Transit, Rail, and Aviation: The 2026 AI Physical Security Sector Playbook for Surface and Air Transportation Operators
Home / Intelligence / Transit, Rail, and Aviation: The 2026...
Sector Playbooks

Transit, Rail, and Aviation: The 2026 AI Physical Security Sector Playbook for Surface and Air Transportation Operators

Transit, rail, and aviation security has crossed a structural threshold. Three numbers define the 2026 buying environment for surface- and air-transportation operators evaluating AI-enabled detection.

Published May 2026
Read Time 16 min read
Stream Sector Playbooks
492
Major transit safety/security events reported in 2023 (FTA NTD)
61%
TSA surface inspections with corrective findings (GAO-24-106366)
$1.4B
FTA capital authority obligated for safety, security, and emergency preparedness in FFY2024

Transit, rail, and aviation security has crossed a structural threshold. Three numbers define the 2026 buying environment for surface- and air-transportation operators.

492
Major transit-system safety and security events reported across U.S. agencies in 2023, the most recent FTA National Transit Database reporting year (Federal Transit Administration, 2024).
61%
Of TSA Surface Transportation Security Inspectors’ FY2024 inspections cited at least one finding requiring corrective action under the post-2021 pipeline and rail security directives (TSA SD-1580/82-2022 series; GAO-24-106366).
$1.4B
FTA capital authority obligated for safety, security, and emergency preparedness eligible activities in FFY2024 under the Bipartisan Infrastructure Law’s Section 5307 and Section 5337 programs (FTA, 2024).

Transit operators, Class I and commuter rail systems, port authorities, and airport security directors are buying physical-security AI under a different procurement calculus than they did before 2022. The federal posture has changed (TSA Security Directives 1580/82-2022, FTA Public Transportation Agency Safety Plan rule expansion, and the new TSA cybersecurity rules for higher-risk transit). Workforce-violence rates inside the sector have climbed (BLS Survey of Occupational Injuries and Illnesses showed transit and ground-passenger transportation workers experienced injury rates from violence and other intentional acts that exceeded the all-industry average in 2023). And insurance carriers underwriting agencies and authorities are pricing transit risk distinctly from general commercial property because of the convergent loss profile: assault, vandalism, suicide-by-train, perimeter intrusion, and the political risk of a high-profile incident on rolling stock or in a terminal.

The shift from passive recording to AI-augmented detection is no longer an exploratory technology bet for this sector. It is becoming the operating expectation, and the federal funding apparatus has begun reflecting that. This sector playbook lays out the threat surface, the regulatory landscape, the funding pathways, the technology selection criteria specific to surface and air transportation, and the failure modes that distinguish a serious deployment from a procurement-theater purchase.

The transit and aviation threat surface in 2026

Transit and aviation security operates at the intersection of three risk classes that almost no other sector combines: high-density public exposure, complex physical perimeters, and a workforce that interacts directly with strangers under operational time pressure. The threat surface that follows from those three conditions is broader than the active-shooter scenario that dominates board conversations.

The Bureau of Transportation Statistics’ National Transportation Statistics data and the FTA’s National Transit Database publish the only consolidated federal numbers on transit incidents. Their 2023 reporting shows an overall transit safety and security event count that has trended upward since pre-pandemic baselines, with the largest absolute increase concentrated in fixed-route bus and heavy-rail modes. The U.S. Government Accountability Office’s 2024 review of TSA surface-transportation oversight (GAO-24-106366) found that more than three in five Surface Transportation Security Inspector visits in FY2024 produced at least one finding warranting corrective action, with the most common deficiencies clustered around access control, employee security training, and security-incident reporting.

What the federal data does not yet capture cleanly is the combined operational impact of three simultaneously rising threat classes:

  • Operator-directed assault. The Bureau of Labor Statistics’ 2023 Survey of Occupational Injuries and Illnesses showed transit and ground-passenger transportation workers experiencing injuries from violence and other intentional acts at rates above the all-private-industry average, with bus operators and station agents bearing the heaviest exposure.
  • Right-of-way and roadway-intrusion fatalities. FRA Office of Safety statistics through 2024 continued to track several hundred trespasser and grade-crossing fatalities annually on the U.S. rail network, with detection windows often measured in single-digit seconds before train arrival.
  • Perimeter intrusion at airports and intermodal facilities. The FAA Airports Office and DHS reporting on airport perimeter incursions over the past decade shows a sustained trickle of unauthorized vehicle and pedestrian intrusions at Class I airports, several of which have produced runway closures or near-collision events documented in NTSB reports.

None of these three classes is solved by recording-only video. They are solved by detection that is fast enough to compress the reaction window, accurate enough to avoid the alert-fatigue spiral, and interoperable enough to actually move information from camera to dispatcher to responding officer to public-address system in real time. That is the technology bar this playbook is addressed to.

Why the federal posture changed after 2021

The Transportation Security Administration’s 2022 surface-transportation Security Directives (the SD-1580/82 series, repeatedly extended through 2024 and 2025) marked the first time TSA imposed binding cybersecurity and security-incident reporting obligations on higher-risk freight rail, passenger rail, and pipeline operators. The same regulatory wave produced the FTA’s Public Transportation Agency Safety Plan (PTASP) rule expansion in 2024, which tightened safety-management-system requirements on every transit recipient of federal funding above the small-operator threshold and added explicit assault-and-harassment risk-mitigation expectations.

The practical effect on transit and rail security buyers is this. Where pre-2021 procurement decisions could be justified on insurance-and-liability logic alone, post-2021 decisions are increasingly framed against an explicit federal safety-management-plan obligation that auditors will read. Buyers who cannot tie a security-technology investment to a documented hazard in the agency safety plan are now exposed during the next FTA Triennial Review or TSA inspection cycle. AI-enabled detection is becoming a credible mitigation entry on those plans precisely because the technology now produces auditable evidence: timestamped detections, response-time logs, false-positive rates, and integration records with dispatch.

Regulatory Reading

The PTASP expansion and what it actually requires

The FTA’s Public Transportation Agency Safety Plan regulation, originally codified at 49 CFR Part 673 and expanded in 2024 to cover assault and harassment, requires covered transit agencies to identify safety hazards, assess and mitigate them, and maintain documented evidence of effectiveness. The expansion specifically requires that agency safety plans address risks of assault on transit workers, with mitigation strategies and a documented review cycle. AI-augmented detection of weapons, fights, and unauthorized access becomes a defensible mitigation entry on a PTASP, but only if the agency can produce audit-quality evidence the system is in service, monitored, and producing actionable alerts during the operating period.

Buyers should expect the next iteration of FTA Triennial Reviews to ask for that evidence directly. A camera that records video without producing detections does not satisfy the documentation expectation. A detection platform that produces logs and integrates with dispatch does.

The detection-to-response window in transit environments

The defining variable in transit security is the time between a threat being observable and a responder being able to act on it. That window is shorter on transit than in almost any other operating environment. A train arrives at a platform every two to four minutes during peak service. A bus is at a stop for fifteen to thirty seconds. A passenger crosses an airport sterile-area boundary in fractions of a second. The detection technology either compresses inside that window or it does not matter.

This is the section where IntelliSee’s computer-vision platform earns its placement in the playbook, but the operational claim has to be made carefully. The platform does not collect facial-recognition data, does not store video, and does not retain personally identifiable images of riders or workers. What it does is run inference on existing camera feeds, classify objects and behaviors of safety interest (firearms, falls, fights, unauthorized perimeter crossings, weapons of opportunity), and push structured alerts to dispatch within seconds of the precipitating event.

IntelliSee real-time computer vision detection of a person carrying a firearm with bounding box and confidence score overlay applicable to transit and aviation environments LIVE CAM-04 / EXTERIOR
Actual IntelliSee detection output. A person-carrying-firearm classification with a high-confidence bounding box from a live customer feed. In a transit or aviation context this is the frame that compresses the response window: the same classification on a station platform, an airport curbside, or a transit center concourse triggers a structured alert to dispatch within seconds, with no facial-recognition data collected, no video retained, and no PHI involved. The platform is built to surface detections, not identities.

The relevant performance variable for transit operators is end-to-end response time, measured from event onset to dispatcher acknowledgement, and the detection log that allows that time to be reconstructed for incident review. Operators who cannot reconstruct the timeline cannot improve it, and cannot defend the program in front of an auditor or a plaintiff. This is why the FTA’s safety-management-system framing matters: audit evidence is the operating currency, not marketing claims.

The five-modality transit detection pipeline

Transit environments are not a single threat surface. They are five distinct operating contexts with different geometries, camera densities, lighting profiles, and detection priorities. A platform that performs well at a bus depot will not necessarily perform well on a heavy-rail platform, and a configuration tuned for an airport curbside will struggle at a parking-structure entry. The pipeline below maps the five modalities a sector operator should evaluate before shortlisting any AI detection vendor.

The five-modality transit detection pipeline

Each modality has distinct threat priorities, camera geometry, and integration requirements. A platform must perform across all five to serve as a sector standard.

Modality 01

Bus Depots & Operating Yards

Operator-assault risk, perimeter intrusion overnight, vehicle-theft and vandalism. Detection needs: weapon, fight, unauthorized-person, vehicle-class.

Modality 02

Station Platforms & Concourses

Platform-edge intrusion, fights, weapons display, falls, suspicious-bag drop. Detection needs: PPE-free behavior classes, weapons, falls, loitering, edge-zone violation.

Modality 03

Right-of-Way & Grade Crossings

Trespasser intrusion, suicide-prevention behavioral signals, vehicle-on-rail. Detection needs: human-on-track, vehicle-on-track, prolonged-loitering near edges.

Modality 04

Airport Curbside & Terminal Approach

Vehicle dwell, unauthorized-pedestrian, weapons in pre-screening zones. Detection needs: vehicle dwell-time, weapon, crowd-density anomaly, perimeter line-cross.

Modality 05

Airfield & AOA Perimeter

Wildlife & vehicle & pedestrian intrusion, fence-line cross, unauthorized airside entry. Detection needs: thermal-tolerant person and vehicle classes, line-cross with bearing, dwell.

Operators should treat any vendor unable to demonstrate substantiated performance across all five modalities as a single-modality specialist. That is not a disqualifier in every case. A platform-edge specialist can be a defensible buy for a heavy-rail authority. But it does not function as the standard-of-care system for an integrated agency that operates buses, light rail, heavy rail, and a regional terminal.

Federal funding pathways for transit and aviation security in 2026

The funding environment for this sector is unusually favorable for AI-enabled physical-security investment because three concurrent federal authorities allow security technology as eligible expense. Buyers who do not understand all three are leaving money on the table.

The Federal Transit Administration’s formula programs (Section 5307 Urbanized Area Formula Grants and Section 5337 State of Good Repair) explicitly make safety, security, and emergency preparedness an eligible activity, and operators may dedicate up to one percent of 5307 apportionments specifically to security projects. Section 5339 Bus and Bus Facilities Grants similarly permit security-related capital investment. Together these formula authorities obligated approximately $1.4 billion across security-eligible activities in FFY2024 across all uses, with security-specific discretion available at the agency level.

The DHS Transit Security Grant Program, restored at appropriated levels in recent fiscal years, provides direct security-project funding to high-risk transit agencies under the Urban Areas Security Initiative framework. The TSGP funds operational packages, training, and detection-system capital expense, with prioritization scoring that explicitly rewards anti-terrorism and active-shooter mitigation projects.

The Federal Aviation Administration’s Airport Improvement Program and the BIL’s Airport Terminal Program fund landside and terminal improvements that include security technology when justified through the airport’s capital improvement plan and approved Part 139 security plan. Airports of Class I size and above are also eligible to apply for Airport Infrastructure Grants under BIL discretionary authority.

Operators preparing capital cases for AI-enabled detection should map proposed equipment to the eligible-expense category on each authority before drafting the procurement document. The funding is available, but it will not survive a federal review if the project narrative does not tie to a specific authority and a documented safety-plan hazard. For deeper coverage of grant strategy and source-of-funds matching, see the IntelliSee Intelligence brief on federal and state grant funding for AI physical security.

The vendor landscape: what surface and air operators should evaluate

Vendor evaluation in this sector splits along five axes that operators should weigh explicitly. The market includes a mix of perimeter specialists, weapon-detection specialists, behavioral-analytics specialists, and integrated platforms. None of those categories is wrong on its own, but the vendor selection should follow the threat-surface map, not the marketing pitch.

Capability axisWhat sector operators should requireCommon procurement failure mode
Modality coveragePerformance evidence across the five transit modalities (depot, platform, right-of-way, terminal approach, airside perimeter), with sample detection logs from comparable deployments.Buying a single-modality specialist (e.g., gun detection only) and discovering platform-edge, fall, and perimeter incidents are uncovered.
Camera-stack interoperabilityVendor-agnostic ingest from existing IP cameras, VMS systems (Milestone, Genetec, Avigilon, etc.), and adherence to ONVIF profiles. No forced rip-and-replace of capital camera plant.Specifying a system that requires proprietary cameras, which kills capital-plan ROI and creates lock-in risk for the agency.
Privacy postureNo facial recognition, no stored video, no biometric retention, no PHI collection. Documented retention policies aligned with FTA, TSA, and agency-policy requirements.Selecting a face-recognition-bundled platform that triggers Section 1798 (CCPA), state biometric-information laws, or transit-agency board policy concerns.
Dispatch & mass-notification integrationReal-time alerting into agency CAD/RMS, Singlewire/InformaCast, RapidSOS, or PA/IPAW systems with documented response-time logs.Deploying a detection system that produces alerts no one acts on, because integration with dispatch was scoped out of the project.
Audit-quality evidenceTimestamped detection logs, false-positive review queue, response-time reconstruction, and integration with the agency’s safety-management-system documentation.Procuring a system that cannot produce evidence sufficient for an FTA Triennial Review, TSA inspection, or post-incident investigation.

Buyers should ask each shortlisted vendor for at least one peer-comparable customer reference and the redacted incident-review logs from a recent deployment. Vendors who cannot produce either are signaling either thin deployment experience or an inability to support the agency through an audit, both of which are disqualifying for a sector standard-of-care purchase. For a deeper market-landscape analysis on the weapon-detection sub-segment specifically, see the 2026 AI Weapon Detection Market Landscape and Buyer’s Guide.

The five-mode operating context: what to deploy where

Bus and motorcoach operations

Operator-assault and depot perimeter are the dominant exposures. AI detection on yard cameras compresses the response window for after-hours intrusion and vehicle vandalism. Onboard systems are out of scope for most fleet operators in 2026; the depot is where the AI investment pays.

Light rail and streetcar

Platform-edge intrusion and fights are the dominant exposures. Stationary-camera AI on platform feeds compresses detection of edge violations, fights, and weapons brandishing. Operator-cab integration is rarely the entry point.

Heavy rail and commuter rail

Right-of-way trespass and grade-crossing intrusion drive the FRA-side risk profile, and platform behavior drives the FTA-side. Different cameras serve different purposes; operators should not assume one detection configuration covers both.

Class I and II airports

Curbside-vehicle dwell and perimeter intrusion dominate. AI-enabled video analytics layered over existing CCTV is the credible path because the airport’s capital camera plant is too valuable to replace. AOA perimeter requires a thermal-tolerant detection class.

Port authorities and intermodal facilities

Layered exposure: perimeter, vehicle access, container-yard fence-line, and worker-assault. Detection priorities should be sequenced against the FMEA conducted under the agency’s safety-management-system process, not against vendor pitch order.

Transit-adjacent properties (TODs and stations under shared management)

Cross-jurisdictional. Detection responsibility split between transit-agency police, contracted security, and adjacent-property owners. Expect data-sharing-agreement complexity to be the primary deployment friction, not technology.

Workforce-violence economics in the sector

The Bureau of Labor Statistics’ 2023 Survey of Occupational Injuries and Illnesses showed that bus drivers, transit and intercity passenger transport workers, and station agents experienced violence-and-other-intentional-acts injury rates exceeding the all-industry private-sector average. Workers’ compensation loss costs in transit are correspondingly elevated, and at least one major commercial carrier has segmented transit-and-ground-passenger as a distinct underwriting class because the loss profile diverges from general fleet risk. The economic case for investing in detection technology is not only the avoided incident; it is the avoided indemnity, lost-time, and rehabilitation cost on the workers’-compensation side.

1.5x

Transit and ground-passenger transportation worker injury rate from violence vs. private-sector average, 2023

Source: BLS Survey of Occupational Injuries and Illnesses, 2023.

~700

Trespasser fatalities reported on U.S. railroads each year through 2024

Source: FRA Office of Safety annual statistics.

$1.4B

FTA capital authority obligated for safety, security, and emergency preparedness eligible activities in FFY2024

Source: Federal Transit Administration, 2024.

Operators presenting an AI-detection capital case to a board should compute the avoided loss alongside the federal-funding-match the project unlocks. Treating AI detection as a pure capital expense and not as a workers’-compensation loss-cost-compression instrument understates its return. For the analytical framework on translating loss-cost compression into expected ROI, see the IntelliSee Intelligence analysis on workers’ compensation economics and AI physical security, and on the broader four-variable buying calculus, see the Four-Variable ROI Framework for AI Physical Security.

Privacy, civil liberties, and the political risk of transit AI

Transit-agency boards, advocacy groups, and state attorneys general have all flagged AI surveillance in public transit as a civil-liberties question. Several state attorneys general have published guidance on biometric-data collection in transit, and at least three state legislatures introduced 2024-2025 bills specifically restricting facial-recognition use by public agencies. A buyer who imports a face-recognition-bundled detection platform into a public-agency operating environment should expect a board challenge.

The privacy-by-design posture for transit AI is well-defined: detect the threat class without identifying the person. IntelliSee’s platform implements that posture explicitly. The system runs object-classification and behavior-classification models, surfaces detections to dispatch, and does not collect, store, or transmit biometric face data, video clips, or PHI. That distinction is procurement-relevant because it removes the most common political and legal disqualifier transit boards encounter when reviewing security-AI proposals. For sector-relevant context on how privacy-by-design intersects retail and public-space deployments, see the 2026 Retail Security Sector Playbook.

Cybersecurity, TSA Security Directives, and the convergent attack surface

The 2022 TSA Security Directives (the SD-1580 and SD-82 series, with multiple revisions through 2025) imposed cybersecurity-incident reporting and minimum security-control obligations on higher-risk surface-transportation operators. The 2024 GAO review of TSA surface oversight observed that compliance was uneven and that many covered operators lacked mature program documentation. AI-enabled physical-security detection sits inside that program scope when the system runs on agency networks, integrates with operational-technology systems, or feeds dispatch.

The implication for procurement: vendors should demonstrate (a) network-architecture documentation suitable for an OT-aware security review, (b) cybersecurity-incident-response procedures aligned with the agency’s reporting obligations, and (c) evidence that the AI inference runs in a manner that does not introduce cybersecurity risk into the safety-critical operating-technology environment. Buyers should expect these conversations to be cross-functional with the agency CISO, not solely the chief safety officer or chief of police.

The procurement timeline and what to expect

Public-transit and aviation procurements move on federal and state procurement timelines, not enterprise SaaS timelines. A typical large-agency security-technology procurement runs 9 to 18 months from RFP issuance to deployment, with the FTA financial-management oversight cycle layered on top. Buyers should plan accordingly:

  • Months 0–3: Hazard identification under the agency safety plan (or PTASP); capital-improvement-plan inclusion; funding-source-mapping (Section 5307/5337/5339, TSGP, AIP, BIL discretionary).
  • Months 3–6: RFI / market scan; vendor briefings; technical-requirements drafting with input from operations, police/security, and CISO.
  • Months 6–12: RFP issuance, evaluation, vendor demonstrations, pilot scoping. For federally-funded procurements, ensure Buy America, DBE, and other federal flow-down requirements are integrated.
  • Months 12–18: Award, contract negotiation, deployment, integration with VMS and dispatch, response-time-evidence baselining.
  • Months 18–24: First post-deployment FTA Triennial Review or TSA inspection cycle. Detection logs and integration evidence should be ready for auditor review.

Agencies that compress this timeline often do so by leveraging cooperative-purchasing vehicles (Sourcewell, OMNIA Partners) where the vendor has prior cooperative contract authority, or by issuing the procurement under the agency’s existing master technology contract with a sole-source justification tied to a documented safety-plan hazard. Both pathways are legitimate but require documentation discipline.

What a successful deployment actually looks like in 2026

A successful sector deployment in 2026 has six characteristics that distinguish it from a procurement-theater purchase. First, the system covers the threat-surface map, not only the most photogenic risk. Second, it integrates with the agency’s existing camera plant rather than replacing it. Third, it produces audit-quality detection logs reviewable by FTA, TSA, and internal auditors. Fourth, it does not collect facial-recognition data, store video, or retain biometric records. Fifth, it integrates into dispatch and mass-notification (Singlewire/InformaCast, RapidSOS, agency CAD) rather than producing orphan alerts. Sixth, it produces a measurable improvement in time-to-acknowledgement for high-severity events, documented in the agency’s safety-management-system review.

Operators measuring against those six criteria should expect to find a small number of credible vendors, several technically capable but procurement-incompatible options, and a long tail of single-modality or face-recognition-bundled platforms that should be excluded early in the evaluation. The 2026 buying environment rewards discipline and audit-readiness more than any prior cycle.

Frequently asked questions

How is AI physical security different from the analytics already built into our VMS?

VMS-bundled analytics typically support motion detection, line-cross, and basic object classification at modest accuracy. Sector-grade AI detection runs deeper computer-vision models trained for specific transit-relevant behaviors (weapons, falls, fights, perimeter intrusion in complex backgrounds) with higher precision and recall, produces structured detection logs suitable for audit, and integrates with dispatch and mass-notification. The shift is from motion-pixels-changed to scene-understood-with-confidence.

Does federal funding really cover AI security technology?

Yes, on multiple authorities. FTA Section 5307 dedicates up to one percent of urbanized-area formula apportionment for security projects; Section 5337 includes safety, security, and emergency preparedness as an eligible activity; Section 5339 supports security-related capital investment in bus and bus-facility projects; and the DHS Transit Security Grant Program funds transit-specific security capital. Aviation operators can use AIP and BIL discretionary authority. The constraints are narrative-level (the project must tie to a documented hazard) and procurement-level (Buy America and DBE flow-downs apply to federally-funded purchases).

Will an AI detection deployment trigger civil-liberties or biometric-privacy concerns?

It depends entirely on the platform. A face-recognition-bundled platform deployed in a public transit setting should expect board, advocacy, and AG-office scrutiny. A privacy-by-design platform that detects threat classes without identifying persons (no facial-recognition data, no stored video, no biometric retention) avoids the most common political disqualifier. Buyers should confirm the privacy posture in writing during procurement.

How does AI detection interact with the agency Safety Plan or PTASP?

AI-enabled detection becomes a defensible mitigation entry on a Public Transportation Agency Safety Plan when the agency can document (a) the hazard the system mitigates, (b) the system is in service and monitored, and (c) the response time and incident-review log evidence supports the mitigation claim during the Triennial Review or internal audit. The SMS framing matters for both procurement justification and audit defense.

What about onboard cameras on buses and trains?

Onboard AI is technically feasible but operationally complex in 2026 because of camera-resolution variability, vibration, lighting changes, and the cybersecurity scope expansion that comes with running inference on rolling stock. Most transit operators in 2026 should treat onboard AI as a phase-2 investment after stationary deployment matures. Bus depots, station platforms, terminal approaches, and AOA perimeters yield faster ROI and audit evidence.

How long should a sector deployment take from RFP to operational?

For a federally-funded transit or aviation procurement, plan for 9 to 18 months from RFP issuance to operational deployment, plus another 6 months to baseline response-time evidence for the first audit cycle. Cooperative-purchasing vehicles can compress the front end. Sole-source justification under a documented safety-plan hazard is also a legitimate accelerant when the procurement code permits it.

How does this differ from active-shooter detection products marketed primarily to schools?

K-12 deployments are optimized for indoor corridor and classroom geometry with weapon and active-shooter classes as the primary detection target. Transit deployments require platform-edge, fall, fight, perimeter-intrusion, and weapon classes operating across five distinct modality contexts (depot, platform, right-of-way, terminal, airside). A K-12-specialized platform may underperform in transit modalities even when the underlying object-detection model is identical, because configuration, camera geometry, and integration requirements diverge.

Continue the research

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment