Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
All Commercial Real Estate guides
Real Estate 17 min read

The AI Policy Playbook for small CRE firms

The AI Policy Playbook for small CRE firms

The point of an AI policy at a small commercial real estate firm is not to control your people; it is to let them move fast without an accident. Your team is already using these tools. The NAR 2025 Technology Survey found 68% of Realtors now use AI, but only 17% report a significant positive business impact, and the gap is not only a skills gap. Some of it is a firm full of people using consumer tools quietly, with no shared rule about what they can paste, whose name they can type, or who owns the output when it goes out the door. A written policy closes that. At a 4-to-20-person firm the whole thing fits on one page, and the version that fits on one page is the only version anyone will follow. This is how to write it.

A note on where this sits. The full arc of getting a lean team from zero to fluent in a quarter is laid out in our CRE AI training playbook, and the broader case for why small shops can out-operate larger competitors is in the small CRE firm manifesto. This piece covers the one document that training depends on and most rollout advice skips: the written rules that make it safe for people to use what you taught them.

A Policy Is What Makes Adoption Safe, Not What Slows It Down

Most owners hear “AI policy” and picture a compliance drag: a document that exists to say no, written by people who do not do the work, filed somewhere no one reads. That version is worth skipping. The version that matters does the opposite job. It is the thing that lets your most careful senior broker stop worrying and start using the tools.

Think about who on your team is holding back. It is rarely the junior who signed up for every beta. It is the 20-year producer with the biggest relationships and the most to lose, who has heard that these tools “train on your data” and has decided the safe move is to stay out. That person is right to be cautious and wrong to opt out, and no amount of enthusiasm from the front of the room will move them. What moves them is a clear, written rule that tells them exactly what is fine, what is off-limits, and who is accountable if something goes wrong. The policy is permission. Without it, caution defaults to abstention, and your best people are the ones who abstain.

There is a second, quieter reason. Right now, if three of your people use AI, they are each making up their own rules about what to paste and how much to trust the answer. A firm with no policy does not have zero AI risk; it has undocumented, uneven AI risk spread across everyone’s private habits. Writing one page does not add risk. It replaces a dozen invisible policies with one you can see.

Throw Out the Enterprise Template

If you search for an AI policy, you will find frameworks built for companies that have a general counsel, an IT department, a chief information security officer, and an AI review board. They run to dozens of pages. They assume a governance committee meets to approve model deployments. They are not wrong for the firms they were written for. They are useless for yours, and copying one is worse than having nothing, because a policy no one can read is a policy no one follows.

Your firm has none of those roles, and it does not need most of what those documents govern. You are not deploying models. You are letting brokers and analysts use a handful of commercial assistants for drafting, summarizing, and analysis. The entire surface you need to govern is: which tools, what data, who checks the work, what you tell clients, what you keep, and who owns the rules. Six questions. One page. Everything past that is borrowed weight that makes the document heavier and less likely to be used. The discipline here is the same one that separates a small firm that out-operates the giants from one that imitates them badly: take the principle, drop the apparatus.

The Six Things a Small-Firm AI Policy Must Cover

Every line that earns its place on the page falls under one of six headings. Write a short, plain paragraph for each and you have a working policy.

1. The approved tools

Name the specific assistants your firm allows, and require that everyone use the firm’s business-tier accounts rather than personal free logins. This is the single most important line in the whole policy. Business and enterprise tiers of the major assistants keep your inputs out of model training by default, where free consumer logins may not, so the account tier does more to protect your confidential data than any rule about what people paste. Approve a small set the team can already use well, such as ChatGPT, Claude, Gemini, or Microsoft Copilot, and say plainly that work data goes only into the approved accounts. Confirm the current data-handling settings for whichever tool you approve, because vendors change defaults and you want the firm standing on what the terms say today, not what someone remembers.

2. The data rule: three buckets

Generic templates say “no confidential data” and stop, which is useless the moment a broker has to decide in real time. Give people three concrete buckets instead. Public is fine anywhere: listing descriptions, generic market questions, hypothetical scenarios with no real party named. Internal is fine in approved accounts: draft language, analysis with the client and address stripped out, a lease clause with the tenant anonymized. Never stays out of every tool: client names tied to financials, unexecuted deal terms, anything under an NDA, and rent rolls with tenant identifiers. The test a broker can run in two seconds is “could this identify a real party and their position.” If yes, it is either anonymized down to Internal or it stays out. Because this bucket carries the most legal weight for a CRE firm, it is worth reading our fuller framework for safe AI use with client deal data alongside this section and lifting its language straight into your policy.

3. The accountability rule

State that the person who sends the work owns the work. AI drafts; a named human is responsible for everything that leaves the firm. This sounds obvious and it is the line that prevents the failure that hurts you most: a confidently wrong number, a misread clause, or an invented citation reaching a client because someone treated a draft as a final answer. The rule is not “check AI output” as a vague suggestion. It is “the broker whose name is on the LOI is accountable for the LOI, regardless of what produced the first draft.” That single sentence keeps the tool in the assistant’s seat and the professional in the responsible one.

4. The disclosure rule

Decide, once, when your firm tells a client or counterparty that AI was involved, so no one has to improvise it deal by deal. A workable default for most firms: routine internal drafting and summarizing does not require disclosure, the same way you would not disclose that you used a spreadsheet or a template. Anything a client could reasonably expect to be your own judgment, and anything a regulation or a listing agreement requires, gets human review and, where relevant, disclosure. Advertising and listing content still has to meet fair-housing and truth-in-advertising obligations no matter what drafted it, so the disclosure rule and the accountability rule work together: the human who approves the copy owns its compliance.

5. The record rule

Two things are worth keeping. First, a shared prompt library, so that when someone finds a prompt that reliably produces a clean lease summary or a usable market blurb, it belongs to the firm instead of evaporating when that person gets busy. Second, a light habit of saving the source and the final human-approved version of anything consequential, so that if a client ever asks how a number was produced, you can answer. You do not need an audit system. You need a shared folder and the expectation that hard-won prompts and material outputs land in it.

6. The owner and the review date

A policy with no owner is a draft. Name one person responsible for keeping it current, and put a review date on it, quarterly is right for a field where the tools change every few months. This is usually the same person who carries day-to-day adoption, and the two jobs reinforce each other. The owner is not a compliance officer; they are the person who notices when a vendor changes its terms or the team adopts a new tool, and updates the one page accordingly.

Write It in an Afternoon, Not a Quarter

The trap that kills small-firm policies is treating this like a committee project. It is not. One person drafts the six paragraphs above in an afternoon, the principal reads it and cuts anything that reads like corporate filler, and you circulate it in a team meeting where people can ask what the buckets mean in practice. That is the whole process. A policy that takes a quarter and three meetings to produce will be obsolete before it ships and resented by everyone who sat through the meetings.

Keep the language at the level a busy broker will read on the first pass. Six short paragraphs, plain sentences, concrete examples drawn from your own deals. If a section needs a diagram or a defined-terms appendix, it is too complex for this firm and you have drifted back toward the enterprise template you were supposed to throw out.

A Policy With No Training Is a Rule Nobody Can Follow

A written rule set and hands-on fluency are two halves of the same thing. A policy tells people what is allowed; training is what lets them do the allowed thing well. Hand a team the three-bucket data rule with no instruction and they will either freeze, unsure what counts as “identifying,” or ignore it, because a rule you cannot apply is a rule you route around. The firms that get this right treat the policy and the skills as a pair, which is the same logic behind putting training before tooling: the rules and the fluency have to arrive together, because either one alone produces the failure the other was meant to prevent.

You can see the finished state in a firm that has done both. Walk into a genuinely AI-fluent brokerage and no one is nervously asking whether summarizing a lease is allowed, and no one is pasting a live deal into a free chat window either. The policy has become invisible because everyone has internalized it, which is exactly what a one-page rule that people were trained on is supposed to do.

Keep It Alive or Watch It Rot

The proptech tools you are governing change their features and their terms quarterly. A policy written once and filed is wrong within two quarters, and a wrong policy is worse than none because it teaches people the rules do not track reality. This is why the owner and the review date are not optional bookkeeping. They are what keeps the document honest.

The quarterly review is short. The owner checks whether the approved tools still handle data the way the policy claims, whether the team has quietly adopted anything not on the approved list, and whether any section is being ignored because it is unclear or wrong. Fix what drifted, note the date, recirculate if anything material changed. Fifteen minutes a quarter keeps the one page true, and a true one page is the only kind anyone respects.

Where an Assessment Fits

Most firms do not need help writing the policy; they need a clear-eyed read on where their real exposure is before they write it. That is what a free AI-readiness assessment produces: a working session that maps how your team is already using these tools, flags the confidential-data situations you need a rule for first, and tells you honestly whether you need a full LLM-fluency workshop, a lighter course, or mostly just this one page and clearer defaults. Market rates for structured training, if it turns out you want it, run from the low thousands to the low tens of thousands depending on team size and depth. The assessment itself costs nothing and usually makes the right first three lines of your policy obvious.

Frequently Asked Questions

What should an AI policy for a small real estate firm include?

Six things, each a short paragraph: the approved tools and a requirement to use business-tier accounts; a data rule with three concrete buckets (public, internal, and never); an accountability rule stating the person who sends the work owns it; a disclosure rule for when clients are told AI was involved; a record rule covering a shared prompt library and saved final versions; and a named owner with a quarterly review date. That is the entire surface a 4-to-20-person firm needs to govern. Anything past those six headings is borrowed from enterprise templates that assume an IT and legal department you do not have.

How long should a small CRE firm’s AI policy be?

One page. A firm of 4 to 20 people is not deploying models or running a governance board; it is letting brokers and analysts use a handful of commercial assistants for drafting, summarizing, and analysis. That surface fits in six short paragraphs. The length is not a shortcut, it is the point: a one-page policy is the only version people will read and follow, and a 40-page framework copied from a large enterprise is a policy that exists on paper and nowhere in anyone’s actual behavior.

Do we need a lawyer to write our AI policy?

Not to produce the working document. One person can draft the six sections in an afternoon using plain language and examples from your own deals. Legal review is worth it for the two highest-stakes areas if your deals warrant it: the confidential-data rule, where NDA and client obligations live, and the disclosure and advertising rule, where fair-housing and truth-in-advertising duties apply. Have counsel pressure-test those two sections rather than commission the whole policy, which keeps the cost small and the document readable.

Is it safe to use ChatGPT for commercial real estate work?

It can be, with two conditions. Use the firm’s business or enterprise-tier account rather than a personal free login, because the paid business tiers keep your inputs out of model training by default where free consumer logins may not, and confirm the current data-handling settings since vendors change them. Then apply a data rule: public and anonymized internal material is fine, but client names tied to financials, unexecuted terms, NDA material, and identified rent rolls stay out. The same logic applies to Claude, Gemini, and Microsoft Copilot. The tool is not the risk; the account tier and the data you put in are.

What data should never go into an AI tool?

Anything that identifies a real party and their position or is legally protected: client names tied to financials, unexecuted deal terms, material under an NDA, and rent rolls with tenant identifiers. The fast test a broker can run in real time is “could this identify a real party and their position.” If the answer is yes, the material either gets anonymized down to a safe internal form (client and address stripped out) or it stays out of every tool entirely. This is the highest-stakes line in the policy for a CRE firm, and it deserves its own careful treatment.

Do we have to tell clients we used AI?

Decide it once as firm policy rather than improvising per deal. A workable default: routine internal drafting and summarizing does not require disclosure, the same way you would not announce using a spreadsheet or a template, but anything a client reasonably expects to be your own professional judgment, and anything a regulation or listing agreement requires, gets human review and disclosure where relevant. The connected rule is that a named human always owns and approves anything client-facing, so compliance and disclosure ride on that person’s sign-off regardless of what produced the first draft.

Who should own the AI policy at a small firm?

One named person, usually the same person who carries day-to-day adoption. They are not a compliance officer; they are the person who keeps the one page current, notices when a vendor changes its terms or the team picks up a new tool, and runs the short quarterly review. A policy with no owner is a draft that rots. Naming the owner and putting a review date on the document is what keeps it tracking reality in a field where the tools change every few months.

How often should we update our AI policy?

Quarterly, with a short review. The proptech and assistant tools you are governing change features and terms every few months, so a policy written once and filed is wrong within two quarters. The review takes about fifteen minutes: the owner checks whether the approved tools still handle data as the policy claims, whether anyone has adopted an off-list tool, and whether any section is being ignored because it is unclear. Fix what drifted, date it, and recirculate if anything material changed.

Does a policy slow down AI adoption?

The opposite, when it is done right. At a small firm the people holding back are usually the careful senior producers who have the most to lose and have heard the tools are unsafe. A clear written rule that tells them what is fine, what is off-limits, and who is accountable is what gives them permission to start. Without a policy, caution defaults to abstention and your best people opt out. The one-page rule set is the accelerator, not the brake, because it converts vague fear into a set of green lights people can act on.

Where to Start

The first move is not downloading a template. It is deciding, on your own deals, what belongs in the “never” bucket and which accounts your team is allowed to use, because those two lines carry most of the risk and most of the reassurance. Write those first, add the other four sections in an afternoon, name an owner, and put a review date on it. If you want an outside read before you write, a free AI-readiness assessment maps how your team already uses these tools, flags the confidential-data situations you most need a rule for, and tells you honestly whether you need training on top of the policy or mostly just the policy. Book a free AI-readiness assessment and you will leave with the first three lines of your own already drafted.

Last Updated: Aug 7, 2026

AW

Arthur Wandzel

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your firm fluent in AI — then automate what works

  • Hands-on training applied to LOIs, lease summaries, and market write-ups
  • Automation across documents, deals, communications, and back office
  • Built for 4–20-person firms with no IT department

Related articles