Jordan Crenshaw Jordan Crenshaw
Senior Vice President, C_TEC, U.S. Chamber of Commerce

Published

August 06, 2026

Share

The U.S. Chamber of Commerce (the “Chamber”) welcomes this opportunity to comment on the Federal Aviation Administration’s (“FAA”) notice of proposed rulemaking (“NPRM”) on Designation-Restrict the Operation of Unmanned Aircraft in Close Proximity to a Fixed Site Facility (“Section 2209 Rule”).

The Chamber thanks the FAA for proposing to establish a process for the restriction of Unmanned Aircraft Systems (“UAS”) operations in the airspace in proximity of certain fixed sites and implementing Section 2209 of the FAA Extension, Safety and Security Act of 2016. The stated objectives of the NPRM align with the Chamber’s strong support for satisfying Congress’ directive in the FAA Reauthorization Act of 2024 and in other laws, supporting homeland security through protecting sensitive fixed site facilities from unauthorized drones, and advancing the Trump Administration’s deregulatory agenda and drone priorities as detailed in Executive Order 14305, Restoring American Airspace Sovereignty.  

Although the Chamber believes the Section 2209 Rule will have tremendous benefit once it is finalized and implemented, we believe important changes must be included in a Final Rule. Importantly, it must strike a balance between two imperatives: (1) effectively protecting fixed-site critical infrastructure facilities and other sensitive sites, while preserving the safety and efficiency of the National Airspace System (“NAS”); and (2) sustaining thousands of authorized UAS operations that are saving lives, inspecting infrastructure, and creating economic growth. 


The Section 2209 Rule is critical to advance homeland security and enable a process to protect against terrorism, espionage, safety hazards to ground operations, and other criminal and illicit activities, while also recognizing the immense value and benefit that authorized drone operations can provide. The use of drones in conflicts in Ukraine and across the Middle East has underscored the vulnerabilities of energy, chemical, rail, electric utility, amusement parks, data centers, and other sensitive sites to surveillance and potential attack by drones. Domestically, these are not hypothetical risks, given the number of close calls and sightings adjacent to sensitive sites including electric utility infrastructure, oil refineries, chemical facilities, and correctional facilities. Additionally, large-scale gatherings at events such as the FIFA World Cup have proven to be a public safety challenge because of hundreds of drone incursions, resulting in arrests of drone operators and confiscation of many unauthorized drones.

Due to delayed federal action, over two dozen states have enacted legislation that would establish restrictions, creating a confusing patchwork of state laws for the drone and critical infrastructure industries and hindering FAA’s oversight over the national airspace system. Finalizing and implementing the Section 2209 Rule, coupled with federal preemption of similar state, local, and tribal laws,  would help to address these issues by providing a single, nationwide program to protect critical infrastructure and other sensitive sites.

The core security concern surrounding illicit drone activity is not only the unauthorized flights themselves, but who is conducting them and why. We respectfully urge the FAA to simplify the Unmanned Aircraft Flight Restrictions (“UAFR”) application process and reconsider eligibility requirements, take steps to protect confidential and highly sensitive security information, digitize the airspace and sharing of information at scale, and consider the possible conflicts and limitations within the UAFR framework.

We further encourage the FAA to implement UAFR in a manner that protects critical facilities while accommodating authorized aviation, public safety, and FAA-approved UAS operations through risk-based and operationally feasible mechanisms.
    
I.    Standard UAFR Application Process and Eligibility Requirements

A.    Streamline the Application Process

The FAA's application and Standard UAFR maintenance requirements would create an unnecessary, burdensome process for facilities with sensitive and comprehensive security plans. In fact, unnecessarily complex application requirements could actually undermine the goal of protecting in-need facilities. The Chamber recommends streamlining application requirements and the process needed to obtain a UAFR designation.

Allowing batch applications from eligible operators with multiple fixed-site facilities and removing the environmental impact assessment in a Standard UAFR application would help expedite the Standard UAFR review process and reduce FAA’s workload. FAA should also ensure that aviation-related critical infrastructure, including airports, FAA air traffic facilities, aviation fuel infrastructure, and other facilities supporting commercial air transportation, are appropriately considered within the eligibility framework.

B.    Reconsider Eligibility Requirements

In certain sectors, the Proposed Rule determines eligibility based on sector-specific criteria and rigid numerical thresholds. The Chamber recommends adopting a risk-based, case-by-case pathway that would allow the FAA and the applicable Sector Risk Management Agency (“SRMA”) to consider facilities that present significant vulnerability and national security risk if left unprotected. For example, fixed site facilities in the energy and chemical sectors may not meet the required numerical thresholds for eligibility despite demonstrating serious risk and vulnerability to unsafe or illicit UAS operations.

II.    Protect Confidential and Sensitive Information

The NPRM requires applicants seeking a UAFR designation to submit highly detailed operational, security, infrastructure, vulnerability, and emergency response information. Even if protected from public disclosure, this information essentially creates a potential roadmap for adversaries seeking information on the nation’s critical infrastructure vulnerabilities and security plans. Even with the most robust cybersecurity and other protections against disclosure, the risk of breach remains, creating extensive vulnerabilities for the nation. Malicious actors could easily harvest and weaponize this data, using this pre-packaged intelligence to disrupt facilities, compromise public safety, or interfere with existing security operations.

We recommend establishing clear rules and standards to protect against disclosure of any proprietary or sensitive information applicants are ultimately required to submit in support of UAFR applications.

The Final Rule should clearly state a presumption that materials submitted in support of UAFR applications containing confidential business information or other non-public security-related information will be maintained confidentially, exempt from other regulatory enforcement, civil litigation, and public disclosure, as well as protected from disclosure under the Freedom of Information Act (“FOIA”) and similar public disclosure laws to the fullest extent permitted by law, including applicable exemptions protecting trade secrets and confidential commercial information, sensitive records compiled for law enforcement or that contain sensitive security information, and privileged and deliberative governmental materials.

Additionally, the Final Rule should establish clear safeguards and cybersecurity standards governing the secure submission procedures, including secure electronic transmission systems, access controls, encryption requirements, storage, handling of sensitive materials, and other cybersecurity safeguards reasonably designed to prevent unauthorized access, disclosure, alteration, or dissemination of submitted materials.

Lastly, the Final Rule should limit the information publicly disclosed by the FAA during the notice-and-comment process and in any final determination to only basic, non-sensitive information sufficient and reasonably necessary to provide meaningful public notice and comment without revealing sensitive operational or security-related details, specifically the general location, dimensions, duration, and general purpose of the proposed UAFR. Public disclosures must not include confidential or security-sensitive information regarding a site’s vulnerabilities, security measures, infrastructure limitations, or emergency response procedures where such disclosure could further increase risks to the safety and security of the applying facility.

In this context, the Chamber recommends that the FAA consider adopting safeguards modeled on the Cybersecurity & Infrastructure Security Agency’s (“CISA”) Protected Critical Infrastructure Information (“PCII”) Program , including restrictions on disclosure, dissemination, and use of information submitted in support of UAFR applications. Doing so would help ensure that applicants can provide the information necessary to support UAFR requests without creating additional cybersecurity or national security risks.

III.    Digitization of the Airspace and Information Sharing

UAS are effective due to their high degree of automation and the ability to respond to conditions based on the availability of digital information. We recommend that the Final Rule state that Standard UAFR information (including lateral boundaries and altitude ceilings) is available in an accessible, machine-readable, and standardized format that can be readily incorporated into existing aviation, airport, and UAS operational systems. This approach will avoid relying on manual processes and meet the needs of operators that depend on the availability of digital information to input into their automated systems. The Final Rule should also ensure that all Standard UAFRs are easily accessible in one integrated location and that they feed into a Notice to Air Missions (“NOTAM”) system. 


We also recommend allowing commercial operators to submit a single "standing notification" covering certain operational service areas, rather than requiring manual per-flight submissions. The FAA has already contemplated a solution that would require one-time submission of airman certificate number(s) and remote ID serial number(s) to the FAA to be “included on a developed ‘whitelist’” that would be made available to fixed-site facilities. The FAA should adopt this concept as a core operational mechanism for implementing access to UAFRs while maintaining oversight and accountability for airspace decisions. For a high-tempo commercial UAS network conducting thousands of daily flights, manually submitting flight details for every individual transit flight breaks the automation loop, introduces human error, and acts as a de facto capacity cap on the industry. For higher risk facilities where UAS mishaps, electromagnetic interference, loss of control, ignition risks, or operational disruptions could create significant safety, environmental, or cascading infrastructure consequences, a tiered approach should be implemented so commercial operators will know where individual flight notifications are required.


For day-to-day monitoring of UAS flight operations, a fixed site facility should be able to rely on broadcast or network-based Remote ID or successor technology. The remote viewing capability of network-based Remote ID will allow a fixed site facility to replace the proposed manual web portal with automated, machine-to-machine communications. This aligns with tech industry standards for data interoperability, cloud integration, and scalable software ecosystems.


The Final Rule should also require an automated notification system that utilizes a standardized and instantaneous process integrated directly with Low Altitude Authorization and Notification Capability (“LAANC”) or an equivalent system. The FAA should encourage a centralized, standardized notification architecture utilizing digital platforms and secure data exchange. Any automated notification architecture should preserve FAA authority over airspace access determinations and support coordination with affected aviation stakeholders where appropriate. The FAA's LAANC framework provides a proven model for how automated notifications and approvals can be implemented at scale. Network-based Remote ID would ultimately provide a more scalable means of identifying, authenticating, and tracking authorized operations, especially as Beyond Visual Line of Sight (“BVLOS”) operations already occurring under Parts 107 and 135, and will occur under proposed Part 108, will soon become more prevalent. The FAA should also consider leveraging emerging service-provider frameworks, including Part 146 Automated Data Service Providers, to support automated notification capabilities. The Final Rule should permit multiple compliance pathways, including: (1) flight-specific notifications; (2) standing notifications for recurring operations; (3) pre-approved or whitelisted operator programs for public safety agencies; and (4) future network-based identity and notification solutions facilitated through FAA-approved service providers.


IV.    Consider Possible Limitation of UAFRs

A. Temporary Flight Restrictions

As drafted, the NPRM prevents commercial facilities that have been granted Temporary Flight Restrictions (“TFR”) from applying for a UAFR, even if the TFR protects less than the geographic entirety of the facility. Section 74.82(e) (Commercial Facilities Sector) states that, to qualify as a fixed-site facility, a location may not also be “a stadium or venue where events may be covered by temporary flight restrictions.”  
This language unnecessarily excludes certain facilities, such as large entertainment venues that are subject to TFRs or other FAA protections, from the definition of an eligible Commercial Facilities Sector facility.  

Many qualifying venues have legitimate operational and security concerns that the FAA has already recognized through temporary, event-specific, or area-specific flight restrictions. However, because those restrictions are limited in duration, scope, or area covered, affected facilities should remain eligible to seek UAFR protections to address ongoing security risks not fully mitigated by existing FAA restrictions. For example, a TFR may protect only a portion of a facility, while other areas of the same property remain exposed to unauthorized UAS activity and could benefit from complementary UAFR protections. Facilities that require temporary flight restrictions or whose protections cover only a subset of the entire property may present some of the strongest justifications for enhanced UAFR protections due to the scale, visibility, density, or recurring nature of the security risks involved. Because TFRs are typically event-specific and time-limited, they serve a different purpose than UAFRs, which are intended to address continuing operational and security risks that exist outside discrete events or protected periods. The existence of a TFR therefore should not automatically prevent an otherwise eligible facility from seeking additional UAFR protections where FAA determines such protections are operationally justified and compatible with existing airspace management requirements.

The rule should provide greater clarity that nothing in the UAFR framework disturbs, limits, or otherwise affects existing FAA authorities, including Temporary Flight Restrictions, Special Security Instructions, or other aviation safety or security-related restrictions. The Chamber requests that the Final Rule expressly clarify that existing FAA protections do not preclude a facility from applying for or receiving a Standard or Special UAFR, that nothing in the UAFR framework disturbs, limits, or otherwise affects existing FAA operational authorities, restrictions, or approvals, and that UAFRs supplement, rather than replace, such existing authorities. The existence or availability of FAA protections should not disqualify facilities facing recurring or long-term UAS security threats from obtaining more durable UAFR protections.

B. Facility Owner Access for Drone Operations

Although facility owners do not own or control the airspace above their facilities, the Final Rule should clearly preserve the ability of facility owners, their authorized agents, and anyone with a legitimate business interest in the site (e.g. a contract party) to conduct UAS operations in support of inspection, maintenance, monitoring, security, and emergency response functions. UAFRs should enhance facility security, not impede the very drone operations that help facilities operate safely and securely.

At the same time, critical infrastructure operators should not be expected to become airspace managers. The Final Rule should minimize administrative burdens on facility operators while improving their ability to identify potentially unauthorized aircraft. The FAA should support scalable approaches such as standing notifications, recurring access arrangements, and automated mechanisms for compliant operators that routinely conduct inspection, maintenance, or security operations within or through the same Standard UAFRs.

To that end, FAA should establish a secure, facility-managed whitelist through the UAFR Module or another FAA-approved system. Once a UAFR has been designated, the operator or proprietor, acting through its designated representative or site manager, should be permitted to submit and update information identifying facility-owned, facility-operated, contracted, or otherwise facility-authorized UAS operators and aircraft.

C. Public Safety and Drone-As-First-Responder Access

The Final Rule should clarify that nothing contained in them will restrict authorized federal, state, local, and tribal public safety agencies to transit through and operate within Standard and Special UAFRs when conducting legitimate operational and select training missions while maintaining appropriate coordination with FAA requirements and applicable airspace procedures. The Final Rule should also explicitly authorize public safety operators to conduct operations within, not merely transit through, UAFRs when responding to emergencies or other time-critical incidents.

D. Expanding Eligibility for a Special UAFR

The Proposed Rule limits eligibility for Special UAFRs to federal facilities, military operations, intelligence-related operations, and certain non-federal facilities deemed to support national or homeland security. This framework does not account for the substantial public safety and security threats faced by large outdoor public venues and amusement parks, which attract dense public gatherings and present heightened vulnerability to unauthorized or malicious UAS activity.

The Proposed Rule recognizes that the purpose of the Special UAFR framework is to address heightened operational, safety, and security risks that cannot be adequately mitigated through a Standard UAFR alone. Those same vulnerabilities exist at large outdoor public venues, amusement parks, destination entertainment venues, and sports complexes that routinely host tens of thousands of guests in highly concentrated outdoor environments.

Unauthorized drone operations over these facilities present serious and escalating threats, including risks of collision with infrastructure, potential interference with public safety personnel, potential intentional acts designed to create panic or mass disruption, and the potential use of drones as weapons or delivery systems for harmful payloads. These threats are not hypothetical, and the number of security incidents caused by unauthorized drone incursions, intentional disruptions, reckless operations, and drone malfunctions that occur over densely crowded venues continue to increase nationwide.
    
The Proposed Rule also does not clearly define the threshold necessary to qualify for a Special UAFR. The Final Rule, as discussed in further detail below, should establish clear criteria focused on the elevated risks associated with large outdoor public venues and amusement parks, specifically unauthorized drone operations over large public gatherings, iconic or symbolic locations that attract heightened unauthorized or malicious UAS activity, and operational or structural conditions that increase both the likelihood and potential consequences of a mass casualty event.

The Final Rule, including Proposed §§ 74.6 and 74.66, and discussions of eligibility for Special UAFRs in the Supplemental Information sections, should expressly provide that eligible fixed-site facilities presenting heightened security or public-safety risks should be permitted to apply for a Special UAFR. We recommend the Final Rule focus on whether the applicant demonstrates that unauthorized UAS activity presents elevated risks of mass casualty events, public panic, interference with emergency response operations, or other substantial security threats. We also recommend that the Final Rule clarify that the existence of a TFR should not prevent an otherwise eligible facility from seeking Special UAFR protections. In keeping with the Proposed Rule’s intent to limit the use of Special UAFRs, we recommend that this designation be used sparingly and only in circumstances where the applicant has provided a sufficient and compelling showing of the heightened security or public-safety risks described above.

Additionally, we recommend that Section 74.6(b) (Special UAFR Designation – Characteristics) remove the requirement that a Special UAFR “must have a designated using agency.” Retaining this requirement as drafted limits Special UAFR eligibility to facilities associated with federal, military, intelligence, or other governmental operations and would effectively exclude private-sector critical infrastructure facilities that may satisfy the heightened operational and security risk standard warranting Special UAFR protections.

V.    Conclusion

The Chamber appreciates the opportunity to provide these comments and welcomes continued engagement with the FAA and the U.S. government on these important issues to ensure homeland security, preserve the safety and efficiency of the NAS, and restore American airspace sovereignty.


Sincerely,

Jordan Crenshaw
Senior Vice President
Chamber Technology Engagement Center
U.S. Chamber of Commerce
 

About the author

 Jordan Crenshaw

Jordan Crenshaw

Crenshaw is Senior Vice President of the Chamber Technology Engagement Center (C_TEC).

Read more