← Back to InsightsAI Readiness

Before AI Touches Your Building Systems, Write the Operating Standard

AI tools are starting to connect to the systems that run your properties. Before anything reads or changes operating data at scale, owners need a repeatable standard for definitions, permissions, approval, logging, and recovery.

October 9, 2026 · By Drew Hall

Before AI Touches Your Building Systems, Write the Operating Standard

If you manage a portfolio, you will soon be asked to approve an AI tool that does more than summarize a report. It will want a connection into your property systems, and some of those connections will be able to change records, not just read them. The decision in front of you is less about which tool to buy and more about what rules your buildings will enforce when any tool shows up.

Let's demystify this. The real question for an asset manager is simple: when software starts acting on operating data, who decides what it may touch, who approves consequential actions, and how does anyone find and fix a mistake before it shows up in OpEx, tenant retention, or a diligence finding? If those answers live in a vendor's settings screen instead of your own documented standard, you have handed a piece of your operating control to someone else.

That is the case for a repeatable, owner-controlled operating standard, written before automation expands, and applied the same way at every property.

What changes when AI can act on the data

For the last several years, most building analytics were read-only. A platform pulled data, drew a chart, and a person decided what to do. The risk of a bad chart was a bad meeting.

The direction of travel is shifting. Brad Hargreaves framed it well with the title of a recent Thesis Driven letter, Buttons and Toggles No More: software interaction is moving away from people clicking through screens and toward conversational and agent-style tools. Industry coverage this season has also described AI connectors that can read from and write to business systems. In CRE, those systems include work order platforms, lease and accounting records, tenant communications, and over time, the operational technology that runs a building.

I want to be precise about what the current evidence supports. None of the material I reviewed for this piece establishes that autonomous AI is controlling HVAC or access control at scale today. What it shows is the plumbing being built: connectors, interfaces, and growing comfort with letting software take action. Owners have a window to set the rules while the stakes are still manageable.

The mechanism matters here. A read-only error produces a wrong answer that a person can catch. A write-capable error changes a record that other systems and people then trust. A wrong value in a work order closes a ticket that should be open. A wrong field in a lease abstract flows into a reconciliation. Each of those starts as a data problem, becomes an operating problem, and eventually lands on the P&L as OpEx variance, recovery leakage, or a tenant relationship that costs you at renewal.

Building context is the input most tools lack

An AI model can be very capable and still be wrong about your building, because capability and context are different things. The model does not know that your meter naming changed after a retrofit, that one tenant's space is submetered and the neighbor's is allocated, or that a particular air handler has been overridden for two years because of a known complaint.

Propmodo put a name on the right behavior with its piece on why the smartest building AI knows when it doesn't know. That is the property owners should require. A system that can recognize missing or unreliable context and stop, flag, or ask is safer than one that confidently fills the gap.

The practical requirement follows directly. If you want a system to know when it doesn't know, it needs a definition of what 'known' looks like. That means consistent data definitions across properties, documented lineage for where each value came from, and validation rules that mark data as trustworthy or not. Without those, every AI tool invents its own interpretation of your building, and you cannot compare its output from one property to the next.

Accuracy and privacy concerns sit on the same foundation. You cannot govern what a tool sees about tenants and occupants if you have not defined which data is sensitive, who may access it, and how long it is retained.

Where operating events fall between systems

Memoori's recent discussion of smart building ROI and the cost of not knowing makes a point every asset manager should sit with. The larger costs often come from things nobody tracks: faults that run for weeks before anyone notices, equipment that drifts out of its commissioned state, and compliance and security risk that builds quietly.

Those costs share a common cause. An event happens in one system, the response belongs to another, and nobody owns the handoff. A fault alarm lives in the building automation system, the work order lives in the maintenance platform, the cost lands in accounting, and the tenant impact shows up in a leasing conversation months later.

Adding AI to that picture without a standard does not close the gaps. It can widen them, because now there is another actor moving information between systems with its own assumptions.

The organizational version of this problem is just as real. Realcomm's framing for CoRE Tech 2026 notes that corporate real estate, facilities, and workplace teams rarely talk technology together even when they share business issues, and that AI is only as useful as the data behind it and the people deciding how it will be used. An operating standard gives those teams a shared document to agree on, so decisions about data and permissions are not made separately in each corner of the organization.

We see the cost of fragmentation in the physical layer too. In one PPP Review of a 400,000 SF office property, we found roughly $300K of redundant fiber, parallel backbones that nobody could explain, each under a different vendor's control. That happened without AI involved. It is what accumulates when every vendor builds to its own rules and the owner has no standard of record.

If you don't own your data & digital infrastructure, your vendors do.

The six parts of an owner operating standard

When I work through this with owners, the standard comes down to six components. Each one answers a specific operating question.

Data definitions. What does each point, field, and record mean, and is it named the same way at every property? This is what makes an AI output comparable across a portfolio and what lets a tool recognize when data is missing.

Permissions. Which systems may a given tool read, and which may it change? Read access to energy trends is a very different decision from write access to a tenant ledger. The owner should hold this list, not each vendor separately.

Validation. What checks must data pass before it is used for a decision or an action? Range checks, freshness checks, and cross-system reconciliation catch the drift Memoori describes before it compounds.

Approval. Which actions require a named person to approve before they execute? A useful rule is that anything affecting tenant billing, life safety, security, or contractual obligations needs human sign-off until the system has a documented track record.

Action logging. Every change made by software should be recorded with what changed, when, why, on whose authority, and from what data. That log is your evidence during diligence, an insurance claim, or a tenant dispute.

Recovery. How is an error detected, and how is the prior state restored? If no one can answer that before go-live, the tool is not ready to write to anything.

None of these components depends on which AI model you choose. That is the point. Model capability is converging and model selection is becoming a procurement decision. The standard is what you keep when you swap the tool.

Where the standard lives: two layers and the PPP 5C™ plan

An operating standard has to be enforced somewhere, and a policy document alone will not do it. At OpticWise, we place it across two layers.

Layer 1 is managed data & digital infrastructure, the foundation the owner controls. This is where connectivity is segmented and secured so a tool can reach only what it is permitted to reach, and where data is captured and normalized into a consistent model.

Layer 2 is the owner-controlled intelligence layer. Property Brain™ is a vendor- and LLM-agnostic data plane plus trust plane for each property. It is where definitions, permissions, approvals, lineage, and logging are governed. Standardize it once, and Property Brain™ becomes Portfolio Brain™, so the rules you wrote for one building apply to the next one without starting over.

The PPP 5C™ plan from Peak Property Performance® maps directly onto the six components:

  1. Clarify (PPP Review): define success metrics, map ownership, identify leakage, and document which data is trustworthy and portable. This produces your data definitions and your current permission map.
  2. Connect (managed data & digital infrastructure): establish secure, owner-controlled connectivity that repeats property to property, so permissions are enforced at the network, not just in an app.
  3. Collect (managed data & digital infrastructure): capture and normalize data into a consistent model you can reuse, with validation built in.
  4. Coordinate (Property Brain™ + Portfolio Brain™): govern identity, access, privacy, lineage, retention, and rules of use, including approval paths.
  5. Control (Property Brain™ + Portfolio Brain™): enable any decision engine, vendor platform, internal analytics, or LLM to act under owner permissions, with every action logged and recoverable.

What it's worth, and where to start

What's it really worth? The economic chain runs through operations. Faults caught earlier and errors reversed quickly hold down OpEx. Clean, logged records protect recoveries and reduce disputes. A documented data package shortens diligence and supports refinancing conversations. Each recovered dollar of NOI is capitalized at your cap rate, which is why expense control is a valuation lever and not just a budget line.

The practical move is to start with one property. Run a review, write the six components down for that asset, and connect one decision engine under those rules. Prove that you can swap the tool without rewiring the building. Then productize the standard and scale it across the portfolio.

The tools will keep changing. Your standard is the part that should not.

Own your data & digital infrastructure. Build for the long game.

Drew Hall

Drew Hall

Founder & Chief Architect, OpticWise • Co-Author, Peak Property Performance®

Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).

Your Next Step

Complimentary CRE Data & Digital Review Session

One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.