CAD/BIM Tips & Tricks
The Big Tech Trend: Predictive Design Over Generative Design
18 August 2026
Generative design may have had its moment. That’s a bold statement, I know, but consider this:
For years, we’ve seen extraordinary projects that look grown rather than designed. Some are ingenious. Others became far less appealing when someone had to price, fabricate and build them.
Architects are fascinated by generative design’s creative possibilities, structural engineers appreciate the math and contractors are left to figure out how to build the thing.
The value isn’t in producing more design options. It’s in seeing trouble sooner.
But currently, attention is shifting toward something less dramatic but potentially more practical: predictive design.
Predictive design is gaining ground across heavy industry, engineering and commercial design. As AI, machine learning and cloud computing become more capable, companies are relying less on expensive trial-and-error prototyping and more on data from previous projects.
The goal is straightforward: Anticipate how a design is likely to perform, identify weaknesses earlier and reduce the time spent discovering problems after development is already underway.
Unlike generative design, the value isn’t in producing more design options. It’s in seeing trouble sooner.
That shift carries an important consequence. Predictive design depends on data. As project models, operational records and digital twins move into cloud-hosted environments, the information behind a building can become almost as valuable as the building itself.
But it can also become vulnerable.
The Digital Twin Vulnerability
A modern digital twin is more than a detailed 3D model. It’s a living digital counterpart of a physical facility, updated through sensors, building management systems and records of how occupants use the space.
Owners and facility teams can track energy use, monitor equipment and respond before failure occurs. Yet that connectivity can expose a dangerous amount of information.
A cloud-hosted digital twin may contain structural layouts, equipment locations, maintenance histories, operational settings, HVAC systems, access controls and structural monitoring data.
Anyone who gains unauthorized access could see far more than just drawings. They could gain a detailed overview of how the building is designed and how it functions.
That changes the role of cybersecurity in BIM. Data protection is no longer solely the domain of IT. Decisions about who can see a model, which systems connect to it and how long access remains active are now also project management decisions. Somehow, security has become part of engineering and design.
The Cost of Compromise
If cybersecurity in BIM sounds a little far-fetched, I assure you that the dangers aren’t merely theoretical.
If cybersecurity in BIM sounds a little far-fetched, I assure you that the dangers aren’t merely theoretical.
During construction of the Australian Security Intelligence Organization’s headquarters, attackers breached a contractor’s network and obtained sensitive building information. Reports indicated that the stolen material included floor plans, communications infrastructure and the locations of secure server rooms.
In a building designed for national security work, those were not ordinary project files. They were a map of spaces and systems never intended to be visible outside the project team.
The apparent motive was intelligence gathering. Construction was reportedly delayed while parts of the interior were redesigned so the stolen information would no longer be useful. A data breach literally forced physical changes to the building.
Commercial contractors face a different version of the same threat.
In December 2019, Canada’s Bird Construction was attacked by the MAZE ransomware group. The attackers entered the company’s network, encrypted files and removed approximately 60 GB of data. The stolen material reportedly included corporate documents and engineering information connected with federal projects, including work for Canada’s Department of National Defense.
The attackers demanded CAD $9 million. Bird Construction isolated affected systems, began its incident response process and continued key operations using backups. When the company didn’t pay, the attackers published the stolen records on the dark web.
Construction and engineering firms are attractive targets because their systems may hold information belonging to clients, consultants, employees and government partners. A breach can spread well beyond the contractor’s network.
ISO 19650-5 and Security-Minded BIM
ISO 19650-5 was developed to help organizations manage sensitive information within BIM and the wider built environment. It asks teams what information they hold, who genuinely needs it and what could happen if it were exposed, altered or made unavailable.
A structural model might reveal how a secure facility is arranged. A utilities model could show where critical services enter a site. Even a commercial project can contain access records, contracts and sensitive designs.
The belief that engineering files are too specialized to interest an attacker is dangerous. Ransomware groups don’t need to understand a structural model. They only need to understand what happens if they lock up the data so that a project team can no longer access it — or its potential value on the dark web.
On an active project, a locked Common Data Environment can stop approvals, delay trades and leave teams working from outdated information. Every lost day increases the pressure to pay.
ISO 19650-5 encourages organizations to identify sensitive assets early. That means deciding which information can be shared widely, which requires tighter control and which should be separated from the main project environment.
Those decisions belong in the BIM execution plan. Making them after a breach is like closing the stable door after the horse has bolted.
The Common Data Environment Problem
The Common Data Environment is designed to give project teams one trusted place to store and exchange information. That centralization is one of its greatest strengths and one of its greatest risks.
Architectural models, structural files, MEP information, schedules, approvals and revisions may all pass through the same environment. If access controls are weak, one compromised account can expose far more information than its owner should be able to reach.
Most firms assign permissions when someone joins a project. Fewer remove them as diligently when that person leaves. Subcontractors may retain active accounts, consultants may have access to irrelevant folders and shared credentials may outlive their creators.
These forgotten accounts simply sit there until someone finds a use for them.
Good data hygiene reduces both the information an attacker can reach and the volume a project team must protect.
Files also accumulate. Old model versions, duplicate exports, temporary folders and abandoned coordination files remain because deleting anything feels risky. Over time, the CDE becomes a digital warehouse where nobody’s entirely sure what should still be there.
Good data hygiene reduces both the information an attacker can reach and the volume a project team must protect.
Protecting the Information That Matters Most
Cloud-hosted models can be protected without turning every file-opening into an obstacle course.
Use Zero Trust access controls. Every connection to the CDE should be verified through authentication, device checks and continuing authorization.
Separate sensitive project information. Public design materials should not sit beside critical infrastructure models under identical permissions. Segmentation limits how far an intruder can move.
Review permissions throughout the project. Access should change when responsibilities change and contractor accounts should be disabled when a phase ends.
Encrypt stored and transmitted data. Project information should be protected while it sits in the cloud and while it moves between users, applications and systems.
Train people using project-specific examples. A believable message about a revised model, overdue invoice or shared drawing package is harder to spot than a generic phishing email. Teams need to understand how attackers use familiar project language.
Built into the project from the beginning, these controls become part of how the work gets done rather than an added interference.
The Human Element
Security tools rarely fail because someone objects to protecting information. They fail because people are simply trying to finish their work.
Architects, engineers and contractors live under schedule pressure. When security adds repeated logins, approvals or delays, someone will eventually find a faster route.
A model gets uploaded to a personal file-sharing account. A password is shared with a colleague. A drawing is sent through a messaging app because the approved system is not cooperating and the site team needs an answer now.
The workaround may solve the immediate problem but remove the file from every control meant to protect it. That’s why usable security matters.
Single Sign-On can reduce password fatigue. Automated permission changes can close accounts without relying on memory. Checks built into project software are less likely to be bypassed than a separate process nobody remembers until an audit.
The best control is often the one the project team barely notices.
Predictive Design Changes What Must Be Protected
The move toward predictive design reflects a broader industry change.
The cleverest engineering system may no longer be the one that creates the most unusual shape. It may be the one that warns a team that a component is likely to fail, a delivery is likely to arrive late or a design decision is likely to create problems after handover.
Those predictions depend on reliable information.
A digital twin cannot guide operations if its data has been compromised. A predictive model cannot support a decision if the team does not trust the records behind it. A cloud-based CDE cannot serve as the source of truth if “forgotten” accounts still have access.
The industry is learning how much value sits inside its models and operational data. It must become equally serious about protecting them.
ISO 19650-5 provides a useful framework, but standards alone won’t secure a project. The real work happens in ordinary decisions: who receives access, what information they can see, when that access ends and how easily they can work without reaching for an unsafe shortcut.
Predictive design promises to give project teams a clearer view of the future, but that insight is only valuable if they can trust the data behind it.
Axiom's President
Oscar Albornoz
Feel free to share this article on your social media:
