Getting AI governance right in real estate

September 22, 2026
News On the Block

Faced with a lengthy chain of resident correspondence before a Resident Management Company (RMC) meeting, a property manager finds an AI tool that could summarise it in minutes. But before they can use it, they need approval, and if that process takes six weeks, they are unlikely to wait. Instead, they may open a free account, paste in the correspondence, and complete the task, leaving the business unaware of where that resident data has gone.

That is where AI governance can become counterproductive. Too much delay or friction can encourage employees to work around the rules and expose the business to even greater risk. A governance board that brings together the right understanding and expertise can provide effective oversight while keeping decisions moving.

Managing agents and other residential property businesses often have systems that store residents’ personal and financial information, service charge accounts, contractor bank details, leases and building-safety records. AI can take some of the repetitive administration out of managing that information, but without the right guardrails, use can expose sensitive data and create new opportunities for fraud.

Make governance a shared responsibility

AI governance should not be treated as an IT issue alone. Technology and information-security specialists have an important role, but they will not always see the wider implications of introducing a new tool.

Legal and compliance teams can assess privacy, contractual, and regulatory concerns. Finance can examine affordability, especially as more AI providers move towards usage-based pricing. HR should help shape training and consider how AI may change people’s roles, while property managers and operational leaders can explain how a tool would be used in practice.

People at different levels of the organisation also need a voice. Senior leaders can ensure that AI supports the wider business strategy, while frontline employees and middle managers are often closer to the day-to-day work, so they may also have the clearest picture of where staff are already experimenting with unofficial tools.

This does not mean bringing a large group into every discussion. Instead, firms should establish a small, permanent committee with a named chair to handle most decisions. The committee can call on specialists when necessary. That said, smaller managing agents may not need a dedicated AI board at all. Responsibility could sit within an existing risk, compliance or technology committee, provided there is clear accountability and access to operational, legal and security expertise. 

Additionally, international firms may need local groups with the authority to interpret different privacy laws or regulatory requirements. Firms with EU operations should also track the EU AI Act, which sets obligations based on how a system is used, not where the supplier sits. A central committee can still set minimum standards, maintain an approved-supplier list and share lessons across markets, while giving regional teams enough authority to make timely decisions.

When employees know who makes decisions and where to take a request, suitable tools can be approved more quickly, risks are less likely to be overlooked, and AI use is less likely to disappear into the shadows.

Match the controls to the risk

Not every AI request needs the same level of scrutiny, so implementing a tiered intake approach often makes the most sense. A simple licence request or tool that helps someone draft a presentation should not face the same approval process as a system that can read residents’ files or connect to a property accounting platform.
An approved tool used only with non-sensitive information may require a policy and budget check. A new supplier or a tool that affects internal workflows may also need IT and operational review. Anything that accesses personal data or third-party systems should receive security, legal and compliance oversight. Where personal data is involved, UK GDPR will usually require a data protection impact assessment before go-live, and the ICO’s guidance on AI and data protection sets out what to cover. Each request should explain the business need, what data the tool can access, whether the supplier can use the data to train its model, and who will check the output.

The UK Government’s Local AI team worked with nine local authorities to test AI in homelessness and temporary-accommodation services. The tool helped draft personalised housing plans and retrieve information from case notes, while housing officers remained responsible for reviewing and approving every output. The important point was not simply that AI was used. The controls reflected the task, allowing technology to reduce repetitive administration, giving officers more time for other tasks, including direct engagement with residents.

Property firms can apply the same principle by setting clear risk tiers and establishing target response times. Low-risk tools can move quickly, while legal, security and compliance teams focus on uses involving sensitive data or higher-consequence decisions.

Find a safe route to yes

Good governance should not treat every request as a choice between full approval and outright rejection. For example, a team may want to pilot an AI assistant that drafts responses using leases and resident correspondence. Giving the tool access to every block and folder would create unnecessary risk. Instead, the governance group could limit the pilot to a small set of documents, restrict the data it can access, and require a person to check every output.

Human oversight is particularly important when an output has legal or safety implications. AI may be suitable for drafting an acknowledgement or summarising correspondence, but a service charge demand, statutory notice, payment instruction or definitive statement about a building-safety obligation should remain the responsibility of a suitably qualified person. 

In addition, creating a safe route for experimentation means the approved route must be easy to understand and follow. Staff should know which AI tools are approved and what information must never be entered into a consumer service. Training should use familiar property-management scenarios, such as summarising resident correspondence or handling contractor information, rather than abstract warnings. If a tool is rejected or restricted, the governance group should explain why and offer a safer alternative where possible; otherwise, employees may simply find their own workaround. It also helps to know what staff already use. A short, no-blame disclosure window tends to surface more than an audit and gives the committee a real picture to work from.

Governance does not end at approval

Approving an AI tool is the start of the process, not the end. Suppliers can change their terms or update their models, so every approved use needs a named owner and a clear process for withdrawing access if the risks change. That only works if the firm knows where AI is in use. A simple register naming the tool, its purpose, the data it can reach, the owner and the last review date make withdrawal a task someone can act on.

Governance groups must also keep pace with emerging threats. AI can make phishing messages more convincing, personalise fraud attempts and introduce unreliable information through data poisoning. In block management, a falsified contractor email or altered payment instruction could have immediate financial consequences, while inaccurate building-safety information could put residents at risk.

Committees should regularly examine incidents, using what they learn to update policies, training and technical controls. As AI becomes part of real estate, firms that review their controls and learn from experience will be better placed to capture its benefits without allowing the risks to outpace them. The goal isn’t to build so much governance that it slows progress down. It’s to build enough trust for people to use it responsibly. Get that balance right, and governance becomes what makes safe adoption possible.

Terry Keller, CTO, MRI Software

Join our mailing list
FREE NOTB email
Get our bi-weekly email packed with the latest articles and events straight to your inbox.

© 2026 News On The Block. All rights reserved.

News on the Block is a trading name of Premier Property Media Ltd.

We use cookies to improve your experience on our site. By using our site you consent cookies.