Engineering and architecture
AI policy template for architecture and engineering firms
By SourceX Editorial · Updated
Short answer
An AI policy template for an architecture or engineering firm should cover scope, approved tools, client data rules, human review, disclosure, records of AI use, vendor terms, external data licensing, and training and exceptions. Most firm policies stop at tool use; the external licensing clause is the one that protects the project archive from ad hoc requests.
Key takeaways
- An A/E firm AI policy needs rules for inbound tool use and for outbound use of firm records.
- Classify data before approving tools: public, firm internal, client confidential and restricted records need different rules.
- A licensed professional remains responsible for any AI-assisted content that goes into sealed documents.
- Licensing project records to outside parties should require a rights review, de-identification, a written license and a named approver.
What should an AI policy for an A/E firm cover?#
An AI policy for an A/E firm should cover how staff use AI tools on project work and how the firm decides whether its own records may leave the firm. The outline below fits most practices; each heading can be a short section of plain rules, with lists that change often kept as attachments.
Write the policy for the project manager at a deadline, not for a compliance file. Short rules with examples get followed; long principles get skipped.
- Purpose and scope: who the policy covers, including consultants and temporary staff working on firm systems.
- Approved tools: how tools are approved, who keeps the list and what happens to tools not on it.
- Data classes: which records may go into which tools.
- Human review and professional responsibility: who checks AI-assisted work before it is issued.
- Disclosure: when the firm tells clients about AI use, and how contract requirements are tracked.
- Records: what the firm logs about AI use on each project.
- Vendor terms: review of AI vendor terms, settings and training opt-outs.
- External data licensing: approvals required before firm records go to outside parties for AI use.
- Training, exceptions and enforcement: how staff learn the policy and who can grant exceptions.
Approved tools: a three-tier model#
Approved tools work best in tiers, so staff know at a glance what they may use and with which records. A short list kept by IT and signed off by a principal is easier to follow than a long list of banned products.
Move a tool between tiers only after a terms review, and record the date. Design platforms that add AI features to existing products count as new tools for this purpose.
| Tier | Definition | Example rule |
|---|---|---|
| Approved | Reviewed tools with business terms and training opt-outs confirmed | May be used with firm internal records and, where contracts allow, client confidential records |
| Conditional | Tools approved for limited or non-project uses | Public and firm internal records only; no client information |
| Not approved | Consumer tools, or tools whose terms let the vendor train on inputs | No firm or client records of any kind |
Client data rules by data class#
Client data rules work when every record falls into a class with a clear rule. Most A/E firms need four classes, and the hard calls sit in the client confidential and restricted classes.
Tag each project with its data class in Deltek, BQE or the project database. When a contract changes the class, such as an owner rider that bars AI use, update the tag so the rule follows the project rather than relying on the team's memory.
| Data class | Examples | Rule for AI tools |
|---|---|---|
| Public | Published project photos, marketing copy, adopted codes and standards | Any approved or conditional tool |
| Firm internal | Master specs, detail libraries, QA/QC checklists, proposal templates | Approved tools only |
| Client confidential | Project drawings, models, reports, owner correspondence | Approved tools, and only where the contract allows |
| Restricted | Security-sensitive designs, critical infrastructure, projects with AI prohibitions | No AI tools unless the client approves in writing |
Human review, disclosure and records#
Human review, disclosure and records rules are the part of the policy staff consult most, so write them as short sample rules a project manager can apply without interpretation. The core principle is that a licensed professional reviews and takes responsibility for any AI-assisted content in drawings, specifications, calculations or reports issued under seal. AI tools draft and check; they do not carry professional responsibility.
State licensing boards set the rules on responsible charge and sealing, so the policy should point to them rather than restate them. The sample rules below can be adapted to the firm's own titles and systems.
- Sample human review rule: Any AI-assisted content in a sealed or issued document must be reviewed by the professional in responsible charge before issue, and that review is recorded in the QA/QC log.
- Sample calculation rule: AI tools may help draft or check calculations, but every result used in design is verified by an independent method or a qualified checker.
- Sample disclosure rule: Project managers check each client contract for AI notice or approval clauses at kickoff and follow them; where a contract is silent, the firm's standard proposal language on AI use applies.
- Sample records rule: Each project record lists the AI tools used, the tasks they supported and the staff member who reviewed the output.
- Sample prohibition: No AI tool may be used to generate or apply a professional seal or signature.
Vendor terms and settings#
Vendor terms decide whether an AI tool keeps, reuses or trains on what staff put into it, so the policy should require a terms review before any tool reaches the approved tier. Check data retention, training on customer inputs, opt-out settings, storage location and how terms changes are announced.
Assign one person, usually in IT or operations, to keep dated copies of the terms the firm relied on and to recheck them at each renewal.
The clause most AI policies miss: external data licensing#
The external data licensing clause covers the outbound question most AI policies ignore: whether firm records may be licensed to AI developers or other outside parties. Without it, a request from a software vendor or developer can land with a project manager who has no basis to judge it.
Sample clause: No project records, model files, review comments or other firm records may be licensed, shared or provided to any outside party for AI training or evaluation without written approval from a principal designated by the firm. Approval requires a rights review of the client contract for each included project, de-identification of client, project and personnel information, and a written license defining permitted use, term, security and deletion. Records from restricted projects are excluded.
Have counsel review the final wording of this clause before the firm adopts it, and align its approval step with the authority matrix in the firm's operating or partnership agreement.
- Route every outside request for firm records to the designated principal.
- Review rights project by project, covering client contracts, consultant agreements and vendor terms.
- De-identify client, project, location and personnel details before release.
- Sign a written license with permitted use, term, security and deletion terms.
- Record what was licensed, from which projects, and who approved it.
Illustrative: a design firm adopts the policy#
Illustrative: a fictional A/E firm found staff using a mix of consumer chat tools on proposals and specification edits. The managing principal asked operations to draft a policy before the firm approved any business-grade tool.
Operations used the outline above, classified active projects in Deltek by data class, and moved a small set of business tools into the approved tier after a terms review. The draft added the external licensing clause after a software vendor asked whether the firm would share past model files.
When an AI developer later asked about the firm's QA/QC records, the request went straight to the designated principal, who started a rights review instead of an informal reply.
How the licensing clause maps to SourceX#
The licensing clause in this template mirrors the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. A firm whose policy already requires a rights review, de-identification, a written license and a named approver can work through a SourceX transaction without changing its own rules.
Each approved package comes with a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization, which is the record the policy asks the firm to keep.
Frequently asked questions
How long should an A/E firm's AI policy be?
Short enough that staff read it. Most firms can fit the rules on a few pages, with the approved tool list and data classes kept as attachments that IT updates without reissuing the policy. Longer guidance, such as prompt tips or tool how-tos, belongs in training materials.
Who should own the AI policy?
A principal should own it, with operations or IT maintaining the tool list and counsel or a risk manager reviewing the contract and licensing rules. Ownership by a principal signals that the policy reflects firm leadership rather than an IT preference.
Should consultants follow our AI policy?
Consultants working in your files or on your projects should at least follow the data class rules and any client AI clauses you must flow down. Add a short AI clause to consultant agreements so the expectations are written rather than assumed.
How often should the policy be updated?
Review it whenever a major tool, client clause or vendor term changes, and on a regular schedule as well. AI features increasingly arrive inside existing design and document platforms, so a scheduled review catches changes nobody requested.
Does the policy replace contract review?
No. The policy sets firm defaults, but each client contract can impose stricter terms. Project managers should check contract AI clauses at kickoff, and the external licensing clause always requires a project-by-project rights review.
Related resources
- InsightAI clauses in owner-architect agreements: what clients now ask for
- InsightDoes AIA B101 let an architect license project records for AI?
- InsightWho owns BIM models and shared project data on construction projects?
- IndustryConstruction data
- IndustrySoftware development agencies data
- DataCode review records
See if your company qualifies
A short company assessment. No data uploads are needed.