Construction & InfrastructureRegulations, Compliance & Governance
The construction AI governance charter, clause by clause: a blueprint you can draft from
A construction AI governance charter is the board-adopted rulebook for every AI system a contractor or infrastructure owner runs: which uses are permitted, who approves models, how site imagery and worker data are handled, and what happens when an AI-informed decision goes wrong. This page is the blueprint — twelve clauses, ready to draft from.

Key takeaways
- A construction AI governance charter is a short, board-adopted rulebook — twelve clauses covering scope, risk classes, roles, data rules, approval gates, incident response and audit — not a 40-page legal treatise. If it has no named owners and no board minute, it is a draft, whatever the document says.
- The charter is enforced through contracts, not memos: a flow-down clause in every subcontract and JV agreement is what makes the rules bind the drone survey firm and the photo-analytics tool your supply chain brings to site — which is where most of the ungoverned AI actually is.
- Site imagery is the most contested clause. The same camera feed that flags a missing harness can score worker productivity, so the charter fixes the purpose in writing, requires a DPIA before deployment, and forbids silent repurposing — the specific failure the ICO's surveillance guidance warns against.
- No AI output enters the design or the CDE unchecked: a named competent person signs a check certificate for every generative or optimisation output that becomes project information, keeping the ISO 19650 audit trail intact and design liability where PI insurance expects it.
- Governance maturity runs Ungoverned → Drafted → Adopted → Enforced → Audited. Most contractors sit in the first two stages, and the move that matters most is the cheapest: a board vote, a named sponsor, and a register of every AI system already in use — including the ones nobody admits to.
Abbreviations used on this page
- CDE
- Common data environment (the ISO 19650 project information store)
- BIM
- Building information modelling
- RACI
- Responsible, accountable, consulted, informed — the accountability matrix
- DPIA
- Data protection impact assessment
- CCTV
- Closed-circuit television (site cameras)
- HSE
- Health and Safety Executive (GB safety regulator)
- OSHA
- Occupational Safety and Health Administration (US safety regulator)
- RIDDOR
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (GB)
- JV
- Joint venture
- LLM
- Large language model
- AIMS
- AI management system (the ISO/IEC 42001 construct)
- PI
- Professional indemnity (insurance)
Free · 8 questions · ~3 minutes
Score your firm on the governance ladder
Eight questions, one at a time, about three minutes. Answer them and we build your personalised governance report — your stage on the ladder, your score on each of the four dimensions, and the specific clause gaps standing between you and the next stage — and send it to your inbox. Your result doubles as the gap list for your first charter draft.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised governance report is ready
Tell us where to send it. Your stage appears on screen straight away, and the full report — dimension scores, the clause gaps to close first, and the 90-day drafting plan matched to your weakest dimension — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Ungoverned
AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
Your next moveName a board sponsor, walk two live projects, and build the register of what is actually in use — including subcontractor tools — before writing any policy.
Stage 2 · Drafted
A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
Your next moveStop editing. Take the charter to the board for formal adoption, issue appointment letters for the named roles, and cite it in one live project's controls within a month.
Stage 3 · Adopted
The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
Your next moveDraft the flow-down clause with commercial and legal, put it into the standard subcontract, and add AI questions to procurement prequalification — then gate the legacy estate.
Stage 4 · Enforced
The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
Your next moveSchedule the first internal audit: sample gate records against live systems on two projects, test one rollback, and report findings — including the awkward ones — to the board.
Stage 5 · Audited
An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.
Your next moveTreat the charter like the safety management system: standing audit schedule, board review with findings on the agenda, and a version history that proves the document is alive.
0 / 24
Charter scope & roles
— / 6
Data & privacy controls
— / 6
Model approval & incident process
— / 6
Audit & enforcement
— / 6
Your score maps to a stage on the governance ladder. The dimension breakdown matters more than the total: the lowest dimension is the clause family your charter is missing or not enforcing, and it is where the next month's work belongs. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a stage on the governance ladder. The dimension breakdown matters more than the total: the lowest dimension is the clause family your charter is missing or not enforcing, and it is where the next month's work belongs.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want the clause gaps turned into a working charter?
We will walk your leadership team through the dimension scores, map them against the twelve clauses on this page, and leave you with a drafted charter and adoption plan sized to your business. No obligation, and you keep the draft either way.
How the score maps to a stage
- 0–5 — Stage 1, Ungoverned. AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
- 6–11 — Stage 2, Drafted. A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
- 12–16 — Stage 3, Adopted. The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
- 17–21 — Stage 4, Enforced. The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
- 22–24 — Stage 5, Audited. An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.
What a construction AI governance charter is — and what it is not
A definition, the boundary with the policies you already have, and the route an AI use case takes through a chartered business versus an ungoverned one.
A construction AI governance charter is the board-adopted document that sets the rules for every AI system a contractor or infrastructure owner uses: which applications are permitted and in what risk class, who may approve a model for use, how site imagery and worker data are collected and retained, what evidence must exist before an AI output enters a design or a programme, and what happens — organisationally, not just technically — when an AI-informed decision goes wrong. It is short by design: a dozen clauses, each with a named owner and a defined piece of evidence, sitting above the detailed procedures the way a safety policy sits above method statements.
It is not an IT acceptable-use policy, and the distinction is where most first drafts fail. An acceptable-use policy governs employees using tools; a charter governs the business using AI — including the AI it buys, the AI its subcontractors bring to site, and the AI whose outputs end up in deliverables carrying the firm's name and its PI cover. Nor is it an ethics statement: a charter contains no aspirations, only rules with owners and evidence. The nearest familiar object on a construction site is the safety management system — and, as with safety, the international standards are converging on the same management-system shape: ISO/IEC 42001 (opens in a new tab) defines the AI management system (AIMS), the NIST AI Risk Management Framework (opens in a new tab) supplies the govern–map–measure–manage cycle, and ISO 19650 (opens in a new tab) already governs the information environment — the CDE — that construction AI reads from and writes into.
How an AI use case reaches a construction site: ungoverned vs chartered
Three routes through the same business. The top lane is how AI actually arrives at most contractors today; the middle lane is the path the charter builds; the bottom lane is the path clause 11 rehearses before it is needed. The stage ladder below measures how much of your estate travels each lane.
- Where value leaks
- Data & feeds
- System-of-record action
- Human in the loop
- AI / model
The process, in words
- On the ungoverned route, a tool is adopted by whoever finds it useful — a site app, a free LLM account, a subcontractor's drone stack. Project data flows out under terms nobody read, outputs enter the work unchecked and unrecorded, and the liability surfaces months or years later, at a claim, an audit or an incident, when no evidence exists to answer with.
- On the chartered route, anyone may propose a use case, but it is risk-classified against clause 3 before anything else happens. Worker-facing or imagery-heavy uses trigger the clause 5 data checks and a DPIA; the model approval gate demands the evidence pack for its risk class; the system goes live with monitoring and, for safety-critical calls, a human confirming; and the register entry plus audit trail are produced as a by-product, not assembled later.
- The incident path exists before it is needed. A wrong output that reached the work is declared an AI incident, contained by the kill-switch and manual fallback, reviewed — through the RIDDOR or OSHA interface where safety-relevant — and closed by a charter revision, so the same failure cannot recur under the same rules.
Step-by-step insights
- Why the ungoverned lane is the default, not the exception
- Construction adopts tools at the edge, not the centre — it always has. The industry's operating unit is the project, projects are measured on programme and cost, and anything that helps this week gets used this week. That culture delivered mobile phones, WhatsApp site groups and drone surveys years ahead of head-office policy, and it is delivering AI the same way. A charter that fights this culture loses; a charter that works with it — cheap proposals, fast classification, gates sized to risk — captures the same energy and makes it visible. The design goal is that the chartered route is barely slower than the ungoverned one for low-risk uses, and unavoidable for high-risk ones.
- Risk classification is the hinge of the whole charter
- Every other clause keys off clause 3. Classify a use case safety-critical and clause 9's human-oversight rules apply; classify it worker-facing and clause 5's DPIA obligation triggers; classify it commercial and clause 10's provenance rules bite. Getting classification wrong in either direction is expensive: over-classify and the gate becomes a bottleneck that pushes teams back to the shadow route; under-classify and a safety-relevant system ships with a back-office system's scrutiny. The classification session should take under an hour per use case, involve the HSE lead for anything site-facing, and be recorded in one page.
- The DPIA is a decision tool, not paperwork
- In the chartered lane the data protection impact assessment happens before deployment, while the decision can still change — which camera positions, what retention period, whether audio is captured at all, whether the vendor may reuse footage for model training. A DPIA done after go-live is a compliance memo about decisions already taken. The ICO's surveillance guidance is explicit that necessity and proportionality must be assessed before processing starts, and in practice the DPIA is where worker consultation happens: the workforce that helped set the purpose limits is the workforce that does not treat the cameras as management spyware.
- The gate produces the evidence, not just the decision
- The model approval gate's output is not a yes — it is a pack: the classification record, the data terms, the validation evidence appropriate to the risk class, the named approver, the date. That pack is what answers a client's assurance questionnaire in a day, satisfies an auditor sampling the register, and defends the firm when a decision informed by the system is challenged in adjudication. Firms that run gates as meetings without artefacts get the delay of governance with none of the protection.
- Human oversight is a duty allocation, not a UX feature
- For safety-critical classes the charter states that AI never discharges a statutory duty: the temporary-works coordinator still certifies the design, the appointed person still owns the lift plan, the supervisor still decides on the exclusion zone. The AI informs; a named competent person decides and remains accountable. This is not caution for its own sake — it is how HSE and OSHA duties actually work, since neither regime recognises a model as a duty holder. Writing it down protects the individual as much as the firm: nobody should discover in an investigation that they were implicitly relying on a system nobody told them they were accountable for.
- The incident path is rehearsed, because construction already knows how
- Construction rehearses failure better than almost any industry — fire drills, rescue plans, service strikes. Clause 11 extends the same discipline to AI: define what counts as an AI incident (a wrong output that reached the work, a data breach through an AI vendor, a system operating outside its approved purpose), name the kill-switch holder, drill the rollback to the manual process on a quiet shift, and route safety-relevant incidents into the existing RIDDOR or OSHA reporting machinery rather than a parallel one. The drill report — what was pulled, how long the fallback took, who was not reachable — is worth more than the procedure it tests.
The twelve clauses, one by one
The charter's full contents: what each clause governs, who owns it, and the evidence it must produce. This table is the blueprint — draft yours against it.
A working construction AI governance charter contains twelve clauses, and each one earns its place by producing evidence somebody will eventually ask for. The table below is the blueprint this page exists to deliver: read the clause, note the owner — a named role your business already has, not a new hire — and note the evidence column, because the evidence is the clause. A rule that generates no artefact cannot be enforced, audited or defended, and has no business in the document.
| Clause | What it governs | Owner | Evidence it produces |
|---|---|---|---|
| 1 · Purpose, scope & definitions | Which entities, projects and AI systems the charter covers — explicitly including supply-chain tools used on the firm's sites — and what counts as an AI system | Board sponsor | Signed charter with scope statement; board adoption minute |
| 2 · AI use-case register | The living inventory: every AI system in use, its owner, risk class, data touched and gate status | AI governance lead | The register itself, with quarterly review dates |
| 3 · Risk classification | The classes every use case is sorted into — safety-critical, worker-facing, design-affecting, commercial, back-office — and who classifies | AI governance lead + HSE lead | One-page classification record per use case |
| 4 · Roles & RACI | Who proposes, classifies, approves, operates and audits — by named role, with deputies | Board sponsor | RACI matrix; appointment letters for named roles |
| 5 · Site imagery & worker data | CCTV and computer-vision purpose limits, retention, DPIA triggers, workforce consultation, biometric red lines | DPO / privacy lead | DPIA records; retention schedule; consultation notes; signage |
| 6 · Subcontractor & JV data sharing | Flow-down obligations, data-sharing terms for supply-chain AI, drone and photo tools brought to site, vendor reuse of project data | Commercial director | Flow-down clause in standard subcontract; data-sharing agreements |
| 7 · Design outputs & information management | The check obligation on generative and optimisation outputs before they enter the CDE; ISO 19650 alignment; who carries design liability | Design manager / information manager | Check certificates; CDE transaction log |
| 8 · Model approval gates | The evidence required before a system goes live, scaled by risk class; who approves; revalidation triggers | Named gate approvers per class | Gate checklist and approval record per system |
| 9 · Human oversight of safety-critical decisions | Where a competent person must confirm before action; the rule that AI never discharges a statutory duty | HSE lead | Oversight protocol; training and briefing records |
| 10 · Bid & estimation models | Training-data provenance, confidentiality across JVs and frameworks, human sign-off on tender figures | Commercial director | Bid-model log; provenance sign-offs; tender sign-off records |
| 11 · Incident, rollback & reporting | What counts as an AI incident, the kill-switch and manual fallback, drill cadence, RIDDOR/OSHA interface | AI governance lead + HSE lead | Incident log; drill reports |
| 12 · Audit cadence & charter review | The sampling audit schedule, board reporting, and how findings become charter revisions | Internal audit + board risk committee | Audit reports; charter version history |
Three drafting principles keep the document usable on a live project. First, clause length is capped: if a clause needs more than a page, the detail belongs in a procedure beneath it, referenced by name — the charter is the safety policy, not the method statement. Second, every owner is a role the business already staffs; a charter that requires hiring before it can operate will wait for the hire and then for the next one. Third, the charter binds by reference from the documents that already have teeth: the subcontract cites clause 6, project controls cite clause 8, the design management plan cites clause 7. A charter nothing else cites is a poster.
Clause 5 is where drafting slows down — let it
Site imagery is the clause that will be read most hostilely, by the workforce first and possibly a tribunal later. Fix the purpose in writing (safety alerting, progress evidence), name what is forbidden without a fresh DPIA and consultation (productivity scoring, disciplinary use, biometric identification), and set retention short enough to defend. The ICO's video surveillance guidance (opens in a new tab) is the reference point for UK sites, and its necessity-and-proportionality test is a sound drafting standard anywhere.
Clause 7 is the one your PI insurer will read
Generative and optimisation tools produce design information faster than checking capacity grows, and an unchecked output that enters the CDE carries the firm's name, not the vendor's. The clause states that AI output becomes project information only through a check certificate signed by a named competent person — which keeps the ISO 19650 information-management trail (opens in a new tab) intact and the liability question boring, which is what insurers prefer.
Clause 10 exists because estimating found AI first
Bid and estimation models were among the earliest quiet adopters, and they concentrate two risks the rest of the charter does not cover: training data whose provenance mixes confidential rates across JVs and frameworks, and tender figures that nobody can explain in a post-award review. Provenance sign-off per training refresh and a human signature on every AI-informed tender figure are cheap, and the day a JV partner or a framework auditor asks, they are priceless.
The construction-specific risk surface the charter must cover
Five risk surfaces are peculiar to this industry — site imagery, supply-chain data, design liability, safety-critical decisions and bid models — and a generic AI policy misses all five.
Construction's AI risk surface is different from every other industry's because the site is a workplace, a camera target, a shared venue for dozens of employers, and a source of statutory duties all at once. A generic corporate AI policy — written for offices, screens and documents — covers almost none of what actually goes wrong on a project. The table below maps the five surfaces the charter must reach, the regulatory hook behind each, and the clause that governs it.
| Risk surface | Where it shows up | Regulatory / contractual hook | Clause |
|---|---|---|---|
| Site CCTV & computer-vision safety monitoring vs worker privacy | PPE detection, exclusion-zone alerts, plant-proximity warnings — and the same feed's capacity for productivity scoring | UK GDPR via ICO surveillance guidance; employment law; union agreements | 5, 9 |
| Subcontractor & JV data sharing | Drone photo-recognition, vendor analytics on your site data, JV partners' models trained on shared rates | Contract terms; confidentiality; principal-contractor duties | 6, 10 |
| Design liability for generative & optimisation outputs | Generative layouts, rebar optimisation, AI-produced temporary-works options entering the CDE | ISO 19650 information management; PI insurance; professional duty of care | 7, 8 |
| Safety-critical decisions | AI-informed lift plans, exclusion zones, structural monitoring alerts, plant automation | HSE / OSHA statutory duties — no model is a duty holder | 3, 9, 11 |
| Bid & estimation model governance | AI-assisted take-offs, tender pricing, subcontractor quote analysis | Confidentiality across frameworks; competition law exposure; auditability of tender figures | 10 |
The first surface deserves the most drafting care because it is the one the workforce experiences daily. Computer-vision safety monitoring genuinely prevents harm — the same detection stack that spots a missing harness spots a worker inside a crane's slew radius — and it sits one configuration change away from being a productivity surveillance system. The ICO's surveillance guidance (opens in a new tab) requires necessity, proportionality and transparency before processing begins; the charter operationalises that as written purpose limits, a DPIA before deployment, workforce consultation, and an explicit prohibition on silent repurposing. On the safety side, HSE's construction guidance (opens in a new tab) and OSHA's construction standards (opens in a new tab) define duties that remain with competent persons regardless of what any model recommends — which is exactly what clause 9 writes down.
Regulation is also converging on this surface from the AI side. The EU AI Act (opens in a new tab) phases in risk-based obligations that reach several construction uses directly — worker-monitoring systems sit in its high-risk employment category, and safety-component AI carries conformity obligations — while ISO/IEC 42001 (opens in a new tab) gives clients a certifiable management-system standard to ask for in prequalification. Firms with an operating charter will experience both as paperwork they already hold; firms without one will experience them as a scramble.
Which approval gate does a use case need?
Clause 3's classification, drawn as a decision aid. Plot a proposed use case by the consequence of a wrong output and the sensitivity of the data it touches; the quadrant names the gate. The top-right — computer-vision safety monitoring — is where both dimensions peak at once, which is why it anchors the 90-day plan below.
Privacy gate
- Workforce analytics, access-control matching, wearables
- DPIA + clause 5 purpose limits + consultation
- DPO sign-off before deployment, not after
Full gate
- CV safety monitoring, plant-proximity AI, operator monitoring
- DPIA + HSE oversight protocol + board-visible approval
- The use case the whole charter is stress-tested against
Log and go
- Document drafting, RFI summarising, tender-text search
- Register entry and standard data terms only
- The lane that keeps the charter credible with site teams
Engineering gate
- Generative design options, quantity take-off, programme optimisation
- Clause 8 gate + clause 7 check certificate
- Named competent person signs before the CDE accepts it
The governance ladder: Ungoverned to Audited
Five stages describe how far the charter actually governs — from a document that does not exist to a management system an outsider can inspect. Each stage below carries its diagnostics, its trap, and what leaving it costs.
Governance maturity in construction runs up a five-stage ladder — Ungoverned, Drafted, Adopted, Enforced, Audited — and the stage is set by what the charter can actually reach, not by what it says. A document nobody adopted governs nothing; an adopted charter that stops at the payroll governs a third of the estate; only contract flow-down reaches the supply chain, and only a sampling audit proves any of it is still true. Each stage below is written for the person who would have to do the work: what it looks like from inside, the signals a reviewer can check in an afternoon, the anti-pattern that traps firms there, and the investment the next rung takes.
Defensible AI capability released against position on the ladder
The curve is steep in the middle for a reason: a charter releases almost no value while it is merely drafted, inflects sharply at adoption — when gates, registers and named owners start producing evidence — and compounds through enforcement as the supply chain comes inside the perimeter. The governance work is front-loaded; the payback is not.
Defensible AI capability released by stage
- Stage 1 · Ungoverned — 38% of operators. AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
- Stage 2 · Drafted — 27% of operators. A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
- Stage 3 · Adopted — 19% of operators. The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
- Stage 4 · Enforced — 11% of operators. The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
- Stage 5 · Audited — 5% of operators. An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.
Curve shape: logistic, plotted from the stage data above. Distribution: Stage model aligned with NIST's govern–map–measure–manage cycle.
Select a stage
Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Ungoverned
38% of operators sit here
AI is already in use across projects — site apps, free LLM accounts, subcontractor drones — with no charter, no register and no named owner.
Ungoverned does not mean AI-free — it means AI-blind. In almost every contracting business at this stage, AI arrived the way mobile phones did: bottom-up, tool by tool, without a decision. An estimator pastes tender text into a free LLM to summarise it. A site engineer trials a photo app that auto-tags defects. A drone subcontractor runs photo-recognition over the site as part of its survey deliverable. Each choice is individually reasonable, and the sum is a portfolio of AI systems the business cannot list, running on data it never agreed to share.
The exposure at this stage is not hypothetical harm from a rogue model — it is the ordinary machinery of construction disputes meeting an evidence vacuum. When a claim lands, the other side's lawyers will ask how a quantity was produced, who checked the temporary-works option, where the site footage went. At Ungoverned the honest answer is 'we don't know', and 'we don't know' is a very expensive sentence in adjudication. The same vacuum applies upward: a main contractor cannot answer a client's assurance questionnaire about AI use it has never inventoried.
This is the cheapest stage to leave, because leaving it requires no technology at all. A register of what is actually in use — built by walking two live projects and asking, without blame, what people use — plus a one-page interim rule set, moves a business out of Ungoverned in weeks. What keeps firms here is not cost but the fear of what the inventory will find. That fear is misplaced: the shadow AI is already there, and the only question is whether management can see it before a dispute does.
In practice
The tender that went into a free chatbot
A regional contractor's estimator, under deadline, pastes a client's confidential bill of quantities into a free LLM account to summarise scope gaps. It works, so the habit spreads through the estimating team over a quarter. Nobody can now say which clients' commercial data has left the business, under which terms of service, or whether it trains someone else's model. The firm discovers the practice only when a client's security questionnaire asks directly — and the truthful answer costs it a place on the framework.
What it looks like
- Site and office staff use AI tools under personal accounts
- No document says which AI uses are permitted on projects
- Subcontractors bring cameras, drones and analytics nobody logs
- Project data leaves the business through tools nobody vetted
Diagnostic signals you can check this week
- Ask three site engineers what AI tools they use; compare answers with what IT thinks is in use
- Search expense claims and app-store invoices for AI tool subscriptions nobody approved
- Ask who signed the data terms for the drone subcontractor's photo-recognition service
- Ask for the list of AI systems on your largest live project — if the answer is a shrug, you are here
Anti-pattern · Banning AI outright
The reflex response to the first scare is a blanket ban. It is the single most counterproductive move available, because the tools demonstrably help and people will keep using them — now on personal phones and personal accounts, invisible to any register. A ban converts visible, governable use into shadow AI and destroys the trust needed to inventory it later. The charter's first clause exists precisely to avoid this: state what is permitted, so that what is not permitted becomes conspicuous.
What holds you here
Nobody owns the question, so every team assumes someone else has the list — and the list does not exist.
Highest-leverage next move
Name a board sponsor, walk two live projects, and build the register of what is actually in use — including subcontractor tools — before writing any policy.
Cost of leaving
- Effort
- 4–8 weeks
- Team
- One senior sponsor, one project lead per pilot project, part-time
- Risk
- Low — the work is an inventory and an interim rule, nothing changes on site yet
- To next stage
- 1–2 months
If this is you, the next step is
A two-week discovery: every AI touchpoint on two live projects, registered and risk-flagged.
Stage 2
Drafted
27% of operators sit here
A charter document exists — often adapted from an IT acceptable-use template — but it has no board adoption, no named owners and no grip on projects.
Drafted is the most deceptive stage, because the artefact exists and the risk does not move. Somebody — usually IT, sometimes QHSE — has adapted a generic AI acceptable-use template, added a construction paragraph, and uploaded it to the management system. In an audit of documents, the firm passes. In an audit of behaviour, nothing has changed: the estimating team's LLM habit, the ungated camera analytics, the subcontractor drone all continue exactly as at stage 1, because no mechanism connects the document to a project decision.
The structural failure is that a drafted charter has no owner with power and no hook into how construction actually governs itself. Construction businesses run on named accountabilities — the principal contractor role, the temporary-works coordinator, the appointed person for lifting. A policy that says 'management shall ensure' belongs to nobody. A charter that says 'the AI governance lead (currently J. Patel) maintains the register and chairs the gate' belongs to someone, and can be asked for in a project review the way a lift plan can.
The move from Drafted to Adopted is governance work, not writing work: a board minute adopting the charter, appointment letters for the named roles, the register made current, and the charter cited in at least one live project's controls. Firms stall here for years because legal review keeps polishing the text — but the text was never the gap. An imperfect charter that a board has adopted and a project quotes governs more than a perfect one in a folder.
In practice
The policy in the QHSE folder
A tier-two contractor publishes a nine-page AI policy in January, adapted from its IT provider's template. It requires 'appropriate approval' for AI tools without saying whose. By August, three new AI systems are live — a progress-photo analyser, a weather-delay predictor, and a subcontractor's crane-camera analytics — and none has touched the policy, because no gate exists to route them through. At the year-end management review the policy is marked 'implemented' because the document is published. Nothing on any site knows it exists.
What it looks like
- An AI policy document sits in the QHSE or IT management system
- It names roles generically ('management', 'IT') rather than people
- Site teams have not read it and projects do not reference it
- New tools still arrive without touching the document
Diagnostic signals you can check this week
- Ask who is named, by name, in the charter — generic role nouns mean Drafted
- Find the board minute adopting it; if there is none, it is a draft
- Ask a project director when the charter last affected a project decision
- Compare the register (if any) against tools actually in use on one site
Anti-pattern · Perfecting the document
The instinct at Drafted is another legal review cycle: more definitions, more caveats, forty pages. Every month spent polishing defers the only act that matters — adoption — and makes the charter less usable on site, where nobody will read past page three. Fix the length at a dozen clauses, accept that version 1.0 will be wrong in places, and let the audit cadence (clause 12) correct it. A charter is a living control, not a contract schedule; it improves by revision, not by pre-emption.
What holds you here
The document has no named owners and no board mandate, so projects have no reason to obey it and no route to follow it.
Highest-leverage next move
Stop editing. Take the charter to the board for formal adoption, issue appointment letters for the named roles, and cite it in one live project's controls within a month.
Cost of leaving
- Effort
- 2–3 months
- Team
- Board sponsor, AI governance lead, HSE and commercial input, a half-day of board time
- Risk
- Low — the risk is reputational only if adoption is announced and then not resourced
- To next stage
- 2–3 months
If this is you, the next step is
We restructure your draft into the twelve clauses, name the owners with you, and prepare the board paper.
Stage 3
Adopted
19% of operators sit here
The board has adopted the charter, roles are held by named people, a register exists, and new AI systems pass through an approval gate — but legacy systems and the supply chain remain outside it.
Adopted is where governance starts to exist in the sense that matters: somebody can be asked. The board minute is not ceremony — it is what makes the charter citable in a project review, quotable in a client assurance response, and defensible in a dispute. The register is current for the firm's own systems, and anything new goes through the gate: classified by risk, checked for data implications, approved by a named person with the evidence recorded. For the first time, the business can answer 'what AI do you run and who approved it?' without an archaeology project.
The characteristic gap at this stage is coverage. The gate catches what is new; it has not been pointed at what already exists. The progress-photo tool adopted two years ago, the estimating model an enthusiast built in a spreadsheet, and — above all — the AI the supply chain brings to site remain outside the register. A contractor's real AI estate at this stage is typically one-third its own gated systems, one-third its own legacy systems, and one-third subcontractor and vendor tools it has never seen. Governance covers the first third.
The stage also exposes an uncomfortable truth about construction's structure: a main contractor's risk surface is mostly other companies. The drone survey firm's recognition models, the plant hire company's operator-monitoring cameras, the design consultant's generative tools all operate on your site, on your data, inside your principal-contractor duties — and none of them reads your charter. The move to Enforced is therefore a commercial move: the charter's obligations must enter subcontracts, JV agreements and procurement questionnaires, because contract terms are the only governance instrument that crosses a company boundary.
In practice
The first gated camera system
A contractor's first system through the new gate is a computer-vision safety camera for a city-centre frame. The gate works exactly as designed: the use is classified safety-critical and worker-facing, the DPIA is done before installation, purpose limitation is written down — safety alerting only, no productivity analytics — and the workforce is briefed. Three floors up, the same project is running a progress-photo tool bought two years earlier that has never been classified, and the steel subcontractor's telematics feed streams operator data to a vendor nobody has assessed. The gate is real; its perimeter is not.
What it looks like
- A board minute adopts the charter and a named sponsor answers for it
- The AI use-case register is current for the firm's own tools
- New systems pass a risk-classified approval gate before going live
- Worker-facing systems get a DPIA before deployment
Diagnostic signals you can check this week
- Pick the oldest AI tool in use and ask for its gate record — legacy exemption means Adopted, not Enforced
- Count register entries flagged as subcontractor or vendor systems; near zero means the perimeter is your payroll
- Ask the DPO when a DPIA last changed a deployment decision, not just accompanied one
- Check whether any subcontract signed this quarter mentions the charter
Anti-pattern · Gating only the new
Approval gates are naturally installed at the front door, so everything already inside is grandfathered by default. But the risk was already in the building: the legacy tools were adopted with the least scrutiny, run on the oldest data terms, and are the most embedded in daily work. Schedule the retrospective gating of the legacy estate as a named programme with a deadline — highest risk class first — or Adopted quietly becomes a stage where the register describes the tidy third of the estate and certifies ignorance of the rest.
What holds you here
The charter binds employees but not the supply chain, and most of the AI on a construction site belongs to the supply chain.
Highest-leverage next move
Draft the flow-down clause with commercial and legal, put it into the standard subcontract, and add AI questions to procurement prequalification — then gate the legacy estate.
Cost of leaving
- Effort
- 3–6 months
- Team
- AI governance lead, commercial director, DPO, procurement; legal input for the flow-down clause
- Risk
- Medium — supply-chain pushback on data terms is real and needs commercial sponsorship
- To next stage
- 3–6 months
If this is you, the next step is
A structured retrospective: classify and gate everything already in use, highest risk first.
Stage 4
Enforced
11% of operators sit here
The charter's obligations are wired into contracts, project controls and inductions — subcontractor AI is registered before use, gates are unavoidable, and the incident drill has actually been run.
Enforced is the stage where the charter stops depending on goodwill. The mechanism of enforcement in construction is never the policy document — it is the contract, the project controls, and the induction. When the subcontract says register-before-use, the drone survey firm's photo-recognition goes through data-sharing terms before its first flight, because payment depends on it. When the gate approval is a hold point in project controls, a camera system cannot be commissioned around it any more than a crane can be erected without its lift plan. Governance has moved from documents into the machinery the industry already obeys.
The second marker of Enforced is that failure has been rehearsed. An AI incident clause that has never been drilled is a theory; the firms at this stage have actually pulled the kill-switch on a live system on a quiet Friday — reverted the camera analytics to plain recording, run the manual take-off process, checked who noticed and how long it took. The drill converts the rollback from a paragraph into a capability, and it produces the artefact that matters in front of a regulator or a client: evidence that the firm can stop its own systems, promptly, and knows what happens when it does.
What Enforced cannot yet prove is itself. The rules bind, the gates hold, the drills run — but nobody independent has sampled the evidence to confirm that what the register says matches what the sites do. That is the audit gap. It matters because enforcement decays silently: a busy project waves a tool through, a subcontractor's renewal drops the clause, a gate checklist gets rubber-stamped. Without a scheduled, sampling audit, the firm discovers the decay the way it discovers most governance failures — during a dispute, when the other side finds it first.
In practice
The subcontract that named the drone
A main contractor's standard subcontract now carries the flow-down clause: any AI system used on the project must be entered in the contractor's register before use, with data-sharing terms for anything touching site imagery or personal data. A survey subcontractor mobilising for a viaduct package discloses its drone photo-recognition stack at prequalification; the data terms take a fortnight to agree and the flight goes ahead — registered, purpose-limited, with imagery retention set at ninety days. The same quarter, the contractor runs its first AI incident drill and finds the camera-analytics kill-switch works but nobody had the vendor's out-of-hours number. The drill report fixes it.
What it looks like
- A flow-down clause puts charter obligations into every subcontract and JV agreement
- Gate approval is a precondition in project controls, not a parallel process
- AI incident and rollback procedures exist and have been drilled, not just written
- Site inductions ask about AI tools the same way they ask about plant tickets
Diagnostic signals you can check this week
- Read the last three subcontracts signed: is the flow-down clause present and unamended?
- Try to commission an AI system around the gate on a test basis — if you can, so can a project under pressure
- Ask for the last incident drill report and what it changed
- Check whether prequalification answers about AI tools reach the register or die in procurement files
Anti-pattern · Enforcement by email
The tempting shortcut is to police the charter through memos, toolbox talks and escalation emails instead of contracts and controls. It works while attention lasts and fails the moment a project is late, because exhortation loses to programme pressure every time. Only two instruments survive a commercial dispute: what the contract says and what the project controls recorded. If an obligation matters, it goes in one of those; if it lives only in an email, assume it does not exist.
What holds you here
Enforcement is real but unverified — nothing independent confirms the register matches the sites, so decay is invisible until a dispute finds it.
Highest-leverage next move
Schedule the first internal audit: sample gate records against live systems on two projects, test one rollback, and report findings — including the awkward ones — to the board.
Cost of leaving
- Effort
- 6–12 months to full audit readiness
- Team
- AI governance lead, internal audit (or external assurance partner), board risk committee time
- Risk
- Medium — the audit will find things; the risk is a culture that punishes the finding rather than the decay
- To next stage
- 6–12 months
If this is you, the next step is
We draft the flow-down clause and prequalification questions with your commercial team.
Stage 5
Audited
5% of operators sit here
An independent audit cycle samples the evidence on a schedule, findings change the charter, and the whole arrangement runs as a management system a client or regulator can inspect.
Audited is not a bigger version of Enforced — it is a different relationship with evidence. At every earlier stage, the firm asserts its governance; at this stage it can demonstrate it, because an independent function has sampled the trail on a schedule and reported what it found. The audit is deliberately adversarial in method: pick systems from the register and walk to site to find them; pick tools on site and walk back to find their gate records; pull a DPIA and check the deployed camera against the purposes it states. The gaps found are the product, not the embarrassment.
This is also the stage where the charter becomes a management system in the formal sense — the shape ISO/IEC 42001 standardises for AI, deliberately parallel to ISO 9001 and 45001, which construction firms already run. Certification is optional and often unnecessary; the shape is not. Plan-do-check-act applied to AI means the charter states intent, the gates and registers do the work, the audit checks it, and the review acts on what the audit found. Construction firms have an advantage here that they rarely notice: they already operate more management systems than almost any other industry, and the muscle transfers directly.
Sustaining Audited is a discipline of revision, because the ground moves constantly — the EU AI Act's obligations phase in, the ICO updates surveillance expectations, clients add AI schedules to their frameworks, and the firm's own AI estate turns over. The version history of the charter is therefore the single best artefact of this stage: a charter still on version 1.0 after two years has not been audited in any meaningful sense, whatever the calendar says. The firms genuinely at this stage treat the charter the way they treat their safety management system — permanently provisional, revised by evidence, and owned at board level without discussion.
In practice
The audit that changed a clause
An infrastructure contractor's second annual AI audit samples the estimating department's bid-model records and finds the model was retrained mid-year on a dataset that included rates from a live JV with a competitor — technically permitted by the charter's silence, commercially indefensible if the JV partner ever asked. The finding goes to the board risk committee; clause 10 is amended to require provenance sign-off on every training-data refresh for commercial models; the version history records the finding, the change and the date. Eight months later a client's framework audit asks exactly that question, and the contractor answers it with the paper trail instead of a promise.
What it looks like
- Internal audit samples gate records, DPIAs and register entries against reality on site
- Audit findings produce charter revisions with a visible version history
- The arrangement aligns with ISO/IEC 42001's management-system shape
- Client and regulator assurance requests are answered from standing evidence, not projects
Diagnostic signals you can check this week
- Read the charter's version history — evidence-driven revisions mean Audited; a frozen v1.0 means theatre
- Ask what the last audit found; 'nothing' is the wrong answer at any real firm
- Check whether audit scope includes supply-chain systems, not just the firm's own
- Time how long a client AI-assurance questionnaire takes to answer — days from standing evidence, or weeks of scramble
Anti-pattern · Audit theatre
The terminal failure mode is auditing the documents instead of the estate: re-reading the charter, confirming the register file exists, ticking that the DPIA template is current — and never walking to a site. A document audit will pass every year while the actual perimeter erodes. The test of a real audit is that it samples outward from paper to reality and inward from reality to paper, and that it finds things. Budget for findings; a clean audit of a live AI estate is a sign the audit is broken, not the estate.
What holds you here
Sustaining the cycle through leadership changes and quiet years — audit is the first budget line cut when nothing has gone wrong recently.
Highest-leverage next move
Treat the charter like the safety management system: standing audit schedule, board review with findings on the agenda, and a version history that proves the document is alive.
Cost of leaving
- Effort
- Continuous — one audit cycle and one board review per year, minimum
- Team
- Internal audit or external assurance partner, AI governance lead, board risk committee
- Risk
- Concentrated — regulatory and client-assurance exposure if the cycle lapses while the badge is still claimed
If this is you, the next step is
We run a mock audit: sample your registers and gates against two live projects, report what a client's auditor would find.
Where construction firms actually sit on the ladder
The distribution is bottom-heavy, and the industry context explains why: the sector that digitised last is now adopting AI faster than it is governing it.
Most construction firms sit on the bottom two rungs — AI in daily use with either no charter at all or a drafted document with no grip. That bottom-heaviness is not a moral failing; it is the predictable result of the industry's structure. Construction digitised later than almost every other sector, then adopted AI tools at the edge — project by project, trade by trade — faster than any central function could see, let alone govern. The distribution below is illustrative, synthesised from the named research rather than measured by us, and it will shift as client prequalification starts asking governance questions.
Distribution of construction firms across the governance ladder
Illustrative distribution — model-derived, not a survey result. Ungoverned is the mode; the sharpest drop on the ladder is into Enforced, where governance must cross company boundaries into the supply chain.
Share of firms (illustrative)
- 38% — 1 · Ungoverned (the mode)
- 27% — 2 · Drafted
- 19% — 3 · Adopted
- 11% — 4 · Enforced
- 5% — 5 · Audited
The pressure to climb the ladder is arriving from three directions at once. Clients — especially public infrastructure clients — are adding AI questions to prequalification and framework audits. Regulation is phasing in: the EU AI Act's (opens in a new tab) risk-based obligations reach worker-monitoring and safety-component AI directly, and ISO/IEC 42001 (opens in a new tab) gives assurance teams a certifiable standard to name. And insurers are beginning to ask how AI-produced design information is checked before it carries the firm's PI cover. The World Economic Forum's construction work (opens in a new tab) has argued since 2016 that the industry's technology transformation depends on governance and skills keeping pace with tooling — the charter is what that looks like at the level of a single firm.
The AI RMF is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
What governed AI looks like in public
Three publicly reported programmes, read against the ladder. None is an Atomic Loops engagement — each links to the organisation's own published material.
The clearest public evidence for the charter thesis is in how the industry's most-watched AI programmes were run. In each case below, the interesting part is not the model — it is the governance shape around it: who reviewed the outputs, how the workforce was brought inside the purpose, and how obligations crossed company boundaries. Each is read against the ladder, on the organisations' own published material.
Three programmes read against the ladder
Outcomes as reported by the organisations themselves; verify against the linked source before reusing figures. Stage readings are our interpretation of the public record, not the organisations' own claims.
SuffolkUS general contractor · multi-billion-dollar annual programme13
- Challenge
- Thousands of jobsite photos and camera frames per week carried safety-relevant content nobody could review manually — and analysing worker imagery at scale raises exactly the privacy and trust questions clause 5 exists for.
- Approach
- Suffolk has publicly described building predictive analytics on jobsite imagery through its innovation programme, using AI to flag safety risk indicators in site photos for human safety managers to act on — the review-and-act loop kept with people, the analytics scoped to safety.
- Reported outcome
- Suffolk publicly presents AI-assisted safety analytics as a standing part of its delivery model, with risk flagged earlier from imagery its teams already capture, as described in its own published material.
- What it shows about the curvePurpose-scoped imagery analytics with humans acting on the flags is what clause 5 plus clause 9 look like when they work: the camera estate became governable because the purpose was fixed and the decision stayed human.
Balfour BeattyUK infrastructure group · 26,000+ employees12
- Challenge
- As one of the UK's largest contractors, Balfour Beatty faced the industry's automation question early: how a business built on human site supervision governs a future of increasingly autonomous plant and AI-assisted delivery.
- Approach
- Its published Innovation 2050 paper set out a public position on automation — up to and including largely human-free sites — and publicly called for the industry to develop the standards and skills to govern that transition, alongside its own digital and AI deployments.
- Reported outcome
- Balfour Beatty's own published material stakes out the governance agenda — the paper is a public artefact of the Drafted stage: a stated position and direction, with the enforcement machinery to be built beneath it.
- What it shows about the curveA published vision is the beginning of governance, not the end: the ladder's hard rungs — adoption, flow-down, audit — are what turn a position paper into rules a project follows. That is exactly the Drafted-to-Adopted gap most large firms are in.
HS2UK major infrastructure programme · delivered through JVs including SCS (Skanska Costain Strabag)24
- Challenge
- Europe's largest construction programme has dozens of contractors and JVs deploying AI — progress monitoring, logistics optimisation, safety analytics — on sites where the client must maintain assurance over systems it neither built nor operates.
- Approach
- HS2 publicly reports running innovation through a structured programme: AI deployments enter through defined trials with named accountabilities, and obligations reach the delivery JVs — such as SCS — through the contractual assurance regime rather than goodwill.
- Reported outcome
- HS2's own published innovation reporting describes AI deployed across the programme under its assurance framework — the client-side pattern of gates plus contractual flow-down operating at national-programme scale.
- What it shows about the curveEnforced-stage governance is contractual: when the client's gates and the JV contracts carry the obligations, supply-chain AI is registered and assured as a condition of working — the exact mechanism clause 6 scales down to a single firm.