The question that stalls AI at most small CRE firms is not “does it work” — it is “can I paste this into it.” A broker has a signed NDA on a $12M industrial deal and a seller’s three years of financials sitting in a PDF. The tool would summarize it in nine seconds. But the firm has no rule, so the honest people hesitate and the incautious people paste it anyway, and both outcomes are bad. Hesitation kills the habit before it forms; recklessness puts a client relationship on the line. What a lean firm needs is not a lecture about being careful. It needs a framework specific enough that anyone on the team can look at a document and know, in five seconds, whether it can go into an AI tool and which one. This is that framework.
Before the framework, a word on where it sits. Getting a small team confident with these tools is a ninety-day arc, and the full sequence — what to teach, in what order, and how to make it stick — is laid out in our CRE AI training playbook; the wider case for why a 10-person shop can out-operate a national brokerage is in the small CRE firm manifesto. This piece is the narrow, load-bearing part of that arc: the data rules that let you say yes to daily AI use on real work instead of quietly forbidding it and losing the advantage.
The Distinction Almost Everyone Gets Wrong
Nearly every article you will read on this subject answers one question — “does the AI company train its model on what I type” — and lets you believe that answers everything. It does not. There are two separate risks, and conflating them is how careful people still get it wrong.
The first risk is training: whether your input becomes part of the model’s future knowledge, so a fragment of your seller’s financials could theoretically surface in someone else’s answer. The major AI products draw a clear line here. On their business, team, enterprise, and API tiers, ChatGPT, Claude, Gemini, and Microsoft Copilot all state that they do not use business customer content to train their models by default. On some consumer free tiers, conversations may be used for training unless you turn that setting off. So the training risk is real but controllable — and mostly a function of which tier you are on.
The second risk is disclosure, and it is the one CRE work actually turns on. When you sign an NDA on a deal, you agree not to disclose the confidential material to third parties. An AI vendor is a third party. Pasting an NDA-bound offering memorandum into a chatbot is a disclosure to that vendor’s systems whether or not the model ever trains on it — the same way emailing it to an outside party would be, even if that party promised never to read it twice. “They don’t train on my data” does not resolve “am I allowed to hand this data to them at all.” Those are different questions, governed by different documents: one by the vendor’s privacy policy, the other by the contract you signed with your client.
Hold both questions in mind and the whole framework falls out of them. You manage training risk by choosing the right tier once. You manage disclosure risk by classifying each document before it goes anywhere near a text box.
Part 1: Classify the Data Before You Classify the Tool
The instinct is to ask “is this tool safe?” The right first move is to ask “how sensitive is this document?” A small CRE firm handles a surprisingly wide range, and lumping it all into one bucket is what produces both the reckless paste and the paralyzed non-use. Four classes cover almost everything that crosses a broker’s or property manager’s desk.
Public. Anything already published or intended to be: listing copy, a marketing flyer, a CoStar or LoopNet description, a press release, a market statistic you would put in a newsletter. There is no confidentiality interest at all. This can go into any tool, any tier, with zero hesitation.
Internal, non-confidential. Your own working material that carries no third-party obligation: a rough market write-up, an internal email draft, a checklist, a generic lease-clause question with no party names. Low stakes. Business-tier tools are the clean default, but the exposure if it leaked is your own, not a client’s.
Client-confidential. The heart of CRE: NDA-bound offering memoranda, a seller’s financials, buyer identities, deal terms before they are public, a rent roll with tenant names, LOI drafts naming the parties. This carries a contractual duty to a specific person. It does not mean “never use AI” — it means the tier and the handling both have to be deliberate.
Regulated / personal. Tenant Social Security numbers, bank account details, driver’s licenses, anything that would be a data-breach problem if it leaked, and anything covered by a state privacy statute. This is the “never paste it raw” bucket, full stop.
The value of naming the classes is that it turns an anxious judgment call into a lookup. Nobody has to decide, under deadline, how paranoid to be about a given file. They match it to one of four labels they already understand, and the label tells them what is allowed.
Part 2: Choose the Tier That Actually Changes the Risk
Here is the single decision that does more for a small firm’s safety than any policy paragraph: put the whole team on the business or team tier of one AI product, not the free consumer version.
The upgrade costs roughly twenty to thirty dollars per person per month, and it buys three things that matter. It moves you onto the no-training-by-default footing for everything the team types. It typically gives an administrator a console — one place to see who has access and to switch data controls on for everyone at once, instead of trusting each person to have found the right toggle. And it gives the firm, rather than an individual’s personal account, the contractual relationship with the vendor, which is what you want when the data touching that account belongs to your clients.
For a 4-to-20-person firm this is not an IT project. It is one person spending an afternoon putting the team on ChatGPT Team, Claude for Work, Microsoft Copilot, or Google’s business tier — pick the one that fits your existing stack, since a Microsoft 365 shop will land on Copilot and a firm already living in Google Workspace on Gemini. Standardizing on one tool also makes the rest of the framework enforceable: a single set of rules, a single place data goes, no shadow accounts. The free consumer tier is genuinely fine for the Public and Internal classes. It is the wrong home for anything client-confidential, and paying the per-seat fee is the cheapest control you will ever buy. The alternative — everyone freelancing on personal free accounts — carries a quiet, compounding cost that we put real numbers to in the DIY AI tax.
Part 3: Set One Default Action per Data Class
With four data classes and a chosen tier, the operating rule writes itself. Each class gets exactly one default action, so there is nothing to deliberate in the moment.
| Data class | Examples | Default action |
|---|---|---|
| Public | Listing copy, flyers, market stats, published descriptions | Paste freely — any tool, any tier |
| Internal, non-confidential | Draft write-ups, internal emails, generic clause questions | Paste into the firm’s business-tier tool |
| Client-confidential | NDA-bound OMs, seller financials, rent rolls with names, pre-public deal terms | Business-tier tool only, and prefer to redact names first |
| Regulated / personal | SSNs, bank details, IDs, tenant PII | Never paste raw — redact to nothing identifying, or do not use AI for it |
The power of the table is that it removes the two failure modes at once. The cautious broker who was refusing to use AI on a routine internal write-up sees it is a green light and stops leaving speed on the table. The broker who was about to drop a seller’s tax returns into a free account sees the red line and stops. Neither had to make a judgment call under pressure; they read a row.
One nuance worth stating plainly for the client-confidential row. “Prefer to redact names first” means you can very often get the AI’s help without disclosing who the deal is about. A rent roll analysis does not need the tenants’ real names to spot the lease expirations clustered in the same quarter. An OM summary does not need the seller’s identity to pull out the cap rate and the deferred maintenance. Strip the identifiers and much of what made the document confidential is gone, while all of what made it useful to summarize remains.
Part 4: Handle the Genuinely Sensitive Documents
Some documents are sensitive enough that even a business tier does not settle it — a deal under an unusually strict NDA, a client who has explicitly said their materials go into no third-party tool, financials whose leak would be catastrophic. The framework does not pretend these away. It gives them three honest options.
Redact, then use. Remove every identifier — names, addresses, entity names, exact figures if they are themselves the secret — and work with the sanitized version. For most analytical tasks the AI is helping with structure and math, not identity, so a redacted document loses little of its usefulness. This is the workhorse move for the top end of the client-confidential class.
Abstract the question. Often you do not need to paste the document at all. Instead of feeding the AI a specific lease, ask it the general question the lease raised: “In a triple-net industrial lease, what does a typical CAM reconciliation clause require the landlord to provide, and what are common tenant disputes?” You get the expertise with none of the confidential specifics in the box.
Keep it out. For a small number of documents the right answer is that AI does not touch them, and saying so in advance is a feature, not a failure. A framework that draws a clear line the team trusts is what makes the other ninety-five percent of daily work safe to accelerate. A firm that has thought this through and can tell a nervous client “your materials never go into an outside tool, and here is our written rule” has turned confidentiality into a selling point rather than a liability.
Part 5: Write the One-Page Rule
None of the above works if it lives in one principal’s head. The final part is the cheapest and the most skipped: write it down on a single page and give it to everyone. A page is enough. It should say which one tool the firm uses, that everyone is on the business tier, the four data classes with two or three real examples each drawn from your own deals, the default action for each class, and the three options for the genuinely sensitive documents. That is the whole document.
Keep it in plain language a new hire could follow on day one, put it in the shared drive, and walk through it once as a team so the examples are concrete. The point is not legal cover — it is that a written, agreed rule is the only version of confidentiality that survives a busy week. This is the firm-level companion to the broader governance questions — acceptable use, client disclosure, what to do when a tool changes its terms — that we work through in the AI policy playbook for small CRE firms; the confidentiality framework here is the operational core that policy is built around.
Why This Is an Adoption Lever, Not a Brake
The reason to do this is not only defense. Clear data rules are one of the strongest predictors of whether AI use actually takes hold at a firm, because fuzzy rules produce hesitation and hesitation is where a new habit dies. When people are unsure whether they are allowed to paste a document, the safe move under deadline is to not use the tool at all — and a week of that and the workshop enthusiasm is gone. We watch this dynamic play out in the crucial first month after training, documented in what sticks and what fades in the first 30 days: the firms whose people had a clear confidentiality rule kept using the tools, and the firms whose rules were vague quietly reverted.
A firm that gives its team explicit permission — here is the tool, here is what you can put in it, here is the short list of what you cannot — has removed the exact friction that stalls usage. Confidentiality done well is what lets a lean CRE shop use AI on its real, valuable, sensitive work every day, which is the only kind of use that changes the economics. Done badly, or not at all, it produces either paralysis or a breach, and both cost more than the framework ever would.
Where to Start
You do not have to design this alone, and you do not have to guess which tier and which handling rules fit your specific mix of brokerage, management, and acquisitions work. A free AI-readiness assessment is a short, concrete working session that maps your firm’s actual document types to a data-classification table, recommends the tool and tier that fit your existing Microsoft or Google stack, and drafts the one-page rule your team can adopt the same week. Book a free AI-readiness assessment and you will leave with a confidentiality framework specific to your deals — and the confidence to let your team use AI on the work that matters instead of forbidding it and falling behind.
Frequently Asked Questions
Is it safe to put confidential deal data into AI tools?
It can be, if you separate two questions most people conflate. “Does the tool train on my data” is answered by the tier — business and enterprise tiers of the major AI products do not train on business customer content by default. “Am I allowed to disclose this material to a third party” is answered by your NDA, because the AI vendor is a third party regardless of its training policy. Public and internal material is safe to paste into a business-tier tool; NDA-bound or personally identifying data should be redacted first or kept out. The safe path is a written rule that classifies each document and assigns it a default action.
Do the major AI products train their models on what I type?
On business, team, enterprise, and API tiers, ChatGPT, Claude, Gemini, and Microsoft Copilot state that they do not use business customer content to train their models by default. On some consumer free tiers, conversations may be used for training unless you turn that setting off. This is the main reason to put a CRE team on a paid business tier: it moves everything the team types onto the no-training footing without relying on each person to have found the right toggle. Verify the current wording on each vendor’s trust or privacy page, since these policies are updated periodically.
Does an NDA stop me from using AI on a deal?
Not necessarily, but it changes how. An NDA restricts disclosure of the confidential material to third parties, and pasting it into an AI tool is a disclosure to that vendor. The practical answer for most deals is to redact the identifiers — names, entities, addresses — and work with the sanitized version, since the AI usually helps with structure and math rather than identity. For deals under unusually strict NDAs or clients who have said their materials go into no outside tool, keep the document out of AI entirely and ask the general question instead of pasting the specific document.
What is the difference between the free and paid versions for confidentiality?
The paid business or team tier, at roughly twenty to thirty dollars per person per month, does three things the free version does not. It puts you on the no-training-by-default footing, it gives an administrator one console to control data settings for the whole firm, and it makes the firm — not an individual’s personal account — the party in the contract with the vendor. The free consumer tier is fine for public and internal material. It is the wrong home for anything client-confidential, and the per-seat fee is the cheapest confidentiality control a small firm can buy.
How should a small CRE firm classify its documents?
Four classes cover almost everything. Public: listing copy, flyers, published market stats — paste freely. Internal, non-confidential: draft write-ups, internal emails, generic clause questions — use the firm’s business-tier tool. Client-confidential: NDA-bound OMs, seller financials, rent rolls with names, pre-public deal terms — business tier only, and redact names first where you can. Regulated or personal: SSNs, bank details, tenant PII — never paste raw. Writing two or three real examples from your own deals next to each class is what makes the table usable under deadline.
Can I use AI on a rent roll or a lease with tenant names?
Yes, with a small change in habit. Most analysis — spotting clustered lease expirations, summarizing terms, checking CAM math — does not require the real tenant names. Redact the identifiers before you paste, and you keep everything that made the document useful to analyze while removing what made it confidential. Tenant Social Security numbers, bank details, or other regulated personal data should never be pasted raw.
Do we need an IT department to do this safely?
No. Putting a 4-to-20-person firm on a business-tier AI product is an afternoon of work for one person, not an IT project. The controls that matter — the paid tier, the admin console, a one-page data rule — are all available to a firm with no technical staff. Standardizing the whole team on one tool is what makes the rules enforceable, because there are no shadow accounts and data goes to exactly one place with one set of rules.
What should the firm’s written confidentiality rule contain?
One page is enough: which single AI tool the firm uses, that everyone is on the business tier, the four data classes with two or three real examples each from your own deals, the default action for each class, and the three options for genuinely sensitive documents — redact, abstract the question, or keep it out. Keep it in plain language a new hire could follow on day one, store it in the shared drive, and walk the team through it once so the examples are concrete. A written, agreed rule is the only version of confidentiality that survives a busy week.
Does having clear confidentiality rules actually help adoption?
More than most firms expect. When people are unsure whether they are allowed to paste a document, the safe move under deadline is to not use the tool, and a week of that erases the enthusiasm a workshop built. Firms whose teams have a clear, written rule about what may go into which tool keep using AI; firms with vague rules quietly revert. Confidentiality done well removes the exact friction that stalls usage, which is why it belongs at the start of an adoption plan rather than bolted on after.
What does it cost to set this up?
Very little. The framework costs the price of the business-tier seats — roughly twenty to thirty dollars per person per month — plus the afternoon to write the one-page rule, which a firm can do on its own or with help. A free AI-readiness assessment maps your document types to the data classes and drafts the rule at no cost. The one control you should not skip at any price is moving off free consumer accounts for anything a client entrusted to you.
Arthur Wandzel