Somewhere today, an agent on your team is pasting a client's pre-approval letter, negotiation ceiling, or divorce timeline into a free AI chatbot to save twenty minutes.
They are not being reckless. They are being efficient. The tools are genuinely good, and the productivity gains are real. But that prompt just left your brokerage, landed on a third party's servers, and depending on the tool and the plan tier, may now be retained, reviewed, and used to train a model that your competitors also use.
Most brokerage owners have thought hard about commission structures, splits, and lead spend. Almost none have thought about what happens to the two most valuable things they own: their clients' confidential information and their company's accumulated intelligence. Both are walking out the door daily, and the legal environment around that leak is tightening fast.
This article covers three things: why your brokerage's institutional knowledge is an asset and should be managed like one, what actually happens to data inside third-party AI tools, and the specific laws, cases, and regulatory guidance now shaping the risk. It closes with a practical playbook.
The asset nobody puts on the balance sheet
A brokerage's most durable asset is not its logo, its office lease, or even its agent roster. It is the accumulated judgment of the operation: a decade of pricing decisions and the reasoning behind them, negotiation histories on hundreds of transactions, the vendor network that actually performs, the objection patterns that kill deals in your specific market, the comp analyses, the inspection war stories, the knowledge of which streets flood and which HOAs fight.
Accountants call this an intangible. Most operators call it nothing at all, because it has never been written down. It lives in the heads of your top producers, in ten thousand email threads, and in transaction folders nobody will ever reopen.
That creates two problems.
First, the asset depreciates every time someone leaves. When a fifteen-year veteran retires or a rainmaker jumps to a competitor, the institutional memory goes with them. You did not lose an employee. You lost an uninsured asset, and your remaining team starts rebuilding it from zero.
Second, unmanaged knowledge cannot compound. A new agent at a knowledge-driven brokerage should be able to ask "what did we learn the last six times we sold on this street" and get an answer in seconds. At most brokerages, the answer exists but is unreachable, so every agent relearns the market at the client's expense.
Operators who treat company knowledge as an asset behave differently. They capture it, structure it, control access to it, and put it to work. And critically, they think hard before handing it to someone else's model. Because here is the uncomfortable version of the AI trade most teams are making: you pay a monthly subscription to rent intelligence, and depending on your plan tier, you pay a second time by contributing your data to an asset the vendor owns.
You are the customer and, on consumer tiers, part of the product.
Where your data actually goes when agents use "free" AI
The core distinction every broker needs to understand is plan tier, because the same brand name can carry radically different data terms.
Consumer tiers (free and individual paid plans). On standard consumer plans of the major AI platforms, user inputs may be used to train and improve models, and even where a user opts out of training, the provider can still retain data and disclose it when legally required. Opting out limits training. It does not create confidentiality. Legal analysts reviewing the major providers' consumer terms have concluded there is no enforceable expectation of confidentiality on standard consumer plans.
That conclusion is no longer theoretical. In United States v. Heppner, decided February 10, 2026 in the Southern District of New York, the court held that documents created using the consumer version of a major AI assistant were protected neither by attorney-client privilege nor as work product. The court leaned heavily on the platform's consumer terms of service, reasoning that users assumed the risk of disclosure when they agreed to them. The case involved legal privilege, not real estate agency, but the underlying logic travels: if the terms of service say the conversation is not confidential, courts are prepared to take the vendor at its word. A brokerage arguing it protected client confidences while routing them through a consumer chatbot is arguing against its own vendor's contract.
Enterprise tiers and APIs. Business-grade offerings from the major providers are a different animal. They typically exclude customer data from model training by default, come with data processing agreements, and carry express contractual confidentiality commitments. This is exactly why legal and compliance advisors now draw a bright line: enterprise-grade tools with no-training commitments for anything touching client information, consumer tools for nothing sensitive at all.
The shadow AI problem. The gap between those two tiers is where brokerages get hurt, because employees default to whatever is fastest. Security telemetry analyzed in 2025 found that roughly 17 percent of enterprise sensitive-data exposures occurred through personal free-tier AI accounts invisible to company IT. IBM's 2025 Cost of a Data Breach research found that breaches involving unapproved "shadow AI" tools added an average of $670,000 to total breach costs. A brokerage with thirty agents on personal ChatGPT and Claude accounts has thirty unmanaged data exits, and the broker-in-charge is accountable for every one of them.
| Dimension | Consumer AI | Enterprise AI | Private AI |
|---|---|---|---|
| Model training on your inputs | Possible by default; opt-outs limit training but not retention. | Excluded by default under business terms. | Never. No outside model ever sees your data. |
| Confidentiality | None enforceable. Courts have taken vendors' consumer terms at their word. | Contractual commitments plus a data processing agreement. | Structural. Data never leaves your ownership boundary. |
| Where data lives | Vendor servers, vendor retention schedule. | Vendor infrastructure, contractually governed. | Hardware and systems your company controls. |
| Legal process exposure | Vendor may disclose when legally required; you may never know. | Reduced and contractually managed, but the vendor still sits between you and your data. | Any demand comes to you, with your counsel responding. |
| Who owns the compounding asset | The vendor. | Shared at best. Your usage improves their product. | You. Knowledge compounds as your equity. |
Fiduciary duty did not get an AI exception
Real estate licensees owe clients a defined set of fiduciary duties. Loyalty, obedience, disclosure, accounting, reasonable care, and the one this article turns on: confidentiality. The duty of confidentiality covers anything that could weaken a client's position if revealed, including financial capacity, motivation, urgency, negotiation strategy, and personal circumstances. In most states it survives the closing and continues after the agency relationship ends.
The NAR Code of Ethics makes the same point in writing:
"The obligation of REALTORS® to preserve confidential information (as defined by state law) provided by their clients in the course of any agency relationship or non-agency relationship recognized by law continues after termination of agency relationships or any non-agency relationships recognized by law."NAR Code of Ethics and Standards of Practice
Now run the everyday AI workflow through that standard. An agent pastes a buyer's full financial picture and maximum price into a consumer chatbot to draft an offer summary. On consumer terms, that information may be retained by a third party, potentially used for model training, and disclosable in response to legal process. No client authorized that transmission. Commentators in both the U.S. and Canada have begun calling this exactly what it looks like: a compliance crisis arriving in slow motion, where fiduciary duty exists independent of any AI-specific regulation and does not pause because the tools got more capable.
State regulators are catching up. NAR's legal reporting tracked state real estate regulator guidance in late 2025 that laid out ground rules for AI use in brokerage practice: licensees remain responsible for their conduct when using AI, must avoid misleading or inaccurate AI-generated content, and must protect consumer privacy and confidential information when using AI tools.
The message from license law is consistent with the message from agency law: the tool is new, the duty is not.
For brokers-in-charge and team leaders, there is also a supervision layer. License law in most states holds the broker responsible for the acts of affiliated licensees. If your agents are moving client data through unvetted tools and you have no policy, no approved-tool list, and no training, the exposure concentrates at the top.
The law is moving faster than most brokerages realize
For years, "check with your attorney" was the beginning and end of AI compliance advice in real estate. In 2026 there is an actual body of law to check.
State privacy laws: twenty and counting
As of 2026, twenty states have comprehensive consumer privacy laws in effect, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026. A second wave enacted in 2026, including Alabama, Louisiana, Oklahoma, and Vermont, pushes the total number of enacted laws to roughly two dozen, with effective dates rolling through 2027.
These laws give consumers rights over personal data (access, deletion, correction, opt-out) and impose duties on businesses that meet coverage thresholds. Thresholds vary widely: Rhode Island's applies at just 35,000 consumers. And enforcement has real teeth now. Reported fines and penalties against U.S. companies reached an estimated $1.4 billion in 2025, California's privacy agency has set successive settlement records, and Texas secured a settlement exceeding $1 billion under its Data Privacy and Security Act.
North Carolina, notably, still has no comprehensive privacy statute. That is not a free pass for Carolinas brokerages. Relocation clients arrive from covered states, referral networks cross state lines, and the fiduciary duty of confidentiality applies everywhere regardless of privacy legislation. Multi-state teams and national franchise networks should assume at least one comprehensive privacy law reaches them today.
AI-specific statutes now in force
The AI-specific layer is newer and moving quickly:
- Texas (TRAIGA, HB 149), effective January 1, 2026. The Texas Responsible AI Governance Act applies to developers and deployers doing business in Texas, prohibits certain AI uses including unlawful discrimination, and offers a safe harbor for substantial compliance with the NIST AI Risk Management Framework. Penalties for uncurable violations run up to $200,000, plus daily penalties for continuing violations.
- California (AB 2013 and SB 53), effective January 1, 2026. AB 2013 requires generative AI developers to publicly disclose summaries of the data used to train their models. Read that twice: training data transparency is now a legal category. Regulators consider what goes into models important enough to legislate.
- California (SB 942, AI Transparency Act), operative August 2, 2026. Requires large generative AI providers to offer detection tools and disclosures for AI-generated content, which matters for AI-generated listing media and marketing.
- Utah (AI Policy Act), effective since May 2024. Requires businesses to disclose when consumers are interacting with generative AI, with heightened obligations for regulated professions. Licensed real estate practice is a regulated profession.
- Colorado (SB 26-189), compliance beginning January 1, 2027. Colorado repealed its sweeping 2024 AI Act before it ever took effect and replaced it in May 2026 with a narrower law governing automated decision-making technology that materially influences consequential decisions, housing among them. It requires pre-use consumer notices, explanations after adverse outcomes, and meaningful human review rights. If AI tools help score leads, screen applicants, or influence housing decisions, this is your preview of where state law is heading.
- California CPPA ADMT regulations. California's privacy agency finalized rules on automated decision-making technology, with significant-decision obligations phasing in from 2027. Housing decisions are squarely in scope.
The federal wildcard
A December 2025 executive order directed federal agencies to evaluate state AI laws for preemption, and a proposed federal framework followed in early 2026. NAR has formally advocated for exactly that outcome: one national standard for data privacy and AI governance instead of a fifty-state patchwork, so members are not exposed to inconsistent liability across jurisdictions. Nothing is settled. No federal preemption has been enacted, and the patchwork is the operating reality for the foreseeable future. Plan for the patchwork, and treat any future federal standard as an upside surprise.
Fair housing, the constant
Layered over everything is the Fair Housing Act. AI tools that touch advertising audiences, lead scoring, or tenant screening can produce discriminatory outcomes at scale, and NAR has pressed federal agencies for clear rules of the road precisely because liability currently sits with the licensee using the tool, not the vendor that built it.
Your listings are training someone else's model
There is a second data-ownership fight running in parallel, and it is about your inventory rather than your clients. Listing content, photography, property descriptions, and MLS data are being scraped and used to train AI models, generally without licensing or compensation. NAR has made copyright protection for listing content a federal advocacy priority and has backed legislation aimed at protecting real estate content used in AI training.
For an operator, the lesson generalizes: in the AI economy, proprietary data is the scarce input. Everyone building models wants what you have. The market analyses you publish, the transaction records you hold, the hyperlocal knowledge you have accumulated: these are exactly the inputs AI companies spend billions to acquire. Which raises the obvious question. If your data is valuable enough for others to want it, why are you giving it away through the side door of consumer chatbot prompts?
The operator's playbook: own the vault
None of this argues against AI. The productivity gains are real, and brokerages that refuse the technology will lose to brokerages that deploy it well. The argument is about the terms on which you adopt it. Five moves, in order:
- Write an AI use policy this quarter, not this year. Define what may never enter a third-party tool: client financials, negotiation positions, personal circumstances, anything covered by the duty of confidentiality. Name the approved tools and tiers. Ban client data in personal accounts outright. NAR publishes a customizable AI policy template through its associations if you need a starting point. A one-page policy you enforce beats a ten-page policy you don't.
- Upgrade every AI seat to business terms. If your team uses cloud AI tools, use enterprise or team tiers where customer data is excluded from training by default, and get a data processing agreement in writing. The cost difference is trivial next to the exposure difference. Treat "which tier are we on" as a compliance question, not an IT question.
- Move the crown jewels onto infrastructure you control. Enterprise cloud tiers reduce risk. Private AI eliminates a category of it. A private, on-premises or dedicated AI knowledge base, running on hardware and infrastructure your company owns, lets you put your transaction archives, pricing rationale, negotiation playbooks, and client intelligence to work without any of it crossing a third party's boundary. No training exposure, no terms-of-service dependency, no vendor's legal process obligations sitting between you and your clients' confidences. It is the difference between renting intelligence by the token and owning a compounding asset.
- Ask vendors the uncomfortable questions. For every AI-enabled tool in your stack, including transaction management, CRM, and marketing platforms quietly adding AI features: Is our data used to train your models or anyone else's? Where is it stored and for how long? Can you delete it on demand and prove it? Will you sign a DPA? Who is liable when your tool gets it wrong? Vendors with good answers put them in the contract. Vendors with vague answers just answered.
- Think like an owner, not a renter. The brokerages that win the next decade will be the ones whose institutional knowledge compounds: captured from every transaction, structured, queryable by every agent, and owned outright. That is an asset that survives agent turnover, raises the floor for new agents, deepens client service, and shows up in enterprise value if you ever sell. Subscription AI is an expense. Owned knowledge infrastructure is equity. Operators who understand the difference will build it deliberately.
The same logic is reshaping every knowledge profession right now. For the parallel analysis in law, wealth management, and tax practice, see our posts on Rule 1.6(c) and law firm confidentiality, the RIA books-and-records rule, and IRC §7216 for CPA firms.
Additional references cited in this article include NAR's AI advocacy hub and Legal Research Center reporting, IBM's Cost of a Data Breach Report 2025, MultiState's 2026 state privacy law tracker, and AI law updates from Baker Botts, Cooley, Fasken, and Bryan Cave Leighton Paisner.
Frequently asked questions
Is it illegal for a real estate agent to put client information into ChatGPT or Claude?
What is the difference between consumer AI, enterprise AI, and private AI?
What laws apply to a brokerage's use of AI in 2026?
Does the duty of confidentiality end at closing?
What is institutional memory worth to a brokerage?
Should small teams care, or is this a big-brokerage problem?
This article is for general information and is not legal advice. AI regulation is changing rapidly; consult a licensed attorney in your state before making compliance decisions.