Two connected learning models Explore the linear model at KillChains.com

Preserved research input · KW-RPT-022

Behavioral Threat Assessment or Pre-Crime? The FBI BTAC, Secret Service NTAC, and the Prevention of Targeted Violence

An evidence-led boundary analysis of structured professional judgment, multidisciplinary threat management, population screening, base rates, rights, and coercive risk labeling.

Digest verified 1b48907e8ebe0844211919cea2cc493b5dc9cff62c5a971cd8f52f0aa01e1b53

Behavioral Threat Assessment or Pre-Crime? The FBI BTAC, Secret Service NTAC, and the Prevention of Targeted Violence

Executive judgment and standards of evidence

Behavioral threat assessment and management occupies a defensible but precarious position between ordinary violence prevention and coercive “pre-crime.” At its best, it is a structured, multidisciplinary process for investigating a concrete safety concern, understanding the person’s circumstances and conduct, resolving crises, restricting access to means when lawful, protecting potential victims, and reassessing whether intervention remains necessary. At its worst, it becomes a system for labeling people as future offenders on the basis of disturbing speech, disability, ideology, grievance, unconventional interests, weakly validated indicators, or opaque data analysis—without an offense, a reliable probability estimate, meaningful notice, or an avenue to challenge the label.

The FBI’s Behavioral Threat Assessment Center, or BTAC, is the central federal operational hub for this work. BTAC describes itself as the federal government’s only national-level, multiagency, multidisciplinary task force devoted to preventing terrorism and targeted violence through behavior-based operational support, training, and research. It is staffed by agents, intelligence analysts, and mental-health practitioners and supports federal, state, local, Tribal, campus, and community partners. Its nationwide Threat Assessment and Threat Management, or TATM, initiative seeks to build scalable multidisciplinary teams at the school, district, county, regional, and state levels. citeturn23search1turn0search0

The U.S. Secret Service’s National Threat Assessment Center, or NTAC, plays a related but institutionally distinct role. Established in 1998, NTAC grew out of the Secret Service’s protective-intelligence mission and now conducts targeted-violence research, issues operational guidance, trains public-safety and school personnel, and consults on difficult cases. NTAC defines threat assessment as a proactive investigative approach intended to prevent targeted violence before it occurs; its public model emphasizes multidisciplinary information gathering, investigative themes, individualized case formulation, management, and continuing reassessment rather than offender profiling. citeturn23search0turn23search18turn1search9

Neither BTAC nor NTAC officially presents behavioral threat assessment as a machine capable of forecasting who will attack. FBI guidance explicitly states that no single behavior predicts targeted violence, that concern categories are not statistical probabilities, and that threat assessment should be understood as case-specific prevention rather than deterministic prediction. The Secret Service likewise rejects the proposition that there is an accurate or useful demographic, psychological, or social “profile” of a school attacker. citeturn7view4turn7view2turn1search6

Their publicly documented method is best characterized as structured professional judgment supported by investigative checklists, behavioral research, multidisciplinary case conferences, and continuing management. The FBI cautions that a checklist may ensure that relevant topics are covered but cannot determine how heavily to weight each fact; it endorses evidence-informed structure combined with trained human judgment rather than a fixed quantitative formula. NTAC’s operational materials similarly organize inquiry around structured themes but do not publish a numerical threshold that produces a probability of attack. citeturn7view0turn7view4turn24search13

There is no reliable public documentation through August 2, 2026 showing that BTAC or NTAC’s standard national practice assigns people algorithmically generated numerical probabilities of committing targeted violence. They may use ordinary law-enforcement databases, analytic software, open-source research, and communications tools, but that is different from an AI model scoring each person’s future dangerousness. The NCBIO-25, discussed below, is a human-administered structured-professional-judgment aid developed for trained law-enforcement threat-assessment personnel—not an AI system, not a general clinical test, and not a validated population-screening instrument. citeturn4search1turn4search5turn24search2

The empirical record nevertheless imposes major limits. Much of the targeted-violence literature consists of retrospective case series of attackers, averted plots, or already-referred “persons of concern.” Such studies can describe common features and identify useful investigative questions, but they usually cannot determine how often the same features occur among nonviolent people, establish a person’s probability of attacking, or prove that an intervention caused an attack not to occur. Researchers in the field themselves recognize that the exceptionally low base rate of mass attacks makes individual prediction extraordinarily difficult and generates unacceptable false-positive rates even for apparently accurate indicators. citeturn5search28turn5search5turn5search9

For this report, evidence is rated as follows:

RatingMeaning in this report
HighReplicated prospective or controlled evidence in relevant populations, sound measurement, external validation, and results that bear directly on the claimed outcome.
ModerateMultiple reasonably rigorous observational or comparative studies with consistent findings, but important limitations in selection, measurement, generalizability, or causal inference.
LowRetrospective case series, highly selected samples, incomplete comparison groups, substantial missing data, or results not externally validated.
Very lowExpert consensus, anecdotal successes, face validity, uncontrolled case reports, or theoretical propositions.

Using those standards, the evidence that many attackers plan, prepare, communicate, acquire means, or display observable behavioral change is moderate as descriptive correlation. Evidence that any one indicator—or any publicly documented combination—reliably predicts which identified person will commit a mass attack is low to very low. Evidence that well-run school threat-assessment programs can reduce unnecessary exclusion, improve problem-solving, and connect students with services is low to moderate, concentrated heavily in studies of one structured school model. Evidence that such programs causally prevent mass shootings is very low, because mass shootings are rare, randomized prevention studies are generally infeasible, and “nothing happened” has many possible explanations. citeturn15search3turn15search8turn15search13turn15search24

The central conclusion is therefore conditional. Behavioral threat assessment is legitimate prevention when it is triggered by articulable conduct or a credible safety concern; uses trained, multidisciplinary judgment; distinguishes ideas from actions; employs the least coercive effective intervention; gives weight to disconfirming evidence; protects disability, speech, privacy, and due-process rights; and promptly retires unsupported concerns. It becomes functionally equivalent to pre-crime when institutions continuously scan populations, assign enduring risk labels from vague or protected characteristics, use opaque scoring or unvalidated indicators, treat distress or dissent as dangerousness, and impose surveillance or punishment without a sufficiently concrete nexus to threatened harm.

Concepts, methods, and institutional architecture

Behavioral threat assessment is a fact-gathering and decision-making process used to determine whether a person’s behavior, communications, circumstances, and access to means indicate a developing risk of intentional violence and, if so, what can be done to reduce that risk. The object is not merely to decide whether a statement is a punishable threat. A person may pose a concern without communicating a direct threat, while another person may make an angry or graphic statement without developing intent, capability, or a plan. FBI and Secret Service guidance therefore instructs teams to evaluate behavior in context, seek corroborating and contradictory information, and ask whether the person is moving toward violence rather than whether the person resembles a stereotypical attacker. citeturn6view1turn1search6turn12search26

Threat management is the intervention and follow-up component. It includes actions intended to interrupt planning, reduce grievance and crisis, protect potential targets, reduce access to weapons or sensitive locations when lawful, increase supervision, facilitate treatment or social support, enforce existing legal restrictions, and monitor relevant changes. Management is dynamic: a person’s circumstances can improve, deteriorate, or shift, and the intervention itself can affect risk. FBI guidance treats reassessment and case retirement as essential components, not administrative afterthoughts. citeturn7view1turn7view2turn8view2

Structured professional judgment, or SPJ, is a method in which trained evaluators consider an organized set of empirically or theoretically relevant factors, formulate how those factors operate in the individual case, identify plausible future scenarios, and design a management plan. Unlike a purely actuarial test, SPJ does not necessarily produce a numerical probability or rely on a fixed equation. Unlike unstructured intuition, it requires evaluators to document the factors considered, sources consulted, reasoning used, uncertainties identified, and management implications. FBI guidance explicitly places its approach closest to SPJ. citeturn7view0turn3search21

Actuarial risk assessment applies a predetermined statistical rule to specified variables and ordinarily produces a category, score, or estimated probability derived from a validation sample. An actuarial instrument can outperform unaided judgment when its outcome, population, predictors, scoring rules, and time horizon are clearly defined and independently validated. But an instrument validated for general recidivism, inpatient aggression, intimate-partner violence, or sexual reoffending cannot be assumed to predict mass targeted violence, whose base rate, pathways, populations, and outcomes are different. citeturn7view0turn3search12turn3search18

Clinical prediction ordinarily refers to a clinician’s individualized judgment about future behavior based on interview, history, diagnosis, presentation, and experience. It may be structured or unstructured. Purely unstructured clinical judgment is especially vulnerable to salience, stereotypes, overconfidence, diagnostic overshadowing, and inconsistent weighting of facts; broader violence-risk research generally finds that appropriately validated structured methods outperform unaided professional intuition, although no method eliminates uncertainty. citeturn7view0turn3search12turn3search3

Intelligence analysis is the organized collection, evaluation, integration, and interpretation of information to identify threats, relationships, patterns, gaps, and implications for decision-makers. In threat-assessment work, it may include checking criminal and court records, evaluating communications, mapping relationships, establishing timelines, verifying weapons access, and resolving conflicting reports. Fusion centers exist partly to receive, analyze, and disseminate threat information across jurisdictions, but criminal-intelligence systems supported by covered federal funding are constrained by rules governing reasonable suspicion, relevance, political and religious information, dissemination, audits, and retention. citeturn2search16turn21view1

Profiling classifies or infers dangerousness from a presumed type: demographic identity, appearance, diagnosis, ideology, lifestyle, personality, social status, or resemblance to previous offenders. Both FBI and Secret Service guidance reject a profile-based approach because attackers are heterogeneous and because many nonattackers share common attacker characteristics. Behavioral assessment is supposed to focus instead on what the person is doing, why, in what context, with what capability and trajectory. In practice, however, vague behavioral categories can become proxies for profiling if teams equate unusualness, autism, mental illness, political anger, religious intensity, social isolation, or violent media interests with dangerousness. citeturn1search6turn5search17turn12search26

Automated risk scoring uses statistical software, machine learning, rules engines, or other computational systems to transform data into a person-level risk score, rank, alert, or classification. Inputs may include criminal records, school data, social-media activity, health information, network associations, attendance, employment data, location, or inferred traits. Automated scoring can operate at a scale impossible for human teams and can reproduce errors, proxy discrimination, or institutional feedback loops across thousands of people before anyone recognizes the problem. NIST’s AI Risk Management Framework therefore emphasizes validity, reliability, transparency, explainability, privacy, accountability, safety, and the management of harmful bias. citeturn22search0turn22search7turn22search19

Predictive policing is the use of data analysis to forecast places, times, groups, or persons thought likely to be associated with future crime or victimization and to allocate police attention accordingly. Place-based systems differ materially from person-based lists, but both can create feedback loops: increased enforcement generates more recorded incidents in the targeted area or population, which then appears to validate continued targeting. The National Academies and GAO have identified unresolved questions about accuracy, bias, transparency, accountability, and whether person-based predictions provide benefits beyond conventional investigation. citeturn3search1turn3search4turn22search3turn22search13

FBI institutional history and present structure. The FBI created BTAC in 2010 as part of its behavioral-analysis capability. Its mission expanded in 2016 to encompass both terrorism and other forms of targeted violence. After the Las Vegas mass shooting and the Parkland school shooting, BTAC established the nationwide TATM initiative in 2018. BTAC operates within the FBI’s Behavioral Analysis Unit and broader National Center for the Analysis of Violent Crime/Critical Incident Response Group structure. By 2024, the FBI reported more than 130 threat-management coordinators across its 56 field offices. citeturn23search1turn17view3

BTAC accepts requests involving persons of concern, planned violence, stalking, threats, extortion, terrorism, workplace or school concerns, and post-incident analysis. Its services may include behavioral assessment, investigative strategy, interview planning, threat-management recommendations, prosecutorial consultation, and prioritization of investigative resources. The center is not itself a national court or civil-commitment authority; coercive measures ordinarily depend on the legal powers of the investigating agency, school, employer, court, health system, or state. citeturn6view1

BTAC’s public guide, Making Prevention a Reality, describes threat assessment as a complex, evolving practice that draws on research, operational experience, and multidisciplinary expertise. Its recommended process includes intake, triage, assignment of a case lead, comprehensive information gathering, concern formulation, management planning, reassessment, documentation, and eventual retirement or closure. It explicitly warns against confirmation bias, availability bias, hindsight bias, and overgeneralization from such features as manifestos or mental illness. citeturn6view1turn7view1turn8view1

Secret Service institutional history and present structure. NTAC was founded in 1998, building on research into attacks and attempted attacks against public officials. Its mission expanded to school attacks, public-space mass attacks, workplace violence, domestic violence connections, and community threat-assessment capacity. NTAC conducts research, issues national guidance, trains multidisciplinary teams, maintains regional support, and provides case consultation to public-safety professionals. citeturn23search0turn23search18turn23search21

NTAC’s school model has been especially influential. Its early Safe School Initiative concluded that there was no accurate or useful school-shooter profile and that attacks were usually preceded by behavior known to others. Its 2018 school operational guide described an eight-step process involving a multidisciplinary team, reporting mechanisms, information gathering, assessment of communications and circumstances, management, and follow-up. In 2024, NTAC published a six-step guide for state and local law-enforcement behavioral-threat-assessment units, supported by twenty investigative themes and management considerations. citeturn1search6turn1search7turn24search13

CISA, DHS prevention programs, and fusion centers. CISA is primarily a critical-infrastructure security and resilience agency, not a central clinical or law-enforcement assessment unit. Its contribution includes active-shooter guidance, insider-threat mitigation, K–12 reporting resources, infrastructure protection, and support for organizations creating prevention systems. CISA and the Secret Service have jointly promoted bystander-reporting and anonymous-reporting resources for schools. citeturn2search0turn2search2turn2search6turn23search10

Within DHS, the Center for Prevention Programs and Partnerships, or CP3, supports targeted-violence and terrorism prevention through grants, technical assistance, community-program development, and BTAM resources. DHS’s National Threat Evaluation and Reporting program trains state, local, Tribal, and territorial personnel and develops master trainers. These programs help create capacity but do not establish that every funded local team follows a uniform method or achieves comparable fidelity. citeturn2search1turn2search12turn2search22turn2search32

Fusion-center participation can provide rapid access to criminal records, court information, police contacts, fire and emergency calls, and partner-agency information. The Southwest Texas Fusion Center’s Behavioral Threat Assessment Group in San Antonio, for example, brings together police, federal agents, fire personnel, mental-health professionals, and other partners three times per week. The same information-sharing capacity that assists intervention also heightens privacy and mission-creep risks, particularly when a case lacks a criminal predicate and information migrates from a supportive assessment file into a criminal-intelligence system. citeturn17view3turn2search7

State, local, school, workplace, and health-care teams. Local models vary sharply. The North Carolina State Bureau of Investigation’s Behavioral Threat Assessment unit is a multidisciplinary law-enforcement, intelligence, and mental-health program that evaluates motive, means, pathway, and management options. Oregon and other jurisdictions have developed community-led teams involving educators, counselors, service providers, and law enforcement. Schools may house teams inside existing student-support structures, while employers frequently combine human resources, security, counsel, employee assistance, and management. citeturn4search2turn0search7turn16search8

Health-care adoption expanded through 2026. The American Hospital Association and FBI Behavioral Analysis Unit released a leadership guide and resource compendium for hospital and health-system BTAM teams, including case studies from Scripps Health, Ascension, Duke Raleigh Hospital, and the University of Virginia Medical Center. The model encourages collaboration among security, clinical personnel, legal counsel, human resources, leadership, and outside law enforcement. citeturn23search3turn23search7turn23search11turn23search17

Schools have become the most widespread setting. A federal school survey reported that by 2024 approximately 85 percent of public schools had a threat-assessment team, and a 2025 RAND–NTAC national study found broad adoption but uneven training, implementation fidelity, documentation, follow-up, and integration with student-support systems. Widespread adoption therefore should not be confused with demonstrated effectiveness or rights compliance. citeturn12search6turn15search11turn24search15

The institutional comparison is summarized below:

Institution or settingPrimary rolePublicly endorsed methodNumerical or algorithmic scoring
FBI BTAC/TATMOperational consultation, research, training, national team-buildingStructured professional judgment; multidisciplinary assessment; investigative and management planning; optional structured aidsNo standard numerical attack-probability formula publicly endorsed; NCBIO-25 is SPJ, not AI. citeturn7view4turn4search1
Secret Service NTACResearch, training, consultation, guidance for schools and law enforcementSystematic investigative themes, multidisciplinary teams, individualized management and reassessmentNo published national person-level numerical probability instrument. citeturn1search7turn24search13
CISAInfrastructure, insider-threat and school-safety guidanceOrganizational preparedness, reporting, BTAM adoption and protective measuresNo general CISA person-scoring model identified in its public BTAM guidance. citeturn2search0turn23search10
DHS CP3/NTERGrants, technical assistance, community prevention and trainingEvidence-informed local BTAM capacity and validated tools where appropriateLocal implementation varies; funding does not itself validate a tool. citeturn2search12turn2search22
Fusion-center teamsCross-agency information sharing and operational coordinationMultidisciplinary case conference, intelligence checks, management coordinationTechnical and data practices vary; criminal-intelligence rules may apply. citeturn17view3turn21view1
Schools, workplaces, health systemsInstitution-specific prevention and supportUsually team-based, contextual, and management-orientedCommercial platforms may digitize workflows; local scoring practices are not necessarily BTAC- or NTAC-validated. citeturn15search11turn23search11

What the behavioral evidence actually establishes

The strongest general proposition in the literature is modest: targeted attacks are often processes rather than wholly spontaneous events. Many perpetrators engage in thinking, planning, preparation, weapons acquisition, target research, rehearsal, or communications that are potentially observable before an attack. This supports inquiry and bystander reporting. It does not establish that everyone who displays one or more such behaviors is likely to attack, or that every attacker passes through a fixed sequence. citeturn0search6turn12search12turn24search5

Pathway to violence. Pathway models generally describe movement from grievance or violent ideation toward research, planning, preparation, breach, and attack. An FBI study applying the pathway-to-intended-violence model to 59 active shooters found observable pathway behaviors but cautioned that the model is not always linear and should be used with other information. Some attackers skip apparent stages, move backward and forward, conceal activity, or accelerate abruptly. citeturn0search6turn24search2

The pathway concept has moderate descriptive and construct evidence but low individual predictive validity. Planning, reconnaissance, acquiring weapons for an identified attack, drafting operational materials, or testing security are more specific than generalized anger, but many pathway studies begin with known attackers and code backward from the outcome. That design increases hindsight effects and does not tell evaluators the prevalence of similar behavior among nonattackers. The model is best treated as an investigative map—“what evidence should we seek?”—not a conveyor belt that mechanically carries a person toward violence. citeturn8view1turn5search28

Leakage and concerning communications. Leakage is the communication to a third party of intent, fantasy, planning, or information suggesting a possible attack. It can occur in conversations, assignments, private messages, manifestos, videos, gaming chats, social-media posts, or communications to peers. Leakage is operationally important because it creates an opportunity for inquiry, and NTAC’s averted-plot research illustrates the central role of classmates, friends, relatives, and other bystanders. citeturn5search11turn24search1

The evidence is moderate that leakage is common among identified attackers and disrupted plotters, but low that leakage alone predicts attack. Many people express violent fantasies, dark humor, despair, revenge narratives, fictional violence, or offensive political views without forming an operational intention. Definitions also vary: a narrow definition requires information plausibly related to an attack, while broader definitions can absorb almost any disturbing statement. Retrospective coding may classify ambiguous words as leakage because researchers already know that the speaker attacked. citeturn5search7turn5search3

A study of 115 public mass murderers found grievance against a person or entity was the only examined variable significantly associated with leakage, but that result concerns differences within an offender sample rather than differences between offenders and the general public. It does not produce an individual probability and should not be read as showing that a person with a grievance who posts angrily is likely to become violent. citeturn5search7

Fixation. Fixation generally refers to increasingly intense or rigid preoccupation with a person, cause, grievance, previous attacker, or violent objective, sometimes accompanied by deteriorating functioning or escalating pursuit. It can be relevant when paired with target-focused research, stalking, repeated boundary violations, weapons activity, or an inability to disengage despite consequences. citeturn5search4

Evidence for fixation is low to moderate as a retrospective warning behavior and low as a stand-alone predictor. The construct can be difficult to distinguish from passionate but lawful political, religious, artistic, academic, or personal interest. It can also be confused with restricted interests associated with autism or with obsessive symptoms that do not entail violence. Reliability depends on clear operational definitions, longitudinal evidence of change, and an identified relationship between the fixation and potential harm—not merely the evaluator’s discomfort with intensity or unconventionality.

Identification. Identification warning behavior refers to a psychological association with warriors, attackers, weapons, violent roles, or a legacy of violent action. It may include adopting an attacker identity, describing oneself as an agent of a cause, studying previous perpetrators, or expressing a wish to surpass them. The concept originates in a proposed warning-behavior typology that also includes pathway, fixation, novel aggression, energy burst, leakage, direct threats, and last-resort behavior. citeturn5search4

Identification has low empirical strength for individual prediction. Interest in military culture, firearms, notorious crimes, extremist history, horror, true crime, or violent fiction is widespread and constitutionally protected. The evidence becomes more concerning when identity claims are linked to a specific target, preparations, efforts to acquire means, operational security, a stated deadline, or rehearsal. Without those links, “identification” can easily become a cultural or ideological profiling device.

Grievance. A grievance is a perceived wrong, humiliation, loss, injustice, betrayal, persecution, or status injury that may organize a person’s narrative. Grievances are common in retrospective studies of mass attackers, but they are also nearly universal human experiences. NTAC’s public-space attack series found grievances and significant stressors in many attacker histories, while FBI and Secret Service guidance treat grievance as something to understand and potentially resolve rather than as proof of dangerousness. citeturn1search4turn24search21

The evidence is moderate for correlation with targeted attackers but very low for specificity. Investigators should examine whether a grievance is becoming target-focused, absolutist, dehumanizing, revenge-oriented, or linked to preparations. They should also ask what restrains the person, what alternative explanations exist, whether the grievance can be addressed lawfully, and whether the person has accepted nonviolent routes. Treating criticism of government, an employer, a school, a religious group, or a political movement as inherently suspicious would invert the First Amendment.

Capability and access to means. Capability includes the physical, technical, financial, logistical, and psychological ability to carry out a contemplated act. Access to firearms, explosives, vehicles, restricted locations, victim schedules, tactical knowledge, or accomplices can alter the urgency and feasible scenarios of a case. These factors have strong face validity and direct management relevance. The FBI’s comparative work found weapons access and behavior involving harm to others more associated with active shooters than with managed persons of concern. citeturn4search1turn0search11

Capability evidence is moderate for risk formulation and strong for immediate operational relevance, but access to weapons remains common and is not by itself predictive. The relevant questions are whether access is lawful, whether it has changed, whether acquisition is connected to an identified target or deadline, whether the person is rehearsing or concealing preparations, and whether there are lawful means to reduce access during a crisis.

Stressors and loss. Employment problems, disciplinary events, relationship breakdown, financial difficulty, family conflict, health problems, legal jeopardy, humiliation, and perceived failure appear frequently in attacker histories. These variables are useful for understanding timing and destabilization but have low specificity because millions of people experience them without violence. Missing-data problems are substantial: records of deceased attackers are often incomplete, and investigators may search more intensely for stressors after a notorious event than they would in an ordinary comparison case. citeturn1search4turn8view1

Suicidality and last-resort thinking. Suicidal ideation, hopelessness, and a belief that violence is the only remaining option occur in some targeted-violence cases and can increase urgency because the person may no longer expect to survive or may seek death by police. Yet the FBI’s matched comparison of 63 active shooters and 63 managed persons of concern found suicidality in both groups and did not establish it as a discriminator that could identify attackers. citeturn0search11turn12search0

The evidence is moderate that suicidality is relevant to crisis and violence management, but low as a specific marker of targeted violence. A suicidal person should ordinarily receive suicide-focused care and safety planning, not automatic treatment as a potential mass attacker. Conflating suicide risk with homicidal intent can deter help-seeking, intensify stigma, and produce unnecessary police intervention.

Stalking and boundary violations. Stalking, repeated unwanted contact, surveillance, trespass, and escalating boundary violations are important because they demonstrate persistence, target focus, and behavior despite rejection or sanctions. Stalking has a substantial independent violence literature, and NTAC has highlighted links among domestic violence, stalking, and some mass attacks. citeturn1search10turn24search11

Yet the FBI matched study reportedly found more documented stalking among managed persons of concern than among active shooters. That counterintuitive result illustrates selection effects: people who attract intervention may display overt behavior that generates records, while attackers who avoid detection may leave fewer documented incidents. The evidence is therefore moderate for broader victim-safety relevance but low for distinguishing a future mass attacker from other concerning or abusive persons. citeturn0search11

Violent ideation. Thoughts and fantasies of violence range from fleeting intrusive images to sustained revenge scripts and operational planning. Violent ideation is not equivalent to intent. The FBI’s First Amendment discussion recognizes that protected expression of ideas cannot be suppressed merely because officials find the ideation troubling when no articulated threat or authorized investigative purpose exists. citeturn8view0

Evidence is low for generalized violent ideation as a predictor but stronger when ideation becomes detailed, target-specific, feasible, repeatedly rehearsed, combined with preparatory conduct, or accompanied by expressed intent. A rights-respecting inquiry asks about content, frequency, voluntariness, emotional function, target, time frame, means, barriers, ambivalence, and behavior—not simply whether violence was mentioned.

Mental illness. Mental-health symptoms may be relevant to an individual formulation, particularly when untreated psychosis, severe mood disturbance, intoxication, cognitive deterioration, or acute crisis affects judgment or behavior. But there is no diagnosis that defines a targeted attacker, and mental illness is neither necessary nor sufficient for targeted violence. FBI and Secret Service materials reject profiles, and the FBI’s active-shooter comparison found diagnosed mental illness in both attackers and managed persons of concern, with higher documented rates among the managed group. citeturn1search6turn0search11

The evidence is moderate that acute symptoms can contribute in some cases and high that diagnosis alone lacks adequate specificity for mass-violence prediction. Clinical information should be used to identify treatment needs, symptom-related mechanisms, and communication accommodations—not to substitute diagnosis for evidence of intent or preparation.

The NCBIO-25. The North Carolina BeTA Investigation Overview-25 is a 25-item structured-professional-judgment aid developed in connection with the North Carolina SBI Behavioral Threat Assessment program. FBI materials describe it as available without charge to law enforcement and direct interested agencies to the North Carolina SBI for training. It is intended to organize multidisciplinary law-enforcement assessment, not to serve as a self-administered public checklist or general psychiatric diagnostic tool. citeturn4search1turn4search2

An initial study involving 64 persons of concern reported high inter-rater reliability among trained raters and a proposed five-factor structure. A later study compared 74 active shooters with 75 managed persons of concern, using five trained coders, and reported evidence characterized by the authors as supporting construct validity and applied utility. “Harming others” and weapons access were associated with the active-shooter group, while documented mental-health and conduct problems were more associated with the managed group. citeturn4search5turn4search1

The validation remains low to preliminary for its most consequential potential use. The samples were small and highly selected; both groups came from known cases rather than a prospective population; coding was retrospective; treatment and law-enforcement intervention may have altered outcomes among persons of concern; and the study did not establish a calibrated future-attack probability. Publicly available reporting on the later factor analysis also indicates weak overall model-fit statistics and unsuccessful loading of some proposed factors, supporting the authors’ call for further testing. citeturn4search8

Accordingly, NCBIO-25 may be defensible as a trained team’s documentation and discussion aid. It is not adequately validated as a numerical screening test for students, employees, patients, protesters, firearm owners, or the general public; it should not be converted into an algorithmic score or cutoff without new prospective validation, independent replication, calibration studies, subgroup analysis, and evidence that the proposed use improves outcomes without disproportionate harm.

Base rates, false positives, and program evaluation

Mass targeted attacks are devastating but statistically rare relative to the number of people who experience grievances, make disturbing statements, own weapons, struggle with mental illness, research previous attacks, or come to official attention. This creates the central mathematical problem of behavioral threat assessment: when the outcome is extremely uncommon, even a test with apparently impressive sensitivity and specificity can falsely identify enormous numbers of nonattackers. Researchers associated with warning-behavior models have explicitly acknowledged that the low base rate makes prediction impossible at acceptable false-positive levels. citeturn5search28turn12search14

Consider a hypothetical tool applied to 100,000 people where one person would otherwise commit the defined attack. Assume an unrealistically strong 90 percent sensitivity and 95 percent specificity. The tool would identify approximately 0.9 true attackers but falsely flag nearly 5,000 nonattackers. The positive predictive value would be approximately 0.018 percent—roughly one true case for every 5,556 people flagged. Increasing sensitivity often expands false positives further unless specificity is nearly perfect.

This example does not mean assessment is useless. It means broad population screening for future mass attackers is fundamentally different from investigating a person already connected to a concrete threat, target, weapon purchase, reconnaissance, or operational plan. Narrowing the referral population can raise the conditional base rate and make inquiry more useful, but it also produces selection bias: findings from referred cases cannot automatically be generalized to all students, employees, patients, or citizens.

False positives are not merely statistical inconveniences. Depending on the setting, a threat designation can produce police contact, searches, suspension, expulsion, firing, loss of housing or professional opportunity, firearm restrictions, involuntary evaluation, damaged relationships, stigmatizing records, or continuing surveillance. The more coercive the consequence, the more demanding the evidentiary threshold and procedural protection should be.

False negatives also matter. A system may close a case too early, fail to integrate information across agencies, discount escalating domestic violence, overlook weapons acquisition, or assume that a person’s denial resolves concern. But responding to false negatives by widening definitions until nearly everyone distressed or angry becomes reportable can destroy trust, overwhelm teams, and bury high-concern cases in noise.

Study-design limitations. Many federal studies begin with completed attacks, identify available records, and code whether designated characteristics appeared. This is useful descriptive epidemiology, but the case selection conditions on the outcome. Researchers know that violence occurred, records may have been assembled through intensive post-attack investigation, and ambiguous facts may appear more meaningful in retrospect. citeturn8view1turn12search12

Averted-plot studies have a different selection problem. NTAC’s 2021 analysis examined 67 plots advanced by current or former students and disrupted before attack. These cases demonstrate that reporting and intervention sometimes interrupt serious planning. But inclusion requires that authorities discovered and characterized the conduct as a plot, while unnoticed abandoned fantasies and resolved crises are absent. The sample therefore cannot show how often similar conduct would have ended without intervention or how many investigated youths were never genuine plotters. citeturn24search1

Persons-of-concern comparison studies improve on attacker-only case series by supplying a nonattacking group. The FBI’s matched study of 63 active shooters and 63 managed persons of concern is particularly valuable because it found that only a small subset of approximately 50 coded variables differentiated the groups. The authors appropriately cautioned that findings should not be translated into individual probabilities and that intervention itself may partly explain why the persons of concern did not attack. citeturn0search11turn12search0

That design still cannot answer the key counterfactual question: what would have happened to each person of concern without management? Some might have attacked; some might have committed lesser violence; some might have harmed themselves; many might have done nothing. Because assignment to intervention was not randomized and because the groups differed in how they came to attention, causal prevention cannot be inferred merely from nonattack.

Missing data and measurement. Attackers who die cannot be interviewed, and their records vary widely in quality. Family members may minimize or reinterpret events. Digital data may be deleted or inaccessible. Clinical records may be legally unavailable. Investigators may code “absent” when a feature was simply undocumented. Studies should therefore report denominators for each variable, distinguish “no” from “unknown,” publish coding manuals, and test whether results change under plausible assumptions about missingness.

Inter-rater reliability. A behavioral construct is not useful if trained evaluators cannot consistently identify it. Some studies, including the NCBIO-25 work, report strong agreement among trained coders, which supports reliability under study conditions. Reliability, however, does not establish validity: evaluators may consistently apply a category that does not predict or causally relate to violence. Nor does agreement among research coders guarantee agreement among busy school administrators, patrol officers, clinicians, or workplace managers with uneven training. citeturn4search5

External validity. Findings from adult public mass attackers may not apply to elementary-school students, intimate-partner cases, extremist mobilization, hospital threats, stalking, or workplace conflicts. Cultural and legal conditions also change over time. Social-media practices, firearm access, reporting systems, school discipline, and intervention availability affect what becomes visible and what authorities can do. Every tool should therefore identify its validation population, outcome, time horizon, setting, and intended user.

School-program evidence. School threat assessment has better program-evaluation evidence than national mass-violence assessment, but the outcome evidence is still narrower than public claims often imply. Virginia studies of structured school threat assessment have reported that most assessed threats were not attempted and that schools frequently resolved cases without arrest or exclusion. One study of 1,865 cases reported attempted threats in approximately 3 percent, with most attempts averted or resulting in fights or assaults rather than mass attacks. citeturn15search5

Those findings suggest that structured assessment can help schools distinguish levels of concern and avoid treating every statement as requiring expulsion or arrest. National Institute of Justice work has also examined effects on disciplinary outcomes, implementation, and disparities. But these studies do not prove prevention of rare mass shootings, and much of the favorable evidence comes from one family of school models and affiliated researchers. Independent replication and national outcome surveillance remain limited. citeturn15search8turn15search15turn15search24

Civil-rights disparities complicate interpretation. In one large multistate dataset of 15,301 school assessments across 1,221 schools, approximately 41 percent of referred students had disabilities. Virginia research reported that students receiving special education were referred at substantially higher rates and that Black students were referred more often than White students. Referral differences may reflect true exposure to behavioral crises, differences in support, biased interpretation, unequal surveillance, or combinations of these factors; outcome analysis must begin at referral, not merely compare team decisions after referral. citeturn10search1turn10search5turn15search8

The evidence ratings are therefore:

ClaimCorrelation or descriptionIndividual predictionCausal prevention
Attackers often plan or prepareModerateLowNot itself a prevention claim
Leakage or concerning communication is often observableModerateLowLow evidence that reporting contributes to disruption
Grievance, fixation, stressors, identificationLow–moderateVery low–lowVery low
Weapon access and target-specific preparationModerateLow–moderate within a high-concern referral populationLow, though reducing access has strong immediate logic
Suicidality or mental illnessModerate for crisis relevanceVery low for mass attack specificityLow for targeted-violence prevention; stronger for appropriate clinical care
Structured school threat assessment reduces exclusion and supports problem-solvingLow–moderateNot applicableLow–moderate for intermediate outcomes; very low for preventing mass attacks
BTAM programs prevent mass shootings overallDescriptive case supportNo validated individual predictionVery low, because counterfactuals are unobserved

A mature evaluation regime should measure more than attacks. It should track referral volume, sources, response times, service access, voluntary engagement, threats attempted, ordinary assaults, suicide attempts, arrests, exclusions, emergency hospitalization, firearm interventions, repeat referrals, case duration, demographic and disability disparities, complaints, record corrections, and whether teams follow their own procedures. The National Academies has emphasized that the field needs stronger implementation and outcome evaluation precisely because rare-event prevention cannot be assessed through success stories alone. citeturn5search2turn15search13

From tip to closure: workflow, interventions, and documented cases

A defensible operational pathway begins with a report but does not presume that the report is accurate. Tips may come from classmates, family, coworkers, clinicians, employers, social-media users, anonymous reporting systems, patrol officers, firearm dealers, or intelligence partners. Reports can be incomplete, malicious, mistaken, decontextualized, or urgent. A reporting system should therefore encourage specific observations—what was said or done, when, to whom, through what medium, with what apparent target and access to means—rather than vague judgments that someone is “creepy” or “off.” citeturn2search2turn2search6turn24search1

Intake and immediate safety screening. The initial reviewer determines whether there is an emergency requiring immediate protective action: an attack underway, a named target and deadline, current weapon possession at a prohibited site, an attempt to breach security, imminent suicide, or another acute danger. Emergency response is distinct from the slower comprehensive assessment. The need to act rapidly does not eliminate documentation or later review.

Triage. FBI guidance distinguishes preliminary triage from a full “360-degree” assessment. Triage verifies basic facts, identifies urgent unknowns, determines whether the matter falls within the team’s mission, and allocates resources. A low-concern statement may be returned to ordinary support or discipline; an ambiguous but potentially serious report may require targeted fact gathering; a high-concern case may require immediate victim protection, law-enforcement action, clinical crisis response, or means restriction. Concern levels describe current conditions, not mathematical predictions. citeturn7view1turn7view2

Case leadership and scope. One person should be accountable for coordinating the case, maintaining the timeline, assigning inquiries, documenting decisions, and ensuring follow-up. The team should state the authorized purpose and define the question narrowly. “Does this employee present an imminent threat to a named supervisor?” is more disciplined than “Is this an unstable person?” Scope control prevents curiosity-driven expansion into unrelated political, religious, sexual, medical, or associational information.

Information gathering. A comprehensive inquiry can include interviews with the person and knowledgeable contacts; review of the original communication in full context; target and witness interviews; relevant school, workplace, court, criminal, and publicly available records; lawful assessment of weapons access; history of violence, stalking, or boundary violations; recent losses and stressors; treatment and support; and evidence that contradicts the allegation. Information-sharing must remain tied to legal authority, need to know, and purpose. citeturn6view1turn21view1

The person’s interview should not be treated solely as an interrogation. Direct, respectful questions about violent thoughts, grievances, targets, plans, weapons, suicide, protective relationships, and willingness to accept help often produce more useful information than accusatory confrontation. Denial is neither automatically exculpatory nor automatically deceptive. The interviewer should consider developmental level, disability, language, culture, trauma, communication style, and whether the person understands figurative or hypothetical questions.

Multidisciplinary assessment. The case conference should separate verified facts, disputed reports, inferences, and unknowns. Members should consider plausible violence and nonviolence scenarios, identify dynamic drivers, evaluate capability and access, examine protective factors, and actively search for disconfirming evidence. The team’s role is not to vote on whether the person is “dangerous” in the abstract but to explain what might happen, under what conditions, to whom, and what interventions could change those conditions.

Management planning. A management plan should specify actions, responsible persons, deadlines, indicators of improvement or escalation, communications with potential targets, and reassessment dates. Interventions should be matched to mechanisms. A housing crisis calls for housing support; workplace humiliation may require conflict resolution and a safe separation process; acute psychosis may require clinical care; stalking requires victim protection and enforcement of boundaries; illegal firearm possession may require law enforcement; a student’s disability-related outburst may require implementation of an individualized behavior plan.

Potential interventions range from minimally intrusive to highly coercive:

  • voluntary counseling, peer or family support, crisis services, substance-use treatment, housing or financial assistance;
  • restoration of medication or clinical follow-up chosen through appropriate care;
  • changes in school, workplace, duty, schedule, access, supervision, or conflict-management arrangements;
  • safety planning and notification for potential targets;
  • lawful restriction of building, network, vehicle, weapon, or sensitive-information access;
  • enforcement of workplace rules, school rules, probation conditions, trespass notices, or protective orders;
  • firearm-related processes authorized by law, including voluntary transfer, enforcement of existing prohibitions, or a court process with the required evidentiary and procedural safeguards;
  • criminal investigation or prosecution where probable cause supports an offense;
  • emergency mental-health intervention only when the jurisdiction’s legal criteria are met.

Supportive intervention differs from punitive preemption in purpose, proportionality, process, and consequences. Support seeks to resolve the conditions producing concern, ordinarily with the person’s participation and without an enduring dangerousness label. Punitive preemption imposes exclusion, surveillance, prosecution, or confinement principally because officials fear what the person might someday do. The same action can fall on either side depending on evidence and process: a temporary workplace reassignment with pay during a specific investigation is not equivalent to indefinite blacklisting based on rumor.

Monitoring, closure, and retention. The team should reassess after meaningful changes rather than maintain perpetual surveillance. FBI guidance recommends documenting attendees, information sources, concern level and rationale, imminence, management recommendations, referrals, and confidentiality considerations. Low-concern cases should be retired; higher-concern cases may remain open while defined management tasks continue. citeturn8view2turn7view2

Closure should answer whether the initial report was substantiated, which interventions were completed, what residual concern remains, who needs limited continuing information, and when records will be reviewed or destroyed. For covered criminal-intelligence systems, 28 C.F.R. § 23.20 requires reasonable suspicion of criminal activity, prohibits retention of political, religious, or social information unless directly related to criminal conduct, restricts dissemination to need-to-know and right-to-know recipients, and generally requires review and validation before a retention period that may not exceed five years. Not every school or workplace file falls under that regulation, which makes locally adopted retention rules essential. citeturn21view1

Documented disruptions. The following examples show that intervention can matter, but none independently establishes a validated prediction method or proves that the worst outcome would have occurred without intervention.

Documented exampleIntervention and outcomeEvidentiary caution
San Antonio Uvalde-admirer caseA 19-year-old posted praise of the Uvalde attacker, weapon images, and a desire to die in a police shootout. A search initially found no weapons; he accepted a mental-health assessment and treatment. Continued BTAG monitoring identified later conduct, including driving past Robb Elementary and attempting to buy a shotgun. He was arrested on a state terroristic-threat charge and later received jail and supervised release. citeturn17view3Strong documentation of escalating conduct and intervention; the counterfactual attack remains unknowable, and the FBI’s account is also a program-success narrative.
Sycamore Middle School, TennesseeIn 2016, a 14-year-old came to counselor Molly Hudgens with a loaded semiautomatic handgun, extra ammunition, and a plan to harm people at school. After an extended conversation, he surrendered the weapon and no shots were fired. citeturn16search9turn16search33This was a direct crisis intervention with weapon and stated plan, not a test of early-stage behavioral scoring.
NTAC “white-shirt” plot exampleNTAC’s averted-school-violence materials describe young students whose warnings or instructions to peers helped expose an attack plot, allowing adults and authorities to intervene before execution. citeturn14search9turn24search1The report reconstructs a selected known plot; it does not estimate how many similar statements were false alarms.
Two-female-student school plotNTAC has used a case involving two female students’ planned school attack to illustrate how communications, bystander information, and coordinated investigation disrupted planning. citeturn14search6turn24search1Details come through an official training case study and may omit information protected by juvenile confidentiality.
FBI “Mr. S” caseAn anonymized FBI case example describes a person who produced a violent manifesto and generated escalating concern; management reportedly included a mental-health hold and structured boundaries through military reserve orders rather than relying on a single punitive response. citeturn7view1Anonymization prevents independent verification, and the absence of later violence does not prove an attack was otherwise inevitable.
NTAC’s 67 averted school plotsNTAC documented 67 cases from 2006–2018 in which a current or former student advanced a school-attack plot that was stopped, frequently after information reached classmates, family, school personnel, or law enforcement. citeturn24search1This is strong evidence that some genuine plots become observable and interruptible, but it is a selected case series without untreated controls.
Virginia threat-assessment cohortIn 1,865 assessed school threats, approximately 3 percent were attempted; most attempted threats were averted or resulted in lower-level fights or assaults, and only a small share of cases led to arrest. citeturn15search5Program-level outcomes support measured responses but cannot identify which nonattempted threats would have progressed without assessment.

Disputed or harmful interventions. Evidence of harm also exists, especially where threat assessment blends into discipline, disability neglect, involuntary treatment, or predictive surveillance.

Documented exampleHarm or disputeEvidentiary caution
Pasco County kindergartnerDOJ found that an elementary student with an emotional-behavioral disability was suspended four times for seven days over roughly two months without evidence that the district took steps to address the behavioral need. citeturn17view2Part of a systemic civil-rights investigation, not proof that every Pasco assessment was improper.
Pasco County autistic sixth graderDOJ reported three sequential exclusionary incidents in less than a month even though the student’s plan allowed breaks and noise-cancelling headphones; staff failed to follow the plan and instead excluded the student. citeturn17view2The example concerns broader discipline practices intertwined with the district’s threat and law-enforcement response system.
Pasco Baker Act referralsDOJ found that students with disabilities underwent threat assessments without adequate consideration of disability, and some were taken into custody for involuntary psychiatric treatment for conduct that manifested their disabilities. citeturn17view2turn18view3DOJ’s findings establish systemic violations under Title II but do not publicly identify every student or case outcome.
LaVine v. Blaine School DistrictA high-school student was emergency-expelled for 17 days after submitting a fictional poem about a school shooting. The Ninth Circuit upheld the school’s response, but the dissent and later commentary argued that officials misread protected literary expression as a threat. citeturn26search0turn26search12turn26search24The judicial holding favored the school; “harmful” reflects the civil-liberties dispute, not a final finding of liability.
Doe v. Pulaski CountyA student was expelled for a violent letter written at home about a former girlfriend. A district court initially found no true threat; the en banc Eighth Circuit ultimately upheld the school’s action, exposing how private fantasy, communication, and true-threat doctrine can produce sharply divided judgments. citeturn26search1turn26search9turn26search33The content was exceptionally severe; the dispute concerns legal classification and proportionality, not an innocuous statement.
Bell v. Itawamba County School BoardA student was suspended and sent to alternative school after posting an off-campus rap criticizing coaches and using violent language. A panel ruled for the student, but the en banc Fifth Circuit upheld school authority, generating continuing criticism that the decision discounted artistic convention and protected criticism of alleged misconduct. citeturn26search2turn26search18turn26search34The case did not arise from a formal BTAC consultation; it illustrates the speech-classification problem that local threat systems face.
Pasco person-scoring and youth surveillanceSeparate from the school district settlement, the Pasco Sheriff’s Office used education, child-welfare, and police information to place youths on “at-risk” lists for predictive policing and surveillance. Reporting and civil-rights analyses described factors such as grades, absences, victimization, and family history, prompting a federal student-privacy investigation and sustained criticism. citeturn26search3turn26search7turn26search23turn26search35This was predictive policing rather than orthodox BTAM, but it is a concrete example of how prevention rhetoric can evolve into person-based pre-crime.

Selection bias cuts in both directions. Successful disruptions are likely to be publicized when plans, weapons, confessions, or arrests make the preventive narrative compelling. Quiet cases that resolved without drama, interventions that had no effect, and attacks that occurred despite assessment are less visible. Conversely, harmful examples disproportionately arise from litigation, investigative reporting, advocacy, or federal civil-rights enforcement and may overrepresent the worst systems. Neither collection is a representative denominator. A credible program must publish routine aggregate outcomes rather than rely on heroic successes or notorious failures.

Constitutional, civil-rights, privacy, and ethical limits

Protected speech and belief. The First Amendment does not prohibit officials from considering speech as evidence when they have a lawful, fact-specific reason to investigate possible violence. A statement can reveal target, intent, planning, motive, or access to means even when it is not independently prosecutable. But government may not open or maintain an inquiry solely because it disfavors a person’s political, religious, or social views. Attorney General guidelines and criminal-intelligence rules prohibit collecting information merely to monitor First Amendment activity and require a nexus to authorized purposes or criminal conduct. citeturn9search1turn21view1

FBI guidance recognizes this distinction. When speech communicates ideation but no articulated threat or authorized investigative basis, government cannot suppress or diminish the person’s ability to communicate merely because officials dislike the ideas. citeturn8view0

For criminal true-threat prosecutions, Counterman v. Colorado requires proof that the speaker was at least reckless as to the threatening character of the communication. The Supreme Court reasoned that a subjective fault requirement provides necessary breathing room for protected speech. The decision does not prevent schools or employers from taking every noncriminal safety measure, but it cautions against treating an objectively frightening interpretation as sufficient for severe punishment without examining the speaker’s state of mind and context. citeturn19search0turn19search4

Schools have additional authority to prevent material disruption and protect students, but their authority over off-campus expression is not unlimited. Mahanoy Area School District v. B.L. emphasized the special First Amendment concerns raised by off-campus speech and held that punishment for a student’s off-campus social-media expression was unconstitutional where substantial disruption was not shown. citeturn19search2

A rights-respecting team should distinguish among protected advocacy, offensive opinion, fiction, humor, quotation, venting, intrusive thoughts, artistic performance, conditional rhetoric, targeted harassment, stalking, true threats, solicitation, conspiracy, and operational preparation. Political radicalism is not synonymous with violent mobilization; religious intensity is not extremism; criticism of institutions is not grievance-fueled dangerousness.

Disability and mental health. Title II of the Americans with Disabilities Act and Section 504 prohibit public entities and federally funded programs from discriminating on the basis of disability. Teams must consider whether communication style, emotional regulation, repetitive interests, literal language, involuntary movements, trauma responses, or disability-related behavior is being mistaken for intent. They must also make reasonable modifications and coordinate with existing individualized education and support plans. citeturn10search23

The Pasco County settlement demonstrates that threat assessment does not displace disability law. DOJ required multidisciplinary participation by student-services personnel and someone knowledgeable about the student’s disability; consideration of whether the conduct was disability-related and whether supports had been provided; parent input; coordination with IEP or Section 504 teams; and limits on law-enforcement referral where support could address the behavior. citeturn17view1turn18view2

Autistic people may display intense interests, atypical affect, direct or scripted language, social misunderstanding, or distress behaviors that observers misinterpret. People with psychosis may express bizarre beliefs without a target or capacity for planned violence. People with obsessive-compulsive symptoms may experience unwanted violent thoughts that are ego-dystonic and feared rather than desired. Teams need qualified clinical interpretation where relevant, but a clinician should not be asked to certify that a person is “safe” or to provide certainty that science cannot support.

Student privacy. FERPA generally restricts disclosure of personally identifiable education records. School threat-team members may use records for authorized educational and safety functions, but outside law-enforcement members do not automatically acquire unrestricted authority to retain or redisclose student information. The health-or-safety emergency exception is case-specific and tied to an actual, impending, or imminent emergency, not a blanket authorization for routine data feeds. citeturn9search2turn9search10turn9search18turn9search26

The Pasco predictive-policing controversy illustrates the danger of repurposing school records for person-based police surveillance. Factors such as poor grades, absences, victimization, or family adversity may identify students who need support, but converting them into police-risk variables punishes vulnerability and creates a self-reinforcing record. citeturn26search23turn26search19

Health information. HIPAA permits covered entities to disclose protected health information in good faith when necessary to prevent or lessen a serious and imminent threat and the disclosure is made to someone reasonably able to prevent or lessen it. The rule defers substantially to professional judgment, but it does not require routine disclosure of complete clinical files whenever a team expresses generalized concern. Disclosure should be limited to information relevant to the safety purpose. citeturn9search3turn9search7turn9search35

The ethical danger is that patients will avoid treatment if clinicians become perceived as intelligence collectors. Clinical participation should focus on mechanisms, needs, protective planning, and lawful disclosure—not diagnosis-based reporting. Teams should never assume that treatment records are objective truth; records can contain provisional diagnoses, unverified third-party allegations, cultural misunderstandings, and outdated information.

Due process. A threat-assessment label may be described as “nonpunitive” while producing severe practical consequences. When a public institution suspends a student, terminates employment, revokes access, imposes a trespass order, confiscates property, or initiates confinement, constitutional or statutory process may attach. Goss v. Lopez established that even short public-school suspensions require notice of the allegations and an opportunity for the student to respond. citeturn19search1turn19search32

At minimum, consequential administrative action should provide timely notice, a description of the factual basis subject to legitimate safety redactions, an opportunity to correct errors, a neutral reviewer, written reasons, proportional duration, and an appeal or reconsideration mechanism. Emergency temporary action may precede full process where necessary, but “emergency” cannot become a device for indefinite exclusion.

Compelled treatment and involuntary confinement. Civil commitment is a profound deprivation of liberty. Supreme Court doctrine requires more than a diagnosis: O’Connor v. Donaldson held that a state cannot constitutionally confine a nondangerous person capable of living safely in freedom, and Addington v. Texas requires clear and convincing evidence for involuntary civil commitment. citeturn20search18turn20search31

A threat team may recommend voluntary evaluation, offer transport, or seek crisis assistance, but it should not use the prospect of police action, expulsion, or firing to manufacture nominal “consent.” Emergency holds must satisfy the jurisdiction’s statutory criteria and receive the required independent clinical and judicial review. Threat assessment is not itself a commitment standard.

Firearms. Teams may encounter illegal possession, prohibited persons, threats involving firearms, unsafe storage, acute suicide risk, attempted purchases, or circumstances potentially covered by a state protective-order or extreme-risk law. The response should distinguish voluntary safety planning from seizure, and criminal enforcement from civil preventive orders. Coercive firearm restriction must rest on applicable law, competent evidence, the correct decision-maker, notice and hearing where required, defined duration, and a process for restoration.

Weapon ownership or interest should never substitute for intent or planning. Conversely, a specific target, stated deadline, operational preparation, and immediate access can justify urgent lawful action even when the person has not yet fired a weapon. The rights-respecting principle is not “never intervene before violence”; it is “match the intervention to concrete evidence and lawful authority.”

Stigma and dangerousness records. A case file may outlive the crisis and affect later police contacts, background checks, educational decisions, professional licensing, security clearances, or treatment. Labels such as “high risk,” “potential active shooter,” or “threat” should not be used when the actual conclusion is merely “insufficient information” or “distressed person requiring support.” Records should preserve uncertainty, corrections, source reliability, and closure status.

Criminal-intelligence rules offer a useful minimum model even where not formally controlling: information should be relevant, reliable, periodically reviewed, protected by audit trails, shared only with recipients who have a need and right to know, corrected when inaccurate, and destroyed when obsolete. Political or religious information should not be retained unless directly related to criminal activity supported by reasonable suspicion. citeturn21view1

Bias and institutional incentives. Threat assessment is vulnerable to racialized interpretations of anger, gender stereotypes, cultural misunderstanding, and diagnostic bias. An identical statement may be perceived differently depending on whether the speaker is Black, Muslim, autistic, unhoused, transgender, politically unpopular, or known to police. Referral and outcome data should therefore be audited by race, ethnicity, sex, disability, language, age, and referral source, while recognizing that statistical disparity alone does not identify its cause. citeturn10search1turn15search8turn18view1

Teams also face asymmetric incentives. Failure to prevent a visible attack can end careers and generate public outrage, while unnecessary surveillance or exclusion is dispersed among less visible individuals. That imbalance encourages overclassification. Programs need explicit accountability for false positives and civil-rights harms, not only for missed threats.

AI person scoring, program safeguards, and the line separating prevention from pre-crime

Human-led BTAM and AI person scoring differ in important respects, but the distinction is not absolute.

Traditional BTAM is ideally triggered by a report connected to observable behavior, evaluates context, allows conversation with the person, incorporates rapidly changing information, and formulates individualized management. AI scoring generally processes standardized data across larger populations, often without a specific complaint, and produces a score, rank, or alert based on historical associations. NIST emphasizes that AI systems are sociotechnical: performance depends not only on model code but on data, users, organizational incentives, implementation, and the consequences attached to outputs. citeturn22search0turn22search14

An algorithm may appear more consistent than a human team, but consistency is not accuracy or fairness. Training labels such as “person of concern,” “gang associate,” “violent,” or “successfully managed” may encode discretionary policing and institutional bias. Arrest data represent enforcement as well as offending. School discipline data reflect teacher and administrator discretion. Treatment data reflect access and diagnosis. A model can therefore reproduce historical surveillance patterns while presenting them as objective risk. citeturn22search3turn22search10turn22search13

The low-base-rate problem is even more severe for population-scale AI screening. A model trained on a small number of heterogeneous attackers and millions of nonattackers is likely to learn proxies, overfit rare cases, or generate an unusable false-positive burden. High overall accuracy can be meaningless when almost everyone belongs to the nonattacker class. Any vendor claiming “90 percent accuracy” should be required to disclose prevalence, sensitivity, specificity, positive predictive value, calibration, time horizon, subgroup performance, missing-data handling, and the exact consequence the score is supposed to predict.

Human-in-the-loop review is not an automatic cure. Automation bias can lead evaluators to defer to a score, while institutional pressure may make overrides rare. NIST recommends documenting the degree of human oversight, downstream actions, overrides, limitations, and recourse for people affected by consequential decisions. citeturn22search15turn22search19

Conversely, a nominally human BTAM system can behave like an algorithm. A rigid checklist that awards points for grievance, diagnosis, social isolation, violent interests, weapon ownership, and political anger may be less transparent and less validated than audited software. Multidisciplinary consensus can also amplify rather than correct bias when all members see the same selected records, defer to law enforcement, or fear responsibility for closing a case.

The proper comparison is therefore functional:

DimensionRights-respecting human BTAMAI person scoring or pre-crime-like BTAM
TriggerSpecific report or articulable safety concernContinuous population screening or generalized suspicion
Unit of analysisIndividual behavior in contextData profile, proxies, associations, or rank
OutputScenario formulation and tailored managementRisk score, watchlist, alert, or enduring classification
EvidenceVerified facts, direct inquiry, disconfirming informationHistorical data whose labels and biases may be opaque
AdaptabilityDynamic reassessment and case closureScores may persist and propagate across systems
AccountabilityNamed decision-makers and written rationaleVendor secrecy or diffuse responsibility
Rights protectionPurpose limitation, notice where feasible, correction, appeal, least-restrictive actionSurveillance or adverse action without meaningful contest
ValidationCase-process quality and outcome auditsRequires external model validation, calibration, subgroup testing, and impact evaluation

Safeguard checklist for a rights-respecting program

  • [ ] Define the mission narrowly. The program should address credible risks of intentional violence, not generalized disorder, ideological deviance, ordinary misconduct, unpopular expression, or predictions of future criminality.
  • [ ] Require an articulable factual trigger. A referral should identify specific behavior, communication, target, preparation, or material change—not merely a diagnosis, identity, reputation, anonymous dislike, or “gut feeling.”
  • [ ] Separate emergency response from assessment. Immediate threats require rapid protective action; ambiguous concerns require verification and proportionate inquiry.
  • [ ] Reject profiles and protected-trait proxies. Race, religion, nationality, political belief, disability, gender identity, social awkwardness, or lawful weapon interest must never serve as substitutes for behavior connected to harm.
  • [ ] Use multidisciplinary membership without law-enforcement domination. Teams should include behavioral-health, legal, disability, educational or workplace, security, and victim-safety expertise appropriate to the setting.
  • [ ] Train and certify users. Structured aids such as NCBIO-25 should be limited to their documented user population and purpose, with competency assessment, refresher training, and fidelity review. citeturn4search1turn4search5
  • [ ] Do not convert checklists into unsupported scores. No item count or local weighting scheme should be treated as a probability unless it has been prospectively validated for that exact population, outcome, and time horizon.
  • [ ] Separate fact from inference. Files and case conferences should distinguish verified information, allegations, interpretations, missing information, and disconfirming evidence.
  • [ ] Assess behavior in context. Teams should review complete communications, cultural and artistic context, disability, developmental level, audience, target, means, intent, planning, and trajectory.
  • [ ] Use structured bias controls. Assign a devil’s advocate, require alternative hypotheses, blind reviewers to irrelevant protected characteristics where feasible, and document why less alarming explanations were rejected.
  • [ ] Prefer supportive and least-restrictive management. Services, conflict resolution, safe separation, disability supports, voluntary treatment, and victim safety should precede coercion unless urgency or law requires otherwise.
  • [ ] Do not make services conditional on surrendering unrelated rights. Treatment should not become indefinite surveillance, and refusal of voluntary treatment should not by itself be treated as evidence of dangerousness.
  • [ ] Provide process before consequential action. Give notice, an opportunity to respond and correct records, written reasons, time limits, neutral review, and appeal, subject to narrowly tailored emergency exceptions.
  • [ ] Apply FERPA, HIPAA, disability law, labor law, and criminal-intelligence rules independently. Participation on a team does not create a universal information-sharing exception. citeturn9search2turn9search3turn21view1
  • [ ] Minimize and compartmentalize data. Collect only what is relevant; restrict access; log disclosures; label source reliability and confidence; prohibit unauthorized onward dissemination.
  • [ ] Set closure and deletion rules at intake. Every case should have review dates, closure criteria, correction procedures, and a maximum retention period appropriate to the legal system and residual risk.
  • [ ] Prohibit automated person scoring absent extraordinary validation. Any proposed AI system should undergo independent predeployment testing, public impact assessment, subgroup and calibration analysis, security review, and legal evaluation under NIST-style governance. citeturn22search0turn22search31
  • [ ] Never permit an AI score to authorize coercive action. A score may, at most, prompt human verification; search, arrest, exclusion, confinement, or firearm deprivation must rest on independently established lawful criteria.
  • [ ] Publish aggregate performance and harm data. Programs should report referrals, dispositions, services, coercive actions, disparities, repeat cases, complaints, record corrections, attacks, ordinary violence, and adverse events.
  • [ ] Commission independent evaluation. Evaluation should be conducted by researchers without program or vendor conflicts and should examine implementation fidelity, comparative outcomes, false positives, and civil-rights effects.
  • [ ] Create an external civil-rights review mechanism. Students, employees, patients, and community members need a confidential way to challenge misuse without retaliation.

Final judgment. Behavioral threat assessment is legitimate when it functions like preventive problem-solving: a specific concern is verified; context and contrary evidence are sought; trained professionals develop transparent scenarios rather than probabilities; interventions address concrete mechanisms; potential victims are protected; coercion is governed by ordinary law; and the case ends when the factual basis ends.

It becomes pre-crime when the state or institution ceases to manage conduct and begins to govern predicted identity. The warning signs are population scanning, vague “concerning behavior” standards, ideology or disability as proxies, unvalidated numerical scoring, secret watchlists, data sharing untethered to purpose, indefinite monitoring, compelled treatment without legal criteria, punishment for protected speech, and adverse action that cannot be meaningfully challenged.

BTAC and NTAC’s formal doctrine contains important protections against that outcome: no profile, no single predictive behavior, structured rather than purely intuitive judgment, multidisciplinary formulation, dynamic management, and recognition that concern levels are not probabilities. Those protections are real but insufficient by themselves. Their effectiveness depends on local fidelity, legal constraints, service availability, data governance, and whether institutions are rewarded for restraint as well as vigilance. citeturn7view2turn7view4turn1search6

The evidence supports reporting and investigating concrete signs of target-focused planning, preparation, escalating pursuit, weapons activity linked to a contemplated act, and communications that plausibly reveal intent. It supports creating off-ramps through treatment, social support, conflict resolution, victim protection, and lawful means restriction. It does not support forecasting mass attackers from grievance, mental illness, autism, violent interests, political anger, social isolation, or checklist totals. It does not justify converting descriptive research on past attackers into individual probabilities.

The ethically and empirically sound objective is therefore not to identify every future attacker. That is unattainable. The objective is to recognize situations in which violence has become sufficiently plausible and sufficiently connected to observable conduct that proportionate, lawful, reviewable action can reduce harm—while preserving the presumption that unusual, distressed, unpopular, or angry people are not criminals in waiting.