AI in Housing: The NHF Report Explained

Written by Phil Brining

The National Housing Federation’s new report shows AI is already widespread in housing, but confidence and governance haven’t kept up. Here’s what the findings mean for your data protection obligations, and four steps to take now.

AI in Housing What the NHF's 2025 Report Means for You

The National Housing Federation has published a new report, The State of AI in Housing 2025, produced with IT services provider Phoenix, looking at how housing associations are adopting artificial intelligence, the opportunities it offers, the risks it creates, and how ready the sector actually is. It is not new legislation and does not create new legal duties, but it is genuinely useful sector insight for any housing provider already using AI, considering it, or finding that colleagues are quietly experimenting with it already.

AI adoption in housing is already well underway

The headline finding is that AI is not a future consideration for housing, it is already in day-to-day use. The report found that 47% of respondents are using AI in their daily operations, with a further 23% not using it yet but planning to. Current use cases span internal administration, data handling, compliance checks, resident communications and service delivery.

Confidence and governance haven’t kept pace with adoption

The report also shows a sector that is moving faster than its own readiness. 87% of respondents rated their knowledge of AI as low, and 44% have no AI policy in place at all. That gap, widespread use alongside limited confidence and limited governance, is the part of the report worth paying closest attention to. AI can genuinely help a housing provider save time, support staff and improve services, but it should never be treated as a straightforward technology purchase or a way around existing data protection obligations.

The same data protection questions still apply

Whatever the tool, the same questions need answering before personal data goes anywhere near it. What is the purpose? Is the use necessary? What is the lawful basis? Have people been told clearly what is happening with their data? Is the information secure? And are you confident the tool itself is accurate and fair?

These questions carry extra weight in housing specifically, given the nature of the data involved, often including residents’ health, financial circumstances, vulnerabilities, safeguarding concerns and household situations.

Where the real risks sit

The report highlights privacy and security, bias and discrimination, accountability, and inaccurate AI-generated information as the key areas to watch. AI can produce an answer that sounds entirely convincing while being wrong, and it can reflect bias baked into the data it was trained on. That matters most where AI could influence decisions about residents, allocations, arrears, complaints handling, vulnerability assessments or safeguarding.

The safest approach is straightforward: do not let AI make high-impact decisions about individuals without a proper assessment, meaningful human involvement, and a clear route for someone to challenge the outcome.

A sensible way to adopt AI, according to the report’s own case studies

The organisations getting this right in the report’s case studies followed a similar pattern: start with a lower-risk use case, secure genuine leadership support, involve staff early, and put governance in place before the project expands rather than after.

Four steps worth taking now

Based on the report’s findings, four immediate actions stand out for any housing provider:

    • Find out which AI tools are actually being used across the organisation, including tools staff may be using independently without anyone else knowing.
    • Put clear guidance in place so staff know exactly what can and cannot be entered into an AI tool. Personal, confidential and special category data should never go into an unapproved tool.
    • Carry out proper due diligence on any AI supplier, understanding the contract, where data is processed, whether there are international transfers, and what security measures are actually in place.
    • Assess higher-risk uses properly. Where an AI project could create a high risk to people’s rights and freedoms, a Data Protection Impact Assessment may be required before processing begins.

Adopt AI thoughtfully, not cautiously or carelessly

The message from the report isn’t to avoid AI, it’s to adopt it thoughtfully. Innovation and data protection aren’t competing priorities. Good governance, clear policies, trained staff and proper oversight are what give a housing provider the confidence to use AI in a way that protects residents, supports staff and builds trust.

For housing associations without the in-house resource to build that governance from scratch, this is exactly the kind of gap an outsourced DPO is built to close, bringing practical AI policy development, supplier due diligence and DPIA support without needing to build the capability internally. If you’re considering an AI project, reviewing a supplier, or need support with an AI policy or DPIA, speak to your Data Protection Officer or get in touch with the Data Protection People team.