
AI adoption in construction is already happening, but not in the way you might expect. While AI is a top priority for many businesses in the sector, an astounding 45% of contractors have not yet actioned any form of AI implementation.
As a result, employees are taking matters into their own hands — often without company permission, oversight, or control.
This bottom-up shift is creating an urgent governance and risk challenge for construction leaders. Recent Microsoft WorkLab research found that 78% of employees who use AI at work bring their own tools rather than using employer‑approved solutions. Even more concerning, 52% admit they would not tell their manager they used AI to complete a task.
For an industry built on tight margins, contractual accountability, and data integrity, unmanaged AI usage introduces a commercial and compliance risk contractors simply can’t afford.
Where is AI being used?
AI usage spans everyday workflows across the business, from finance to commercial and operational roles, and often in ways leadership never sees.
Finance teams are using AI to summarise CVRs, analyse cost movements, draft reports, and interrogate data. Meanwhile, commercial managers are asking public tools why margins are shifting, and site teams are uploading documents to AI chat interfaces to save time.
The intent is understandable, but the risk is significant.
Because when AI enters the business through individual behaviour rather than organisational design, safeguarding measures get lost — and that’s where problems begin.
Shadow AI is accelerating faster than governance
This phenomenon — often referred to as shadow AI — mirrors the shadow IT problem construction has battled for years, but at a far greater scale and speed.
In construction, the implications are particularly serious. Commercial rates, supplier costs, payroll data, valuations, and cashflow forecasts are some of the most sensitive data a business holds. Once this information is entered into public AI platforms, organisations lose visibility over where that data is stored, how it may be retained, and whether it could be reused, exposed, or referenced outside the business.
Public AI tools create real data exposure risks
Unlike enterprise‑grade AI, public AI platforms provide little to no control over data retention, reuse, or governance. Surveys show that 46% of employees using unapproved AI tools have pasted confidential business or customer data into those platforms.
At a time when UK construction businesses are already under pressure — from tightening margins and rising costs to growing regulatory and cybersecurity scrutiny — this level of unmanaged AI usage is a critical risk. What may feel like harmless productivity gains can quickly translate into data leakage that leadership teams simply can’t monitor.
‘AI lockdown’ isn’t a solution
In an attempt to address the situation, the instinctive response might be to clamp down and block external AI tools. However, this approach has historically backfired and often amplified the problem.
Multiple studies have shown that employees continue using AI even where formal bans exist, driven by workload pressure and the productivity gains it delivers. One survey found 46% of workers would keep using AI even if their employer prohibited it.
In other words, the question is not whether teams will use AI, but whether it will happen safely, transparently, and under your control.
Secure AI is a leadership decision, not a user choice
This is where responsibility shifts firmly to leadership. AI governance cannot be delegated to individual discretion.
Microsoft’s approach reflects this reality. Tools like Copilot operate within existing security roles and permissions, ensuring users can only access the data they are authorised to see. Importantly, company data is not used to train public AI models, addressing one of the biggest concerns around commercial leakage.
For finance and IT leaders, this distinction matters. Secure, enterprise‑grade AI allows teams to gain productivity and insight without compromising confidentiality, compliance, or commercial integrity.
In construction finance, the stakes are higher. As an industry that already operates on thin margins, volatile costs, and complex contracts, the financial exposure from a data breach, compliance failure, or loss of commercial confidentiality can be severe.
That’s why AI adoption cannot be left to chance. Managed, governed deployment is not a technical nuance — it’s a strategic requirement. AI is not something organisations can afford to discover retrospectively.
AI adoption on your own terms
The reality is clear: AI will be used in construction. Leadership must decide whether it evolves as a trusted capability embedded within the organisation, or bubbles away as an unmanaged liability behind closed doors.
With threats of leaked data and compliance breaches on the line, contractors should set clear guardrails, provide approved tools that genuinely support day-to-day work, and ensure AI operates within existing permissions and accountability frameworks.
In doing so, AI transitions from a hidden risk into a disciplined advantage. As such, contractors can support better forecasting, sharper commercial decisions, and stronger financial control without compromising data integrity.

