Shadow AI in CRE: 4 Governance Options Compared
What shadow AI looks like inside a brokerage
The term showed up in a Bisnow Studio B branded piece this month on eliminating shadow AI and getting value from AI tools (Bisnow) — note that’s sponsored content, not independent reporting, so treat it as a signal that the conversation is happening, not as evidence of how widespread the problem is. I have no data on prevalence, and neither does anyone quoting a scary percentage at you.
What I can describe is the shape of it, because it’s the same in every professional services firm:
- An analyst drops a 40-page lease PDF into a free consumer chatbot to pull the rent steps, because the alternative is two hours of manual abstraction.
- A broker runs a free meeting bot on a listing pitch that’s covered by a confidentiality agreement.
- Marketing uses a personal image tool on site photos the firm licensed but didn’t clear for derivative use.
- Someone builds a genuinely useful custom GPT on their own account, then leaves the firm and takes it with them.
None of these people are being reckless. They’re being productive with the only tools available to them. That’s the whole diagnosis.
Shadow AI is not a discipline problem. It’s a procurement problem wearing a discipline costume.
Why a written ban is the option that fails quietly
A policy that says “do not use AI tools with firm data” produces two outcomes: the cautious people stop using AI and lose the productivity, and everyone else keeps going on a personal device where you have zero visibility. You end up with the risk you had plus a compliance document that says the risk doesn’t exist — which is worse than knowing.
The practical alternative is to make the sanctioned path faster than the unsanctioned one. People route around friction, not around rules.
Four ways brokerages actually handle this
1. Policy only
A one-page acceptable-use policy, an approved-tools list, and a short training session. Cheap, fast, and the right first move — but on its own it’s a statement of intent, not a control. It works when your firm is small enough that everyone actually reads it, and when the sensitive-document volume is low.
2. Sanctioned enterprise or team assistant seats
Buy team/enterprise plans for a general assistant (Claude, ChatGPT, or Microsoft 365 Copilot) and give everyone one. Admin consoles, SSO, and business-tier data-handling terms move the activity onto managed accounts. Don’t assume anything about training use or retention: read the vendor’s current business-tier terms in their own official documentation before you roll out, because those terms change and they differ between vendors and between consumer and business plans. Our ChatGPT vs Claude vs Copilot comparison for CRE brokers walks the trade-offs.
Strength: covers the long tail of ad-hoc work — email drafting, summarizing a market report, cleaning up a tour recap. Weakness: it doesn’t know your CRM, your deal files, or your comps. People still copy-paste, they just do it into a managed window.
3. Off-the-shelf CRE AI features
The AI capabilities inside the platforms you already pay for. In practice these fall into three familiar categories: CRM-side summarization and activity capture, document and lease abstraction AI, and marketing generation for flyers, OM copy, and listing descriptions. Data stays inside a vendor you’ve already vetted and contracted with, which is a real governance win — but only if you know where it actually goes, so ask the vendor directly which model providers and subprocessors handle your documents, and get it in writing. Limitation: each tool only sees its own slice, and you inherit the vendor’s roadmap. If your firm’s actual bottleneck sits between two systems, no single vendor feature closes it.
4. A custom agent connected through MCP
MCP — the Model Context Protocol — is an open standard for giving an AI assistant governed access to specific data and tools. Instead of a human pasting a rent roll into a chat box, you stand up a server that exposes narrow, named capabilities (get_listing, search_comps, draft_followup) and the assistant calls those. You decide what’s readable, what’s writable, and what requires a human approval step, and you get a log of every call. We cover the build pattern in connecting Claude to your CRE systems via a custom MCP server.
This is the strongest control of the four and the most work. It’s justified when the same sensitive workflow repeats weekly and the data can’t leave your boundary casually.
There is no single best tool — run two layers
People search for the best AI tool for commercial real estate expecting a name, and any list that hands them one is selling something. The honest framing is two layers: a sanctioned general assistant for everyone (so shadow AI has somewhere to go), plus one or two deep tools for the workflows that consume the most hours in your specific shop. A capital markets team and a tenant rep team will pick different deep tools from the same starting point. Score candidates against your own criteria rather than a roundup — the 10-point vetting scorecard is a reasonable starting template.
Two rules of thumb worth putting in context
People searching this topic often land on two phrases, so here’s a plain read on both.
The 2% rule is a residential investing heuristic — monthly rent should equal roughly 2% of purchase price — that gets imported into CRE conversations. In most commercial contexts it’s close to useless: pricing is driven by cap rate, NOI, debt service coverage, and lease credit, not a rent-to-price ratio. It’s also a clean illustration of the shadow-AI risk: a consumer chatbot with no scoping will repeat this confidently to a junior analyst who asks it to sanity-check a price, which is exactly the kind of unsupervised opinion a sanctioned, scoped setup is supposed to fence off.
The 30% rule in AI is not a defined standard from any governing body, despite how confidently it gets quoted. Different people use it to mean different things — a share of tasks AI can plausibly handle, a share of a model’s output you should expect to rewrite. There is no authoritative source behind it that I can point you to, so don’t plan around it. If you want a real governance framework, the NIST AI Risk Management Framework (AI RMF 1.0) is a published, freely available reference with a Govern/Map/Measure/Manage structure that maps cleanly onto a brokerage’s tool-approval process.
A 30-day plan to bring it into the light
-
Run an amnesty survey, not an audit
Ask what people are using and what problem it solved, explicitly with no consequences. You will learn where your real workflow pain is. Audits produce silence; amnesty produces a roadmap. -
Classify your document types
Sort into three buckets: public marketing material, internal work product, and third-party confidential (NDA-bound seller data, tenant financials, PII). The rules differ per bucket; a blanket rule guarantees over- or under-restriction. -
Buy the sanctioned layer this month
Managed seats for everyone who touches deal work, with SSO. Speed matters more than picking perfectly — you can switch vendors later, but you can’t recover data already pasted into a personal account. -
Write one page, then train on it
Approved tools, the three data buckets, what always needs a human review, and who to ask. Short enough that people read it. Pair it with a working session, not a PDF email. -
Pick one workflow to bring in-house properly
The one with the highest repetition and the most sensitive inputs — usually lease abstraction or pipeline hygiene. Evaluate it against the readiness questions in the agent deployment checklist before you build anything.
Modeling whether the sanctioned layer pays for itself
Don’t take a vendor’s ROI headline. Build your own with numbers you can defend:
The piece most firms omit is the third term: what the recovered hours get reallocated to. An hour returned to an analyst who then does nothing revenue-generating with it is a cost saving on paper only. If you want a more structured version of this math, see the broker-ops payback walkthrough.
What stays human regardless of which option you pick
Anything with a signature, a fiduciary duty, or a number that goes in front of a client. An agent can abstract a lease, draft the follow-up, and update the CRM record — but the failures are quiet, not loud. A lease abstraction can return a clean, well-formatted rent schedule and silently omit a co-tenancy clause that never made it into the output template, and nothing in the result looks wrong. A meeting notetaker can attribute a concession to the wrong party on a recorded call — logging the buyer as having offered a TI allowance the seller’s broker floated — and that summary lands in the deal file as fact.
So a licensed professional still reads the abstraction against the source document before it feeds an offering memorandum, and still owns the advice. That division doesn’t change based on how good the model gets — it changes based on who carries the liability, which is you.
Not sure where to start?
Get a free automation audit: we map your deal pipeline, marketing, and back-office workflows and show you what's worth automating — before you spend a dollar.
Get a free automation audit