The Real Estate Authority’s Generative AI guidance is clear: licensees remain responsible for the services they provide. An error made by a Gen AI tool is not a defence. Agencies and supervisors can be held to account for staff under their supervision.
REA also encourages agencies to have policies in place. Many offices already have fragments — an IT acceptable-use clause here, a privacy notice there — but nothing that tells a salesperson, in one page, what they may put into Claude on a Tuesday night before an open home.
Below is a practical one-pager you can adapt — plus the “why” behind each clause so managers can defend it in a sales meeting. This is not legal advice; run it past your counsel and align it to your brand and stack.
Based on
REA Generative AI guidance (Registrar, Real Estate Agents Act 2008 purposes). Also consider Privacy Act / Code rule 9.17 confidentiality, Fair Trading Act accuracy, REA appraisals guidance (rules 10.2–10.3), and CERT NZ cyber guidance. OPC AI expectations: privacy impact thinking, human review, and no personal/confidential uploads without retention/disclosure assurance (OPC generative AI page).
1. Purpose
This policy sets how [Agency Name] uses generative AI so we can improve productivity without compromising client care, confidentiality, accuracy or compliance under the Real Estate Agents Act 2008 and the Code of Conduct.
Why it matters: REA’s guidance exists because tools that create fluent drafts still leave the licensee holding the bag. A written purpose stops “innovation theatre” from outrunning client care.
2. Approved tools
Only tools on the agency’s approved list may be used for agency work (name them: e.g. PropertyLM Atlas / Newton, Microsoft Copilot under agency tenancy, approved marketing tools).
Personal consumer accounts (e.g. free ChatGPT) are not approved for client or agency data.
New tools require written approval from [AI Owner / Compliance Lead] before use.
Why it matters: Shadow IT is how confidential LIMs end up in consumer prompts. An approved list is a supervision tool, not bureaucracy for its own sake. Update the list when tenancies change.
3. Banned inputs
Do not paste or upload into external Gen AI tools:
Client or customer personal information (names, contact details, finances, ID)
Confidential vendor files, LIMs, builder reports, body corporate packs, or unredacted contracts
Agency credentials, internal pricing strategy, or unpublished appraisal workings
Anything you would not put on a postcard if the vendor asked how you handled their file
REA line to pin on the wall
“Government guidance recommends against inputting personal and client information into external AI tools.” — REA Generative AI guidance
4. Human review (non-negotiable)
Every AI-assisted output that is client-facing or decision-relevant must be fact-checked for accuracy, relevance and completeness by a licensed person before use (rules 5.1, 6.4, 10.7; Fair Trading Act).
AI drafts marketing copy, emails or scripts; humans own the publish button.
“The model said so” is never an acceptable explanation in a complaint file.
Why it matters: REA’s guidance is built around the fact that Gen AI can sound right while being wrong. Review is the control that turns a drafting aid into something you can defend.
5. Appraisals vs drafting
Keep the products separate
Allowed: AI-assisted drafting of CMA packs, market narratives and follow-up answers where comps and sources remain traceable and the licensee forms the opinion.
Not allowed: presenting an automated estimate or Gen AI mid-point as a rule 10.2 appraisal, or as a substitute for verified comparable sales.
Label clearly: if an automated estimate is shown, call it automated — never your professional appraisal.
REA’s appraisals guidance remains the north star: written appraisal, realistic market reflection, comparable sales support, and you can’t solely rely on electronic estimates. Rule 10.3 still requires a written explanation when comps are thin.
6. Supervision
Branch managers / supervisors must know which tools salespeople use and spot-check AI-assisted work.
Agencies remain accountable for staff under supervision — treat Gen AI like any other junior: useful drafts, supervised outputs.
Include Gen AI use in periodic file reviews the same way you review appraisal quality.
7. Incidents
If client data may have been entered into an unapproved tool, or an AI error reached a client:
Stop further use of that workflow.
Notify [AI Owner / Privacy Officer] the same day.
Preserve prompts/outputs for the incident file.
Follow Privacy Act / client notification steps as advised.
Why it matters: Speed of response after a bad paste often matters as much as the paste itself. Write the path before you need it.
8. Training
All licensees complete Gen AI induction covering this policy, REA guidance, and privacy basics within 30 days of joining (or of this policy’s adoption).
Annual refresher; update when tools or REA guidance change.
Use concrete bad examples (LIM paste, invented comps) so the rules stick.
Actionable checklist (copy into your ops doc)
□ Appoint AI Owner + Privacy contact.
□ Publish approved-tool list + banned-input list.
□ Block or discourage personal ChatGPT for agency files.
□ Require human sign-off on appraisals and marketing.
□ Separate “drafting aid” from “appraisal opinion” in training.
□ Log incidents; review quarterly.
□ Re-read REA Gen AI guidance when you add a new tool.
PropertyLM builds Atlas and Newton so agencies can use AI for drafting and research with traceable NZ sources — and keep the licensed human in charge of the opinion.
How to roll this out in 14 days
Day 1–2: appoint AI Owner and privacy contact; inventory tools actually in use. Day 3–5: draft the one-pager from this template; get counsel eyes on banned inputs and incident wording. Day 6–8: publish approved-tool list; close obvious shadow-IT gaps. Day 9–11: run a 30-minute induction with two live examples (bad LIM paste; good drafting prompt). Day 12–14: spot-check five recent AI-assisted client outputs; fix whatever the spot-check finds.
Then put the policy in induction and revisit quarterly — or whenever REA updates guidance or you add a tool.
Manager tip
Do not launch a policy without an approved-tool path. A ban with no alternative drives shadow use. Give people a sanctioned way to draft faster.
What “good” looks like in a complaint file
If a complaint arrives, you want to show: a policy existed; the salesperson was trained; the tool used was approved; client data was not pasted into a consumer model; a human checked accuracy; and appraisal opinions were formed under rule 10.2 rather than copied from an estimate. That file story is the point of the one-pager.
Template language you can paste into induction
“We use approved Gen AI tools to draft and research. We do not paste client personal information, LIMs, builder reports, agreements or trust details into consumer AI. Every client-facing AI-assisted output is checked by a licensed person for accuracy, relevance and completeness. Automated estimates are never presented as appraisals. Appraisals remain rule 10.2 opinions owned by the licensee. If something goes wrong, notify the AI Owner the same day.”
That paragraph is not poetry. It is a memorable minimum. Put it on the wall next to the REA guidance link and the approved-tool list.
Then schedule the boring part: a quarterly review where you update tools, re-read REA’s page, and ask whether any incident patterns suggest the policy needs a sharper banned-input line.
What “good” looks like after 90 days
After three months you should be able to point to: a named AI Owner; an approved-tool list people actually recognise; zero unexplained consumer-account pastes of client PDFs in spot-checks; and file reviews that mention AI the same way they mention appraisal quality. If those four are missing, the one-pager is decoration.
Also watch for two failure modes. First, the “approved tool” that still gets fed confidential files because nobody defined banned inputs clearly enough. Second, the marketing team that treats Gen AI as a publish button. Both are policy problems, not software problems — and both show up in complaints as accuracy or confidentiality issues long before anyone mentions the model name.
Revisit the policy whenever you add a connector, change CRM tenancy, or REA updates guidance. A living one-pager beats a perfect PDF nobody opens.
— PropertyLM.
