← Back to InsightsOperational Control

Govern Your Building Systems Before AI Agents Connect to Them.

AI is lowering the cost and skill required to attack building systems. The owners who stay in control will be the ones who governed identity, access, and vendor permissions before autonomous tools ever touched operational technology.

September 4, 2026 · By Drew Hall

Govern Your Building Systems Before AI Agents Connect to Them.

A group of the largest AI labs and cloud providers just told the market it has months, not years, to prepare for AI-enabled cyberattacks. In late August, OpenAI, Anthropic, Microsoft, AWS and more than 100 other companies signed an open letter warning that hospitals, water treatment plants, and other critical operational systems will face a swarm of hacking threats as AI makes sophisticated attack capability cheaper and easier to acquire.

Commercial buildings belong on that list. Not the marketing version of a building, the actual one: the HVAC controllers, the access control system, the elevator management, the metering, the cameras, the building management system, and the dozen vendor connections that keep all of it running. That collection of systems is operational technology, or OT. It is the layer that makes a building physically work, and it was never designed to defend itself against a fast, cheap, tireless attacker.

For an asset manager, this is not an IT footnote. It is an operating-standard question with direct consequences for NOI, insurability, and valuation. Let's demystify what is actually changing, and what it takes to stay in control.

What AI actually changes about building risk

The threat to a building's operational systems has always existed. What is changing is the economics of the attacker.

Historically, compromising a building control system took time, specialized knowledge, and patience. An attacker had to understand obscure protocols, find the exposed device, and know what to do once inside. That skill requirement acted as a natural filter. Most buildings were safe not because they were well defended, but because they were not worth the effort.

AI collapses that filter. AI-assisted tooling reduces the skill and time required to find exposed systems, understand them, and act. What used to require a specialist can increasingly be done by a less sophisticated attacker using automated assistance. The volume goes up, the cost goes down, and the buildings that were previously ignored because they were too much trouble become reachable.

The insurance market is already repricing around this. Cyber insurers have spent years defining what counts as a covered event, and now carriers are adapting their policies as AI agents go rogue, rewriting terms because autonomous tools introduce failure modes their old language never anticipated. When the people who price risk for a living start rewriting the contract, that is a signal owners should read carefully. The insurability of your operational systems is becoming a function of how well you govern them.

Why buildings are structurally exposed

Operational technology in most commercial buildings grew up one vendor at a time. The access control vendor installed their system with their own network path and their own remote access. The HVAC vendor did the same. The metering provider, the camera integrator, the elevator company, each brought their own connectivity, their own credentials, and their own assumptions about who could reach what.

The result is a building with many doors and no single doorkeeper. Each vendor holds keys the owner rarely sees. Remote access sits open so the vendor can service the equipment. Default credentials linger because no one owns the job of rotating them. Network segments that should be isolated are flat, so a compromise in one system can move sideways into another.

This is the same fragmentation that shows up in our physical findings. In one PPP Review of a 400,000 square foot office property, we found roughly $300,000 of redundant fiber backbones running in parallel, each under a different vendor's control, none of it documented in a way the owner could explain. The physical duplication is the visible version of a deeper problem: no one at the ownership level had a complete map of what connected to what, or who could reach it.

When you cannot see the connections, you cannot govern them. And when an attacker's cost drops, ungoverned connections become the path of least resistance.

The real problem is governance, not gadgets

The instinct, when a threat like this appears, is to buy a security product. Install a monitoring tool. Add a firewall. Bolt on a detection service. Those tools have their place, but they treat the symptom.

The underlying problem is that most buildings have no governing layer over their operational systems. There is no single answer to basic questions: Who has access to the building management system, and how is that access granted and revoked? Which vendors can connect remotely, from where, and with what permissions? Is the network segmented so a breach in one system stays contained? Is there a log of what happened, so an incident can be reconstructed? Is there a defined response when something goes wrong?

These are not product questions. They are governance questions, and they are the same questions AI agents force to the surface. As autonomous tools begin to connect to operational systems, whether an attacker's agent or an owner's own automation, the building needs clear rules about identity, access, and permission before anything connects. When AI agents go beyond the guardrails, the damage is not caused by the agent being malicious. It is caused by the agent operating in an environment with no guardrails to begin with.

This is where a hard truth lives. If you don't own your data & digital infrastructure, your vendors do. Every vendor connection you cannot see or govern is a decision someone else made about your building's risk. You are accountable for the outcome, but a third party controls the exposure.

What owner-controlled governance looks like

Governing operational technology is not about becoming a cybersecurity company. It is about establishing an owner-controlled foundation so that connectivity, access, and rules of use belong to the owner rather than to whichever vendor showed up first.

That foundation has a specific shape. It starts with a single, secure, segmented network foundation rather than a tangle of vendor-installed paths. In our approach, this is BoT® (Building of Things®): consolidating and governing building connectivity so every device or system runs on one owner-controlled foundation instead of a dozen uncoordinated ones. Segmentation matters here because it is what keeps a compromise in one system, say a camera, from becoming a compromise of the whole building.

On top of that foundation sits governance: identity, access control, logging, and vendor permissions defined by the owner. When a vendor needs remote access, it is granted under owner rules, scoped to what they actually need, logged, and revocable. When an incident happens, there is a record to reconstruct it. When a new tool wants to connect, autonomous or not, it connects under permissions the owner set, not under whatever access a hurried installation left open.

This is not theoretical hardening. The industry is converging on the same conclusion from the data side too. A recent Realcomm session on building a trusted foundation for CRE technology framed data quality and governance as the defining factor in how CRE organizations manage risk. Whether the entry point is a compromised control system or an untrustworthy data feed, the requirement is the same: a governed foundation the owner controls.

Mapping this to a plan the owner controls

Governance sounds abstract until it becomes a sequence of concrete steps. Our PPP 5C™ plan turns it into one.

Clarify starts with a PPP Review that maps what actually connects to your operational systems, which vendors hold access, where the segmentation gaps are, and what remote paths are open. You cannot govern what you have not mapped, and most owners have never had a complete map made for them.

Connect establishes secure, owner-controlled connectivity, replacing the tangle of vendor-installed paths with a single segmented foundation. This is where flat networks become segmented ones and where vendor access becomes a permission the owner grants rather than an assumption the vendor made.

Collect normalizes the operating data and the logs into a consistent, owner-held record. This is what makes incident reconstruction possible and what makes anomalies detectable in the first place.

Coordinate governs identity, access, privacy, lineage, retention, and rules of use through Property Brain™. This is the layer that answers the governance questions directly: who can reach what, under what permission, with what record.

Control enables decision engines and automation, including AI tools, to act only under owner permissions. When an autonomous agent connects to your building, it operates inside guardrails you defined, not in an open field.

Standardize this across a portfolio and Property Brain™ becomes Portfolio Brain™, so a security standard set once applies everywhere instead of being reinvented building by building. That is how a governance posture stops being a per-property fire drill and becomes a portfolio-level operating standard.

Why this reaches valuation

An asset manager can reasonably ask why an OT governance question deserves capital attention. The answer runs through the same math every other operating decision does.

Ungoverned operational systems create three quiet liabilities. The first is insurability: as carriers reprice cyber exposure, buildings that cannot demonstrate governance face higher premiums or narrower coverage, and premium increases hit NOI directly. The second is operational continuity: a compromised building system is not a data breach in a spreadsheet, it is elevators, access, or climate control failing in a physical asset full of tenants, with retention and reputation consequences that follow. The third is diligence: at refinancing or sale, ungoverned vendor access and undocumented systems are findings, and findings move price.

Each of those consequences reaches NOI, and every dollar of NOI capitalizes at your cap rate into asset value. Governance is not a cost center. It is the difference between an operating story you can defend under diligence and one that surprises you at the worst possible moment.

The warning from the AI labs was aimed at critical operators. Commercial real estate is one of them, whether the industry has framed it that way or not. The owners who treat OT governance as an operating standard now, before autonomous tools connect to their systems at scale, will be the ones still in control when everyone else is reacting.

Start with a PPP Review of one property. Map what connects, who holds access, and where the gaps are. Prove you can govern one building's operational systems under owner permissions, then make that the standard across the portfolio.

Own your data & digital infrastructure. Build for the long game.

Drew Hall

Drew Hall

Founder & Chief Architect, OpticWise • Co-Author, Peak Property Performance®

Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).

Your Next Step

Complimentary CRE Data & Digital Review Session

One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.