The most expensive red flag in an AI project proposal is not a bad vendor. It is a clean, well-written proposal to custom-build something a $300-a-month subscription already does. A weak proposal rarely announces itself. It reads professionally, uses the right words, and quotes a number that feels reasonable because you have nothing to compare it against. For a 4-to-20-person commercial real estate firm with no IT department and no one to translate the technical sections, that is the whole problem: the document was written by the party who benefits from you not knowing which questions to ask. Here is the read-through, eight red flags in roughly the order they appear in a real proposal, each with a question you can ask on the call and the market ranges that tell a fair quote from an expensive one.
Red flag 1: it never says what it is beating
A custom build only makes sense when nothing you can rent does the job, so an honest proposal first establishes what it is beating. The first red flag is a proposal that never mentions the alternatives at all.
If the document proposes a deal-screening tool but never names Dealpath or a thin ChatGPT workflow, or a lease-abstraction pipeline with no word about Prophia or Leasecake, it is hiding its weakest flank. The vendor knows those options exist. Leaving them out is what makes the quote look necessary.
Ask directly: “What is the cheapest thing that already does most of this, and why isn’t it enough for us?” A vendor worth signing has a real answer, usually a version of “the subscriptions cover 70% of this but can’t touch your rent-roll format or your underwriting model, and that last 30% is the point.” A vendor who deflects is selling a build for its own sake. The honest way to run that comparison is laid out in the buy-vs-build playbook for small CRE firms: custom earns its cost only when a repeatable, high-volume workflow has no off-the-shelf fit.
Red flag 2: the scope is a technology tour, not your workflow
Read the scope and count two things: how many sentences describe the AI, and how many describe your actual problem. If the technology outweighs the workflow, that is a red flag.
Weak proposals spend paragraphs on the model and the pipeline and a single vague line on what your team does today. The tell is a scope that could be copy-pasted to a law firm with the noun swapped. Your problem is specific: brokers forwarding LOIs into a shared inbox, an analyst re-keying rent rolls from PDFs, a principal who wants a market write-up before Monday. A proposal that studied your firm names those tasks; one that did not describes a technology.
Ask: “Walk me through exactly what my analyst stops doing on day one, and what she does instead.” If the answer stays abstract, the build will drift toward what is easy to build rather than what you need. A well-formed scope reads like the structure in the anatomy of a CRE automation statement of work, where every deliverable ties back to a task someone performs today.
Red flag 3: deliverables you cannot verify
Every deliverable should be something you can test and either accept or reject. A deliverable you cannot verify is one the vendor can claim to have met while you are still unhappy.
“An AI-powered lease abstraction system” is not verifiable. “A tool that extracts fifteen named fields from a lease PDF and matches a human abstractor on parties, dates, and base rent across twenty of your real leases” is. The difference is an acceptance test: a standard you agreed to in advance that decides whether the thing works. Proposals that skip acceptance criteria are how a project ends with the vendor paid and the firm holding software no one uses.
Each deliverable needs three properties: a concrete output, the standard that output must meet, and who signs off. If one is missing, ask for it in writing before you sign. A vendor who resists putting acceptance criteria on paper is not confident the system will meet them.
Red flag 4: you do not own the account, data, or code
Somewhere in the proposal sits the question of what you keep when the engagement ends, and it is easy to skim past. For a small firm, ownership is the difference between a tool you keep and a dependency you rent forever.
Three questions decide it. Whose account does the AI run on? If it calls ChatGPT, Claude, or Gemini through the vendor’s account, the vendor sits between you and the model, and your access ends when the relationship does. Who owns the code and configuration? A build you paid for should live in a repository your firm controls, so a second developer could pick it up. Who owns the output, your extracted lease fields and normalized rent rolls? That is your firm’s asset and should live somewhere you control.
A proposal that leaves any of these with the vendor changes what you are buying, from an asset into a subscription to the vendor’s continued existence. Ask flatly: “If we part ways in eighteen months, what do we keep, and can someone else run it?”
Red flag 5: the price does not map to the market
You cannot judge a number in isolation, which is exactly why a proposal quotes one. Anchor it against the market first.
Today a focused LLM fluency workshop for a small CRE team runs roughly $2,000 to $15,000, and a scoped custom automation project generally runs $25,000 to $150,000 depending on complexity. Those ranges are wide on purpose; your job is to find where an honest quote for your scope should land. A single-workflow automation, like turning forwarded broker emails into a ranked pipeline, sits near the bottom. A multi-system build that writes into your accounting software sits higher. A quote at three times the market for a modest scope is a red flag. So is one far below it, because a number that cheap usually has the hard parts left out.
Two structural details matter as much as the total. The payment schedule: a large deposit with the balance due on vague “completion” puts the risk on you, while payments tied to accepted milestones keep the vendor honest. And the pricing model, fixed-price versus time-and-materials, which changes who absorbs overruns, a trade-off we break down in fixed-price versus time-and-materials for a CRE automation project. For where the money actually goes, what a custom AI automation project costs a small CRE firm walks the line items to expect.
Red flag 6: there is no line for maintenance
The most consequential part of most proposals is what they leave out: the standing cost of keeping the tool working after launch.
This is where the industry’s failure numbers come from. Gartner has projected that roughly 30% of generative-AI projects are abandoned after the proof of concept, and MIT’s 2025 study of AI in business found only a small fraction of pilots produced measurable value. The failure rarely happens at the build. It happens in the months after, when a document format changes or a model updates and the tool quietly starts returning a wrong renewal date with full confidence. A firm with an engineer catches that; a small CRE firm with no one to diagnose it does not, until it surfaces in a live deal.
A proposal that prices a build but not its upkeep is quoting half the real cost. Ask who fixes it when it breaks, how fast, and at what monthly or per-incident cost. A vendor who has thought about your firm has a maintenance line and a plan for the day the model behind ChatGPT or Claude shifts underneath the tool. This is the through-line of the small-firm AI manifesto: a lean shop’s edge is low overhead, and an unmaintained dependency quietly erases it.
Red flag 7: confidentiality is left unaddressed
Your deal data is not ordinary business data. Leases, LOIs, rent rolls, and tenant financials move under NDA, and a proposal silent on how they are handled has skipped the part that could put you in breach.
Two specifics matter. Where does your data go when the tool processes it, and is it used to train anyone’s model? The workable pattern is a business-tier arrangement where inputs are not used for training by default, on an account your firm controls; a tool running your leases through a consumer account is a real exposure. And what leaves your control at all? A tool that ships tenant financials to a third-party service you never vetted is a confidentiality decision the vendor made for you, buried in an architecture diagram.
Ask: “Where does our data go, who else can see it, and is any of it used to improve someone else’s product?” A vendor who works with confidential data answers without hesitation.
Red flag 8: the proof is a demo, not a reference
Near the end, the proposal makes its case for the vendor. The red flag is proof that is all polished demo and no way to verify it worked for anyone real.
A demo shows the tool succeeding on data the vendor chose. It says nothing about how it behaves on your scanned estoppels, hand-marked amendments, and non-standard leases, which is where these systems break. Claims of “99% accuracy” belong here too: accuracy on standard fields like parties and base rent is genuinely high across the industry, but it drops on the unusual clause that carries the risk, so a headline number is a claim about the easy fields.
What you want instead is a reference and a pilot: a firm like yours you can call, and the vendor running the tool on a set of your real, messy documents while someone who knows the work checks the output. The vendor-side signals to weigh are collected in the AI vendor evaluation checklist for CRE principals. A demo is the start of diligence, not the end.
Reading the whole proposal in twenty minutes
You do not need a technical background to pressure-test a proposal. Run it against the eight questions, in order, and note where the document goes quiet.
- What does this beat? If the off-the-shelf alternative is not named and dismissed for a reason, stop here.
- Is the scope about my workflow or their technology? Count the sentences.
- Can I test every deliverable? Each needs an output, a standard, and a sign-off.
- What do I own at the end? The account, code, and data, or none of them.
- Does the price map to the market? Not 3x high, not suspiciously low.
- Is maintenance priced? Who fixes it, how fast, at what cost.
- Is my confidential data handled? Where it goes, who sees it, whether it trains a model.
- Is the proof a reference and a pilot, or just a demo?
A strong proposal answers all eight without you having to dig. The pattern that should make you walk is not one weak answer; it is a proposal that goes quiet on ownership, maintenance, and the baseline it is meant to beat, because those three silences together describe a build you will pay for twice and cannot run without the vendor.
Frequently asked questions
What are the biggest red flags in an AI project proposal?
The most expensive is a proposal to custom-build something an existing subscription already does, which shows up as a scope that never names the off-the-shelf alternative it is beating. Close behind: deliverables with no acceptance test, no answer on who owns the account and code, no maintenance line, a price that does not map to market ranges, silence on confidential-data handling, and proof that is a polished demo rather than a reference you can call and a pilot on your own documents.
How do I know if a custom AI build is even necessary?
Ask the vendor what the cheapest existing tool does and why it is not enough. Off-the-shelf proptech like Dealpath, Prophia, and Buildout, plus general assistants like ChatGPT or Claude used with saved prompts, covers a large share of common CRE tasks at subscription cost. A custom build earns its price only when a repeatable, high-volume workflow has no off-the-shelf fit, usually because it depends on your document formats or must write into a system no vendor integrates with.
What is a fair price for a custom AI automation project?
In the current market a scoped custom automation project generally runs $25,000 to $150,000 depending on complexity, and a focused team workshop runs roughly $2,000 to $15,000. A single-workflow automation sits near the bottom of the build range; a multi-system build that writes into your accounting software sits higher. Three times the market for a modest job is a red flag, and so is a number far below it, because a cheap quote usually has the maintenance and edge-case handling stripped out.
Why does maintenance matter so much in an AI proposal?
Because the failure usually happens after the build, not during it. Gartner has projected roughly 30% of generative-AI projects are abandoned after the proof of concept, and most pilots never reach durable daily use. Formats change, models update, and edge cases appear, so a tool that worked at launch starts returning wrong answers confidently. A firm with no engineer cannot diagnose that, so a proposal without a maintenance line, a support commitment, and a fix-it plan is quoting half the real cost of ownership.
Who should own the code and data at the end?
Your firm. The code and configuration you paid to build should sit in a repository your firm controls, so another developer could run it. The AI should call ChatGPT, Claude, or Gemini through an account your firm owns, not the vendor’s. And the output, your extracted lease fields and normalized rent rolls, is your asset and should live somewhere you control. A proposal that leaves any of these with the vendor is selling a subscription to that vendor’s continued existence, not an asset you keep.
How do I protect confidential deal data when I hire an AI vendor?
Confirm three things in writing before signing. The tool should run on a business-tier account where inputs are not used to train anyone’s model by default, on an account your firm controls. You should know exactly where your data goes when the tool processes it and which third-party services can see it. And nothing containing tenant financials or draft agreements should leave your control without explicit sign-off. A vendor who handles confidential data answers these plainly.
What should acceptance criteria look like?
Each deliverable should name a concrete output, the standard it must meet, and who signs off. “An AI lease-abstraction system” fails all three. “A tool that extracts fifteen named fields from a lease PDF and matches a human abstractor on parties, dates, and base rent across twenty of your real leases, verified by your analyst” passes. Acceptance criteria are the written standard that decides whether the thing works, and a vendor who resists putting them on paper is signaling low confidence.
Is a large upfront deposit a red flag?
A big deposit with the balance due on vague “completion” shifts the risk onto you and gives the vendor little reason to finish well. The healthier structure ties payments to accepted milestones, so money moves as verified work lands. A deposit itself is normal; a payment schedule with no milestones and no acceptance gates is the flag. Pair that with the pricing model, fixed-price versus time-and-materials, to understand who absorbs an overrun before you sign.
Where to start
A weak proposal is easy to spot once you know the eight questions, but the harder problem sits upstream: most firms cannot tell whether they need a custom build, an off-the-shelf tool, or a month of getting fluent first, and a proposal cannot answer that, because the vendor writing it has a preferred answer. A free AI-readiness assessment produces an honest read: a short working session that maps your workflows, your document mix, and your team’s current fluency, and returns a recommendation for what you actually need before any vendor quotes it. Book a free AI-readiness assessment before you sign a proposal, not after.
Arthur Wandzel