Back to home

AI Compliance for AEC

The verifiable, ongoing alignment of AI tool use with the codes, standards, and liability frameworks that govern licensed professional practice — proven on a per-tool, per-firm, per-decision, and per-day basis.

01

The Definition

AI compliance for AEC is the discipline of ensuring that any AI tool used in licensed Architecture, Engineering, or Construction work meets the technical, legal, and professional standards required for the licensed individual to defensibly stamp, sign, or take responsible charge of the resulting work product.

Working definition

AI compliance for AEC is the verifiable, ongoing alignment of AI tool use with the codes, standards, and liability frameworks that govern licensed professional practice — proven on a per-tool, per-firm, per-decision, and per-day basis, and recorded in a form that survives external scrutiny from a state board, an E&O carrier, or opposing counsel.

02

The Four Dimensions

The definition decomposes into four layered questions. Each maps to one Shield module. The four together produce the complete compliance posture; no single dimension is sufficient on its own.

01

Per-Tool Defensibility

The tool-level question. Every AI tool used in stamped work must be assessable against a published rubric. Does it meet the threshold for safe use under the licensed professional's responsible charge?

Module
C1 · Compliance Scanner
Asks
Is THIS tool ready for our licensed practice?
Output
ACS score (7-layer rubric, 22 questions) · DCS verdict (GREEN ≥88% / AMBER 68–87% / RED <68%) · Q21b liability transfer flag · HF1–HF5 hard-filter status
Standards
ISO 42001 · NIST AI RMF · FDA SaMD · EU AI Act Articles 8/9/10 · CMMC 2.0
Audit record
Per-tool scoring session frozen with methodology version, user, timestamp
02

Firm Readiness

The firm-level question. A compliant tool is necessary but not sufficient. The firm using the tool must have the governance, training, and policy infrastructure to use it safely. An Emerging firm using ChatGPT Enterprise is not the same risk profile as an Advanced firm using the same tool.

Module
C2 · Digital Maturity
Asks
Are WE ready as a firm to use these tools?
Output
Firm maturity band (Emerging / Developing / Established / Advanced / Leading) · D1-D7 maturity spider chart against peer-baseline medians · ISO 19650 adoption stage (D2b) · per-dimension gap narrative with suggested actions · D4.5 governance ceiling rule (cap at Developing if no named AI-output reviewer)
Standards
D1-D7 in-house dimension framework · ISO 42001 firm-level requirements · ISO 19650 information management stages · IBM AI governance principles
Audit record
Annual maturity assessment frozen with score, methodology version, leadership sign-off
03

Procurement Defensibility

The decision-level question. When a firm chooses one tool over another, that choice must itself be defensible. Not 'we picked it because we like it' but 'we picked it because it scored higher against this rubric for this project type.' Compliance includes the audit trail of how the tool was selected, not just whether the tool was scored.

Module
C3 · Software Comparison
Asks
WHICH tool wins for this project, and why?
Output
FitScore = ACS×0.50 + LayerAlignment×0.30 + MaturityMatch×0.20 · D1-D7 comparison radar (7 axes) · project-context weighting (DBB / DB / CMAR / P3 / IPD)
Standards
PMBOK procurement governance · ISO 19650 information management for BIM · firm-tier matching from C2
Audit record
Per-comparison decision frozen — tools compared, FitScore weights used, project context, chosen tool, timestamp, user, methodology version. Exportable as signed PDF for E&O carrier or state board.
04

Operational Compliance

The practice-level question. Daily use must produce a record. Which tools were used on which projects, by whom, when, and what was the kernel's verdict at sign-off. Compliance is not a one-time score — it is an ongoing record of safe practice that survives years of subsequent work.

Module
C4 · Project AI Gate
Asks
Are we doing this safely TODAY?
Output
Per-project sign-off receipts (with identity attestation) · Project AI Register PDF · AI Liability Audit Report · Shadow-AI reporting form (user-submitted; practitioners self-report unregistered tool use, flagged against the firm's Tool Register — no automated detection)
Standards
OSHA safety protocols · CMMC 2.0 federal cybersecurity · state board record-keeping requirements · 7-year retention
Audit record
Per-project, per-day immutable record. The defence document the firm hands to its E&O carrier or state board if the call comes.
03

The Fifth Dimension

Horizontal AI compliance products — IBM Consulting, Vanta, Drata — define compliance as policy + risk register + control documentation. That definition is correct for SaaS companies and financial services firms, where the buyer is a CISO or compliance officer and the liability is corporate.

For licensed AEC practice, compliance has a fifth dimension those products do not address: personal professional liability that follows an individual's stamp for the life of the work. A bridge stamped today can produce litigation in 2055. An architect who signs a building plan in 2026 can be deposed in 2046. The licensed individual's career and personal financial exposure follow the work product, not the corporate entity that paid for it.

This changes what “compliance” has to mean and what an audit trail has to survive. AECO Shield is shaped by that constraint; horizontal governance products are not. The methodology, the audit format, the retention policy, and the registry — all of these are designed for an audit window measured in decades, not quarters.

04

Compliance vs Governance

AI compliance and AI governance are not the same thing. They are related but distinct.

AI Governance

The system that produces compliance.

Policies, oversight structures, accountability frameworks, risk management. Strategic. Defines what good looks like. Examples: ISO 42001, NIST AI RMF, EU AI Act, IBM Consulting.

AI Compliance

The act of meeting those requirements.

Verifiable, on the ground, every day. Tactical. Proves you are doing it. AECO Shield operates here.

AECO Shield is not a governance product. Shield is the operational layer that makes governance true on a per-tool, per-firm, per-decision, per-day basis. Shield aligns with governance frameworks but does not compete with them.

05

The Integrated System

AI compliance is not a tool score. It is an ongoing practice across four dimensions.

  • C1Tool snapshot. Defensibility for that tool, that day.
  • +C2Tool was scored — and the firm is qualified to use it.
  • +C3Tool was scored, firm is qualified, AND the choice was rational.
  • +C4Everything above PLUS proof the firm actually used the tool the way the assessment said it would.
06

Glossary

ACS
AI Compliance Score. The 7-layer weighted rubric output from C1, range 0.0–10.0. Produced by 22 questions distributed across L1 Responsible Charge (22%), L2 AI Governance (20%), L3 Code Edition (16%), L4 BIM/ISO 19650 (14%), L5 Cybersecurity (12%), L6 Safety/OSHA (10%), L7 Transparency (6%).
DCS
Decision Confidence Score. Color-coded verdict derived from ACS — GREEN (≥88%), AMBER (68–87%), RED (<68%). Anchored to v3.4 multi-framework convergent reasoning (ISO/IEC 42001:2023 + NIST AI RMF 1.0 + FDA SaMD).
FitScore
Per-comparison procurement output from C3. FitScore = ACS×0.50 + LayerAlignment×0.30 + MaturityMatch×0.20. Used to rank up to 8 tools against a specific project context.
Q21b
Liability Transfer Test. The 22nd question in the C1 rubric (numbered 21b for historical reasons). Requires multi-AI verification (3-of-3 consensus) before a tool can be marked defensible. Designed to catch tools that score well on hygiene but fail on actual liability transfer.
HF1–HF5
Hard Filters. Five conditions that produce instant disqualification regardless of ACS score. HF1 · Licensure jurisdiction — tool must be licensed in the project’s state. HF2 · Licensure discipline — tool must cover the project’s required disciplines. HF3 · E&O insurance — tool’s E&O coverage must meet the project’s minimum for its risk sensitivity. HF4 · GL insurance — tool’s General Liability coverage must meet the project minimum. HF5 · DBE — on public projects with DBE requirements, the tool’s DBE subcontractor capacity must meet the threshold. Any critical fail blocks the FitScore for the affected project class before procurement.
Responsible Charge
The licensed professional whose name and seal appear on the work product. Under most state board rules, the responsible charge individual carries personal liability for the work, including AI-assisted work, for the life of the engagement and beyond.
Stamp-Safe
A three-state classification of a tool's stampability, derived from canonical scoring inputs (ACS + Q21b).Stamp-Supporting — ACS ≥ 8.8 AND Q21b tier ≥ 3. A Licensed Professional can place responsible charge on outputs.Conditional — AMBER ACS, or GREEN ACS with Q21b tier < 3. Usable with documented governance conditions.Not Stamp-Safe — RED ACS or Q21b Tier 1. Output cannot enter stamped deliverables without significant additional governance.Visible per tool in the public Registry. Derivation is numeric + evidence-grounded (src/lib/registry/stamp-safe.ts); the render surface additionally gates on DCS state per v3.4 §2.7.5.
E&O
Errors & Omissions insurance. Professional liability insurance carried by licensed AEC professionals to protect against claims of negligent advice or errors in their professional services. Sometimes called professional indemnity insurance.
Shadow AI
AI tool usage occurring within a firm without firm-level registration, scoring, or governance. The C4 module surfaces shadow AI via a user-submitted reporting form — practitioners self-report unregistered tool use, and reports flag tools not in the firm's registered Tool Register. No automated detection, no API-call or SaaS-auth event monitoring.
Methodology Version
Every Shield output is stamped with the methodology version that produced it (currently v3.4). When the methodology updates, prior scores remain valid in their original form. This is what makes the audit trail survive multi-year scrutiny.
07

Foundational Sources

  • ISO/IEC 42001:2023 — AI Management Systems
  • NIST AI Risk Management Framework (AI RMF 1.0)
  • FDA Software-as-a-Medical-Device (SaMD) framework
  • EU AI Act, Articles 8, 9, 10
  • CMMC 2.0 (federal AEC contracts)
  • ISO 19650 (BIM information management)
  • IBM AI governance principles
  • McKinsey AEC Digitisation Index (peer-baseline data source)
  • Autodesk State of Design & Make 2024 (peer-baseline data source)
  • KPMG Global Construction Survey (peer-baseline data source)
  • PMBOK procurement governance