Close-up of a smartphone displaying ChatGPT with vibrant background. Ideal for tech and AI themes.

How to Write an AI Use Policy for Your Design Firm in One Afternoon

Your team is already using AI. Right now, today, whether you have talked about it or not, and none of them are sure what is actually allowed, because your firm never said.

A sleek laptop on a wooden desk showing the ChatGPT homepage by a window.

Someone is summarizing a spec in ChatGPT. Someone is cleaning up a proposal. Someone dropped a client’s project details into a free tool last week to save time. That gap, real AI use and zero rules, is where the risk lives. The good news is that closing it is not a big legal project.

Here is the short version. Your staff are almost certainly using AI, and probably more than you think. You do not need a forty page legal document. You need a one page AI use policy that covers seven things: why it exists and who it covers, which tools are approved, what data must never go into AI, checking the client contract before AI touches a project, a human who reviews and owns the output, who to ask when unsure, and a line to sign. That is enough to protect your firm, and it is also the kind of documentation your insurance carrier and your clients are starting to ask for.

Your team is using AI more than your firm knows

If you feel behind on AI, you are not alone, and you are not wrong. AIA’s 2024 Firm Survey found that 27% of small architecture firms use AI in day to day work, compared to 61% of large firms. Small firms are not the ones racing ahead. That is a reasonable place to be.

But that number counts what firms know about. Ask the workers instead and you get a very different picture. Surveys through 2026 put unapproved AI use somewhere between roughly half and two thirds of employees. Most of those people are on free versions with no business protections. A large share admit they have pasted company or client information into them.

So the honest version is this. Your firm’s official AI adoption is probably low. Your firm’s actual AI use is probably much higher. The industry calls that gap, shadow AI: people quietly using tools their own way, on their own accounts, because nobody told them what the rules are.

You will also see a bigger number going around. Unanet’s 2026 AEC Inspire Report, based on about 300 AEC leaders, found 75% of AEC firms now use AI. That survey leans toward larger firms and construction, so do not measure your six person office against it. The same report found only 29% of firms have high confidence in the data feeding their AI tools, which is a separate and real problem about data quality, not about leaks.

When there are no rules, everyone makes their own. One person is careful. Another pastes a whole contract into a free tool to “clean it up.” Nobody is being reckless on purpose. They just have never been told where the line is. A simple written policy turns all that guessing into one clear standard.

A forty page compliance document that sits unread protects no one. A clear one pager that everyone follows protects your firm every day.

You do not need a legal treatise

Here is what stops most firms from writing a policy: they picture a giant, lawyerly document full of clauses nobody will read. So they never start.

Throw that picture out. The best AI policy for a small design firm is short, plain, and one page. Something your whole team can read in two minutes and actually remember.

This is the same principle as everything else we believe about small firm IT. Simple and used beats complex and ignored. So aim for short.

A smartphone displaying the Wikipedia page for ChatGPT, illustrating its technology interface.

The reason to write it this year: your insurance

Here is the part most firms have not heard yet, and it is the one that costs money. Insurance carriers are starting to write AI out of policies. Verisk, the organization that writes the standard forms most carriers build on, released generative AI exclusion endorsements for commercial general liability, effective January 1, 2026. The form numbers are CG 40 47, CG 40 48, and CG 35 08. They are optional forms, so each carrier decides whether to attach them to your policy. Many have filed to do so.

There are also reports of carriers filing similar AI exclusions on professional liability (E&O). We are not going to tell you what your specific policy says, because we cannot see it and it varies by carrier and by state. What we will tell you is to ask.

Here is the useful part. Brokers report that carriers are willing to negotiate carve backs for firms that can show a documented AI governance program. That means approved tools, verification steps, client disclosure, and licensed professional sign off. Read that list again. That is your one page policy. The document you write this afternoon is the thing you hand a carrier or a client when they ask how you control AI.

So at your next renewal, ask your broker two questions. First: does my policy exclude anything related to AI, on general liability or E&O? Second: what do you need to see from us to keep AI covered? Then bring your policy to that conversation. Proactive is better than reactive, and this is one of those places where the timing is not up to you.

The seven things to put in your policy

Here is the whole policy, in seven plain parts. Write a few sentences for each, fill in your firm’s specifics, and you are done.

  • One: why it exists and who it covers — Open with a sentence or two on the point of the policy (to use AI safely without putting client data or your firm at risk) and who it applies to: everyone, including staff, contractors, and anyone doing work for the firm. This stops the “I did not think it applied to me” excuse.
  • Two: which tools are okay, and which are not — On free and Plus ChatGPT accounts, your chats can be used to train the model unless someone turns that setting off. On business accounts (ChatGPT Business, Enterprise, Edu, and the API), OpenAI says it does not train on your inputs or outputs by default. So the paid account is genuinely better. Keep the tool list in a linked appendix that one named person owns, so the policy page itself does not go stale.
  • Three: what never goes into AI — Spell out in plain words what must never be pasted into a public AI tool: client names and details, project specifics, drawings and models, contracts, budgets, and any private or personal information. The simple rule: if it is confidential or it belongs to a client, keep it out of public AI. We explain why this matters in our post on the risk of pasting project data into AI tools.
  • Four: check the client contract first — A business AI account solves the training question. It does not solve the contract question. Plenty of agreements flatly prohibit sharing project information with any third party, and an AI vendor is a third party. Federal work with controlled unclassified information (CUI), ITAR work, healthcare, data centers, utilities, and some school district and municipal contracts all commonly restrict this.
  • Five: a person reviews it and owns it — AI output is a draft, not a final answer. For engineering firms this is not just a quality habit, it is a licensure question. NSPE’s Board of Ethical Review has already addressed an engineer who failed to keep responsible charge over an AI tool and its output before sealing a document, and found it unethical. If you seal it, you own it.
  • Six: who to ask — Name a real person or role to go to when someone is unsure whether a use is okay. Most people want to do the right thing. They just need somewhere to ask.
  • Seven: sign and date — End with a line for each person to acknowledge they read and understood the policy. It gives you standing if someone ignores it, and it is proof of a real program when a client or a carrier asks how you manage AI.

For example, let’s say your team buys the paid version of a tool and feels safe. Someone runs a federal project’s scope through it to draft a narrative. The tool did not train on it. The firm still breached the contract. So make the rule plain: before AI touches a project, check that project’s contract. If you are not sure, ask the client. Written permission beats a good guess.

Close-up of a smartphone showing a chat interface with a laptop in the background.

Write it this afternoon

Here is how to actually get it done today, not “someday.” Block off about two hours. Start from a template so you are editing, not staring at a blank page. Fill in your firm’s specifics: your approved tools, your point person, and any rules unique to your work. Keep cutting until it fits on one page.

Then have your team read it and sign it, and take ten minutes to walk through what it means for their day, so it is understood, not just filed. That last step, actually talking it through, is what makes people follow it.

By five o’clock you have a one page policy, your team has read it, and everyone knows the two rules that matter most: keep client data out of public AI, and check the contract before AI touches a project. That is a real reduction in risk for an afternoon’s work.

A policy says what to do. It does not tell you what people did.

One honest caveat, because we would rather you hear it from us. A policy is a rule, not a control. Nothing about a signed one pager tells you whether someone pasted a floor plan into a free tool last Tuesday. You will never know unless you back the policy with something technical.

The basics are not complicated. Give everyone a licensed business AI account, so the safe path is also the easy path. Block consumer AI sites on firm computers if your work calls for it. Run AI through a managed tenant where the firm controls the settings. You should pair the policy with at least one of these. A rule with nothing behind it is a hope.

Keep it alive

One last thing, because AI changes fast. A policy you write once and forget goes stale quickly, as new tools appear and old ones change how they handle data.

Put a simple habit in place: review the policy every quarter, mostly to update the approved tools list. Then add three triggers that force a review no matter what the calendar says. Someone asks to use a new tool. A new client contract comes in with AI or confidentiality terms. Your insurance renews. Those three catch the changes that actually matter.

This pairs naturally with your other basic protections, like the ones we cover in our post on what small firms get wrong about passwords and our post on the phishing emails targeting AEC firms.

Frequently asked questions

Yes. Your team is very likely using AI already, often on free accounts you do not know about, and without a policy everyone makes their own rules. A one page policy sets a clear standard, and it is also the documentation clients and insurance carriers are starting to ask for.

Seven things: why it exists and who it covers, which tools are approved, what data must never go into AI, checking the client contract before AI touches a project, a human who reviews and owns the output, who to ask when unsure, and a line for each person to sign. Keep it to one page and in plain English.

Usually no, with one real exception. A flat ban with no alternative pushes people to use AI secretly on their phones, which removes your visibility and makes the risk worse. But if you do federal work with controlled information or ITAR work, or your E&O policy excludes AI, then pausing AI on project work until you have approved tools and a broker answer is a reasonable call. The bad version is banning it and offering nothing.

It helps, and it does not settle the question. On business accounts OpenAI says it does not train on your inputs or outputs by default. That is a real difference from a free account. But “they will not train on it” is not the same as “your client’s contract allows it.” Those are two separate checks, and you need both.

Quarterly is plenty for most firms, mainly to refresh the approved tools list. Also review it any time someone asks for a new tool, a new client contract lands, or your insurance renews.

We will help you set up safe AI, policy and all

Writing the policy is the first step. Setting your team up with AI tools that actually protect your data, and making the rules stick, is where it becomes real protection. We help small architecture and engineering firms around Knoxville roll out safe AI: the right tools, a simple policy, the technical settings behind it, and a short conversation with the team, so you get the speed of AI without leaking your clients’ information.

If your firm is using AI with no rules yet, give us a call. We will help you write the policy, pick safe tools, and get your team on the same page. So they can move fast with AI, and your data stays yours.

Key takeaways

  • Your firm’s official AI use is probably low, and your team’s actual AI use is probably much higher. 2026 surveys put unapproved AI use at roughly half to two thirds of workers, most of them on free accounts with no business protections.
  • You do not need a legal treatise. A one page policy covering seven things (why it exists and who it covers, approved tools, what never goes into AI, checking the client contract, human review and ownership, who to ask, and a signature) is enough, and you can write it in an afternoon.
  • Do it this year because of insurance. Carriers began attaching generative AI exclusions in 2026, and brokers report that a documented AI program is what buys back coverage. Then back the policy with a real control, because a rule nobody can check is a hope.

Is your team using AI with no rules yet?

We help you write a one page policy, pick tools that protect your data, and get everyone on the same page. No obligation, no sales pitch.


Sources: Unanet 2026 AEC Inspire Report; AIA Firm Survey Report 2024; Verisk generative AI exclusions for general liability (Independent Agent); Enterprise privacy at OpenAI; OpenAI business data privacy; NSPE Board of Ethical Review: Use of Artificial Intelligence in Engineering Practice; CIO: roughly half of employees are using unsanctioned AI tools; Generative AI Usage Policy Template (SHRM); A Complete Guide to Creating Your Company’s AI Acceptable Use Policy (Tenable)

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *