Negligent Security and Premises Liability: The 2026 Standards-Compliance Briefing on the Foreseeability Test, the 2025 Tort-Reform Wave, and the Detection Record That Decides the Verdict
A standards-and-compliance analysis of the foreseeability test that decides who pays when a third party commits a crime on the premises, the 2025 tort-reform wave led by Georgia's SB 68, and how a property's detection record builds or rebuts the negligent security case.
Negligent security litigation is the fastest-moving liability exposure in physical security, and the law that decides who pays now turns on a single legal question: was the crime foreseeable? Three numbers define the 2026 landscape.
Negligent security is the body of premises-liability law that holds a property owner or occupier responsible when a third party commits a violent crime on the premises and inadequate security was a proximate cause of the harm. It is not a niche doctrine. It is the legal mechanism through which a parking-lot assault, a lobby shooting, or an apartment-complex robbery becomes a multimillion-dollar judgment against the property owner rather than only against the perpetrator. For security directors, risk officers, and the general counsel who sign off on physical security budgets, negligent security is where the cost of an underspent security program is ultimately priced.
This briefing is a standards-and-compliance analysis of how that pricing works. It covers the legal architecture of a negligent security claim, the competing foreseeability standards that determine liability across U.S. jurisdictions, the 2025 wave of tort reform that is reshaping the doctrine, and the specific way that the documentary record produced by a security program either builds the plaintiff's case or rebuts it. It closes with where AI-assisted detection fits into that record. The goal is a reference a risk leader can use to understand why the foreseeability question, not the security budget, is the variable that decides the verdict.
The anatomy of a negligent security claim
A negligent security case is a negligence action, which means the plaintiff must establish the same four elements as any negligence claim: duty, breach, causation, and damages. What makes negligent security distinct is that the harm was inflicted by a criminal third party rather than by the defendant directly, and the law has to decide when a property owner owes a duty to protect a visitor from someone else's crime.
The starting principle is that there is generally no duty to protect another person from the criminal conduct of a third party. Negligent security is the exception to that principle. The exception arises from the special relationship between a property possessor and the people it invites onto its land. Under the Restatement (Second) of Torts § 344 and the framework carried into the Restatement (Third) of Torts: Liability for Physical and Emotional Harm, a business that holds its premises open to the public owes its invitees a duty of reasonable care, and that duty can extend to protecting against the foreseeable criminal acts of third parties. The decisive word in that sentence is foreseeable.
The four elements map onto a negligent security case as follows. Duty exists when the criminal act was foreseeable enough that a reasonable property owner should have anticipated it and taken protective measures. Breach occurs when the security measures actually in place fell below what reasonable care required given that foreseeability. Causation requires the plaintiff to show that the inadequate security was a proximate cause of the harm, meaning adequate security would more likely than not have prevented or mitigated it. Damages are the medical costs, lost income, pain and suffering, and in wrongful-death cases the survivors' losses that flow from the attack.
The element that consumes most of the litigation is the first one, and the reason is structural. If the crime was not foreseeable, no duty to guard against it ever arose, and the case ends before breach is even reached. This is why the foreseeability standard a jurisdiction applies is not a technicality. It is the gate that determines whether a property owner is exposed to a multimillion-dollar verdict or is dismissed on summary judgment. The U.S. Chamber's Institute for Legal Reform found that premises-liability cases accounted for roughly a quarter of the nuclear verdicts (jury awards of $10 million or more) it tracked in Georgia, with a statewide median nuclear verdict of $24 million. The difference between owing a duty and not owing one is, in dollar terms, the entire case.
The four foreseeability standards that decide who pays
American courts do not apply a single test for foreseeability in negligent security cases. They apply four different ones, and which test a jurisdiction has adopted is the single most important predictor of whether a property owner is liable. The standards range from highly defendant-favorable to highly plaintiff-favorable, and they have been the subject of decades of state supreme court litigation. Understanding which test governs a given property is the foundation of any premises-liability risk assessment.
The most restrictive standard is the specific-imminent-harm rule, which imposes a duty only when the owner is aware of a specific, imminent threat. The most common defendant-favorable standard is the prior-similar-incidents test, under which foreseeability is established by a history of substantially similar crimes on or near the property. The most plaintiff-favorable widely-adopted standard is the totality-of-the-circumstances test, which lets a jury weigh the property's overall condition, location, and crime environment rather than requiring a documented history of identical prior crimes. A fourth approach, the balancing test, weighs the foreseeability of harm against the burden of the duty to be imposed.
The California Supreme Court's decision in Ann M. v. Pacific Plaza Shopping Center, 6 Cal.4th 666 (1993), is the canonical articulation of the prior-similar-incidents approach in its strict form. The plaintiff, an employee assaulted in a shopping-center business, sued the landlord for failing to provide security guards. The court held that the high burden of requiring roving guards could be imposed only where the harm was highly foreseeable, and that such foreseeability "rarely, if ever, can be proven in the absence of prior similar incidents of violent crime on the landowner's premises." Because Pacific Plaza had no notice of prior similar violent crimes, no duty to provide guards arose. Ann M. became the reference point for how demanding a prior-similar-incidents jurisdiction can be.
The Texas Supreme Court's decision in Timberwalk Apartments v. Cain, 972 S.W.2d 749 (Tex. 1998), produced the most widely cited operational framework for evaluating prior-incident foreseeability. A tenant sexually assaulted in her apartment sued the complex. The court held that foreseeability in the third-party-crime context is measured by four factors: the proximity of other crimes to the property, the recency and frequency of those crimes, the similarity of those crimes to the one at issue, and the publicity of those crimes, meaning whether the owner knew or should have known of them. The Timberwalk factors are now applied or cited well beyond Texas because they convert an abstract foreseeability inquiry into a structured, evidence-driven analysis. They are also, for a security director, a checklist: they describe exactly what a plaintiff's expert will assemble to prove the owner should have seen the attack coming.
The Four Foreseeability Standards in U.S. Negligent Security Law
| Standard | What Triggers a Duty | Posture | Representative Authority |
|---|---|---|---|
| Specific imminent harm | Owner has actual knowledge of a specific, imminent threat unfolding in the moment | Most defendant-favorable | Historically the narrowest rule; echoed in Georgia's 2025 "actual knowledge of imminent threat" trigger |
| Prior similar incidents | A documented history of substantially similar crimes on or near the premises | Defendant-favorable | Ann M. v. Pacific Plaza Shopping Center, 6 Cal.4th 666 (Cal. 1993) |
| Prior-incident factor test | Weighing proximity, recency and frequency, similarity, and publicity of prior crimes | Balanced, evidence-driven | Timberwalk Apartments v. Cain, 972 S.W.2d 749 (Tex. 1998) |
| Totality of the circumstances | The property's overall location, condition, and crime environment, with or without identical prior crimes | Most plaintiff-favorable | Adopted in varying forms across numerous states; widely regarded as the broadest standard |
Layered on top of these standards is a doctrinal shift in how foreseeability is allocated between judge and jury. The Restatement (Third) of Torts deliberately removed foreseeability from the duty determination and reassigned it to the breach question. Under § 7, courts decide duty as a matter of law based on policy, and under the negligence analysis foreseeability becomes a fact question for the jury rather than a legal gatekeeping question for the judge. In jurisdictions that have adopted the Third Restatement's approach, this matters enormously: it makes summary judgment on the no-duty theory harder to obtain, because the foreseeability dispute that once let a judge dismiss a case now goes to a jury. For property owners, that change shifts more cases into the high-variance zone where nuclear verdicts live.
Why the foreseeability standard is a procurement variable, not just a legal one
The foreseeability standard governing a property is fixed by the jurisdiction, not by the owner. But what the owner controls is the evidentiary record that the standard is applied to. Under every standard except specific-imminent-harm, the analysis is retrospective: a plaintiff's expert reconstructs the crime history around the property and argues the owner should have responded to it. A security program that detects, logs, and responds to lower-level precursor events (trespass, loitering, after-hours intrusion) is generating contemporaneous evidence that the owner was not ignoring the environment. The same logging that proves an owner knew about prior incidents can also prove the owner acted on them. Which of those two stories the record tells is a function of how the security system is configured and documented, and that is a procurement decision.
How the 2025 tort-reform wave is rewriting the doctrine
The negligent security landscape changed materially in 2025, and Georgia's Senate Bill 68 is the clearest example of the direction of travel. Signed into law on April 21, 2025, SB 68 was a response to Georgia's reputation as a "judicial hellhole" for premises-liability defendants, and it rewrote the rules for negligent security claims through seven new code sections, O.C.G.A. §§ 51-3-50 through 51-3-57, codified in a newly created Article 5 of Title 51, Chapter 3. The statute is the most significant single-state recalibration of negligent security liability in recent memory, and it telegraphs the framework other reform-minded states are likely to borrow.
SB 68 changes the doctrine in three structural ways. First, it codifies a heightened foreseeability standard. For invitees, an owner can be held liable only where the owner had a specific warning of an imminent threat with actual knowledge, prior substantially similar crimes on the property with documented knowledge, prior similar crimes within 500 yards of the property with actual knowledge, or prior conduct by the same perpetrator that the owner knew or should have known about. The 500-yard radius is notable because it converts the previously fuzzy "near the premises" inquiry into a hard geographic line, and it ties liability to documented owner knowledge rather than to the abstract existence of area crime.
Second, it mandates apportionment of fault to the criminal. A jury in a Georgia negligent security action must now apportion fault among the owner or occupier, the third party whose wrongful conduct caused the injury (the perpetrator), and any other responsible person. SB 68 creates a rebuttable presumption that an apportionment is unreasonable if the total fault assigned to all perpetrators is less than the total assigned to all owners, security contractors, and other non-criminal parties. A trial court must set aside a verdict that fails to apportion a reasonable degree of fault to the perpetrator and order a new trial. This directly attacks the dynamic that produced the largest premises verdicts, in which juries assigned the overwhelming majority of fault to the property owner because the perpetrator was absent, judgment-proof, or unidentified.
Third, it creates a statutory right to bifurcation. Before SB 68, splitting a trial into separate liability and damages phases was a discretionary decision for the judge. Now, parties have a statutory right to demand bifurcation, with exceptions for cases where the amount in controversy is under $150,000 and cases alleging injuries from sexual offenses. Bifurcation matters because it prevents a jury from hearing the full emotional weight of a catastrophic-injury damages presentation before it has decided whether the defendant is liable at all, which reform advocates argue suppresses the anchoring that drives nuclear verdicts.
The reforms to negligent security and the related "phantom damages" provisions apply to causes of action arising after the April 21, 2025 effective date, while other procedural changes applied immediately to pending cases. The practical effect for property owners operating in Georgia, and increasingly in states watching Georgia's model, is that the documentary record of owner knowledge has become more central than ever. The 500-yard rule and the actual-knowledge requirement reward owners who can show precisely what they knew and when, which is exactly the kind of timestamped, logged record a modern detection system produces.
The four Timberwalk factors, as a plaintiff's expert assembles them
Every prior-incident foreseeability analysis is built from these four evidentiary blocks. Each one is also something a security program can document on its own terms.
How close prior crimes occurred to the property. Under Georgia's 2025 rule, codified as a hard 500-yard radius tied to documented owner knowledge.
How recently and how often prior crimes occurred. A cluster of recent precursor events weighs heavily toward foreseeability.
Whether prior crimes resembled the one at issue. A history of assaults supports foreseeability of assault; property crime alone may not.
Whether the owner knew or should have known of prior crimes. This is the factor the owner's own records most directly control.
How a security program builds or rebuts the case
The decisive evidence in a negligent security trial is rarely the security budget. It is the documentary record of what the property owner knew, when the owner knew it, and what the owner did in response. Plaintiff's counsel reconstructs that record from police reports, prior incident logs, prior complaints from tenants or employees, and the property's own surveillance and dispatch history. The same documents that an owner generates to run a competent security program are the documents that get subpoenaed, and they will tell one of two stories.
The first story is the one that produces nuclear verdicts. Cameras recorded prior incidents that no one reviewed. Complaints were filed and filed away. Alarms went unverified. A pattern of precursor events accumulated in the record while the security posture stayed flat. In that fact pattern, the surveillance footage is not a defense. It is the plaintiff's exhibit demonstrating that the danger was visible and ignored, which is precisely the "publicity" and "recency and frequency" showing the Timberwalk factors call for. A property with hundreds of recording cameras and no system to act on what they capture has built an evidentiary record of awareness without response.
The second story is the one that supports a defense. The owner can show a documented program of monitoring, a log of detected precursor events, a record of escalation and response to each one, and a security posture that demonstrably scaled with the property's risk environment. In jurisdictions applying the totality-of-the-circumstances test, this record rebuts the inference that the owner was indifferent. In a Georgia case under the new actual-knowledge standard, it goes directly to what the owner knew and did. The difference between the two stories is not how many cameras were installed; it is whether the system converted observation into documented action.
This is the structural problem with passive surveillance. A conventional camera network is a recording system. It captures footage that becomes forensic evidence after an incident, and in litigation that evidence frequently cuts against the owner because it shows the precursor events without showing any response to them. The Mackworth attention-degradation research, replicated extensively in video-monitoring studies, established that human operators watching static monitors lose detection accuracy within roughly 20 to 30 minutes, which means that in practice most recorded footage is never observed in real time. The record exists; the awareness does not. Negligent security law does not credit the distinction. If the information was capturable and the owner had the means to act, the failure to act is what the jury weighs.
Where negligent security risk concentrates by property type
Negligent security exposure is not evenly distributed. It concentrates in property types where the public is invited in, where the physical environment creates isolation or concealment, and where prior-incident histories are easiest for a plaintiff to assemble. A property-level risk assessment should be calibrated to the specific exposure profile of the asset class.
Multifamily Housing
Apartment complexes are the archetypal negligent security defendant. Tenants are invitees with a long-term relationship to the property, common areas (parking lots, stairwells, laundry rooms, mail rooms) create isolation, and tenant complaints generate a documented knowledge trail. Timberwalk itself was an apartment case. The multifamily sector playbook covers the asset-class detail.
Parking Facilities & Garages
Structured garages and surface lots combine low lighting, limited sightlines, concealment behind vehicles and columns, and predictable occupancy patterns at shift change. They are the highest-frequency setting for the catastrophic parking-lot assault verdicts that anchor premises-liability nuclear awards. Exterior and perimeter detection is the relevant layer here.
Hospitality & Lodging
Hotels owe a heightened duty to guests and face concentrated exposure around assaults in rooms, corridors, and pool and parking areas. Search data and verdict surveys both show hotel third-party-crime cases routinely settling in the seven figures. The hospitality sector playbook details the duty landscape.
Retail & Mixed-Use
Shopping centers and standalone retail invite the public in large volumes and own large exterior footprints. Ann M. was a shopping-center case. Parking-area assaults, after-hours intrusion, and loss-prevention confrontations drive the exposure, and the prior-incident history of a high-traffic retail site is rarely empty.
Bars, Nightclubs & Entertainment
Venues serving alcohol to crowds at night carry elevated foreseeability almost by definition, because intoxication and density make altercations predictable. Courts frequently find the totality of circumstances supports a duty even without a long prior-incident list, given the inherent risk profile.
Healthcare Campuses
Hospitals combine 24-hour public access, emotionally charged environments, large exterior grounds, and a workforce with its own injury-claim exposure. Negligent security and workplace-violence liability converge here. The healthcare workplace violence playbook treats the convergence in depth.
Where AI detection fits in the foreseeability record
AI-assisted detection does not change the law of negligent security, and no technology eliminates premises liability. What it changes is the quality of the contemporaneous record an owner can produce, and that record is what the foreseeability standards are applied to. The connection between the doctrine and the technology runs through a single idea: the same precursor events that build a plaintiff's foreseeability case (trespass, loitering, after-hours intrusion, a weapon visible in a common area) are events a detection system can identify and timestamp in real time, generating a logged response instead of unwatched footage.
IntelliSee's platform performs object, posture, and motion-pattern detection on the feeds from a property's existing camera network. It identifies a person entering a defined restricted zone, a person loitering past a configured threshold, a drawn firearm, or a fall, and it routes an alert to designated responders in real time through the property's existing dispatch workflow. It does not perform facial recognition, does not store video, and does not compute the identity of any person it detects. For a negligent security posture, that architectural boundary is meaningful in both directions: the system strengthens the record of what the owner observed and did, without creating the biometric-identity record that would trigger a separate privacy-compliance burden under frameworks discussed in the biometric privacy compliance briefing.
The operational mechanism matters for the doctrine. Under the prior-similar-incidents and totality standards, a property that detects and logs a pattern of trespass or loitering events, and documents an escalating response to that pattern, is generating exactly the record that distinguishes a responsive owner from an indifferent one. Under Georgia's new actual-knowledge standard, the timestamped log of what was detected and when speaks directly to the statutory question. The platform connects to existing video management systems such as Milestone XProtect and Genetec, processes detection on a dedicated on-premises appliance so video never leaves the network, and can route alerts through existing consoles or via RapidSOS to first responders. The detection sits upstream of the property's existing response protocol, providing the earliest documented trigger.
IntelliSee holds DHS SAFETY Act Full Designation as a Qualified Anti-Terrorism Technology, which provides defined liability protections under the SAFETY Act if a designated act of terrorism occurs while the platform is deployed. That designation is a distinct statutory liability shield, separate from the common-law negligent security analysis, and is covered in the DHS SAFETY Act briefing. For an owner assembling a defensible security posture, the two operate in parallel: the SAFETY Act addresses terrorism-event liability, while the documented-detection record addresses the ordinary third-party-crime foreseeability inquiry that drives the large majority of premises cases.
Detection without identity, response without storage
The negligent security inquiry asks what the owner knew and did, not who the people on the property were. IntelliSee's detection layer is built to answer the first question without raising the second. It logs that a person was detected in a restricted zone at a given time and that an alert was dispatched, which is the evidence a foreseeability defense is built from. It does not identify the person, store the footage, or create a biometric profile, which is the evidence a privacy plaintiff would seek. For a risk leader, the value is that the system improves the litigation posture under negligent security law while staying clear of the surveillance-privacy exposure that facial-recognition systems introduce.
Frequently asked questions about negligent security liability
What is the difference between negligent security and general premises liability?
Premises liability is the broad body of law governing a property owner's responsibility for injuries on the premises, including slip-and-fall and unsafe-condition cases. Negligent security is the specific subset in which the injury was caused by a third party's criminal act, and the claim is that inadequate security measures failed to protect against a foreseeable crime. The defining feature of a negligent security case is the foreseeability inquiry: because there is generally no duty to protect against the criminal acts of others, the plaintiff must establish that the crime was foreseeable before any duty to provide security arises.
What is the "foreseeability" test in a negligent security case?
Foreseeability is the legal question of whether a reasonable property owner should have anticipated the criminal act and taken protective measures. U.S. jurisdictions apply one of four standards: specific imminent harm (the narrowest), prior similar incidents, the Timberwalk four-factor test (proximity, recency and frequency, similarity, and publicity of prior crimes), and totality of the circumstances (the broadest). Which standard governs a property is set by its jurisdiction and is the strongest single predictor of whether the owner will be found liable.
How did Georgia's 2025 tort reform (SB 68) change negligent security claims?
Georgia SB 68, effective April 21, 2025, codified a heightened foreseeability standard for negligent security at O.C.G.A. §§ 51-3-50 through 51-3-57. It limits owner liability to situations involving actual knowledge of an imminent threat, prior substantially similar crimes on the property, prior similar crimes within 500 yards with actual knowledge, or prior conduct by the same perpetrator. It also mandates that juries apportion fault to the criminal perpetrator, with a rebuttable presumption against verdicts that assign perpetrators less fault than non-criminal parties, and it grants parties a statutory right to bifurcate liability and damages phases of trial.
Can a property owner's own security cameras be used against them in a lawsuit?
Yes. Surveillance footage and incident logs are routinely subpoenaed in negligent security litigation. When cameras recorded prior incidents that no one acted on, that footage becomes the plaintiff's evidence that the danger was known and ignored, supporting the "publicity" and "frequency" elements of foreseeability. The same records support a defense only when they show a documented pattern of detection and response. The determining factor is not how many cameras exist but whether the system converted observation into documented action.
Does installing AI detection reduce negligent security liability?
No technology eliminates premises liability, and AI detection does not change the underlying law. What it changes is the contemporaneous record an owner can produce. A detection system that identifies and timestamps precursor events such as trespass, loitering, and after-hours intrusion, and that logs an alert and response to each, generates the evidence that distinguishes a responsive owner from an indifferent one under every foreseeability standard. It improves the litigation posture by documenting awareness and action, which is precisely what the foreseeability analysis examines.
How does AI detection address privacy concerns in a negligent security context?
The negligent security inquiry turns on what an owner knew and did, not on identifying the individuals present. IntelliSee performs object, posture, and motion-pattern detection without facial recognition, video storage, or identity computation. This means the system builds the record relevant to a foreseeability defense (a person detected in a restricted zone at a specific time, with a logged alert) without creating the biometric-identity record that would raise separate privacy-compliance exposure under state biometric privacy statutes.
What property types face the highest negligent security exposure?
Exposure concentrates in property types that invite the public in, create physical isolation or concealment, and accumulate documented prior-incident histories. Multifamily housing, parking facilities and garages, hotels and lodging, retail and mixed-use centers, bars and nightclubs, and healthcare campuses carry the highest concentrations. Parking-area assaults in particular anchor many of the largest premises-liability verdicts because the combination of low lighting, limited sightlines, and predictable occupancy makes the harm comparatively foreseeable.
Continue the research
This briefing covers the legal architecture of negligent security liability and where detection fits into the evidentiary record. For deeper reading on adjacent pieces of the picture:
- Agentic AI Liability in Physical Security — who carries the risk when an autonomous system, rather than a human, decides on a response, and how that reshapes the liability allocation analyzed here.
- How Insurers Are Underwriting AI Physical Security — how carriers are pricing the same premises-liability exposure into premiums and factoring detection technology into loss-cost models.
- Security legislation tracker — the actively maintained database of state and federal physical security and liability legislation, including premises and tort-reform developments beyond Georgia.
- Perimeter control solution page — the detection modality most directly tied to the exterior and parking-area exposure that drives the largest negligent security verdicts.
To map the foreseeability and documentation exposure of a specific property portfolio, a structured risk assessment is the starting point.
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment