Your firm already has a shadow-AI problem. The only question is whether you know its shape. Somewhere on your team right now, a broker is pasting a lease into ChatGPT to get a summary, an analyst is asking it to clean up a rent roll, and an assistant is drafting a tenant email with it, all on personal accounts you never approved and cannot see. This is not a hypothetical about firms larger than yours. MIT’s 2025 study of enterprise AI found that employees at more than 90% of companies use personal AI tools for work, while only about 40% of those companies have any official subscription in place. The gap between those two numbers is shadow AI, and at a small brokerage it is almost total, because there is no IT department standing between the team and the app store. The mistake most owners make is treating this as a problem to stamp out. It is closer to a resource you have not organized yet.
Before the diagnosis, one piece of orientation. The full 90-day arc of getting a lean team fluent and governed sits in our CRE AI training playbook, and the wider argument for why a small shop can out-operate a larger one runs through the small CRE firm manifesto. This piece is narrower: it is about the specific mess of AI use that is already happening at your firm without your sign-off, why that mess is a signal rather than a threat, and what a principal does about it in a week.
What Shadow AI Actually Is at a Brokerage
Shadow AI is any use of an AI tool at your firm that you did not approve, do not oversee, and cannot see. The enterprise version of this term conjures rogue software and data-loss-prevention dashboards. At a 12-person brokerage it is far more ordinary: a broker who opened a free ChatGPT account on their own phone and now uses it for an hour a day, an assistant who runs every tenant notice through Gemini before sending, an acquisitions analyst who feeds deal memos to Claude to pull out the numbers. None of it went through you. None of it is on a firm account. And all of it touches the firm’s actual work product.
The reason it matters more at your size, not less, is that the enterprise safeguards simply do not exist here. A large firm’s shadow AI is bounded by a corporate network, single sign-on, and a security team that can at least see the traffic. Your firm has none of that infrastructure, which means the same behavior runs completely unobserved. The label “shadow” is precise: the activity is real, it is producing output that goes to clients, and it is invisible to the one person accountable for the firm’s confidentiality obligations. None of this is a sign of a bad team. People reach for these tools because the tools work, and they do it on personal accounts because no one gave them a firm one. The behavior is rational; the absence of a rule around it is the problem.
Why It Is Already Happening at Your Firm
You do not need to survey your team to know this is happening, because the industry numbers make the base rate unmistakable. The National Association of Realtors’ 2025 Technology Survey, which drew on a random sample of 49,233 active Realtors, found that 68% now use AI tools in their business, with ChatGPT the most common at 58%. Adoption at that level does not arrive through a firm rollout at shops your size. It arrives one person at a time, quietly, on whatever account each person set up for themselves.
The confidentiality exposure inside that adoption is the part owners rarely see. The CybSafe and National Cybersecurity Alliance “Oh, Behave!” report for 2024–25, built on responses from more than 7,000 people, found that 38% of AI users have submitted sensitive work information to these tools without their employer’s knowledge, while only 48% had received any training on the risks. Roughly four in ten AI users are already putting confidential material into a chatbot, and fewer than half have been told what is safe to share. At a firm handling rent rolls, unexecuted terms, and client financials, that is not a distant enterprise risk. It is the median behavior of the people down the hall.
The final number worth holding is the one about results. That same NAR survey found only 17% of Realtors report a significant positive impact from AI, and 46% see no noticeable difference. So the base case at an ungoverned firm is the worst of both: the confidentiality risk of widespread use, without the productivity return, because nobody is being trained to use the tools well or safely. Shadow AI is not a productivity win the firm gets for free. It is exposure the firm takes on for very little.
The Three Risks That Actually Matter
Strip away the enterprise vocabulary and shadow AI at a brokerage carries three concrete risks, in descending order of how much they should worry you.
Confidential data walking out the door. This is the one that can genuinely damage the firm. A personal, free-tier account often has no meaningful data controls, and the default terms on some consumer tools allow inputs to be used to improve the model. When a broker pastes a rent roll with named tenants and rents, an LOI with unexecuted terms, or a client’s financials into that kind of account, the firm has moved confidential material onto a third-party system it does not control, sometimes against an NDA it signed. Nobody did anything malicious. The rule that would have stopped it simply did not exist.
Output nobody checked. AI tools produce fluent, confident text that is sometimes wrong. An assistant who trusts a lease summary without reading the lease, or sends a market write-up with an invented comp, exposes the firm to an error with the firm’s name on it. Ungoverned use means there is no shared expectation that AI output gets verified before it goes out.
Quality that swings by person. When every broker is self-taught on a personal account, output quality depends entirely on who happened to figure the tool out. One person produces excellent first drafts, another produces sloppy ones, and the firm has no consistent standard because it never set one.
None of these three is solved by better software. They are solved by a rule, a habit, and a shared standard, all of which are owner decisions.
Why Banning It Makes the Problem Worse
The instinct, once an owner understands the exposure, is to ban it. Send an email, tell the team no ChatGPT with firm data, consider the matter closed. This is the single most common response and it reliably makes things worse, for a reason the enterprise data already showed. When a large security vendor studied firms that had blocked consumer AI tools, most of their employees kept using them anyway, just on personal devices the firm could no longer see. A ban does not remove the behavior. It removes your visibility into the behavior.
At a small brokerage the mechanism is even more direct. Your team already knows AI makes them faster, and they are not going to give that up because of a one-line email. What a ban actually does is push the exact same rent roll off a firm-controlled account and onto a personal phone, which is the worst data posture available. You have taken a governable activity and made it ungovernable, while telling yourself the problem is handled. A ban also forfeits the upside: the firms pulling ahead are the ones that took the demand already in the building and pointed it somewhere safe and productive, not the ones with the strictest AI email. Suppressing it is choosing to be slower and no safer.
How to Surface It Without a Witch Hunt
You cannot govern what you cannot see, and at your scale you make it visible with a conversation, not a monitoring tool. The move is an amnesty, not an audit. Tell the team plainly that AI use is fine, that you would rather know than not, and that no one is in trouble for what they have already been doing. The goal of the conversation is a simple map: who is using what, for which tasks. People will tell you, because most of them were never hiding it out of guilt; they just never had a reason to mention it.
That map is more valuable than any dashboard, because it doubles as your list of the workflows AI is already touching. The same handful surfaces at almost every firm: lease abstraction and summary, LOI and proposal drafting, market and comparable write-ups, and the daily grind of tenant and inquiry email. Those are the workflows to govern first, because they are where the confidential material and the volume both concentrate. Turning that map into an ordered rollout is exactly the “map, then contain” opening of the sequence we lay out in our AI adoption framework for small CRE firms; the map you get from the amnesty conversation is stage one already done.
The tone of this conversation decides whether it works. Run it as an investigation and people go quiet and keep their real usage hidden. Run it as an invitation and you get the honest picture you need. You are not trying to catch anyone. You are trying to see the firm clearly for the first time.
Turning Shadow Into Standard
Once the use is visible, converting it from liability to asset takes two moves, neither of which requires a technical hire.
The first is a one-page rule for confidential data. Not a policy binder, not a committee, one page that says which tools are approved, what data is fine to paste, and what data never leaves the firm. Public listings, generic prompts, and hypotheticals are safe; client names tied to financials, unexecuted terms, and anything under NDA are not. Paired with that rule is the shift off personal free accounts and onto business-tier accounts, whose settings keep firm inputs out of model training. The business tiers of ChatGPT, Claude, Gemini, and Microsoft Copilot all offer data controls that a firm handling confidential deals should treat as the baseline; confirm the current terms for whichever you standardize on, since these settings change.
The second move is fluency, and this is where the productivity that shadow AI was supposed to deliver actually shows up. The reason 17% of Realtors see a real impact and the rest do not is largely training: a self-taught team on personal accounts gets self-taught results. Structured practice on the firm’s own leases, LOIs, and market write-ups is what turns scattered dabbling into a dependable capability. That practice is also where most training goes wrong, drilling generic examples instead of the real documents, a failure mode we break down in why most AI training programs fail at real estate firms. What a session that changes behavior actually looks like, as opposed to a pleasant afternoon, is the subject of our anatomy of a great AI workshop.
The sequence matters. Surface first so you know what is happening, contain second so the confidential exposure stops, then train so the use becomes both safe and genuinely productive. Do those three in order and the shadow-AI problem inverts into the thing it always could have been: a team that was already motivated to work faster, now doing it on firm accounts, under a clear rule, with real skill.
This Is a Leadership Problem, Not an IT Problem
Every piece of writing about shadow AI aimed at large companies frames it as a security-team challenge to be met with discovery software and monitoring. That framing is useless to you, and following it would send you shopping for tools you do not need and cannot run. Your firm’s shadow-AI problem is not technical. It is a governance gap, and governance gaps are closed by the person in charge, not by a piece of software.
That is the good news hiding in the diagnosis. You do not need budget, a security stack, or a new hire to fix this. You need one honest conversation, one page of rules, a switch to business accounts, and a commitment to training the team on the work they actually do. Deloitte’s 2026 Commercial Real Estate Outlook, surveying more than 850 industry executives, still found more than a quarter of firms held back by change resistance and expertise gaps even with real technology budgets behind them. A small firm can move faster than any of them, because there is no committee between the owner deciding and the firm changing. The shadow-AI problem is not a reason to fear AI. It is the clearest sign your team is ready for it.
Frequently Asked Questions
What is shadow AI at a brokerage?
Shadow AI is any use of an AI tool at your firm that leadership did not approve, does not oversee, and cannot see. At a small commercial real estate firm it usually means brokers, analysts, and assistants using personal free accounts on tools like ChatGPT, Claude, or Gemini for real work, summarizing leases, drafting LOIs, cleaning up rent rolls, writing tenant emails, without any firm account, rule, or training around it. It matters because that ungoverned use touches confidential deal material, and at your size there is no IT department or corporate network making the activity visible the way there would be at a large firm.
Is my team already using AI without telling me?
Almost certainly, at least some of them. The National Association of Realtors’ 2025 survey of 49,233 Realtors found 68% already use AI tools, and MIT’s 2025 study found employees at more than 90% of companies use personal AI tools while only about 40% of firms have an official subscription. Adoption at small firms happens one person at a time on personal accounts, not through a formal rollout, so the safe default is to assume it is already happening. An open, no-blame conversation confirms the specifics faster than any monitoring tool.
Is shadow AI a compliance or legal problem?
It can become one, which is the reason to address it. The concrete risk is confidential data: when someone pastes a rent roll with named tenants, unexecuted deal terms, or client financials into a personal free-tier tool, the firm may have moved NDA-protected material onto a third-party system it does not control. For a business that depends on discretion, that exposure is serious even when no regulator is involved. A one-page data rule and business-tier accounts remove most of it quickly.
Should we just ban ChatGPT at the firm?
No. Banning consumer AI is the most common response and it reliably backfires. Studies of firms that blocked these tools found most employees kept using them on personal devices the firm could no longer see, which is the worst possible data posture. A ban does not remove the behavior; it removes your visibility into it, pushing the same confidential documents off any account you might have governed and onto personal phones. The productive move is the opposite: make approved use easy and safe so there is no reason to hide it.
What data is actually dangerous to paste into AI?
The dangerous category is anything that identifies a specific party tied to confidential terms: client names attached to financials, unexecuted or under-negotiation deal terms, rent rolls with named tenants and rents, and anything covered by an NDA. None of that should go into a personal free-tier account. Public listing details, generic market questions, and hypothetical scenarios are generally safe. Draw the line with a one-page rule everyone reads, paired with business-tier accounts whose settings keep firm inputs out of model training.
How do I find out who is already using it?
Ask, in a way that makes honesty safe. At a firm of 4 to 20 people you do not need discovery software; you need a short, no-blame conversation where you tell the team AI use is fine and no one is in trouble for what they have already been doing. Most people were never hiding it and will tell you what they use and for which tasks. That gives you a map of who is using what on which workflows, which is more useful than any dashboard and is the first step of governing the use.
What is the difference between a free account and a business account?
The difference that matters is data handling. Personal free-tier accounts on some consumer AI tools may use your inputs to improve the model and often lack administrative controls, so confidential material pasted there can leave the firm’s control. Business or team tiers of ChatGPT, Claude, Gemini, and Microsoft Copilot offer settings that keep firm inputs out of model training and give the owner administrative oversight, which is the baseline a firm handling confidential deal data should insist on. Standardizing on a business tier is one of the fastest risk reductions available; confirm the current terms for whichever tool you choose, since these settings change.
Do we need to hire an IT person to fix this?
No. Fixing shadow AI at a small brokerage is a leadership task, not a technical one. The whole remedy is a conversation to surface the use, a one-page rule for confidential data, a switch to business-tier accounts, and training the team on the firm’s real documents. Every one of those is an owner decision that needs no security software and no new hire. The enterprise framing that treats shadow AI as an IT-department problem does not apply at your scale, and following it would send you buying tools you cannot run.
How long does it take to get from shadow to standard?
The containment part is fast; the fluency part compounds over weeks. Surfacing the use and writing the one-page rule is a matter of days, and moving the team to business-tier accounts can happen the same week. Building dependable skill across the team takes longer, on the order of a few weeks to a couple of months of practice on actual firm work, because a habit and a shared standard take repetition to set. You can stop the confidential-data exposure quickly; the productivity that ungoverned use was never going to deliver on its own is what you build more gradually.
Where to Start
The first move is not a purchase or a ban. It is seeing your firm clearly: which tools your team already uses, on which workflows, with which confidential material at risk, and what a clear rule and a little training would change. That is exactly what a free AI-readiness assessment produces, a working session that maps your firm’s real AI use, flags the confidential-data rules you need before anyone touches another deal, and tells you honestly whether you need a full workshop, a lighter course, or just clearer rules for the tools your team already has. Book a free AI-readiness assessment and you will leave with your shadow-AI problem mapped, contained, and pointed toward the productivity it was always supposed to deliver.
Arthur Wandzel