Most real estate companies recognize that artificial intelligence (AI) is revolutionizing our industry, and many are eager to adopt the latest and greatest technologies. But if AI use isn’t managed effectively, it can be dangerous. Risks include inaccuracies, compromised cybersecurity and fraud. And although other market sectors face the same risks, real estate is among the most vulnerable, given its widespread dependence upon multimillion-dollar transactions and large quantities of confidential data.
Consider what sits inside a typical firm’s systems: wire instructions for closings, tenant and applicant files full of personal and financial data, and lease and loan documents that carry real legal weight. A single manipulated payment instruction or one exposed applicant file can cost a firm more than a year of technology budget.
For these reasons, it’s critical that real estate companies establish AI governance boards. But who should be involved, and what exactly should a board do? Below are some answers to these questions.
The Who
It’s clear that AI governance boards should contain representatives from IT, innovation and information security. But other departments, such as legal and compliance, should be represented as well. And to fully assess the role of AI in a company’s current and future operations, it’s important to invite product development, client support and sales and marketing.
Don’t forget finance: AI tools can be expensive, especially now that many vendors are moving from a per-user license to charging by consumption. Your finance reps can make sure that the company isn’t incurring unexpected costs that exceed budgets.
In addition, HR should be involved because AI will likely have profound effects on the workforce. (For the record, I firmly believe that AI will not replace people — accuracy and ethics require human oversight — but it will alter responsibilities and will enable massive output increases.)
The multi-department representation ensures diversity of thought, skills and subject matter expertise. Executives from the innovation team might not think too much about compliance, while the legal team may not prioritize innovation. The more perspectives considered, the better the decisions.
Seek diversity of seniority as well, from junior staff to middle management to senior leaders. The junior employees and middle managers can speak to the ways staff are using (or wish to use) AI tools in their day-to-day activities. They are boots on the ground who experience the effects of decisions. The senior-level employees, meanwhile, can ensure that the use of AI aligns with corporate goals and departmental expectations.
Important consideration: International companies should not assume that one advisory board will work for the whole enterprise. Laws and compliance standards differ from country to country, and boards must address these differences. The boards across a company should share best practices and collaborate on initiatives, but they must also function independently.
One caution on size: A board large enough to cover all of these perspectives can easily become too large to decide anything. Keep the standing membership tight and bring in additional subject matter experts as individual requests warrant. Name a chair who owns the agenda and holds the group to its decision deadlines and agree in advance on how a deadlocked decision is escalated. For most companies, meeting monthly is enough, provided routine intake decisions are handled between meetings rather than queued up for the next.
What the Board Does
Boards should establish guidelines for the intake process for AI technologies, when requests for tools and subscriptions are evaluated. Requests should identify what an employee or team hopes to accomplish by adopting a particular tool, and what data the tool would touch.
Some requests require greater oversight than others. To accommodate these variances, companies may wish to use a similar model to what MRI employs: We have categorized tiers of requests into minimal, medium or maximal oversight.
For example, if an employee is requesting a license to use Copilot, only one approval is needed from finance. Middle-tier requests center on tools that would incur greater costs than a simple user license and, in some cases, affect internal operations. In these instances, IT also must approve the adoption. At the highest level are requests for tools that could touch third-party systems or private data. That’s when I get involved, along with colleagues from security, legal and governance, risk and compliance (GRC) teams. Together, we make sure that the proposed technology will integrate into our system architecture and that it meets our standards of integration and security.
A single example shows why that top tier earns its overhead. A team asks to pilot a capable drafting assistant that would connect directly to a repository of executed leases. The tool is sound, and the use case is real. The problem is scope: The connector requests read access to the entire repository when the pilot needs a handful of folders. The board’s job in that moment is not to say no. It is to narrow the data scope, set a retention limit and approve. That is the outcome a working board produces most often — not a rejection, but a smaller, safer yes.
Another responsibility is communication. The board needs to inform staff about the intake decisions and the rationale behind them. Ideally, AI policies should appear in the employee handbook, and the board can help in compiling them.
Furthermore, the board should explore options for compliance training and work with HR and training departments to organize the programs. Employees who understand the board’s policies and processes and the reasons behind them are prepared to use AI responsibly and in accordance with company rules. Such employees will encounter few surprises and benefit from rapid adoption once a tool is approved. The results are happier employees and significant risk reduction. Beyond specific requests, the advisory board should meet regularly to discuss what new AI models are on the horizon, how those models may affect security and what tools the company may want to consider adopting. Every month, it seems that a new AI model or tool is introduced. Companies must keep up if they are to remain competitive, but an emphasis on the latest and greatest doesn’t always convert into ROI. The board can make sure that any adoption supports a specific business goal.
Along with the introduction of new AI models comes new AI threats. It’s important for the board to stay on top of emerging dangers, such as phishing or data poisoning, which at best cause inaccuracies and at worst result in major instances of fraud. Ironically, although AI can open new doors for fraudsters, it also offers one of the best ways to combat fraud. Board members should research the latest scams and hacks, as well as new methods, and include them on the agenda for every board meeting.
Where Boards Go Wrong
Two failure modes are worth guarding against. The first is the rubber stamp. A board that approves everything put in front of it, meeting after meeting, has stopped governing and started processing paperwork. If your board has never sent a request back for rework, treat that as a warning rather than a milestone.
The second failure is more common and more damaging. A board that takes six weeks to answer a simple question teaches employees to stop asking. They will sign up for the free tier on a personal account or paste company data into a consumer chatbot, and the governance you built will have made your risk profile worse by driving usage into the shadows. Speed is a control. Publish your target turnaround times, hold the board to them and keep the lightest tier genuinely light.
Alternatives?
There is no alternative to the function.
Smaller firms may not need a standalone board, as the work can sit within an existing risk or technology committee, but somebody has to own the intake process, the policy, the training and the threat landscape and it cannot be one person in IT deciding alone.
Companies that neglect this entirely are playing with fire. Boards can guide companies on leveraging the most appropriate and powerful tools for real estate without endangering security or privacy.
If you haven’t yet established a board, begin identifying potential members across different departments who represent a wide range of roles.
Set up that first meeting to outline goals and responsibilities.
Yes, the meetings are likely to be time-consuming and the responsibilities formidable. But they are utterly necessary for the health and longevity of your business.








