Skip to content
AI Metric

Chris M.

The AI in your business that nobody procured

A firm can have no AI strategy, no AI procurement and no AI budget, and still have AI shaping its project records every week. The question is not whether to allow it. That decision has already been taken, quietly, by people trying to do their jobs.

What were the answers to the previous five questions?

1. Your firm has no AI policy and no procurement record for any AI tool. Does that mean AI is not being used?

No. It means AI use is unrecorded. Copilot ships inside Microsoft 365, AI features arrive inside estimating, design and document management software by update, and consumer accounts need no purchase order. Absence of procurement evidence is evidence of absent governance, not absent use.

2. Why is enterprise grade data security an incomplete answer to the question "is our AI use safe"?

Because it answers only where the data went. An enterprise secure system can still summarise forty emails and miss the one that changes the commercial position, work from a superseded revision, or produce fluent wording that concedes something. Security and correctness are separate problems with separate controls.

3. A project manager asks a model to make a delay email "more professional and contractual". What has changed about that email that matters?

The author knew what they meant. The redraft contains wording chosen by a language model: which programme, whether it was agreed, whether causation has been established. Making language better and making a project record correct are different operations, and only one of them was requested.

4. What is the difference between an AI system making a decision and an AI system influencing one, and which is more common?

Making means the output is actioned without meaningful human involvement. Influencing means a human decides, but some of the reasoning in front of them originated with a model. Influence is far more common, far harder to see, and currently far less governed.

5. Why is the first governance exercise a discovery exercise rather than writing a policy?

Because a policy written without knowing what is happening governs an imaginary organisation. You cannot classify by consequence, assign owners or set proportionate controls over use cases you have not found.

What does shadow AI actually look like on a live project?

It looks like ordinary competence. A quantity surveyor pastes a subcontract clause in to understand it faster. An estimator asks a model to interrogate a 180 page specification because reading it properly costs half a day. A bid manager improves a methodology. A design coordinator summarises a technical submission. None of it feels like implementing anything.

THE PATH GOVERNANCE WATCHESProcurementBusiness caseSupplier due diligenceSecurity reviewDeploymentPilot, then rolloutNamed ownerTraining programmeOversightRegister entryRisk assessmentReview cycleVisible useManagement sees itand can control itTHE PATH IT DOES NOTAn ordinary TuesdaySomeone pastes a clauseinto a tool to understand it,then uses what comes back.The output becomes workIt goes into an email,a report, an assessment,a project record.Invisible useNo procurement, no register entry,no owner, no review. The firmcarries the risk without seeing it.
Two routes AI takes into a construction business. Governance was built for the top route. Almost all real use arrives by the bottom one, where there is no procurement gate to attach a control to.

The top path is the one every governance framework anticipates: business case, due diligence, deployment, register entry, review cycle. The bottom path has no gate anywhere along it. By the time an output has become an email, a report or a commercial assessment, it is a project record, and the organisation carries it.

Why is the rewritten email the sharpest example?

Because it is the smallest possible intervention with the largest possible consequence, and because everybody has done it.

What the author wroteWhat came backWhat moved
The works remain delayed because we still do not have the revised information.The works remain delayed pending receipt of the outstanding design information, which continues to impact progress against the agreed programme.Causation is now asserted rather than described
(no reference to a programme)"the agreed programme"A programme is characterised as agreed, which may be contested
"we still do not have""outstanding"A neutral statement becomes a term with contractual colour
(no attribution)"design information"Responsibility is implied without being established

None of that is a hallucination. The model did precisely what it was asked. The employee asked for better prose and received, alongside it, a contractual position. That is why "check the AI output" is too vague an instruction to be a control: checked against what, by whom, for which risk?

Is this now a regulatory matter rather than a matter of taste?

For surveying firms, yes. The RICS professional standard on the responsible use of artificial intelligence took effect on 9 March 2026 and is mandatory for members and regulated firms where AI has a material impact on the delivery of surveying services. It expressly recognises that AI becomes involved in producing professional work both knowingly and unknowingly, and requires firms to keep a written record of AI use and a risk register (RICS).

The wider industry is not formally bound by that standard, but the direction is unambiguous, and the same logic reaches anyone carrying a duty. A principal designer or principal contractor under CDM 2015 holds their duties personally and organisationally. Nothing about a model participating in the reasoning redistributes them.

What should you do about it this week?

Nothing punitive. The single most effective change is to the question you ask, and the discovery exercise in part 4 is built on it.

Do not ask whether anyone is using unauthorised AI. You will get denial, or one minor confession, and neither gives you the picture. Ask instead where AI is currently helping people do their work, and be precise about what you are promising. You are promising that nobody is in trouble for telling you. You are not promising that everything continues unchanged, because some of what you find will need controls around it, and an assurance you break in week four is worse than one you never gave.

Say what the amnesty covers and what it cannot. It covers the fact of use: nobody is disciplined for telling you they have been using a tool the firm never gave them. It cannot cover an actual data breach or a breach of client confidentiality, because those carry notification duties the firm does not control, and a personal data breach starts a seventy two hour clock whether or not you would rather handle it gently. Brief interviewers on two escalation triggers: personal data or client confidential information in an unmanaged account, and anything touching a live dispute or a statutory submission. On either, stop, say plainly that this one goes to the data protection lead today and that the escalation is about the information rather than the person, and route it the same day.

It is also worth being clear internally that this is not a character issue. People reach for these tools because the alternative is reading 180 pages on a Thursday evening. The pull is real and it is not going to weaken. See also shadow AI in the workplace and controlled AI adoption rather than blanket bans.

That leaves an obvious objection, and it is the one directors raise first. If AI can now read the contract, challenge the valuation and interrogate every record on the project, what exactly is left for the professional? part 3, AI can read the contract. It cannot become the dutyholder answers it, and the answer is not sentimental.

What five questions should you be able to answer now?

Attempt these before tomorrow. Each has a defensible answer, and each is answered at the top of the next part.

  1. Under CDM 2015 and, in England, Part 2A of the Building Regulations, who can hold a dutyholder role, and could that ever be a software system?
  2. What is the difference between work that AI can perform and responsibility that AI can carry?
  3. Which parts of a project manager's week are genuinely at risk from automation, and which are not?
  4. If a firm automates every routine judgement a graduate used to make by hand, what happens to their ability to catch the machine when it is wrong, and when does that bill arrive?
  5. Why does an approval button on a screen not necessarily constitute human oversight?

Which sources is this part built on?

Every figure quoted above resolves to one of these. Each was checked before publication.

AI Metric is a construction-native AI consultancy. If your team is spending more time operating software than doing their job, book a 30 minute call.