I read a vendor page last week selling AI compliance monitoring to New Zealand real estate agencies. It promised to watch forms, calls, contracts and emails for compliance risk, and it listed what it covered: Health and Safety, the Privacy Act, Fair Trading, the FMA. Audit-ready logs for WorkSafe and the Privacy Commissioner.

Every one of those is a real obligation, and a real estate agency can breach any of them. Misleading advertising engages the Fair Trading Act. Mishandling a buyer’s information engages the Privacy Act. An unsafe vacant property engages the Health and Safety at Work Act. Only the FMA is a genuine misfit — residential agency work does not touch the Financial Markets Conduct Act, though a developer selling interests in a scheme is a different question. That is not what is wrong with the list.

What is wrong is that none of those regimes can touch a licence, and none of them is where the sector’s exposure accumulates.

Agency work here runs on the Real Estate Agents Act 2008 and the Professional Conduct and Client Care Rules 2012, enforced through Complaints Assessment Committees and the Real Estate Agents Disciplinary Tribunal, with the AML/CFT Act 2009 alongside it, supervised for this sector by the Department of Internal Affairs. Those are the frameworks that end careers. Neither was on the page.

And they are not parallel tracks. Section 73(c)(ii) makes a wilful or reckless contravention of other Acts that apply to the conduct of licensees a ground for misconduct — so a Fair Trading breach does not stay inside Fair Trading. It gets re-tried in a different forum, with the licence on the table.

Note the asymmetry, because it is the whole point. Another Act only reaches the disciplinary regime if the contravention was wilful or reckless. The Rules carry no such threshold: contravening them is unsatisfactory conduct on its own terms. The everyday exposure runs through the Rules at the lower bar, not through the general statutes. A system calibrated to Fair Trading thresholds will under-detect against the misleading conduct rule, because that rule catches conduct the Fair Trading Act would leave alone.

Scoping the wrong framework is the most common failure mode in compliance technology, and it has a documented history offshore that anyone buying in this market should read first.

The pattern, three times

In Massachusetts, an AI tenant screening tool scored applicants on credit history and non-rental debt. It did that accurately. What it did not do was account for housing vouchers, which meant it systematically penalised voucher holders — disproportionately Black and Hispanic applicants — in a way that engaged the Fair Housing Act. The class action settled for USD 2.275 million and the product changed. The tool was working. The rulebook it was measured against was one nobody had loaded into it.

In the same period, the US Department of Justice pursued a revenue management platform over algorithmic rent pricing. That product was built to optimise yield, and it was good at it: landlords took its recommendations most of the time. The framework that eventually caught it was antitrust. The November 2025 settlement imposed restrictions on which data can inform pricing at runtime, aged the training data, and installed a court-appointed monitor for three years. Nobody scoped the Sherman Act into a pricing tool, because the Sherman Act is not what a pricing tool is about.

And in the UK, HMRC keeps publishing its estate agency penalties. In the six months to September 2025 it issued 369 penalties across all supervised sectors; estate agency businesses took 170 of them, worth £835,842 — the largest single group. Around nine in ten of all those penalties were for trading without registration. Not weak customer due diligence. Not missed suspicious activity reports. Registration.

Read that last one twice, because it is the sharpest of the three. The firms being fined are not the firms with bad procedures. A tool that reads documents and grades their quality would have returned a clean report to every single one of them.

What actually generates findings in New Zealand

The REA’s 2025 annual report records 487 complaints in the year to 30 June 2025, up from 361. Complaints Assessment Committees issued 145 decisions; the Tribunal issued 43. The dominant themes were customer service, skill and care, disclosure, and misleading advertising, with poor communication running underneath all of them.

Look at that list and notice what is absent. There is no category for defective documents. Nothing there is a formatting error, a missing clause, or an unsigned form.

Every item on that list is a representation — something a licensee said, or failed to say, to a person who relied on it. What was disclosed about the building report. What was implied about the boundary. What was told to one buyer and not another. What the listing said versus what the agent knew.

This is the structural point, and it is why generic scanning cannot reach the risk. A document scanner treats the artefact as the unit of analysis: here is a contract, here is a recording, does it satisfy the checklist. But in real estate the unit of analysis is the representation, and representations do not live in documents. They live scattered across a text message, an open home conversation, a listing edit, an email at 9pm, a phone call nobody recorded. Individually each one looks fine. The finding emerges from the sequence — from what was said in March being inconsistent with what was known in February.

You cannot detect that with a point-in-time scan. There is nothing wrong with any single frame. The problem only exists across time.

The compliance tool is itself a compliance event

There is a closing irony worth naming.

The DIA’s refreshed guidance now treats Sector Risk Assessments as a mandatory reference point, and requires a reporting entity intending to use new or developing technology to update its risk assessment before deployment. The REA’s generative AI guidance is equally direct: a licensee stays responsible for the service they provide, including errors made by a tool they used.

So an agency that installs a generic AI compliance scanner without first updating its AML/CFT risk assessment has, in the act of buying compliance software, created a compliance gap. And if the tool mis-summarises a vendor disclosure into a listing, the licensee wears it — not the vendor, not the model.

Australia is about to run this experiment at scale. From 1 July 2026, Tranche 2 brings roughly 80,000 new entities into the AML/CTF regime, real estate agents among them, with civil penalties reaching A$31.3 million per contravention for a body corporate. A very large number of those firms are going to buy KYC tooling ported straight across from banking. Some of it will be excellent at verifying identity. Very little of it will know what a property transaction looks like when it goes wrong.

Five questions worth asking a vendor

  1. Which statute and which rule numbers does the system test against? If the answer is a category — “Fair Trading”, “privacy” — rather than a provision, it is scanning a topic, not an obligation.

  2. What is the unit of analysis: the document, or the representation?

  3. Can it see across time, or only within a single artefact?

  4. What does it output at the end — a risk score, or an evidenced record with provenance, timestamps and attribution? A score is a management report. Only the second one is any use in front of a Committee.

  5. Has the risk assessment been updated to cover the tool itself, before it goes live?

None of this is an argument against AI in compliance. It is an argument that in a regulated profession, domain specificity is not a feature of the product. It is the entire product. Everything else is a wrapper.

The regulator that fines you is not the one on the brochure.


I write Field Notes while building Resaido — compliance memory for New Zealand real estate, built on the sector's own case law.