AI Governance
·August 2026·9 min readYour Agents Are Already Using AI. Do You Have a Governance Policy?
Your agents are already using AI. The only open question is whether they are using it inside a policy you wrote, or outside one you never published. In a relationship business regulated by fair housing law, that is not a technology problem. It is an operating problem.
When we rolled out Gemini and a custom chatbot to 1,200 users, the deployment was the visible work. The harder work was the policy layer underneath it: what people may put into a model, what they may not, how fair housing applies to AI-assisted marketing, and what happens when the tool lives on a personal phone instead of Workspace. When local models landed on consumer phones, that last question stopped being theoretical. Silence is not a strategy.
This is the framework we use. It is not legal advice. It is what a multi-state brokerage actually needs on paper and in training so AI deepens the relationship business instead of creating a compliance incident.
Why Does AI Governance Matter More in Brokerage Than Most Industries?
Three constraints stack on top of each other.
First, the Fair Housing Act and state fair housing laws prohibit discrimination in housing transactions, including advertising, steering, and terms of service, on protected bases. Second, agents handle client financials, motivation, and confidential negotiation strategy every day. Third, most of the firm is independent contractors using a mix of company systems and personal devices. That combination makes shadow AI inevitable and unmanaged AI expensive.
HUD has been explicit that digital tools do not get a free pass. Advertising and tenant-screening systems that produce discriminatory outcomes can violate the Act even when the intent was not discriminatory. The same logic applies to AI-generated listing copy, automated buyer-matching language, and chatbots that paraphrase neighborhood "fit." If a human agent would not be allowed to say it, an agent using a model should not say it either. See HUD's guidance on fair housing advertising and marketing.
The National Association of Realtors' Code of Ethics still applies when the draft came from a model. Article 10 and related standards on discrimination and truthful advertising do not carve out generative tools. The model is a drafting assistant. The agent remains responsible for the output that reaches a client or the public.
What Are the Real Failure Modes?
In practice we worry less about autonomous agent science fiction and more about four concrete failure modes we have already seen or narrowly avoided.
Fair housing in generated content. An agent asks a model to "rewrite this listing to attract the right buyers" or "describe who this neighborhood is good for." Models trained on the open web will invent demographic shorthand, coded language, or exclusions that would never survive a compliance review. The risk is not that AI invents a new civil rights theory. The risk is that it recreates old steering patterns at scale, in a voice polished enough to publish without a second look.
Client and transaction data leaving the firm. Pasting a purchase agreement, a seller's financial picture, or a negotiation email thread into a consumer chatbot can put non-public information into a system with different retention and training defaults than your enterprise stack. That is the problem we solved first with a managed deployment. It does not go away because local models exist. It changes shape. Cloud consumer tools still leak outward. Local tools reduce egress but eliminate audit visibility.
Confident wrong answers on regulated topics. An AI that invents a disclosure requirement, a commission rule, or a contract timeline is worse than no AI. Our custom chatbot requires citations back to firm source material for that reason. Consumer tools do not.
Policy vacuum as cultural permission. When leadership deploys AI without written rules, people fill the silence with whatever is convenient. Some will be careful. Some will not. In a 30-office firm, variance is the default. Governance is how you reduce variance without killing adoption.
What Belongs in an Agent AI-Use Policy?
A usable policy is short enough to train and specific enough to enforce. Ours organizes around five rules.
1. Approved tools first. Prefer enterprise-approved AI (Workspace Gemini, the firm chatbot, and other named systems) for work that touches company or client data. Consumer tools are not a parallel IT stack. If a use case is not covered, escalate. Do not improvise.
2. Never paste what you would not email to a stranger. No Social Security numbers, full account numbers, wire instructions, unpublished financials, personnel matters, or privileged legal strategy into unapproved tools. When in doubt, strip identifiers and use approved systems.
3. Fair housing applies to every AI-assisted output. Listing descriptions, social posts, buyer emails, and neighborhood summaries must meet the same standards as human-written marketing. No protected-class preferences, no coded exclusions, no "ideal buyer" stereotypes. Agents must review model output before they publish or send. The human remains the publisher of record.
4. Disclose when it matters, and always own the content. You do not need to watermark every email with "written by AI." You do need to stand behind accuracy, fair housing compliance, and brand voice. If a client or counterparty would reasonably expect a human judgment, the human must actually make it.
5. Local and personal-device AI has a defined lane. On-device models are useful for offline drafts and private brainstorming with de-identified prompts. They are not a place for full client files, firm policy Q&A that should cite official sources, or anything that requires an audit trail. Treat them as a pocket notepad, not as the system of record. That is the complementary posture we described when local models hit the mainstream.
How Should Leaders Operationalize This?
A PDF in a policy binder is not governance. Operating discipline is.
Write it once, train it often. Include AI use in onboarding and annual compliance training alongside fair housing. Use real bad examples: a listing blurb with coded language, a prompt that leaked a client budget, a chatbot answer that invented a rule. People remember scenarios, not principles.
Put guardrails in the product, not only in the memo. Our firm chatbot is constrained to institutional sources with citations. Enterprise Gemini sits inside our Google admin and data controls. That is innovation work, not a side project for legal. Policy without product design is theater.
Give people a better path than the forbidden one. Consumer AI exploded inside enterprises because it was useful and free of friction. If approved tools are slow, locked down into uselessness, or never explained, agents will leave. Governance that only says no will lose to a browser tab that says yes.
Review marketing workflows, not just chat. The highest fair housing risk is not a private Q&A. It is AI-assisted public content: listing copy, ads, social, and email campaigns. Build a review step where volume is high. Sample outputs. Fix templates that produce bad prompts.
Update fair housing materials for the AI era. Our fair housing notice is the public commitment. Internally, fair housing training should include AI-generated content and advertising. The law did not change because the keyboard got smarter.
What About Vendor AI and Prop-Tech?
Brokerages do not only use general models. CRMs, CMA tools, lead routers, and marketing platforms ship AI features every month. Procurement needs three questions that used to be optional.
Where does prompt and client data go, and is it used for training? Can we disable or scope features that touch fair housing-sensitive decisions, such as lead scoring, "best fit" neighborhoods, or image generation of people? Who is liable when the model is wrong, and can we export logs if a complaint arrives?
The FTC has warned repeatedly that automated systems do not excuse unfair or deceptive practices. Companies remain responsible for how tools are used in the market (FTC guidance on AI claims). Treat vendor AI like any other high-risk vendor: security review, data processing terms, and an exit plan.
What Should You Do This Quarter?
If you have no written AI policy, write a one-page version of the five rules above and put it in onboarding this month. If you have a policy but no approved enterprise tool, you are still pushing people to consumer products. Fix the stack. If you have tools and a policy but no fair housing examples in training, you are one viral listing rewrite away from learning the hard way.
We did not deploy AI because it was fashionable. We deployed it because unmanaged use was already happening, and because technology should serve the relationship, not invent a second set of rules that ignore the first. Governance is how you keep that true when every agent has a model in their pocket.
The firms that treat AI policy as a living operating document, tied to fair housing, data handling, and tools people actually prefer to use, will move faster and sleep better. The firms that treat it as a press release will discover that their agents already wrote the policy for them, one prompt at a time.
Interested in discussing these topics further.
Get in touch