Your Team Is Using AI. Do They Know What They’re Not Allowed to Do With It?
Your leasing staff is already using AI. So are your regional managers, your property accountants, probably your maintenance coordinators. Some of that use is fine. Some of it is creating exposure you can’t see. And almost none of it is governed by a written policy that tells anyone what they’re allowed to touch, what they’re not, and what happens when something goes wrong.
The tools arrived before the rules did. ChatGPT, Copilot, AI summarizers, AI writing assistants — they’re already in the workflow across your portfolio. Nobody waited for approval. Nobody asked. That’s not a criticism. It’s how useful technology spreads, and honestly, it’s how every useful technology has always spread inside property operations. But at some point, the absence of rules stops being an oversight and starts being a liability.
What’s pushing this conversation to a head right now isn’t AI adoption. Adoption already happened. What’s pushing it is the board member who asked your CFO what the company’s AI policy looks like. The insurer who added AI governance to the renewal questionnaire. The compliance officer who sat through a shadow AI presentation and recognized half of what she heard.
A policy isn’t bureaucracy. It’s the structure that lets your team use AI productively without creating liability every time they open a browser tab. This post covers why you can’t wait on it, and what a property management AI policy actually has to contain to do the job.
Why Now? The Ground Just Shifted Under You.
Several things happened in a short window that turned AI governance from a future consideration into a present one.
In May 2024, HUD issued formal guidance on AI in tenant screening and housing advertising. The guidance makes one thing explicit: the Fair Housing Act applies whether you wrote the algorithm or just use it.
If an AI tool your team uses produces a discriminatory outcome in a screening or advertising context, your organization carries the liability, not the vendor. The guidance names housing providers, tenant screening companies, advertisers, and online platforms as all subject to FHA enforcement when AI is involved. Most operators haven’t read it. Their attorneys have.
Shadow AI is already in your operation whether you’ve addressed it or not. KPMG’s 2025 global study, 48,000 respondents across 47 countries, found that nearly half of employees admit to using AI in ways that violate company policy – and 46% have uploaded sensitive company information to public AI platforms. Only 40% say their workplace has any policy or guidance on generative AI at all. In property management, the data moving through those unauthorized tools includes SSNs, income documents, credit reports, and for senior living operators, resident health information. Nobody flagged it. Nobody approved it. It just happened.
Boards and insurers are asking about this now. What had been a forward-looking governance question is showing up on renewal questionnaires, board agendas, and acquisition due diligence checklists. The operators who can answer it clearly are ahead. The ones who can’t are carrying a named risk with no documentation to show they addressed it.
Research from Articulate and McKinsey puts 88% of employees using generative AI regularly for at least one business function. Most of their employers have given them no rules to work with. That gap between adoption and governance is where exposure lives.
What It Looks Like When Nobody Has the Same Rules
Without a policy, you don’t have chaos. You have drift. Every site, every team, and every role is making its own call about which tools to use, what data to put into them, and when a human needs to be in the loop. We see this constantly across property portfolios. The decisions aren’t consistent, they aren’t documented, and they aren’t defensible.
A leasing agent at one property is using a free AI tool to summarize applications. Her counterpart at the property across town isn’t. The regional manager drafting renewal language runs it through ChatGPT. The maintenance coordinator uses a different AI tool entirely for vendor communications. Nobody has the same rules. Nobody’s handling data the same way. And if a fair housing complaint or a data incident surfaces, there’s no documentation showing the company had any standards in place.
The shadow AI layer compounds this. You already have employees using tools nobody approved, processing data nobody authorized, on platforms with no data agreement in place. Without a policy there’s no approved-tool list to compare against, no accountability structure, and no mechanism to surface what’s already happening.
A policy doesn’t fix all of this overnight. But it creates the baseline, a named list of what’s allowed, clear rules on what data can be touched, and something to point to when the question comes up. Without it, you’re defending decisions nobody made.
A Good AI Policy Does Two Jobs, and Most Only Do One
Here’s where most property management AI policies fall short. They get written by the compliance team or drafted from a Fair Housing framework, and they address the Fair Housing governance half in solid detail human review requirements, disparate impact testing, documentation of automated decisions. All of that is necessary and correct.
The half that gets underweighted is data security and approved-tool governance. Which specific tools are cleared for use. What data can never be entered into an AI system. How accounts are provisioned. Who has access to what. What happens when an employee uses a personal account. What monitoring looks like. How the policy gets enforced when someone steps outside it. This is the half the multifamily compliance crowd skips, and it’s the half where resident PII walks out the door.
A policy that covers only Fair Housing leaves your resident data exposed. A policy that covers only data security leaves your housing decisions legally vulnerable. Both halves need to be present and built together. Most operators end up with one. That’s a half-policy.
What a Property Management AI Policy Actually Needs to Include
Seven components make up the minimum viable structure for a policy that actually protects a property management company. Think of this as the inventory your policy needs to cover before you can call it done.
What a Property Management AI Policy Needs to Cover
- Approved tools: A specific list of AI applications cleared for work use, with the corresponding use cases each tool is approved for. Everything not on the list is off-limits by default. A named list, updated on a defined schedule.
- Approved data: An explicit definition of what can and cannot be entered into any AI tool. Resident PII, application financials, income documentation, credit information, health records for senior living properties, and anything regulated are all off-limits in unsanctioned tools. Named categories, not a general statement.
- Use cases: Where AI is permitted, where it’s restricted, and where it requires human sign-off before output becomes an action. Drafting maintenance communications is different from generating screening language. The policy draws those lines explicitly.
- Human-review thresholds: Which decisions can’t be fully automated and what documented review looks like before AI-assisted output becomes an action. Anything touching housing eligibility, screening, pricing, or resident communications is high-risk. The policy names which categories trigger mandatory human review.
- Account and access rules: Company-provisioned accounts only. No personal ChatGPT or Claude accounts. No shared credentials. No using AI tools on personal devices to process work data. This needs to be explicit because employees default to personal accounts when no company account has been set up.
- Acknowledgement and training: Who receives the policy, who signs off, what training is required before an employee is authorized to use any approved tool, and how often that training refreshes. A policy nobody has read won’t hold up.
- Ownership and review cadence: Who keeps the policy current as tools change and guidance evolves. The approved-tool list needs a named owner. The review schedule needs to be written in. Without both, the policy is accurate on day one and unreliable by month six.
The next two sections break out the Fair Housing half and the data security half in more detail, because each has components specific to property management that are easy to underweight.

The Fair Housing Half: Where AI Decisions Need a Human
HUD’s May 2024 guidance was direct: the Fair Housing Act applies to AI-assisted tenant screening and housing advertising. Disparate impact, when a neutral-seeming tool produces outcomes that disproportionately disadvantage a protected class, can violate the law without any discriminatory intent. The algorithm doesn’t have to be malicious to be illegal. That’s the part most operators haven’t fully absorbed yet. For your policy, the Fair Housing half needs to name specific governance requirements, not just state a commitment to compliance.
Human-review thresholds are the core of it. Any AI-assisted output that affects a housing decision — screening scores, eligibility determinations, pricing recommendations, renewal decisions, needs documented human review before it becomes an action. The policy names which decision categories trigger this requirement and what that review looks like in practice.
Override documentation matters just as much. When a human reviewer overrides an AI recommendation, that decision needs to be logged: why the override was made and who made it. That documentation is the audit trail that protects the organization if a decision gets challenged later.
Escalation paths need to exist and be defined before anyone needs them. When an AI-assisted workflow surfaces something the system can’t handle, a reasonable accommodation request, a complex eligibility question, any scenario touching a protected class characteristic, there has to be a clear path to a human with the authority to make the call. The policy names that path.
Audit triggers close the loop. A fair housing complaint is the obvious trigger for a review of AI-assisted decisions. But a pattern of outcomes at a specific property, a vendor model update, or a new state law are all legitimate triggers too. The policy defines what those are and who initiates the review.
Most AI vendor agreements place the compliance obligation squarely on the housing provider. Signing a contract with an AI screening vendor doesn’t transfer your Fair Housing liability. Your policy has to govern how you use their tool, not just whether you use it.
The Data-Security Half: What Your Team Can Never Put Into AI
The data security half is where most multifamily compliance frameworks stop short. Fair Housing training covers the bias and discrimination risk. Almost nothing covers what happens when a leasing agent pastes an applicant’s income documents into a free AI summarizer because it’s faster than reading through three pay stubs manually. That scenario plays out across property portfolios every day, and nobody is flagging it.
The approved-tool list is the foundation. Employees can only use AI tools that appear on a company-maintained list, specific applications, the use cases each is approved for, and the data classification each tool is permitted to handle. Any tool not on the list is off-limits for work use, regardless of how useful it looks.
The prohibited-data list has to be equally specific. The policy names the categories of information that can never be entered into any AI tool, approved or otherwise, without explicit security review:
- Resident PII: names, SSNs, dates of birth, contact information
- Application financials: bank statements, pay stubs, tax returns, income documentation
- Credit and background check results
- Health and care information for senior living residents
- Lease terms, pricing strategy, or confidential vendor agreements
- Any data subject to state or federal privacy regulation
One pasted document is the exposure. A leasing agent summarizing an application in a free personal AI account has just sent resident financial data to a system with no data retention limits, no data processing agreement, and no audit trail. The organization has no record it happened. If that data surfaces elsewhere or the resident requests its deletion under a state privacy law, the company has nothing to account for it with.
Account and access rules close the loop. Company-provisioned accounts for all approved tools. No personal accounts for work-related AI activity. No processing work data on unmanaged personal devices. These rules sound obvious until you realize most employees are already using their personal ChatGPT account because nobody set up a company one.
How Do You Actually Enforce an AI Policy?
A policy sitting in a shared drive folder, acknowledged once during onboarding, protects no one. We see this pattern constantly. The document exists. Nobody can find it. Nobody remembers what’s in it. And when something happens, the organization discovers that having a policy written down and having a policy in practice are two different things.
The rollout matters as much as the document. Sending a PDF via email and assuming it landed is the approach that won’t hold up. The policy needs to be introduced with context, why it exists, what it’s protecting against, why the specific rules are what they are. Employees follow rules they understand. They route around rules that feel arbitrary or disconnected from the actual work.
Role-specific training lands better than generic training. A leasing agent’s AI risk profile is different from a regional manager’s, which is different from a corporate finance employee’s, and training that covers AI policy in the abstract misses the actual scenarios each role encounters. Walk through the specific situations. Show what the policy requires in each one. That’s what gets retained.
Signed acknowledgement creates accountability on both sides. Every employee covered by the policy should sign off that they’ve received it, read it, and understand it. That documentation matters when enforcement is needed and creates a clear record that the organization met its obligation to inform staff.
Technical enforcement is what makes the policy enforceable rather than aspirational. Monitoring which AI tools are accessed on company networks, deploying approved tools that reduce the pull toward unsanctioned ones, building visibility into where data is going, these are the infrastructure layers that close the gap between what the policy says and what employees actually do. Without them, you’re relying entirely on self-reported compliance with rules people may not remember.
A Policy Isn’t Done When It’s Written
The AI tool landscape changes faster than any policy document can keep up with passively. A policy written today and reviewed a year from now is already outdated. The approved-tool list that was accurate in January may have three tools on it that changed their data retention terms, two that were acquired, and one the vendor sun-setted entirely. If nobody is tracking this, your employees are operating against rules that no longer reflect reality.
HUD guidance will keep developing. State-level AI legislation is moving faster than federal – Colorado, Illinois, and California have all passed or are advancing laws that specifically regulate automated decision systems in employment and housing contexts. What’s compliant under federal guidance today may fall short of a state requirement by next quarter. The policy needs someone tracking this and updating the document when it matters.
Review cadence should be written into the policy itself. At minimum, an annual review of the full document and a quarterly check on the approved-tool list. Any significant development, a new HUD notice, a state law taking effect, a major vendor change, should trigger an unscheduled review.
The harder question is who owns this. Most property management companies don’t have an internal IT governance function or a compliance officer whose scope includes AI, so the policy gets written by whoever had the bandwidth at the time and then it sits, nobody updates the tool list, nobody tracks the regulatory changes, nobody pulls the document out when a vendor announces a model update that might affect fair housing outcomes. That’s not a failure of intent. It’s a resource gap.
That ownership gap is where most property management AI policies actually fail. Getting the policy written is step one. Keeping it current is the ongoing job, and most operators don’t have someone assigned to it.
A Clear Policy Is What Lets Your Team Actually Use AI
A written AI policy doesn’t slow your team down. It answers the question every employee is currently solving on their own, every time they open a new AI tool: is this allowed? What can I put into it? Does someone need to review the output before I use it?
Without a policy, employees either avoid AI out of uncertainty or use it without guardrails and create exposure you can’t see. Neither outcome serves the operation. When the decisions about what’s allowed have already been made and written down, your team can move faster with confidence because they’re not guessing anymore. That’s the actual value.
The two halves of the policy, Fair Housing governance and data security, address different exposure surfaces and both need to be present. Fair Housing governance without data security leaves your resident information and audit trail exposed. Data security without Fair Housing governance leaves your housing decisions legally vulnerable. A policy that covers both is the one that holds up.
Using AI without rules is where the exposure comes from. A policy is how you close that gap and let the tools do their job.
Need Help Building the Policy Your Property Company Can Actually Use?
Most property management companies don’t have the internal IT or governance resources to build both halves of an AI policy from scratch, keep the approved-tool list current, track regulatory developments, and enforce what they’ve written. That’s the gap Far Out Solutions fills.
We work with multifamily and CRE operators on the security and usage side of AI governance: mapping what tools are already in use across the portfolio, building the data classification and approved-tool framework, setting up account and access controls, and keeping the policy current as tools and guidance change. That’s the half most operators can’t maintain on their own.
We’re not a compliance guarantor. We’re the partner that gets you protected and audit-ready, with the infrastructure and documentation to back it up when it matters.
If your board has asked, your insurer has asked, or you’ve had the shadow AI realization and you’re ready to put the rules in place, reach out. We can start with a Property Technology Assessment to map what’s in use and build from there.