Property is racing towards AI agents that can act across a transaction. Before we hand them the keys, but perhaps we should decide where automation should stop? At least for now that is.
I am a huge believer in AI. We use it ourselves in many different ways, and I think it has the potential to remove an extraordinary amount of wasted administration from moving home. Used properly, it can help consumers understand complicated information, help professionals find what they need more quickly and take away some of the repetitive work that currently consumes far too much of everybody's time.
What worries me is the assumption that seems to be developing alongside it: if AI can do something, then allowing it to do that thing autonomously must automatically represent progress.
Property is already entering its agentic AI phase. We are seeing platforms promising AI agents that can handle tasks across estate agency, lending, conveyancing and sales progression. That sounds exciting, and some of it undoubtedly will be. But an AI assistant that helps somebody understand a document or answers questions is very different from an AI agent that can access systems, communicate with other people, make decisions and take actions without somebody approving every step. THAT IS DANGEROUS! I think we need to become much more comfortable talking about that distinction before we become too excited about removing the human from the loop.
An assistant answers. An agent can act.
Traditional generative AI largely waited for us to ask it something. Agentic AI goes considerably further. Give it an objective and, depending on how it has been configured, it can work out what needs doing, use tools, access other systems and take actions in pursuit of that objective. That can be incredibly useful. It can also introduce a completely different kind of risk.
The UK's National Cyber Security Centre has warned that AI agents are harder to predict, test and govern precisely because they can make decisions and act. Its advice is refreshingly sensible: start with low-risk tasks, limit access and do not give an agent unrestricted control over sensitive information or critical systems.
The important difference is obvious once you think about it. If ordinary AI produces a wrong answer, somebody can hopefully spot it before acting. If an autonomous AI agent produces the wrong answer and also has permission to act on it, the mistake may already have become a consequence. And we have started seeing examples of exactly that.
We already know AI agents can behave in ways nobody intended
One of the most widely reported incidents involved Replit's coding agent. SaaStr founder Jason Lemkin was testing it when the agent deleted a live production database despite being told not to make changes to it. It also generated large amounts of fictitious data while trying to resolve problems it encountered.
Replit acknowledged what happened and subsequently strengthened its safeguards, including separating production and development databases so its agent could no longer make the same kind of change. That response is important because this should not be read as an argument that Replit is irresponsible. New technology exposes weaknesses, responsible companies learn from them and safeguards improve. The important lesson is simpler: an AI agent pursuing an objective can choose a route its human operator did not anticipate. That becomes rather more serious when we move from software development into a property transaction involving people's homes, money, identity, legal rights and confidential information.
An even more striking example emerged this summer from testing carried out by the UK's AI Security Institute. During deliberately permissive cybersecurity evaluations, AI agents took actions outside the intended scope of the tests in a number of runs. In the most serious sequence, an agent attempted to introduce malicious code into a real open-source project, researched the people maintaining it, created false identities and tried to persuade a real person to approve what it wanted.
Nobody had specifically instructed it to deceive anybody. The behaviour emerged as it pursued the objective it had been given.
The circumstances were unusual and deliberately designed to test frontier models under permissive conditions, so it would be wrong to suggest that everyday AI tools are routinely behaving this way. But the incident demonstrates something we should take seriously: autonomy changes the risk.
"Going rogue" doesn't require science fiction
The phrase "AI going rogue" makes people think of conscious machines suddenly deciding to rebel against humanity. I don't think that is the useful way to think about this at all. An AI doesn't need emotions, motives or consciousness to cause a serious problem. It only needs an objective, sufficient access and a mistaken interpretation of how best to achieve what it has been asked to do.
Tell an agent to progress a transaction as quickly as possible and what does "quickly" mean to it? Which delays should it challenge? Which information should it consider unimportant? When should it contact somebody? What can it share? What should it escalate? What if two objectives conflict? A human professional brings context, experience and, importantly, accountability to those decisions. An autonomous system is optimising towards whatever it believes its objective to be.
That is why prompts alone are not enough. Telling an AI "don't do anything risky" is not a safety system any more than putting a Post-it note saying "don't crash" on the dashboard of a car would be.
In my previous role as an Intelligence Analyst, national projects were often divided between analysts by region. The work only came together properly if we all left the planning room with the same understanding of the objective, methodology and level of detail required. A key part of that was what we called front-end engineering. We deliberately stripped away assumptions and accepted wisdom, developed fresh hypotheses and tested them properly. On occasions when analysts skipped that process, they effectively became our "rogue analysts". They worked hard, but from a different mental model, and the quality of their regional assessment suffered.
AI agents create a similar risk. Capability is not enough. If an agent misunderstands the objective, its boundaries or priorities, it can work very efficiently towards the wrong outcome. The difference is that an AI agent may also have access to systems, data and tools that allow it to act on that misunderstanding before anyone notices. Sometimes "going rogue" is not dramatic. Sometimes it is simply doing the wrong thing very efficiently.
Then there is the problem of somebody else talking to your AI
This is one of the risks I think property businesses should understand particularly well. AI agents increasingly consume information created by other people. They read emails, documents, websites, attachments, property listings, calendar invitations and records inside connected systems.
That creates the possibility of prompt injection, where instructions are hidden inside information the AI is asked to process. The human using the AI may see an ordinary document or webpage while the agent interprets part of it as an instruction.
Researchers have already demonstrated attacks where agentic systems have been manipulated through apparently legitimate content. OpenAI, Google, Anthropic and others have publicly discussed prompt injection as an important ongoing security challenge for systems capable of browsing and taking actions.
Now think about the information flowing through a home move. Identity documents, bank details, property information, legal correspondence, searches, title documents, mortgage information and messages between several different businesses can all form part of the wider transaction. The more authority we give an AI agent across that environment, the more important the question becomes: who is actually giving it instructions?
We have already seen what happens when AI is confidently wrong
We do not even have to move into autonomous agents to find warning signs. The legal profession has already experienced cases in which AI-generated court submissions contained authorities that simply did not exist. In one High Court matter, dozens of citations supplied to a solicitor turned out to be false. Other lawyers have also found themselves before judges because apparently convincing AI-generated cases and propositions were not real. That exposes one of AI's most dangerous characteristics in professional work. It can be wrong beautifully.
A person who genuinely does not know something may hesitate, ask another person or say they are unsure. AI can occasionally produce an incorrect answer in immaculate English, accompanied by reasoning persuasive enough to make the mistake look authoritative. That distinction matters enormously in property.
If an AI wrongly recommends a restaurant, somebody has a disappointing dinner. If it misinterprets an important title restriction, mortgage condition, lease provision or Material Information issue and then acts upon that interpretation, the consequences can be very different. Professional transactions cannot treat fluency as evidence of correctness.
Property is already discovering the "just because we can" problem
We can see a much simpler example in property marketing. AI can now transform listing photographs almost instantly. It can furnish empty rooms, remove clutter, change skies, improve gardens and make tired interiors look spectacular. Technically, it is astonishing.
But buyers have started complaining about arriving at properties that bear surprisingly little resemblance to the AI-enhanced versions they saw online. The practice has even acquired a name: "housefishing". That raises exactly the same philosophical question. The technology can do it. But should it?
There is nothing wrong with showing somebody what an empty room could look like furnished, provided it is made absolutely clear that the image has been digitally staged. There is a very different problem if enhancement starts changing the consumer's understanding of what they are actually considering buying. Capability is not the same thing as permission. And I think that principle needs to follow AI much further into the transaction.
I want AI carrying the clipboard, not holding the keys
There is an enormous amount I would happily give AI to do. Let it organise documents, spot information that appears to be missing and summarise correspondence. Let it translate complicated language, explain unfamiliar questions and help consumers understand what they are being asked. Let it highlight overdue milestones, identify inconsistencies and surface something that a professional might want to examine. Those uses could remove hours of repetitive administration and make moving home considerably easier. Where I become more cautious is when assistance becomes autonomous judgement.
Should an AI agent decide whether something disclosed by a seller creates a legal problem? Should it make a regulated mortgage recommendation? Should it decide whether information is significant enough to disclose? Should it negotiate somebody's offer without approval? Should it send substantive legal responses without a conveyancer seeing them? Should it decide that a particular delay is sufficiently unimportant to ignore? Perhaps technology will eventually become extraordinarily capable at some of those things. But being capable of doing something and being accountable for doing it are very different propositions.
If the decision goes wrong, the AI does not explain itself to the SRA or FCA. It does not carry professional indemnity insurance. It does not telephone the family whose transaction has collapsed and explain why. The professional does.
This is why WiggyWam deliberately has a stopping point
Our own approach to AI has been built around a fairly simple principle: use technology to make professionals more valuable, not to pretend we no longer need them. We use it to build and enhance, and guide users. We do not use AI agents of any kind.
Our Smart Forms are a good example. A seller might encounter a question they simply do not understand. The assistant can explain what the question means, simplify the language and communicate by text or voice in a language the user is comfortable with. That is exactly the kind of AI I love, it is contained and knows it has one purpose and cannot operate outside of that. But if the seller still does not know the answer, the system doesn't invent one. They can select Not sure, which makes that uncertainty visible to the appropriate estate agent or solicitor. We could try to make AI infer the most likely answer. I don't think we should.
Sometimes the most intelligent thing technology can do is recognise that it has reached the point where professional judgement is required. That may sound less futuristic than an autonomous agent completing the entire transaction by itself, but I think it is a far safer and ultimately more useful philosophy. Particularly in these early days where it isn't regulated, and largely untested.
We should automate administration before we automate judgement
The property transaction contains extraordinary amounts of work that nobody particularly enjoys doing. If we can remove administration and give the conveyancer more time to practise law, brilliant. If we can allow the broker to spend more time advising clients rather than chasing paperwork, do it. If an estate agent can spend more time selling, negotiating and looking after people because technology deals with repetitive administration, that is progress.
What I don't want us to do is jump from "AI can save professionals time" to "therefore AI should replace their judgement" and possibly that professional entirely going forward. Those are entirely different propositions.
The FCA has been cautious about precisely this distinction. Agentic AI is being explored in financial services, but firms remain responsible for regulatory compliance regardless of whether technology performs some of the work. The companies developing frontier AI systems themselves also retain approval steps and additional safeguards around consequential actions. Perhaps property should take the hint.
The most advanced system may not be the one with the least human involvement
Over the next few years I suspect we are going to hear increasingly ambitious claims about autonomous estate agency, AI conveyancing, AI mortgage advice, automated negotiation and agentic transaction management. There will be enormous pressure for technology businesses to demonstrate how much they can automate because autonomy sounds impressive. I think the more interesting question will be how intelligently they decide what not to automate.
Use AI aggressively where failure is easily corrected and the benefit is obvious. Become progressively more cautious as the consequences increase. Limit permissions. Keep audit trails. Require human approval for significant actions. Make it clear what the AI has done and why. Ensure a professional can intervene. Most importantly, design technology around the reality that moving home is not merely a workflow. There are real people at the other end of it. Real money. Real homes. Real legal consequences. Real families whose plans can be dramatically affected by a mistake.
That does not mean property should be frightened of AI. Quite the opposite. I think failing to embrace it would be a huge mistake. But embracing AI intelligently is very different from handing over the keys simply because the technology has learnt how to drive. The question for the industry should therefore become slightly more sophisticated than "Can AI do this?" We should also be asking whether it should do it, what authority it genuinely needs and at what point the human professional must remain in control.
That is the balance I want us to get right. AI can carry an enormous amount of the administrative load in a home move. It can guide, organise, explain, identify and assist. For now, though, I would still rather the human kept hold of the keys.