The legal problem with AI shark monitoring drones is not that they are useless. It is that they may be useful enough for the public to rely on, imperfect enough to miss a threat, and official enough to change the duty analysis after something goes wrong.
New South Wales has now made that problem concrete. In late June 2026, the state announced a $120 million shark mitigation program that adds 21 shark-spotting drones across 10 additional beaches, with dawn-to-dusk, 365-day coverage described as part of the expansion.[1] The same government statement also included the sentence every municipal lawyer would notice first: “no government can promise there will never be another shark incident.”[1]
That is not just cautious phrasing. It is the liability paradox in one program announcement. A public authority that once might have said it had no general duty to detect every shark near every swimmer has chosen to operate a surveillance system at scale. The stronger the public assurance around that system becomes, the harder it may be to argue later that nobody reasonably depended on it.

Premier Chris Minns has also acknowledged that expanded detection will mean more shark alarms and that the public will need to adjust.[2] Surf Life Saving NSW says the drone program has completed more than 100,000 flights and prevented more than 2,000 shark interactions in the past year.[3] Those are meaningful operational claims. They are also the kind of claims that can become exhibits: what was promised, what was measured, what was known, and what people were led to expect.
The Duty Question Starts After the Government Chooses to Watch
In a missed-threat case, the first fight would not be about whether sharks are dangerous. It would be about duty. Did the agency merely provide a public benefit within resource limits, or did it voluntarily undertake a protective service in a way that created obligations to swimmers, lifeguards, and beach users?
In U.S. tort law, the natural anchor is the voluntary-undertaking doctrine reflected in Restatement (Second) of Torts § 324A. The doctrine is commonly used when someone undertakes to render services to another and the negligent performance of that undertaking increases the risk of harm, substitutes for another protective measure, or induces reliance. A government defendant would still raise immunity defenses, statutory limits, public-duty doctrines, and causation arguments. But the plaintiff’s theory would be straightforward: once the government undertook shark surveillance, it had to perform that undertaking with reasonable care.
The same basic tension appears outside the United States, even though the doctrinal machinery differs. An Australian discussion of sharks and the law in New South Wales frames the relevant questions around public-authority obligations, reasonable care, foreseeability, and the limits of liability for government decision-making.[7] That does not mean a NSW court would treat an AI drone program like a U.S. voluntary undertaking. It means the question is not peculiar to one legal system: when a public authority creates and operates a safety intervention, courts tend to ask what the authority knew, what it controlled, what was reasonable, and whether a claimant can cross the boundary from policy disappointment into legally actionable negligence.
Sovereign immunity complicates that path. Many jurisdictions protect discretionary policy choices: whether to fund a drone program, how many beaches to cover, whether to prioritize drones over nets or tagged-shark alerts. Operational execution is different. If a protocol says a sighting must be relayed to lifeguards within a defined chain, and an operator fails to follow that chain, immunity may be less protective than it would be for the original budget decision. The exact answer depends on jurisdiction, statute, and the facts pleaded.
That distinction is why procurement documents, public statements, pilot training, escalation logs, and beach-closure protocols matter. A negligence claim after an injury would not be litigated against the slogan “AI saves lives.” It would be litigated against the actual duty chain: who reviewed the feed, who received the alert, who had authority to clear the water, what counted as a confirmed detection, and what the agency had disclosed about blind spots.
Known Imperfection Is Not Just a Technical Detail
The accuracy figures around AI shark detection should be handled with care because they do not measure the same thing. Researchers at UNSW described human drone pilots as achieving about 60% accuracy and reported an AI detector reaching 80% frame-by-frame accuracy in real conditions.[4] NVIDIA’s account of SharkEye reports 92% mean average precision after training on more than 15,000 images from one California beach.[5] Other public descriptions of shark-spotting systems have claimed performance above 90%, but those figures were produced under different conditions, on different datasets, and at different times.
Those numbers should not be lined up as if they were a clean leaderboard. A frame-by-frame result in field conditions is not the same as mean average precision from a dataset concentrated at a single beach. A 2022 figure is not necessarily the ceiling for a 2026 deployment. And a favorable test environment is not the same as a crowded holiday beach with glare, chop, turbidity, paddleboards, bait balls, and swimmers moving through the same frame.
Legally, the important point is notice. Water clarity, sea glitter, and species confusion are known failure modes. UNSW researchers have described the difficulty of distinguishing sharks from other marine life and noted that white, whaler, and bull sharks can look similar from the air.[4] Once those limits are known, they become part of the reasonableness analysis. The issue is not whether the system was perfect. The issue is whether the operator’s policies, training, disclosures, and response protocols matched what the operator knew the system could and could not do.
That is where “imperfect but useful” stops being a complete answer. It may be a sound public-safety justification for using drones. It is not, by itself, a legal defense to careless operation, overstated public messaging, or a broken chain between detection and warning.
Two Failure Paths, Two Different Liability Profiles
A false negative is the severe case: the system misses a shark, swimmers remain in the water, and someone is injured. A false positive is less dramatic but still consequential: the system identifies a shark or possible shark, officials close the beach, and businesses, workers, or beachgoers absorb the cost of a closure that later appears unnecessary.

The false-negative claim has the clearer injury profile. Bodily injury supplies damages that courts recognize readily, and a plaintiff would focus on reliance, foreseeability, and operational breach. Did the beach advertise drone surveillance? Did lifeguards rely on the feed instead of another patrol method? Was there a known blind spot? Did a detection occur but fail to reach the person with authority to clear the water? Was the system marketed as coverage when it was actually coverage subject to flight rules, weather, staffing, and visibility?
The false-positive case is harder but not imaginary. The Rockaways in New York City show the practical side of more detection. Between late May and mid-July 2026, the city recorded 23 beach closures, more than double the 11 closures at the same point in 2025; the policy described in that reporting was to close one mile in each direction for at least one hour after a sighting.[6] More eyes in the sky can mean more warnings, and more warnings can mean more disruption.
Economic claims from unnecessary closures would face obstacles. In U.S. tort law, pure economic loss rules often bar recovery where there is no physical injury or property damage. Public authorities would also argue that beach-closure decisions are discretionary public-safety judgments made under uncertainty. A shop owner who loses an afternoon of revenue after a mistaken alert is not in the same litigation posture as a swimmer who suffers physical injury after a missed alert.
Still, false positives belong in the risk analysis. They affect public trust, emergency compliance, lifeguard workload, and political tolerance for the program. A system that alarms too often may teach the public to discount warnings; a system that alarms too rarely may leave swimmers exposed. The legal risk sits inside that operational balance.
Coverage Boundaries Matter More Than Coverage Language
The June 2026 Coogee Beach attack is not proof that drone surveillance failed. ABC reported that Leah Stewart was attacked while swimming at Coogee and that no drone patrol was operating there because of Sydney Airport flight path restrictions.[2] That distinction matters. A coverage gap is not the same as a missed detection.
But the gap is exactly the kind of fact that tests public messaging. If a state describes expanded, year-round, dawn-to-dusk drone coverage, the next question is where the exceptions live. Are flight-path exclusions displayed at the beach? Are they explained on government websites? Do lifeguards receive scripts that distinguish between “covered today,” “not covered here,” and “covered only if flying conditions allow”? Does the public hear “365-day coverage” as a program description or as an assurance about the water in front of them?
A good limitation disclosure does not make a dangerous beach safe. It does something more modest and legally important: it reduces the distance between what the agency knows and what the public is likely to believe. That distance is where reliance arguments grow.
The False-Security Argument Is Policy Evidence Before It Is Court Evidence
Marine biologist Greg Skomal has warned that drones can create a false sense of security while also noting that the odds of a shark attack remain 1 in 4.3 million.[6] Chris Lowe of the CSULB Shark Lab told The Guardian that his team has not, “in thousands of flights, seen any footage of a shark acting aggressively towards a person,” and he cautioned against unnecessary beach closures.[6] The same reporting noted 65 unprovoked bites globally in 2025, below the 10-year average of 72.[6]
Those facts pull in different directions. Low attack odds support restraint in closing beaches after every ambiguous shape in the water. Known detection limits support restraint in promising what drones can do. Actual prevented interactions support continued experimentation. None of that resolves the legal question, but it sharpens it: if the risk is rare, the system incomplete, and the public messaging confident, what exactly has the government undertaken to provide?
The false-sense-of-security concern would be strongest where a claimant can show reliance on official surveillance. A swimmer who ignores a posted beach closure is one case. A swimmer who enters an open, advertised-as-monitored beach after officials have failed to disclose that drones are not operating, cannot see through glare, or are staffed only during certain periods is a different case. Courts do not usually turn public-safety communications into guarantees, but they do examine whether official conduct induced reasonable reliance.
What a Risk Manager Should Treat as Liability Architecture
As of Q3 2026, no jurisdiction has yet tested a lawsuit specifically alleging negligent operation of AI shark surveillance. That absence should not be comforting. It means agencies are building the first generation of facts that a later court would use.
The most important documents are not the glossy launch materials. They are the procurement criteria, vendor performance assumptions, pilot training materials, maintenance logs, staffing rosters, flight cancellation rules, public-warning scripts, escalation protocols, and after-action reports. If the agency says the system detects sharks, the file should say under what conditions, at what confidence threshold, with whose review, and with what required response.
A legally disciplined program would separate at least four decisions that public messaging often compresses into one: whether to fly, whether the feed identifies a possible shark, whether the sighting is sufficient to warn or close, and when the beach can reopen. Each decision needs an owner. Each owner needs a rule for uncertainty. Each rule needs to be consistent with what the technology can actually support.
That does not require agencies to bury the public in disclaimers. It requires them not to let promotional language outrun the duty chain. “Drone-monitored beach” is a public-facing phrase. In litigation, it becomes a question: monitored when, by whom, with what limitations, and with what consequence after detection?
Incomplete surveillance may still improve beach safety. The legal exposure begins when incomplete surveillance is sold, staffed, and relied on as if its limits are someone else’s problem. Once a government chooses to watch at scale, the question shifts from “why didn’t you watch?” to “having chosen to watch, did you do so with reasonable care, and did the public reasonably rely on what you built?”
References
- Major boost to shark spotting drones to improve beach safety in $120 million shark program, NSW Government, June 28, 2026.
- More funding for NSW shark spotting drone program, ABC News, June 28, 2026.
- Major boost to shark drone program to improve beach safety, Surf Life Saving Australia.
- How shoring up drones with artificial intelligence helps surf lifesavers spot sharks at the beach, UNSW Newsroom, October 2022.
- Real-Time AI Shark Detection Is Boosting Beach Safety, NVIDIA Developer Blog.
- Sharks, drones and public safety at beaches, The Guardian, July 11, 2026.
- A deep dive on sharks and the law in NSW, Law Society Journal.
Comments
Join the discussion with an anonymous comment.