Abstract topographic contour field in dark tones, with select elevation lines picked out in blue.
← Resources
article·

Drones and the Advance: What a Protection Team Can Legally Do

The SAFER SKIES Act redrew who can counter drones. What a protective team can legally detect, what stays off-limits, and how to plan the air layer.

By Arcline Team

A private protective team can legally detect, identify, and track a drone near its principal. It cannot legally jam it, hack it, seize control of it, or bring it down. That line did not move when the SAFER SKIES Act became law. What moved is who else can now act, and a well-run advance accounts for both sides of that equation.

Airspace is part of the advance now, the same way the loading dock and the ingress route are. A drone over the venue during arrival is a surveillance problem, a disruption problem, and occasionally a weapons problem. The team standing on the X has to know, before the motorcade rolls, exactly what it is allowed to do about one. Most of the trouble in this space comes from teams that either ignore the air layer entirely or assume they can act against it.

This is not legal advice — it's planning craft. Get counsel involved before you buy or deploy anything that emits.

What the SAFER SKIES Act actually changed

The short version: it deputized state and local law enforcement into counter-UAS — not you. The SAFER SKIES Act passed as part of the FY2026 NDAA (Pub. L. 119-60), signed December 18, 2025, and is codified at 6 U.S.C. § 124n. The implementing DOJ/DHS interim final rule took effect July 1, 2026 (91 FR 41466).

The rule authorizes state, local, tribal, and territorial law enforcement and correctional agencies under two certification tiers:

  • Detection and Warning Certification, completed through online training. Certified units may detect, identify, monitor, and track UAS, intercept the drone's control communications, and warn the operator.
  • Mitigation Certification requires resident instruction at the FBI's National Counter-UAS Training Center. Certified units may disrupt, disable, or seize control of a drone, or use reasonable force against it, when it presents a credible threat — subject to authorized-technology lists, FAA and FCC coordination, credible-threat documentation, and 48-hour reporting.

What the rule explicitly does not do: authorize private security to mitigate. Private contractors may design, manufacture, install, and maintain counter-UAS systems. They may not operate mitigation. The rule says so directly, and there is no workaround in it.

Where the line sits for a private team

For private parties, drone mitigation remains federally criminal. The SAFER SKIES Act changed nothing here:

  • 18 U.S.C. § 32 (destruction of aircraft). A drone is an aircraft under federal law. Downing one implicates the same statute as downing a Cessna.
  • 49 U.S.C. § 46502 (aircraft piracy). Taking control of a drone in flight.
  • 18 U.S.C. § 1030 (computer fraud). Hacking the drone or its controller.
  • The Wiretap Act, ECPA, and pen-register statutes. Intercepting the operator's communications, including control-link content.
  • 47 U.S.C. § 301 and the Communications Act. Jamming and spoofing put you in front of the FCC, not just the DOJ.
If it emits, seizes, or downs — it is not your call. If it observes, receives, and records, it probably is. When in doubt, treat the action as mitigation and stand down.

Detection is the lawful lane. Private detection that doesn't require statutory relief remains legal under existing law: visual observation, receiving Remote ID broadcasts (the drone is transmitting its identity to anyone who listens), and passive RF detection that doesn't capture communications content. The caution flag sits on anything that intercepts comms. That is ECPA and pen-register territory, and it is exactly where counsel needs to look before you sign a purchase order.

The detection posture a private team can run

Layer it, and keep every layer passive. One way we've seen teams structure it (adapt to your operation, your budget, and your jurisdiction):

  • Eyes. A dedicated air-watch assignment during arrivals, departures, and outdoor exposure windows. Low-tech, legally clean, and it catches the hand-launched quadcopter that no sensor was pointed at.
  • Remote ID receipt. Commodity apps and receivers pick up the broadcast most drones are now required to transmit: position, altitude, operator location. You are picking up a signal the drone is required to send, and nothing is being intercepted.
  • Passive RF detection. Sensors that characterize drone activity without capturing communications content. This is the layer where procurement diligence matters — vendors blur the line between passive detection and interception, and the two sit on opposite sides of federal law.

What this posture buys you is time and documentation: early warning that something is up, a track history, and an operator location to hand to responding officers.

Airspace context belongs in the venue assessment

Before you think about hostile drones, know what the sky over the venue already is. Is the site under controlled airspace? Is there a standing flight restriction? Stadiums and certain venues carry them on event days. Is a TFR active or likely for the movement window, especially around VIP travel? Each answer changes both the threat picture and the response picture: a drone inside a TFR is already an FAA problem the moment it launches, which strengthens the hand-off to law enforcement.

This work slots into the physical assessment phase of the advance, the same pass where you walk the site lines and choke points. If you're deciding how deep that assessment goes, the distinction in site survey versus advance survey applies to the air layer too: a survey notes the airspace; an advance plans against it.

The escalation path: document, report, hand off

A private team's counter-UAS play is a hand-off, and the advance decides how fast that hand-off happens. The practical effect of the interim final rule is that your local PD may now hold real counter-UAS authority — detection tier, mitigation tier, or none. Find out which one during the advance; the incident is a bad time to learn it.

The path itself is short: detect and track through your passive layers, document (time, track, altitude, behavior, Remote ID data, operator location if broadcast, video), report to the coordination contact you established in the advance, and hand off. If the responding agency holds mitigation certification, they can act. If they don't, they can still enforce operator-side violations on the ground: reckless operation, TFR breach, state harassment and surveillance statutes.

Questions worth asking the venue and local agencies during the advance:

  • Does the venue have an existing drone detection capability, and who monitors it?
  • Has the venue had drone incidents? What happened?
  • Does the local agency have a certified counter-UAS unit? Detection tier or mitigation?
  • Who is the on-shift contact for a drone report during the movement window, and what do they need from you to act?
  • Are any flight restrictions active or expected for the date?

Putting the air layer in the brief

The air layer earns a short, standing block in the advance brief, under the same discipline that governs the rest of the security advance: airspace context for the site, detection posture and who owns the air-watch, the legal line stated plainly (detect and document — no interference), the LE hand-off contact and what they're certified to do, and the trigger conditions for moving the principal rather than waiting on the sky to resolve.

The executing team plans its own mission, and the agents on the ground own the call when a drone forces a route or timing change. The advance's job is to make sure that call gets made with the airspace already understood, the legal line already drawn, and the phone number of someone with actual authority sitting in the plan.