Autonomous systems · Insurance · Risk topology

When the Driver Becomes Software

Autonomous vehicles will not merely reduce motor claims. They will move risk from millions of mostly independent human decisions into versioned, observable and correlated driving systems—and force insurance to become a continuous control loop.

The correlation inversion in motor insuranceTraditional motor insurance sees many independent human drivers and sparse annual claims. Autonomous mobility sees one software release connected to many vehicles and a continuous stream of telemetry, safety events, claims and fleet defects, with insurance controls fed back into deployment.TRADITIONAL MOTOR RISKMany drivers. Mostly local errors. ACCIDENT → CLAIM → RENEWALSparse observation · annual ratingHigh frequency · lower common causeTHE CORRELATION INVERSIONAUTONOMOUS MOBILITY RISKOne release. Many vehicles.ADS RELEASE 8.4.17policy · perception · maps · ODDCONTINUOUS INSURANCE CONTROL LOOPtelemetrysafety eventsclaimsfleet defectspricing · release gates · ODD limits · rollback · reinsuranceSafer in the mean. More connected in the tail.
Figure 1. Autonomous driving changes the statistical structure of motor risk. The number of vehicles may remain large, but the number of independent causal systems can collapse when one software release is copied across a fleet.

An autonomous car is not merely a car without a human driver. It is a vehicle whose driver can be copied, measured, updated, rolled back and shared by thousands of other vehicles.

That distinction changes insurance more profoundly than the familiar debate over whether liability moves from the individual driver to the manufacturer. Traditional motor insurance was built around a population of heterogeneous people making mostly local mistakes. Each policyholder has a different history, temperament, route, reaction time and appetite for risk. Weather, road design and congestion create common exposures, but most failures remain idiosyncratic.

Autonomous mobility reorganizes that pool. A mature driving system may generate far fewer collisions than human drivers. Yet vehicles running it can share the same perception model, planning policy, sensor generation, map release, operational rules and remote-operations stack. One latent defect can therefore exist in thousands of vehicles before it is visible in a conventional claim.

The portfolio can become safer in the mean and more fragile in the tail.

This is the correlation inversion. Human motor risk is relatively high-frequency and mostly local. Autonomous motor risk may become lower-frequency, more observable and more controllable, while also becoming more concentrated in shared technical causes. The central insurance question is no longer only, “How often does this car crash?” It becomes, “How many vehicles can fail for the same reason at the same time?”

The resulting institution will not look like ordinary fleet insurance with better telematics. It will combine motor liability, product risk, software assurance, cyber coverage, recall, business interruption and service guarantees. It will monitor the behavior of software cohorts. It will classify near misses and antisocial driving before they become claims. It will offer the public one simple route to compensation while reconstructing a complicated causal graph behind the scenes.

In the limit, insurance stops being a passive promise to reimburse losses and becomes part of the control system through which autonomous driving is deployed.

01

The wrong mental model

There are two common ways to think about autonomous-vehicle insurance. The first is that safer driving will reduce claim frequency and therefore reduce premiums. The second is that ownership will move toward robotaxi and logistics fleets, so personal motor insurance will become commercial fleet insurance.

Both are directionally plausible and conceptually incomplete.

The first treats autonomy as another safety feature, like automatic emergency braking. The second treats it as another ownership structure, like a rental fleet. Neither captures the change in the object doing the driving. Once the automated system performs the dynamic driving task, the relevant risk-bearing unit is no longer only a person paired with a vehicle. It is a continuously changing technical system operating inside a defined environment.

RISK TRANSFORMATION

Autonomy changes several dimensions at once

DimensionHuman-driven motorMature autonomous system
Collision frequencyHigh baselinePotentially much lower
ObservationSparse and post hocDense, event-level telemetry
Risk changeSlow; driver and vehicle ageInstant; software or ODD update
Immediate controlWeakGeofence, rollback, fleet restriction
Common causeUsually limitedPotentially fleet-wide
Fault reconstructionHuman testimony and physical evidenceVersioned machine evidence and causal graph
Figure 2. The important shift is not a single arrow from unsafe to safe. Frequency, observability, controllability and correlation move in different directions.

An insurer that looks only at average collision frequency will miss the tail. An insurer that looks only at the legal owner will miss the software cohort. One million privately owned cars running the same driving release may be one million policies and one statistical fleet.

The statistical fleet can exist before the corporate fleet.

02

Not all automation transfers the driver

Any analysis that collapses driver assistance and driverless operation into one category will produce the wrong liability model. NHTSA describes Level 2 systems as assistance that can provide speed and steering input while requiring the human to remain fully engaged. Automated driving systems encompass Levels 3 through 5 and aim, within a defined operational design domain, to perform the full dynamic driving task without driver involvement.1

LEVEL 2Human remains the driver

Software shares control, but attention, misuse and supervision remain central risks.

LEVEL 3Conditional transfer

The system drives in a domain but may request a human fallback, creating handoff risk.

LEVEL 4System drives in its ODD

No human fallback is required inside the defined domain; fleet and system liability become primary.

LEVEL 5Unbounded aspiration

The system is intended to drive everywhere a human could, removing most ODD segmentation.

A supervised consumer system therefore preserves the old ambiguity. The human remains legally and operationally central even when software heavily influences motion. A driverless Level 4 fleet exposes the new architecture directly: the “driver” is a product, a process and an operating organization.

This also means the SAE level is not enough for underwriting. A Level 4 system limited to mapped urban roads in dry daylight is not the same object as a Level 4 system allowed on freeways, in heavy rain or around active construction. Insurance needs the precise domain, not the marketing label.

03

The underwriting object becomes a versioned system

Traditional motor rating compresses a complicated reality into a manageable set of variables: driver, vehicle, territory, use, mileage and claims history. Those variables do not disappear, but the center of gravity moves.

driver × vehicle × territory
ADS release × hardware × ODD × operator × time

The operational design domain, or ODD, describes the circumstances in which the system is designed to drive: road type, geography, weather, lighting, traffic conditions, speed and other constraints. The same vehicle and software can be a different risk on a divided highway at noon than on an unmarked urban diversion in heavy rain. Raw mileage therefore becomes a weak denominator.

A more useful exposure measure would resemble risk-weighted autonomous miles. Each mile would be attached to the software release, sensor configuration, ODD state, maintenance condition, remote-assistance arrangement and traffic context that generated it.

AN ILLUSTRATIVE LOSS DECOMPOSITIONExpected loss = risk-weighted exposure × event frequency × severity + common-cause charge

The first three terms resemble conventional motor pricing. The last term prices the fact that many vehicles may share one latent defect. This is a conceptual architecture, not a regulatory formula.

INTERACTIVE · UNDERWRITING STACK

Click the layer that changes

The VIN is no longer enough

Insurer asks
Figure 3. The insured object is a configuration, not a static vehicle. A useful exposure registry must reconstruct that configuration at any moment.

This changes the timescale of underwriting. A human driver’s risk profile usually drifts. A software fleet can change overnight. The premium may still be invoiced monthly or annually, but the model underneath it becomes continuous.

04

Frequency can fall sharply

The empirical case for autonomous driving begins with a plausible mechanism: machines do not become intoxicated, sleepy, distracted or emotionally aggressive. They can maintain continuous attention, react consistently and learn from events observed elsewhere in the fleet. If the system is competent, removing human error should remove a large share of collisions.

The strongest public insurance-linked result so far comes from research by Waymo and Swiss Re. Across 25.3 million fully autonomous miles, the study reported nine property-damage claims and two bodily-injury claims. Its human-driver benchmark predicted 78 property-damage and 26 bodily-injury claims over the same distance—reductions of 88% and 92%, respectively.2

CLAIMS AT 25.3 MILLION MILES

Observed Waymo claims versus the human benchmark

Property damage
78
Human expected
9
Waymo observed
88% fewer
Bodily injury
26
Human expected
2
Waymo observed
92% fewer

The two panels use separate scales. Counts are shown directly; the comparison is based on liability claims, not every contact or safety-relevant event.

Figure 4. The result is strong evidence about one system operating in selected U.S. domains. It is not a universal estimate for every autonomous-driving system, road network or deployment model.

The caveat is not cosmetic. Autonomous systems are deployed selectively. Their routes, speeds, weather exposure and reporting capabilities differ from the human population. NHTSA warns that public crash data should not be treated as directly comparable across companies because telemetry access and reporting awareness vary, and because incident counts are not normalized by miles, fleet size or ODD.1

There is also a subtler economic effect. Highway Loss Data Institute research on advanced driver-assistance bundles found substantial reductions in claim frequency while many systems were associated with higher average claim severity. Expensive sensors and components contribute, but the mix also changes because safety systems remove many low-speed, low-dollar crashes from the denominator. Overall losses generally still fell.3

01Frequency can fall

Fewer ordinary collisions and fewer small claims.

02Remaining claims can cost more

High-value components, calibration and a changed mix of crashes.

03The tail can thicken

A shared defect can connect losses that looked diversified.

The insurer should resist a simple story in which safer cars merely shrink an existing book. Expected loss can fall while the architecture required to understand and control the remaining risk becomes far more demanding.

05

Correlation becomes the new catastrophe

A human driver makes a bad merge. One car is involved. An autonomous system contains a bad merge policy. Every vehicle running that policy may be involved.

The distinction is not that software is uniquely fallible. Mechanical components have always produced recalls, and motor portfolios already face weather catastrophes and pileups. The difference is that driving software participates in a high-frequency stream of context-sensitive decisions, can be updated rapidly and can create the same behavioral tendency across geographically dispersed vehicles.

CAUSAL CONCENTRATION

A portfolio of vehicles can be a single technical exposure

HUMAN DRIVERSSHARED ADS RELEASEeight policies · eight mostly local causesRELEASE 8.4one latent policy defectmany policies · one common technical cause
Figure 5. Diversification must be measured in causal systems, not vehicle count. A geographically distributed fleet can remain highly concentrated if its behavior is generated by the same release.

This is already visible in real deployment. A June 2026 NHTSA recall covered 3,871 fifth-generation Waymo automated-driving systems capable of driverless freeway operation. The filing described circumstances in which vehicles could enter active freeway construction zones after failing to recognize closures or prioritizing other hazards. Its chronology included multiple Phoenix events and a San Francisco Bay Area incident in which seven vehicles entered closed lanes. The remedy combined software improvements with operational protocols.4

A July 2026 Zoox recall covered 105 automated-driving systems because the software might fail to detect and respond to heavy smoke near an active emergency scene. The filing described an unoccupied vehicle entering the smoke-obscured scene, braking hard and then reversing under remote guidance. The remedy was deployed as a software update across the affected fleet.5

These filings do not imply that either system is broadly unsafe. They illustrate the insurance unit. The relevant exposure was not an individual driver with a poor history. It was a behavior shared by a release cohort. The remedy was not driver training. It was a fleet restriction, root-cause investigation, software change and revised operating protocol.

Policy and reinsurance language will eventually need an explicit definition of a common-cause autonomous event. Possible anchors include one software release, model family, sensor-generation defect, map failure, cloud outage, cyber compromise or regulatory grounding order. Without a causal event definition, a hundred losses may be handled as a hundred ordinary motor claims even when they are economically one event.

THE NEW ACCUMULATION QUESTIONHow much of the portfolio can change behavior in the same software-deployment window?
06

A car can be dangerous without crashing

Conventional claims data begin after something has gone wrong enough to create damage. Autonomous fleets produce a much richer field of evidence before that threshold.

Consider a vehicle that cuts into a lane and forces the following driver to brake hard. No vehicles touch. No property is damaged. There is usually no ordinary motor claim. Yet the maneuver reveals something important about the driving policy. If the same behavior appears repeatedly across a software cohort, the insurer has observed a latent loss mechanism before the loss.

The key distinction is between a claim event and a safety event. A collision, injury or damaged object is a loss event. A forced-braking conflict or right-of-way violation can be a safety event. A stranded passenger or unacceptable trip can be a service event. Recurrence of the same behavior across a release can be a systemic fleet event.

INTERACTIVE · EVENT LOGIC

What kind of event just happened?

Claim ≠ every safety signal
AV
H
!

Primary response
Evidence needed
Figure 6. A modern insurer needs an event ontology broader than the claims ledger. The purpose is not to compensate every uncomfortable maneuver, but to detect behaviors that predict future loss or indicate a fleet-wide defect.

Traffic-safety research already uses surrogate measures to study conflicts that do not become crashes. The Federal Highway Administration’s Surrogate Safety Assessment Model includes time-to-collision, post-encroachment time, deceleration rates, speed differentials and conflict type.7 An autonomous fleet can record related measures continuously rather than waiting for years of collision history.

The insurer should go further and measure roadmanship risk: not only the danger absorbed by the autonomous vehicle, but the danger it imposes on other road users. A system might reduce its own contact rate by making humans resolve ambiguity around it—braking, swerving, yielding unnecessarily or accepting smaller gaps. Its internal collision statistics could improve while the road system absorbs the externalized risk.

THE EVENT PYRAMID

Claims are the visible tip of a much larger behavioral stream

Severe lossinjury · major property damage
Ordinary claimcollision · minor damage
Near missevasive action · critical conflict
Roadmanship eventforced braking · unsafe gap · right-of-way failure
Telemetry anomalyuncertainty · sensor degradation · policy drift
Figure 7. Lower layers occur more frequently and provide earlier evidence. The challenge is to identify which signals are predictive rather than merely abundant.

This is why “edge case” is often the wrong institutional category. In July 2026, NHTSA told driverless-system developers that it had observed a pattern of vehicles interfering with emergency responders and argued that flashing lights, flares, smoke, fire and traffic cones were not rare extreme cases but ordinary safety conditions systems must handle.6

A repeated failure around emergency scenes may produce no insured loss on the first occasion. It is still insurance-relevant because it changes the estimated hazard of the fleet.

07

The claims file becomes a causal graph

Traditional claims handling asks who owned the vehicles, who was driving, what each person did and how much damage followed. Autonomous claims preserve those questions and add a technical chain.

The relevant parties can include the automated-driving developer, vehicle manufacturer, fleet owner, operator, maintenance and calibration provider, mapping or localization provider, remote-assistance team, telecommunications or cloud vendor, passenger, roadway operator and other road users. Responsibility can be distributed across design, deployment, maintenance and real-time operation.

CAUSAL RECONSTRUCTION

One public claim, many possible technical causes

Injured partyone claims doorfast compensationInsurerpay firstallocate laterADS developerpolicy · model · releaseVehicle OEMplatform · integrationFleet operatordispatch · ODD · proceduresMaintenancecalibration · repairMaps / cloudcontext · availabilityRemote operationsguidance · escalationEVENT PACKAGEAutonomous incidenttrajectory · video · release · ODDsensor state · remote actions · damage
Figure 8. The claimant should not be required to solve this graph. The insurer can provide a simple front end, then use technical evidence and subrogation to allocate the loss among responsible parties.

This creates two distinct questions: Who pays the victim first? and Who ultimately bears the loss? Conflating them would make autonomous claims slow and adversarial. A pedestrian should not need to identify whether the relevant failure occurred in planning software, sensor calibration, fleet operations or roadway data before receiving compensation.

The United Kingdom provides one institutional model. Its 2018 automated-vehicle legislation places first-instance liability on the insurer for accidents caused while an insured automated vehicle is driving itself, while preserving recovery against other responsible parties.8 The 2024 framework separately establishes an authorised self-driving entity responsible for how the vehicle drives while the automated feature is engaged.9

The specific legal answer will vary by jurisdiction, but the architecture is compelling: one claims door for the public; a sophisticated liability graph behind it.

That graph requires a standard evidence package. At minimum, the insurer should reconstruct the exact automated-driving release, map and policy versions, ODD state, sensor health, calibration and maintenance state, trajectory, relevant object predictions, planning decision, remote-assistance interaction, fallback behavior and known related events elsewhere in the cohort.

This does not necessarily require insurers to possess source code or model weights. It does require tamper-evident records, stable identifiers and enough technical access to test the causal claims made by every party. Otherwise the company that designed the driver also controls the only evidence about what the driver did.

08

The motor policy becomes an autonomous-mobility program

A conventional motor policy divides the world into familiar coverages: third-party liability, collision, comprehensive, personal injury and related extensions. Autonomous mobility creates losses that cross those boundaries.

A collision may begin as motor liability, become a product-liability dispute, reveal a software defect, require a fleet-wide remediation campaign and ground operations long enough to create business interruption. A cyber event can change vehicle behavior without damaging the vehicle. A safe shutdown can avoid physical loss while stranding thousands of passengers. A regulator can restrict a fleet after a pattern of safety events that have not yet produced many claims.

COVERAGE ARCHITECTURE

One mobility service, several risk layers

01Public compensation

Third-party motor liability · passenger injury · physical damage

02Technical responsibility

Product liability · technology E&O · maintenance and calibration

03System integrity

Cyber · cloud dependency · data corruption · remote operations

04Fleet continuity

Recall · remediation · regulatory grounding · business interruption

05Mobility performance

Service credits · trip failure · stranded passengers · safety guarantees

Figure 9. The program can still be assembled from existing insurance lines, but boundaries, triggers and causal-event definitions must be designed together.

The last layer is easy to misunderstand. An uncomfortable stop or delayed trip should not be converted into a bodily-injury claim. Yet commercial autonomous services may need a contractual or parametric performance layer that pays for defined failures in mobility service. This keeps service quality separate from tort liability while making it financially visible.

Release cohort

Vehicles, hardware and models governed by a defined family of software or policy versions.

Common-cause event

Losses attributable to one defect, deployment, compromise or dependency failure.

Fleet-grounding event

A voluntary or mandated restriction that removes defined vehicles or ODDs from service.

Safety-performance breach

A measured pattern of behavior outside agreed roadmanship or operational thresholds.

The annual policy does not necessarily disappear. Insurance law, capital planning and commercial procurement still favor stable contracts. What changes is the logic inside the contract: risk can be segmented by version, coverage can attach to a changing cohort, and controls can trigger during the policy period.

A fleet-wide software update becomes economically similar to changing the insured machinery. A material ODD expansion resembles adding a new territory or operation. An insurer that cannot observe either event is underwriting a moving object with a static form.

09

Insurance becomes part of the control system

Motor insurance has traditionally been reactive. It prices a class, waits for losses, adjusts reserves and learns at renewal. Autonomous fleets make a faster loop possible—and eventually necessary.

The system can produce continuous exposure data, near-miss signals and cohort comparisons. The operator can restrict geography, slow a deployment, roll back a release or change remote-operations procedures within hours. The insurer can make those capabilities conditions of coverage rather than merely observing them after a loss.

THE INSURANCE FEEDBACK LOOP

From reimbursement after failure to governance before loss

01Fleet behaviortrips · ODD · versions
02Event registryclaims · conflicts · anomalies
03Risk modelfrequency · severity · correlation
04Controlsprice · limits · release gates
↩ ODD restrictions · rollback · remediation · reinsurance
Figure 10. The insurer does not replace the regulator or safety engineer. It adds a capital-and-contract layer that can make safe deployment practices economically mandatory.
SignalInterpretationPossible response
Conflict rate rises after releaseBehavioral regressionPause rollout; canary or rollback
One ODD dominates severe eventsContext concentrationRestrict conditions; reprice exposure
Sensor health driftsMaintenance hazardMandatory calibration or withdrawal
Roadmanship score deterioratesRisk imposed on othersBehavioral-remediation threshold
Portfolio concentrates on one cohortAccumulation riskCommon-cause limit and reinsurance
INTERACTIVE · RISK TOPOLOGY

Lower ordinary loss does not eliminate accumulation

Illustrative, not actuarial
Ordinary loss index34Human baseline = 100
Simultaneous fleet exposure42%largest cohort × defect reach
Suggested insurance architecture

Figure 11. The ordinary loss index multiplies remaining frequency by severity. Simultaneous exposure is not expected loss; it is a simple view of how much of the fleet could share one defect.

Safety standards offer an interface for this role. ISO 21448 frames the safety of intended functionality around unreasonable risk caused by specification or performance insufficiencies and includes operational-phase activities needed to maintain safety.10 UL 4600 centers a safety argument and addresses risk analysis, testing, autonomy validation, data integrity and human-machine interaction, while remaining technology-neutral and not defining one universal threshold of acceptable risk.11

The insurer can use these safety cases without pretending they eliminate uncertainty. A safety case explains why a system is believed to be acceptably safe. Insurance prices the possibility that the argument is incomplete, deployment differs from the argument, or the environment reveals a failure testing did not.

10

The insurer becomes a new kind of institution

The strategic value of autonomous insurance may not come from writing a familiar motor policy at a lower price. It may come from becoming the trusted institution that can compare driving systems across companies while protecting proprietary data.

Individual developers know their own fleets deeply. Regulators can compel information and enforce minimum standards. But neither necessarily has the cross-fleet claims history, capital model, subrogation machinery and incentive to translate technical behavior into monetary risk. An insurer or reinsurer can sit at that junction.

01

A versioned exposure registry

Every insured trip can be joined to the vehicle, hardware, ADS release, map, ODD, maintenance state and operator controls that produced it.

02

A shared event ontology

Losses, near misses, roadmanship conflicts, service failures and systemic defects are recorded separately but linked causally.

03

A neutral evidence layer

Tamper-evident logs, stable identifiers and auditable event packages prevent any one party from owning the facts of the claim.

04

A common-cause capital layer

Limits, reinsurance and possibly capital-market structures absorb release-level, cyber and grounding accumulation.

Data access is the decisive bargaining issue. If the insurer receives only a mileage total and curated safety report, it cannot independently price the driving configuration. It knows the chassis but not the driver.

This creates a disintermediation trap. The autonomous-driving company observes behavior, controls the update channel, owns the customer relationship and may retain most predictable risk. The insurer is invited only to supply regulated capacity for extreme losses. In that world, the insurer becomes a commodity balance sheet.

The alternative is to own the cross-system risk language. The insurer develops the event taxonomy, defines the data contract, prices correlation, audits release governance, maintains the causal claims graph and offers the public a trusted compensation interface. The premium pool may become smaller as roads become safer, but the institutional role can become more central.

Autonomous mobility may shrink the amount of motor risk while increasing the value of whoever can measure and govern it.

This is the fundamental shift. Insurance was historically a mechanism for pooling uncertainty that could not be observed or controlled at the individual level. Autonomous systems make much of that risk observable and controllable—but create new uncertainty about shared causes, model behavior and tail dependence. The insurer’s job moves up the stack, from estimating average driver behavior to governing technical systems whose risk changes in real time.

11

What could break this thesis

The correlation inversion is a structural possibility, not a forecast that every market will arrive at the same institutional endpoint.

Driver assistance may dominate for longer than expected.

If Level 2 remains the main commercial form, human attention, misuse and handoff ambiguity stay central. New technical risks layer onto old driver risk rather than replacing it.

Developers may retain the risk.

Large operators can self-insure predictable losses, purchase only excess capacity and keep the data. Insurance would migrate toward reinsurance, catastrophe and fronting.

Fast rollback may reduce correlation.

A shared defect creates common exposure, but centralized control also allows rapid detection, restriction and remediation. The same architecture that correlates risk can contain it.

Regulation may allocate responsibility directly.

Some jurisdictions may make manufacturers or authorised system entities bear most driving liability, leaving motor insurers with a smaller public-compensation role.

Safety gains may overwhelm every other effect.

If severe losses decline by an order of magnitude and common-cause events remain rare, the economic story may simply be a much smaller motor market.

The data may never become portable.

Without standardized event access, each insurer will depend on private bilateral reports and the cross-fleet benchmark may fail to emerge.

These are not objections to the argument. They determine who captures the value. The core shift still holds whenever multiple vehicles share a continuously updated driving system: independence assumptions beneath traditional motor insurance weaken, and version-level technical governance becomes relevant to the portfolio.

12

The thesis

Autonomous driving is usually described as a substitution: software replaces the driver. For insurance, it is better understood as a transformation in risk topology.

01

The insured driver becomes copyable. A software release can govern thousands of vehicles, including vehicles with separate owners and policies.

02

The unit of underwriting becomes a configuration. Release, hardware, ODD, operator and time matter more than the VIN alone.

03

Claims become the top of an event hierarchy. Near misses, roadmanship failures and telemetry anomalies become leading indicators without automatically becoming compensable losses.

04

Average loss can fall while tail dependence rises. A safer fleet can still require explicit common-cause capital and reinsurance.

05

The public interface should become simpler. One insurer can compensate the victim first while allocating responsibility through a technical causal graph.

06

Insurance becomes a feedback controller. Pricing, coverage and capital are linked to release gates, ODD limits, maintenance, rollback and remediation.

The future insurer will not merely ask whether autonomous vehicles are safer than humans. It will ask what kind of safety they produce, where that safety fails, how risk is imposed on everyone around the vehicle, and how many vehicles share the same reason for failure.

That insurer may collect less premium per mile. It may also become part of the institutional machinery that makes machine driving legible, compensable and governable.

When the driver becomes software, insurance becomes systems engineering.
S

Sources and notes

  1. NHTSA, “Standing General Order on Crash Reporting.” Used for the ADS/Level 2 distinction, reporting rules and limits of cross-company crash data.
  2. Di Lillo et al., “Do Autonomous Vehicles Outperform Latest-Generation Human-Driven Vehicles?” The result is specific to the evaluated deployments and comparison baseline.
  3. IIHS / HLDI, “Safety benefits stack up from driver assistance features,” March 26, 2026.
  4. NHTSA Safety Recall Report 26E035, Waymo LLC, June 17, 2026.
  5. NHTSA Safety Recall Report 26E044, Zoox, July 16, 2026.
  6. NHTSA, letter to Driverless ADS Developers, July 8, 2026.
  7. FHWA, “Surrogate Safety Assessment Model.”
  8. United Kingdom, Automated and Electric Vehicles Act 2018, explanatory notes.
  9. United Kingdom, Automated Vehicles Act 2024, explanatory notes.
  10. ISO 21448:2022, Road vehicles — Safety of the intended functionality.
  11. UL Standards & Engagement, “Underwriters Laboratories Publishes UL 4600 Autonomous Vehicle Standard.”

Charts labeled illustrative are conceptual tools created for this essay. They should not be used to price a policy, set reserves or infer the safety of an unevaluated autonomous-driving system.

Link copied