ACEC Research Institute Report: Real Risk of AI Isn’t Technology. It’s the Org Chart. 

Jeff Urbanchuk

|

August 19, 2026

The ACEC Research Institute today released Leading Through AI Risk: The Enterprise Framework for Engineering Firm Leaders, a new study finding that the most significant risks artificial intelligence poses to engineering firms are organizational rather than technological, and that firms treating AI as an IT initiative are managing the wrong issue.  

The report, part of the Institute’s yearslong Firm of the Future initiative, combines an extensive literature review with in-depth interviews of 21 leaders drawn from engineering firms, public infrastructure owners, technology vendors, insurance and legal professionals, licensing and regulatory agencies, and AI consultants.  

The report groups AI risk into eight interconnected domains:  

  • technical reliability and model risk 
  • professional liability and standard of care risk  
  • data governance, privacy, and intellectual property risk  
  • organizational and workforce risk 
  • ethical, regulatory, and reputational risk 
  • operational and cybersecurity risk 
  • financial and business model risk 
  • strategic leadership and enterprise governance risk  

The last serves as the integrating domain through which firms coordinate responsible AI adoption enterprise wide. 

The report stresses that firms do not experience these risks one at a time. Weak oversight may create legal liability. Workforce gaps may affect quality assurance. “Understanding these interactions,” the study notes, “is often more important than understanding individual risks independently.” 

“The most important takeaway from this report is that AI readiness is ultimately a leadership issue,” said Daphne Bryant, executive director of the ACEC Research Institute. “The technology will continue to evolve, but the fundamentals of responsible engineering stay the same. Firms that succeed will be those that pair innovation with strong governance, preserve engineering judgment, and make conscious choices about how AI supports their people and their responsibility to clients and the public.” 

Governance Must Keep Pace with Technology
AI is not simply a new version of engineering software. It shapes technical analysis, project delivery, client service, hiring and mentoring, pricing, and strategy. Firms keep asking what tools to buy, but the more consequential question is whether the organization can govern them.  

There was broad consensus among participants with the notion that AI would not eliminate the need for engineers. A substantial number raised a more nuanced issue: the work that has traditionally built technical judgement – running calculations, checking drawings, researching standards, preparing documentation – is precisely the work AI is best positioned to absorb. Participants asked how the next generation acquires judgment it no longer earns by doing, and pressed firms to be intentional about redesigning professional development and mentoring. 

What Firms Must Govern is Changing
Information management has long been an operational function composed of storing, securing, and retrieving files. AI ends that model. AI systems draw on whatever information they can reach, which means the quality of an AI-assisted deliverable is contingent on the quality of knowledge behind it.  

But knowledge and data are not the same thing. Project files are data. But the finer lines of a project such as why a design alternative was rejected or which assumptions proved fragile in the field is knowledge, and much of it has not been written down. Participants named the capture of institutional expertise, before retirement and turnover take it, as a pressing organizational priority. AI can transform access to documented knowledge, but it can’t retrieve expertise that was never captured.  

Misdiagnosing the Nature of Risk
The report’s broader contention is that the engineering industry has been examining the wrong exposures. Public discussion has centered on hallucinations, cybersecurity, and model accuracy. Interview participants acknowledged all three and, with few exceptions, declined to identify any of them as the industry’s top vulnerability. 

From the report: “Reliable AI depends upon reliable organizations. AI reliability is not determined solely by the technology itself. It depends on trusted data, disciplined governance, robust quality assurance, and sound engineering judgment.” 

Legal and insurance participants applied the same logic to liability. AI itself does not create legal exposure. Exposure arises, the report states, “when organizations fail to exercise reasonable professional care.” An inaccurate output becomes a legal problem at the point it influences an engineering decision without adequate review. Public infrastructure owners registered comparatively little concern about whether firms use AI at all. They expect consistent quality, transparency, and accountability irrespective of the technologies behind project delivery. 

Separate Vantage Points, But Common Ground
The degree of consensus across stakeholder groups is among the more significant results of the study. Participants approached the topic from very different positions and arrived at substantially similar conclusions about the organizational challenges involved and how engineering firms should respond. That convergence, the report argues, indicates that “responsible adoption depends less on individual technologies than on the organizational capabilities required to govern them effectively.” 

AI does not reduce the engineering industry’s responsibility. “Instead,” the report states, “it raises the standard for governance, engineering judgment, and organizational leadership.”  

But participants also identified the inverse exposure, with several arguing that the greater long-term risk is not adopting AI too quickly but, rather, failing to adapt as clients, competitors, technology providers, and infrastructure owners move toward AI-enabled ways of working. 

The report closes on the distinction it says should govern firm leadership. “Artificial intelligence will undoubtedly reshape how engineering firms work. It should never redefine why they exist.” 

“What stands out in the data is the consistency of the message across very different parts of the industry,” said Joe Bates, senior research consultant to the ACEC Research Institute. “Firm leaders, infrastructure owners, technology providers, insurers, attorneys, regulators, and AI experts came to this issue from different vantage points but repeatedly pointed us toward the same conclusion: the greatest AI risks are interconnected organizational risks. That convergence gives engineering leaders a much clearer picture of where they need to focus.” 

The full report can be found here