A construction company AI policy is a short set of rules for how employees use AI tools like ChatGPT, Claude and Copilot.
It should list approved tools, say what data can never go in, require a person to check anything tied to cost, safety or pay, and name who owns the policy. One page is enough.
Your team is likely using AI already, whether there's a policy or not.
In RSM's 2025 survey, 95% of the 80 construction firms surveyed said they use generative AI. And 29% named data privacy and security as a top challenge.
Generic AI policies are written for office workers. Construction has extra risks:
Copy this and fill in the brackets to kickstart creating your company's AI policy.
[Company name] AI Use Policy
Purpose. We use AI to save time on writing, summarizing and planning. These rules protect our clients, our employees and our company.
Approved tools. [List tools, e.g., ChatGPT, Claude, Microsoft Copilot]. Use your company account only. Ask [policy owner] before trying a new AI tool.
Never put into an AI tool:
Always have a person check:
Disclosure. Tell [client/owner] when AI wrote a large part of a deliverable, if the contract requires it.
Questions and new tools: [Name, title, email].
Next review: [Date].
Keep it to one page.
Share it at your next all-hands or safety meeting.
Show three good examples and three bad ones.
Add it to onboarding for new hires.
Revisit it every six months.
Some AI tools make these rules easier to follow. When you evaluate one, ask: Does it use our existing permissions? Does it log what it does? Does a person confirm changes?
That's how we built Vyki, our AI payroll assistant in hh2 Time Tracking. She works inside your hh2 permissions. Every action is logged under the user's identity. She proposes changes and waits for confirmation. And she won't give tax advice, classify workers or rule on whether a pay practice is legal.
A construction AI policy should include approved tools, data that can never be shared (like SSNs, bid pricing and confidential contracts), work a person must check (quantities, contracts, safety and payroll), disclosure rules, a policy owner and a review date. Keep it to one page so people read it.
Yes. Small contractors often have fewer IT controls, so one pasted spreadsheet can expose employee data or bid pricing. A one-page policy takes an hour to write and gives everyone clear rules.
Most companies should say no. Personal accounts are outside company control, and you can't see or manage what's shared. Approve company accounts and check their data settings with IT.
Every six months is a good starting point. AI tools, features and data settings change often. Review the approved tools list, the never-share list and any new use cases your team has found.
Copy the template, fill in the brackets, and share it at your next team meeting. When you look at new AI tools, check them against the same rules.