top of page

Shadow AI is already in commercial real estate. Are you governing it?

Writer: MAREJ
MAREJ
9 hours ago
3 min read

By Michael Mullin, Integrated Business Systems (IBS) and ProtectMyIT


Shadow IT required a purchase. Shadow AI requires a paste. That distinction may be one of the most important technology issues commercial real estate executives need to understand as artificial intelligence moves into everyday operations.

For years, companies worried about employees purchasing software or subscribing to cloud applications without involving IT. There was usually some friction - a purchase, installation, credit card, or approval. AI has removed that friction. An employee can open a browser, upload a document, paste information into a prompt, and receive an answer within seconds. IT may never know it happened.

And commercial real estate has plenty of information employees may be tempted to give AI. A property manager might use AI to summarize a tenant issue. An asset manager could upload operating results for a variance analysis. Accounting might use it to reconcile a spreadsheet. A leasing professional could paste sections of a lease into AI and request a summary. These are understandable uses of AI. They can also create risks many CRE organizations haven’t addressed.

Shadow AI vs. Sanctioned AI

Shadow AI uses artificial intelligence tools without organizational review, approval, or oversight. Employees generally aren’t trying to circumvent company policy. They’re trying to get their jobs done faster.

Sanctioned AI is different. The organization determines which tools employees can use, what information they can enter, how company data is protected, and where human review is required.

That distinction matters in CRE because organizations possess enormous amounts of potentially sensitive information: leases, tenant records, banking information, investor reports, property financials, vendor contracts, employee records and confidential acquisition and disposition documents.

The most important question isn’t which AI tool employees use. It’s what information they’re giving it. Using AI to improve the wording of a generic tenant notice is very different from uploading a rent roll. Brainstorming marketing ideas is different from uploading confidential acquisition documents.

Start With an AI Audit

Before writing another policy or attempting to prohibit AI, determine what’s actually happening.

An effective AI audit should answer four questions:

1. What AI tools are employees using? Include standalone platforms, browser extensions, and AI capabilities embedded within existing applications.

2. What information is being entered? Determine whether company, tenant, employee, investor, or transaction information is moving into systems that haven’t been reviewed.

3. Which uses create meaningful risk? Not every AI interaction deserves the same concern. Focus on situations involving information the organization is responsible for protecting.

4. What alternatives can you provide? Simply telling employees to stop using AI isn’t a long-term strategy. Give them approved tools and clear boundaries.

Don’t Turn Discovery into Enforcement

If employees believe admitting to using AI will get them in trouble, management will learn very little. Ask employees what they’re using, what they’re using it for, and which repetitive tasks they’re trying to eliminate. Those conversations may uncover risks, but they can also uncover opportunities. Shadow AI isn’t only a cybersecurity problem. It can also map where employees believe existing business processes are inefficient.

AI Isn’t the Problem. Ungoverned AI Is.

Commercial real estate shouldn’t respond to AI by trying to stop it. The productivity opportunity is too significant. But adoption cannot be separated from governance. The question CRE leadership should be asking isn’t, “Should we allow employees to use AI?”

A better question is: “How are our employees already using AI, and do we have the appropriate controls around it?”

The CRE organizations that answer that question now will be better positioned to take advantage of AI without unnecessarily exposing their properties, tenants, investors, or businesses to risk.

Michael Mullin is president & CEO of Integrated Business Systems (IBS) and ProtectMyIT. He has more than three decades of experience helping businesses use technology while managing cybersecurity and operational risk.

 
 
bottom of page