Why Engineering Firms Need a Written AI-Use Policy

Most engineering firms today have staff using AI tools informally — a drafter pasting a spec into ChatGPT to summarize it, an engineer asking an AI assistant to check a formula, a project manager using AI to draft a client email. Without a written policy, this usage happens inconsistently, without any record of what was shared, which tool was used, or whether the output was checked before it reached a client deliverable. A written AI-use policy does not need to be restrictive to be useful — its job is to make explicit what is already implicit: which uses are fine without a second thought, which need review, and which are off-limits.

This is a starting template, not a finished policy. Every firm's risk tolerance, client contracts, and regulatory environment differ — legal counsel should review any policy before it's adopted, particularly around confidentiality and liability language.

Section 1 — Scope and Definitions

State plainly what the policy covers: any use of AI tools (chatbots, coding assistants, CAD/BIM copilots, document generators, calculation-checking tools) by firm staff in connection with firm work, whether on a firm-provided tool or a personal account. Define "AI tool" broadly enough to cover both obvious cases (ChatGPT, Claude, Copilot) and less obvious ones (AI features built into CAD, project-management, or document-review software).

Section 2 — Approved and Prohibited Uses

A useful policy names concrete categories rather than a single blanket rule:

  • Generally approved without prior review: drafting internal notes, summarizing publicly available reference material, generating boilerplate non-technical text (meeting agendas, generic email drafts), code-completion suggestions in a sandboxed development environment.
  • Approved with mandatory human review before use: AI-assisted drafting of RFIs, submittals, specifications, or client-facing reports; AI-suggested values in engineering calculations; AI-generated code that will run in a production tool or affect a deliverable.
  • Prohibited without explicit written approval from a principal or firm leadership: uploading client drawings, specifications, proprietary calculation methods, or any personally identifiable information (PII) to a public/consumer AI tool; using AI output as the sole basis for a stamped or sealed engineering deliverable without independent verification; using AI to generate content for a jurisdiction or code context the tool has not been verified against.

Section 3 — Data and Confidentiality Handling

This is the section most firms get wrong by omission. Specify: which AI tools (if any) are approved for use with client-confidential material, and under what data-handling terms (enterprise/business-tier accounts with no-training-on-inputs guarantees, versus free consumer tiers that may retain and train on submitted content). Require staff to strip or redact project-identifying information, client names, and site addresses before submitting any content to a tool that has not been explicitly cleared for confidential use. State explicitly that "the AI tool said it wouldn't retain the data" is not sufficient verification — only a written data-processing agreement or documented enterprise-tier terms qualify.

Section 4 — Review and Sign-Off Requirements

Require that any AI-assisted output entering a client deliverable, calculation, or code-compliance document be reviewed and explicitly signed off by a qualified staff member before it leaves the firm — the same standard applied to any other draft work product. Specify who is qualified to review AI-assisted calculation content (typically the engineer of record or a licensed reviewer, not whoever happened to generate the AI output). Log the review, even briefly — a dated initials-and-date on the AI-assisted section is enough to establish that human review occurred.

Section 5 — Tool Approval Process

Define who approves new AI tools for firm use (IT lead, a designated principal, or a small governance committee) and what they check before approval: data handling terms, whether the vendor offers an enterprise/business tier with no-training guarantees, and whether the tool has any track record of security incidents. Require staff to request approval before adopting a new AI tool for firm work, rather than discovering unauthorized tool use after the fact.

Section 6 — Incident Reporting

Define what counts as an incident (confidential material submitted to an unapproved tool, an AI-generated error that reached a client deliverable without being caught) and require prompt reporting to firm leadership without punitive consequences for the reporting staff member — the goal is catching problems early, not discouraging disclosure.