Plainstart Back to the kit

Free generator

An AI usage policy built for a construction business.

The exposure on a building site is not usually a data leak. It is a quote that was wrong, or a method statement nobody checked. This writes the policy for the risks that actually apply, filled in for your business.

No email required. No signup. Copy it, download it, use it.

Your business

Approved tools

Settings

AI Usage Policy

AI Usage Policy for [Business name]

A plain-language policy covering what staff may and may not do with AI tools at work. Read it, adapt anything that does not fit, then circulate it.

1. Why we have this policy

[Business name] uses AI tools because they save time and improve our work. They also carry real risks: leaking confidential or customer data, producing wrong or biased output, and creating work that nobody has checked. This policy sets out how we use AI so we get the benefit without the harm.

It applies to everyone: employees, contractors, and anyone acting on behalf of [Business name].

2. The one rule that matters most

Never put information into an AI tool that you would not email to a stranger.

If you are unsure whether something is safe to enter, it is not. Ask your manager before you proceed. Asking is always the right call and nobody will think less of you for it.

3. What you must never enter into a public AI tool

Unless the specific tool has been approved for it in writing, never enter:

  • Your cost structure: labour rates, supplier pricing, margins, and preliminaries
  • Subcontractor rates and terms
  • Client names combined with contract value or payment history
  • Tender documents and pricing where you are bound to confidentiality
  • Employee personal details, including anything held for health and safety purposes
  • Site addresses combined with security, access, or alarm information
  • Photographs or documents from a client site that were not provided for public use

4. Approved tools

Only use AI tools on this list for work. Using an unapproved tool for work is a breach of this policy.

ToolApproved forNot approved for
[Tool name]Wording a client update, drafting a scope description you have priced yourself, or turning your own site notes into a tidier documentProducing prices, rates or quantities, and generating safety documentation that is not reviewed against the actual site

Free consumer versions of AI tools often train on what you enter and keep it. Paid business tiers usually let you turn that off. Only approve a tool once someone has checked how it handles your data.

5. Getting a new tool approved

Want to use an AI tool that is not on the list? Do not just start using it. Send a request to the operations manager with three things: what the tool is, what you want to use it for, and what data it would touch. The operations manager will check its data handling and security before approving or declining, and approved tools are added to the table above.

6. You are accountable for what AI produces

AI makes mistakes. It invents facts, gets numbers wrong, and is often confidently incorrect.

  • Check everything before it leaves the business. You are responsible for any AI-assisted work you send to a customer, publish, or rely on for a decision, exactly as if you had written it yourself.
  • Never send AI output to a customer or an external party without a person reading it first.
  • Do not use AI to make final decisions about people, including hiring, firing, discipline and pay, or about anything with legal, safety, or financial consequences. AI can assist your thinking. A person decides.

7. Be honest about AI use

  • If a customer or a colleague asks whether something was AI-assisted, tell the truth.
  • Do not present AI-generated work as if it involved professional judgement that it did not.
  • Customer-facing written work must note where AI was used in preparing it.

8. Quotes and safety documents are not AI output

No price, rate, quantity, allowance or timeframe produced by an AI tool goes into a quote, an estimate, a variation or an invoice without being worked out or verified independently by the person responsible for the job. A tool may help you lay a quote out or word it. It does not price it.

No safety documentation is issued on the basis of AI-generated content alone. Method statements, risk assessments and site-specific safety plans must be written or fully reviewed by the person accountable for the work, against the actual site and the actual method. Generic hazard content that has not been checked against the job is treated as a breach of this policy, because it is a document people rely on standing next to the hazard it describes.

9. Bias and fairness

AI reflects the data it was trained on and can produce biased or unfair output. Be especially careful using AI for anything involving people, and never let it be the sole basis for a decision that affects someone.

10. If something goes wrong

If you accidentally enter sensitive information into an AI tool, or you spot AI output that has caused a problem, tell your manager straight away. The point is to fix it fast, not to assign blame. Reporting something early is always treated better than a hidden problem that surfaces later.

11. Breaches

Not following this policy may be treated as a disciplinary matter under our normal procedures, because it can put the business, our customers, and our people at real risk.

Policy owner: [name and role]
Applies to: [Business name]
Version date: [date]
Review: every six months, because AI tools change fast

The risk that dominates in construction

Most AI policy material is written for businesses whose main asset is information. That is not this sector, and applying the standard template here produces a document about confidentiality risks that barely arise while missing the two that do.

The first is pricing. A tool asked to help with a quote or an estimate will produce numbers, and the numbers will look reasonable. Rates, allowances, quantities, timeframes. It has no knowledge of your suppliers, your labour cost, or what the job actually involves, and a quote is a commercial commitment. An estimate that is ten percent light does not announce itself until the job is underway.

The second is safety documentation. Method statements, risk assessments, and site-specific safety plans are exactly the sort of repetitive writing people want help with, and they are documents that get relied on by someone standing next to a hazard. Generic AI-generated safety content is worse than a short document written by someone who walked the site, because it reads as thorough while being unspecific to the actual work.

The data risk that does apply is narrower than elsewhere: client contact details, pricing structure and margins, and subcontractor rates.

What this looks like in practice

An estimator is quoting a fit-out and asks a chatbot for a labour allowance for a task. It returns a figure with a confident breakdown by hours and rate.

The figure is not based on the crew, the site access, the hours the building allows, or what the estimator's own last three jobs cost. It is an average of text. Under this policy it cannot go in the quote, and the practical harm if it does is not a compliance issue, it is a job priced light that has to be built anyway.

What the policy does allow, and what is genuinely useful, is the estimator pricing the job from their own rates and then using the tool to check they have not left a trade off the scope entirely. Asking what a fit-out of this type usually includes is a question about categories. Asking what it costs is a question about numbers.

The same split applies on the safety side. Asking what hazards a task of this type commonly involves is a reasonable prompt. Issuing the answer as the site's risk assessment is not.

Why this is free

An AI policy is the first thing a business needs and the easiest thing to put off. Charging for it would just mean fewer businesses have one. Handing it over, with no email wall in front of it, is also the honest way to show you what our work is like before you spend anything.

Use it, change it, put your own letterhead on it. There is no attribution requirement and nothing to sign.

If the policy was useful

The policy is document one of nine.

A policy tells people where the line is. It does not tell you which tools to trust, where AI is actually worth using in your business, or whether any of it paid off. That is the rest of the kit.

  • Data governance checklist, so you know what a tool does with your data before it touches it
  • Tool evaluation scorecard, with two real tools compared and the better product losing
  • Use-case grid, seven candidates scored including the high-value one worth refusing
  • 90-day adoption plan, with the staff announcement script and the five failure modes
  • ROI tracker, a worked quarter and the three challenges a sceptic always makes
  • Prompt libraries for finance, operations, marketing, HR and customer service
Get the full kit$149 one time, nine documents

Other versions of this policy

The same document rebuilt around a different set of risks. If none of these is you, the general version is the place to start.

Questions

Is this actually free, or do I hit a paywall at the end?
Free. The policy is complete on this page, you can copy or download it right now, and there is no email step. The paid kit is a separate thing you can ignore.
Is this legal advice?
No. It is practical business guidance written to be usable, not a legal document. Employment and privacy law differ by country, so have your final version checked against your local law before you rely on it, particularly the breaches section.
Can I edit it and put my own branding on it?
Yes. Change anything, remove sections that do not apply, add your logo. There is no attribution requirement.
Does it work outside New Zealand?
The policy is deliberately written without country-specific law in it, so the substance travels. The one part to check locally is how breaches are handled under your employment rules.
How long should an AI policy be?
Short enough that people read it. A one-page policy that staff follow beats a twenty-page document nobody opens. This one is deliberately about one page once you delete what does not apply.
How often should we update it?
Every six months is a sensible default while AI tools are changing this fast, and immediately if you approve a new tool or something goes wrong.
Our team is not office-based. Does a policy like this apply?
It applies to the phones. Most AI use in this sector happens on a personal device between jobs, which is precisely why a short written rule works better here than a long document, and why the one-page version is the one to circulate.
Can AI help with a health and safety plan at all?
As a prompt for what you might have missed, yes. As the document itself, no. The distinction this policy draws is between a tool that widens your own thinking and a tool whose output is issued to people relying on it. A safety plan is always the second one.
Who wrote this?
Plainstart, a brand of Sypher Limited. We publish plain-language operational material for small and medium businesses adopting AI.