On Wednesday, Nexus Labs published an "Owner Signal" briefing that named something every building practitioner already deals with but never had a clean phrase for. The phrase is construction loophole, and the briefing is going to define the language of connected-buildings service contracts for the next 18 months.
The argument is simple. Every capital project either advances an owner's connected-buildings program or sets it back. The structural reason it usually sets it back is that the development team is disconnected from the operating departments who will inherit the asset. The operating departments — facilities, energy, OT, security, sustainability — show up after handover and discover that important capabilities were value-engineered out, the wrong tech got installed, or the right tech got installed but the handover was botched. None of that is caught at closeout. It is caught two months later, when the maintenance team is asked to swap 500 wireless sensor batteries that nobody planned for.
The Nexus Labs briefing is aimed at owners with thousands of OT devices and millions of square feet. Inova Health System is the worked example: five hospitals, 45,000 OT devices, 1.5 million square feet of active construction. Their answer is a construction governance program with a $10 million cyber-liability requirement in contractor agreements, a no-third-party-networks policy, and an IT team that vets every construction submittal.
This post is about the same loophole at three orders of magnitude smaller, where it actually hits harder, and what a $199-a-month monitoring contract should now promise to close it.
What the loophole looks like in a 30,000 square foot building
I deploy sensors into existing buildings. Every project starts with the same archaeological dig. The owner has paperwork from the original mechanical contractor, paperwork from the controls vendor, paperwork from a building-automation upgrade that happened in 2019, and three different submeter installations from three different electricians. Nothing is labeled. The sensor that the original BAS spec called for is not in the building. A sensor that the BAS spec did not call for is in the building. The submeter circuits are not documented anywhere except inside the head of an electrician who has since moved to Florida.
This is the construction loophole at small scale. The owner did not have a connected-buildings program. They had a series of disconnected capital decisions, each of which seemed reasonable at the time, none of which talked to the next.
The three failure modes Nexus Labs named for portfolio owners all show up unchanged in a single building:
- Important capabilities get value-engineered out. The mixed-air temperature sensor that would let you analyze air-handler performance was on the original spec, then got crossed off when the GC came in over budget. The owner does not know that happened. The energy team — when one finally exists, possibly years later — discovers the gap and cannot retroactively fix it without new ductwork access.
- The wrong tech gets installed. The wireless humidity sensors run on coin cells that need replacing every 18 months. Nobody told operations. The maintenance budget did not include 20 minutes of ladder time per sensor per year, multiplied by 60 sensors. Two years in, half of them have dead batteries and the data layer has silently gone dark.
- The right tech gets installed but the handover is botched. The submeters are reading kilowatt-hours correctly. The data is flowing into a dashboard. But nobody knows which submeter covers which panel, which panel covers which equipment, or which equipment is on which lease. The data is technically present and operationally useless.
Every one of these failures was decided at construction time. None of them shows up on the day the building opens. All of them show up later, as a structural cost on every operating decision the owner makes for the next decade.
Why the loophole is worse for small buildings, not better
Inova has $10 million cyber-liability requirements in contractor agreements. A small commercial building has none of that. The portfolio owner has an MSI (Master Systems Integrator) translating between IT, cyber, and facilities. The small-building owner has a property manager and a phone number for whoever installed the rooftop unit.
That is not a sympathy point. It is a practical one. The same structural problem — disconnected construction decisions accumulating into a non-operable asset — hits small buildings harder because there is no governance layer of any kind to absorb it. Every construction decision is an irreversible commitment, made by someone who is not the owner, against requirements that are mostly implicit, on a timeline that closes out the day the punch list is signed.
Eighteen months later, the owner notices that nothing in the building is talking to anything else. They call somebody like me.
The case-study version of what good handover looks like
The two case studies this site has already published — the agentic sump pump running 97 recovery cycles in a single rainy night, and the smart-building deployment that cut 42% off energy costs in six weeks — are both, in retrospect, exercises in retroactively closing a construction loophole.
The sump pump deployment did not close it at construction. It closed it 14 years later, when an edge-AI node was added to a basement that nobody had instrumented during the original build. The model running on that node now knows what "normal" sounds like for that specific pump, on that specific concrete, in that specific basement. None of that information existed in any record from the original construction. We had to generate it from scratch by running the building.
The community-center smart-building deployment was the same exercise at scale. The MQTT bridge that consolidated 35 separate sensor streams into one feature vector existed because the original building had no sensor-fusion architecture. The contractor who put in the original Z-Wave switches did not know what the contractor who put in the original utility submeters had labeled. We had to label it ourselves, sensor by sensor, the way a portfolio owner would have a commissioning agent do at handover.
Both deployments work. Both saved the customer real money. Both are, structurally, repair work for a construction process that left the building unreadable.
What a $199-a-month service contract should now promise
Here is the new framing for proposals starting this quarter. The connected-buildings industry just gave practitioners a phrase ("construction loophole") that owners are about to start hearing in their own ecosystem. The proposal that explicitly names the loophole and promises to close it reads as professional rather than artisanal.
Three concrete things a small-building monitoring service contract should now promise:
- The service is a construction memory. Every sensor we install gets labeled, every circuit gets traced, every cadence gets documented. If the customer ever does another capital project, the next contractor walks into a building that already has a record of what is in it. That record alone — independent of the monitoring data — is worth the contract. Inova built it for 45,000 OT devices with a $10M liability policy. We can build the small-building version with a notebook and a labelmaker. The framework is the same.
- The model is retrained on this building's data. Microsoft runs four parallel ML models — linear regression for occupancy timing, random forest for ramp times, plus two more — across roughly 50 buildings on its Redmond campus, retrained every day. The reason is that every building is its own non-stationary process. The same loop, on a longer interval, is correct for a 30,000 square foot commercial building. The proposal language is now: "we retrain the model on your building's data weekly." That is verifiable, defensible, and now backed by the largest sophisticated owner in the world.
- The alarm list is prioritized and standardized. QuadReal Property Group runs 60 properties on KODE OS with a centralized offsite tech team quarterbacking site staff through a prioritized alarm list standardized across the portfolio. The single-property version is a one-page document that names which conditions trigger a phone call, which trigger an email, and which sit in a queue for monthly review. Most small-building monitoring contracts ship without that document. Adding it is free, and it converts the deliverable from "anomaly detected, please investigate" into "you will hear from us about these specific things on these specific timelines."
The architectural shift that makes all three promises affordable
None of this would have been priceable two years ago. The reason it is priceable now is the supplier-side shift covered in yesterday's post on Ouster's native color lidar: sensors are now shipping as integrated modules with on-device inference, born-aligned data, and standard transport protocols. The integration that used to consume two months of engineering on a smart-building deployment now consumes two weeks.
That is what the connected-buildings industry has been waiting for. The supplier side made the modules deployable. The Nexus Labs Owner Signal briefing this week made the operator-side language explicit. Both halves of the playbook are now writable into a small-building proposal at a price the owner will sign.
What I'm watching
Three things to watch over the next two quarters as this language proliferates from portfolio owners to small-building practitioners:
- Whether NexusCon Detroit's Connected Construction track in October produces a published reference framework. The four moments named in the briefing — design, procurement, commissioning, handover — are the right scaffolding. If a written checklist comes out of the conference, every small-building practitioner can adopt the long form and cite the short form in proposals.
- Whether commercial real-estate insurance carriers start asking for evidence of a connected-buildings program at renewal. The Inova $10M cyber-liability policy is the leading edge. The trailing edge is small commercial property insurance starting to ask questions about OT cybersecurity at policy renewal. When that question gets asked, the answer becomes "yes, my monitoring service maintains an inventory and an alarm protocol" — which is, again, the same product, just with insurance underwriting as the forcing function.
- Whether the Microsoft daily-retrain loop becomes a published reference architecture. Right now it is a paragraph in a Nexus Labs briefing. If Microsoft publishes a longer-form description, every practitioner deploying ML for HVAC scheduling has a citable architecture. That collapses the proposal-defense work to a hyperlink.
The bottom line
The connected-buildings industry just named the structural problem that small-building practitioners have been quietly absorbing for years. The phrase is "construction loophole." It describes the gap between the building that gets built and the building that gets operated, and it accumulates compounding cost on every owner who has ever inherited a half-documented asset.
The fix at portfolio scale is a connected-buildings program with construction governance, MSI translation, and a $10M cyber-liability requirement. The fix at small-building scale is a $199-a-month monitoring service that promises construction memory, retrained models, and a prioritized alarm list — the same architecture, sized down to one building.
The proposal language for that service should change this quarter. The phrase to put on the cover page is "we close the construction loophole on your building." Owners are about to start hearing the phrase from their portfolio peers. Being the practitioner already publishing under it is the cheapest possible inbound-positioning move available right now.
We close the construction loophole on small commercial buildings.
Construction memory, retrained models, prioritized alarm lists. The same architecture portfolio owners are deploying, sized for one building, at a price you will sign. Local inference, local action, local logs. Under $500 to start a pilot.
See What We BuildRead the case studies and related posts: How edge AI prevented a basement flood | 42% off energy costs on a community center | What Ouster's native color lidar tells us about building sensors | Three things that stopped building monitoring just got fixed at Sensors Converge