Drone Incursions and Counter-UAS for Physical Security: The 2026 Threat Intelligence Briefing on Airspace Risk, the FAA Fixed-Site Rule, and the AI Detection Layer Between Sensing and Mitigation
A threat intelligence analysis of drone incursions as a facility-perimeter risk, the FAA's May 2026 fixed-site rule, the SAFER SKIES counter-UAS authority, and where AI visual detection sits between sensing and the mitigation that remains a federal authority.
Drone incursions have become a facility-perimeter threat, and the 2026 question is no longer whether to plan for them, but how AI detection watches the airspace the ground-level camera plant was never built to see.
For most of the last decade, the unauthorized drone sat in an awkward position on the physical-security threat list. It was novel enough to make headlines, rare enough to lose budget arguments, and legally ambiguous enough that most facility operators concluded there was nothing they were permitted to do about it anyway. That framing is now obsolete. Between the FAA's May 2026 proposed rule on restricting drone flights near fixed-site facilities, the counter-UAS authority expansion buried in the FY2026 National Defense Authorization Act, and incident curves that have gone vertical at prisons, airports, and stadiums, the small unmanned aircraft has crossed from curiosity into the category of a planned-for threat surface.
This briefing treats the drone incursion the way a risk manager has to treat it: as a perimeter and airspace problem that the existing security architecture was not designed to detect, sitting inside a regulatory environment that is shifting faster than most procurement cycles can track. The analysis separates the threat patterns from the legal framework, and then examines where AI visual detection fits into a layered response. The detection question matters because the single most important distinction in the 2026 counter-drone conversation, the line between detecting a drone and mitigating one, is also the line that most facility operators are legally allowed to cross in only one direction.
The Threat Surface: Why the Drone Is a Perimeter Problem the Camera Plant Cannot See
The defining characteristic of the drone threat is that it arrives through the one approach vector most physical-security programs never instrumented. Decades of perimeter design assumed that a threat approaches at ground level, through a gate, a fence line, a loading dock, or a parking structure. Fences, bollards, access control, and the camera plant that watches them all share the same blind spot: they look outward and along the ground, not up. A drone routes around every one of those controls by traveling over them, and it does so in a payload-agnostic way. The same airframe that carries a camera for reconnaissance can carry contraband, a chemical dispersal device, or simply itself as a kinetic or disruptive object.
The incident data makes the trajectory unambiguous. The Federal Bureau of Prisons recorded 479 drone incidents in 2024, up from 23 in 2018, a more than twentyfold increase. The pattern is not confined to the federal system. South Carolina's state prisons recorded 273 drone smuggling incidents in 2025, and Georgia's prisons are averaging roughly 58 drone events per month, with the recovered payloads including narcotics, weapons, razor blades, and the burner phones and SIM cards that let incarcerated individuals continue to run criminal enterprises from inside the wire. The DOJ Office of the Inspector General flagged the federal government's limited ability to detect and respond to drones over its facilities in its audit of efforts to protect federal facilities, identifying the gap years before the incident curve went vertical.
Aviation tells the same story from a different altitude. The FAA's published drone sighting records show the agency receives more than 100 reports of unmanned aircraft sightings near airports every month, and an Associated Press analysis of FAA data found that drones accounted for 51 percent of reported aircraft near-misses over the past decade, 122 of 240 incidents. More than 60 percent of those close encounters occurred within 200 feet of an airport, and more than one in five came within 50 feet of an aircraft. These are not abstractions. They are the empirical basis for the executive and legislative actions that followed, and they are the reason the airspace immediately above and around a facility has become a security zone rather than an afterthought.
Incursion is not the same as attack, and that distinction shapes the entire response
An incursion is any unauthorized entry of a drone into protected airspace, the vast majority of which are careless or clueless operators rather than hostile actors. The security challenge is that the detection layer has to surface every incursion in real time precisely because the small fraction that are deliberate, the contraband run, the pre-attack reconnaissance, the coordinated disruption, are indistinguishable from the benign ones until behavior, payload, or persistence reveals intent. A program that cannot see the incursion at all cannot triage the threat inside it.
The Legal Wall Between Detection and Mitigation
The most consequential fact in the entire counter-drone landscape is that detecting a drone and doing something about it are governed by two completely different bodies of law. Detection, observing, tracking, and recording an unmanned aircraft using passive sensors, is broadly permissible. Mitigation, actively interfering with a drone by jamming its control link, spoofing its GPS, seizing control, or physically disabling it, implicates a stack of federal statutes that for most private operators makes the action a crime regardless of how justified it feels in the moment.
Those statutes are not obscure. Interfering with an aircraft in flight, intercepting the drone's communications link, and accessing its onboard computer can run afoul of the Aircraft Sabotage Act, the Wiretap Act, the Pen/Trap Statute, and the Computer Fraud and Abuse Act. The FAA has consistently taken the position that an unmanned aircraft is an aircraft, which means shooting one down or forcing it down implicates federal aviation crimes. This is why the joint advisory from DHS, the FBI, the FAA, and the DoD on the counter-drone authority question has been so insistent: the authority to mitigate is narrow, federally held, and not delegable to a private security team by wishful thinking.
The FY2026 National Defense Authorization Act is the most significant attempt yet to redraw those lines, and reading it carefully matters because it expands authority unevenly across agencies. Section 912 creates Joint Interagency Task Force 401 inside the Department of Defense as the central coordinating body for the counter-small-UAS mission, with a director reporting directly to the Deputy Secretary of Defense. Section 3111 grants the Department of Energy explicit statutory authority to detect, track, warn, and use reasonable force to disable drones that threaten nuclear sites. And Title LXXXVI, the SAFER SKIES Act, extends detection, tracking, and mitigation authority for credible threats to covered facilities and events across DHS and DOJ, and creates a pathway for state, local, tribal, and territorial law enforcement and correctional agencies to conduct counter-UAS operations once implementing regulations and training requirements are in place.
The guardrails in that same statute are the part facility operators tend to skip and should not. Section 8605 establishes civil penalties of up to $100,000 per violation for individuals or agencies who conduct unauthorized counter-UAS actions without the required federal coordination. In other words, the law that finally creates a domestic mitigation pathway also raises the penalty for freelancing one. For the overwhelming majority of private critical-infrastructure operators, mass-gathering venues, and correctional facilities, the practical reality through 2026 remains unchanged: you may detect, you may document, and you may coordinate, but you may not mitigate on your own authority. The defensible program is therefore built on the side of the wall you are actually allowed to stand on.
| Capability | What It Does | Primary Legal Constraint | Who May Lawfully Perform It (2026) |
|---|---|---|---|
| Passive RF / radar / acoustic detection | Senses a drone's presence, position, and sometimes its controller location | Generally permissible; RF interception raises Wiretap Act questions | Most facility operators, with counsel review of any RF capture |
| AI visual detection | Identifies and tracks an airframe in camera fields of view, logs the event, alerts responders | Permissible; no transmission interference, no airspace control action | Facility operators on their own camera infrastructure |
| RF jamming / GPS spoofing | Disrupts the control or navigation link to force a drone down or away | Wiretap Act, Pen/Trap, FCC rules; restricted federal authority | Designated federal agencies; SAFER SKIES pathway pending rules |
| Kinetic / cyber takedown | Physically disables or seizes control of the aircraft | Aircraft Sabotage Act, CFAA; $100K penalty for unauthorized action | Narrow federal authorities; DOE for nuclear sites under Sec. 3111 |
The FAA Fixed-Site Rule: A Detection Mandate in Disguise
The FAA's May 2026 notice of proposed rulemaking is the regulatory development most likely to reshape facility security budgets in the near term, and its mechanics reward close reading. Published in the Federal Register on May 6, 2026, with public comments due July 6, 2026, the proposed rule finally implements Section 2209 of the FAA Extension, Safety, and Security Act of 2016, a mandate Congress first imposed in 2016 and repeatedly extended through the FAA Reauthorization Acts of 2018 and 2024. It would create a new Part 74 establishing a formal process for operators and proprietors of fixed-site facilities to petition for unmanned aircraft flight restrictions, or UAFRs.
The scale is what makes it a planning event rather than a footnote. Working with the Sector Risk Management Agencies, the FAA identified approximately 125,000 fixed-site facilities across 16 critical-infrastructure sectors that could be considered for UAFR eligibility, and it estimates receiving more than 9,000 applications over the first five years. The eligible categories now include critical infrastructure such as energy and railroad facilities, oil refineries and chemical plants, amusement parks, and, added by the 2024 Reauthorization Act, state prisons. The proposed restrictions come in two forms: Standard UAFRs that prohibit unauthorized drone operations within a volume of airspace typically capped at 400 feet above ground level and bounded by the facility's property line, and Special UAFRs reserved for sites with credible threats and sponsored by federal security agencies.
The detail that turns this rule into a detection mandate is hiding in the application requirements. To qualify for a UAFR, an applicant must already have layered security in place, including restricted access, security personnel, and monitoring, and the facility must have the capability to receive and log broadcast Remote Identification messages from drones operating nearby. The FAA is, in effect, telling 125,000 facility operators that the price of a no-fly designation is the ability to see what is in their airspace in the first place. A flight restriction without detection is an unenforceable line on a chart. And the rule is explicit on the limit of what it confers: designations under Part 74 do not grant counter-UAS authorities. The restriction tells lawful operators to stay out. It does nothing about the operator who ignores it, which is precisely the operator a security program exists to catch.
Executive Order 14305 set the clock, and the comment window closes in July 2026
The 2025 Executive Order 14305, "Restoring American Airspace Sovereignty," directed the FAA to publish the Section 2209 rule "promptly" and to finalize it "as soon as practicable." The NPRM is the result. Facility operators in eligible sectors have a narrow window to shape the final rule through the comment process, which closes July 6, 2026. The strategic read is that the detection capability a UAFR application will require is the same capability a facility needs whether or not the restriction is ever granted, which means the smart move is to build the detection layer now and treat the designation as the regulatory benefit it unlocks rather than the reason to act.
The AI Detection Layer: What Visual Detection Sees in the Airspace
AI visual detection occupies a specific and defensible position in the counter-drone stack: it is the layer that surfaces the incursion using infrastructure a facility already owns, without crossing the legal line into mitigation. Dedicated counter-UAS systems built on radar, radio-frequency sensing, and acoustic arrays are powerful, but they are also expensive, regulated, and in the case of RF interception legally fraught. A facility's existing IP camera plant, by contrast, is a passive sensor network that already watches the perimeter, the rooftop, the yard, and the approach corridors. Applying computer vision to those feeds turns a recording system into a detection system, and detection is the action a facility operator is unambiguously allowed to take.
The technical reality is that a drone in a camera's field of view is, to a well-trained object-detection model, simply another object class with characteristic motion. The same architectural pattern that flags a person crossing a perimeter line at night, or a vehicle moving against expected traffic flow, can flag a low-altitude airframe loitering over a yard or converging on a rooftop. The detection does not depend on intercepting the drone's signal or identifying its operator. It depends on the airframe being visible, which is why camera placement and the low-altitude approach geometry matter as much as the model. Visual detection is not a substitute for radar against a fast, high-altitude approach, and the honest framing is that it is a complementary layer that excels precisely where drones do their facility-level damage: low, slow, and close to the structures they are targeting.
What visual detection adds to the airspace problem is continuous coverage of the zone where the threat becomes actionable. A radar return tells you something is in the sky; a camera detection tells you it is over your loading dock, descending toward your exercise yard, or hovering at your rooftop intake. That spatial specificity is what lets a security operations team move from awareness to a control action: locking down the yard, holding inmate movement, dispatching a responder, or escalating to the agency that does hold mitigation authority. The detection layer is the input that makes every downstream response possible, and it is the one layer a facility can stand up on its own authority today.
A Four-Layer Framework for the Drone-Aware Facility
The defensible counter-drone posture for a 2026 facility is layered, and each layer has a different owner, a different legal footing, and a different failure mode. The framework below is built around what a private operator can actually do, which means it leans heavily on detection and coordination rather than the mitigation actions reserved for federal authorities. The point is not that any single layer stops the threat. It is that the layers together convert a blind spot into a managed risk.
Four layers between the airspace and the asset. Only the first three are yours to operate.
Airspace Designation (Legal)
Part 74 UAFR petitionPetition the FAA for a Standard or Special UAFR under the proposed Section 2209 rule. Establishes the no-fly line that makes a lawful operator's entry a violation and a hostile operator's entry a documented one.
AI Visual Detection (Sensing)
<30s Alert to responderComputer vision on existing perimeter, yard, and rooftop cameras surfaces low-altitude airframes and logs the event. Passive, lawful, and built on infrastructure the facility already owns.
Response Integration (Action)
2-min Decision windowRouting the detection to lockdown, movement holds, mass notification, and a documented escalation to the agency that holds mitigation authority. Closes the gap between seeing the incursion and acting on it.
Mitigation (Federal)
$100K Unauthorized-action penaltyJamming, spoofing, or takedown, reserved for designated federal authorities and the SAFER SKIES SLTT pathway once rules issue. Not a private-operator action. Coordinate, do not freelance.
The architectural insight worth emphasizing is that the value of the program concentrates in Layers 02 and 03, the two layers a facility fully controls. Detection without response integration is an alert nobody acts on. Response integration without detection is a plan with no trigger. The mitigation layer, however appealing, is the one most operators cannot lawfully operate, which is exactly why a serious program does not wait on it. The facility that has instrumented its airspace and rehearsed its response is the facility that can hand a federal partner a precise, time-stamped, location-specific picture of the threat the moment mitigation authority is in play.
Sector Realities: Where the Drone Threat Lands Hardest
The drone threat is not evenly distributed, and the sectors feeling it first are the ones whose incident data forced the regulatory response. Correctional facilities face the most mature criminal use case: organized contraband delivery that has scaled from a novelty into a logistics operation, with state systems now measuring drone events in the dozens per month and the payloads escalating from tobacco to narcotics, weapons, and communications devices that sustain criminal activity inside the wire. For a warden, the drone is not a hypothetical; it is the supply chain a security program is fighting in real time.
Mass-gathering venues face a different profile. Here the concern is less contraband and more crowd safety, disruption, and the worst-case scenario of a payload over a packed stadium, which is why the NFL pressed hard for the counter-drone provisions in the FY2026 NDAA and why jurisdictions hosting 2026 FIFA World Cup matches are receiving priority for counter-UAS training and resources. Critical infrastructure operators, energy, water, chemical, and the substations and control rooms that anchor them, face the reconnaissance-and-disruption case, where a drone surveils a site to plan a physical or cyber attack, or directly interferes with sensitive operations. And airports sit at the intersection of safety and security, where the 51 percent near-miss share is not a property-crime statistic but an aviation-safety emergency.
The common thread across all four is that each sector already operates a camera plant pointed at the ground. The retrofit logic that has driven AI adoption across physical security applies directly: the fastest and most legally clean way to add airspace awareness is to extend detection to the cameras that already watch the perimeter, rather than procure a parallel sensor network and the regulated mitigation authority that network implies but cannot deliver.
Airspace detection does not require identifying anyone
A recurring objection to adding any new detection capability is the privacy question, and the airspace case is unusually clean on this point. Detecting an airframe is detecting an object, not a person. The visual detection layer described here does not perform facial recognition, does not attempt to identify a drone operator, and does not retain video beyond the facility's existing retention policy. It surfaces an object class and a location, which is exactly the information a responder needs and nothing more. The privacy-sensitive question of who is flying the drone is a law-enforcement matter that begins only after the incursion is detected and escalated through lawful channels.
What This Means for Procurement in 2026
For a security director or risk officer building next year's budget, the drone question resolves into a sequence rather than a single purchase. The first move is to determine whether the facility falls within one of the 16 FAA critical-infrastructure sectors and whether a UAFR petition is worth filing, a decision that benefits from engaging during the comment window that closes July 6, 2026. The second move is to instrument the airspace, and the most defensible path is to extend AI visual detection onto the existing camera plant rather than to lead with a costly dedicated counter-UAS system whose mitigation features a private operator cannot legally use. The third move is to wire the detection into the response plan so that an airspace alert triggers the same disciplined escalation as any other perimeter event.
The mistake to avoid is sequencing the program around mitigation. Counter-drone marketing leads with the dramatic capability, jamming, spoofing, takedown, that is precisely the capability the law reserves for someone else, so a program built on that premise spends the most money on the layer it can use the least. The posture that ages well is built on detection and response, the two layers a facility fully owns, with mitigation treated as a federal partnership to be invoked rather than a product to be deployed. Given the $100,000 penalty for unauthorized action, that is both the legally sound posture and the financially prudent one.
The broader frame is that the drone is the newest entry in a long list of threats that exploit the seam between what the legacy security architecture was built to watch and what the modern threat actually does. The facility that has already moved from passive recording to real-time AI detection on its perimeter has done most of the architectural work. Extending that detection upward, into the airspace the camera plant was never asked to consider, is an increment rather than a rebuild, and the facilities that move now will have a defensible answer when the auditor, the insurer, or the board asks what the plan is for the sky.
Frequently Asked Questions
Continue the research
- Perimeter Intrusion: The 90-Second Window That Defines Your Security Posture
- Critical Infrastructure and Electric Utilities: The 2026 AI Physical Security Sector Playbook
- Correctional Facilities and Detention Centers: The 2026 AI Physical Security Sector Playbook
- Stadiums, Arenas, and Mass-Gathering Venues: The 2026 AI Physical Security Sector Playbook
- NDAA Section 889 and FAR 52.204-25: The Camera Supply-Chain Compliance Briefing
- How IntelliSee detection works on existing IP cameras
- Industries protected by IntelliSee AI detection
- Request a site-specific risk assessment for your facility
Request a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment