Vehicle Ramming Attacks: The 2026 Threat Intelligence Briefing on the 27-Attack Global Surge, Hostile Vehicle Mitigation Standards, and the AI Detection Layer Between Bollards and the Crowd
27 vehicle ramming attacks worldwide in seven months. The 2026 procurement question is no longer whether to invest in hostile vehicle mitigation, but how AI detection sits between rated bollards and the crowd.
Vehicle ramming attacks have re-entered the active threat list. The 2026 question is no longer whether to plan for them, but how AI detection sits between bollards and the crowd.
For most of the last decade, vehicle ramming sat in an uncomfortable middle position on the U.S. threat list. Frequent enough to demand contingency planning, rare enough to lose budget arguments. The seven months between November 2024 and May 2025 collapsed that ambiguity. The Mineta Transportation Institute, which has maintained a public vehicle ramming dataset since 2017, documented twenty-seven attacks worldwide in that window, including the deadliest U.S. ramming incident on record. The dataset's longer-term trendline is what should concern American security directors: since 2012, the United States has recorded more vehicle ramming attacks than any country in the world.
This briefing is for the security directors, risk officers, and procurement teams who now have to defend a budget line for hostile vehicle mitigation alongside their gun detection, perimeter intrusion, and workplace violence programs. It separates the threat profile from the detection architecture, walks through the four crash-rating standards procurement teams will encounter (ASTM F2656, PAS 68, IWA 14-1, and the ISC Risk Management Process), and explains where AI video analytics fits between bollards and the crowd, because hardware-only mitigation, as both Bourbon Street and Magdeburg have now demonstrated, is not a complete control.
The 2025 Inflection: Why Vehicle Ramming Demands a New Threat Model
The five-month span from December 2024 through May 2025 produced three distinct, geographically separated, high-casualty vehicle ramming events that together reshape the underwriting and procurement conversation. Each illustrates a different failure mode in the standing playbook.
On December 20, 2024, an SUV was driven into the Christmas market at Magdeburg, Germany, killing six and injuring 309. The vehicle traveled at least 400 meters through pedestrian zones at speeds reaching 48 km/h, according to the official chronology released by Saxony-Anhalt prosecutors. The market had perimeter controls. The vehicle entered through a designated emergency lane that had not been blocked. This is the access-route failure mode: bollard placement was correct on the primary approach, but the secondary entry point used by emergency services became the attack vector.
On January 1, 2025, at approximately 3:15 a.m. local time, a 42-year-old U.S. Army veteran drove a rented pickup truck into a crowd celebrating the new year on Bourbon Street in New Orleans, killing fourteen and injuring fifty-seven before being shot by responding officers. As the FBI's New Orleans Field Office confirmed in its public statement, the attacker drove onto the sidewalk to bypass a police vehicle and the temporary steel barricades that had been deployed at the street's main entrance. The city's permanent anti-ramming bollards, replaced and not yet operational ahead of Super Bowl LIX, were unavailable. This is the hardware-status failure mode: the engineering design was correct, the operating posture was not.
On May 26, 2025, during the open-bus victory parade for Liverpool Football Club's Premier League title, a 53-year-old driver accelerated a Ford Galaxy into spectators on Water Street, injuring 134, including children as young as six months old. The driver was eventually convicted on all thirty-one counts and sentenced to 21 years and 6 months. This is the temporary event failure mode: route protection during a non-recurring mass-gathering event where permanent infrastructure does not exist and surge-deployed barriers are sized to budget, not threat.
The pattern across the three events is the throughline that matters for procurement. None of them failed because the standards were wrong. ASTM F2656, PAS 68, and IWA 14-1 specify vehicle barrier performance with sufficient precision that a properly rated bollard, properly positioned, properly maintained, and properly active at attack time will defeat the threat vehicle. Each event failed somewhere upstream of the barrier itself.
Inside the Attack Profile: Who, What, Where, and How Long
The Mineta Transportation Institute, working from a proprietary database the Institute has maintained since 1970, published an updated analysis in 2025 that re-baselines the attacker profile in a way that has procurement implications. Mineta's longitudinal data through March 2025 documents 8,440 attacks of varied vehicle-involvement type. The narrower category that matters for hostile vehicle mitigation, attacks in which a vehicle was the primary weapon used against a crowd or building, shows a clear acceleration in OECD countries (Group 1 in Mineta's classification) over the past five years.
Three findings reshape the threat model that has dominated procurement since 2017.
First, mental disturbance, not ideology, accounts for the largest share of attackers and the largest share of fatalities in the Mineta dataset. This is a meaningful departure from the post-2014 ISIS-inspired playbook that framed earlier U.S. and European HVM investment cycles. The shift means that traditional ideological threat indicators, the kind that intelligence-led policing programs are designed to surface, are less reliable as forward warning. A grievance attack by a single individual with no extremist affiliation will produce no detectable pre-incident signature in the open-source intelligence layer.
Second, vehicle type and acquisition pattern have not meaningfully changed. Rental trucks, SUVs, and full-size pickups remain the modal vehicles. The Bourbon Street attacker used a Ford F-150 Lightning rented through a peer-to-peer car-sharing service. The Magdeburg attacker used a BMW rented through a conventional commercial channel. This is operationally significant: the vehicles are indistinguishable from legitimate traffic until the moment of attack, which means access control alone cannot screen them out. Any detection that depends on vehicle classification at the perimeter ("commercial truck" vs. "private car") will misclassify the most common attack vehicles.
Third, the attack window itself is short and asymmetric. The Magdeburg attack lasted one minute and four seconds across 400 meters. The Bourbon Street attack covered roughly three city blocks of Bourbon Street pedestrian zone before the attacker exited the vehicle and engaged law enforcement. In both cases, the kinetic phase from first entry into the pedestrian zone to last casualty was under two minutes. This is the operational window that any detection architecture must measure itself against. A response chain that begins with a human observer in a downstream control room is too slow by an order of magnitude.
Hostile Vehicle Mitigation Standards: ASTM F2656, PAS 68, IWA 14-1, and the ISC Framework
Four standards govern the engineering side of hostile vehicle mitigation, and procurement teams will see all four invoked in the specification documents they receive from vendors. Understanding what each one actually rates, and what they do not rate, prevents the most common procurement mistake: assuming a "certified bollard" means the entire installation has been validated.
ASTM F2656, formally the Standard Test Method for Crash Testing of Vehicle Security Barriers, is the dominant U.S. specification. The rating string carries two pieces of information: the vehicle class and impact speed (for example, C730 indicates a 7,200 kg medium-duty truck at 30 mph), followed by a penetration code from P1 (one meter or less) to P4 (thirty meters or more). The standard explicitly distinguishes between "static" pass criteria (the barrier stops the vehicle) and the "dynamic" penetration distance that determines stand-off requirements behind the barrier. ASTM F3016 covers low-speed (under 30 mph) crash testing for situations where higher-rated barriers are over-engineered for the actual threat speed.
PAS 68 is the British counterpart, originated by the BSI Group, and historically the standard cited in most international specifications because of the U.K. counter-terrorism heritage of its development. A typical PAS 68 test uses a 7,500 kg truck at 48 km/h or 80 km/h, hitting the bollard head-on. PAS 68 is also more granular than F2656 about lateral debris dispersion behind the barrier, which is the second source of casualties after the vehicle itself.
IWA 14-1:2013, published by ISO as an International Workshop Agreement, harmonized the two earlier standards into a single methodology that procurement teams now see most often in cross-border specifications. A bollard rated to a given IWA 14-1 energy class has effectively been tested under PAS 68 methodology with documentation suitable for procurement teams that cannot rely on the British or American standards alone. The IWA pathway has become the de facto international currency for cooperative purchasing programs.
The DHS Interagency Security Committee Risk Management Process is the standard that determines where on the site the bollard goes and at what rating. The ISC Risk Management Process Standard, most recently updated in 2021 and available through the Whole Building Design Guide, requires a site-specific vehicle dynamics assessment to determine attainable vehicle speeds and a blast analysis to determine penetration and stand-off requirements. This is the document procurement teams should be reading before the bollard specification document, not after. The ISC framework also distinguishes between active vehicle barriers (AVBs), which retract or lower to allow authorized passage, and passive barriers, which are fixed.
| Standard | Origin | Typical Test Vehicle | Rating Format | Procurement Use |
|---|---|---|---|---|
| ASTM F2656 | U.S. (ASTM International) | 2,300 kg car to 29,500 kg heavy truck | Class + Speed + Penetration (e.g., C730 P1) | Dominant in U.S. federal and state procurement specifications |
| PAS 68 | U.K. (BSI Group) | 7,500 kg truck at 48 or 80 km/h | Vehicle type + speed + penetration + debris | Historic standard for counter-terrorism HVM in U.K. and Commonwealth markets |
| IWA 14-1:2013 | International (ISO Workshop Agreement) | Aligned to PAS 68 methodology | Energy class + penetration distance | Cross-border specifications and cooperative purchasing |
| ISC RMP | U.S. (DHS Interagency Security Committee) | Not a barrier standard; site assessment | Facility Security Level + countermeasure tailoring | Required for federal facilities; advisory for critical infrastructure |
What the rating does not tell you
A bollard certified to ASTM F2656 C730 P1 has stopped a 7,200 kg truck at 30 mph with one meter of penetration in a controlled test. It has not been tested with your soil conditions, your foundation depth, the lateral pre-load from your adjoining hardscape, or the gap configuration between adjacent bollards. The ISC Risk Management Process exists precisely because the certification is necessary but insufficient. Procurement teams that move directly from "rated barrier" to installation, without the intervening dynamics and blast analysis, often discover the gap during the post-incident review, not during commissioning.
The Bollard Gap: Why HVM Hardware Alone Is Insufficient
The Bourbon Street, Magdeburg, and Liverpool attacks reveal a structural limitation in the hardware-only model of vehicle mitigation. Each event surfaced a different version of the same underlying failure: the barrier is correct, the operating posture is not. CISA's Vehicle Incident Prevention and Mitigation Security Guide acknowledges this directly by structuring its recommendations around a "Plan-Prevent-Protect" framework rather than a pure hardware specification. The Plan and Prevent layers are where AI detection has the highest marginal return on investment, because they correspond to the windows in which a vehicle attack is detectable but not yet kinetic.
Three operating posture failures recur across the post-incident reviews of vehicle ramming events since 2017.
The first is the off-cycle hardware failure. Bollards retracted for maintenance, removed for streetscape work, or scheduled to operate on a time-based cycle that does not match the actual attack window. Bourbon Street's bollards were physically removed for upgrade ahead of Super Bowl LIX. The maintenance plan was correct in isolation. The window during which the bollards were absent had no compensating control. An AI detection layer would not have stopped the truck, but it would have shortened the dispatch interval and, in the documented incident timeline, every second between detection and first responder engagement reduced the casualty count.
The second is the alternate-route entry. Bollards positioned on primary approaches with adjacent emergency lanes, service driveways, or sidewalk transitions that were not similarly rated. Magdeburg's emergency lane is the canonical example, but the pattern recurs at U.S. event sites with surge-deployed jersey barriers. Static geometry leaves seams; intelligent perimeter detection can monitor the seams without requiring full hardware coverage at every entry point.
The third is the parked-and-deactivated vehicle. Vehicles that arrive at the perimeter before the protected event window begins, park inside the inner zone, and only become weapons when the event begins. Parking lots and structured garages adjacent to high-occupancy zones are the principal vulnerability. Our 2026 parking facilities sector playbook walks through the convergence between parking lot AI detection and pedestrian zone protection in more depth, but the principle here is that the bollard line cannot defend against a vehicle that is already inside it.
The AI Detection Layer: Behavioral Motion, Speed Anomaly, and Perimeter Convergence
AI video analytics on existing perimeter cameras provides three detection signatures that bear directly on the vehicle ramming threat model, none of which require new sensor hardware beyond the camera the facility already operates.
The first is speed anomaly detection. Vehicles moving at unusual rates of acceleration through pedestrian-adjacent zones, accelerating toward perimeter geometry, or entering pedestrian-only zones at speeds above the posted threshold. A vehicle moving at 30 mph toward a stand-off line that is designed for 5-mph approach traffic is statistically distinguishable from normal flow before the impact moment. The detection window is short, but not zero. CISA's Vehicle Ramming Self-Assessment Tool explicitly references reducing reliance on human observation for this exact scenario.
The second is trajectory deviation detection. Vehicles departing from designated roadways and entering pedestrian-only zones, sidewalks, or restricted approach lanes. This is the Bourbon Street signature: the truck mounted the sidewalk to bypass the police SUV. A camera with a tuned region-of-interest mask covering the sidewalk and pedestrian zone produces a trajectory deviation event the moment the vehicle crosses the boundary, well before it reaches the casualty zone.
The third is perimeter convergence with secondary indicators. The fusion case, where speed and trajectory anomalies coincide with other behavioral indicators (loitering vehicles repositioning before an event, repeated approach-and-retreat patterns characteristic of pre-attack reconnaissance, or perimeter intrusion at off-hours). Each indicator alone is below the alert threshold; the convergence is the trigger. Our prior reporting on the 90-second window in perimeter intrusion covers the underlying detection architecture in technical depth.
Three layers between the attacker and the crowd. None of them is sufficient alone.
Hostile Vehicle Mitigation (Hardware)
ASTM F2656 Crash-rated standoffBollards, planters, wedge barriers, and active vehicle barriers rated to ASTM F2656, PAS 68, or IWA 14-1. Sized to the facility's vehicle dynamics assessment. Stops the vehicle, contains debris, and protects the inner zone.
AI Detection (Behavioral Layer)
<30s Alert to responderSpeed anomaly, trajectory deviation, and perimeter convergence detection on existing cameras. Surfaces threat vehicles before the kinetic phase. Covers seams in the hardware layer and parked-and-deactivated vehicle scenarios.
Response Integration (Action Layer)
2-min Kinetic windowRouting to mass notification, PSAP dispatch, public-address override, and active vehicle barrier closure. Closes the gap between an alert and a control action while the attack is still in its sub-two-minute window.
The architectural point worth emphasizing is that the AI detection layer does not replace the bollard line. It is positioned upstream of the bollard line in time and downstream of it in physical geometry. Upstream in time because behavioral indicators precede impact. Downstream in physical geometry because the perimeter cameras typically already exist inside the bollard line and inside the property line. The two layers cover different failure modes and exhibit very different cost-of-failure curves. Hardware failures are categorical (the bollard either holds or it does not). Detection failures are probabilistic (the system either flags the anomaly in time, flags it late, or misses it entirely). A defensible procurement posture acknowledges both curves.
Sectoral Risk Concentration: Where the Attack Profile Hits Hardest
The Mineta dataset, the CISA Vehicle Ramming Self-Assessment Tool's recommendation logic, and the operational pattern of recent attacks together identify the sectors carrying the highest residual exposure. Three categories warrant the most attention from procurement teams.
Mass-gathering events and venues. Stadiums, arenas, parade routes, holiday markets, religious processions, and political rallies share the same architectural vulnerability: a high-density pedestrian zone with controlled but not crash-rated perimeter, often defended with temporary jersey barriers or surge-deployed assets that have not been engineered to the same rating as permanent infrastructure. Our stadiums and mass-gathering venues sector playbook covers the convergent AI detection profile in operational depth.
Critical infrastructure perimeters. Electric substations, water treatment plants, telecom switching centers, and chemical facilities are the second-most-targeted category in the Mineta dataset across the past decade. The threat profile is different (deliberate attack on infrastructure rather than mass casualty), but the detection requirements overlap heavily with the mass-gathering case. Our 2026 sector playbook on critical infrastructure and electric utilities documents the additional NERC CIP-014 implications that compound the standard ISC framework.
Houses of worship and religious gatherings. The targeting profile here is asymmetric: low-frequency attacks with extremely high consequence and very limited budget capacity. Our houses of worship sector playbook covers the FEMA Nonprofit Security Grant Program (NSGP) eligibility, which is now the primary funding vehicle for HVM and detection installation in this category.
A fourth category, public buildings and government facilities, sits inside the ISC framework directly and has the most mature procurement architecture, but also the lowest tolerance for residual risk. The 2026 government and public buildings playbook documents the Facility Security Level (FSL) cascade and the corresponding ISC tailoring. For the active-assailant adjacency, where the vehicle attack converges with a coordinated kinetic event, the 2026 active assailant threat intelligence briefing covers the convergent detection profile.
The 2026 Procurement Question: Building a Defensible HVM + Detection Stack
The procurement question that follows from the threat profile and the standards landscape is, in practice, a question about how to specify and validate a two-layer stack: rated hardware plus AI detection. The CISA framework, the ISC Risk Management Process, and the post-incident reviews from the December 2024 through May 2025 events together imply a sequence that has been borne out in multiple federal and state procurements over the past eighteen months.
The first procurement step is the vehicle dynamics assessment. This is a site-specific engineering analysis that determines attainable vehicle approach speeds across every credible entry vector. Stand-off requirements, barrier rating selection, and detection camera placement all depend on the output. ISC requires this analysis for federal facilities; critical infrastructure operators and large mass-gathering venues benefit from following the same methodology even where it is not formally required. The output is a defensible record for board, insurer, and grant-program reviewers that the subsequent procurement decisions were grounded in the actual threat geometry of the site.
The second step is the barrier specification with crash-rated certification. ASTM F2656, PAS 68, or IWA 14-1 ratings, sized to the dynamics assessment output. Active vehicle barriers (wedge barriers, retractable bollards) for entries that require authorized passage; passive bollards or planters for fixed standoff. The specification should reference both the static stop criterion and the dynamic penetration distance, because the latter determines the survivable inner zone behind the barrier.
The third step is the AI detection layer specification. This is where most procurement teams under-specify, because the standards landscape is less mature for detection than for hardware. A defensible specification covers four properties: detection latency from event to alert (under thirty seconds is the operational floor), detection modalities supported (speed anomaly, trajectory deviation, perimeter convergence, parked-and-deactivated vehicle classification), privacy architecture (no facial recognition, no biometric collection, no video retention beyond the customer's defined policy), and integration surface (mass notification, PSAP dispatch, active vehicle barrier control). Our 2026 procurement and proof-of-concept methodology covers the proof-of-concept architecture in technical depth and applies directly to vehicle detection POCs.
The fourth step is the response integration plan. Speed anomaly detection that does not feed mass notification within seconds is a logged event, not a control. The plan should document who receives the alert, what the receiving system can do with it (lock down a public-address override, close an active vehicle barrier, dispatch a PSAP request), and what the fallback is if the primary channel fails. The detection-to-lockdown architecture briefing in our standards-compliance stream covers the integration patterns that recur across customer deployments.
The fifth step is the governance documentation. The NIST AI Risk Management Framework, the EU AI Act if the deployment is in scope, and the ISC tailoring documentation if the site is federal. Our NIST AI RMF briefing for physical security AI documents the documentation architecture procurement teams now expect to receive from vendors.
Why carriers are increasingly asking about the detection layer
Casualty insurance underwriters and excess liability carriers have begun requesting hostile vehicle mitigation documentation as part of standard renewal questionnaires for venues, houses of worship, and mass-gathering operators since the New Orleans attack. The question being asked is no longer "do you have bollards"; it is "what is your time from a vehicle anomaly to a control action." Detection-layer documentation, including alert latency, response routing, and post-incident review records, is increasingly material to the premium calculation. The trend mirrors the post-2018 trajectory of cyber underwriting, where MFA and EDR coverage became premium-impacting controls within three renewal cycles.
What This Means For Your 2026 Program
For security directors, risk officers, and procurement teams, the practical implication of the 2025 inflection is that the budget conversation has moved. The question is no longer whether vehicle ramming warrants HVM investment. The Mineta data, the CISA guidance, and the underwriting market have settled that. The question now is whether the program is structured as a two-layer stack with the hardware layer rated and the detection layer specified, or as a single-layer hardware investment that the post-incident review will identify as necessary but insufficient.
Three near-term moves typically pay back fastest. First, request a site-specific vehicle dynamics assessment from a qualified engineering firm if one is not already on file from the past five years. Site conditions and traffic patterns drift; the assessment is a current document or it is not useful. Second, audit existing perimeter cameras for coverage of speed-anomaly and trajectory-deviation zones. The cameras typically already exist; the question is whether the AI layer can be added without ripping and replacing the camera infrastructure. Most facilities discover the answer is yes once they walk the site with a vendor that supports ONVIF/RTSP integration. Our retrofit architecture briefing documents the integration economics. Third, document the response integration plan. This is the cheapest step and the one most often left for later; it is also the step that turns a logged alert into a control action and, by extension, into a reduction in expected loss cost.
Frequently Asked Questions
Continue the research
- Perimeter Intrusion: The 90-Second Window That Defines Your Security Posture
- Parking Facilities, Campus Lots, and Structured Garages: The 2026 AI Physical Security Sector Playbook
- Stadiums, Arenas, and Mass-Gathering Venues: The 2026 AI Physical Security Sector Playbook
- How IntelliSee detection works on existing IP cameras
- Industries protected by IntelliSee AI detection
- Request a site-specific risk assessment for your facility
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Site-Specific Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment