City Digital Twins

The Smart City Needs a Manual Override

Photo by martin fenton (@mhfphotographygb) on Unsplash

Cities have spent years connecting physical infrastructure to software. Traffic lights respond to congestion. Water networks detect leaks remotely. Streetlights adjust themselves. Parking systems process payments automatically. Public buildings optimise energy consumption while sensors monitor everything from air quality to pedestrian flows.

Each connection can make a city more efficient. It can also create another system that has to keep working when something goes wrong. That second problem deserves considerably more attention as smart-city technology moves from pilot projects into ordinary municipal infrastructure.

Bousta has already examined the hidden maintenance costs behind smart-city sensors and the growing role of digital infrastructure across urban systems. The next stage of the discussion concerns resilience: what happens when the intelligent layer stops being intelligent?

Cities cannot treat software failure like an app outage

A retailer can tolerate an analytics dashboard going offline for an hour. A traffic junction has different requirements.

Once software controls physical infrastructure, digital reliability becomes operational reliability. A communications failure can affect transport. A faulty sensor can trigger the wrong response. A cyberattack can move beyond stolen information and interfere with real equipment.

The smart city therefore inherits a problem that industrial operators have understood for decades: automation works best when the system also knows how to fail safely.

That means cities need to design infrastructure around degraded operation rather than assuming permanent connectivity.

Traffic signals should have fallback behaviour. Buildings should remain operable when cloud services disappear. Local controllers should continue performing essential functions when central platforms cannot communicate with them.

And human operators need a way to take control.

Automation quietly removes institutional knowledge

There is another problem.

When an automated system performs the same task successfully for several years, organisations gradually stop practising the manual version.

The system becomes normal.

Employees who once knew how to operate infrastructure manually retire or move elsewhere. Procedures disappear into old documents. Suppliers gain expertise that municipalities no longer possess internally.

Efficiency improves until the automation fails.

At that point, the organisation discovers that redundancy existed technically but not operationally.

A manual override is useless when nobody knows how to use it.

This is why resilience cannot consist entirely of backup servers and duplicated communications networks. Cities also need people, procedures and exercises that test whether critical services can operate with less technology than usual.

Smart-city procurement has to include failure

Municipal tenders usually describe what a technology should accomplish.

They should increasingly ask what happens when it cannot.

How does a connected lighting system behave when communications fail? How long can a transport platform function without its primary data feed? Can another supplier operate the equipment if the original vendor disappears? Who holds the credentials required to administer the system? Can the city extract its operational data in a usable format?

These questions are less attractive than discussing artificial intelligence or digital twins.

They may determine whether the investment still works ten years later.

Smart-city infrastructure often outlives the technology companies that supply individual components. A bridge can remain in service for a century. Software vendors merge, restructure products and discontinue platforms within years.

The city has to plan for both timescales simultaneously.

Resilience can require less intelligence

Cities also need to distinguish between functions that benefit from central optimisation and functions that require local autonomy.

An AI platform may calculate the most efficient traffic pattern across an entire metropolitan area. The individual intersection should still know what to do if it loses contact with that platform.

The principle resembles modern power-grid design. Sophisticated central coordination can improve overall performance while local systems protect essential operations when communication disappears.

Smart infrastructure becomes stronger when intelligence is distributed rather than concentrated in one control centre.

That architecture may look less elegant on a presentation slide. It is considerably more useful during an outage.

The smartest city may be the one that can become temporarily stupid

Urban technology tends to be sold through maximum capability. More sensors. More automation. More predictive analytics. More integration. Cities should also evaluate minimum capability.

What is the smallest amount of technology the water network needs to keep supplying water? What must traffic infrastructure preserve to prevent dangerous junctions? Which building systems can operate locally? How much of the transport network continues functioning if a major data platform disappears?

These questions change the definition of a smart city. A genuinely intelligent urban system does not depend on everything working perfectly at once.

It expects individual components to fail. It isolates problems. It preserves essential services. It gives people enough information and authority to intervene.

The city of the future may contain more automation than any city before it. Its resilience will depend partly on whether it still knows what to do without it.