What Not to Paste Into AI: Privacy and Compliance for Agents
Using AI with client information is safe when you follow one rule: never paste a real client’s private details into a public AI tool. That means no full names tied to financial data, no Social Security numbers, no loan account numbers, no contract terms that identify a specific person. Use AI for the thinking work. Keep client data out of the prompt.

Where agents get into trouble
A while back, a story circulated about a law firm that submitted a court brief full of citations to cases that did not exist. The AI invented them. The attorneys had not checked. The judge was not amused.
That story made headlines because lawyers made it embarrassing. But the quieter version of this happens in real estate every week. Agents copy-paste an offer, a disclosure, or a buyer’s financial summary into a chat window because it is faster than typing everything out. They get a useful response, move on, and never think about what happened to what they typed.
That is the gap worth understanding.
What AI tools actually do with what you type
Public AI tools, the ones you access through a browser without a business agreement in place, generally store your conversations. Some use them to improve the model. The specific terms vary by platform and change over time, but the pattern is consistent: you do not always control what the service keeps or how it uses what you have typed.
This is not a reason to panic. It is a reason to treat a public AI tool the way you would treat a conversation at a coffee shop. You would not recite your client’s Social Security number and income at a table next to strangers. Same idea applies here.
Your brokerage has a policy on this. If you have not read it, that is the first step. Many brokerages are updating their AI guidelines right now, so it is worth checking even if you read something a year ago.
Forward Loans
What do you want help with?
Forward Loans NMLS #2006640. Michael Creel NMLS #420674.
The information that stays out
There is a short list of data that should never go into a public AI prompt. Memorize it once and you are done.
- Full names tied to financial details (income, credit score, debt, savings)
- Social Security numbers or any government ID numbers
- Loan account numbers or bank account numbers
- Contract terms that identify a specific buyer, seller, or property when combined with other details
- MLS data with personally identifiable information attached
- Anything from a signed document that lets someone reverse-engineer a person's identity
The risk is not that a hacker intercepts your chat. The risk is that you have put identifying information into a system whose data handling you do not control, and you have done it for a client who trusted you with that information. That is a trust problem before it is a legal problem.
How to still get real value from AI
Here is the good news. You do not need client data in the prompt to get useful output. Most of the work AI is actually good at, drafting emails, writing listing descriptions, summarizing a market, brainstorming objection responses, creating checklists, does not require a single piece of personal information.
When you do need AI help on a situation involving a real transaction, swap the details out. Instead of "My client John Rodriguez has a 642 credit score and $14,000 in savings for a $480,000 home," type "A buyer has a 640 credit score and limited cash reserves for a home around $480,000. What are the typical loan options?" You get the same answer. The client's name and exact numbers never leave your keyboard.
Anonymized examples get you most of the value with none of the exposure. Once you build the habit, it takes about five seconds of editing before you hit send.
Fair housing applies to what AI writes for you
This section matters and not enough people talk about it.
Fair housing law applies to AI output the same way it applies to anything you publish or send as an agent. If you ask an AI to write a listing description and the output uses language that signals a preference for or against a protected class, even indirectly, that is on you. You published it.
The practical rule: never let an AI describe people in a listing or marketing piece. Do not feed it prompts that use neighborhood demographics, proximity framing that codes for race or national origin, or language about "the type of buyer" who fits a home. Write listings about the property. Let the buyer decide if it fits their life.
AI tools do not know fair housing law the way you do. They know patterns in text. Review everything before it goes out, and treat it as you would a piece you wrote yourself, because legally, you did.
A clean do and do-not list
Print this out if it helps. Put it next to your monitor.
| Do | Do not |
|---|---|
| Use AI to draft emails, listing copy, and client FAQs | Paste a client's name, SSN, or financial data into a public tool |
| Anonymize scenarios before prompting ("a buyer with X credit score") | Copy-paste signed contracts or disclosures with identifying details |
| Ask general market or strategy questions | Ask AI to describe the "type of buyer" that fits a neighborhood |
| Review AI output before publishing or sending | Publish listing copy that uses protected-class proxies |
| Check your brokerage's AI policy | Assume a public tool keeps your data private by default |
| Use business-tier tools with a data agreement when available | Mix client-specific data with general questions in the same prompt |
For a broader look at how agents are using AI day to day, the guide at forward.loans/ai-for-realtors covers the full picture.
Frequently asked questions
Does it matter which AI tool I use?
Yes. Some tools offer a paid business tier with different data handling terms, often including a commitment not to use your inputs for model training. If your brokerage has one of these agreements in place, the rules shift. Ask your broker. If you are using the free consumer version of any tool, assume the same standard applies: keep client data out.
What if I accidentally paste something with client information in it?
Do not treat it as a crisis. Most platforms let you delete individual conversations. Delete it, note what happened, and adjust the habit. If your brokerage has an incident reporting process for data, follow it. The goal going forward is building the edit-before-you-send reflex so it does not happen again.
Can I use AI to help explain mortgage options to my clients?
Yes, and this is one of the better uses of it. Ask general questions ("explain how an FHA loan works for a buyer with moderate credit in plain language"), get the output, review it, and use it to build your own explanation. Do not send AI output directly to a client as though it is your advice. Run it through your own knowledge first, because if it is wrong, you are the one who sent it.
What does "business tier" actually mean for AI tools?
Most major AI providers offer a paid business version with a data processing agreement that limits how your inputs are stored and used. This is different from a standard paid subscription. If your brokerage has this set up, your prompts are typically not used to train the model. Check with whoever manages your brokerage's tech tools to find out what is in place.
Is AI going to replace agents?
Not the question this article answers, but worth a short answer: no tool replaces judgment, relationships, or fiduciary responsibility. AI handles repetitive text work faster than a person can. The client sitting across the table from you deciding whether to buy a home is not a text problem.
Do I need to disclose to clients that I used AI on their transaction?
Disclosure requirements around AI are evolving and vary by state, brokerage policy, and the type of use. For anything that touches a client's legal documents or formal advice, check with your broker or your brokerage's legal team. For general productivity tasks like drafting an email, most situations do not require disclosure today, but that may change.
Protect the client first. Keep their private data out of the prompt, use anonymized examples, and review everything before it goes out. Do that and AI stays a help instead of a liability.