Drone Incursions and Counter-UAS for Physical Security: The 2026 Threat Intelligence Briefing on Airspace Risk, the FAA Fixed-Site Rule, and the AI Detection Layer Between Sensing and Mitigation
Home / Intelligence / Drone Incursions and Counter-UAS for Physical...
Threat Intelligence

Drone Incursions and Counter-UAS for Physical Security: The 2026 Threat Intelligence Briefing on Airspace Risk, the FAA Fixed-Site Rule, and the AI Detection Layer Between Sensing and Mitigation

A threat intelligence analysis of drone incursions as a facility-perimeter risk, the FAA's May 2026 fixed-site rule, the SAFER SKIES counter-UAS authority, and where AI visual detection sits between sensing and the mitigation that remains a federal authority.

Published June 2026
Read Time 15 min read
Stream Threat Intelligence
125,000
Fixed-site facilities the FAA flagged for possible drone flight restrictions
479
Federal-prison drone incidents in 2024, up from 23 in 2018
51%
Share of aircraft near-misses over the past decade involving drones
Threat Intelligence Briefing

Drone incursions have become a facility-perimeter threat, and the 2026 question is no longer whether to plan for them, but how AI detection watches the airspace the ground-level camera plant was never built to see.

125,000 Fixed-site facilities across 16 critical-infrastructure sectors the FAA identified as potentially eligible for drone flight restrictions in its May 2026 proposed rule. FAA NPRM, Federal Register 2026-08943, May 6, 2026
479 Drone incidents recorded at federal prisons in 2024, up from 23 in 2018, a more than twentyfold rise in six years. Federal Bureau of Prisons, reported December 2025
51% Share of reported aircraft near-misses over the past decade that involved drones, 122 of 240 incidents in an analysis of FAA data. Associated Press analysis of FAA reporting, 2025
Primary sources cited inline: FAA, the FY2026 National Defense Authorization Act, the Federal Bureau of Prisons, the DOJ Office of the Inspector General, DHS, CISA, and 49 U.S.C. 44802.

For most of the last decade, the unauthorized drone sat in an awkward position on the physical-security threat list. It was novel enough to make headlines, rare enough to lose budget arguments, and legally ambiguous enough that most facility operators concluded there was nothing they were permitted to do about it anyway. That framing is now obsolete. Between the FAA's May 2026 proposed rule on restricting drone flights near fixed-site facilities, the counter-UAS authority expansion buried in the FY2026 National Defense Authorization Act, and incident curves that have gone vertical at prisons, airports, and stadiums, the small unmanned aircraft has crossed from curiosity into the category of a planned-for threat surface.

This briefing treats the drone incursion the way a risk manager has to treat it: as a perimeter and airspace problem that the existing security architecture was not designed to detect, sitting inside a regulatory environment that is shifting faster than most procurement cycles can track. The analysis separates the threat patterns from the legal framework, and then examines where AI visual detection fits into a layered response. The detection question matters because the single most important distinction in the 2026 counter-drone conversation, the line between detecting a drone and mitigating one, is also the line that most facility operators are legally allowed to cross in only one direction.

The Threat Surface: Why the Drone Is a Perimeter Problem the Camera Plant Cannot See

The defining characteristic of the drone threat is that it arrives through the one approach vector most physical-security programs never instrumented. Decades of perimeter design assumed that a threat approaches at ground level, through a gate, a fence line, a loading dock, or a parking structure. Fences, bollards, access control, and the camera plant that watches them all share the same blind spot: they look outward and along the ground, not up. A drone routes around every one of those controls by traveling over them, and it does so in a payload-agnostic way. The same airframe that carries a camera for reconnaissance can carry contraband, a chemical dispersal device, or simply itself as a kinetic or disruptive object.

The incident data makes the trajectory unambiguous. The Federal Bureau of Prisons recorded 479 drone incidents in 2024, up from 23 in 2018, a more than twentyfold increase. The pattern is not confined to the federal system. South Carolina's state prisons recorded 273 drone smuggling incidents in 2025, and Georgia's prisons are averaging roughly 58 drone events per month, with the recovered payloads including narcotics, weapons, razor blades, and the burner phones and SIM cards that let incarcerated individuals continue to run criminal enterprises from inside the wire. The DOJ Office of the Inspector General flagged the federal government's limited ability to detect and respond to drones over its facilities in its audit of efforts to protect federal facilities, identifying the gap years before the incident curve went vertical.

Aviation tells the same story from a different altitude. The FAA's published drone sighting records show the agency receives more than 100 reports of unmanned aircraft sightings near airports every month, and an Associated Press analysis of FAA data found that drones accounted for 51 percent of reported aircraft near-misses over the past decade, 122 of 240 incidents. More than 60 percent of those close encounters occurred within 200 feet of an airport, and more than one in five came within 50 feet of an aircraft. These are not abstractions. They are the empirical basis for the executive and legislative actions that followed, and they are the reason the airspace immediately above and around a facility has become a security zone rather than an afterthought.

Definition Brief

Incursion is not the same as attack, and that distinction shapes the entire response

An incursion is any unauthorized entry of a drone into protected airspace, the vast majority of which are careless or clueless operators rather than hostile actors. The security challenge is that the detection layer has to surface every incursion in real time precisely because the small fraction that are deliberate, the contraband run, the pre-attack reconnaissance, the coordinated disruption, are indistinguishable from the benign ones until behavior, payload, or persistence reveals intent. A program that cannot see the incursion at all cannot triage the threat inside it.

The Legal Wall Between Detection and Mitigation

The most consequential fact in the entire counter-drone landscape is that detecting a drone and doing something about it are governed by two completely different bodies of law. Detection, observing, tracking, and recording an unmanned aircraft using passive sensors, is broadly permissible. Mitigation, actively interfering with a drone by jamming its control link, spoofing its GPS, seizing control, or physically disabling it, implicates a stack of federal statutes that for most private operators makes the action a crime regardless of how justified it feels in the moment.

Those statutes are not obscure. Interfering with an aircraft in flight, intercepting the drone's communications link, and accessing its onboard computer can run afoul of the Aircraft Sabotage Act, the Wiretap Act, the Pen/Trap Statute, and the Computer Fraud and Abuse Act. The FAA has consistently taken the position that an unmanned aircraft is an aircraft, which means shooting one down or forcing it down implicates federal aviation crimes. This is why the joint advisory from DHS, the FBI, the FAA, and the DoD on the counter-drone authority question has been so insistent: the authority to mitigate is narrow, federally held, and not delegable to a private security team by wishful thinking.

The FY2026 National Defense Authorization Act is the most significant attempt yet to redraw those lines, and reading it carefully matters because it expands authority unevenly across agencies. Section 912 creates Joint Interagency Task Force 401 inside the Department of Defense as the central coordinating body for the counter-small-UAS mission, with a director reporting directly to the Deputy Secretary of Defense. Section 3111 grants the Department of Energy explicit statutory authority to detect, track, warn, and use reasonable force to disable drones that threaten nuclear sites. And Title LXXXVI, the SAFER SKIES Act, extends detection, tracking, and mitigation authority for credible threats to covered facilities and events across DHS and DOJ, and creates a pathway for state, local, tribal, and territorial law enforcement and correctional agencies to conduct counter-UAS operations once implementing regulations and training requirements are in place.

The guardrails in that same statute are the part facility operators tend to skip and should not. Section 8605 establishes civil penalties of up to $100,000 per violation for individuals or agencies who conduct unauthorized counter-UAS actions without the required federal coordination. In other words, the law that finally creates a domestic mitigation pathway also raises the penalty for freelancing one. For the overwhelming majority of private critical-infrastructure operators, mass-gathering venues, and correctional facilities, the practical reality through 2026 remains unchanged: you may detect, you may document, and you may coordinate, but you may not mitigate on your own authority. The defensible program is therefore built on the side of the wall you are actually allowed to stand on.

CapabilityWhat It DoesPrimary Legal ConstraintWho May Lawfully Perform It (2026)
Passive RF / radar / acoustic detectionSenses a drone's presence, position, and sometimes its controller locationGenerally permissible; RF interception raises Wiretap Act questionsMost facility operators, with counsel review of any RF capture
AI visual detectionIdentifies and tracks an airframe in camera fields of view, logs the event, alerts respondersPermissible; no transmission interference, no airspace control actionFacility operators on their own camera infrastructure
RF jamming / GPS spoofingDisrupts the control or navigation link to force a drone down or awayWiretap Act, Pen/Trap, FCC rules; restricted federal authorityDesignated federal agencies; SAFER SKIES pathway pending rules
Kinetic / cyber takedownPhysically disables or seizes control of the aircraftAircraft Sabotage Act, CFAA; $100K penalty for unauthorized actionNarrow federal authorities; DOE for nuclear sites under Sec. 3111

The FAA Fixed-Site Rule: A Detection Mandate in Disguise

The FAA's May 2026 notice of proposed rulemaking is the regulatory development most likely to reshape facility security budgets in the near term, and its mechanics reward close reading. Published in the Federal Register on May 6, 2026, with public comments due July 6, 2026, the proposed rule finally implements Section 2209 of the FAA Extension, Safety, and Security Act of 2016, a mandate Congress first imposed in 2016 and repeatedly extended through the FAA Reauthorization Acts of 2018 and 2024. It would create a new Part 74 establishing a formal process for operators and proprietors of fixed-site facilities to petition for unmanned aircraft flight restrictions, or UAFRs.

The scale is what makes it a planning event rather than a footnote. Working with the Sector Risk Management Agencies, the FAA identified approximately 125,000 fixed-site facilities across 16 critical-infrastructure sectors that could be considered for UAFR eligibility, and it estimates receiving more than 9,000 applications over the first five years. The eligible categories now include critical infrastructure such as energy and railroad facilities, oil refineries and chemical plants, amusement parks, and, added by the 2024 Reauthorization Act, state prisons. The proposed restrictions come in two forms: Standard UAFRs that prohibit unauthorized drone operations within a volume of airspace typically capped at 400 feet above ground level and bounded by the facility's property line, and Special UAFRs reserved for sites with credible threats and sponsored by federal security agencies.

The detail that turns this rule into a detection mandate is hiding in the application requirements. To qualify for a UAFR, an applicant must already have layered security in place, including restricted access, security personnel, and monitoring, and the facility must have the capability to receive and log broadcast Remote Identification messages from drones operating nearby. The FAA is, in effect, telling 125,000 facility operators that the price of a no-fly designation is the ability to see what is in their airspace in the first place. A flight restriction without detection is an unenforceable line on a chart. And the rule is explicit on the limit of what it confers: designations under Part 74 do not grant counter-UAS authorities. The restriction tells lawful operators to stay out. It does nothing about the operator who ignores it, which is precisely the operator a security program exists to catch.

Regulatory Nuance

Executive Order 14305 set the clock, and the comment window closes in July 2026

The 2025 Executive Order 14305, "Restoring American Airspace Sovereignty," directed the FAA to publish the Section 2209 rule "promptly" and to finalize it "as soon as practicable." The NPRM is the result. Facility operators in eligible sectors have a narrow window to shape the final rule through the comment process, which closes July 6, 2026. The strategic read is that the detection capability a UAFR application will require is the same capability a facility needs whether or not the restriction is ever granted, which means the smart move is to build the detection layer now and treat the designation as the regulatory benefit it unlocks rather than the reason to act.

The AI Detection Layer: What Visual Detection Sees in the Airspace

AI visual detection occupies a specific and defensible position in the counter-drone stack: it is the layer that surfaces the incursion using infrastructure a facility already owns, without crossing the legal line into mitigation. Dedicated counter-UAS systems built on radar, radio-frequency sensing, and acoustic arrays are powerful, but they are also expensive, regulated, and in the case of RF interception legally fraught. A facility's existing IP camera plant, by contrast, is a passive sensor network that already watches the perimeter, the rooftop, the yard, and the approach corridors. Applying computer vision to those feeds turns a recording system into a detection system, and detection is the action a facility operator is unambiguously allowed to take.

The technical reality is that a drone in a camera's field of view is, to a well-trained object-detection model, simply another object class with characteristic motion. The same architectural pattern that flags a person crossing a perimeter line at night, or a vehicle moving against expected traffic flow, can flag a low-altitude airframe loitering over a yard or converging on a rooftop. The detection does not depend on intercepting the drone's signal or identifying its operator. It depends on the airframe being visible, which is why camera placement and the low-altitude approach geometry matter as much as the model. Visual detection is not a substitute for radar against a fast, high-altitude approach, and the honest framing is that it is a complementary layer that excels precisely where drones do their facility-level damage: low, slow, and close to the structures they are targeting.

LIVE DETECTION CAM-7 / NORTH PERIMETER Actual IntelliSee AI detection output on a night-time perimeter camera showing a bounding box labeled Person 1 with a 0.83 confidence score
Actual IntelliSee detection output. A night-time perimeter camera frame with the platform flagging a person at the property line, bounding box labeled "Person 1" at 0.83 confidence. The same behavioral motion and object-detection layers that surface a ground-level perimeter incursion at low light operate continuously on the customer's existing camera feeds, and the identical architecture applies to a low-altitude airframe loitering over a yard or rooftop. No facial recognition is performed, no video is retained beyond the customer's defined retention policy, and no protected health information is collected. Alerts route to designated responders within seconds.

What visual detection adds to the airspace problem is continuous coverage of the zone where the threat becomes actionable. A radar return tells you something is in the sky; a camera detection tells you it is over your loading dock, descending toward your exercise yard, or hovering at your rooftop intake. That spatial specificity is what lets a security operations team move from awareness to a control action: locking down the yard, holding inmate movement, dispatching a responder, or escalating to the agency that does hold mitigation authority. The detection layer is the input that makes every downstream response possible, and it is the one layer a facility can stand up on its own authority today.

A Four-Layer Framework for the Drone-Aware Facility

The defensible counter-drone posture for a 2026 facility is layered, and each layer has a different owner, a different legal footing, and a different failure mode. The framework below is built around what a private operator can actually do, which means it leans heavily on detection and coordination rather than the mitigation actions reserved for federal authorities. The point is not that any single layer stops the threat. It is that the layers together convert a blind spot into a managed risk.

Drone-Aware Facility Framework

Four layers between the airspace and the asset. Only the first three are yours to operate.

LAYER 01

Airspace Designation (Legal)

Part 74 UAFR petition

Petition the FAA for a Standard or Special UAFR under the proposed Section 2209 rule. Establishes the no-fly line that makes a lawful operator's entry a violation and a hostile operator's entry a documented one.

Owner: Legal + compliance
LAYER 02

AI Visual Detection (Sensing)

<30s Alert to responder

Computer vision on existing perimeter, yard, and rooftop cameras surfaces low-altitude airframes and logs the event. Passive, lawful, and built on infrastructure the facility already owns.

Owner: Security operations + IT
LAYER 03

Response Integration (Action)

2-min Decision window

Routing the detection to lockdown, movement holds, mass notification, and a documented escalation to the agency that holds mitigation authority. Closes the gap between seeing the incursion and acting on it.

Owner: Emergency management
LAYER 04

Mitigation (Federal)

$100K Unauthorized-action penalty

Jamming, spoofing, or takedown, reserved for designated federal authorities and the SAFER SKIES SLTT pathway once rules issue. Not a private-operator action. Coordinate, do not freelance.

Owner: Federal / authorized SLTT
Framing aligned to the FAA Section 2209 NPRM, the FY2026 NDAA SAFER SKIES Act, and DHS / CISA counter-UAS guidance. Layer 04 authority varies by site and statute.

The architectural insight worth emphasizing is that the value of the program concentrates in Layers 02 and 03, the two layers a facility fully controls. Detection without response integration is an alert nobody acts on. Response integration without detection is a plan with no trigger. The mitigation layer, however appealing, is the one most operators cannot lawfully operate, which is exactly why a serious program does not wait on it. The facility that has instrumented its airspace and rehearsed its response is the facility that can hand a federal partner a precise, time-stamped, location-specific picture of the threat the moment mitigation authority is in play.

Sector Realities: Where the Drone Threat Lands Hardest

The drone threat is not evenly distributed, and the sectors feeling it first are the ones whose incident data forced the regulatory response. Correctional facilities face the most mature criminal use case: organized contraband delivery that has scaled from a novelty into a logistics operation, with state systems now measuring drone events in the dozens per month and the payloads escalating from tobacco to narcotics, weapons, and communications devices that sustain criminal activity inside the wire. For a warden, the drone is not a hypothetical; it is the supply chain a security program is fighting in real time.

Mass-gathering venues face a different profile. Here the concern is less contraband and more crowd safety, disruption, and the worst-case scenario of a payload over a packed stadium, which is why the NFL pressed hard for the counter-drone provisions in the FY2026 NDAA and why jurisdictions hosting 2026 FIFA World Cup matches are receiving priority for counter-UAS training and resources. Critical infrastructure operators, energy, water, chemical, and the substations and control rooms that anchor them, face the reconnaissance-and-disruption case, where a drone surveils a site to plan a physical or cyber attack, or directly interferes with sensitive operations. And airports sit at the intersection of safety and security, where the 51 percent near-miss share is not a property-crime statistic but an aviation-safety emergency.

The common thread across all four is that each sector already operates a camera plant pointed at the ground. The retrofit logic that has driven AI adoption across physical security applies directly: the fastest and most legally clean way to add airspace awareness is to extend detection to the cameras that already watch the perimeter, rather than procure a parallel sensor network and the regulated mitigation authority that network implies but cannot deliver.

Privacy by Design

Airspace detection does not require identifying anyone

A recurring objection to adding any new detection capability is the privacy question, and the airspace case is unusually clean on this point. Detecting an airframe is detecting an object, not a person. The visual detection layer described here does not perform facial recognition, does not attempt to identify a drone operator, and does not retain video beyond the facility's existing retention policy. It surfaces an object class and a location, which is exactly the information a responder needs and nothing more. The privacy-sensitive question of who is flying the drone is a law-enforcement matter that begins only after the incursion is detected and escalated through lawful channels.

What This Means for Procurement in 2026

For a security director or risk officer building next year's budget, the drone question resolves into a sequence rather than a single purchase. The first move is to determine whether the facility falls within one of the 16 FAA critical-infrastructure sectors and whether a UAFR petition is worth filing, a decision that benefits from engaging during the comment window that closes July 6, 2026. The second move is to instrument the airspace, and the most defensible path is to extend AI visual detection onto the existing camera plant rather than to lead with a costly dedicated counter-UAS system whose mitigation features a private operator cannot legally use. The third move is to wire the detection into the response plan so that an airspace alert triggers the same disciplined escalation as any other perimeter event.

The mistake to avoid is sequencing the program around mitigation. Counter-drone marketing leads with the dramatic capability, jamming, spoofing, takedown, that is precisely the capability the law reserves for someone else, so a program built on that premise spends the most money on the layer it can use the least. The posture that ages well is built on detection and response, the two layers a facility fully owns, with mitigation treated as a federal partnership to be invoked rather than a product to be deployed. Given the $100,000 penalty for unauthorized action, that is both the legally sound posture and the financially prudent one.

The broader frame is that the drone is the newest entry in a long list of threats that exploit the seam between what the legacy security architecture was built to watch and what the modern threat actually does. The facility that has already moved from passive recording to real-time AI detection on its perimeter has done most of the architectural work. Extending that detection upward, into the airspace the camera plant was never asked to consider, is an increment rather than a rebuild, and the facilities that move now will have a defensible answer when the auditor, the insurer, or the board asks what the plan is for the sky.

Frequently Asked Questions

Can a private facility legally shoot down or jam a drone flying over its property?
No. For nearly all private operators in 2026, actively interfering with a drone, by jamming its control link, spoofing its GPS, seizing control, or physically disabling it, implicates federal statutes including the Aircraft Sabotage Act, the Wiretap Act, the Pen/Trap Statute, and the Computer Fraud and Abuse Act. The FAA treats an unmanned aircraft as an aircraft. The FY2026 NDAA's SAFER SKIES Act begins to create a pathway for state, local, and correctional agencies to conduct counter-UAS operations, but only after implementing regulations and training requirements are in place, and the same law sets a penalty of up to $100,000 per violation for unauthorized counter-UAS action. Detection and documentation are lawful for facility operators; mitigation generally is not.
Does AI drone detection require buying new cameras, or can it work on the cameras we already have?
In most deployments, AI visual detection runs on a facility's existing IP cameras, provided they support ONVIF or RTSP and meet minimum resolution and frame-rate requirements for the relevant zones, and provided the cameras actually cover the low-altitude approach geometry where drones do facility-level damage. The retrofit pattern dominates because it converts a passive recording network into a detection network without a parallel sensor procurement. The practical limit is camera placement: a plant pointed only at ground-level gates and fence lines may need additional fields of view aimed at rooftops, yards, and intake areas to see airspace incursions reliably.
How is the FAA's May 2026 proposed rule different from a counter-drone system?
They solve different problems. The FAA's proposed Part 74 rule creates a legal designation, the unmanned aircraft flight restriction, that tells lawful drone operators to stay out of a defined volume of airspace around an eligible facility. It is a regulatory line, not a security technology, and the rule is explicit that a designation does not confer any authority to mitigate a drone. A counter-drone system, by contrast, is the technical capability to detect and potentially act on an incursion. The two are complementary: the rule even requires applicants to demonstrate they can receive and log Remote ID messages, which means the designation effectively presumes a detection capability is already in place.
Why are prisons such a prominent part of the drone threat conversation?
Correctional facilities have the most mature criminal drone use case in the country. The Federal Bureau of Prisons recorded 479 drone incidents in 2024, up from 23 in 2018, and state systems report similar trajectories, with some averaging dozens of events per month. The payloads have escalated from tobacco to narcotics, weapons, and the burner phones and SIM cards that let incarcerated individuals continue running criminal enterprises. That severity is why the 2024 FAA Reauthorization Act specifically added state prisons to the list of facilities eligible for drone flight restrictions, and why the SAFER SKIES Act created a counter-UAS pathway for correctional agencies.
Is visual detection enough on its own, or do we still need radar and RF sensors?
Visual detection and dedicated counter-UAS sensors are complementary, not interchangeable. Radar and RF systems excel at detecting fast or high-altitude approaches and can sometimes locate the operator, but they are expensive, regulated, and in the case of RF interception legally complicated. Visual detection excels precisely where drones do facility-level harm, low, slow, and close to the structures they target, and it runs on infrastructure a facility already owns. The honest framing is that the right mix depends on the threat profile: a nuclear site with federal mitigation authority will layer multiple sensor types, while a typical critical-infrastructure operator or correctional facility often gets the most defensible coverage per dollar by extending AI detection onto its existing camera plant.
What should a facility do before the FAA comment window closes in July 2026?
Two things. First, determine whether the facility falls within one of the 16 critical-infrastructure sectors eligible for a UAFR and, if so, consider submitting comments on the proposed rule before the July 6, 2026 deadline, since the final rule will shape eligibility, application burden, and the Remote ID sensing requirements. Second, and independent of the rule, begin instrumenting the airspace, because the detection capability a UAFR application will require is the same capability the facility needs whether or not the restriction is ever granted. Treating the designation as a benefit that detection unlocks, rather than as the reason to act, is the sequencing that ages best.

Continue the research

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment