How To

AI Governance for AEC Firms: The Guardrails to Set Before You Scale

Kitae KimBy Kitae Kim
September 8, 202613 min read

AI governance for an AEC firm is the set of rules that decides which tools are approved, what data can go into them, and who stays accountable for the output. You need it because your staff are already using AI, and the real choice is whether that use happens inside a framework you set or outside one. Good governance speeds adoption up rather than slowing it down, because people move faster when they know the boundaries. Here are the four guardrails that matter, in the order to set them.

Governance sounds like the thing that kills momentum. Done right, it's the thing that lets you say yes to AI without lying awake about a client data leak or a stamped drawing built on a hallucination.


Two numbers frame the whole problem. Bluebeam's 2026 outlook found data security is the top AI concern for 42% of AEC firms, and that 69% worry about coming AI regulation. At the same time, only 65% of firms invest even 10% of their tech budget in training.

Put those together and you get the actual risk picture: firms are anxious about AI risk while under-training the people already using it. That's the gap governance closes. Not by banning tools, which just pushes the use underground, but by setting clear rules people can actually follow.

Guardrail 1: Deal with shadow AI first

"Shadow AI" is your staff using AI tools you haven't approved, on work you don't know about. It's the most common AI risk in firms right now, and it's already happening in yours.

The instinct is to ban it. Don't. A ban doesn't stop the use, it just stops you knowing about it, which is the worst of both worlds: the risk continues and you've lost all visibility into it. Someone will still paste a confidential RFP into a public chatbot to hit a deadline. You just won't find out until it matters.

The move is to make sanctioned use easier than shadow use. Two steps:

  • Publish a short list of approved tools that actually do the job people are reaching for. If the approved option is worse than the one they're already using in secret, you've lost.
  • Make it safe to ask. People go around the rules when asking feels like admitting they broke them. Frame it as "tell us what you're using and we'll help you use it safely," not "confess."

You can't govern what you can't see. The first job of governance is to bring the existing use into the light.

Guardrail 2: Draw a hard line on data

This is the guardrail with the most immediate exposure, because a lot of public AI tools may use what you type to train future models. Client-confidential material pasted into the wrong tool can leave the building in a way you can't take back.

Set a simple, memorable data rule. Something like: never paste client-confidential material, anything under NDA, personnel information, or unpublished project data into a public AI tool. For anything in those categories, use only the firm-approved tools that keep your data private.

Then make it enforceable by removing the excuse. If the rule is "don't use public tools for sensitive data," you have to give people a private tool that handles that data properly. A rule without an approved alternative is a rule people break under deadline pressure.

When you evaluate any AI vendor, three questions settle most of the data risk:

  • Does it use our data to train its models? (You want no, or a clear opt-out.)
  • Where does our data live, and who can see it?
  • Can we delete it, and what happens to it when we leave?

A vendor that can't answer these cleanly is a vendor you don't put client data into. The 42% of firms losing sleep over data security are mostly losing it over questions they never asked at purchase.

Guardrail 3: Assume it hallucinates, and build the check in

AI models produce fluent, confident text that is sometimes wrong. A hallucinated statistic, a fabricated code reference, an invented precedent, all of them read exactly like the real thing, because the model has no internal signal that says "I'm guessing now."

For a licensed profession, this is the guardrail that carries the most consequence. A wrong number in a proposal is embarrassing. A hallucinated code citation in a report or a fabricated fact in a submission is a liability problem.

The rule is simple to state and non-negotiable to follow: every factual claim, code reference, or number that an AI produces gets verified against a source before it leaves the firm. AI drafts. A human checks. Nothing AI-generated goes out unverified.

This is a process rule, not a trust setting. You don't get to decide the model is "usually reliable" and skip the check. The whole point is that you can't tell from the output which parts are the confident wrong ones. So you check all of it, or you check none of it and accept the exposure. There's no reliable middle.

Guardrail 4: Keep a licensed human accountable

This is the one specific to AEC, and it's the boundary that defines where AI can and can't operate in a design firm.

The professional standards our field already runs on, the requirement that a licensed professional exercise responsible control over the work they stamp, don't have an AI exception. A model can't hold a license. It can't be named on a contract. It can't stand behind a stamped drawing or a sealed report. When AI contributes to work that carries professional liability, a licensed human is still fully accountable for it.

So the governance rule is: AI can assist, inform, and draft, but a licensed professional owns and is responsible for any output that touches a stamp, a seal, or a professional judgment. That accountability doesn't transfer to the tool, ever, and no vendor claim changes it.

Practically, that means writing down, for each AI use, who the accountable human is. For a proposal, the person who signs off. For anything approaching design or code compliance, the licensed professional in responsible control. Make it a named role in the workflow, not an assumption.

Put it in one page

Governance fails when it's a 40-page policy nobody reads. It works when it fits on a page people actually remember. A workable AEC AI policy is short:

  • Approved tools: the specific list, kept current.
  • The data rule: what never goes into a public tool, and which private tools to use instead.
  • The verification rule: every AI-produced fact, number, or citation gets checked against a source before it leaves the firm.
  • Accountability: a licensed human owns anything touching a stamp or professional judgment; a named human owns anything client-facing.
  • Who to ask: one person or channel, and a clear message that asking is encouraged, not punished.

That page, published and actually socialized, closes most of the risk that the 42% and the 69% are worried about. It costs a morning to write and it's the highest-value AI move most firms haven't made.

Governance is the accelerator, not the brake

The framing that stops firms is treating governance as the thing you do to slow AI down. It's the opposite. People adopt faster when the boundaries are clear, because the fear of doing something wrong is what actually freezes them. A designer who knows exactly which tool is approved and what data is off-limits will use AI confidently. One who's guessing will either avoid it or do something risky.

Set the guardrails first. Then scale, knowing you can say yes without gambling the firm's data, its work product, or its license.

Where Foveate fits

Foveate is built for firms that take these guardrails seriously. It's a private, firm-connected system for pursuit work, so your RFPs, project history, and client data aren't going into a public model. It's designed to inform decisions like the go/no-go rather than make them, keeping your people accountable for the calls that matter. And it's a sanctioned Tier-2 workflow you can point staff toward instead of the shadow tools they'd otherwise reach for on a deadline.

If you're setting AI policy and want to see what a governed, firm-connected AI workflow looks like in business development, book a demo and we'll walk through how the data and accountability actually work.

Frequently Asked Questions

What is AI governance for an architecture firm? It's the set of rules defining which AI tools are approved, what data may go into them, how AI output gets verified, and who stays accountable for the result. Its purpose is to let a firm adopt AI confidently without risking client data, work quality, or professional liability.

Should we just ban AI to avoid the risk? No. A ban doesn't stop use, it hides it, so the risk continues while you lose all visibility. The effective move is to make sanctioned, safe use easier than shadow use: approve tools that do the job, give people a private option for sensitive data, and make it safe to ask questions.

What data should never go into a public AI tool? Client-confidential material, anything under NDA, personnel information, and unpublished project data. For anything in those categories, use only firm-approved tools that keep your data private and don't train on it. Always confirm a vendor's data-training, storage, and deletion policies before trusting it.

How do we handle AI hallucinations on professional work? Assume the model can be confidently wrong and build verification into the process. Every AI-produced fact, number, or code citation gets checked against a source before it leaves the firm. Because you can't tell which outputs are the wrong ones from how they read, you verify all of them.

Does using AI change who's liable for stamped work? No. A licensed professional in responsible control remains fully accountable for any work that carries professional liability. AI can assist and draft, but it can't hold a license or stand behind a stamp, so accountability stays with your licensed people and never transfers to the tool.

Sources

About the Author

Kitae Kim

Kitae Kim

Architect with 10 years of experience in design and client communication. Co-founder of Foveate, the Pursuit Intelligence Platform for AEC firms. Former studio lead who saw too many winning designs lose to worse proposals.

Mitigate Risk. Move Faster.

Show clients how the event will feel. Align every production team. Ship with confidence.