Is Your HOA Manager Using AI? What California Law Has to Say About It.
It's probably fair to assume your property manager is using AI, whether backstage in drafting correspondence, customer facing in the answers you receive, or built into a chatbot in your HOA portal. That's not automatically the problem. The problem starts when it gives you incorrect information, when it doesn't forward your request, when it promises something the manager can't actually fulfill, or, more importantly, when it touches your data.
Why This Matters
Here's the thread running through all of this: the manager is the one deciding to use AI, choosing which product to use and benefiting from it, and because it's classifying AI as a software tool, it does not ask the association for permission. But the software comparison undersells what's actually different here. The accounting platform, the e-signature tool, the CRM, all of that software does exactly what it's told and nothing more, the manager stays fully in control of the output. AI doesn't work that way: it generates its own answers, with its own judgment calls baked in, and it can be confidently wrong in ways none of those older tools ever were. That's not a difference of degree, it's a difference in kind, and it's exactly why treating AI like just another item on the software list undersells the risk. And underneath the risk question is a control question: the manager is the association's agent, and an agent's authority comes from the principal, bounded by what the board actually authorized. The board pays the manager for management services, not for the manager to make unilateral calls about exposing the association to serious risks and liability which may result from irresponsible use of a new generation of tools to perform that management. Using AI without asking isn't just a source of downstream liability, it's a question of whether the manager is acting within the scope of what it was hired to do.
That same agency relationship also decides who bears responsibility once something goes wrong, and that protection for the manager runs deep on its own: agency liability is typically limited by exclusions like fraud, gross negligence, and otherwise has a contractual monetary cap, which usually reflects a few months of compensation. And even where the manager's own insurance might otherwise pick up a loss, that coverage is increasingly carved out for AI specifically, professional liability and cyber policies that used to be silent on AI (neither covering nor excluding it by default) are now adding explicit AI exclusions.
So the two layers that would normally absorb some of this risk, agency-law limitations and insurance, are both narrowing for AI specifically, at exactly the moment AI use is expanding. That's the real argument here: AI isn't just another tool the manager has picked up, it's different in kind, and it deserves its own explicit discussion and regulation in the contract, rather than being left to default agency principles that leave the association liable for decisions it didn't make and often didn't even know about.
That argument breaks down into three concrete problems: (a) data privacy, (b) responsibility for errors, meaning who's actually on the hook when the AI is wrong, and (c) the general problem with relying on AI. Understanding all three is what makes it possible to have the right conversation with your manager, and to know what belongs in the contract, covered further down.
References below to “§” are to the Davis-Stirling Common Interest Development Act, California Civil Code §§4000-6150, unless otherwise stated.
The Data Privacy Problem
Under Civil Code §5230(c)(1)(B), an association or its managing agent shall not transmit a member's personal information to a third party without the consent of the member, unless required to do so by law.
So what does it mean? That under the law, the managing agent cannot, without the member's consent, transmit a member's personal information to a third party. It also means that the consent must come from the member. The board cannot give such consent on behalf of the member, and a property management agreement cannot change the statutory law. The association holds the member's information as a custodian, and a member is required to provide certain details to the association. Neither the association nor the board can, without the member's consent, share the member's details with an AI tool, particularly to retain that information or train a model on it.
This is also where the specific AI tool matters, and it's a fair thing to ask your manager directly. The line that actually matters isn't price, it's whether the manager is on an individual consumer account or a business account covered by a data processing agreement.
On individual accounts, free or paid, whether conversations are used to train future models by default depends on the provider: some make it opt-out, meaning training happens unless the user turns a setting off, others make it opt-in, meaning it doesn't happen unless the user turns a setting on. Either way, that setting is typically tucked into account or privacy settings rather than surfaced prominently, so a paid subscription alone doesn't tell a manager which state they're in, let alone confirm they've actually checked. Some tools also offer a separate temporary or incognito-style chat mode with its own rules. Whichever direction applies, it's a training setting, not anonymization: even where training is off, the conversation itself is typically still retained for some period regardless.
Business, team, and enterprise accounts, and most API access, typically exclude training by default and separately negotiate their own retention terms, often shorter, sometimes reducible to zero for qualifying accounts.
Neither promise is absolute. A provider's stated retention policy is a default, not a guarantee, and litigation can override it. In 2025, a federal court ordered OpenAI to preserve ChatGPT logs, including ones users had deleted, across its free, Plus, Pro, and Team tiers, as part of discovery in an unrelated lawsuit, overriding its usual 30-day deletion window, until the order was lifted later that year. Accounts under a zero-data-retention business agreement were excluded. A manager's promise that a tool "doesn't keep your data" is only as good as what happens the day a subpoena or litigation hold shows up.
None of this means the data stays off a server, either. Short of the manager running an open-weight model entirely on its own hardware, which is rare in practice, the information is still transmitted to and processed by the provider even when training is switched off. Not being trained on is not the same as not being stored, and not being stored under normal policy is not the same as not being recoverable under legal process.
Who Pays When AI Gets It Wrong
As covered above, that agency relationship means all errors, hallucinations, or unauthorized actions the manager's AI system makes fall on the association by default.
Underneath that is a question of supervision and judgment. Using AI is the manager's choice to make, and it's usually made autonomously: the board isn't asked, isn't told which tool is used, and has no visibility into whether a human ever checked the output before it was relied on. That autonomy is exactly what turns an AI mistake into the association's problem. The manager decides, banking the gains; the association takes the risk and pays.
That exposure is written into the statute directly for privacy violations specifically. Under Civil Code §5230(c)(2), a member may bring an action against an association that violates §5230(c)(1)(B), the data-privacy rule above, for injunctive relief and actual damages caused by the violation. A member is entitled to recover reasonable costs and expenses, including reasonable attorney's fees, in a successful action to enforce the member's rights.
Note that under this statute, the member brings the action against the association, not the manager, and that the statute explicitly allows recovery of reasonable costs and expenses in a successful action. So ultimately, both the responsibility and the cost for the manager's AI use fall on the association.
The General Problem With Reliance on AI
Large language models (LLMs) have been trained on broad sets of data. That rarely includes vast data sets on your jurisdiction's HOA law. There's a broader pattern here too: the more specific the questions you ask, particularly in narrow areas where exceptions apply and reasoning is complicated so that expert knowledge is required to provide a correct and comprehensive answer, the higher the margin of error. AI can be trained for specific knowledge of specialized narrow areas like insect recognition, different dermatological conditions, or, in this case, a jurisdiction's HOA law, but generic models rarely do good work with this.
In practice, the LLM's answers, while sounding authoritative, are either partially wrong or incomplete, or the model performs so-called sycophancy, where it's trying to please the person who's asking by bending facts or hallucinating. It's not a bug, it's a feature. People wouldn't like a model that constantly disagrees and challenges you. And the more complicated the answer is, the more likely that the model will omit exceptions, provisions that should be read together, or simply not collect the data required to provide an accurate answer. This kind of authoritative-sounding advice can also feed conflict from both sides of a dispute, where each party thinks they're right because their AI said so.
Unless there's a trusted source outside the AI, or a human expert, to verify the answer against, a person without training or expertise often has no way to know if the answer is correct. You don't know what you don't know. So use the tools, they often help, just verify what you read to the extent you can, and give the advice the level of confidence you'd give a law student who prepared well for an exam, not an attorney who has practiced for ten years. If you are communicating on behalf of the board or association, it would be genuinely useful to share the sources of your reasoning, both references to statutory law, and unless you're fully confident of the answer and have the means to verify it, disclosure that the advice comes from an AI model which can make mistakes.
Mitigating the Risk: What the Contract Should Say
Three problems, one common root: the manager decides whether and how to use AI, and the association carries the liability regardless. That's not a reason to ban AI use, it's a reason to make sure the contract addresses it. Here's where that risk actually gets negotiated, starting with what to watch for.
What a One-Sided AI Clause Looks Like
Some management contracts try to sneak clauses like this into the agreement: a very generic clause allowing the manager to use AI while providing services, paired with a very specific exclusion of liability for any errors and hallucinations, or how inputted data is handled, and a very generic, very broad disclaimer covering AI use on top of that.
Read together, that combination does two things at once: it gives the manager unrestricted permission to use AI, and it disclaims the manager's own responsibility for the two things most likely to go wrong, bad output and mishandled data, including exactly the kind of data-transmission issue §5230(c)(1)(B) already regulates. The manager keeps the efficiency gains. The association keeps the risk, and under §5230(c)(2), the statutory liability too. A contract cannot waive the underlying statute, but it can absolutely leave the association fully exposed to it while the manager who created the exposure walks away clean.
What Goes Into a Balanced Contract
If you're a board member and you're asked to sign off on a new contract, or changes to the existing contract that include clauses allowing AI use, or you're auditing your existing contract and find such clauses already in it, what should you do? Or, more likely, AI hasn't been mentioned in the contract at all, whether it's being used quietly in the back office or openly in member-facing tools.
Well, use of AI itself is not a problem, it can be a very helpful tool. The problem is if the manager, instead of using general tools like email proofreading, template generation, or asking general questions, starts to input members' personal details into a system where a third party has access to them and can retain them, in direct breach of §5230(c)(1)(B).
The second problem is if the manager wants to keep all the efficiency gains for themselves and allocate all the risks to the association.
First thing I'd do: ask if the contract template was drafted and blessed by the manager's attorney. A professional manager should have its contract templates blessed by an attorney since they probably have more than one customer and are using the same tools across their business, and anything else is a red flag meaning they are not serious about their business. It's also a good practice for the association to retain its own attorney to review the contract and any amendments to it. Even if the contract template was prepared by an attorney, it's an attorney for the manager, who owes no duty to the association.
A property management agreement is an important document of the association, the property manager is the most important vendor who can also cause the most harm, so it is prudent to allocate budget for review of arguably the most important contract of the association or significant changes to it.
One more thing worth checking, and it's fair to expect the answer might be no: ask whether the manager's professional liability or cyber policy actually covers AI-related losses at all. As covered above, insurers have been adding explicit AI exclusions to standard professional liability (E&O) and cyber policies since early 2026. A handful of specialty insurers have started offering AI liability coverage since then, either as its own policy or as an endorsement added to professional liability, so the option exists in the market in a way it didn't two years ago. That's a different claim from "your manager can easily go get one," though: this is a new, specialty corner of the insurance market, not something every general small-business broker offers yet, and whether a particular manager's size, carrier, and AI use pattern would actually qualify is a separate question that would have to be checked policy by policy, not assumed either way. So don't expect "yes, we're covered" as the default answer, and don't expect "we'll just go buy that" to be a simple fix either. The honest answer may well be that nothing the manager carries responds to an AI-related loss at all, and that finding out is worth doing before you sign, not after something goes wrong.
That changes what the indemnity clause is actually worth. Most property management companies are LLCs, and an LLC's owners aren't personally on the hook beyond what they've put into the company. If there's no insurance behind an AI-related loss and the manager has little capital, a signed indemnity clause can be legally solid and still worth very little in practice, there's simply nothing there to collect. That's not a reason to skip the indemnity clause. It's still worth having. But it is a reason to go in clear-eyed: for a thinly capitalized manager with no AI-inclusive coverage, the contract's promises are largely aspirational. The real risk management happens earlier, in deciding whether to use that manager at all, or how much AI-related exposure the association is willing to accept.
What Fair Risk-Sharing Actually Looks Like
None of this is really about banning AI or the association simply absorbing whatever risk shows up, it's about fair risk-sharing, and there's more than one way to get there. The manager chose to use AI and generally captures the benefit of that choice: faster turnaround, lower staffing costs, a feature it can market to clients. If a normal professional liability or cyber policy no longer covers AI-related losses, and using AI is the manager's own decision, then insuring that decision properly, whether through a standalone AI liability policy or another form of adequate coverage, is a fair cost of doing business that way, not something the association should be expected to absorb by default.
That will likely cost something, where it's obtainable at all, and there's no fixed number to point to. Standalone AI liability coverage and AI endorsements are underwritten individually, based on how intensively a business uses AI and how much governance it can document. A manager may reasonably want to pass that cost through in its management fee. That's a legitimate negotiation, not a reason to skip asking. The alternative is the manager keeping the full benefit of using AI while the association carries the uninsured risk of it going wrong, which isn't a fair split by any measure. And if no coverage turns out to be available, that's not a dead end, it just shifts more weight onto the indemnity clause and the human-review requirements below.
Insurance isn't the only lever, either. A manager running its AI tool on its own infrastructure, rather than through a third-party consumer or business cloud product, reduces the data-transmission exposure covered earlier; that doesn't eliminate liability for a bad or hallucinated answer, but it does take one whole category of risk off the table, and it's worth asking whether that's realistic given the manager's size and technical capability. And responsible use, human review of anything that matters before it's relied on, disclosure when advice comes from AI, documented staff training, is doing real work on its own: that's what Clauses 1 and 5 below are for, and it's also, not coincidentally, the kind of governance insurers say they price coverage on. Better practice and lower premiums point the same direction.
So there's a real menu here: require AI-inclusive insurance, favor tools that keep data in-house, tighten the human-review and disclosure requirements, or some combination. The association doesn't have to solve all of it in one clause. What matters is that whichever combination the board lands on actually shares the risk, rather than leaving the manager with the full upside of using AI and the association with the full downside.
If you are reviewing a new contract or changes to the existing one, here's the suggested clause language, also discussed in HOA Property Management Contract Review Checklist, which walks you through the relevant issues that should be discussed in relation to AI use by the manager:
1. Permission, with a disclosure floor
Management Company may use artificial intelligence tools (“AI Tools”) to assist in performing its duties under this Agreement, provided that any output materially relied upon in a decision, communication, or recommendation affecting the Association shall be reviewed, exercising reasonable judgment, by a qualified human employee of Management Company prior to reliance. Management Company represents that it uses [insert AI tools and tiers] as its designated AI Tool(s), and that the following services involve AI Tool use: [name]. If Management Company changes or adds AI Tools, it will notify the Board in writing within five (5) business days identifying which AI Tools are used for which services.
2. Data-handling restriction
Consistent with Civil Code §5230(c)(1)(B), Management Company shall not transmit any member's personal information to any AI Tool without that individual member's own consent, obtained directly from them, Board approval alone does not satisfy this requirement, unless the transmission is otherwise required by law (including disclosures required under Civil Code §5200 et seq.). Management Company shall not input any confidential Association information, financial records, or privileged communications into any publicly available or general-purpose AI Tool that retains, trains on, or otherwise processes such data outside Management Company's controlled environment. Use of enterprise-grade AI Tools with contractual data-protection and non-training commitments equivalent to Management Company's obligations under this Section is permitted without separate consent.
3. Accountability when it goes wrong
Management Company shall promptly correct any error, omission, or adverse consequence to the Association or its members arising from Management Company's use of an AI Tool, at Management Company's own expense, and shall notify the Board within 48 hours of discovering any unauthorized disclosure of Association or member data caused or contributed to by an AI Tool, in addition to and without limiting any notification obligation arising under Civil Code §5230(c)(2) or other applicable law.
4. The liability/insurance balance
The limitation of liability set forth in Section [Indemnity and Liability] shall not apply to losses arising from Management Company's breach of Clauses [2] or [3] above. Management Company shall carry, at its own expense, professional liability (errors and omissions) insurance and cyber liability insurance, each in an amount of not less than $[1,000,000] per occurrence, and shall furnish certificates evidencing such coverage upon request. Regardless of whether such insurance responds to the claim, Management Company shall indemnify, defend, and hold harmless the Association for any damages, injunctive relief compliance costs, and attorney's fees awarded against the Association under Civil Code §5230(c)(2) or other applicable law arising from Management Company's use of an AI Tool.
5. Individual acknowledgment
Before gaining access to Association files, every manager working on the Association's data will sign a statement, delivered to the Association, confirming they are: (i) aware AI can make mistakes and outputs should be double-checked, or disclosed as unverified if they cannot verify it themselves; (ii) aware of AI sycophancy; (iii) aware that information entered into non-designated AI tools may be retained indefinitely, used to train future models, or produced under subpoena; and (iv) familiar with this AI clause and undertake to comply with it.
Not every board reading this is negotiating a new agreement, some of you are dealing with an existing signed contract that already has AI exposure baked in, and a full renegotiation isn't realistic right now. From there, two options: ask the manager to sign an AI annex or addendum incorporating the clauses above, or, a lighter-weight alternative, ask for the standalone indemnity letter described below. The rest of what to look for in a management contract beyond AI specifically is covered in HOA Property Management Contract Review Checklist.
For that lighter route: at minimum, ask the existing manager to sign an indemnity letter, a written confirmation covering the same ground as clauses 2 through 4 above, that it's aware of and will comply with its obligations under §5230(c)(1)(B), and that it will indemnify and defend the association for any losses under §5230(c)(2) arising from its AI use, whether or not that use technically breaches the statute. This is purely a risk-allocation exercise, and a manager unwilling to sign a simple letter confirming it'll follow a law it's already bound by is telling you something.
What This Means for You
If You're a Board Member
Where you are shapes what to do next:
- Selecting a new manager, or negotiating a new contract: build the clauses above in from the start, permission with a disclosure floor, the data-handling restriction, and the liability and insurance language.
- Reviewing an existing contract at renewal, or negotiating changes to it: that's the moment to add AI-specific clauses if they aren't in there already, don't let the renewal go through silently.
- Already locked into a contract that's silent on AI, or has one of the one-sided clauses above, with no renewal in sight: ask for the standalone indemnity letter rather than waiting for the next negotiation window.
Whichever applies, ask your manager which AI tool and tier it uses, and for which services, and read any existing liability language carefully for the one-sided pattern above. If they want to use AI, the risks for the association should be mitigated, in writing. The alternative is no AI use permission.
If You're an Individual Member
If you're concerned about how your association or its manager is handling AI, put your concern in writing to the board, citing §5230(c)(1)(B) and §5230(c)(2) directly. Ask the board to confirm with the manager whether any of your personal information has been shared with an AI tool, and if so, under what consent. Treat an AI-sourced answer about your specific situation as a starting point for your own verification, not a final answer.
Key Takeaways
An AI-generated answer from your property manager can be wrong in exactly the way that sounds right. Always verify the answers with the statute, and ideally with an expert or at least someone familiar with the regulations. Agency law puts that cost on the association by default, and §5230 makes it explicit for privacy violations specifically, unless the management contract says otherwise. Ask what tool your manager uses, read what your contract says about it, and if it says nothing, that silence is not neutral.
AI is a powerful tool and should be used responsibly.
Not legal advice. General information for California board members and homeowners navigating AI use by their property manager.
© 2026 Haveny LLC. All rights reserved. This article may be quoted with attribution to Haveny LLC and a link to the original. For licensing or republication, contact [email protected].
This article provides general legal education and strategic guidance, not legal advice. For guidance specific to your situation, consult a qualified attorney.