AI falls within the board's duty of oversight

Jul 21 / Thomas Wiegelmann
At some point this year, a board member will ask a simple question: Which figures in this paper were produced using AI, and who checked them? In most real estate organisations, nobody in the room can answer with confidence.

This is not a question born of opposition to AI. Analysts use generative AI tools to draft sections of memos. Asset managers summarise lease agreements in minutes. Fund teams produce first drafts of investor updates using material from the previous quarter. All of this is useful. But this material increasingly reaches committees and boards, and the path it took to get there - before becoming relevant to material decisions - is rarely documented. In real estate, this is less a question of tools than of leadership, workflows and governance. Boards have a role that they cannot delegate.

The bottleneck has moved

Each major technology wave has reduced the cost of a particular bottleneck. Industrialisation reduced the cost of physical labour. Computerisation reduced the cost of calculation. The internet reduced the cost of accessing information. AI is reducing the cost of producing knowledge itself. Market summaries, risk memos and portfolio commentary can now be drafted in minutes. When creation becomes a commodity, value shifts to what remains scarce: validation, judgment and responsibility. The strategic question is no longer simply who has the information, but who can evaluate it and translate it into better decisions.

This shift matters in real estate because the outputs inform consequential decisions. An incorrect statistic in a social media post is embarrassing. An incorrect assumption in a valuation model can cost money and trust. The same is true of a mispriced capital expenditure estimate or poorly judged language in a tenant letter. The bottleneck in real estate was never simply document production. It was validation. AI has made that visible.

Plausibility is not correctness, and correctness is not reliability

A useful distinction in any leadership discussion is between three levels of output quality. Plausibility means that an output sounds convincing and appears logical. This is what generative AI primarily optimises for. Correctness means that the facts are accurate and the statements can be supported by evidence. This is the minimum standard for professional work in real estate. Reliability means that the output is complete, traceable and ready to support a decision. This is what real estate organisations require.

In practice, these three levels diverge. An AI-generated market report can be plausible and even factually correct, yet still omit a key covenant or planning constraint that changes the investment case. A sensible default for management is to assume that AI provides plausibility; the surrounding processes must turn it into reliability. In a previous newsletter article, we explained why verification belongs in the workflow rather than being left to individual habit. The governance point goes further: someone must decide which outputs require which level of verification. That decision is, or should be, a leadership responsibility.

Oversight should scale with consequences

AI can help prepare decisions. What it cannot absorb is judgment, liability or governance. When a valuation informs a purchase, a person owns the outcome. The same applies when a screening result affects a tenant or a board paper shapes strategy. The question for every AI-supported process should not be only what AI can take over, but also what level of oversight the result requires. A practical approach is to calibrate oversight to the consequences of the output. High oversight applies to outputs that carry significant weight and are difficult to reverse. Examples include valuations used in transactions, financing documents and decisions affecting tenants. These require formal sign-off, an audit trail and a named accountable owner. Medium oversight applies to anything that is decision-relevant or shared outside the team, such as client market reports and investor communications. These require structured review, checks against sources and a defined escalation path. Low oversight applies to drafts and personal preparation, such as meeting notes, first drafts and internal brainstorming. A light review at the user's discretion is often sufficient.

One warning is important here: having a "human in the loop" is not, by itself, governance. We hear this often in discussions with professionals across the industry. Someone reading over an AI-generated output before it is sent provides reassurance, but not a complete control. What matters is who reviews, who approves and who carries responsibility. An organisation that cannot answer those three questions for its main AI use cases may already have strong adoption - which is positive - but it does not yet have governance embedded in the workflow.

Individuals still learn faster than organisations

We have written before about the gap between individual experimentation and team capability. The governance perspective provides another reason to close it. As long as AI expertise resides in the heads of a few capable users, quality control remains difficult and tends to be informal. Standards remain personal. Governance, however, requires shared practices that can be reviewed, taught and improved over time. Converting the routines of power users into documented team standards is therefore more than a productivity measure; it is a precondition for any oversight model to work.

Regulation will make this concrete

For European real estate organisations, there is also an external reason to act. The EU AI Act classifies certain systems as high-risk, including those used for credit scoring and employment. These categories may affect tenant screening, mortgage decisions and HR processes. The obligations for deployers resemble a formalised version of the oversight model described above. They cover human oversight, logging, monitoring during use and informing affected tenants and employees. In regulated sectors, they also require fundamental rights impact assessments. The recent Digital Omnibus deferred the main high-risk deadline to December 2027. This extends the timeline, but does not change the underlying substance.

Three practical questions from the board
Board and advisory board members do not need to understand model architecture in detail. They do, however, need clear answers on data, responsibility and value. Three practical questions can help.

1) First, data and confidentiality: do we know what information is being shared, with which tools and under which conditions?
Management should be able to show which AI tools are approved, what categories of data may or may not be entered, where that data is processed and stored, and who can access it. This should include clear rules for confidential information, personal data, tenant and employee information, and commercially sensitive documents. A simple register of approved tools and permitted data uses is often a practical starting point.

2) Second, policy and responsibility: do we know who may use AI, for what purpose and who remains accountable for the result?
A binding policy should define acceptable use, prohibited use and the process for approving exceptions. For material workflows, it should also be clear who reviews the output, who approves its use and who owns the final decision. The policy should create enough control to manage risk without preventing sensible experimentation.

3) Third, effect and effort: can we demonstrate that the process is genuinely better after review and verification are included?
Management should assess not only the time saved in producing a first draft, but also the effort required to check it, correct it and make it decision-ready. Useful measures may include turnaround time, review effort, error rates, quality improvements and ongoing tool costs. An AI-supported process creates value only when the complete workflow becomes better, faster or safer.

These questions can be asked at any level, from a team lead to the board. A management team that can answer them with evidence can also explain which outputs were produced with AI, how they were checked and who remains responsible.

Where to start?

Start by reviewing the AI use already taking place and classifying it by consequence. Which outputs leave the team or reach a committee? Which affect tenants, transactions or regulated decisions? Then select one workflow and assign the three elements of governance: who reviews, who approves and who is responsible. Write this down, then repeat the process for the next workflow.

The key point is that AI does not scale through better prompts alone. It scales through better workflows, standards and responsibility. In real estate, decisions have significant consequences and mistakes can be long-lasting. This is often where our work at VARi begins. We start with the workflows in which AI is already being used and build the oversight structures that allow a team to trust its own outputs.

Created with