Subcontractor and Vendor AI Flow-Down
A drywall sub submits a product data package on your $140M hospital tower, and it looks clean: the cut sheets are formatted, the spec references are present, the transmittal is professional. Six weeks later, during the AOR's fire-rating review, you learn that the fire-rated assembly the sub submitted does not exist. The sub's project engineer had used a public chatbot to assemble the submittal, the model fabricated a UL listing number that reads like a real one, nobody on the sub's side verified it, and your submittal coordinator passed it through because it looked complete. The assembly gets installed in twenty-two rated corridors before anyone catches it. Now it is your problem: your name is on the GC submittal log, your schedule absorbs the demolition and rework, and when you reach for your subcontract to push the cost back to the sub, you find the subcontract says nothing about AI, nothing about verification, nothing about disclosure. You have a quality failure with no contractual recourse, because your firm spent a year building AI governance for your own people and zero minutes making it flow down to the people who do seventy percent of the work. This lesson fixes that. By the end you will have drafted the AI flow-down clause for your standard subcontract and the disclosure rider for the architect of record and engineer of record, the two instruments that make your firm's AI standards binding on the subs and vendors whose AI use you do not otherwise control.
Your Governance Is Only as Strong as Your Weakest Sub
A general contractor's AI governance, the risk register, the committee charter, the verification gates, the disclosure language on transmittals, governs the GC's own people. It says what your project engineers may draft with AI, what your estimators must verify, what your superintendents disclose. But on a real project the GC's own staff produce a fraction of the work product that flows to the owner and the design team. The subcontractors author the shop drawings, the product submittals, the T and M tickets, the fabrication releases, the as-built redlines; the vendors author the cut sheets, the equipment schedules, the O and M data. And every one of those subs and vendors is, in 2026, under the same pressure your firm is to use AI, with far less governance behind it, because the typical mechanical or drywall sub does not have an AI committee or a verification policy. They have a project engineer with a deadline and a chatbot.
The controlling idea of this lesson is the flow-down principle, which every contracts owner already understands from insurance, indemnity, and safety: an obligation in your prime contract is worthless if it stops at your office door, so you flow it down to your subs through the subcontract, making each sub responsible to you for the same obligations you owe the owner. Your subcontract already flows down the prime's insurance requirements, the additional-insured endorsement, the indemnity, the safety program, the schedule, the lien-waiver chain. AI governance is no different. If your firm's standard requires verification before a submittal goes out, that standard is only real on your project if it flows down to the sub who authors the submittal. A governance program that governs your fifteen project engineers but not the four hundred subcontractor personnel on the job is a governance program with a hole in it the size of the project.
So the reframe for the contracts owner is this: your AI governance is only as strong as your weakest sub's AI practice, because the sub's AI-authored work product enters your project as your work product, carrying your name on the submittal log and your liability to the owner. The defense is not to police every sub's internal tooling, which you cannot do, but to flow down the standards through the one instrument you control: the subcontract. The flow-down clause is how your firm's AI governance reaches the people who do the work, and the disclosure rider is how the AOR and EOR learn what AI touched the design-assist contributions they have to stamp. Those two instruments are the deliverable.
The Four Things the Flow-Down Clause Must Cover
A useful AI flow-down clause is not a paragraph that says the sub will be careful. It is four specific obligations, each tied to a real failure mode you have seen, each enforceable because it is concrete. The four are disclosure, verification, data handling, and intellectual property, and they map one-to-one onto the four columns of your firm's own AI governance, which is the point: the clause flows your standards down, it does not invent new ones the sub cannot meet.
Disclosure requires the sub to tell you when AI materially assisted a deliverable that carries consequence, the submittals, the shop drawings, the priced change requests, the schedule fragments, the notices. It does not require disclosure of every spell-check; it requires disclosure proportioned to consequence, the same proportionality your own governance uses. Verification requires the sub to have verified AI-assisted work against the controlling documents before it reaches you, and to warrant that verification, so the fabricated UL listing becomes a breach of the sub's express warranty rather than a quality surprise you absorb. Data handling governs what the sub may put into AI tools: the clause must prohibit uploading owner-confidential plan sets, NDA-protected scopes, the BIM model, and federal-project DBE and MWBE lists into public or non-contracted AI services, flowing down the confidentiality and IP obligations your prime contract and AIA E203 and G202 impose on you. Intellectual property addresses who owns AI-generated work product and model geometry the sub contributes, and warrants that the sub's AI use does not infringe third-party rights or train a public model on the project's protected data.
The discipline in drafting is that each of the four obligations should reference an existing subcontract mechanism rather than create a freestanding one. Disclosure rides on the existing transmittal and submittal procedures. Verification rides on the sub's existing warranty of its work. Data handling rides on the existing confidentiality and the flow-down of the prime's IP terms. IP rides on the existing intellectual-property and work-product provisions. Anchoring the four obligations to provisions the subcontract already has makes the clause enforceable and makes it survive your counsel's review, because it extends instruments the sub already agreed to rather than bolting on a new regime the sub will negotiate out.
A general contractor's AI governance is only as strong as its weakest subcontractor's AI practice, because the sub's AI-authored work enters the project as the GC's work, carrying the GC's name to the owner and the GC's liability with it. The subcontract is the only instrument that makes the firm's AI standards bind the people who do the work, so the flow-down clause is not paperwork, it is the load path of the entire governance program.
Disclosure and Verification: The Warranty That Bites
Disclosure and verification are the two obligations that would have saved you on the fabricated-UL-listing submittal, and they work together. Disclosure alone is weak: a sub telling you "AI assisted this submittal" gives you information but no protection, because the burden of catching the fabrication shifts back to your coordinator. Verification alone is strong but unprovable without disclosure, because you cannot police verification you do not know happened. Paired, they create the mechanism that bites: the sub discloses that AI assisted the deliverable, and the sub warrants that it verified the AI-assisted content against the controlling specifications, drawings, and listings before submission. The warranty is what converts the quality failure into a breach.
This is the same logic as the verification gates the program has carried since L1: the cardinal rule that AI output is verified before it touches a stamp, a schedule, a pay app, or a safety plan. The flow-down clause pushes that rule down to the sub, requiring the sub to apply the same gate to its own AI-assisted work that your firm applies to yours. The sub's project engineer who pastes a submittal out of a chatbot without checking the UL listing has, under the clause, breached an express warranty, which gives you the contractual recourse the subcontract previously lacked: the rework cost, the schedule impact, and the demolition are the sub's, not a loss you eat because the subcontract was silent. The clause does not prevent the sub from using AI, which you could not enforce and should not want; it makes the sub accountable for verifying what the AI produced, exactly the accountability your own governance imposes on your own people.
The proportionality matters and should be written in. A blanket requirement that every AI-touched email be disclosed and verified is unworkable and the subs will ignore it, which is worse than no clause because it trains everyone to treat the clause as theater. The clause should scope disclosure and verification to the consequential deliverables, the submittals and shop drawings (quality consequence), the priced change requests and T and M tickets (dollars consequence), the schedule fragments and notices (contract-authority consequence), and the safety submittals (life-safety consequence), which are the same gates your firm's verification policy uses. Scoping to consequence is what makes the clause both enforceable and respected, because it asks the sub for exactly the verification the work warrants and no more.
Data Handling and IP: The Quiet Exposures
Data handling and IP are the obligations whose failures are quiet until they are catastrophic, which is why a contracts owner has to put them in writing rather than assume the sub knows. The data-handling failure is the sub's project engineer pasting the owner-confidential plan set, the NDA-protected program, or the federal-project DBE and MWBE list into a public chatbot to get a quick answer, which can breach your prime contract's confidentiality obligations, expose owner data to a model's training set, and, on a defense or healthcare or hyperscaler project, create a disclosure incident with consequences far beyond the trade scope. Your prime contract and the AIA E203 and G202 model-IP terms impose confidentiality on you; the flow-down clause is how that confidentiality reaches the sub's chatbot, by prohibiting the sub from inputting protected project data into AI services that are not contracted with appropriate data-handling terms, training opt-out, and the security posture your diligence requires.
The IP failure is subtler and lives in the design-assist and BIM space. When a sub or its design-assist engineer contributes AI-generated routing, geometry, or detailing to the federated model, the question of who owns that geometry, and whether the AI tool's terms claim any rights in it or used protected inputs to produce it, is governed by AIA E203 and G202, which the program covered in the responsible-AI lessons. The flow-down clause must require the sub to warrant that its AI-generated contributions do not infringe third-party IP, that the sub has the rights to convey the contributed geometry to you and onward to the owner per the model-IP terms, and that the sub's AI use did not train a public model on the project's protected data. Without that warranty, you are conveying AI-generated geometry up the chain to the owner with no assurance of clean title, which is an IP exposure the owner's counsel will eventually find.
Both obligations connect directly to the firm's risk register and governance from the prior lessons in this chapter. The data-handling and IP rows on your AI risk register, confidentiality breach, model-training exposure, IP infringement, are real risks on your own work and larger risks on sub work because you have less visibility. Flowing the obligations down through the subcontract is the register's mitigation extended to the subs, closing the gap between the risks your governance addresses for your people and the risks the subs create with no governance at all. The flow-down clause makes your risk register cover the whole project, not just your office.
The AOR/EOR Disclosure Rider for Design-Assist
The flow-down clause governs the subcontract, the GC-to-sub relationship. The disclosure rider governs a different relationship: the design-assist contributions that flow from a sub or its design-assist engineer to the architect of record and the engineer of record, the licensed professionals who have to stamp the design that incorporates those contributions. This is the design-assist Wednesday scenario the program opened with: a mechanical contractor brings AI-generated routing options through the federated model, and the engineer of record asks who stamps this and what the basis-of-design memo says, and nobody on the call has an answer. The disclosure rider is the answer prepared in advance.
The rider's purpose is narrow and important: the AOR and EOR cannot responsibly stamp what they cannot see, and an AI-generated design-assist contribution that arrives undisclosed deprives the stamping professional of the information they need to exercise responsible charge. The stamp is binary, as the program has said repeatedly: the seal means the licensed professional takes professional responsibility for the work, and they cannot take responsibility for AI-assisted content they did not know was AI-assisted. The rider requires the design-assist sub to disclose, in the basis-of-design or design-assist transmittal, where and how AI materially generated or assisted the contributed design, so the AOR and EOR can apply their independent professional judgment to that content before incorporating and stamping it. The disclosure does not delegate the stamp to the AI, which is never permissible; it informs the human who holds the stamp.
The rider also documents the contribution for the project record: the basis-of-design memo, the OPR-to-BoD handshake, and the commissioning record should reflect that an AI-generated design-assist contribution was made, disclosed, reviewed by the responsible professional, and adopted under that professional's responsible charge. That paper trail answers the EOR's three questions, who stamps this, what is the basis of design, how do we file it for commissioning, before fourteen days of float burn rather than after. The rider is short, rides on the existing design-assist and transmittal procedures, and gives the AOR and EOR exactly what responsible charge requires: visibility into the AI-assisted content so the human judgment the stamp represents is applied to it knowingly.
Tying Flow-Down to the Prime Contract and AIA A201
The flow-down clause is not freestanding; it ties to the prime contract obligations, which is what makes flow-down the correct legal mechanism rather than an invention. Under AIA A201-2017, the contractor is responsible to the owner for the acts and omissions of its subcontractors, and the contractor warrants the work, which means a sub's AI-fabricated submittal becomes the contractor's breach of warranty to the owner whether or not the subcontract addressed AI. Flow-down does not create the GC's exposure to the owner; that exposure already exists in A201. Flow-down creates the GC's recourse against the sub for the exposure the GC already carries, which is the entire reason subcontract flow-down exists for insurance, indemnity, and safety, and why it is the right instrument for AI.
The contracts owner should map the AI flow-down obligations to the prime-contract provisions they mirror, so the clause reads as an extension of obligations the sub already accepted. The disclosure and verification obligations extend the contractor's A201 responsibility for the work and the express warranty. The data-handling obligation extends the confidentiality and IP terms the prime contract and any owner amendment impose, along with the AIA E203 and G202 model-IP framework. The IP obligation extends the work-product and model-rights provisions. Anchoring each AI obligation to the prime-contract provision it flows down keeps the clause inside the structure the subcontract already uses, which is both why counsel will accept it and why an arbitrator will enforce it: it is a flow-down, not a novelty.
This is also why the lesson frames the deliverable as clauses to take to counsel, not legal advice. The contracts owner authors the substance, the four obligations, the proportionality, the tie to A201 and E203 and G202, the disclosure rider's purpose, because the contracts owner knows the failure modes and the governance the clause must flow down. Counsel converts that substance into enforceable contract language that fits the firm's standard subcontract form and the governing law. The contracts owner who arrives with the four obligations specified, the proportionality scoped to the verification gates, and the prime-contract tie mapped gets a far better clause than the one who asks counsel to "add something about AI," because the substance is the part only the builder knows, and that is the part this lesson produces.
The Applied Problem: Draft the Flow-Down Clause and the Disclosure Rider
Here is the exercise. Draft two instruments your counsel can convert into enforceable language. First, the AI flow-down clause for your standard subcontract: write the four obligations, disclosure, verification, data handling, and IP, with each obligation scoped to the consequential deliverables (submittals and shop drawings, priced change requests and T and M, schedule fragments and notices, safety submittals) and anchored to the existing subcontract mechanism it extends (transmittal procedures, the sub's warranty, the confidentiality and IP flow-down, the work-product provisions). Make the verification obligation a warranty so a fabricated listing becomes a breach, make the data-handling obligation prohibit protected project data in non-contracted AI services, and make the IP obligation warrant clean title and non-infringement in AI-generated contributions.
Second, the AOR/EOR disclosure rider for design-assist AI contributions: write the short instrument that requires a design-assist sub to disclose, in the basis-of-design or design-assist transmittal, where and how AI materially generated or assisted the contributed design, so the architect of record and engineer of record can apply independent professional judgment before incorporating and stamping it, and so the basis-of-design memo and commissioning record document that the AI-assisted contribution was disclosed, reviewed under responsible charge, and adopted. State plainly that the disclosure informs the stamping professional and does not delegate the stamp.
Then write the one-page cover memo to counsel that maps each obligation to the prime-contract provision it flows down (the contractor's A201 responsibility for the work and warranty, the confidentiality and IP terms, the AIA E203 and G202 model-IP framework), states the proportionality logic, and frames the request: convert this substance into enforceable subcontract language and a rider for our standard form. The deliverable is the flow-down clause, the disclosure rider, and the counsel memo, and the lasting product is a subcontract that makes your firm's AI governance reach the people who do the work, the only way that governance covers the whole project rather than just your office. This is informational, not legal advice; the clauses are drafted to take to your counsel, who makes them enforceable in your jurisdiction and your standard form.
Key Takeaways
- A general contractor's AI governance is only as strong as its weakest subcontractor's AI practice, because the sub's AI-authored work product (submittals, shop drawings, T and M, fabrication releases) enters the project as the GC's work, carrying the GC's name on the log and the GC's liability to the owner.
- The defense is the flow-down principle the contracts owner already uses for insurance, indemnity, and safety: an obligation that stops at your office door is worthless, so you flow your AI standards down to the subs through the one instrument you control, the subcontract.
- The flow-down clause covers four obligations that mirror the firm's own AI governance columns: disclosure (tell us when AI materially assisted a consequential deliverable), verification (warrant you verified AI-assisted work before submission), data handling (no protected project data in non-contracted AI services), and intellectual property (warrant clean title and non-infringement in AI-generated contributions).
- Disclosure and verification work together and bite as a warranty: the sub discloses AI assistance and warrants it verified the content, so a fabricated UL listing becomes a breach of express warranty (the GC's recourse) rather than a quality surprise the GC eats, applying the cardinal verification rule down to the sub.
- Scope the obligations to consequence using the same verification gates: submittals and shop drawings (quality), priced change requests and T and M (dollars), schedule fragments and notices (contract authority), and safety submittals (life-safety), because a blanket "disclose everything" clause is unworkable and trains everyone to ignore it.
- The AOR/EOR disclosure rider serves a different relationship: it requires a design-assist sub to disclose where and how AI generated or assisted contributed design, so the architect of record and engineer of record can apply independent professional judgment before stamping, because the stamp is binary and the professional cannot take responsibility for AI-assisted content they did not know was AI-assisted; the disclosure informs the stamp, it never delegates it.
- Flow-down is the correct mechanism because it ties to AIA A201: the contractor is already responsible to the owner for its subs' acts and warrants the work, so flow-down does not create the GC's exposure (A201 already does), it creates the GC's recourse against the sub, anchored to the confidentiality and IP terms and the AIA E203 and G202 model-IP framework.
- The deliverable is the flow-down clause, the disclosure rider, and a counsel memo that maps each obligation to the prime-contract provision it extends; this is informational, not legal advice, so the contracts owner authors the substance (the part only the builder knows) and counsel converts it into enforceable language for the firm's standard form and jurisdiction.
Skill.re