Charlotte Clayson, Kathryn Noble and Matt Whelan from Trowers & Hamlins explore the growing role of AI and connected technologies at airports, and the importance of building cyber resilience and security alongside them.
Airports are among the most complex, data-intensive environments in the modern economy with thousands of passengers passing through their terminals, connecting to free Wi-Fi, booking car parking, accessing airport lounges and fast-tracking through security on a daily basis.
Each of those interactions generates data; and that data has value, not only to the airports that collect it, but to the criminal hackers who seek to exploit it.
The fast pace of developing AI technology means that these processes are becoming more efficient. However, the integration of AI comes with its own, developing risks, including cyber security.
Separately, the importance of broader cyber resilience within the sector has most recently been emphasised by the attack on Manchester Airports Group, which operates Manchester (MAN), East Midlands (EMA) and London Stansted (STN) in the UK.
As airports increasingly deploy artificial intelligence, technology and connected digital systems to improve the passenger experience and operational efficiency, cyber resilience must sit at the very heart of that technological transformation.
In this article we examine the ethical considerations of AI in the aviation industry and its impact on cyber security.
AI IN THE AIRPORT ENVIRONMENT: OPPORTUNITY AND RESPONSIBILITY
The airport sector is undergoing a fundamental technological shift. Where passenger processing was once defined by shared terminal equipment and standardised check-in infrastructure, airports are now deploying AI-enabled systems across virtually every stage of the passenger journey.
Biometric identification at eGates, AI-driven security screening, predictive maintenance of critical infrastructure, automated baggage handling, and intelligent self-service kiosks are no longer aspirational; they are operational realities in airports across the United Kingdom and globally.
The industry is moving from simply processing passengers to understanding them: AI-enabled touchpoints can now interpret passenger context, anticipate needs and deliver personalised services in real time.
This transformation, however, generates vast quantities of sensitive data. Every AI-enabled touchpoint collects, processes and transmits personal and operational data across interconnected networks.
The more intelligent and connected these systems become, the greater the volume of data flowing through airport infrastructure, and the larger the potential attack surface for malicious actors.

The commercial value of this data is significant: for many airports, non-aeronautical revenues (driven in part by data-enabled services) account for a substantial proportion of total income.
The same data that enables personalisation and operational efficiency is precisely the data that threat actors seek to exploit.
The deployment of AI in airports does not operate in a regulatory vacuum. Although the United Kingdom, for example, has not yet enacted dedicated AI legislation, AI systems are already subject to a substantial body of existing law.
The UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025 impose strict requirements on automated decision-making, particularly where decisions produce legal or similarly significant effects on individuals.
The Equality Act 2010 constrains the use of algorithmic systems that may perpetuate or amplify discrimination across protected characteristics (a risk that is particularly acute where AI is deployed in passenger screening, security profiling or service eligibility decisions).
Beyond these statutory obligations, the UK government’s principles-based regulatory framework (emphasising safety, transparency, fairness, accountability and contestability) places the onus on deploying organisations to demonstrate that their AI systems operate responsibly and in accordance with fundamental rights.
A further dimension of risk arises from the airport AI supply chain.
The majority of AI systems deployed in airports are not developed in-house but procured from third-party technology vendors.
This creates what has been described as the problem of “moral outsourcing”, if airports delegate operationally and ethically sensitive functions (such as passenger identification, security screening and data analytics) to systems over which they may have limited visibility or control.
Critically, legal responsibility cannot be delegated down the supply chain. An airport deploying a third-party AI system that produces discriminatory, unlawful or unsafe outcomes will bear liability regardless of the system’s origin.
Robust contractual safeguards (including transparency obligations, audit rights, liability and indemnity provisions, and change control mechanisms) are essential to managing this risk.
Equally important is rigorous pre-procurement due diligence, encompassing supplier audits of training data, validation processes, bias testing and regulatory alignment.
Perhaps most fundamentally, the current landscape demands a shift in how airports approach the design and construction of their increasingly digital and physical infrastructure.
Cyber security and AI governance should be embedded at the design stage rather than retrofitted after deployment, ensuring that consultant and contractor procurement factors in these requirements, including intellectual property liabilities and ownership considerations.
This principle, often described as “ethics by design” or “security by design”, requires organisations to conduct structured risk assessments, data protection impact assessments and algorithmic impact assessments during the design phase, before systems go live.
Successful implementation and security of AI-enabled and complex digital solutions relies not only on this being a key consideration at concept and construction phases, but also in the training of engineers and analysts who will maintain and interpret data generated by these systems throughout operations.
This is particularly important where design and construction is being undertaken to upgrade and enhance existing facilities and buildings.
Integration of existing and new technological models and products will impact on the efficiency, future-proofing, ROI, and security of the airport’s AI network.
For airports undertaking new construction or terminal redevelopment, this means careful consideration is required to ensure effective and co-ordinated integration of cyber-resilient architecture into the physical fabric of the building and the airport’s complex building management systems: network segmentation, computer services, secure data centres reliable power sources, resilient communications infrastructure and access controls should be designed alongside passenger flow, retail space, mechanical and electrical systems, and operational facilities.
The convergence of digital and physical security is a prerequisite for any airport seeking to deploy AI responsibly and to future-proof its operations against an evolving threat landscape.
The recent cyber attack on MAG illustrates precisely the risks that arise when the volume of data generated by connected, passenger-facing systems is compromised.
Whilst the MAG attack did not itself involve AI, it demonstrates the broader cyber security challenges facing airports as they adopt increasingly data-intensive technologies.
THE IMPACT IN REALITY
For MAG, approximately 8.7 million customers had their data accessed and published by hackers, who subsequently demanded a ransom for the return of that data. The majority of the data related to customer email addresses was gathered through airport Wi-Fi sign-ups.
However, more detailed personal information (including vehicle registrations and postcodes) was also accessed, obtained through passengers who had booked car-parking spaces, lounge access or fast-track services.
The incident has been referred to the Information Commissioner’s Office (ICO), which has confirmed it has launched an investigation. MAG has moved quickly to put protective measures in place for those impacted and has been clear that passenger and aviation safety have not been compromised.
For those passengers whose data has been compromised, this is a particularly sensitive issue, where personal information has been provided to improve their experience in transit, but has led to them becoming victims of an attack.
This does not mean the sector should avoid digital transformation. AI-enabled systems offer transformative benefits for both passengers and operators alike.
However, the more interconnected and data-dependent an organisation becomes, the larger its attack surface. Every new system that processes passenger data, and every third-party vendor that integrates with airport infrastructure, represents a potential vulnerability.
Without robust AI governance, ethical safeguards and supply chain oversight operating alongside protective cyber security measures, the very technologies deployed to enhance the passenger experience risk becoming the vectors through which that experience is compromised.
Recent incidents do not exist in isolation. They form part of a broader pattern of escalating cyber attacks against critical infrastructure and large data-holding organisations across the United Kingdom.
The UK is now the most targeted country in Europe for cyber attacks, with the estimated annual cost of significant cyber attacks on the UK economy reaching a staggering £14.7 billion according to research by KPMG.
Recent high-profile incidents affecting major UK institutions such as the NHS and the Ministry of Defence, and businesses such as Marks & Spencer and Jaguar Land Rover, have demonstrated the devastating operational and financial impact of cyber attacks, with incidents ranging from sophisticated social engineering to ransomware deployment.

LESSONS FOR AIRPORTS: WHAT CYBER RESILIENCE LOOKS LIKE
The MAG attack demonstrates the risks to passenger data and the evolving threat landscape. However, there are actionable steps that airports and other large data-holding organisations operating in a complex or AI-augmented environment, can take to protect themselves and the data they hold:
– Incident Response Plans must be well prepared. MAG responded to this incident very quickly, notified relevant individuals and authorities, and worked with specialists to mitigate the risks.
Ensuring that incident response plans are in place and stress tested on a regular basis can have a significant and positive effect on the potential impact of a cyber attack.
– Security monitoring must be comprehensive. Monitoring only a fraction of an IT environment leaves significant blind spots. Organisations should ensure security monitoring platforms are fully integrated across their networks.
This is especially acute for airports, whose IT environments span terminal operations, retail, transport and aviation systems.
– Keep software current. Running end-of-life operating systems exposes organisations to known vulnerabilities which are an easy target for threat actors to exploit.
– Conduct regular vulnerability scanning. Routine scanning (both internal and external) should be a standard part of any cyber security programme; otherwise critical weaknesses may go unidentified and unpatched.
– Plan for supply chain risk. The majority of AI systems deployed in airports are procured from third-party vendors, and an exploited vulnerability in one supplier can have knock-on effects across the entire airport ecosystem.
Airports must conduct rigorous due diligence on every supplier that handles passenger data or provides AI-enabled services, encompassing not only cyber security standards but also ethical safeguards, bias testing and regulatory alignment.
Legal responsibility for the outcomes of third-party AI systems cannot be delegated down the supply chain.
– Embed security into design and construction. Whether building new terminal infrastructure or integrating AI-enabled systems into existing operations, cyber security and data protection should be incorporated at the design stage and maintained and tested appropriately throughout operations to optimise efficiency and coordination with the live building management systems.
Network architecture, data storage, access controls and AI governance frameworks should be specified alongside physical infrastructure requirements.
Retrofitting security measures after deployment is invariably more costly, less effective and leaves systems exposed during the interim period.
THE ROAD AHEAD
Whilst the MAG breach did not compromise passenger safety or aviation security, and did not have an impact on operations, it will, in all likelihood, continue to attract scrutiny given the sheer number of individuals involved.
More broadly, the incident underscores that as the sector enhances its service offering through interconnected and customer-facing systems, cyber resilience is essential.
For organisations that also deploy AI, ethical AI governance is an interdependent discipline that must be pursued alongside robust cyber security.
Any organisation that deploys AI without adequate ethical safeguards, supply chain oversight and security-by-design principles exposes itself to significant cascading risk, and any organisation that handles large volumes of personal data without robust cyber security measures is similarly vulnerable.
The intersection of AI, aviation and cyber security is a present one. As airports deploy increasingly sophisticated AI systems across their operations, they must invest with equal sophistication in the cyber resilience frameworks that protect them, whether technical, operational, or people led.
That investment must begin at the earliest stages of design and construction: airports that embed cyber security, data protection and AI governance into their infrastructure from the outset will be far better positioned to withstand the threats of tomorrow than those that seek to retrofit protections onto legacy systems.
The goal is not to resist digital transformation, but to ensure that it is pursued securely, ethically and with the resilience that critical national infrastructure demands.
About the authors
All work at Trowers & Hamlins in the UK. Charlotte Clayson is a partner for dispute resolution and litigation; Kathryn Noble, partner, projects and construction; and Matt Whelan, senior associate, corporate and commercial.



