Shadow AI in CRE: 4 Governance Options Compared

By Jude Lee · · Comparison

Commercial real estate brokers reviewing a rent roll and laptop in a glass conference room

What shadow AI looks like inside a brokerage

The term showed up in a Bisnow Studio B branded piece this month on eliminating shadow AI and getting value from AI tools (Bisnow) — note that’s sponsored content, not independent reporting, so treat it as a signal that the conversation is happening, not as evidence of how widespread the problem is. I have no data on prevalence, and neither does anyone quoting a scary percentage at you.

What I can describe is the shape of it, because it’s the same in every professional services firm:

None of these people are being reckless. They’re being productive with the only tools available to them. That’s the whole diagnosis.

Shadow AI is not a discipline problem. It’s a procurement problem wearing a discipline costume.

Why a written ban is the option that fails quietly

A policy that says “do not use AI tools with firm data” produces two outcomes: the cautious people stop using AI and lose the productivity, and everyone else keeps going on a personal device where you have zero visibility. You end up with the risk you had plus a compliance document that says the risk doesn’t exist — which is worse than knowing.

The practical alternative is to make the sanctioned path faster than the unsanctioned one. People route around friction, not around rules.

Four ways brokerages actually handle this

1. Policy only

A one-page acceptable-use policy, an approved-tools list, and a short training session. Cheap, fast, and the right first move — but on its own it’s a statement of intent, not a control. It works when your firm is small enough that everyone actually reads it, and when the sensitive-document volume is low.

2. Sanctioned enterprise or team assistant seats

Buy team/enterprise plans for a general assistant (Claude, ChatGPT, or Microsoft 365 Copilot) and give everyone one. Admin consoles, SSO, and business-tier data-handling terms move the activity onto managed accounts. Don’t assume anything about training use or retention: read the vendor’s current business-tier terms in their own official documentation before you roll out, because those terms change and they differ between vendors and between consumer and business plans. Our ChatGPT vs Claude vs Copilot comparison for CRE brokers walks the trade-offs.

Strength: covers the long tail of ad-hoc work — email drafting, summarizing a market report, cleaning up a tour recap. Weakness: it doesn’t know your CRM, your deal files, or your comps. People still copy-paste, they just do it into a managed window.

3. Off-the-shelf CRE AI features

The AI capabilities inside the platforms you already pay for. In practice these fall into three familiar categories: CRM-side summarization and activity capture, document and lease abstraction AI, and marketing generation for flyers, OM copy, and listing descriptions. Data stays inside a vendor you’ve already vetted and contracted with, which is a real governance win — but only if you know where it actually goes, so ask the vendor directly which model providers and subprocessors handle your documents, and get it in writing. Limitation: each tool only sees its own slice, and you inherit the vendor’s roadmap. If your firm’s actual bottleneck sits between two systems, no single vendor feature closes it.

4. A custom agent connected through MCP

MCP — the Model Context Protocol — is an open standard for giving an AI assistant governed access to specific data and tools. Instead of a human pasting a rent roll into a chat box, you stand up a server that exposes narrow, named capabilities (get_listing, search_comps, draft_followup) and the assistant calls those. You decide what’s readable, what’s writable, and what requires a human approval step, and you get a log of every call. We cover the build pattern in connecting Claude to your CRE systems via a custom MCP server.

This is the strongest control of the four and the most work. It’s justified when the same sensitive workflow repeats weekly and the data can’t leave your boundary casually.

Sanctioned assistant seats
Fast to deploy, per-seat pricing, covers unpredictable ad-hoc work. Governance is account-level: you know who used it, not exactly what data moved. Best first layer for nearly every brokerage.
Custom MCP agent
Weeks of build plus ongoing maintenance. Governance is action-level: scoped permissions, audit trail, approval gates. Worth it for repeatable, high-volume, sensitive workflows — abstraction, pipeline updates, portfolio Q&A.

There is no single best tool — run two layers

People search for the best AI tool for commercial real estate expecting a name, and any list that hands them one is selling something. The honest framing is two layers: a sanctioned general assistant for everyone (so shadow AI has somewhere to go), plus one or two deep tools for the workflows that consume the most hours in your specific shop. A capital markets team and a tenant rep team will pick different deep tools from the same starting point. Score candidates against your own criteria rather than a roundup — the 10-point vetting scorecard is a reasonable starting template.

Two rules of thumb worth putting in context

People searching this topic often land on two phrases, so here’s a plain read on both.

The 2% rule is a residential investing heuristic — monthly rent should equal roughly 2% of purchase price — that gets imported into CRE conversations. In most commercial contexts it’s close to useless: pricing is driven by cap rate, NOI, debt service coverage, and lease credit, not a rent-to-price ratio. It’s also a clean illustration of the shadow-AI risk: a consumer chatbot with no scoping will repeat this confidently to a junior analyst who asks it to sanity-check a price, which is exactly the kind of unsupervised opinion a sanctioned, scoped setup is supposed to fence off.

The 30% rule in AI is not a defined standard from any governing body, despite how confidently it gets quoted. Different people use it to mean different things — a share of tasks AI can plausibly handle, a share of a model’s output you should expect to rewrite. There is no authoritative source behind it that I can point you to, so don’t plan around it. If you want a real governance framework, the NIST AI Risk Management Framework (AI RMF 1.0) is a published, freely available reference with a Govern/Map/Measure/Manage structure that maps cleanly onto a brokerage’s tool-approval process.

A 30-day plan to bring it into the light

  1. Run an amnesty survey, not an audit

    Ask what people are using and what problem it solved, explicitly with no consequences. You will learn where your real workflow pain is. Audits produce silence; amnesty produces a roadmap.
  2. Classify your document types

    Sort into three buckets: public marketing material, internal work product, and third-party confidential (NDA-bound seller data, tenant financials, PII). The rules differ per bucket; a blanket rule guarantees over- or under-restriction.
  3. Buy the sanctioned layer this month

    Managed seats for everyone who touches deal work, with SSO. Speed matters more than picking perfectly — you can switch vendors later, but you can’t recover data already pasted into a personal account.
  4. Write one page, then train on it

    Approved tools, the three data buckets, what always needs a human review, and who to ask. Short enough that people read it. Pair it with a working session, not a PDF email.
  5. Pick one workflow to bring in-house properly

    The one with the highest repetition and the most sensitive inputs — usually lease abstraction or pipeline hygiene. Evaluate it against the readiness questions in the agent deployment checklist before you build anything.

Modeling whether the sanctioned layer pays for itself

Don’t take a vendor’s ROI headline. Build your own with numbers you can defend:

hrs/wk × loaded rate × 52
Annual value of recovered time (per person)
Worked example — use your own inputs
seats × monthly price × 12
Annual sanctioned-tool cost
Worked example — use vendor list pricing
build + maintenance
Custom agent cost to compare against
Worked example — quote it before committing

The piece most firms omit is the third term: what the recovered hours get reallocated to. An hour returned to an analyst who then does nothing revenue-generating with it is a cost saving on paper only. If you want a more structured version of this math, see the broker-ops payback walkthrough.

What stays human regardless of which option you pick

Anything with a signature, a fiduciary duty, or a number that goes in front of a client. An agent can abstract a lease, draft the follow-up, and update the CRM record — but the failures are quiet, not loud. A lease abstraction can return a clean, well-formatted rent schedule and silently omit a co-tenancy clause that never made it into the output template, and nothing in the result looks wrong. A meeting notetaker can attribute a concession to the wrong party on a recorded call — logging the buyer as having offered a TI allowance the seller’s broker floated — and that summary lands in the deal file as fact.

So a licensed professional still reads the abstraction against the source document before it feeds an offering memorandum, and still owns the advice. That division doesn’t change based on how good the model gets — it changes based on who carries the liability, which is you.

Not sure where to start?

Get a free automation audit: we map your deal pipeline, marketing, and back-office workflows and show you what's worth automating — before you spend a dollar.

Get a free automation audit