The DHS SAFETY Act in AI Security: Designation, Certification, and What It Actually Means
Home / Intelligence / The DHS SAFETY Act in AI...
Market Analysis

The DHS SAFETY Act in AI Security: Designation, Certification, and What It Actually Means

A market analysis of DHS SAFETY Act designations across AI-powered physical security vendors, including the QATT-vs-Designated-vs-Certified distinction buyers most often miss.

Published April 2026
Read Time 14 min read
Stream Market Analysis
3 of 11
AI weapons-detection vendors with full SAFETY Act Designation as of Q2 2026 (DHS Approved Technologies database)
5 yrs
Standard term of a full SAFETY Act Designation; Developmental Testing & Evaluation status caps at 36 months (6 CFR Part 25)
2002
Year Congress enacted the SAFETY Act inside the Homeland Security Act, Public Law 107-296 (DHS S&T)

The DHS SAFETY Act is the single most cited credential in AI physical security procurement, and the one most often misunderstood at the buying table. Vendors say "SAFETY Act Designated" the way software vendors say "SOC 2 Type II"; security directors and risk managers nod, sign, and assume parity. There is no parity. The SAFETY Act has three statutory tiers, two of them confer materially different liability protection, and the gap between a Developmental Testing & Evaluation Designation and a full Designation is wider than most procurement teams realize.

This market analysis decodes the SAFETY Act for security buyers evaluating AI-powered detection platforms. It explains the QATT, Designated, and Certified distinction in the language Congress wrote it; maps which vendors hold which tier as of Q2 2026; and surfaces the contractual and insurance questions a buyer should ask before signing a master service agreement. The objective is not vendor advocacy. It is to give risk-rated decision-makers a defensible reference for the SAFETY Act question that increasingly determines whether AI security technology gets through legal review.

Real IntelliSee active-shooter and weapons detection output with bounding box and confidence score on monitored camera feed
LIVE CAM-12 · INTERIOR CORRIDOR
Actual IntelliSee detection output. A drawn firearm identified on a monitored corridor feed with a visible bounding box and confidence score. The detection runs on existing cameras through an on-premises appliance with no facial recognition, no stored video, and no PHI. The same architectural constraints DHS evaluates during a SAFETY Act review apply to every alert routed to security dispatch in under 30 seconds.

What the SAFETY Act actually is, in the language Congress wrote it

The Support Anti-Terrorism by Fostering Effective Technologies Act of 2002, the SAFETY Act, was enacted as Subtitle G of Title VIII of the Homeland Security Act of 2002, Public Law 107-296. The statute is implemented through the Code of Federal Regulations at 6 CFR Part 25 and administered by the DHS Science & Technology Directorate's Office of SAFETY Act Implementation (OSAI). Its core purpose, written into the text of the statute, is to ensure that the threat of post-event tort liability does not deter manufacturers and sellers of effective anti-terrorism technologies from developing and commercializing them.

The mechanism is liability management, not technical certification. Anti-terrorism technologies that pass DHS review become Qualified Anti-Terrorism Technologies, or QATTs. A QATT designation triggers a defined set of statutory benefits that limit the seller's exposure if the technology is in use during a declared act of terrorism. Those benefits compound through three tiers, and the difference between the tiers is the difference between a discount on liability and an effective immunity.

The SAFETY Act is therefore a procurement document as much as a security one. A general counsel reviewing an AI security MSA wants to know what statutory floor the vendor sits on. A risk manager pricing terror exposure into the property and casualty book wants to know whether the technology shifts the loss-cost calculation. A federal contractor preparing a bid wants to know whether the platform deployed under the contract will trigger the Government Contractor Defense for the Department's own contracting officers. The SAFETY Act answers all three questions, but only at the right tier.

The three SAFETY Act tiers, decoded

OSAI grants three distinct levels of SAFETY Act protection. Each provides a different statutory benefit, requires a different level of operational evidence, and runs on a different term clock. Treating them as interchangeable on a procurement scorecard is the single most common buyer error.

SAFETY Act Tier Reference

Three statutory tiers, three different liability outcomes

From provisional testing protection to full Government Contractor Defense immunity.

Tier 3

Certified Anti-Terrorism Technology

Technology Certified by DHS as a QATT. Provides Designation benefits plus the rebuttable presumption of the Government Contractor Defense for claims arising from declared acts of terrorism.

5 to 8 yrsRenewable
  • Government Contractor Defense presumption
  • Liability cap to insurance amount
  • Federal exclusive jurisdiction
Tier 2

Designated Technology (QATT)

Full Designation. Liability capped at the insurance amount set by OSAI; no joint and several liability for non-economic damages; no punitive damages or prejudgment interest; recovery reduced by collateral sources; federal exclusive jurisdiction.

5 yrsRenewable
  • Liability cap to insurance amount
  • No punitive damages
  • Federal exclusive jurisdiction
Tier 1

Developmental Testing & Evaluation Designation

Provisional protection during further trial deployment. Same Designation benefits but limited to acts during the DT&E period and capped at a presumptive 36 months. Terminable at-will by the Department on safety concerns.

≤36 mosLimited
  • Time-limited protection
  • Terminable at-will by DHS
  • Use restrictions in DT&E order

The shape of the protection looks the same on a marketing slide. It is not the same in a deposition. A Designated Technology compresses the liability tail materially. A Certified Technology effectively closes it through the Government Contractor Defense presumption, which under SAFETY Act jurisprudence can only be overcome by evidence of "knowing and deliberate intent to deceive the government" during the application process. A DT&E Designation provides real but provisional cover, scoped to the trial deployment and bounded by a clock the seller cannot control. Treating these as a single credential is a procurement failure mode.

The Common Misread

"SAFETY Act Designated" is not "SAFETY Act Approved"

OSAI does not issue an "Approved" status. The phrase appears on vendor marketing pages but does not exist in the statute or 6 CFR Part 25. The accurate reading is whether the technology is listed on the public DHS Approved Technologies database at safetyact.gov, and at which tier. A buyer should verify two things: that the vendor's company name appears in the database, and that the listing shows the tier the vendor claims. A DT&E entry is genuine SAFETY Act recognition; it is also not equivalent to a full Designation. The tier the listing actually shows is what controls the liability outcome.

Why the SAFETY Act tier matters more in 2026 than it did in 2022

The SAFETY Act has been on the books since 2002, but its weight in security procurement has grown sharply over the past three years for three converging reasons. Each reason puts more pressure on the procurement question, and each rewards buyers who know how to read the tiers.

First: state legislation is naming SAFETY Act status as evaluation criteria. A growing number of state-level school security and hospital security mandates either explicitly reference SAFETY Act Designation or use language that effectively requires it. Tennessee's school weapons-detection grant programs, several state hospital workplace violence statutes, and federal grant programs administered through CISA and FEMA all reference SAFETY Act status as a procurement screen. A live tracker of these mandates is maintained in the Q2 2026 state AI security legislation tracker and the broader grant funding resource.

Second: insurance carriers are using SAFETY Act status as a risk-rating input. Property and casualty underwriters and active-assailant policy writers increasingly factor whether a deployed security platform is SAFETY Act protected into the risk-rating model. A buyer running a Designated platform sits in a different risk pool than a buyer running an unprotected platform. The premium impact is small per individual policy but compounds across portfolios.

Third: tort exposure for security failures has expanded. Plaintiff-bar cases following high-profile attacks have established that security technology vendors and their customers can both be named in negligent-deployment, failure-to-warn, and failure-to-detect claims. The SAFETY Act's Designation tier exists precisely to compress this exposure. Where it applies, the limitations on damages, joint and several liability, and forum selection materially change the litigation calculus. The dynamic is most visible in environments where the underlying threat model includes mass-attack scenarios, which is the same reason buyers in K-12 education, healthcare, and houses of worship are now framing the SAFETY Act question early in evaluation. The 2026 Houses of Worship Security Sector Playbook provides a practical deployment and NSGP grant strategy framework for faith communities evaluating SAFETY Act-designated platforms.

This is upstream of the technology question. A buyer evaluating AI threat detection for a school district, a hospital system, or a critical-infrastructure facility is now asking the SAFETY Act question before the false-positive-rate question. That order of operations is a 2025 to 2026 development, not a 2002 one.

The SAFETY Act vendor landscape in AI physical security as of Q2 2026

The DHS Approved Technologies database is the authoritative source for vendor SAFETY Act status. The database is publicly searchable at safetyact.gov/at/, and the entries are the controlling record. A buyer should always confirm the listing rather than rely on a vendor's marketing claim.

As of Q2 2026, the AI-powered weapons and threat detection segment shows a small number of vendors at full Designation, a handful at DT&E status, and a long tail of platforms with no SAFETY Act presence. The table below summarizes the structural picture, anchored to the safetyact.gov database. Vendors are listed alphabetically; the absence of a vendor name indicates no SAFETY Act listing as of the verification date.

AI Physical Security Vendors and SAFETY Act Status, Q2 2026

VendorTechnologySAFETY Act TierSource / Notes
Evolv TechnologyEvolv Express, Evolv Edge weapons screeningDesignated (QATT)Designated for Evolv Express on March 31, 2022; Evolv Edge designated subsequently. Public press release on file.
IntelliSeeAI computer-vision platform on existing cameras (gun, fall, perimeter, loitering, crowd)Designated (QATT)Designation effective November 24, 2025; expiration January 31, 2031. Verifiable on the DHS database.
OmnilertOmnilert Gun Detect AI gun-detection softwareDesignated (QATT)Full Designation announced; previously held DT&E status before promotion to full Designation.
ZeroEyesAI-based gun detection and intelligent situational awarenessDesignated (QATT)First AI-based gun detection technology to receive SAFETY Act Designation; promoted from earlier DT&E status.
ActuateAI gun-detection video analyticsNone on fileNo SAFETY Act listing on safetyact.gov as of verification date.
Ambient.aiAI behavior intelligence platformNone on fileNo SAFETY Act listing on safetyact.gov as of verification date.

Several characteristics of the database matter when reading this picture:

The database is granular at the product level, not the company level. A vendor with multiple products may have one Designated product and others without protection. Buyers should verify the specific platform configuration they intend to deploy, not the company name.

DT&E status precedes full Designation in most cases. ZeroEyes and Omnilert both moved through DT&E before earning full Designation. The Designation step is a meaningful upgrade in liability protection and an indication that the technology has accumulated enough operational data for OSAI to grant the longer term.

Certification, Tier 3, is rare in the AI physical security segment. No widely deployed AI weapons detection platform held Certification status as of Q2 2026 verification. Certification requires a higher evidentiary bar and typically follows a multi-year Designation track record. Buyers asking "are you Certified?" are in most cases asking for a tier no AI security vendor has yet reached, and the more useful question is which Designated tier the platform sits at and when the term expires.

The contractual questions a SAFETY Act-aware buyer should ask

If a deployed security platform might be in service during a declared act of terrorism, the SAFETY Act controls a large portion of the resulting liability allocation. A procurement team that understands the structure can pull material concessions from a vendor and reduce the buyer's own exposure in three contracting dimensions.

Tier verification and evidence of currency

Ask the vendor to provide the specific OSAI letter granting Designation or Certification, including the tier, the covered technology description, the effective date, and the expiration date. Confirm the company name and product name on safetyact.gov match the contracting party. A vendor whose Designation expires during the contract term should be required to commit to renewal in the master agreement.

Insurance amount and coverage scope

The SAFETY Act caps liability at the insurance amount specified by OSAI for the Designation. Ask the vendor to confirm the insurance amount on file with DHS and to provide a current certificate of insurance demonstrating the coverage is in force. Confirm the policy is occurrence-based and that the named insured includes the contracting entity.

Pass-through liability protection

Designation benefits flow to the seller; the buyer benefits derivatively because suits arising from a covered act are channeled into the SAFETY Act's federal cause of action. Confirm the contract does not require the buyer to indemnify the vendor in a way that would defeat the SAFETY Act's design. Have legal review confirm that the buyer's existing insurance does not contractually subrogate against the vendor in a way the SAFETY Act preempts.

Configuration and deployment fidelity

SAFETY Act protection is tied to deployment of the technology as approved. Material modifications to the deployment scope, configuration, or use case can put protection out of reach. Ask the vendor to provide written deployment guidance consistent with the Designation, and require change control on any deviation from approved configurations during the term.

These are not exotic clauses. They are the SAFETY Act-aware version of insurance and configuration management language that already exists in well-drafted security technology contracts. The legal value is the difference between a contract that preserves the statutory protection through deployment and one that inadvertently narrows it.

Three false equivalences buyers should reject

The SAFETY Act question often gets compressed in procurement scoring in ways that flatten material differences. Three false equivalences come up most often, and each is worth pushing back on in evaluation.

"DT&E and Designated are basically the same." They are not. DT&E is provisional, capped at 36 months, and terminable at-will by the Department. The protection scope is also limited to acts during the DT&E period itself. A buyer signing a five-year contract with a vendor at DT&E status assumes substantial renewal risk that a Designated vendor's contract does not carry.

"Designated and Certified are basically the same." They are not. Certification adds the rebuttable presumption of the Government Contractor Defense, which is a categorically different liability outcome. The presumption can be overcome only by evidence of "knowing and deliberate intent to deceive the government" during application. In a post-event suit, that evidentiary bar is extraordinarily high. Designation does not include the presumption.

"SAFETY Act protection covers any incident." It does not. The SAFETY Act's liability framework activates upon a Secretary of Homeland Security declaration that an event was an act of terrorism under section 865 of the Homeland Security Act. Many security incidents, including workplace violence, suicide, accidental discharge, and fall events, will not trigger that declaration. SAFETY Act protection is most consequential for the specific class of mass-attack scenarios the statute was written to address. It is not a general litigation shield.

A clear-eyed reading is that the SAFETY Act is a powerful but bounded protection, scoped to a specific event class, layered through three tiers with material differences, and useful as a procurement screen primarily where the deployment context puts terrorism-class events on the realistic threat surface.

How SAFETY Act status fits into a defensible AI security buying decision

SAFETY Act status is a meaningful screen, but it is one input in a broader buying calculus. A platform with full Designation that does not meet the operational threshold for the buyer's environment is still a poor purchase. A platform without a SAFETY Act listing that delivers the right detection accuracy in the right deployment may still be the right answer for a buyer whose threat surface does not credibly include declared acts of terrorism.

The question is therefore how SAFETY Act status fits into the larger framework rather than whether it is the decisive criterion in isolation. Three principles operationalize the screen well:

Use SAFETY Act status as a tier-discriminator at the long-list stage. If the buyer's threat surface includes mass-attack scenarios, which is the case for most schools, hospitals, houses of worship, large public-facing commercial buildings, and critical infrastructure, vendors at Designated or higher status sit in a different risk pool than vendors without. Use the tier to narrow the long list before deeper technical evaluation.

Use technical performance as the decisive screen at the short-list stage. Once the SAFETY Act floor is established, the decision moves to detection accuracy, false-positive behavior, integration depth, alert routing, and the operational realities covered in the 2026 definitive guide to proactive computer vision and the failure-mode analysis in the perimeter intrusion 90-second window report. SAFETY Act status does not certify performance; it certifies eligibility for liability protection. How the platform works and what the detection modalities actually catch is the operational evaluation.

Use contracting language to preserve the protection through the term. The SAFETY Act benefits flow only when the technology is deployed in the configuration covered by the Designation. Procurement language that locks the configuration scope, requires renewal commitment from the vendor, and pulls the OSAI letter into the contract is the difference between a SAFETY Act platform on paper and one that actually performs in a litigation event.

A Note on Competitor Framing

Designated peers are peers

This analysis names Evolv, Omnilert, and ZeroEyes alongside IntelliSee at the Designated tier because that is what the safetyact.gov database shows. Each vendor reaches the tier through a different application path, evidentiary base, and product scope, and each has architectural and operational characteristics that distinguish it from the others. The point of the SAFETY Act analysis is not to rank Designated peers against one another; it is to draw the line between vendors at the Designated tier and vendors without SAFETY Act protection, which is where the procurement calculus changes most.

Frequently asked questions about the SAFETY Act in AI security procurement

Is SAFETY Act Designation the same as a federal certification of accuracy or effectiveness?

No. SAFETY Act Designation is a liability-management determination by DHS, not a technical accuracy certification. OSAI evaluates whether the technology has demonstrated effectiveness during operational testing or prior use sufficient to qualify for liability protection. It does not publish accuracy benchmarks, false-positive rates, or comparative performance data. Buyers evaluating detection accuracy should rely on operational pilots, customer references, and independent technical evaluation in addition to the SAFETY Act tier.

Does SAFETY Act protection apply to workplace violence incidents that are not declared acts of terrorism?

The SAFETY Act's liability protections activate upon a Secretary of Homeland Security declaration under section 865 of the Homeland Security Act that an event was an act of terrorism. Many workplace violence incidents do not meet that statutory threshold and therefore would not trigger the SAFETY Act framework. The protection is most consequential for the specific class of mass-attack scenarios. For workplace violence prevention specifically, see the healthcare workplace violence AI playbook.

How does the Government Contractor Defense work under Certification?

Under Tier 3 Certification, the seller of a Certified Anti-Terrorism Technology is entitled to a rebuttable presumption that the Government Contractor Defense applies. In the SAFETY Act framework, the presumption can only be overcome by evidence of a knowing and deliberate intent to deceive the government during the application process. In litigation, that evidentiary standard is extremely high. The result is that Certification approaches a practical immunity from third-party tort claims arising from a covered act of terrorism while the technology is deployed.

What insurance is the seller required to maintain?

OSAI sets a specific liability cap during the Designation process, and the seller is required to maintain liability insurance at that level. The cap and insurance amount are set based on the deployment context, scale, and risk profile. The cap is what the buyer should look for in a certificate of insurance request, confirming the insurance amount in force matches the OSAI determination, that the policy is occurrence-based, and that it remains in force across the contract term.

If the vendor renews their Designation, does my contract roll over?

The Designation term is between the seller and DHS, not the seller and the buyer. A renewal extends the seller's protection forward; it does not automatically modify the buyer's contract. Procurement teams should require the vendor to provide written notice of renewal status, copies of the new OSAI letter, and a commitment to pursue renewal through the contract term. A lapse in Designation creates a coverage gap that affects the protection scope of any incident occurring during the lapse.

Are there AI physical security technologies that are SAFETY Act Certified rather than Designated?

As of Q2 2026 verification, no widely deployed AI weapons or threat detection platform held SAFETY Act Certification status. Certification, the highest tier, requires a higher evidentiary bar and typically follows a multi-year Designation track record. The Designated tier is the current ceiling for the AI physical security segment, and the practical procurement question is which platforms hold Designation versus DT&E versus no listing.

Does SAFETY Act status affect federal grant eligibility for security technology purchases?

It increasingly does. Several federal grant programs administered through CISA, FEMA, and DHS S&T reference SAFETY Act status as an evaluation criterion or eligibility screen. State school security grants, hospital workplace violence prevention funding, and houses-of-worship security grants have started incorporating the same language. Grant teams should verify the specific NOFO language for the program in question; the trend is clearly toward weighting Designated technologies in evaluation scoring.

Continue the research

This market analysis covers the SAFETY Act tier framework and the Q2 2026 vendor landscape. For deeper reading on specific pieces of the procurement and deployment picture:

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment