Treat information entered into an AI system as disclosed outside the firm until a documented review establishes what the service does with it. A tool’s marketing statement about security is not enough to answer questions about data retention, model training, human access, deletion, or subcontractors. Those details can affect client obligations and the firm’s own risk.
Create a simple intake rule for employees: use only approved accounts and tools, and do not paste drawings, calculations, field photos, personal information, credentials, or commercially sensitive details into an unapproved service. Before approving a tool, ask the vendor for clear terms on storage, training use, access controls, deletion, breach notice, and subprocessors. Have the firm’s security lead review the answers, and ask counsel to compare them with client agreements, privacy duties, and any applicable restrictions.
Reduce exposure even in an approved workflow. Include only the information needed for the task. Remove names, addresses, parcel identifiers, and other details when they are not needed. Use synthetic examples for demonstrations and training. Limit access to firm-managed accounts, require strong authentication, and make sure staff know how to report an accidental upload without delay.
Owners should maintain an approved-tool list with an internal contact and review date. Assign someone to check for changes in vendor terms and remove access when an employee leaves or a tool is no longer approved. If information is disclosed by mistake, follow the firm’s incident process, preserve relevant details, and involve the people responsible for client notification and legal review.
Ask each project manager to identify contract-specific data restrictions before a team adopts an AI workflow. Ask the security lead what evidence supports the approval and what would trigger a re-review. Contracts and applicable law govern data handling.
Set a clear rule that staff do not paste client files, personal information, unpublished designs, or contract details into an AI service unless the firm has approved that specific use. Ask the person responsible for information security to review data retention, access, and account settings before a tool is adopted. For example, replace a client name and site address with neutral labels when asking for help with generic wording. Keep a record of approved tools and permitted data types, and train staff to pause when they are unsure.
This is general education, not cybersecurity, legal, or engineering advice.
