
The third part in our 'AI in CRE' series, exploring the threats, risks, and ethical challenges concerning AI usage.

As we’ve noted in the first two parts in this series, Artificial Intelligence has the potential to generate significant opportunities for commercial real estate owners, but the conversation around AI adoption often focuses on the potential for efficiency gains, automation, and innovation and gives far less attention to the risks. But it’s vital to recognise the challenges that must be met to be successful with AI, and that is what this post covers.
As AI becomes more deeply integrated into buildings, operational workflows, and investment systems, CRE firms are going to face a growing set of challenges. Importantly, the same technologies that improve efficiency will doubtless result in new vulnerabilities, many of which are new even to experienced IT people. And this is without considering the current noise around AI ‘agents’ which purport to be able to take decisions that replace human input (spoiler: very unwise without extreme caution).
What vulnerabilities? Quite a number: Smart buildings can become targets for hackers; they can also become surveillance environments. Automated systems can make flawed decisions. Connected infrastructure, and particularly AI, expands cyber risk. And organisations can become overly dependent on technology they do not fully understand.
Whilst I am a strong advocate for AI adoption optimising CRE assets and decision-making, the CRE sector must confront an important reality: AI adoption is not simply a technology initiative - it’s also a governance and risk management challenge.
Without a doubt, the greatest risk in AI today across the market is unrealistic expectations. AI vendors are marketing systems as fully autonomous, highly intelligent, or transformational - effectively, as if they’re magic. In reality, many deployments remain relatively narrow in capability. That isn’t a bad thing - it’s actually the right approach in many, perhaps most, cases. But non-technical people in general have come to see AI as somehow intelligent (it isn’t) and capable of understanding the risks or real-world ramifications of its actions (it doesn’t).
Worse, many business leaders are seeing AI as a silver bullet answer to the problems they’re facing, particularly around higher costs, squeezed margins, siloed systems, and poorly-performing assets. The problem is that AI cannot fix processes or data that are broken. People are quite good at that because they understand context and meaning, and they have experience to fallback on. AI has none of those things. Many organisations that have tried to adopt AI at scale quickly to reduce headcount (and therefore costs) are learning that costly lesson now. And worse, as the cost of Generative AI (tokens) rises, they’re finding it’s becoming much more expensive than they assumed.
None of this should be taken as a negative view on AI - it’s a call for strategic clarity and a well-considered adoption process, planned with the knowledge of the realities of AI. And if you don’t have them in-house, get outside help - and not from anybody that’s trying to sell you the AI!
So let’s walk through the leading challenges:
1. Technical
2. Legal, regulatory,and ethical
3. Financial
4. Organisational
5. Systemic complexity
AI is only as effective as:
• The quality of underlying data
• The integration of building systems into a single control plane
• The maturity and reliability of operational workflows
AI systems depend on the provision of high-quality data. If data isunstructured, duplicated, incomplete or anomalous, most if not all AI systemswill struggle. Humans can often work round such problems, but AI won’t.
Unfortunately, commercial real estate data is often siloed, inconsistent, or incomplete. Common problems include:
• Manual reporting errors
• Fragmented (and paper-based) operational databases
• Inaccurate equipment metadata
• Inconsistent naming and data format conventions
• Faulty or poorly planned sensor installations
If AI systems are trained on flawed data, the outputs will be flawed. Some examples (among many) include:
• Energy optimisation platforms may make inefficient or counterintuitive adjustments
• Predictive maintenance systems may generate false alerts
• Occupancy analytics may misinterpret building usage patterns
• Investment models may produce inaccurate forecasts
Organisations that attempt AI adoption without first addressing data quality and governance will experience disappointing results and wasted investment.
Most M&E equipment and software platforms, even in modern PropTech, are not designed to integrate or share data, leaving the integration problem to Master Systems Integrators (MSIs) and/or middleware platforms. The former can be expensive (even if they succeed), the latter are often compromised through the sheer complexity of buildings and almost infinite combinations of installed systems. In CRE, every building is a snowflake. As a result, many organisations underestimate the complexity of implementation. Buildings frequently contain:
• Proprietary vendor ecosystems
• Legacy systems that don’t support data output/sharing
• Inconsistent equipment standards
• Incomplete sensor deployment
• Siloed and fragmented data environments
Given the criticality of achieving good quality data, AI systems will only produce reliable outputs if these issues are addressed. In poorly integrated environments, AI is likely to create more operational confusion than clarity.
There is a temptation to think of AI as intelligent in the same way ashumans are (a problem in the naming), but it isn’t. AI can do amazing things inpattern processing or analysing high quantities of data far more quickly than ahuman would, and if used in the right way offers significant benefits. But,like all waves of new information technologies before it, AI is not a silverbullet. As well as requiring good data for training and operation, AI alsoneeds well-defined processes and workflows. If they are poorly-defined now(relying on humans to know or work out where the problems are and what they’resupposed to do), AI won’t fix them. In fact, it will amplify them.
Just as data needs tobe fixed to implement AI successfully, your operational processes need to befully thought through to ensure that an automated system can adopt them.
AI governance regulations are evolving rapidly (though many would argue not quickly enough). But even at the current pace, Governments and regulators are increasingly scrutinising:
• Data privacy
• Biometric systems
• AI transparency and automated decision-making
• Cybersecurity requirements
The first two points are straightforward to understand. The second two less so. Transparency in how AI systems do their work, and particularly when automated decision-making enters the picture, is becoming an important issue, largely for legal reasons. If an AI makes a choice that causes harm or loss, who is responsible? How did it make the decision it made? And how might you ensure that it doesn’t make that mistake again?
Many deep learning systems are essentially black-box - they have learned from data, then established internal decision structures and rules that aren’t available for checking or explanation. When Google subsidiary DeepMind created AlphaGo Zero in 2017, it learned the game of Go from scratch, played itself a few million times as practice, then beat its predecessor AI100-0. And that earlier system had already beaten the best human player to have ever lived. But nobody from DeepMind understood how it was making its decisions. There was no transparency, or any way to reverse-engineer the system to work it out. In an environment in which legal ramifications could be serious, transparency must be considered.
CRE firms deploying AI systems will surely face growing compliance obligations. This is especially important for healthcare properties, Government facilities, financial institution offices, and large corporate campuses.
I will cover cybersecurity in more detail in the next paper in this series, but for now it’s enough to say that there are two tiers to the cybersecurity challenge.
First, very few buildings that we’ve audited to date actually have proper cybersecurity provisions in place today(less than 15%). This is likely to be a result of a historic lack of digitisation, and therefore need. But the introduction of connected and smart systems, public wifi, etc. is opening up those buildings to real cybersecurity threats.
Second, AI cybersecurity is not like traditional cybersecurity. In the latter, you’re effectively putting up walls and shielding your data from attack (usually from the outside). You can architect a solution that will protect you. AI systems can’t be protected inthat way, because of how they work. And that’s particularly true for Large Language Models (LLMs) like ChatGPT, Gemini, CoPilot, or Claude, because they’ve been trained on data over which you have no control and to which anybody can(and has by definition) had access. I’ll go into this in more detail in the next paper.
Smart buildings collect enormous amounts of data that relates to humans - personal data - including:
• Occupancy patterns
• Movement throughout buildings
• Workspace usage
• Environmental conditions
• Access control records and behaviour
• Video capture
• Mobile device interactions
AI-powered analytic systems are designed to transform this data into highly detailed behavioural insights, in order to make operations more efficient and provide a better tenant experience. But collecting such data also leads to serious questions about privacy.
The potential for misuse is considerable. Employers may be tempted to use occupancy analytics to monitor employee productivity or movement patterns. Facial recognition systems may raise concerns around consent, data retention, misidentification, and bias. All of these concerns can erode employee trust.
As buildings become more smart and connected, organisations must laydown carefully defined ethical boundaries. Without clear governance, suchbuildings risk damaging tenant relationships and workplace culture.
AI systems are not inherently neutral. They are trained on data provided to them and/or human input. By definition, they will reflect the assumptions in the humans and/or data used to train them. In commercial real estate, this could create significant risks, including issue such as:
• Biased tenant screening algorithms
• Discriminatory leasing recommendations
• Unequal workplace access experiences
All of which may unintentionally create legal and reputational exposure. As AI regulation expands globally, ensuring fairness and transparency will become increasingly important.
A notable challenge is dependence on technology vendors. Everyone understands vendor lock-in, the costs associated with rising annual maintenance or licence costs, and the high barriers to change that switching suppliers can engender. Some vendors actively discourage change through contract conditions. One example I’ve seen is a vendor of a SaaS platform that imposes significant charges for a leaving customer to get possession of their own data!
The CRE sector is not immune to these issues. Many smart building platforms operate within proprietary ecosystems. Owners may find themselves locked into:
• Specific software platforms
• Sensor manufacturers
• Cloud providers
• Data formats
• Long-term service agreements
This can create operational and financial constraints and push the barriers to innovation even higher.
Given the proliferation of PropTech vendors and the high level of failures, consolidation in the smart building market is also likely to contract and reduce flexibility over time. CRE firms should therefore prioritise:
• Open standards
• Interoperability
• Data portability
• Contract flexibility
Technology decisions made today may shape building operations for decades.
AI implementation can require substantial investment. Not just for the AI itself, but in making the underlying data and systems fit for purpose. Costs might include:
• Sensor deployment
• Networkmodernisation
• Software licensing
• Cloud infrastructure
• Integrationconsulting
• Cybersecurity, and
• Staff training
Over the past few years, I’ve seen many projects fail to generate the expected return on investment. Mostly because of the technical challenges outlined in section 1 above, which result in organisations finding that the technologies and the data they produce remain underutilised. Others struggle to scale pilot projects across portfolios, often because of different technical environments in different buildings, which wasn’t fully understood at the outset.
The pace of technological change also creates obsolescence risk - platforms that appear advanced today may become outdated quickly, which is why avoiding vendor lock-in is so important. The right way to approach AI iswith strategic intent - a clear plan in place for what you’re trying to achieve with AI, where it can be applied to best effect, and how you’re going to avoid the challenges outlined in this paper.
One of the most important strategic questions in CRE is how much operational control should be delegated to AI. As buildings become increasingly autonomous, there is a risk that organisations become overly dependent on automated systems.
While it is likely that, over time, properly-deployed AI will displace many human roles that exist today, skilled human operators will remain important for the long term. Many companies in other sectors that are crashing ahead with AI deployment to reduce headcount are losing institutional knowledge and/or become less capable of responding during unforeseen edge events or system failures, resulting in operational vulnerabilities.
This is particularly true of AI systems that “learn” and adjust their model (and behaviour) over time based on the data they’ve received. In CRE for example:
• An AI-driven HVAC system could optimise aggressively for energy savings while reducing occupant comfort
• Automated maintenance scheduling could overlook unique equipment conditions
• AI-generated leasing recommendations could misinterpret local market dynamics
The important thing to consider here is that not all AI is created equal. There are many different technologies and options within the AI world, and properly matching the right tech to the right application will avoid many of these issues. Although fully automating some tasks makes sense, it is certain that many other tasks will benefit from humans being augmented by AI assistance, rather than their roles being eliminated.
Companies are fond of saying that people are their most important asset, which is recognised as often being little more than lip service. And the marketing hype around AI (almost exclusively originating from the AI vendors themselves) promotes AI as replacing all jobs in the near future. The good news is that it isn’t true, or even desirable. But most people who aren’t AI specialists don’t know that - they just see the headlines, which gives rise to considerable suspicion about AI in general. Many of those people - either employed by an owner or any of the service providers they work with - may well become unsettled, and could create resistance to implementation.
Successful AI adoption requires organisational alignment, training, and leadership communication. All firms deploying AI should be cognisant of this, and handle deployments with transparency, being clear about the objectives, and the role that humans will still play in the organisation.
And finally, the issue of systemic complexity. As buildings become more interconnected, operational dependencies increase - a failure in one system can potentially affect many others. Examples include:
• Network outages disrupting access control
• Software failures affecting HVAC operations
• Cloud service interruptions impacting building management systems
• Sensor failures distorting analytics
Highly connected buildings may become operationally fragile if resilience is not prioritised. This is why governance, redundancy, cybersecurity, and operational oversight are becoming increasingly important. These issues are not traditionally high on an asset owner’s priority list; usually such issues are outsourced to service providers (property managers particularly). But this can’t remain the case. To deploy AI successfully, buildings must become digital platforms. In achieving that goal, these issues become critical; their potential impact on financial performance(and legal liability) dictate that they must fall under the purview of the owner.
As we’ve covered in the first two papers, there is little doubt that AI offers transformative potential for commercial real estate. However, organisations that approach AI solely as a technology issue will expose themselves to unnecessary risks. Future market leaders will be those that:
• Reimagine their workflows to enable AI to deliver efficiencies and productivity gains
• Sort out their underlying data and build strong data governance
• Prioritise cybersecurity
• Maintain operational oversight
• Establish ethical boundaries
• Train their workforce effectively
• Focus on interoperability and resilience
The smartest buildings will not simply be the most automated. They will be the most trusted, resilient, transparent, and well-governed.
As a final note, this paper should not be read as a negative take, but as an outline of the key issues, in which most CRE firms have little experience. Properly addressing these challenges clears the path for market leaders to win in an era increasingly defined by AI.
AI can create significant value, but only when the foundations are in place. Trustek helps owners and operators gain a clear picture of their current technology landscape and the steps needed to prepare for the future. So if you're ready to evaluate and optimise your assets, book a consultation with Trustek today.
Jonathan is a board-level advisor with a 35-year career in emerging digital technologies, and a serial entrepreneur, having founded a number of companies.
As a consultant, Jonathan has advised C-level executives in the finance, media, industrial and government sectors on adoption strategies around technologies including AI/ML, IoT, and quantum& high-performance computing.
His clients have included IBM, NASA, Barclays Bank, the BBC, Oracle, Microsoft, Cisco, Accenture, BT and many others. He has also consulted with the UK DTI, the European Union, and the World Economic Forum, and contributes due diligence for VC and PE investors.