AI can forecast tomorrow's heat demand, identify an air-handling unit that is fighting the heating system or suggest that an empty floor does not need full lighting. It cannot prove a saving from a dashboard, decide that cold staff should tolerate discomfort or safely write arbitrary commands into a building-management network.
The useful objective is narrower: reduce avoidable consumption while an accountable facilities team retains the safety envelope, occupants can report problems and every control change can be reversed. This guide is current to 31 July 2026 and focuses on non-domestic offices and mixed commercial sites. Energy, building, landlord and workplace duties differ across England, Scotland, Wales and Northern Ireland. Minimum Energy Efficiency Standards and certificate rules cited below have specific territorial scope, so confirm the property, tenancy and responsible party.
Define the controlled outcome before selecting AI
Start with a written control objective for each building. “Save energy” is not testable. “Reduce weather-normalised gas consumption outside occupied hours without increasing comfort complaints or ventilation exceptions” is.
| Decision | Suitable machine support | Control that stays with people |
|---|---|---|
| Plant start time | forecast warm-up from weather and recent response | engineer approves operating limits |
| Zone set-point | recommend within an agreed temperature band | facilities owner sets the band and exceptions |
| Ventilation | flag mismatches among schedule, CO2 and fan state | competent person protects air quality |
| Fault detection | rank simultaneous heating and cooling or sensor drift | engineer diagnoses and authorises repair |
| Occupancy schedule | estimate demand at zone level | manager handles events, access needs and local override |
| Maintenance | prioritise inspection from condition signals | competent maintainer isolates and repairs equipment |
Do not let an optimiser directly control life-safety systems, smoke control, fire alarms, lifts, critical laboratories or clinical areas merely because they share a network. Treat each interface as a separate safety case.
Build a baseline that survives operational reality
Collect at least one complete seasonal cycle where practical. At minimum, retain half-hourly electricity and gas, local weather, operating hours, floor area, occupancy schedule, plant state, material faults and tariff periods. Mark shutdowns, refurbishments and tenant changes rather than asking a model to explain them away.
The government's non-domestic smart-metering collection explains the data offer for smaller non-domestic customers and the role of accessible consumption data. A meter total is still not an equipment diagnosis. Reconcile the main meter to sub-meters, check time zones and daylight-saving changes, and document estimated or missing reads.
Choose a baseline method before the pilot. Compare like-for-like periods using degree days, operating hours and material occupancy changes. Keep an untouched holdout period. Report absolute kilowatt-hours, cost and carbon separately; a tariff change can cut cost without cutting energy, while an emissions-factor change can alter carbon without changing the building.
Fit optimisation into current UK energy obligations
Large qualifying organisations should map the project to the current Energy Savings Opportunity Scheme guidance. ESOS Phase 3 introduced action plans and annual progress updates, with the second Phase 3 progress deadline on 5 December 2026. An AI dashboard is not an ESOS assessment and does not replace a lead assessor where one is required.
For rented non-domestic property in England and Wales, check the updated Minimum Energy Efficiency Standard landlord guidance. Since April 2023, covered properties generally need EPC E or a valid registered exemption. Do not claim that live optimisation changes the EPC rating; operational control and asset-rating methodology answer different questions.
Public authorities with qualifying buildings should distinguish design performance from actual operation. The official Display Energy Certificate guidance bases the operational rating on recorded energy consumption. Private operators can still use the same discipline: preserve meter evidence, boundary definitions and the reasons for material changes.
Put comfort, ventilation and equipment protection first
An energy model should operate inside engineering constraints, not discover them by experimentation. Define minimum and maximum temperatures, humidity or air-quality limits, frost protection, minimum ventilation, warm-up and cool-down rules, equipment cycling limits, and zones that cannot be curtailed.
The HSE's thermal-comfort guidance stresses that air temperature alone is not an adequate measure; humidity, air movement, radiant temperature, clothing and work rate also matter. Its workplace ventilation guidance warns that fans do not replace fresh air and that mechanical airflow may need adjustment to avoid uncomfortable draughts.
Use occupant feedback as a safety signal, not a popularity contest. Offer an accessible route to report cold, heat, noise or poor air, connect complaints to zones and times, and investigate clusters. Do not infer an individual's health or productivity from a temperature preference. The government's Energy Technology List criteria for HVAC building controls provide a useful reference for zoned modes, weather compensation, temporary override and anti-tampering features.
Commission sensors, constraints and handover
Optimisation cannot repair an uncommissioned building. Before training or control, walk the plant with the people who operate it. Verify sensor location, units, range, calibration date and relationship to the controlled zone. A wall sensor beside a kettle, server rack or sunny window can be internally consistent and operationally misleading.
Create plausibility rules: supply temperature should relate to valve and plant state; a fan command should agree with run feedback; zone occupancy should not remain permanently high after a sensor loses connectivity. Route disagreements to engineering rather than letting the model select whichever signal supports a saving.
Commission one change at a time where feasible. Record pre-condition, command, observed response and recovery. This identifies stuck dampers, inverted valves and undocumented local controllers that historic data may hide. Keep a change freeze during comparison periods unless safety or service requires intervention, and mark every exception.
Require a usable handover pack from installer and analytics supplier:
- current schematics, point names and units;
- control narrative and approved ranges;
- alarm and override ownership;
- model features, update schedule and known limitations;
- local fallback and restoration procedure;
- administrator, support and end-of-contract access.
Recommission after plant replacement, tenancy change or a sustained shift in sensor relationships. Model drift may be a building change, not an abstract statistics problem. Retain calibration certificates and link every adjustment to its maintenance work order.
Protect occupancy data and the building-control network
Badge events, Wi-Fi associations, desk sensors and room bookings may identify workers or reveal patterns about attendance. Use aggregated zone demand when it is sufficient. Before introducing individual-level monitoring, define a lawful basis, purpose, retention period and access policy, consult staff where appropriate, and assess whether a less intrusive signal works.
The ICO's guidance on monitoring workers says availability does not make a monitoring method necessary or proportionate. Do not quietly reuse occupancy data for performance scoring, attendance discipline or individual profiling.
Treat the building-management system as operational technology. The NCSC's secure-connectivity principles for OT recommend standard secure protocols and brokered exchange rather than direct IT access to control networks. A practical architecture is:
- read-only replication of selected telemetry into a protected integration layer;
- separate service identities for analytics and control;
- allow-listed commands with rate, range and time limits;
- multi-factor authentication and restricted administrative devices;
- signed configuration changes and an immutable event log;
- tested local fallback schedules if cloud or network access fails.
Never place model credentials in a controller script or give a vendor unrestricted remote access. Record firmware, gateways, integrations and ownership in an OT asset inventory.
Measure savings without rewarding unsafe behaviour
Define one energy metric and several guardrails. Suitable headline measures include weather-normalised kWh per occupied square metre, out-of-hours base load and peak demand. Guardrails should include:
- comfort and air-quality complaints per 100 occupied days;
- hours outside agreed environmental bands;
- manual overrides and the time taken to resolve them;
- plant short-cycling, alarm volume and safety trips;
- missing telemetry and sensor disagreement;
- model recommendations rejected by engineers;
- avoided and created maintenance call-outs.
Use a comparison zone, matched building or staged switchback where operations allow. Have finance verify tariff and invoice effects and facilities verify physical performance. Publish the baseline, exclusions and uncertainty. A claimed 15% reduction is not credible if half the floor was empty during the comparison.
Related archive guidance covers AI in smart buildings and property operations and energy AI across grids and renewables. Building optimisation should consume those wider signals without pretending it controls them.
Run a bounded 90-day deployment
Days 1–30: observe.
- choose one building and two non-safety-critical plant decisions;
- assign facilities, energy, IT/OT security, data-protection and finance owners;
- validate meters, sensors, schedules, alarms and network diagrams;
- freeze the baseline method and comfort guardrails;
- run the model read-only and compare suggestions with engineer judgement.
Days 31–60: advise.
- expose source readings and reasons with every recommendation;
- require named approval and capture rejection reasons;
- test missing sensors, stale weather, clock errors and unusual events;
- rehearse loss of cloud service, compromised credentials and manual fallback;
- review worker notices and complaint handling.
Days 61–90: control a narrow envelope.
- allow only pre-approved commands in selected zones and hours;
- start with conservative limits and automatic expiry;
- review energy and guardrails weekly;
- independently reconcile the reported saving;
- expand only after stable performance through representative conditions.
Pause and rollback gates
Return to the last known safe schedule if any critical life-safety interface is affected, a command exceeds its approved envelope, sensor provenance is unclear, remote access is unexplained, or the local fallback does not operate. Pause optimisation when comfort or ventilation exceptions rise materially, equipment cycles exceed engineering limits, savings disappear after normalisation, or staff cannot explain and reverse a change.
For a pilot, pre-agree quantitative gates: no unresolved critical cyber finding; no severe safety event attributable to control; zero unauthorised commands; telemetry completeness above 98%; and measured energy improvement above the uncertainty band without a statistically or operationally material deterioration in guardrails. The precise thresholds belong to the building owner and competent advisers, not the vendor.
The operating verdict
Building AI earns trust by making small, reversible decisions from well-understood telemetry. The durable asset is not a clever forecast but a governed control loop: verified meters, explicit environmental limits, separated OT access, human override and measurement that survives scrutiny. Scale only when the site uses less energy and remains demonstrably safe, comfortable and operable.



