Digital globe showing outlines of continents with grid lines and glowing borders.
News
»
Artificial Intelligence

AI in Commercial Real Estate: Cybersecurity, resilience, and the future of AI-powered buildings

The fourth and final part in our 'AI in CRE' series, which explores why cybersecurity, resilience, and trust will be the defining foundations of tomorrow's AI-powered buildings, not just baseline intelligence capacity.

23 June 2026

Part Four: Cybersecurity, resilience, and the future of AI-powered buildings

 

As we’ve covered in previous papers, the commercial real estate (CRE) industry is undergoing a profound digital transformation, evolving into intelligent environments powered by artificial intelligence (AI), the Internet of Things (IoT), cloud computing, and advanced automation systems. These smart buildings promise greater operational efficiency, sustainability, tenant satisfaction, and financial performance. But as commercial buildings become increasingly interconnected and data-driven, they also become more vulnerable to cyber threats and operational disruptions.

 

Cybersecurity and resilience have therefore emerged as critical priorities for property owners, developers, facility managers, and technology providers. The future of AI-powered commercial real estate depends not only on innovation but also on the ability to protect digital infrastructure, ensure business continuity, and maintain trust among tenants and stakeholders. The integration of robust cybersecurity measures and resilient operational frameworks will be a key determinant of success in digitised commercial real estate.

 

That’s particularly true as AI makes inroads into the sector, because AI brings with it a set of additional security challenges, not least as the attack surface is considerably greater. And the attack surface is no longer just the model itself; particularly in agentic implementations, it includes every server, tool, and API that an agent can reach, drastically increasing potential entry points.

 

So let’s look at some key elements of this expanding and demanding challenge space:

1.    General cybersecurity challenges

2.    Regulatory and compliance considerations

3.    AI-related challenges

4.    The importance of cyber resilience

5.    Building a secure Smart Building ecosystem

6.    The future of resilient AI-powered buildings

 

 

1. General cybersecurity challenges

 

As commercial buildings become increasingly connected, cybersecurity risks grow in both complexity and severity. Modern smart buildings rely on numerous interconnected devices and systems that communicate through networks and cloud platforms. Each connected device represents a potential entry point for attackers.

 

One major challenge involves the convergence of operational technology (OT) and information technology (IT). Historically, building systems such as HVAC, lighting, elevators, and access control operated independently. Today, these systems are often integrated into centralised platforms accessible through corporate networks and cloud services. While integration improves efficiency, it also creates pathways through which cyber threats can spread.

 

Cybercriminals may target commercial buildings for a variety of reasons, including financial gain, espionage, sabotage, or disruption. Potential threats include:

•  Unauthorised access to building management systems

•  Ransomware attacks that disable critical operations

•  Theft of tenant or employee data

•  Manipulation of environmental controls

•  Disruption of physical security systems

•  Compromise of surveillance and monitoring networks

 

A successful attack on a commercial property could result in financial losses, operational downtime, reputational damage, regulatory penalties, and even physical safety risks for occupants. Most specifically, the impact on occupiers can be considerable, and the resulting lack of trust could result in tenants not renewing leases or, in some cases, trigger break clauses. The financial risk for landlords should not be underestimated.

 

2. Regulatory and Compliance Considerations

 

As smart buildings become more sophisticated, governments and regulatory bodies are introducing stricter cybersecurity requirements, comprising a complex landscape of regulations related to data privacy, cybersecurity, and critical infrastructure protection. Compliance considerations may include:

•  Data protection regulations governing tenant information

•  Cybersecurity standards for critical infrastructure

•  Industry-specific security frameworks

•  Building safety and operational requirements

•  Third-party vendor security obligations

 

Failure to comply with regulatory requirements can result in significant penalties, so cybersecurity governance must become an integral component of commercial real estate management. Organisations should establish clear cybersecurity policies, assign accountability, conduct regular audits, and ensure that security requirements are incorporated into procurement and vendor management processes.

 

Trustek audits many commercial buildings however, and has found that fewer than 15% of those audited to date had any effective cybersecurity policy in place.

 

3. AI-related security challenges

 

While AI can deliver substantial operational benefits to commercial real estate, as outlined in the previous papers, it also introduces a new category of cybersecurity risks that extend beyond traditional IT and operational technology (OT) threats. Unlike conventional building automation systems, AI-powered platforms depend heavily on data, machine learning models, cloud connectivity, and autonomous decision-making. As a result, attackers can target not only the underlying infrastructure but also the AI systems themselves.

 

Sections 1 & 2 below refer to adversarial attacks. An adversarial AI attack is a malicious technique that manipulates machine learning models by deliberately feeding them deceptive data to cause incorrect or unintended behaviour. These attacks exploit vulnerabilities in the model's logic, often through subtle changes designed to trick the system that are imperceptible to humans.

 

1. Training phase attacks (data poisoning)

Most AI systems (including LLMs like ChatGPT, Claude, Gemini, etc.) use models trained on very large quantities of data. In the training phase, attackers can interfere with the data used for training. Threat actors inject manipulated or false information into the training dataset. This causes the model to learn incorrect patterns, resulting in built-in biases, poor accuracy, or intentional backdoors that the attacker can exploit later. Even small quantities of poisoned data can impact a model’s output.

 

In commercial buildings, as well as using models trained on external data, internal training and/or prompt data may originate from occupancy sensors, smart meters, HVAC equipment, access control systems, surveillance cameras, and tenant applications.

 

Attackers may intentionally manipulate such data to influence AI behaviour. If occupancy data is altered for example, an AI-driven energy management system may incorrectly estimate building usage patterns, resulting in inefficient heating, cooling, or lighting decisions.

 

In commercial properties where AI models continuously retrain themselves using operational data, the effects of data poisoning may remain undetected for extended periods, degrading system performance, increasing energy costs, and reducing tenant comfort.

 

2. Inference phase attacks (model exploitation)

These attacks occur after the AI is trained and deployed in the real world, instead targeting how the model makes decisions on new data. Vulnerabilities include:

•  Evasion attacks: Attackers make subtle, intentional alterations to the input data. For example, they might add invisible digital noise to an image or alter pixels, causing a facial recognition system to misidentify an object or person.

•   Adversarial perturbations: Modifying input data (like audio, text, or images) in highly specific ways designed to break the model's confidence or force a targeted misclassification. An attacker could exploit weaknesses in image-recognition algorithms by altering visual patterns, badges, or QR codes to bypass security controls. For instance, a facial recognition system may incorrectly identify an unauthorised individual as an approved tenant or employee. Similarly, AI-powered surveillance systems could fail to detect suspicious behaviour if adversarial techniques manipulate how video analytics algorithms interpret visual information.

•  Prompt injection / adversarial images: Malicious instructions or prompts are cleverly hidden within an image or piece of text. When the AI processes or compresses the data, the hidden command emerges, tricking the system into executing malicious instructions.

•  Indirect prompt injection I - AI memory poisoning (context corruption): Many AI agents and assistants use "long-term memory" to personalise future interactions. Through an indirect prompt injection (e.g., hiding a malicious command in a web page, an email, or a document the AI reviews), an attacker can instruct the AI to store corrupted "facts" or malicious rules in its long-term memory. Once this flawed data is registered as a trusted user preference or instruction, it poisons the AI's future behaviour across subsequent tasks.

•  Indirect prompt injection II - poisoning RAG knowledge bases: An attacker hides adversarial instructions in external data that the AI system later retrieves (such as a webpage, email, or document), which introduces corruptions into the model.

 

3. Other challenges

•  Model theft and Intellectual Property risks: Developing sophisticated AI models requires significant investment in data collection, training, and optimisation. Consequently, trained models themselves become valuable assets. Cybercriminals may attempt to steal proprietary AI algorithms used for predictive maintenance, energy optimisation, or occupancy forecasting. By extracting or replicating these models, competitors or malicious actors can gain access to intellectual property worth millions of pounds. In some cases, stolen models may reveal sensitive information about building operations, occupancy patterns, or tenant behaviour.

•   AI supply chain vulnerabilities: Modern AI systems rarely operate in isolation. Most rely on third-party software libraries, cloud platforms, pre-trained models, APIs, and external data sources. This interconnected ecosystem creates supply chain risks. If a third-party AI component is compromised, attackers may gain indirect access to building systems. For example, a vulnerability in an AI-powered video analytics platform could provide a pathway into broader building management networks. The increasing adoption of generative AI services and external machine learning platforms further expands the attack surface. Property owners may unknowingly inherit vulnerabilities from vendors whose security practices they cannot directly control.

•  AI-driven social engineering: AI is significantly enhancing the effectiveness of social engineering attacks. Cybercriminals can now use generative AI to create highly convincing phishing emails, synthetic voices, fake video messages, and personalised scams. Facility managers, building operators, and security personnel may become targets of AI-generated communications that appear to come from trusted executives, vendors, or tenants. Deepfake audio could be used to impersonate a senior property manager and request urgent changes to access permissions or payment instructions. Because commercial real estate operations often involve numerous stakeholders, contractors, and service providers, distinguishing legitimate communications from AI-generated deception is becoming increasingly challenging.

•   Autonomous decision-making risks: Many next-generation smart buildings are moving toward autonomous operations, where AI systems make decisions with minimal human intervention. While autonomy improves efficiency, it also creates new risks. If attackers compromise an AI system, they may influence decisions affecting critical building operations. An AI-controlled HVAC system could be manipulated to create unsafe indoor conditions, while compromised predictive maintenance algorithms might overlook critical equipment failures. The greater the level of automation, the more significant the consequences of AI compromise become.

•   AI model drift and security blind spots: Machine learning models are not static. Their performance can deteriorate over time due to changes in occupancy patterns, tenant behaviour, equipment usage, or environmental conditions. This phenomenon, known as model drift, can create security vulnerabilities. For example, an AI-based anomaly detection system trained on historical building data may fail to recognise new attack techniques or evolving operational patterns. As accuracy declines, security teams may experience increased false positives or missed threats. Continuous monitoring, validation, and retraining of AI models are therefore essential components of cyber resilience in intelligent buildings.

•  AI-powered cyberattacks: Cybercriminals are increasingly leveraging AI to automate reconnaissance, identify vulnerabilities, generate malware, and launch attacks at scale. AI-powered attack tools can rapidly analyse building networks, discover exposed devices, and adapt attack strategies in real time. In commercial real estate environments containing thousands of interconnected sensors and IoT devices, such capabilities can significantly accelerate the speed and sophistication of cyber intrusions.

 

Point 1 in section 2 illustrates an enduring challenge with AI security that goes far beyond the traditional “shield”-style cybersecurity protections. As the data with which a model has been trained determines the behaviour and output of the model, interference during this phase means that AI using such a system is compromised by definition. And there’s no telling who has had access to the training data, or(in most cases) from where it was sourced. So anyone using AI with trained models (such as LLMs) must assume the system is insecure from minute one.

 

4. The importance of cyber resilience

 

While cybersecurity focuses on preventing attacks, resilience emphasises the ability to withstand, respond to, and recover from disruptions. In the context of AI-powered commercial real estate, resilience extends beyond traditional cybersecurity measures.

Cyber resilience involves developing systems and processes that continue operating even when attacks occur. Since no security framework can guarantee complete protection, organisations must assume that breaches are possible and prepare accordingly.

Key elements of cyber resilience include:

 

Risk assessment

Organisations must identify critical assets, vulnerabilities, and potential threat scenarios. Comprehensive risk assessments help prioritise security investments and establish appropriate controls. This is particularly important with respect to AI in which threat modelling is the only way to set out safeguards.

Business continuity planning

Building operators should develop continuity plans that outline procedures for maintaining essential services during cyber incidents. Critical systems such as security controls, fire safety mechanisms, and emergency communications must remain operational under adverse conditions of course, but connectivity and important occupier services should also be considered, if client confidence is to be retained.

Incident response

Effective incident response frameworks enable organisations to detect, contain, and mitigate cyber threats quickly. Well-trained response teams can significantly reduce the impact of attacks.

 

Recovery and restoration

Rapid recovery capabilities are essential for minimising operational disruption. Backup systems, redundant infrastructure, and disaster recovery plans help restore services efficiently after an incident.

 

Continuous improvement

Cyber resilience requires ongoingevaluation and adaptation. Organisations must regularly test defences, updatepolicies, and learn from emerging threats and incidents. Again, this is vitalin AI-enabled environments, ensuring that threat modelling and assessment iscontinually updated.

 

5. Building a secure Smart Building ecosystem

 

Cybersecurity in AI-powered buildings cannot be achieved through technology alone however. A holistic approach involving people, processes, and technology is required.

 

Secure-by-design principles

Security should be incorporated during the design and construction phases rather than added after deployment. Developers should evaluate cybersecurity risks when selecting building technologies and infrastructure.

 

Network segmentation

Separating critical operational systems from corporate IT networks can limit the spread of cyber threats and reduce attack exposure.

 

Strong authentication

Multi-factor authentication and robust identity management controls help prevent unauthorised access to building systems.

 

Regular updates and patch management

Many cyber incidents exploit known vulnerabilities. Timely software updates and security patches are essential for maintaining system security.

 

Employee awareness

Human error remains a major cybersecurity risk. Regular training helps employees recognise phishing attempts, social engineering tactics, and other common threats. As noted above, this is particularly challenging in the AI era, given the potential impact of voice and video deepfakes.

 

Vendor collaboration

Smart buildings often rely on multiple technology providers. Effective cybersecurity requires collaboration among property owners, facility managers, software vendors, and service providers. Collaboration between multiple stakeholders in CRE can sometimes be challenging, but from a security standpoint, is imperative.

 

6. The future of resilient AI-powered buildings

 

Commercial real estate is increasingly being defined by intelligent, autonomous, interconnected, and AI-enabled buildings. Technologies such as digital twins, edge computing, 5G connectivity, and advanced robotics will further expand building capabilities.

 

Digital twins—virtual replicas of physical buildings—will allow operators to simulate scenarios, optimise performance, and evaluate cybersecurity risks before implementing changes. Edge computing will improve resilience by enabling local data processing, reducing dependence on centralised cloud infrastructure. Advanced AI systems will deliver more accurate predictions and automated decision-making capabilities.

 

At the same time, cyber threats will continue evolving. Attackers will likely employ AI to develop more sophisticated intrusion techniques, automate attacks, and exploit vulnerabilities at unprecedented speed. As a result, cybersecurity strategies must evolve continuously. Future resilient buildings will likely incorporate:

•  Self-healing network architectures

•  AI-driven autonomous security operations

•  Real-time cyber risk monitoring

•  Advanced encryption technologies

•  Zero-trust security frameworks

•  Integrated physical and cyber security systems

 

These approaches will help organisations balance technological advancement with security and operational resilience.

 

Conclusion

 

The future success of smart commercial buildings depends on integrating cybersecurity and resilience into every stage of the building lifecycle. Organisations must move beyond traditional security approaches and adopt comprehensive resilience strategies that enable them to anticipate, withstand, and recover from cyber threats. AI itself will play a crucial role in strengthening defences through advanced threat detection, predictive analytics, and automated response capabilities.

 

As commercial real estate continues its digital evolution, cybersecurity and resilience will become fundamental pillars of building value and operational excellence. Those organisations that successfully combine innovation with robust security practices will be best positioned to thrive.

 

The future winners in CRE will not simply be the smartest buildings — they will be the most trusted and resilient.

Author Info

Jonathan Steel

Non-executive Director
LinkedIn logo

Jonathan is a board-level advisor with a 35-year career in emerging digital technologies, and a serial entrepreneur, having founded a number of companies.

As a consultant, Jonathan has advised C-level executives in the finance, media, industrial and government sectors on adoption strategies around technologies including AI/ML, IoT, and quantum& high-performance computing. 

His clients have included IBM, NASA, Barclays Bank, the BBC, Oracle, Microsoft, Cisco, Accenture, BT and many others. He has also consulted with the UK DTI, the European Union, and the World Economic Forum, and contributes due diligence for VC and PE investors.