Editor's note — September 16, 2026. This article was revised to correct the citation for the mitigation notification requirement, which is § 124.11(a) — an earlier version cited § 124.12(a), which actually governs detection and warning operations; to correct an overbroad statement that detection and warning need no notification at all, when § 124.12(c) preserves advance coordination for RF-emitting systems; to note the rule's exception for technologies that do not require the Act's statutory relief; and to remove secondary-reported enforcement statistics and event claims that UAVHQ could not verify against retained primary sources. Primary citations carry Federal Register page and section locators.

The comment window on the counter-UAS interim final rule closed September 4, and the rule itself has been effective since July 1. What the government has said about the build-out's intended size is in the rule's own economic analysis: the departments "expect approximately 1,500 agencies to certify" at the detection tier within two years (91 FR 41477). Hold onto the verb — that is a projection of where the program is headed, not a count of anything deployed today, and a national projection tells you nothing certain about whether a certified agency operates near any particular flight area.

The equipment side of that build-out runs through two lists — an Authorized Technologies List of approved categories and an Authorized Systems List of specific products — and the rule describes the mechanics of populating them as an interagency process handled outside the codified regulation, with nominations submitted "via an internal process announced via the Federal C-UAS coordination portal, which houses the list" (91 FR 41472). That is the rule describing an internal process; whether any version of the lists is or will be publicly viewable is not something the rule text settles, and UAVHQ has not tested portal access. What a remote pilot can say today is narrower: the rule itself does not establish a public lookup for what a certified agency near your operation is flying, and until public availability is demonstrated, plan as though you cannot check.

If you fly commercially, for a public safety program, or for infrastructure clients, the practical question the projection raises is not whether capability will exist near your specific operations — the rule does not tell you that — but whether your flight will look legal to a sensor operator who finished an online course last month, wherever detection is in fact deployed.

What actually changed on July 1

The SAFER SKIES Act, signed December 18, 2025 as part of the FY2026 NDAA, extended counter-drone authority to state, local, tribal, and territorial law enforcement and correctional agencies for the first time. The Justice and Homeland Security interim final rule implementing it took effect July 1, 2026 and published in the Federal Register on July 6 (91 FR 41466). We covered the framework in detail when it landed: what the SAFER SKIES rule authorizes and where your lawful flight now carries mitigation exposure.

The short version is a two-tier certification structure run through the FBI's National Counter-UAS Training Center (NCUTC):

The rule carries real constraints, and their exact wording matters:

The part that should bother you: the equipment process is internal

Here is the structural situation for legal operators, stated no more strongly than the record supports. Under the rule's two-list framework, for technologies whose operation requires the legal relief the Act provides, category-level limits from the Authorized Technologies List apply at all times, and once the Authorized Systems List is populated for a category, agencies must use a listed system (91 FR 41472). The rule carves out an important exception: technologies an agency may use lawfully without that statutory relief — the rule's examples are cameras, radar, and acoustic sensors — are not subject to the list requirement at all and remain available on the same basis as before the Act, subject to existing FCC, FAA, and state and local law. The detailed mechanics of evaluating and listing the covered technologies are explicitly not codified in the rule; they run through an interagency process, and the list lives on a federal coordination portal that the rule describes agencies accessing through an internal nomination process.

The departments expect early listed categories to include radio-frequency detection that reads a drone's control link and command-injection systems that can take an aircraft over. Which specific hardware clears the bar, what it collects, and how it behaves toward a compliant aircraft is not something the rule text gives a remote pilot a way to look up, and whether the portal-housed list ever gains a public view is an open question this rulemaking has not answered.

I spent a career flying test programs where every system that could touch my aircraft was documented, and the documentation was the safety case. What is being built here is a different arrangement: a distributed sensor and effector network, operated by independent agencies at varying training levels, running hardware from a catalog whose public visibility is, at best, unsettled. From a C2 link integrity standpoint, that matters. RF detection is passive and should not affect your link. Command injection, by definition, is not. Your protection is the rule's credible-threat standard and its reporting requirements, plus the paper trail you carry — not technical transparency, because the rule text does not promise any to you.

Your preflight now includes the detection environment

These are six recommendations, not obligations the rule imposes on pilots. The risk-based logic is simple: you generally cannot verify where certified detection is deployed, so treat its possible presence the way you treat controlled airspace — assume it where the stakes warrant, plan for it, and carry proof of your legitimacy. Concrete changes worth making now:

Fly with Remote ID actually working, not just installed. The rule's framework permits agencies to use Remote ID in identifying aircraft, and whatever identification methods an agency actually uses, a broadcast module with a dead battery or a firmware fault makes your legal flight look like an anonymous track. Verify broadcast before launch, log that you verified it, and spot-check your own aircraft with a receiver app periodically.

Carry your authority and make it reachable. Waiver, COA, LAANC approval, airspace authorization, exemption conditions: have them on the device in your hand, not on a server at the office. If an officer approaches mid-mission, how fast you can produce documentation can be the difference between a short conversation and a much longer problem.

Pre-coordinate where it makes sense. For recurring operations near stadiums, prisons, critical infrastructure, or event venues, a proactive call to the local agency's UAS or special-events unit changes your status from unknown track to known operator. Being in an agency's operating picture as a cooperative actor is cheap insurance.

Check TFRs and NOTAMs at planning time and again immediately before launch, and document both checks. A TFR miss is among the cheapest ways for an otherwise lawful operator to draw enforcement attention, and a documented check is your evidence that you did the step.

Decide your seizure protocol before you need it. If your aircraft is interdicted or confiscated, your recourse runs through the rule's reporting and records provisions. Know that mitigation actions must be documented and reported within 48 hours, get the incident, agency, and officer details in writing, and call counsel before negotiating for your airframe back.

Log defensively. Flight logs, firmware versions, crew assignments, and command link records tied to timestamps are how you prove after the fact that your aircraft was where it was authorized to be, doing what it was authorized to do.

Where the record goes from here

The comment period closed September 4, 2026 (91 FR 41466 set the deadline at 11:59 p.m. Eastern). If you filed during the window we flagged in our comment-deadline briefing, your input is part of the rulemaking record. To be clear about status in the meantime: the interim final rule is in effect now — a pending final rule does not suspend it. The rulemaking questions that matter most for legal operators are whether the privacy and data-handling limits survive into the final rule, and whether the authorized-equipment process ever gains a public-facing component. The rule's own projections sketch the direction either way: detection broadly and quickly through the online tier, with resident-trained mitigation capacity growing behind it.

The operators who thrive in that environment will be the ones whose flights are boring to a sensor operator: broadcasting identity, matching an authorization, and documented end to end. If your program needs the enforcement and counter-UAS landscape distilled into working documents your crews can actually use, the UAVHQ Briefing Packs cover this terrain, and the weekly UAVHQ dispatch on Substack is where we track the final rule and the equipment-list process as they develop.

This article is operator analysis, not legal advice. Consult your own counsel on interactions with law enforcement and on your obligations under your operating authority.

Sources

  1. DOJ/DHS, "Counter-UAS Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional Agencies," Interim Final Rule, 91 FR 41466, July 6, 2026 (GovInfo PDF) — effective/comment dates at 41466; list framework and statutory-relief exception at 41472; 1,500-agency projection at 41477; 61 certified officers at 41478; § 124.11 at 41492; § 124.12 at 41493; § 124.14(d) at 41494–41495; § 124.21 sunset at 41498