Your AI Policy May Be Governing the Wrong Thing

MLSs and REALTOR® associations are trying to establish responsible boundaries around AI, a technology that is advancing quickly, appearing inside more products, and raising legitimate questions about security, accuracy, privacy, intellectual property, and accountability.

The instinct to create a policy is reasonable. The problem is that many organizations begin with a question that is almost impossible to answer:

What is our policy on AI?

AI is not a single activity. It can help an employee revise an email, retrieve an answer from an approved policy manual, analyze member records, generate listing remarks, alter property photographs, recommend a course of action, or make changes inside another system.

Writing one set of rules for all of those uses is like writing a single policy for “using technology.” The category is too broad to produce meaningful governance.

A more useful policy begins with the role the system performs. What information does it receive? What can it access? What authority has it been given? Where is human review required? Who remains accountable for the result?

The goal should not be to govern the label. It should be to govern the use.

AI Is Already Inside the Organization

It may be tempting to think of AI adoption as a future decision that leadership can formally approve or reject. In practice, that decision has largely been made.

AI is already embedded in email platforms, meeting tools, search functions, marketing software, customer support systems, productivity applications, MLS technology, association management platforms, and products used independently by employees and members.

An organization may never purchase a product marketed primarily as an “AI platform” and still rely on AI throughout its operations.

This makes a blanket policy difficult to enforce. It also makes it less useful. A policy that simply prohibits employees from using AI with “organizational information” may sound cautious, but what qualifies as organizational information? Does it include a publicly available policy? A draft email? Meeting notes? Member records? Listing content? Financial information? Internal credentials?

Those are not equally sensitive uses, and they should not be governed as though they are.

The presence of AI does not tell the organization enough to determine what controls are appropriate. The organization must first understand the information involved, the function being performed, and the potential consequences if something goes wrong.

Start With the Role, Not the Technology

Organizations already understand that access and oversight should correspond to a person’s role.

An intern reading the employee handbook does not require the same controls as an accountant accessing financial records. A staff member answering routine questions does not have the same authority as an executive approving payments or changing organizational policy.

AI systems should be evaluated similarly.

A support assistant retrieving answers from approved resources has one role. A system reviewing member records and recommending disciplinary action has another. A tool that drafts a response for staff approval is different from one that sends the response automatically. A system that summarizes information is different from one authorized to modify a record, initiate a payment, or act on someone’s behalf.

Calling all of these systems “AI” obscures the distinctions that matter most.

The broader the role, the more carefully the organization should consider permissions, testing, monitoring, human review, and accountability. Intelligence does not determine authority. The organization does.

Govern the Information

One of the most practical things an AI policy can do is tell employees and vendors what information may be provided to which systems. That requires more precision than telling users not to enter “confidential data into AI.”

Organizations should identify the categories of information they handle and establish appropriate rules for each. Those categories might include:

  • Public organizational resources

  • Internal operational information

  • Member or customer information

  • Personal or financial information

  • MLS or listing data

  • Contractually restricted information

  • Credentials and security information

  • Privileged or legally sensitive material

The policy should then explain which categories may be used with approved systems, under what conditions, and for what purposes.

The word “approved” matters. Two tools that appear to perform the same function may handle information differently. One provider may retain prompts or use submitted content to improve a shared model. Another may process the information only to deliver the contracted service. One tool may provide organizational controls, access restrictions, and defined deletion practices. A consumer version of the same product may not.

The policy should not assume that every AI product uses information in the same way. It should require the organization to understand the arrangement before approving the use.

Govern Access Separately From Information

The information provided to a system is only part of its risk. Organizations must also understand what the system can access on its own.

An employee pasting a public policy into a writing tool is different from connecting that tool to the organization’s entire document library. A support assistant retrieving answers from an approved knowledge base is different from an agent with access to the association management system, MLS records, financial applications, internal communications, and the public internet.

Integrations can make AI significantly more useful. They can also expand the consequences of a mistake, compromised account, incorrect configuration, or unintended action.

An AI policy should therefore require access to be limited to what the system needs for its defined role. It should also establish who may authorize new integrations, how access is reviewed, and what happens when a system is no longer used.

This is not a new principle created for AI. It is the familiar practice of least-privilege access applied to a newer type of technology.

Govern the Authority to Act

The most important distinction in AI governance may not be whether a system uses sensitive information. It may be whether the system is allowed to do anything with it.

There is a meaningful progression between a system that:

  • Finds information

  • Summarizes information

  • Recommends an answer

  • Drafts an answer for approval

  • Communicates directly with a user

  • Changes a record

  • Initiates a transaction

  • Makes or materially influences a consequential decision

Each step grants the system more authority and increases the potential impact of an error.

An organization may be comfortable allowing an AI assistant to answer routine questions from approved resources while requiring staff review for legal, financial, compliance, or disciplinary matters. It may allow a system to recommend a record correction but prohibit it from changing the record automatically. It may permit AI to draft member communications while requiring a qualified person to approve certain categories before they are sent.

These are useful governance decisions because they address what the system is actually allowed to do.

“AI is permitted” and “AI is prohibited” are not governance frameworks. They are conclusions without enough context.

“Human in the Loop” Is Not a Complete Control

Many AI policies rely on a reassuring phrase: a human must remain in the loop. That sounds responsible, but it does not explain what the human is expected to do.

A person clicking “approve” does not provide meaningful oversight if that person lacks the information, expertise, time, or authority to recognize a problem. Human review only functions as a safeguard when the reviewer understands what must be verified and is capable of identifying an error.

Organizations should define when review is required based on the potential impact of the output. They should consider:

  • Whether the information is internal or public-facing

  • Whether an error could affect a member, consumer, employee, or transaction

  • Whether the output involves legal, financial, compliance, or policy interpretation

  • Whether the action can be reversed

  • Whether the reviewer has the expertise needed to evaluate it

  • Whether the system is providing information or exercising authority

A human does not need to manually approve every low-risk AI-assisted task. That would eliminate much of the efficiency the technology is intended to create. But consequential uses require more than the ceremonial presence of a person somewhere in the process.

The policy should define meaningful review, not merely mention it.

Accountability Cannot Be Delegated to the AI

An AI system can produce content, recommend an action, or perform a task. It cannot accept organizational responsibility for the outcome.

“The AI did it” is not an accountability model.

The organization must determine who is responsible for approving the use, monitoring its performance, correcting problems, and responding when the system produces an inappropriate result. Depending on the use case, responsibility may be shared among the organization, employee, vendor, platform provider, or another party.

Those responsibilities should be established before an incident occurs.

The same principle applies to employees using AI independently. If an employee uses AI to draft a communication, create marketing content, interpret a policy, or summarize a document, the employee does not transfer responsibility for the final work to the tool.

AI may assist with the task. It does not become the accountable party.

Governance Must Extend Beyond Employee Use

Many early AI policies focus heavily on employees using consumer tools. That is an important concern, but it is only one part of the organization’s exposure.

An association or MLS should also consider:

  • AI capabilities embedded within existing software

  • AI products purchased from third-party vendors

  • AI used by contractors and service providers

  • AI-generated or altered content submitted by members

  • AI systems accessing licensed MLS data

  • AI used to provide information or services directly to members

  • AI agents connected to internal systems or authorized to take actions

These uses may be governed by different departments, agreements, policies, and technical controls. The organization still needs a consistent framework for evaluating them.

NAR has released an AI Policy Template for Associations to help organizations establish responsible internal practices. At the same time, RESO is exploring machine-readable usage rights and hierarchical governance that could help communicate how data may be used across increasingly complex technology relationships.

These efforts reflect the breadth of the issue. AI governance involves employee behavior, vendor management, data rights, system permissions, organizational accountability, and industry standards. It cannot be reduced to a list of approved or prohibited chatbots.

A Useful Policy Should Help People Make Decisions

A policy should do more than warn employees and protect the organization on paper. It should help people determine what to do when they encounter a new use of AI.

A practical framework should allow someone to answer:

  • What role will the system perform?

  • What information will it receive?

  • What systems or resources can it access?

  • Is the provider permitted to retain or reuse the information?

  • What outputs or actions can the system produce?

  • Could the use materially affect a person, record, transaction, or organizational decision?

  • Where is qualified human review required?

  • Who approves the use?

  • Who monitors it?

  • Who is accountable for the outcome?

  • When should the use be reevaluated?

The specific tools will continue to change. A policy built around one product list or one moment in the development of AI will quickly become outdated.

A framework built around information, access, authority, review, and accountability is more durable because those responsibilities remain relevant even as the technology evolves.

Govern the Use, Not the Label

Organized real estate does not need policies that treat every use of AI as equally dangerous or equally harmless.

It needs governance capable of distinguishing between an employee improving the wording of an email, an assistant retrieving an approved policy, a vendor analyzing member information, an application using MLS data, and an autonomous system taking action inside an organizational platform.

Those distinctions are where responsible decisions begin.

The right question is no longer simply, “Do we allow AI?”

The better questions are: What information does this system receive? What can it access? What role does it perform? What authority has it been given? Where is meaningful review required? Who is responsible for its performance? Who is accountable when something goes wrong?

An effective AI policy should make those questions easier to answer. It should give staff permission to use appropriate tools responsibly, provide leadership with a consistent evaluation framework, and apply stronger controls as access, authority, and potential impact increase.

Governing the label may feel simpler. Governing the actual use is what makes the policy useful.

Previous
Previous

Coastal Carolinas Association of REALTORS® Partners with Voiceflip to Launch AI Assistant Harbi for Real Estate Professionals

Next
Next

REALTORS® Land Institute Partners with Voiceflip to Launch AI Assistant Dolly for Land Real Estate Professionals