Skip to content

Rights and contracts

Engineering ethics rules on client confidential information and AI

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Engineering ethics rules treat information about a client's business and technical processes as confidential, and that duty applies whether the information goes into an AI tool or into a licensed dataset. Before licensing project records, separate client-confidential content from the firm's own internal process records, and get written client consent for anything in between.

Key takeaways

  • Professional codes and state board rules both restrict disclosing client or employer information without consent.
  • The confidentiality duty applies the same way to pasting text into an AI tool and to licensing records.
  • Firm-generated process records such as QA/QC comments and RFI logs are often easier to license than client deliverables.
  • Removing client names is not always enough, because unique projects can identify the client on their own.
  • Ethics, contract and privacy reviews are three separate filters, and a record must pass all three.

What do engineering ethics codes say about confidential information?#

Engineering ethics codes say that engineers should not disclose confidential information about the business affairs or technical processes of a present or former client or employer without consent, except where law requires it. The NSPE Code of Ethics for Engineers sets that duty for its members, and state licensing boards adopt their own rules of professional conduct that bind licensees. NCEES, whose model rules many boards draw on, includes a similar duty not to reveal information obtained in a professional capacity without consent.

The two sources work differently. A society code is a professional standard for members, enforced through the society. A board's rules of professional conduct carry the force of the state licensing law, and a violation can affect a license. Many firms also commit to confidentiality by contract, which is often stricter than either.

None of these rules mentions data licensing by name, and none needs to. The duty attaches to the information, so the question for a managing principal is whether a given record contains client-confidential information and whether consent covers the proposed use.

Where do licensing boards and societies stand on AI?#

Licensing boards and engineering societies are still working out how existing duties apply to AI. Discussion has centered on responsible charge, competence, sealing work the engineer did not fully review, and confidentiality when project information goes into third-party tools.

Because guidance is evolving and differs by state, check your own board's current rules and any published statements before relying on a general summary. A firm licensed in several states should look at each one, since the strictest rule tends to shape firm-wide policy.

Watch for guidance on records as well as tools. A rule about disclosing project information to software vendors may reach a data license too, so read any statement for what it says about sharing information outside the firm, not only about using AI to produce work.

Which project records are client-confidential, and which belong to the firm?#

Project records divide roughly into what the client provided, what the firm delivered to the client, and what the firm produced to run its own practice. The third group is usually the most licensable; the first is usually the least.

Which project records are client-confidential, and which belong to the firm?
RecordTypical statusCommon licensing approach
Client-provided surveys, process data and site informationClient confidentialExcluded unless the client consents in writing
Stamped drawings, calculations and reportsDeliverables; the firm may own them under the contract, but they carry client informationExcluded or reviewed project by project
Internal QA/QC review comments and checklistsFirm process records that may quote client detailsOften licensable after de-identification
RFI and submittal response logsShared project records with mixed contentLicensable in part, depending on owner contracts
Proposals, fee estimates and staffing plans in DeltekFirm business recordsOften licensable after removing client and pricing details
Firm standards, design guides and lessons learnedFirm know-howUsually licensable, subject to trade secret choices

How confidentiality duties shape what a firm can license#

Confidentiality duties shape a license by deciding which record families enter scope and how they are prepared. A firm that maps each record family to its source, client or firm, can usually find a defensible core of internal process records.

Owning a document does not end the duty. EJCDC owner-engineer forms, for example, let the engineer keep an ownership interest in its documents, including copyright, while licensing the owner to use them on the project. Those same documents still hold the owner's site conditions, process requirements and budgets, so ownership answers who may copy a drawing, not whether the client's information inside it may be disclosed.

De-identification has to go further than names. A one-of-a-kind bridge, a hospital tower in a small city or a plant expansion for a known manufacturer can identify the client from technical details alone. Preparation should remove project names, addresses, site coordinates and distinctive features, or exclude the record.

  • Map each record family to its source: client-provided, deliverable or firm-generated.
  • Pull the confidentiality and ownership clauses from active and closed owner agreements.
  • Flag projects for public owners or critical infrastructure for separate review.
  • Set a de-identification standard that covers names, places and identifying features.
  • Request written consent where a client's information is central to a record.
  • Record the decision in a release memo signed by the managing principal.

Illustrative: a structural engineering firm draws the line#

Illustrative: a fictional structural and civil engineering firm runs Deltek Vantagepoint for projects, Bluebeam for markups and an internal peer review checklist for every set it seals. The managing principal wants to know what could be licensed without breaching duties to clients.

The firm's counsel and quality lead sort the records. Client-provided geotechnical reports and stamped calculation packages are excluded. Peer review comments, RFI response logs and proposal scoping notes are kept, with project names, addresses and distinctive structure descriptions removed. Two long-standing private clients are asked for consent to include richer records from their projects, and one agrees in writing.

The principal signs a release memo listing each included record family, the de-identification rules and the single consent. The firm can show any client exactly how its information was treated.

Using AI tools and licensing records are two separate questions#

Using AI tools inside the firm and licensing records to an AI developer raise the same confidentiality duty in different ways. An engineer who pastes client calculations into a consumer chatbot may be disclosing information to a vendor whose terms allow retention or training. A firm that licenses de-identified review comments under a negotiated agreement is making a controlled, documented disclosure.

Firms often need two policies: an acceptable-use policy for AI tools, which settles which tools and account types staff may use, and a licensing review process for records. Keeping them separate prevents a tool-use rule from blocking a well-prepared license, or the reverse.

Mistakes that create confidentiality exposure#

Confidentiality exposure in engineering firms usually comes from records that look internal but carry client content inside them. A peer review checklist may quote a client's process parameters, and a lessons-learned file may name the owner whose project went wrong.

Duties can also reach backward. Codes generally protect information about former clients and former employers, so material an engineer brought from a previous firm, or records from a closed client relationship, deserve the same scrutiny as current work.

  • Treating every internal file as firm-owned without reading its content.
  • Relying on a search for client names while leaving addresses, drawings and photos in place.
  • Including email threads where clients wrote freely about their own operations.
  • Forgetting subconsultant records that carry their own confidentiality terms.
  • Skipping a written record of who approved the scope and why.

How SourceX approaches professional confidentiality#

SourceX handles professional confidentiality in the Rights and Preparation steps of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Client-controlled material is identified and carved out before preparation, and the firm approves the final scope.

The SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization, so a firm can show what was excluded, how records were de-identified and who signed off.

Frequently asked questions

Does the NSPE code apply to firms or only to individual engineers?

Society codes and board rules are written mainly for individual engineers, but the people who would approve or prepare a license are usually licensed engineers bound by them. Firms typically turn those duties into firm policy, so the practical answer is to treat the duty as applying to the firm's decision.

Is removing client names enough to protect confidentiality?

Often not. Project type, location, size and unusual design features can identify a client even without a name. A de-identification standard for engineering records should cover places, identifiers and distinctive technical details, and records that cannot be made non-identifying should be excluded.

Do architects face similar confidentiality rules?

Architects have comparable duties through the AIA Code of Ethics and Professional Conduct for members and through state architecture board rules for licensees. The same sorting of client-provided, delivered and firm-generated records works well for architecture firms. Multidisciplinary firms should apply the stricter of the two rule sets to shared records.

What if the owner contract says nothing about confidentiality?

A silent contract does not remove the professional duty, and trade secret law or implied terms may still protect client information. Treat silence as a reason for care, not as permission, and consider asking the client for consent. Closed projects deserve the same care, since the duty does not end when the work does.

Who in the firm should sign off on a licensing decision?

Usually the managing principal or another officer with authority to bind the firm, after review by the quality lead and counsel. Where a specific client's information is involved, the principal in charge of that client relationship should confirm the treatment.

Sources

  • EJCDC E-500 language states that the Engineer retains an ownership and property interest in the Documents, including the copyright. Source
  • EJCDC E-500 grants the Owner a limited license to use the Documents on the Project. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify