Real Estate 11 min read

The knowledge your brokerage gives away: private AI, data ownership, and the new rules of client confidentiality.

Twenty states now enforce comprehensive privacy laws, AI statutes are live in Texas, California, and Utah, and a federal court has held that consumer AI chats carry no expectation of confidentiality. A guide for brokerage operators, from one.

The Short Answer

Brokerages that feed client information into consumer-grade AI tools are taking on fiduciary, regulatory, and competitive risk most operators have not priced. Twenty states now enforce comprehensive privacy laws, AI-specific statutes are live in Texas, California, and Utah, and a federal court has held consumer AI chats carry no expectation of confidentiality. The alternative: treat your knowledge as an owned asset.

Somewhere today, an agent on your team is pasting a client's pre-approval letter, negotiation ceiling, or divorce timeline into a free AI chatbot to save twenty minutes.

They are not being reckless. They are being efficient. The tools are genuinely good, and the productivity gains are real. But that prompt just left your brokerage, landed on a third party's servers, and depending on the tool and the plan tier, may now be retained, reviewed, and used to train a model that your competitors also use.

Most brokerage owners have thought hard about commission structures, splits, and lead spend. Almost none have thought about what happens to the two most valuable things they own: their clients' confidential information and their company's accumulated intelligence. Both are walking out the door daily, and the legal environment around that leak is tightening fast.

This article covers three things: why your brokerage's institutional knowledge is an asset and should be managed like one, what actually happens to data inside third-party AI tools, and the specific laws, cases, and regulatory guidance now shaping the risk. It closes with a practical playbook.

The asset nobody puts on the balance sheet

A brokerage's most durable asset is not its logo, its office lease, or even its agent roster. It is the accumulated judgment of the operation: a decade of pricing decisions and the reasoning behind them, negotiation histories on hundreds of transactions, the vendor network that actually performs, the objection patterns that kill deals in your specific market, the comp analyses, the inspection war stories, the knowledge of which streets flood and which HOAs fight.

Accountants call this an intangible. Most operators call it nothing at all, because it has never been written down. It lives in the heads of your top producers, in ten thousand email threads, and in transaction folders nobody will ever reopen.

That creates two problems.

First, the asset depreciates every time someone leaves. When a fifteen-year veteran retires or a rainmaker jumps to a competitor, the institutional memory goes with them. You did not lose an employee. You lost an uninsured asset, and your remaining team starts rebuilding it from zero.

Second, unmanaged knowledge cannot compound. A new agent at a knowledge-driven brokerage should be able to ask "what did we learn the last six times we sold on this street" and get an answer in seconds. At most brokerages, the answer exists but is unreachable, so every agent relearns the market at the client's expense.

Operators who treat company knowledge as an asset behave differently. They capture it, structure it, control access to it, and put it to work. And critically, they think hard before handing it to someone else's model. Because here is the uncomfortable version of the AI trade most teams are making: you pay a monthly subscription to rent intelligence, and depending on your plan tier, you pay a second time by contributing your data to an asset the vendor owns.

You are the customer and, on consumer tiers, part of the product.

Where your data actually goes when agents use "free" AI

The core distinction every broker needs to understand is plan tier, because the same brand name can carry radically different data terms.

Consumer tiers (free and individual paid plans). On standard consumer plans of the major AI platforms, user inputs may be used to train and improve models, and even where a user opts out of training, the provider can still retain data and disclose it when legally required. Opting out limits training. It does not create confidentiality. Legal analysts reviewing the major providers' consumer terms have concluded there is no enforceable expectation of confidentiality on standard consumer plans.

That conclusion is no longer theoretical. In United States v. Heppner, decided February 10, 2026 in the Southern District of New York, the court held that documents created using the consumer version of a major AI assistant were protected neither by attorney-client privilege nor as work product. The court leaned heavily on the platform's consumer terms of service, reasoning that users assumed the risk of disclosure when they agreed to them. The case involved legal privilege, not real estate agency, but the underlying logic travels: if the terms of service say the conversation is not confidential, courts are prepared to take the vendor at its word. A brokerage arguing it protected client confidences while routing them through a consumer chatbot is arguing against its own vendor's contract.

Enterprise tiers and APIs. Business-grade offerings from the major providers are a different animal. They typically exclude customer data from model training by default, come with data processing agreements, and carry express contractual confidentiality commitments. This is exactly why legal and compliance advisors now draw a bright line: enterprise-grade tools with no-training commitments for anything touching client information, consumer tools for nothing sensitive at all.

The shadow AI problem. The gap between those two tiers is where brokerages get hurt, because employees default to whatever is fastest. Security telemetry analyzed in 2025 found that roughly 17 percent of enterprise sensitive-data exposures occurred through personal free-tier AI accounts invisible to company IT. IBM's 2025 Cost of a Data Breach research found that breaches involving unapproved "shadow AI" tools added an average of $670,000 to total breach costs. A brokerage with thirty agents on personal ChatGPT and Claude accounts has thirty unmanaged data exits, and the broker-in-charge is accountable for every one of them.

Dimension Consumer AI Enterprise AI Private AI
Model training on your inputs Possible by default; opt-outs limit training but not retention. Excluded by default under business terms. Never. No outside model ever sees your data.
Confidentiality None enforceable. Courts have taken vendors' consumer terms at their word. Contractual commitments plus a data processing agreement. Structural. Data never leaves your ownership boundary.
Where data lives Vendor servers, vendor retention schedule. Vendor infrastructure, contractually governed. Hardware and systems your company controls.
Legal process exposure Vendor may disclose when legally required; you may never know. Reduced and contractually managed, but the vendor still sits between you and your data. Any demand comes to you, with your counsel responding.
Who owns the compounding asset The vendor. Shared at best. Your usage improves their product. You. Knowledge compounds as your equity.

Fiduciary duty did not get an AI exception

Real estate licensees owe clients a defined set of fiduciary duties. Loyalty, obedience, disclosure, accounting, reasonable care, and the one this article turns on: confidentiality. The duty of confidentiality covers anything that could weaken a client's position if revealed, including financial capacity, motivation, urgency, negotiation strategy, and personal circumstances. In most states it survives the closing and continues after the agency relationship ends.

The NAR Code of Ethics makes the same point in writing:

NAR Code of Ethics · Article 1, Standard of Practice 1-9
"The obligation of REALTORS® to preserve confidential information (as defined by state law) provided by their clients in the course of any agency relationship or non-agency relationship recognized by law continues after termination of agency relationships or any non-agency relationships recognized by law."
NAR Code of Ethics and Standards of Practice

Now run the everyday AI workflow through that standard. An agent pastes a buyer's full financial picture and maximum price into a consumer chatbot to draft an offer summary. On consumer terms, that information may be retained by a third party, potentially used for model training, and disclosable in response to legal process. No client authorized that transmission. Commentators in both the U.S. and Canada have begun calling this exactly what it looks like: a compliance crisis arriving in slow motion, where fiduciary duty exists independent of any AI-specific regulation and does not pause because the tools got more capable.

State regulators are catching up. NAR's legal reporting tracked state real estate regulator guidance in late 2025 that laid out ground rules for AI use in brokerage practice: licensees remain responsible for their conduct when using AI, must avoid misleading or inaccurate AI-generated content, and must protect consumer privacy and confidential information when using AI tools.

The message from license law is consistent with the message from agency law: the tool is new, the duty is not.

For brokers-in-charge and team leaders, there is also a supervision layer. License law in most states holds the broker responsible for the acts of affiliated licensees. If your agents are moving client data through unvetted tools and you have no policy, no approved-tool list, and no training, the exposure concentrates at the top.

The law is moving faster than most brokerages realize

For years, "check with your attorney" was the beginning and end of AI compliance advice in real estate. In 2026 there is an actual body of law to check.

State privacy laws: twenty and counting

As of 2026, twenty states have comprehensive consumer privacy laws in effect, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026. A second wave enacted in 2026, including Alabama, Louisiana, Oklahoma, and Vermont, pushes the total number of enacted laws to roughly two dozen, with effective dates rolling through 2027.

These laws give consumers rights over personal data (access, deletion, correction, opt-out) and impose duties on businesses that meet coverage thresholds. Thresholds vary widely: Rhode Island's applies at just 35,000 consumers. And enforcement has real teeth now. Reported fines and penalties against U.S. companies reached an estimated $1.4 billion in 2025, California's privacy agency has set successive settlement records, and Texas secured a settlement exceeding $1 billion under its Data Privacy and Security Act.

North Carolina, notably, still has no comprehensive privacy statute. That is not a free pass for Carolinas brokerages. Relocation clients arrive from covered states, referral networks cross state lines, and the fiduciary duty of confidentiality applies everywhere regardless of privacy legislation. Multi-state teams and national franchise networks should assume at least one comprehensive privacy law reaches them today.

AI-specific statutes now in force

The AI-specific layer is newer and moving quickly:

The federal wildcard

A December 2025 executive order directed federal agencies to evaluate state AI laws for preemption, and a proposed federal framework followed in early 2026. NAR has formally advocated for exactly that outcome: one national standard for data privacy and AI governance instead of a fifty-state patchwork, so members are not exposed to inconsistent liability across jurisdictions. Nothing is settled. No federal preemption has been enacted, and the patchwork is the operating reality for the foreseeable future. Plan for the patchwork, and treat any future federal standard as an upside surprise.

Fair housing, the constant

Layered over everything is the Fair Housing Act. AI tools that touch advertising audiences, lead scoring, or tenant screening can produce discriminatory outcomes at scale, and NAR has pressed federal agencies for clear rules of the road precisely because liability currently sits with the licensee using the tool, not the vendor that built it.

Your listings are training someone else's model

There is a second data-ownership fight running in parallel, and it is about your inventory rather than your clients. Listing content, photography, property descriptions, and MLS data are being scraped and used to train AI models, generally without licensing or compensation. NAR has made copyright protection for listing content a federal advocacy priority and has backed legislation aimed at protecting real estate content used in AI training.

For an operator, the lesson generalizes: in the AI economy, proprietary data is the scarce input. Everyone building models wants what you have. The market analyses you publish, the transaction records you hold, the hyperlocal knowledge you have accumulated: these are exactly the inputs AI companies spend billions to acquire. Which raises the obvious question. If your data is valuable enough for others to want it, why are you giving it away through the side door of consumer chatbot prompts?

The operator's playbook: own the vault

None of this argues against AI. The productivity gains are real, and brokerages that refuse the technology will lose to brokerages that deploy it well. The argument is about the terms on which you adopt it. Five moves, in order:

  1. Write an AI use policy this quarter, not this year. Define what may never enter a third-party tool: client financials, negotiation positions, personal circumstances, anything covered by the duty of confidentiality. Name the approved tools and tiers. Ban client data in personal accounts outright. NAR publishes a customizable AI policy template through its associations if you need a starting point. A one-page policy you enforce beats a ten-page policy you don't.
  2. Upgrade every AI seat to business terms. If your team uses cloud AI tools, use enterprise or team tiers where customer data is excluded from training by default, and get a data processing agreement in writing. The cost difference is trivial next to the exposure difference. Treat "which tier are we on" as a compliance question, not an IT question.
  3. Move the crown jewels onto infrastructure you control. Enterprise cloud tiers reduce risk. Private AI eliminates a category of it. A private, on-premises or dedicated AI knowledge base, running on hardware and infrastructure your company owns, lets you put your transaction archives, pricing rationale, negotiation playbooks, and client intelligence to work without any of it crossing a third party's boundary. No training exposure, no terms-of-service dependency, no vendor's legal process obligations sitting between you and your clients' confidences. It is the difference between renting intelligence by the token and owning a compounding asset.
  4. Ask vendors the uncomfortable questions. For every AI-enabled tool in your stack, including transaction management, CRM, and marketing platforms quietly adding AI features: Is our data used to train your models or anyone else's? Where is it stored and for how long? Can you delete it on demand and prove it? Will you sign a DPA? Who is liable when your tool gets it wrong? Vendors with good answers put them in the contract. Vendors with vague answers just answered.
  5. Think like an owner, not a renter. The brokerages that win the next decade will be the ones whose institutional knowledge compounds: captured from every transaction, structured, queryable by every agent, and owned outright. That is an asset that survives agent turnover, raises the floor for new agents, deepens client service, and shows up in enterprise value if you ever sell. Subscription AI is an expense. Owned knowledge infrastructure is equity. Operators who understand the difference will build it deliberately.

The same logic is reshaping every knowledge profession right now. For the parallel analysis in law, wealth management, and tax practice, see our posts on Rule 1.6(c) and law firm confidentiality, the RIA books-and-records rule, and IRC §7216 for CPA firms.

Primary Sources

Additional references cited in this article include NAR's AI advocacy hub and Legal Research Center reporting, IBM's Cost of a Data Breach Report 2025, MultiState's 2026 state privacy law tracker, and AI law updates from Baker Botts, Cooley, Fasken, and Bryan Cave Leighton Paisner.

Frequently asked questions

Is it illegal for a real estate agent to put client information into ChatGPT or Claude?
No statute flatly prohibits it. But entering confidential client information into a consumer-tier AI tool likely conflicts with the fiduciary duty of confidentiality, NAR Code of Ethics Standard of Practice 1-9, and state license law, and may implicate state privacy statutes depending on the data and the client's home state. A 2026 federal court decision confirmed consumer AI conversations carry no enforceable expectation of confidentiality. Enterprise tools with no-training commitments, or private AI infrastructure, are the defensible path.
What is the difference between consumer AI, enterprise AI, and private AI?
Consumer AI (free and individual paid plans) may use your inputs for model training and offers no contractual confidentiality. Enterprise AI excludes your data from training by default and adds contractual protections, but your data still transits and rests on the vendor's infrastructure. Private AI runs on hardware and systems your company controls, so client data and institutional knowledge never leave your ownership boundary.
What laws apply to a brokerage's use of AI in 2026?
Layered obligations: fiduciary duty and state license law (everywhere), the NAR Code of Ethics (for REALTORS), comprehensive privacy laws in twenty states and counting, AI-specific statutes in Texas, California, and Utah with Colorado's automated-decision law arriving January 2027, and the Fair Housing Act over all of it. A federal preemption effort is underway but nothing has replaced the state patchwork.
Does the duty of confidentiality end at closing?
No. Under the NAR Code of Ethics and most states' agency law, the obligation to preserve confidential client information continues after the agency relationship ends. Historical transaction files are not fair game for consumer AI tools just because the deals closed years ago.
What is institutional memory worth to a brokerage?
It is the difference between a business and a collection of independent contractors sharing a sign. Pricing judgment, negotiation history, vendor networks, and market pattern recognition are what make a brokerage's service defensible, and they are a meaningful component of enterprise value in a sale. Unmanaged, that knowledge walks out with every departing agent. Captured in owned infrastructure, it compounds.
Should small teams care, or is this a big-brokerage problem?
Small teams arguably have more at stake. A ten-agent team's competitive edge is almost entirely knowledge and relationships, the exact assets leaking through consumer AI tools, and a single confidentiality complaint or privacy claim is more damaging at that scale. The fixes (a written policy, business-tier tools, owned knowledge infrastructure sized to the team) are all accessible to small operators.

Mitch Boraski

Co-Founder of Deepvine AI and a practicing luxury real estate broker. Deepvine installs private AI knowledge systems for brokerages, law firms, RIAs, CPA firms, and other knowledge-driven businesses: connected to your systems, backfilled with your history, deployed in your environment, and owned by you.

This article is for general information and is not legal advice. AI regulation is changing rapidly; consult a licensed attorney in your state before making compliance decisions.

Private AI for Brokerages

Own the vault. Compound the knowledge.

Deepvine deploys a private AI knowledge system in your brokerage's environment: transaction archives, pricing rationale, negotiation playbooks, and years of market intelligence, answerable in Slack with source-backed citations. Client confidences never leave your control.

Bring us one real question about your market. We will show you where the answer comes from.