Skip to content
AI Metric

Chris M.

Controlled adoption, not blanket bans

No UK professional body in the built environment recommends banning AI, and none recommends using it unsupervised. Every published standard converges on the same position: managed use, with professional judgement in the loop, data controlled, decisions documented, and checking that is proportionate rather than total.

Ask around the sector and you will hear two extreme positions. One camp wants it banned from anything professional. The other is pasting confidential tender information into free chatbots. The official guidance supports neither.

What do the institutions actually say?

BodyPositionThe specific requirement worth knowing
RICSProfessional standard on responsible AI use in surveying, effective March 2026Risk registers, documented reliability decisions for material outputs, proportionate assurance
CIOBAI Playbook: technology can improve skills, sustainability, quality and safetyManage data quality, IP and GDPR, and contractual clarity on risk allocation
RIBA2025 AI reportPractice adoption rose from 41% in 2024 to 59% in 2025, alongside concerns about imitation and reliability
ICEDesign workflows so engineers can genuinely evaluate outputsPreserve learning and accountability rather than blindly accepting output
CECAMay 2025 reportAI tools already entering businesses, sometimes unwittingly. Manage risk and upskill

The RICS position contains the detail most firms get wrong in the cautious direction. It explicitly does not require checking every output. For high-volume automated use it says that is generally neither necessary nor proportionate, and requires randomised dip-sampling instead, with the firm remaining accountable. Firms that promise 100% review are promising something the standard does not ask for and that nobody actually delivers.

The RIBA number is the one to sit with. Adoption moved 18 points in a year. It is happening either way. The only open question is whether it is governed.

What do government and regulators add?

One red line worth adopting verbatim, whatever sector you are in.

The government's guidance for its own departments, now the AI Playbook for the UK Government, which superseded the earlier Cabinet Office generative AI framework, says never enter official or sensitive information into public generative AI tools unless it is already public, and build safeguards and human review into higher-impact uses.

The NCSC's guidance helps leaders ask informed security questions. The ICO sets out how UK GDPR applies when AI touches personal data: accountability, transparency, fairness, accuracy and security. BSI's governance guidance ties it together as a lifecycle discipline covering data governance, model lifecycle management, risk and compliance, and ongoing monitoring, rather than a one-off policy document.

That red line only works if people have a sanctioned alternative, which is the whole public, enterprise and private tier question.

What does this look like as an actual playbook?

Read side by side, the guidance converges on five things for a business of any size.

  • Set data red lines first. Decide what can never go into public tools. If data cannot leave your environment, use a private deployment instead.
  • Keep a named human accountable for every material output. AI drafts, your people decide. No automatic issue of instructions, notices or compliance decisions.
  • Check proportionately. Review material outputs properly, dip-sample high-volume automated ones. Blanket checking is not required and pretending to do it helps nobody.
  • Write it down. A short risk register and a record of what you rely on each tool for is most of what good governance requires.
  • Train by role. The risks a bid writer runs differ from those a QS or an H&S manager runs, and generic awareness training misses all three.

Why does a ban fail in practice?

Because it does not reduce use, it only removes your visibility of it.

The predictable result is shadow use: personal accounts on personal phones, with no oversight and no audit trail. The information leaves anyway and you can no longer see it happening, which is a worse position than the one you were trying to fix.

The built environment does not need a ban. It needs clear rules on data, responsibility and checking, so the technology supports professionals rather than quietly bypassing governance. Start with one well-scoped pilot under those rules rather than a policy covering tools nobody has used yet.

The practical question for your business is not whether AI gets used. It is whether it gets used under your rules or under nobody's.

AI Metric is a construction-native AI consultancy. If your team is spending more time operating software than doing their job, get in touch or book a call.