← Blog

AI Vendor Risk in Construction Starts Before the Safety Report

Parminder Singh
Parminder Singh··4 min read
Summarize with AI

OSHA record rules protect identifiable injury information and can require employee medical records to be preserved for the duration of employment plus thirty years. Construction teams need AI vendor controls before a superintendent, safety manager, or claims workflow sends the unredacted source narrative to a model.

Industry Verticalsai-securityai-governanceai-complianceauditpolicy-enforcementidentity-and-authorization
AI Vendor Risk in Construction Starts Before the Safety Report

A site safety manager sends an incident narrative to a model to draft the OSHA forms. The prompt includes the injured worker's name and foreman, plus treatment details that identify the body part and project address. The final OSHA 300 Log may hide the name, but the vendor has already received the unredacted source. AI vendor risk construction starts at that HTTPS request, before the compliant form exists.

I want to work through the two OSHA record rules that make this vendor path concrete, then define the controls and evidence a construction company needs around the model call.

TL;DR

  • 29 CFR 1904.29 requires privacy concern cases to omit the employee's name from the OSHA 300 Log and may require a less identifying description.
  • 29 CFR 1910.1020 can require employee medical records to be preserved for employment plus thirty years, regardless of how they are made or maintained.
  • AI vendor approval should specify the endpoint, model version, identity, and project controls. It should also specify the approved region and retention setting.
  • Request-level evidence proves that the approved conditions governed the transmission.

OSHA privacy begins with the source narrative

29 CFR 1904.29 says an employer may not enter the employee's name on the OSHA 300 Log for a privacy concern case. The employer instead enters "privacy case" and keeps a separate confidential list of case numbers and employee names.

The rule also anticipates identification through the narrative. When the remaining information could identify the employee, the employer may use a general description that preserves the cause and severity while omitting intimate or private detail. The listed privacy concern cases include injuries to an intimate body part, sexual assault, mental illness, HIV infection, hepatitis, tuberculosis, contaminated needlesticks, and certain voluntarily requested omissions.

A model prompt can contain the fuller source record before staff apply those form controls. Vendor review therefore needs to cover source narratives and attachments. It also needs to cover images converted to text and retrieved project files. AI data protection for construction covers the recordkeeping duties in more depth.

The retention horizon changes the assessment

29 CFR 1910.1020 applies to construction employers that make, maintain, contract for, or have access to qualifying employee exposure or medical records. It states that preservation and access requirements apply regardless of how the records are made or maintained, including records handled under contract.

The rule generally requires an employee medical record to be preserved for at least the duration of employment plus thirty years, subject to stated exceptions. Employee exposure records generally carry a thirty-year period. The construction company needs clear terms for retention, deletion, export, and backups. The same terms need to cover subprocessors, incident notice, account closure, and evidence access.

A provider's short prompt-retention setting can reduce one risk. Records counsel and safety leadership set the construction company's record schedule. The gateway needs to enforce their technical conditions for every project user.

Approval narrows to an identity and model route

A single construction vendor status is too broad for every permitted use. Public specification text presents a different risk from a medical restriction or a workers' compensation narrative. Badge rosters and bid pricing require separate treatment, as do access-control plans.

The supplier record should name the provider and account type. It should identify the endpoint and region, model family and approved versions, retention configuration and administrative access, plus subprocessors and change-notice terms. The request contributes the authenticated user or agent, role, company, and project. It also contributes the application and purpose, along with the classification. Policy evaluates the combination while the HTTP request remains under company control.

Picture a superintendent's trailer with a yellow hard hat beside a laptop and a handwritten incident sheet under the keyboard. Copying that sheet into a browser chat removes the project permissions that controlled the original file. Request classification has to inspect the content itself. PII redaction in LLM traffic describes one possible treatment when the approved workflow allows it.

My opinion is that a vendor questionnaire marked green for "data protection" carries little weight until the organization can name the exact endpoint and data classes it permits.

Live evidence tests the supplier conditions

The useful record includes the authenticated person or agent, employer and project context, application, and request classification. It also records the provider and endpoint, model version and region, decision and reason, plus the timestamp. It also binds the current policy and supplier assessment to the event. A protected correlation value links the response and the originating application event. Plaintext retention can then follow the construction company's approved schedule rather than becoming a default side effect of logging.

Model and route changes should trigger review. A stable product name can point to a newer model. An application update can add retrieval from a broader project folder. A provider can add a subprocessor or change regional availability. The control point should bind an approved version or record the resolved version for investigation. AI vendor risk management provides the broader assessment structure, while AI inline enforcement explains the timing of the request decision.

DeepInspect

DeepInspect sits between authenticated users or agents and LLM endpoints as a stateless proxy. It receives identity and project context, classifies the request, evaluates the provider and region against the model version, then permits, redacts, reroutes, or refuses the HTTP call before the vendor receives the content.

Every decision creates a signed record with the caller, application, employer and project context, and data classification. The record also identifies the provider and endpoint, model version and outcome, plus the reason and timestamp. The record also binds the current policy and assessment. DeepInspect governs authenticated HTTP AI traffic. Workplace safety decisions and OSHA scope remain with the construction company. Supplier contracts and records retention also remain with the company, as do subcontractor governance and non-HTTP systems.

Book a demo today.

Frequently asked questions

Does every construction incident prompt fall under 29 CFR 1910.1020?

The section has defined scope for employee exposure records and medical records, along with analyses and stated exceptions. Safety and legal teams should classify each workflow against the rule. Request records provide evidence about what was transmitted without deciding the legal scope.

Can redaction make an external model acceptable?

Redaction can reduce disclosure when an approved procedure removes direct and contextual identifiers before transmission. The remaining content and model purpose still require review. The review must also cover retention and region under the contract. A blocked request remains appropriate when safe transformation is unavailable.

Is a subcontractor's AI use covered by the general contractor's policy?

Contract terms and project governance decide the organizational requirement. Technical enforcement reaches only identities, plus applications and agents routed through the managed HTTP boundary. A subcontractor's independent account or bypass path requires separate control and evidence.

Should the audit record store the full incident narrative?

A decision record can store identity, project context, classification, and destination. It can also store the policy and outcome, plus an integrity reference, without duplicating the full narrative. The construction company's records owner should decide when plaintext retention is required and where the authoritative record belongs.