The EU AI Act, which has established a binding legal framework for the use of artificial intelligence across all sectors since 2 August 2026, finds the real estate industry largely unprepared. A survey conducted by pom+ Deutschland among 86 decision-makers in the real estate sector in July 2026 illustrates this. The results show that a significant proportion of executives do not fully grasp the implications and requirements of the new regulations.
Specifically, the survey revealed that almost one in three executives has no knowledge of the challenges posed by the EU AI Act. A similarly high proportion of respondents could not assess how well their own company is prepared for the new requirements. These deficits particularly concern areas such as the transparency of AI applications, governance structures, and the handling of risks that may arise when using AI in processes such as document analysis, tenant communication, or property valuation. The deadline for full implementation of the requirements is December 2027.
Knowledge Gaps in Data Protection and Compliance
The pom+ Deutschland survey also uncovers that key aspects such as data protection, data security, and compliance with legal requirements are considered essential by only a minority of respondents. Just 11 per cent of executives attach high relevance to data protection and data security, while only 9 per cent classify compliance with legal provisions as critical. This suggests an underestimation of the complex demands that the EU AI Act places on companies.
Furthermore, the organisational effort associated with the implementation of the EU AI Act is perceived as a significant challenge by merely 2 per cent of respondents. Rebekka Ruppel, CEO of pom+ Deutschland, comments on these findings and emphasises that the real estate industry lacks the necessary expertise. The real challenge does not lie in the technical implementation of the AI Act, but in the realignment of responsibilities and the development of internal competencies. Creating expertise and adapting working methods would require a longer period than many assume. Ruppel points out that decisions regarding data protection and compliance are often made in different departments, but the ultimate responsibility lies with the board. Managing the issue "on the side" underestimates the regulatory and organisational changes that the AI Act entails.
- —One in three executives is unaware of the challenges of the EU AI Act.
- —One third of companies do not know how well prepared they are for the AI Act.
- —Data protection and data security are considered relevant by only 11 per cent.
- —The organisational effort is estimated as a hurdle by merely 2 per cent.














