Redefining Technology

Construction & InfrastructureRegulations, Compliance & Governance

The construction AI governance charter, clause by clause: a blueprint you can draft from

A construction AI governance charter is the board-adopted rulebook for every AI system a contractor or infrastructure owner runs: which uses are permitted, who approves models, how site imagery and worker data are handled, and what happens when an AI-informed decision goes wrong. This page is the blueprint — twelve clauses, ready to draft from.

Construction leadership team reviewing an AI governance charter against live project and site-monitoring data
Construction & Infrastructure · Regulations, Compliance & Governance

Key takeaways

  1. A construction AI governance charter is a short, board-adopted rulebook — twelve clauses covering scope, risk classes, roles, data rules, approval gates, incident response and audit — not a 40-page legal treatise. If it has no named owners and no board minute, it is a draft, whatever the document says.
  2. The charter is enforced through contracts, not memos: a flow-down clause in every subcontract and JV agreement is what makes the rules bind the drone survey firm and the photo-analytics tool your supply chain brings to site — which is where most of the ungoverned AI actually is.
  3. Site imagery is the most contested clause. The same camera feed that flags a missing harness can score worker productivity, so the charter fixes the purpose in writing, requires a DPIA before deployment, and forbids silent repurposing — the specific failure the ICO's surveillance guidance warns against.
  4. No AI output enters the design or the CDE unchecked: a named competent person signs a check certificate for every generative or optimisation output that becomes project information, keeping the ISO 19650 audit trail intact and design liability where PI insurance expects it.
  5. Governance maturity runs Ungoverned → Drafted → Adopted → Enforced → Audited. Most contractors sit in the first two stages, and the move that matters most is the cheapest: a board vote, a named sponsor, and a register of every AI system already in use — including the ones nobody admits to.

Abbreviations used on this page

CDE
Common data environment (the ISO 19650 project information store)
BIM
Building information modelling
RACI
Responsible, accountable, consulted, informed — the accountability matrix
DPIA
Data protection impact assessment
CCTV
Closed-circuit television (site cameras)
HSE
Health and Safety Executive (GB safety regulator)
OSHA
Occupational Safety and Health Administration (US safety regulator)
RIDDOR
Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (GB)
JV
Joint venture
LLM
Large language model
AIMS
AI management system (the ISO/IEC 42001 construct)
PI
Professional indemnity (insurance)

Free · 8 questions · ~3 minutes

Score your firm on the governance ladder

Eight questions, one at a time, about three minutes. Answer them and we build your personalised governance report — your stage on the ladder, your score on each of the four dimensions, and the specific clause gaps standing between you and the next stage — and send it to your inbox. Your result doubles as the gap list for your first charter draft.

0 of 8 answered

Question 1 of 8Charter scope & roles

If a client's assurance team asked for the document that says which AI uses are permitted on your projects, what would you send them?

The charter's existence and adoption status is the fastest single tell of governance stage — and clients increasingly ask.

How the score maps to a stage
  • 05 — Stage 1, Ungoverned. AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
  • 611 — Stage 2, Drafted. A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
  • 1216 — Stage 3, Adopted. The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
  • 1721 — Stage 4, Enforced. The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
  • 2224 — Stage 5, Audited. An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.

What a construction AI governance charter is — and what it is not

A definition, the boundary with the policies you already have, and the route an AI use case takes through a chartered business versus an ungoverned one.

A construction AI governance charter is the board-adopted document that sets the rules for every AI system a contractor or infrastructure owner uses: which applications are permitted and in what risk class, who may approve a model for use, how site imagery and worker data are collected and retained, what evidence must exist before an AI output enters a design or a programme, and what happens — organisationally, not just technically — when an AI-informed decision goes wrong. It is short by design: a dozen clauses, each with a named owner and a defined piece of evidence, sitting above the detailed procedures the way a safety policy sits above method statements.

It is not an IT acceptable-use policy, and the distinction is where most first drafts fail. An acceptable-use policy governs employees using tools; a charter governs the business using AI — including the AI it buys, the AI its subcontractors bring to site, and the AI whose outputs end up in deliverables carrying the firm's name and its PI cover. Nor is it an ethics statement: a charter contains no aspirations, only rules with owners and evidence. The nearest familiar object on a construction site is the safety management system — and, as with safety, the international standards are converging on the same management-system shape: ISO/IEC 42001 (opens in a new tab) defines the AI management system (AIMS), the NIST AI Risk Management Framework (opens in a new tab) supplies the govern–map–measure–manage cycle, and ISO 19650 (opens in a new tab) already governs the information environment — the CDE — that construction AI reads from and writes into.

How an AI use case reaches a construction site: ungoverned vs chartered

Three routes through the same business. The top lane is how AI actually arrives at most contractors today; the middle lane is the path the charter builds; the bottom lane is the path clause 11 rehearses before it is needed. The stage ladder below measures how much of your estate travels each lane.

  • Where value leaks
  • Data & feeds
  • System-of-record action
  • Human in the loop
  • AI / model

The process, in words

  • On the ungoverned route, a tool is adopted by whoever finds it useful — a site app, a free LLM account, a subcontractor's drone stack. Project data flows out under terms nobody read, outputs enter the work unchecked and unrecorded, and the liability surfaces months or years later, at a claim, an audit or an incident, when no evidence exists to answer with.
  • On the chartered route, anyone may propose a use case, but it is risk-classified against clause 3 before anything else happens. Worker-facing or imagery-heavy uses trigger the clause 5 data checks and a DPIA; the model approval gate demands the evidence pack for its risk class; the system goes live with monitoring and, for safety-critical calls, a human confirming; and the register entry plus audit trail are produced as a by-product, not assembled later.
  • The incident path exists before it is needed. A wrong output that reached the work is declared an AI incident, contained by the kill-switch and manual fallback, reviewed — through the RIDDOR or OSHA interface where safety-relevant — and closed by a charter revision, so the same failure cannot recur under the same rules.
Step-by-step insights
Why the ungoverned lane is the default, not the exception
Construction adopts tools at the edge, not the centre — it always has. The industry's operating unit is the project, projects are measured on programme and cost, and anything that helps this week gets used this week. That culture delivered mobile phones, WhatsApp site groups and drone surveys years ahead of head-office policy, and it is delivering AI the same way. A charter that fights this culture loses; a charter that works with it — cheap proposals, fast classification, gates sized to risk — captures the same energy and makes it visible. The design goal is that the chartered route is barely slower than the ungoverned one for low-risk uses, and unavoidable for high-risk ones.
Risk classification is the hinge of the whole charter
Every other clause keys off clause 3. Classify a use case safety-critical and clause 9's human-oversight rules apply; classify it worker-facing and clause 5's DPIA obligation triggers; classify it commercial and clause 10's provenance rules bite. Getting classification wrong in either direction is expensive: over-classify and the gate becomes a bottleneck that pushes teams back to the shadow route; under-classify and a safety-relevant system ships with a back-office system's scrutiny. The classification session should take under an hour per use case, involve the HSE lead for anything site-facing, and be recorded in one page.
The DPIA is a decision tool, not paperwork
In the chartered lane the data protection impact assessment happens before deployment, while the decision can still change — which camera positions, what retention period, whether audio is captured at all, whether the vendor may reuse footage for model training. A DPIA done after go-live is a compliance memo about decisions already taken. The ICO's surveillance guidance is explicit that necessity and proportionality must be assessed before processing starts, and in practice the DPIA is where worker consultation happens: the workforce that helped set the purpose limits is the workforce that does not treat the cameras as management spyware.
The gate produces the evidence, not just the decision
The model approval gate's output is not a yes — it is a pack: the classification record, the data terms, the validation evidence appropriate to the risk class, the named approver, the date. That pack is what answers a client's assurance questionnaire in a day, satisfies an auditor sampling the register, and defends the firm when a decision informed by the system is challenged in adjudication. Firms that run gates as meetings without artefacts get the delay of governance with none of the protection.
Human oversight is a duty allocation, not a UX feature
For safety-critical classes the charter states that AI never discharges a statutory duty: the temporary-works coordinator still certifies the design, the appointed person still owns the lift plan, the supervisor still decides on the exclusion zone. The AI informs; a named competent person decides and remains accountable. This is not caution for its own sake — it is how HSE and OSHA duties actually work, since neither regime recognises a model as a duty holder. Writing it down protects the individual as much as the firm: nobody should discover in an investigation that they were implicitly relying on a system nobody told them they were accountable for.
The incident path is rehearsed, because construction already knows how
Construction rehearses failure better than almost any industry — fire drills, rescue plans, service strikes. Clause 11 extends the same discipline to AI: define what counts as an AI incident (a wrong output that reached the work, a data breach through an AI vendor, a system operating outside its approved purpose), name the kill-switch holder, drill the rollback to the manual process on a quiet shift, and route safety-relevant incidents into the existing RIDDOR or OSHA reporting machinery rather than a parallel one. The drill report — what was pulled, how long the fallback took, who was not reachable — is worth more than the procedure it tests.

The twelve clauses, one by one

The charter's full contents: what each clause governs, who owns it, and the evidence it must produce. This table is the blueprint — draft yours against it.

A working construction AI governance charter contains twelve clauses, and each one earns its place by producing evidence somebody will eventually ask for. The table below is the blueprint this page exists to deliver: read the clause, note the owner — a named role your business already has, not a new hire — and note the evidence column, because the evidence is the clause. A rule that generates no artefact cannot be enforced, audited or defended, and has no business in the document.

ClauseWhat it governsOwnerEvidence it produces
1 · Purpose, scope & definitionsWhich entities, projects and AI systems the charter covers — explicitly including supply-chain tools used on the firm's sites — and what counts as an AI systemBoard sponsorSigned charter with scope statement; board adoption minute
2 · AI use-case registerThe living inventory: every AI system in use, its owner, risk class, data touched and gate statusAI governance leadThe register itself, with quarterly review dates
3 · Risk classificationThe classes every use case is sorted into — safety-critical, worker-facing, design-affecting, commercial, back-office — and who classifiesAI governance lead + HSE leadOne-page classification record per use case
4 · Roles & RACIWho proposes, classifies, approves, operates and audits — by named role, with deputiesBoard sponsorRACI matrix; appointment letters for named roles
5 · Site imagery & worker dataCCTV and computer-vision purpose limits, retention, DPIA triggers, workforce consultation, biometric red linesDPO / privacy leadDPIA records; retention schedule; consultation notes; signage
6 · Subcontractor & JV data sharingFlow-down obligations, data-sharing terms for supply-chain AI, drone and photo tools brought to site, vendor reuse of project dataCommercial directorFlow-down clause in standard subcontract; data-sharing agreements
7 · Design outputs & information managementThe check obligation on generative and optimisation outputs before they enter the CDE; ISO 19650 alignment; who carries design liabilityDesign manager / information managerCheck certificates; CDE transaction log
8 · Model approval gatesThe evidence required before a system goes live, scaled by risk class; who approves; revalidation triggersNamed gate approvers per classGate checklist and approval record per system
9 · Human oversight of safety-critical decisionsWhere a competent person must confirm before action; the rule that AI never discharges a statutory dutyHSE leadOversight protocol; training and briefing records
10 · Bid & estimation modelsTraining-data provenance, confidentiality across JVs and frameworks, human sign-off on tender figuresCommercial directorBid-model log; provenance sign-offs; tender sign-off records
11 · Incident, rollback & reportingWhat counts as an AI incident, the kill-switch and manual fallback, drill cadence, RIDDOR/OSHA interfaceAI governance lead + HSE leadIncident log; drill reports
12 · Audit cadence & charter reviewThe sampling audit schedule, board reporting, and how findings become charter revisionsInternal audit + board risk committeeAudit reports; charter version history
The twelve-clause construction AI governance charter. Owners are roles most contracting businesses already staff; the evidence column is what an auditor, client or opposing counsel would ask to see. Clause numbers are referenced throughout this page.

Three drafting principles keep the document usable on a live project. First, clause length is capped: if a clause needs more than a page, the detail belongs in a procedure beneath it, referenced by name — the charter is the safety policy, not the method statement. Second, every owner is a role the business already staffs; a charter that requires hiring before it can operate will wait for the hire and then for the next one. Third, the charter binds by reference from the documents that already have teeth: the subcontract cites clause 6, project controls cite clause 8, the design management plan cites clause 7. A charter nothing else cites is a poster.

  • Clause 5 is where drafting slows down — let it

    Site imagery is the clause that will be read most hostilely, by the workforce first and possibly a tribunal later. Fix the purpose in writing (safety alerting, progress evidence), name what is forbidden without a fresh DPIA and consultation (productivity scoring, disciplinary use, biometric identification), and set retention short enough to defend. The ICO's video surveillance guidance (opens in a new tab) is the reference point for UK sites, and its necessity-and-proportionality test is a sound drafting standard anywhere.

  • Clause 7 is the one your PI insurer will read

    Generative and optimisation tools produce design information faster than checking capacity grows, and an unchecked output that enters the CDE carries the firm's name, not the vendor's. The clause states that AI output becomes project information only through a check certificate signed by a named competent person — which keeps the ISO 19650 information-management trail (opens in a new tab) intact and the liability question boring, which is what insurers prefer.

  • Clause 10 exists because estimating found AI first

    Bid and estimation models were among the earliest quiet adopters, and they concentrate two risks the rest of the charter does not cover: training data whose provenance mixes confidential rates across JVs and frameworks, and tender figures that nobody can explain in a post-award review. Provenance sign-off per training refresh and a human signature on every AI-informed tender figure are cheap, and the day a JV partner or a framework auditor asks, they are priceless.

The construction-specific risk surface the charter must cover

Five risk surfaces are peculiar to this industry — site imagery, supply-chain data, design liability, safety-critical decisions and bid models — and a generic AI policy misses all five.

Construction's AI risk surface is different from every other industry's because the site is a workplace, a camera target, a shared venue for dozens of employers, and a source of statutory duties all at once. A generic corporate AI policy — written for offices, screens and documents — covers almost none of what actually goes wrong on a project. The table below maps the five surfaces the charter must reach, the regulatory hook behind each, and the clause that governs it.

Risk surfaceWhere it shows upRegulatory / contractual hookClause
Site CCTV & computer-vision safety monitoring vs worker privacyPPE detection, exclusion-zone alerts, plant-proximity warnings — and the same feed's capacity for productivity scoringUK GDPR via ICO surveillance guidance; employment law; union agreements5, 9
Subcontractor & JV data sharingDrone photo-recognition, vendor analytics on your site data, JV partners' models trained on shared ratesContract terms; confidentiality; principal-contractor duties6, 10
Design liability for generative & optimisation outputsGenerative layouts, rebar optimisation, AI-produced temporary-works options entering the CDEISO 19650 information management; PI insurance; professional duty of care7, 8
Safety-critical decisionsAI-informed lift plans, exclusion zones, structural monitoring alerts, plant automationHSE / OSHA statutory duties — no model is a duty holder3, 9, 11
Bid & estimation model governanceAI-assisted take-offs, tender pricing, subcontractor quote analysisConfidentiality across frameworks; competition law exposure; auditability of tender figures10
The five construction-specific AI risk surfaces, where each shows up on a project, the regulatory or contractual hook, and the charter clause that governs it.

The first surface deserves the most drafting care because it is the one the workforce experiences daily. Computer-vision safety monitoring genuinely prevents harm — the same detection stack that spots a missing harness spots a worker inside a crane's slew radius — and it sits one configuration change away from being a productivity surveillance system. The ICO's surveillance guidance (opens in a new tab) requires necessity, proportionality and transparency before processing begins; the charter operationalises that as written purpose limits, a DPIA before deployment, workforce consultation, and an explicit prohibition on silent repurposing. On the safety side, HSE's construction guidance (opens in a new tab) and OSHA's construction standards (opens in a new tab) define duties that remain with competent persons regardless of what any model recommends — which is exactly what clause 9 writes down.

Regulation is also converging on this surface from the AI side. The EU AI Act (opens in a new tab) phases in risk-based obligations that reach several construction uses directly — worker-monitoring systems sit in its high-risk employment category, and safety-component AI carries conformity obligations — while ISO/IEC 42001 (opens in a new tab) gives clients a certifiable management-system standard to ask for in prequalification. Firms with an operating charter will experience both as paperwork they already hold; firms without one will experience them as a scramble.

Which approval gate does a use case need?

Clause 3's classification, drawn as a decision aid. Plot a proposed use case by the consequence of a wrong output and the sensitivity of the data it touches; the quadrant names the gate. The top-right — computer-vision safety monitoring — is where both dimensions peak at once, which is why it anchors the 90-day plan below.

Privacy gate

  • Workforce analytics, access-control matching, wearables
  • DPIA + clause 5 purpose limits + consultation
  • DPO sign-off before deployment, not after

Full gate

  • CV safety monitoring, plant-proximity AI, operator monitoring
  • DPIA + HSE oversight protocol + board-visible approval
  • The use case the whole charter is stress-tested against

Log and go

  • Document drafting, RFI summarising, tender-text search
  • Register entry and standard data terms only
  • The lane that keeps the charter credible with site teams

Engineering gate

  • Generative design options, quantity take-off, programme optimisation
  • Clause 8 gate + clause 7 check certificate
  • Named competent person signs before the CDE accepts it
Sensitivity of data touched — top: Worker imagery, personal and biometric data, bottom: Project documents, quantities
Consequence of a wrong output — left: Rework and embarrassment, right: Injury, structural or major commercial harm

The governance ladder: Ungoverned to Audited

Five stages describe how far the charter actually governs — from a document that does not exist to a management system an outsider can inspect. Each stage below carries its diagnostics, its trap, and what leaving it costs.

Governance maturity in construction runs up a five-stage ladder — Ungoverned, Drafted, Adopted, Enforced, Audited — and the stage is set by what the charter can actually reach, not by what it says. A document nobody adopted governs nothing; an adopted charter that stops at the payroll governs a third of the estate; only contract flow-down reaches the supply chain, and only a sampling audit proves any of it is still true. Each stage below is written for the person who would have to do the work: what it looks like from inside, the signals a reviewer can check in an afternoon, the anti-pattern that traps firms there, and the investment the next rung takes.

Defensible AI capability released against position on the ladder

The curve is steep in the middle for a reason: a charter releases almost no value while it is merely drafted, inflects sharply at adoption — when gates, registers and named owners start producing evidence — and compounds through enforcement as the supply chain comes inside the perimeter. The governance work is front-loaded; the payback is not.

Defensible AI capability released by stage

  • Stage 1 · Ungoverned — 38% of operators. AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
  • Stage 2 · Drafted — 27% of operators. A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
  • Stage 3 · Adopted — 19% of operators. The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
  • Stage 4 · Enforced — 11% of operators. The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
  • Stage 5 · Audited — 5% of operators. An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.

Curve shape: logistic, plotted from the stage data above. Distribution: Stage model aligned with NIST's govern–map–measure–manage cycle.

Select a stage

Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Ungoverned

38% of operators sit here

AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.

Ungoverned does not mean AI-free — it means AI-blind. In almost every contracting business at this stage, AI arrived the way mobile phones did: bottom-up, tool by tool, without a decision. An estimator pastes tender text into a free LLM to summarise it. A site engineer trials a photo app that auto-tags defects. A drone subcontractor runs photo-recognition over the site as part of its survey deliverable. Each choice is individually reasonable, and the sum is a portfolio of AI systems the business cannot list, running on data it never agreed to share.

The exposure at this stage is not hypothetical harm from a rogue model — it is the ordinary machinery of construction disputes meeting an evidence vacuum. When a claim lands, the other side's lawyers will ask how a quantity was produced, who checked the temporary-works option, where the site footage went. At Ungoverned the honest answer is 'we don't know', and 'we don't know' is a very expensive sentence in adjudication. The same vacuum applies upward: a main contractor cannot answer a client's assurance questionnaire about AI use it has never inventoried.

This is the cheapest stage to leave, because leaving it requires no technology at all. A register of what is actually in use — built by walking two live projects and asking, without blame, what people use — plus a one-page interim rule set, moves a business out of Ungoverned in weeks. What keeps firms here is not cost but the fear of what the inventory will find. That fear is misplaced: the shadow AI is already there, and the only question is whether management can see it before a dispute does.

In practice

The tender that went into a free chatbot

A regional contractor's estimator, under deadline, pastes a client's confidential bill of quantities into a free LLM account to summarise scope gaps. It works, so the habit spreads through the estimating team over a quarter. Nobody can now say which clients' commercial data has left the business, under which terms of service, or whether it trains someone else's model. The firm discovers the practice only when a client's security questionnaire asks directly — and the truthful answer costs it a place on the framework.

What it looks like

  • Site and office staff use AI tools under personal accounts
  • No document says which AI uses are permitted on projects
  • Subcontractors bring cameras, drones and analytics nobody logs
  • Project data leaves the business through tools nobody vetted

Diagnostic signals you can check this week

  • Ask three site engineers what AI tools they use; compare answers with what IT thinks is in use
  • Search expense claims and app-store invoices for AI tool subscriptions nobody approved
  • Ask who signed the data terms for the drone subcontractor's photo-recognition service
  • Ask for the list of AI systems on your largest live project — if the answer is a shrug, you are here

Anti-pattern · Banning AI outright

The reflex response to the first scare is a blanket ban. It is the single most counterproductive move available, because the tools demonstrably help and people will keep using them — now on personal phones and personal accounts, invisible to any register. A ban converts visible, governable use into shadow AI and destroys the trust needed to inventory it later. The charter's first clause exists precisely to avoid this: state what is permitted, so that what is not permitted becomes conspicuous.

What holds you here

Nobody owns the question, so every team assumes someone else has the list — and the list does not exist.

Highest-leverage next move

Name a board sponsor, walk two live projects, and build the register of what is actually in use — including subcontractor tools — before writing any policy.

Cost of leaving

Effort
4–8 weeks
Team
One senior sponsor, one project lead per pilot project, part-time
Risk
Low — the work is an inventory and an interim rule, nothing changes on site yet
To next stage
1–2 months

If this is you, the next step is

A two-week discovery: every AI touchpoint on two live projects, registered and risk-flagged.

Inventory your shadow AI

Stage 2

Drafted

27% of operators sit here

A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.

Drafted is the most deceptive stage, because the artefact exists and the risk does not move. Somebody — usually IT, sometimes QHSE — has adapted a generic AI acceptable-use template, added a construction paragraph, and uploaded it to the management system. In an audit of documents, the firm passes. In an audit of behaviour, nothing has changed: the estimating team's LLM habit, the ungated camera analytics, the subcontractor drone all continue exactly as at stage 1, because no mechanism connects the document to a project decision.

The structural failure is that a drafted charter has no owner with power and no hook into how construction actually governs itself. Construction businesses run on named accountabilities — the principal contractor role, the temporary-works coordinator, the appointed person for lifting. A policy that says 'management shall ensure' belongs to nobody. A charter that says 'the AI governance lead (currently J. Patel) maintains the register and chairs the gate' belongs to someone, and can be asked for in a project review the way a lift plan can.

The move from Drafted to Adopted is governance work, not writing work: a board minute adopting the charter, appointment letters for the named roles, the register made current, and the charter cited in at least one live project's controls. Firms stall here for years because legal review keeps polishing the text — but the text was never the gap. An imperfect charter that a board has adopted and a project quotes governs more than a perfect one in a folder.

In practice

The policy in the QHSE folder

A tier-two contractor publishes a nine-page AI policy in January, adapted from its IT provider's template. It requires 'appropriate approval' for AI tools without saying whose. By August, three new AI systems are live — a progress-photo analyser, a weather-delay predictor, and a subcontractor's crane-camera analytics — and none has touched the policy, because no gate exists to route them through. At the year-end management review the policy is marked 'implemented' because the document is published. Nothing on any site knows it exists.

What it looks like

  • An AI policy document sits in the QHSE or IT management system
  • It names roles generically ('management', 'IT') rather than people
  • Site teams have not read it and projects do not reference it
  • New tools still arrive without touching the document

Diagnostic signals you can check this week

  • Ask who is named, by name, in the charter — generic role nouns mean Drafted
  • Find the board minute adopting it; if there is none, it is a draft
  • Ask a project director when the charter last affected a project decision
  • Compare the register (if any) against tools actually in use on one site

Anti-pattern · Perfecting the document

The instinct at Drafted is another legal review cycle: more definitions, more caveats, forty pages. Every month spent polishing defers the only act that matters — adoption — and makes the charter less usable on site, where nobody will read past page three. Fix the length at a dozen clauses, accept that version 1.0 will be wrong in places, and let the audit cadence (clause 12) correct it. A charter is a living control, not a contract schedule; it improves by revision, not by pre-emption.

What holds you here

The document has no named owners and no board mandate, so projects have no reason to obey it and no route to follow it.

Highest-leverage next move

Stop editing. Take the charter to the board for formal adoption, issue appointment letters for the named roles, and cite it in one live project's controls within a month.

Cost of leaving

Effort
2–3 months
Team
Board sponsor, AI governance lead, HSE and commercial input, a half-day of board time
Risk
Low — the risk is reputational only if adoption is announced and then not resourced
To next stage
2–3 months

If this is you, the next step is

We restructure your draft into the twelve clauses, name the owners with you, and prepare the board paper.

Turn the draft into an adopted charter

Stage 3

Adopted

19% of operators sit here

The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.

Adopted is where governance starts to exist in the sense that matters: somebody can be asked. The board minute is not ceremony — it is what makes the charter citable in a project review, quotable in a client assurance response, and defensible in a dispute. The register is current for the firm's own systems, and anything new goes through the gate: classified by risk, checked for data implications, approved by a named person with the evidence recorded. For the first time, the business can answer 'what AI do you run and who approved it?' without an archaeology project.

The characteristic gap at this stage is coverage. The gate catches what is new; it has not been pointed at what already exists. The progress-photo tool adopted two years ago, the estimating model an enthusiast built in a spreadsheet, and — above all — the AI the supply chain brings to site remain outside the register. A contractor's real AI estate at this stage is typically one-third its own gated systems, one-third its own legacy systems, and one-third subcontractor and vendor tools it has never seen. Governance covers the first third.

The stage also exposes an uncomfortable truth about construction's structure: a main contractor's risk surface is mostly other companies. The drone survey firm's recognition models, the plant hire company's operator-monitoring cameras, the design consultant's generative tools all operate on your site, on your data, inside your principal-contractor duties — and none of them reads your charter. The move to Enforced is therefore a commercial move: the charter's obligations must enter subcontracts, JV agreements and procurement questionnaires, because contract terms are the only governance instrument that crosses a company boundary.

In practice

The first gated camera system

A contractor's first system through the new gate is a computer-vision safety camera for a city-centre frame. The gate works exactly as designed: the use is classified safety-critical and worker-facing, the DPIA is done before installation, purpose limitation is written down — safety alerting only, no productivity analytics — and the workforce is briefed. Three floors up, the same project is running a progress-photo tool bought two years earlier that has never been classified, and the steel subcontractor's telematics feed streams operator data to a vendor nobody has assessed. The gate is real; its perimeter is not.

What it looks like

  • A board minute adopts the charter and a named sponsor answers for it
  • The AI use-case register is current for the firm's own tools
  • New systems pass a risk-classified approval gate before going live
  • Worker-facing systems get a DPIA before deployment

Diagnostic signals you can check this week

  • Pick the oldest AI tool in use and ask for its gate record — legacy exemption means Adopted, not Enforced
  • Count register entries flagged as subcontractor or vendor systems; near zero means the perimeter is your payroll
  • Ask the DPO when a DPIA last changed a deployment decision, not just accompanied one
  • Check whether any subcontract signed this quarter mentions the charter

Anti-pattern · Gating only the new

Approval gates are naturally installed at the front door, so everything already inside is grandfathered by default. But the risk was already in the building: the legacy tools were adopted with the least scrutiny, run on the oldest data terms, and are the most embedded in daily work. Schedule the retrospective gating of the legacy estate as a named programme with a deadline — highest risk class first — or Adopted quietly becomes a stage where the register describes the tidy third of the estate and certifies ignorance of the rest.

What holds you here

The charter binds employees but not the supply chain, and most of the AI on a construction site belongs to the supply chain.

Highest-leverage next move

Draft the flow-down clause with commercial and legal, put it into the standard subcontract, and add AI questions to procurement prequalification — then gate the legacy estate.

Cost of leaving

Effort
3–6 months
Team
AI governance lead, commercial director, DPO, procurement; legal input for the flow-down clause
Risk
Medium — supply-chain pushback on data terms is real and needs commercial sponsorship
To next stage
3–6 months

If this is you, the next step is

A structured retrospective: classify and gate everything already in use, highest risk first.

Gate the legacy estate

Stage 4

Enforced

11% of operators sit here

The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.

Enforced is the stage where the charter stops depending on goodwill. The mechanism of enforcement in construction is never the policy document — it is the contract, the project controls, and the induction. When the subcontract says register-before-use, the drone survey firm's photo-recognition goes through data-sharing terms before its first flight, because payment depends on it. When the gate approval is a hold point in project controls, a camera system cannot be commissioned around it any more than a crane can be erected without its lift plan. Governance has moved from documents into the machinery the industry already obeys.

The second marker of Enforced is that failure has been rehearsed. An AI incident clause that has never been drilled is a theory; the firms at this stage have actually pulled the kill-switch on a live system on a quiet Friday — reverted the camera analytics to plain recording, run the manual take-off process, checked who noticed and how long it took. The drill converts the rollback from a paragraph into a capability, and it produces the artefact that matters in front of a regulator or a client: evidence that the firm can stop its own systems, promptly, and knows what happens when it does.

What Enforced cannot yet prove is itself. The rules bind, the gates hold, the drills run — but nobody independent has sampled the evidence to confirm that what the register says matches what the sites do. That is the audit gap. It matters because enforcement decays silently: a busy project waves a tool through, a subcontractor's renewal drops the clause, a gate checklist gets rubber-stamped. Without a scheduled, sampling audit, the firm discovers the decay the way it discovers most governance failures — during a dispute, when the other side finds it first.

In practice

The subcontract that named the drone

A main contractor's standard subcontract now carries the flow-down clause: any AI system used on the project must be entered in the contractor's register before use, with data-sharing terms for anything touching site imagery or personal data. A survey subcontractor mobilising for a viaduct package discloses its drone photo-recognition stack at prequalification; the data terms take a fortnight to agree and the flight goes ahead — registered, purpose-limited, with imagery retention set at ninety days. The same quarter, the contractor runs its first AI incident drill and finds the camera-analytics kill-switch works but nobody had the vendor's out-of-hours number. The drill report fixes it.

What it looks like

  • A flow-down clause puts charter obligations into every subcontract and JV agreement
  • Gate approval is a precondition in project controls, not a parallel process
  • AI incident and rollback procedures exist and have been drilled, not just written
  • Site inductions ask about AI tools the same way they ask about plant tickets

Diagnostic signals you can check this week

  • Read the last three subcontracts signed: is the flow-down clause present and unamended?
  • Try to commission an AI system around the gate on a test basis — if you can, so can a project under pressure
  • Ask for the last incident drill report and what it changed
  • Check whether prequalification answers about AI tools reach the register or die in procurement files

Anti-pattern · Enforcement by email

The tempting shortcut is to police the charter through memos, toolbox talks and escalation emails instead of contracts and controls. It works while attention lasts and fails the moment a project is late, because exhortation loses to programme pressure every time. Only two instruments survive a commercial dispute: what the contract says and what the project controls recorded. If an obligation matters, it goes in one of those; if it lives only in an email, assume it does not exist.

What holds you here

Enforcement is real but unverified — nothing independent confirms the register matches the sites, so decay is invisible until a dispute finds it.

Highest-leverage next move

Schedule the first internal audit: sample gate records against live systems on two projects, test one rollback, and report findings — including the awkward ones — to the board.

Cost of leaving

Effort
6–12 months to full audit readiness
Team
AI governance lead, internal audit (or external assurance partner), board risk committee time
Risk
Medium — the audit will find things; the risk is a culture that punishes the finding rather than the decay
To next stage
6–12 months

If this is you, the next step is

We draft the flow-down clause and prequalification questions with your commercial team.

Put the charter into your subcontracts

Stage 5

Audited

5% of operators sit here

An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.

Audited is not a bigger version of Enforced — it is a different relationship with evidence. At every earlier stage, the firm asserts its governance; at this stage it can demonstrate it, because an independent function has sampled the trail on a schedule and reported what it found. The audit is deliberately adversarial in method: pick systems from the register and walk to site to find them; pick tools on site and walk back to find their gate records; pull a DPIA and check the deployed camera against the purposes it states. The gaps found are the product, not the embarrassment.

This is also the stage where the charter becomes a management system in the formal sense — the shape ISO/IEC 42001 standardises for AI, deliberately parallel to ISO 9001 and 45001, which construction firms already run. Certification is optional and often unnecessary; the shape is not. Plan-do-check-act applied to AI means the charter states intent, the gates and registers do the work, the audit checks it, and the review acts on what the audit found. Construction firms have an advantage here that they rarely notice: they already operate more management systems than almost any other industry, and the muscle transfers directly.

Sustaining Audited is a discipline of revision, because the ground moves constantly — the EU AI Act's obligations phase in, the ICO updates surveillance expectations, clients add AI schedules to their frameworks, and the firm's own AI estate turns over. The version history of the charter is therefore the single best artefact of this stage: a charter still on version 1.0 after two years has not been audited in any meaningful sense, whatever the calendar says. The firms genuinely at this stage treat the charter the way they treat their safety management system — permanently provisional, revised by evidence, and owned at board level without discussion.

In practice

The audit that changed a clause

An infrastructure contractor's second annual AI audit samples the estimating department's bid-model records and finds the model was retrained mid-year on a dataset that included rates from a live JV with a competitor — technically permitted by the charter's silence, commercially indefensible if the JV partner ever asked. The finding goes to the board risk committee; clause 10 is amended to require provenance sign-off on every training-data refresh for commercial models; the version history records the finding, the change and the date. Eight months later a client's framework audit asks exactly that question, and the contractor answers it with the paper trail instead of a promise.

What it looks like

  • Internal audit samples gate records, DPIAs and register entries against reality on site
  • Audit findings produce charter revisions with a visible version history
  • The arrangement aligns with ISO/IEC 42001's management-system shape
  • Client and regulator assurance requests are answered from standing evidence, not projects

Diagnostic signals you can check this week

  • Read the charter's version history — evidence-driven revisions mean Audited; a frozen v1.0 means theatre
  • Ask what the last audit found; 'nothing' is the wrong answer at any real firm
  • Check whether audit scope includes supply-chain systems, not just the firm's own
  • Time how long a client AI-assurance questionnaire takes to answer — days from standing evidence, or weeks of scramble

Anti-pattern · Audit theatre

The terminal failure mode is auditing the documents instead of the estate: re-reading the charter, confirming the register file exists, ticking that the DPIA template is current — and never walking to a site. A document audit will pass every year while the actual perimeter erodes. The test of a real audit is that it samples outward from paper to reality and inward from reality to paper, and that it finds things. Budget for findings; a clean audit of a live AI estate is a sign the audit is broken, not the estate.

What holds you here

Sustaining the cycle through leadership changes and quiet years — audit is the first budget line cut when nothing has gone wrong recently.

Highest-leverage next move

Treat the charter like the safety management system: standing audit schedule, board review with findings on the agenda, and a version history that proves the document is alive.

Cost of leaving

Effort
Continuous — one audit cycle and one board review per year, minimum
Team
Internal audit or external assurance partner, AI governance lead, board risk committee
Risk
Concentrated — regulatory and client-assurance exposure if the cycle lapses while the badge is still claimed

If this is you, the next step is

We run a mock audit: sample your registers and gates against two live projects, report what a client's auditor would find.

Stress-test the audit trail

Where construction firms actually sit on the ladder

The distribution is bottom-heavy, and the industry context explains why: the sector that digitised last is now adopting AI faster than it is governing it.

Most construction firms sit on the bottom two rungs — AI in daily use with either no charter at all or a drafted document with no grip. That bottom-heaviness is not a moral failing; it is the predictable result of the industry's structure. Construction digitised later than almost every other sector, then adopted AI tools at the edge — project by project, trade by trade — faster than any central function could see, let alone govern. The distribution below is illustrative, synthesised from the named research rather than measured by us, and it will shift as client prequalification starts asking governance questions.

Distribution of construction firms across the governance ladder

Illustrative distribution — model-derived, not a survey result. Ungoverned is the mode; the sharpest drop on the ladder is into Enforced, where governance must cross company boundaries into the supply chain.

Share of firms (illustrative)

  • 38% — 1 · Ungoverned (the mode)
  • 27% — 2 · Drafted
  • 19% — 3 · Adopted
  • 11% — 4 · Enforced
  • 5% — 5 · Audited

Source: Illustrative, synthesised from McKinsey construction-productivity and WEF construction-digitalisation research

The pressure to climb the ladder is arriving from three directions at once. Clients — especially public infrastructure clients — are adding AI questions to prequalification and framework audits. Regulation is phasing in: the EU AI Act's (opens in a new tab) risk-based obligations reach worker-monitoring and safety-component AI directly, and ISO/IEC 42001 (opens in a new tab) gives assurance teams a certifiable standard to name. And insurers are beginning to ask how AI-produced design information is checked before it carries the firm's PI cover. The World Economic Forum's construction work (opens in a new tab) has argued since 2016 that the industry's technology transformation depends on governance and skills keeping pace with tooling — the charter is what that looks like at the level of a single firm.

The AI RMF is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.

What governed AI looks like in public

Three publicly reported programmes, read against the ladder. None is an Atomic Loops engagement — each links to the organisation's own published material.

The clearest public evidence for the charter thesis is in how the industry's most-watched AI programmes were run. In each case below, the interesting part is not the model — it is the governance shape around it: who reviewed the outputs, how the workforce was brought inside the purpose, and how obligations crossed company boundaries. Each is read against the ladder, on the organisations' own published material.

Three programmes read against the ladder

Outcomes as reported by the organisations themselves; verify against the linked source before reusing figures. Stage readings are our interpretation of the public record, not the organisations' own claims.

Suffolk construction operations with AI-assisted site monitoringSuffolkUS general contractor · multi-billion-dollar annual programme13
Challenge
Thousands of jobsite photos and camera frames per week carried safety-relevant content nobody could review manually — and analysing worker imagery at scale raises exactly the privacy and trust questions clause 5 exists for.
Approach
Suffolk has publicly described building predictive analytics on jobsite imagery through its innovation programme, using AI to flag safety risk indicators in site photos for human safety managers to act on — the review-and-act loop kept with people, the analytics scoped to safety.
Reported outcome
Suffolk publicly presents AI-assisted safety analytics as a standing part of its delivery model, with risk flagged earlier from imagery its teams already capture, as described in its own published material.
What it shows about the curvePurpose-scoped imagery analytics with humans acting on the flags is what clause 5 plus clause 9 look like when they work: the camera estate became governable because the purpose was fixed and the decision stayed human.

Suffolk — published material (opens in a new tab)

Balfour Beatty infrastructure worksBalfour BeattyUK infrastructure group · 26,000+ employees12
Challenge
As one of the UK's largest contractors, Balfour Beatty faced the industry's automation question early: how a business built on human site supervision governs a future of increasingly autonomous plant and AI-assisted delivery.
Approach
Its published Innovation 2050 paper set out a public position on automation — up to and including largely human-free sites — and publicly called for the industry to develop the standards and skills to govern that transition, alongside its own digital and AI deployments.
Reported outcome
Balfour Beatty's own published material stakes out the governance agenda — the paper is a public artefact of the Drafted stage: a stated position and direction, with the enforcement machinery to be built beneath it.
What it shows about the curveA published vision is the beginning of governance, not the end: the ladder's hard rungs — adoption, flow-down, audit — are what turn a position paper into rules a project follows. That is exactly the Drafted-to-Adopted gap most large firms are in.

Balfour Beatty — published material (opens in a new tab)

HS2 main works delivered by the SCS joint venture of Skanska, Costain and StrabagHS2UK major infrastructure programme · delivered through JVs including SCS (Skanska Costain Strabag)24
Challenge
Europe's largest construction programme has dozens of contractors and JVs deploying AI — progress monitoring, logistics optimisation, safety analytics — on sites where the client must maintain assurance over systems it neither built nor operates.
Approach
HS2 publicly reports running innovation through a structured programme: AI deployments enter through defined trials with named accountabilities, and obligations reach the delivery JVs — such as SCS — through the contractual assurance regime rather than goodwill.
Reported outcome
HS2's own published innovation reporting describes AI deployed across the programme under its assurance framework — the client-side pattern of gates plus contractual flow-down operating at national-programme scale.
What it shows about the curveEnforced-stage governance is contractual: when the client's gates and the JV contracts carry the obligations, supply-chain AI is registered and assured as a condition of working — the exact mechanism clause 6 scales down to a single firm.

HS2 — published material (opens in a new tab)

The governance stack: the artefacts behind the clauses

Five layers of working machinery turn the charter from a document into a system — and each rung of the ladder switches another layer on.

The charter is enforced by a stack of five artefact layers, and knowing which layer each ladder stage requires stops firms building the wrong thing first. Nothing in the stack is exotic — it is registers, checklists, contract clauses and logs, the same species of artefact construction already runs its safety and quality systems on. The annotation on each layer marks the stage that first requires it: a firm at Drafted needs only the top layer done well, and a firm buying audit tooling before it has a register is decorating a house with no foundations.

The five-layer governance stack, stage-annotated

Layers render top to bottom in the order a firm should build them. 'From stage' marks the ladder rung that first requires the layer — build ahead of your stage by one layer at most.

  1. The charter itself

    Stage 2+

    • Twelve clausesEach with a named owner and defined evidence
    • Scope statementEntities, projects and supply-chain tools covered
    • Version historyEvery revision dated, with the finding that drove it
  2. AI use-case register

    Stage 3+

    • Register entriesSystem, owner, risk class, data touched, gate status
    • Supply-chain flagsSubcontractor and vendor systems marked as such
    • Quarterly reviewEntries confirmed against reality, not rolled forward
  3. Approval gates & checks

    Stage 3+

    • Gate checklistsEvidence scaled to risk class, approver named
    • DPIA workflowTriggered by worker-facing classification, before deployment
    • Check certificatesSigned before any AI output enters the CDE
  4. Contract & flow-down layer

    Stage 4+

    • Flow-down clauseRegister-before-use in every subcontract and JV agreement
    • Data-sharing termsImagery, personal data and reuse rights per vendor
    • Procurement questionsAI disclosure at prequalification, feeding the register
  5. Monitoring, incident & audit layer

    Stage 4+

    • Performance monitoringEach gated system watched against its approved envelope
    • Incident log & kill-switchDrilled rollback to the manual process
    • Audit trail & cadenceSampling audits on a schedule, findings to board (stage 5)

Pipeline described

  1. The charter itself (stage 2+) — Twelve clauses: Each with a named owner and defined evidence; Scope statement: Entities, projects and supply-chain tools covered; Version history: Every revision dated, with the finding that drove it
  2. AI use-case register (stage 3+) — Register entries: System, owner, risk class, data touched, gate status; Supply-chain flags: Subcontractor and vendor systems marked as such; Quarterly review: Entries confirmed against reality, not rolled forward
  3. Approval gates & checks (stage 3+) — Gate checklists: Evidence scaled to risk class, approver named; DPIA workflow: Triggered by worker-facing classification, before deployment; Check certificates: Signed before any AI output enters the CDE
  4. Contract & flow-down layer (stage 4+) — Flow-down clause: Register-before-use in every subcontract and JV agreement; Data-sharing terms: Imagery, personal data and reuse rights per vendor; Procurement questions: AI disclosure at prequalification, feeding the register
  5. Monitoring, incident & audit layer (stage 4+) — Performance monitoring: Each gated system watched against its approved envelope; Incident log & kill-switch: Drilled rollback to the manual process; Audit trail & cadence: Sampling audits on a schedule, findings to board (stage 5)
Step-by-step insights
The charter layer — short, owned, versioned
Everything about the top layer is designed for citation: short enough that a project director has actually read it, owned clause-by-clause so questions have an addressee, and versioned so that 'which rules applied last March?' has an answer. The version history matters more than firms expect — in any dispute about an AI-informed decision, the first question is what the rules were at the time, and a charter without version control cannot answer it. Treat the document like a controlled QHSE document from day one, because that is what it is.
The register — the single most diagnostic artefact in the stack
Show us a firm's AI register and we can read its true stage in ten minutes. No register: Ungoverned, whatever documents exist. A register of only the firm's own tools: Adopted, with the supply-chain third of the estate dark. A register where subcontractor systems appear with data-sharing terms attached: Enforced. Entries that carry audit-sampling dates: Audited. The register is also where governance meets reality fastest, because it decays within a quarter unless someone owns it — which is why clause 2 gives it a named owner and a review cadence rather than assuming completeness.
Gates and checks — scale the evidence to the class, ruthlessly
The commonest way firms kill their own charter is a one-size gate: the same committee, the same form, whether the use case is tender-text summarising or plant-proximity detection. Within a quarter the gate is a bottleneck, site teams route around it, and the shadow estate regrows. The gate design that survives is class-scaled: log-and-go uses clear in a day on a register entry; engineering uses add the check certificate; worker-facing uses add the DPIA and consultation; the full-gate class gets the board-visible pack. The gate's throughput for low-risk uses is a governance feature, not a compromise.
The contract layer — where governance crosses company boundaries
Nothing in the top three layers reaches a subcontractor. The flow-down clause is short — any AI system used on the project enters the contractor's register before use, with data-sharing terms for anything touching imagery or personal data — but its effect is structural: it converts the charter from an internal policy into a condition of doing business on your sites. Pair it with two procurement questions at prequalification ('what AI systems will you use on this package?' and 'what data do they send off-site?') and the register starts filling from the supply chain instead of chasing it.
Monitoring, incident and audit — the layer that proves the rest
The bottom layer exists because every layer above it decays silently. Monitoring watches each gated system against the envelope it was approved for — the camera that was approved for safety alerting and starts feeding a productivity dashboard has left its envelope, and something should notice. The incident log and drilled kill-switch turn failure into evidence instead of folklore. And the sampling audit is the only mechanism that tests the whole stack at once: pick register entries and walk to site; pick site systems and walk back to the paper. Firms that run this layer stop being surprised by their own estate, which is the quiet definition of the Audited stage.

The build order is the reverse of how firms instinctively buy: the temptation is to start with monitoring tooling because it is purchasable, but the stack only works top-down. A register you cannot buy — it is a week of walking projects and asking. Gates you cannot buy — they are decisions about evidence and named approvers. The tooling layer accelerates a governance system that already exists on paper and in habit; it cannot substitute for one.

A 90-day plan: draft and adopt the charter around your site cameras

The fastest honest route from Ungoverned to Adopted, run against one live risk — the computer-vision safety cameras most contractors already operate — so every clause is tested on a real system before the board signs it.

Drafting and adopting a charter takes about 90 days when it is built around one live system, and much longer when it is written in the abstract. The plan below uses the computer-vision safety camera estate as the test article, for three reasons: most contractors already run one, it sits in the full-gate quadrant of the classification matrix — maximum consequence, maximum data sensitivity — so a charter that handles it handles everything below it, and it is the system your workforce already has opinions about, which forces the consultation muscle to develop early. The safety context is not abstract either: HSE's fatal-injury statistics (opens in a new tab) record more worker deaths in construction than in any other GB sector, which is both why these cameras exist and why the rules around them must be written down.

Ungoverned to Adopted in one quarter, on the camera estate

One firm, two pilot projects, one named sponsor. If any phase needs more than its window, narrow the scope — fewer projects, one camera system — rather than extending the plan.

  1. Days 1–15

    Register the estate, cameras first

    Name the board sponsor and the AI governance lead. Walk two live projects and register every AI touchpoint — the camera analytics, the progress-photo tools, the estimating models, the subcontractor drones — without blame, or the inventory will be fiction. Issue a one-page interim rule: no new AI system on any project without a register entry.

    A register that matches reality, and a named owner

  2. Days 16–40

    Draft the twelve clauses against the cameras

    Use the camera system as the test article for every clause. Run the DPIA properly — camera positions, retention, vendor reuse rights, no audio. Write the purpose limits (safety alerting, incident evidence; no productivity scoring, no disciplinary use without a fresh assessment). Consult the workforce and record it. Where a clause cannot answer a camera question, redraft the clause, not the answer.

    A twelve-clause draft, tested against a live system

  3. Days 41–65

    Adopt, appoint and gate

    Take the charter to the board for formal adoption and minute it. Issue appointment letters for the named roles. Run the camera system through the approval gate retrospectively — classification record, DPIA, data terms, named approver — so the first gate pack exists. Put the flow-down clause into the next subcontract signed on each pilot project.

    Board minute, appointed owners, first gate pack, first flow-down

  4. Days 66–90

    Drill, audit, report

    Drill the kill-switch on a quiet shift: revert the cameras to plain recording, run the manual observation process, time it, note who was unreachable. Run a mini-audit: sample the register against one project's actual tools and report the gaps honestly. Take findings to the board with the standing audit cadence for approval.

    A drilled rollback, an honest first audit, a standing cadence

The order matters

  1. Register before drafting

    A charter written before the inventory governs an imaginary estate. The register built in days 1–15 is what makes every clause concrete: you are writing rules for the drone that flew last Tuesday, not for a hypothetical.

  2. One live system before generic policy

    Every clause drafted against the camera estate earns its wording by answering a real question — what retention period, whose kill-switch, which approver. Clauses drafted in the abstract read well and fail their first contact with a project.

  3. Adoption before tooling

    Buy nothing in the first 90 days. The register is a spreadsheet, the gate is a checklist, the drill is an afternoon. Tooling accelerates a governance habit that exists; it cannot create one, and procurement lead times will quietly eat the quarter.

Enforcing and auditing the charter: cadence, evidence, checklist

Enforcement is contracts and controls; audit is sampling evidence on a schedule. This is the machinery that keeps the charter true after the launch energy fades.

The charter stays true through two mechanisms, and neither is enthusiasm: enforcement wires the obligations into instruments projects already obey — subcontracts, project controls, inductions — and audit samples the evidence on a schedule to catch the decay that enforcement alone cannot see. The cadence table below is the standing schedule clause 12 commits to. It is deliberately modest: six audit lines, most quarterly or six-monthly, each naming what is sampled and who answers for it. A governance system that demands more than this will be the first thing dropped in a busy quarter — and a schedule this size has no excuse to lapse.

What is auditedCadenceEvidence sampledWho
Register completenessQuarterlyRegister entries walked against two live projects' actual tools, both directionsAI governance lead
Gate complianceQuarterlyGate packs for a sample of recent approvals; any system found live without oneInternal audit
Imagery & worker-data controlsSix-monthlyDPIAs against deployed camera configurations; retention actually enforced, not just scheduledDPO / privacy lead
Supply-chain flow-downAnnual, plus every new frameworkRecent subcontracts for the unamended clause; prequalification answers reaching the registerCommercial director
Incident readinessSix-monthlyDrill reports; kill-switch access rights; vendor out-of-hours contacts currentHSE lead + AI governance lead
Charter reviewAnnualVersion history; audit findings closed or escalated; board minute of the reviewBoard risk committee
The standing audit cadence from clause 12. 'Evidence sampled' is the test of a real audit: every line samples outward from paper to a live project, never just re-reading documents.

The checklist below is the adoption bar this page has been building to. It is deliberately harder than publishing a document: every item is an artefact somebody could hand you, and together they are what 'we have an AI governance charter' should mean before a firm says it to a client. Tick honestly — the count maps to a stage on the ladder, and the gap it reveals is the work.

The charter adoption checklist

Eight artefacts, each either exists or does not. Tick as you go — this list works without JavaScript, and the honest count is the point.

0 of 8 ticked

0 of 8 — Ungoverned, and now you know it

A blank list is the honest starting point for most of the industry, and it is two weeks from changing: name a sponsor, walk two projects, build the register. Everything else on this list descends from that first artefact. The 90-day plan above is written for exactly this position.

Failure modes that unwind a charter

Governance regresses silently. Four failure modes account for most of it — and every one is cheaper to prevent than to survive.

Charters do not fail loudly; they erode. The document stays published, the register stays on the server, and the perimeter quietly moves until an incident or a dispute reveals how little the paper still governs. Four failure modes account for most of the erosion in contracting businesses, and each has a cheap, specific prevention that belongs in the clauses named.

Likelihood: highImpact: high

The safety camera quietly becomes a productivity tool

The vendor ships a dashboard update; someone in operations notices the same feed can score crew activity; six months later the safety system the workforce consented to is a surveillance system nobody consented to. Trust collapses, union grievances follow, and the ICO's purpose-limitation expectations have been breached by drift rather than decision.

PreventionClause 5's written purpose limits plus a monitoring check that flags any use outside the approved envelope — repurposing requires a fresh DPIA and consultation, never a configuration change.

Likelihood: mediumImpact: high

A generative output enters the CDE unchecked

Under deadline, a designer accepts an AI-produced option and uploads it; the check that would have caught the flawed assumption never happens; the information carries the firm's name into construction. Discovered at the worst possible time — after the work is built — with the ISO 19650 trail showing exactly who skipped what.

PreventionClause 7's check certificate as a CDE workflow gate, not a policy request — the upload path itself refuses AI-classified information without a signed check.

Likelihood: highImpact: medium

The charter binds employees while the supply chain runs dark

The firm's own systems are registered and gated, and the drone contractor, the plant-telematics vendor and the design consultant's generative tools operate on the same sites under no obligations at all. The principal contractor holds the duties; the supply chain holds the AI; a subcontractor's data incident becomes the main contractor's client conversation.

PreventionClause 6's flow-down in the standard subcontract plus two AI questions at prequalification — enforced by commercial, because only commercial instruments cross company boundaries.

Likelihood: mediumImpact: medium

The charter freezes after adoption

Version 1.0 is adopted with real energy, and then nothing: the audit slips, findings stop arriving, the register ages, and two years later the document describes a business that no longer exists — while the firm keeps claiming the badge to clients. The claim is now worse than no charter, because it is checkable and false.

PreventionClause 12's annual review with findings on the board agenda, and a version history treated as evidence — a charter still on v1.0 after two years is a standing audit finding in itself.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

AI governance charter
The board-adopted document that sets the rules for every AI system a business uses — permitted uses, risk classes, named owners, data rules, approval gates, incident response and audit cadence. Distinct from an IT acceptable-use policy, which governs employees rather than the business and its supply chain.
AI use-case register
The living inventory of every AI system in use across the business and its sites — including subcontractor and vendor tools — with owner, risk class, data touched and gate status per entry. The charter's foundational artefact and its most diagnostic one.
Risk classification
The sorting of every AI use case into defined classes — safety-critical, worker-facing, design-affecting, commercial, back-office — that determines which gates, checks and oversight rules apply. The hinge clause: every other obligation keys off it.
Model approval gate
The checkpoint an AI system must pass before going live, demanding evidence scaled to its risk class — classification record, data terms, validation, DPIA where triggered — approved by a named person and recorded as a gate pack.
DPIA
Data protection impact assessment — the structured evaluation of a processing activity's necessity, proportionality and risks to individuals, done before deployment while decisions can still change. Mandatory in the charter for any worker-facing AI system.
Purpose limitation
The data-protection principle that information collected for one stated purpose may not be silently reused for another. In construction AI, the rule that stops a safety camera becoming a productivity surveillance system by configuration change.
Flow-down clause
The subcontract and JV term that extends charter obligations to the supply chain — typically register-before-use plus data-sharing terms for anything touching imagery or personal data. The only governance instrument that crosses a company boundary.
Check certificate
The signed record that a named competent person has reviewed an AI-produced output — a generative layout, an optimisation result — before it enters the CDE as project information. What keeps design liability with a person and the ISO 19650 trail intact.
Common data environment (CDE)
The managed information store ISO 19650 defines for project information — the single source of truth AI systems read from and write into, and therefore the natural enforcement point for the check-certificate rule.
AI incident
A defined event class in the charter: a wrong AI output that reached the work, a data breach through an AI vendor, or a system operating outside its approved purpose. Declaring it triggers the kill-switch, the manual fallback, review and — where safety-relevant — the RIDDOR or OSHA reporting interface.
Shadow AI
AI tools in active use without the business's knowledge or approval — personal LLM accounts, unvetted site apps, subcontractor analytics. The default state of construction AI estates, and the reason the register is built by walking projects rather than surveying managers.
Audit cadence
The standing schedule on which governance evidence is sampled against reality — register walked against live projects, gate packs pulled, DPIAs checked against deployed configurations — with findings reported to the board and closed through charter revisions.

Frequently asked questions

The questions construction leaders ask most often when drafting their first AI governance charter.

What is an AI governance charter in construction?

It is the board-adopted rulebook for every AI system a contractor or infrastructure owner uses: which applications are permitted and in what risk class, who approves models before they go live, how site imagery and worker data are handled, what evidence must exist before an AI output enters a design, and what happens when an AI-informed decision goes wrong. A working charter is short — about twelve clauses — with a named owner and a defined evidence artefact per clause, sitting above detailed procedures the way a safety policy sits above method statements.

How is a charter different from an IT acceptable-use policy?

Scope and subject. An acceptable-use policy governs employees using tools — what staff may type into a chatbot. A charter governs the business using AI: the systems it buys, the models its subcontractors bring to site, the outputs that enter deliverables carrying its name and PI cover, and the duties that stay with competent persons regardless of what a model recommends. Most firms need both, but only the charter reaches the supply chain, the CDE and the statutory duty holders — which is where construction's actual AI risk lives.

Who should own the AI governance charter in a contracting business?

A board sponsor owns the charter; an AI governance lead runs it day to day; and each clause names the role that already holds the relevant accountability — the HSE lead for safety-critical oversight, the DPO for imagery and worker data, the commercial director for flow-down and bid models, the design or information manager for CDE checks. The ownership design principle is that every owner is a role the business already staffs. A charter that requires a new hire before it can operate will wait for the hire.

Do we need ISO/IEC 42001 certification to have a charter?

No. ISO/IEC 42001 standardises the AI management system — the plan-do-check-act shape the charter, register, gates and audits together form — and certification is worth considering when clients start naming the standard in prequalification. But the charter is the prerequisite, not the product: a firm with an adopted, enforced, audited charter can certify later with modest effort, while certification pursued without the working machinery produces exactly the document-first failure this page warns against. Build the charter; let certification follow demand.

How does the charter handle site CCTV and worker privacy?

Through clause 5, which fixes four things in writing before any camera analytics deploy: the purpose (safety alerting and incident evidence, stated exhaustively), the prohibitions (productivity scoring, disciplinary use or biometric identification without a fresh DPIA and consultation), the retention period, and the workforce consultation record. The DPIA happens before deployment, while camera positions and retention can still change. This follows the ICO's surveillance guidance directly: necessity, proportionality and transparency assessed before processing starts — and it is also what keeps the workforce treating the cameras as protection rather than surveillance.

Are we liable for AI tools our subcontractors use on our sites?

Exposure is hard to avoid, whatever the strict legal position case by case. A main contractor holds principal-contractor duties on the site where the subcontractor's drone flies, receives the client conversation when a vendor's data practice fails, and cannot answer an assurance questionnaire about systems it never saw. The charter's answer is clause 6: a flow-down clause making register-entry-before-use a subcontract condition, data-sharing terms for anything touching imagery or personal data, and AI disclosure questions at prequalification — because contract terms are the only governance instrument that crosses a company boundary.

Who carries design liability when a generative tool produced the option?

The firm and the named checker — never the model, and rarely the vendor, whose terms will say so explicitly. That is why clause 7 makes the check certificate mandatory: no AI-produced output becomes project information in the CDE until a named competent person has reviewed and signed it. This keeps the ISO 19650 information-management trail intact, keeps the professional duty of care with a person, and keeps the PI insurance conversation boring. An unchecked generative output in the CDE is uninsured ambiguity wearing your firm's name.

Can AI make safety-critical decisions on site?

It can inform them; under the charter it never discharges them. Neither HSE's nor OSHA's regime recognises a model as a duty holder: the temporary-works coordinator still certifies, the appointed person still owns the lift plan, the supervisor still sets the exclusion zone. Clause 9 writes this down as an oversight protocol — which decisions require a competent person's confirmation, and who that person is per system. The protocol protects individuals as much as the firm: nobody should discover during an investigation that they were accountable for a system they did not know they were relying on.

How do bid and estimation models get governed?

Clause 10 adds two controls the rest of the charter does not cover. First, training-data provenance: every dataset refresh for a commercial model is signed off against confidentiality boundaries, so rates from a live JV or framework never silently train a model that prices against the partner. Second, human sign-off on tender figures: an AI-informed price carries a named estimator's signature, so every figure can be explained in a post-award review or a framework audit. Both controls are cheap, and the day a JV partner or auditor asks, they are the difference between a record and a scramble.

How long does it take to draft and adopt an AI governance charter?

About 90 days to genuine adoption when the work is built around one live system, as in the plan above: register first, clauses drafted against a real deployment, board adoption with appointment letters, then a drill and a mini-audit inside the same quarter. What extends it is abstraction — charters drafted without a register, reviewed by legal in successive polishing cycles, govern nothing for a year. What the 90 days does not deliver is Enforced: putting flow-down into every subcontract and gating the legacy estate typically takes a further two to four months of commercial work.

How often should the charter be audited and revised?

Sampling audits quarterly to six-monthly by line — register completeness quarterly, imagery controls and incident readiness six-monthly, supply-chain flow-down annually — with a full charter review at board level once a year, per clause 12. The test of a real cycle is findings: an audit that samples evidence against live projects always finds something, and the finding should change a clause, with the version history recording what and why. A charter still on version 1.0 after two years has not been audited in any meaningful sense, whatever the calendar says.

Does the EU AI Act apply to construction AI?

Parts of it, and directly. Worker-monitoring systems sit in the Act's high-risk employment category, which reaches the site-camera analytics and operator-monitoring tools contractors already run in the EU; AI acting as a safety component carries conformity obligations; and general transparency duties reach the generative tools in daily office use. Obligations phase in over several years, and firms operating in or bidding into EU markets should track the schedule. A firm with an operating charter will experience the Act mostly as paperwork it already holds — the register, DPIAs and gate packs are the evidence the obligations ask for.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for construction, manufacturing and infrastructure operators — computer-vision site monitoring, schedule and quantity intelligence, and decision support integrated into project controls and the CDE — with the governance artefacts (registers, gates, audit trails) built alongside the models rather than after them.

  • · Production AI deployments across contractors and infrastructure owners
  • · Governance charters drafted jointly with HSE, commercial and information-management leads
  • · Delivery includes the evidence layer: registers, approval gates, incident drills, audit trails
  • · 14 cited sources on this page

Sources

  1. ISOISO 19650-1 — organisation and digitisation of information (BIM) (opens in a new tab)
  2. ISOISO/IEC 42001 — AI management systems (opens in a new tab)
  3. NISTAI Risk Management Framework (opens in a new tab)
  4. HSEConstruction health and safety (opens in a new tab)
  5. HSEWork-related fatal injuries statistics (opens in a new tab)
  6. OSHAConstruction industry standards and guidance (opens in a new tab)
  7. Information Commissioner's OfficeVideo surveillance guidance (opens in a new tab)
  8. European CommissionRegulatory framework for AI (EU AI Act) (opens in a new tab)
  9. UK BIM FrameworkUK BIM Framework (opens in a new tab)
  10. McKinsey Global InstituteReinventing construction: a route to higher productivity (opens in a new tab)
  11. World Economic ForumShaping the Future of Construction (opens in a new tab)
  12. SuffolkSuffolk — company published material (opens in a new tab)
  13. Balfour BeattyBalfour Beatty — company published material (opens in a new tab)
  14. HS2 LtdHS2 — programme published material (opens in a new tab)

Draft the charter with the people who build the systems it governs

We run the assessment with your leadership team, map the clause gaps against the twelve-clause blueprint, and leave you with a drafted charter, a working register and a 90-day adoption plan. You keep the draft whether or not we build anything after it.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.