Multi-Family Office Expert: Your Team Is Using AI the Wrong Way

Multi-Family Office Expert: Your Team Is Using AI the Wrong Way | The Kitti Sisters - 1

EP 391 Multi-Family Office Expert: Your Team Is Using AI the Wrong Way

APPLE PODCASTS | SPOTIFY

The 5 Things Your Family Office Should Never Put Into AI

AI can do in an afternoon what used to take an investment team a week.

We love that.

We use AI across our own real estate investment business, and we believe it’s going to fundamentally change how small investment teams operate.

But there’s a side of this conversation that doesn’t get nearly enough attention.

What happens to the information we give it?

Because somewhere inside a family office right now, someone is probably trying to save themselves 30 minutes.

They have a document they need summarized.

A spreadsheet they need analyzed.

An investor update they need drafted.

So they open an AI tool, upload the file, and hit enter.

Done.

Except the file might contain a K-1.

Or an investor list.

Or account information.

Or an estate document.

Or something protected by an NDA.

And the person uploading it probably wasn’t being careless.

They were just trying to get their job done faster.

That’s what makes this issue so important.

We don’t think family offices should stop using AI.

We think they need to become much more intentional about what crosses the line into AI in the first place.

Because your portfolio can recover from a bad year.

Your privacy can’t recover from a leak.

Money can compound back.

Information doesn’t un-spread.

And for families who have spent decades building wealth, privacy isn’t simply a preference.

Privacy is an asset.

The More Wealth You Build, the More Valuable Privacy Becomes

There was probably a point in your life when almost nobody cared what you owned.

Nobody was trying to figure out your net worth.

Nobody cared which bank you used.

Nobody was searching public records to understand your holdings.

Nobody knew which deals you were investing in.

Then wealth grows.

And quietly, something changes.

A filing appears here.

A deal announcement appears there.

Your name becomes connected to a company.

Your company becomes connected to an investment.

Your investments become connected to your family.

And suddenly, information that once felt completely ordinary becomes valuable to someone else.

That’s one reason family offices have historically been so protective of privacy.

UBS’s 2025 Global Family Office Report found that among family offices keeping work in-house, 63% cited protecting family privacy as a reason.

That isn’t paranoia.

That’s part of the job.

Because knowing what a family owns can expose much more than money.

It can expose where they live.

Where their children go to school.

Which banks they use.

Who their advisors are.

How much liquidity they have.

Which investments they’re making.

How their estate is structured.

And all of that information can become useful to someone with very different intentions.

A criminal can create a more believable wire request.

A counterparty can understand how much negotiating room you have.

Someone can identify the people investing alongside you.

A family member might discover an estate decision before the family was ready to discuss it.

None of these risks appear neatly on a balance sheet.

But any one of them can cost more than a bad year in the market.

That’s why we believe sophisticated families need to start thinking differently about AI.

The question isn’t:

“Should we use AI?”

The better question is:

“What information should AI ever be allowed to see?”

Banning AI Isn’t the Answer

The obvious reaction might be:

Fine. We’ll just ban ChatGPT.

We don’t think that’s the answer.

In fact, it can make the problem worse.

Imagine an analyst discovers that AI can turn a two-hour task into a 15-minute task.

Then the company bans it.

What happens?

Sometimes the analyst stops using AI.

But sometimes the work simply moves somewhere you can’t see.

Their personal ChatGPT account.

Their phone.

A browser extension.

A meeting transcription app.

An AI feature buried inside software your office already uses.

You haven’t eliminated the risk.

You’ve eliminated your visibility into the risk.

And there’s a real opportunity cost on the other side.

AI can help summarize operating agreements.

Compare insurance quotes.

Organize data.

Draft investor communications.

Review documents.

Assist with underwriting.

We don’t think family offices should give that leverage away.

The goal isn’t to build a wall around AI.

The goal is to control what crosses the wall.

Speed and Privacy Aren’t Opposites

Here’s the part we think gets missed.

Most of the value AI gives you comes from the structure of the work, not the identity of the people involved.

Imagine you’re analyzing a rent roll.

Does AI need to know that John Smith lives in Unit 203?

Probably not.

It needs:

Unit 203.

Monthly rent.

Lease start date.

Lease expiration.

Maybe delinquency.

Maybe concessions.

The name contributes almost nothing to the analysis.

The same principle applies to a surprising amount of family-office work.

AI can compare two insurance quotes without knowing your Social Security number.

It can summarize an agreement without knowing your children’s school.

It can analyze investment data without knowing which investor owns which account.

It can draft an investor update without seeing everyone’s bank information.

Speed and privacy were never opposites.

The offices that use AI well won’t necessarily be the ones sharing the most information.

They’ll be the ones that decided ahead of time what information actually needs to be shared.

The Simple Rule We Use Before Giving Anything to AI

Before we give an AI system information, we ask:

What does this task actually require?

Not:

What information do we have?

Those are very different questions.

If the task only requires rents and lease dates, that’s what the AI gets.

If someone’s identity isn’t relevant, we remove it.

John Smith becomes:

Investor 14.

The Kitti Family Trust might become:

Entity A.

A property might become:

Property 3.

The key connecting those placeholders back to real identities stays somewhere else.

This sounds almost embarrassingly simple.

But that’s the point.

You don’t need an elaborate cybersecurity architecture to start making better decisions today.

You need to stop giving AI information it never needed in the first place.

Try This Experiment With One Document

Take one document your team regularly runs through AI.

Make a copy.

Then remove every name and account number.

Replace them with consistent placeholders:

Investor 1.

Investor 2.

Property A.

Entity B.

Keep the key connecting those placeholders to the actual identities somewhere inside your own controlled environment.

Then give the stripped-down document to the AI.

See what happens.

Most of the time, you may discover something interesting:

The answer is just as useful.

Which means the AI never needed the sensitive information in the first place.

And if removing something does meaningfully change the result?

Great.

Now you’ve identified exactly which information the task actually requires, and you can make a deliberate decision about whether sharing it is worth the risk.

Do this with the three AI tasks your team performs most often and you’ve already started building an AI privacy playbook.

But There Are Five Things We Would Put Behind a Bright Red Line

If we were writing a one-page AI policy for a family office, there are five categories we’d put at the very top.

1. Identity and account information

Social Security numbers.

Passport information.

Bank account numbers.

Brokerage account numbers.

And especially:

Wire instructions.

These are raw materials for fraud and identity theft.

There is almost never a legitimate reason an AI task needs them.

2. Credentials

Passwords.

Login information.

Access codes.

API keys.

Never.

Not even because you’re trying to get AI to “quickly fix something.”

If a credential gets pasted somewhere it shouldn’t have been, we’d treat it as exposed and change it.

3. Names attached to money

This one is easy to overlook.

K-1s with names attached.

Investor lists.

Cap tables.

Balance sheets carrying the family’s identity.

Why does this matter?

Because the combination of identity + financial information creates a map.

Who owns what.

Who invested where.

How much capital someone may have.

Who might be worth contacting.

Strip the identity and much of the document may still be perfectly useful for analysis.

Leave it attached and you’ve potentially shared much more than the task required.

4. The family’s private life

Trusts.

Wills.

Prenuptial agreements.

Family governance documents.

Health information.

Travel itineraries.

Children’s schools.

Some of those are financial privacy issues.

Others are much bigger than that.

They’re physical safety issues.

And no productivity gain is worth casually expanding that exposure.

5. Other people’s secrets

This one matters just as much.

Deal terms protected by an NDA.

Another investor’s information.

Confidential partner information.

Anything someone trusted you to keep private.

Our confidentiality obligations don’t suddenly disappear because we pasted the information into an AI tool instead of emailing it to another person.

If it wasn’t ours to share, it isn’t ours to share with AI either.

There’s Another Question Most Teams Forget to Ask

Even after you’ve decided what information is appropriate to share, you still need to understand where that information is going.

Because “secure” isn’t a useful enough answer.

Every technology company will tell you its product is secure.

We want more specific answers.

If we were evaluating an AI vendor for a family office, we’d ask four questions.

Where does our data actually go?

Which companies receive it?

Which subprocessors touch it?

Don’t settle for “it’s encrypted.”

Ask for the list.

Who at the company can see it?

Support?

Administrators?

Engineers?

Under what circumstances?

Ask about roles, not promises.

What gets kept—and for how long?

This is the question we think far too few people ask.

Information can show up in logs.

Analytics.

Error trackers.

Conversation history.

Storage systems.

You need to understand what’s retained, for how long, and what deletion options exist.

Does the provider train on our data?

Don’t rely on what someone told you during a demo.

Read the actual terms.

And keep a copy.

Because privacy isn’t something we’d want to manage through assumptions.

If a vendor can clearly answer those four questions in writing, you can make an informed decision.

If they can’t?

That tells you something too.

This Is One Reason We Built AIREI Differently

These concerns weren’t theoretical for us.

We were building AI systems while managing real investments, real investors, and real financial information.

We wanted the leverage of AI without unnecessarily widening the circle of people who knew our investors’ business.

That’s part of why we built our own AI operating system, AIREI.

AIREI runs AI through the user’s own AI account and key, so that relationship sits directly between the user and the AI provider.

Our administrative tools are designed around account and billing functions rather than exposing users’ deals, documents, or financial information.

Documents remain available in the user’s account so they can continue working with them, while AIREI itself does not use analytics trackers or log user prompts and AI responses.

But even with a system designed around these boundaries, we still come back to the same principle:

Technology doesn’t eliminate the need for rules.

Someone still has to decide what should go in.

Someone still has to review what comes out.

Someone Has to Own the Rule

Here’s another lesson we’ve learned from building systems:

If everyone owns something, nobody owns it.

Your AI privacy policy needs a name attached to it.

In a smaller family office, that might be the COO or CFO.

In a larger organization, it could be whoever owns security or compliance.

The title matters less than the accountability.

That person should know:

Which AI tools are approved.

Which tools people are actually using.

What the terms say.

What information can be shared.

What information cannot.

And what happens when someone makes a mistake.

Because someone eventually will.

That’s not cynicism.

That’s why processes exist.

Your AI Policy Should Fit on One Page

We wouldn’t start with a 47-page compliance manual nobody reads.

We’d start with one page.

Put the approved tools at the top.

List the five categories that never get pasted into AI.

Put the owner’s name at the bottom.

Then have everyone read it.

Not:

“It’s somewhere in the shared drive.”

Actually read it.

Employees.

New hires.

Assistants.

Contractors.

Outside advisors who handle family information.

And then add one more section that almost everyone forgets:

What happens when something goes wrong?

Tell the owner immediately.

If a credential was exposed, change it.

Contact the relevant vendor about available deletion options.

Document what happened.

Learn from it.

And most importantly, create a culture where someone would rather report a mistake in five minutes than hide it for five months.

A fast, no-blame report is far more valuable than a perfect-looking record.

Then revisit the policy every quarter.

Because AI is changing far too quickly for a policy written today to sit untouched for three years.

Here’s the Question We’d Ask Your Team Tomorrow

If we sat down with everyone in your family office and asked:

“Which AI tools did you use during the last seven days?”

Would you know the answer?

Not just ChatGPT.

Personal accounts.

Phone apps.

Browser extensions.

Meeting note-takers.

Transcription tools.

AI inside email.

AI inside your CRM.

AI features that quietly appeared inside software you’ve been using for years.

Write them all down.

You might be surprised by how long the list becomes.

And that’s okay.

Because you can’t create rules around tools you don’t know you’re using.

Then we’d ask the harder question:

Of the five categories we just talked about, how many have made their way into one of those tools this year?

Zero?

One?

Or:

“We genuinely don’t know.”

That last answer might actually be the most valuable.

Because now you know where to start.

Wealth Gives Your Family Options. Privacy Lets Them Use Those Options in Peace.

This is the part of the conversation that matters most to us.

When you’re first building wealth, there’s a kind of safety you don’t even realize you have.

Nobody knows what you own.

Nobody cares.

Then, little by little, that anonymity starts disappearing.

A filing here.

A deal announcement there.

A business article.

A public record.

A chatbot conversation someone didn’t think twice about.

And if you’re the first person in your family to build meaningful wealth, you probably didn’t work this hard because you wanted everyone to know exactly what you have.

You built it so your family would have options.

So your children could go to school without someone calculating what their last name might be worth.

So your parents could live normally.

So the people you love could have freedom without automatically becoming targets.

That’s what we’re really protecting when we talk about AI privacy.

Not PDFs.

Not spreadsheets.

Not files.

People.

Wealth gives your family options.

Privacy is what lets them use those options in peace.

Want to See How We’re Using AI Without Building a Bigger Team?

If you’re running a real estate portfolio somewhere between $100 million and $1 billion, this becomes even more important as you grow.

Because growth creates more of everything.

More deals.

More people.

More systems.

More reporting.

More decisions.

And more places where sensitive information can slip through.

On October 21, we’re hosting a free live masterclass where we’ll break down how we’re thinking about privacy when using AI—and how we’re using AI inside our own investment structure to build the capability of a much larger team without building the overhead of one.

The masterclass is free.

Click below to save your seat and join us live on October 21.

Comments +

Leave a Reply

We're Palmy ➕ Nancy Kitti 〰️ The Kitti Sisters

A sister duo team obsessed with all things financial freedom, passive income, and apartment investing + apartment syndication, who turned a $2,000 bank account into a nine-figure empire.  Now, we're sharing with you the behind-the-scenes secrets of our wealth building strategy.

pin with us