,

My Thoughts on AI – Part 3 – Taking Your AI Policy from the Boardroom to the Boiler Room

As we continue this series on how facilities leaders can think about and leverage AI, I want to turn to AI policy, the thing that governs how your teams actually use these tools. 

For those of you who know me, you know policies generally make my head hurt. I recognize their importance, but creating and managing them is not my favorite thing, to say the least. This one is different. This is a policy I am very close to. 

Last week I argued that you should build the sandbox first and hand out the shovels second. So why am I now telling you to write a policy? 

Because they do different jobs. The sandbox is for the things you can’t afford to leave to human judgment and it makes the catastrophic mistake impossible rather than merely forbidden. The policy is for everything configuration can’t decide for you. Is this the kind of problem we use AI on at all? Does anyone need to know we did? Who checks the output before it goes to the Board or to the public? No sandbox is going to provide those answers. People do, and they need to know what good judgment looks like around here. 

As I said last week, our original policy was essentially “don’t.” Once we opened up, we needed to be very clear with staff about what was allowed and what wasn’t. 

I’ve generally been an ask-for-forgiveness kind of guy in my career. On AI, I’ve shifted and, it isn’t because I’m getting older. It’s because the blast radius changed. With most tools, a bad call is your problem and you can generally clean it up. With AI, you can put private or confidential information somewhere it should never have gone, or let something unreviewed find its way into a public document. That isn’t only your reputation on the line anymore. It’s your organization’s good name. 

So if you run a facilities team inside a larger organization, start by finding out what your broader corporate AI policy says. If there isn’t one, there’s an opportunity for you and your team to help build it. Every organization should agree on a set of ground rules so nobody gets out over their skis and ends up in trouble when the organization catches up. 

But here’s the part I really want you to hear. Even if your organization has a broad AI policy, your facilities team still needs its own. 

If you’re at a university, chances are the institutional policy is aimed at how professors use AI for lesson planning and marking, or what students can and can’t do on assignments. If you’re with a municipality, it’s probably written around public communications and privacy. Fair enough, those are real risks and somebody had to address them. 

But nobody in that working group was thinking about condition assessment data, work order histories, building management systems, vendor submittals, or what happens when a technician in a mechanical room points their phone at a control panel and asks an AI what’s wrong with it. 

That last one matters more than it might sound. Most AI policies are quietly written for people sitting at desks. You run trades, custodial, grounds and operations staff whose work happens in boiler rooms and on rooftops, often on a phone, often under time pressure. A policy that only contemplates an analyst at a keyboard will miss most of your department on day one. 

Facilities is a specialized niche, and chances are the higher-ups don’t understand your part of the business well enough to set sensible boundaries around it. Anything you write has to align with the corporate policy; don’t contravene it. But make it your own, fit it to your data and your processes, and put it in facility speak. 


Next week I’ll get specific about what actually goes in it. There are a handful of questions your policy needs to answer, and at least three of them are ones I’d bet nobody in your organization has asked yet. 

   

Published on

8 October 2026

Under

,

Further Insights

At Roth IAMS, we take great pleasure in sharing our stories and knowledge