tracking

If you’re unsure whether a tool is covered, contact [Name/Title] at [email or phone] before using it.


An explanation of who the policy applies to

Your AI policy should apply to everyone in the company from the top down. Because even if someone isn’t using AI now, they might be in the future.

According to Brightmine, this includes:

  • Employees and Staff: Full-time, part-time, and remote workers who interact with AI tools during daily tasks.

  • Contractors and Consultants: Third-party individuals who work on company systems and must follow the same security rules.

  • Vendors and Partners: External providers supplying AI software or services integrated into company workflows.

  • Management and Supervisors: Leaders responsible for enforcing rules, reviewing AI output, and approving new tools.

Here’s an example of language that covers all AI policy users:


This policy applies to everyone who uses AI while working for or with [Company Name], whether in the office, in the trailer, or on the jobsite. This includes:

  • Employees at every level, including full-time, part-time, seasonal, and remote staff

  • Leadership, managers, and supervisors, who are also responsible for enforcing this policy and approving new tools

  • Subcontractors, consultants, and temporary workers who access company systems, data, or project information

  • Partners who provide AI tools or services used in our workflows

  • Employees who don’t currently use AI are still covered, since new tools and features may become part of their work at any time.


What’s allowed or not for AI use

Lastly, clearly define what’s not allowed, but also include what is. Giglio says he commonly sees a “what not to do list” but AI policies should also include what’s allowed. He explains you want employees to feel like AI is something that empowers them and not something that is a restrictive thing they must navigate.

Giglio reinforces including which types of proprietary and confidential information not to put into any tool. For example, PII, credit cards, social security numbers, but also trade secrets and private contracts.

Acknowledge that there’s gray area. Your AI policy cannot cover absolutely everything so point employees in the direction of who they can contact if they’re unsure if their AI use aligns with the policy.

And if something goes wrong, note what actions to take, who to call, and how to stop it. Give people that guidance because if you use AI enough, something eventually will go wrong.

Here’s an example of language to use:


What’s Allowed and What’s Not

We want AI to make your work easier. When used responsibly, approved AI tools can help you:

  • Draft emails, meeting notes, reports, and other routine communications

  • Summarize long documents, specifications, or meeting transcripts

  • Brainstorm ideas, organize information, and check writing for clarity

  • Support planning and analysis, as long as a person reviews the results

Never enter the following into any AI tool unless it has been approved for that use:

  • Personal information, such as Social Security numbers, birth dates, medical information, or home addresses

  • Financial information, such as credit card numbers, bank details, or payroll data

  • Confidential business information, such as bids, pricing, trade secrets, or customer agreements

You are always responsible for AI output. Review everything AI produces for accuracy before you use or share it. AI should never make final decisions on safety, hiring, estimates, or schedules.

When in doubt, ask. This policy can’t cover every situation. If you’re unsure whether use is allowed, contact [Name/Title] at [email or phone] first.

If something goes wrong, such as entering confidential information by mistake or noticing AI output that caused an error, stop using the tool and report it to [Name/Title] right away. Reporting quickly helps us limit the impact, and no one will be penalized for reporting an honest mistake.


An AI usage policy doesn’t need to be long or complicated to be effective. By defining your purpose, clarifying what counts as AI, spelling out who the policy covers, and setting clear guidelines for what’s allowed and what’s not, you give your team the confidence to use AI productively while protecting your company’s data and reputation.

AI tools are changing quickly, so plan to revisit your policy regularly and update it as new tools and risks emerge. With a clear policy in place, AI becomes a tool your people can trust, from the office to the jobsite.

Want to see how other construction companies are approaching AI? Download Arcoro’s A Practical AI Adoption Plan for Construction HR report to explore survey insights from construction professionals on how AI is being used across HR today.

See a demo of how HR technology can help your construction business.