When the Driver Becomes Software
Autonomous vehicles will not merely reduce motor claims. They will move risk from millions of mostly independent human decisions into versioned, observable and correlated driving systems—and force insurance to become a continuous control loop.
An autonomous car is not merely a car without a human driver. It is a vehicle whose driver can be copied, measured, updated, rolled back and shared by thousands of other vehicles.
That distinction changes insurance more profoundly than the familiar debate over whether liability moves from the individual driver to the manufacturer. Traditional motor insurance was built around a population of heterogeneous people making mostly local mistakes. Each policyholder has a different history, temperament, route, reaction time and appetite for risk. Weather, road design and congestion create common exposures, but most failures remain idiosyncratic.
Autonomous mobility reorganizes that pool. A mature driving system may generate far fewer collisions than human drivers. Yet vehicles running it can share the same perception model, planning policy, sensor generation, map release, operational rules and remote-operations stack. One latent defect can therefore exist in thousands of vehicles before it is visible in a conventional claim.
The portfolio can become safer in the mean and more fragile in the tail.
This is the correlation inversion. Human motor risk is relatively high-frequency and mostly local. Autonomous motor risk may become lower-frequency, more observable and more controllable, while also becoming more concentrated in shared technical causes. The central insurance question is no longer only, “How often does this car crash?” It becomes, “How many vehicles can fail for the same reason at the same time?”
The resulting institution will not look like ordinary fleet insurance with better telematics. It will combine motor liability, product risk, software assurance, cyber coverage, recall, business interruption and service guarantees. It will monitor the behavior of software cohorts. It will classify near misses and antisocial driving before they become claims. It will offer the public one simple route to compensation while reconstructing a complicated causal graph behind the scenes.
In the limit, insurance stops being a passive promise to reimburse losses and becomes part of the control system through which autonomous driving is deployed.
The wrong mental model
There are two common ways to think about autonomous-vehicle insurance. The first is that safer driving will reduce claim frequency and therefore reduce premiums. The second is that ownership will move toward robotaxi and logistics fleets, so personal motor insurance will become commercial fleet insurance.
Both are directionally plausible and conceptually incomplete.
The first treats autonomy as another safety feature, like automatic emergency braking. The second treats it as another ownership structure, like a rental fleet. Neither captures the change in the object doing the driving. Once the automated system performs the dynamic driving task, the relevant risk-bearing unit is no longer only a person paired with a vehicle. It is a continuously changing technical system operating inside a defined environment.
Autonomy changes several dimensions at once
An insurer that looks only at average collision frequency will miss the tail. An insurer that looks only at the legal owner will miss the software cohort. One million privately owned cars running the same driving release may be one million policies and one statistical fleet.
The statistical fleet can exist before the corporate fleet.
Not all automation transfers the driver
Any analysis that collapses driver assistance and driverless operation into one category will produce the wrong liability model. NHTSA describes Level 2 systems as assistance that can provide speed and steering input while requiring the human to remain fully engaged. Automated driving systems encompass Levels 3 through 5 and aim, within a defined operational design domain, to perform the full dynamic driving task without driver involvement.1
Software shares control, but attention, misuse and supervision remain central risks.
The system drives in a domain but may request a human fallback, creating handoff risk.
No human fallback is required inside the defined domain; fleet and system liability become primary.
The system is intended to drive everywhere a human could, removing most ODD segmentation.
A supervised consumer system therefore preserves the old ambiguity. The human remains legally and operationally central even when software heavily influences motion. A driverless Level 4 fleet exposes the new architecture directly: the “driver” is a product, a process and an operating organization.
This also means the SAE level is not enough for underwriting. A Level 4 system limited to mapped urban roads in dry daylight is not the same object as a Level 4 system allowed on freeways, in heavy rain or around active construction. Insurance needs the precise domain, not the marketing label.
The underwriting object becomes a versioned system
Traditional motor rating compresses a complicated reality into a manageable set of variables: driver, vehicle, territory, use, mileage and claims history. Those variables do not disappear, but the center of gravity moves.
driver × vehicle × territoryADS release × hardware × ODD × operator × timeThe operational design domain, or ODD, describes the circumstances in which the system is designed to drive: road type, geography, weather, lighting, traffic conditions, speed and other constraints. The same vehicle and software can be a different risk on a divided highway at noon than on an unmarked urban diversion in heavy rain. Raw mileage therefore becomes a weak denominator.
A more useful exposure measure would resemble risk-weighted autonomous miles. Each mile would be attached to the software release, sensor configuration, ODD state, maintenance condition, remote-assistance arrangement and traffic context that generated it.
Expected loss = risk-weighted exposure × event frequency × severity + common-cause chargeThe first three terms resemble conventional motor pricing. The last term prices the fact that many vehicles may share one latent defect. This is a conceptual architecture, not a regulatory formula.
Click the layer that changes
This changes the timescale of underwriting. A human driver’s risk profile usually drifts. A software fleet can change overnight. The premium may still be invoiced monthly or annually, but the model underneath it becomes continuous.
Frequency can fall sharply
The empirical case for autonomous driving begins with a plausible mechanism: machines do not become intoxicated, sleepy, distracted or emotionally aggressive. They can maintain continuous attention, react consistently and learn from events observed elsewhere in the fleet. If the system is competent, removing human error should remove a large share of collisions.
The strongest public insurance-linked result so far comes from research by Waymo and Swiss Re. Across 25.3 million fully autonomous miles, the study reported nine property-damage claims and two bodily-injury claims. Its human-driver benchmark predicted 78 property-damage and 26 bodily-injury claims over the same distance—reductions of 88% and 92%, respectively.2
Observed Waymo claims versus the human benchmark
The two panels use separate scales. Counts are shown directly; the comparison is based on liability claims, not every contact or safety-relevant event.
The caveat is not cosmetic. Autonomous systems are deployed selectively. Their routes, speeds, weather exposure and reporting capabilities differ from the human population. NHTSA warns that public crash data should not be treated as directly comparable across companies because telemetry access and reporting awareness vary, and because incident counts are not normalized by miles, fleet size or ODD.1
There is also a subtler economic effect. Highway Loss Data Institute research on advanced driver-assistance bundles found substantial reductions in claim frequency while many systems were associated with higher average claim severity. Expensive sensors and components contribute, but the mix also changes because safety systems remove many low-speed, low-dollar crashes from the denominator. Overall losses generally still fell.3
Fewer ordinary collisions and fewer small claims.
High-value components, calibration and a changed mix of crashes.
A shared defect can connect losses that looked diversified.
The insurer should resist a simple story in which safer cars merely shrink an existing book. Expected loss can fall while the architecture required to understand and control the remaining risk becomes far more demanding.
Correlation becomes the new catastrophe
A human driver makes a bad merge. One car is involved. An autonomous system contains a bad merge policy. Every vehicle running that policy may be involved.
The distinction is not that software is uniquely fallible. Mechanical components have always produced recalls, and motor portfolios already face weather catastrophes and pileups. The difference is that driving software participates in a high-frequency stream of context-sensitive decisions, can be updated rapidly and can create the same behavioral tendency across geographically dispersed vehicles.
A portfolio of vehicles can be a single technical exposure
This is already visible in real deployment. A June 2026 NHTSA recall covered 3,871 fifth-generation Waymo automated-driving systems capable of driverless freeway operation. The filing described circumstances in which vehicles could enter active freeway construction zones after failing to recognize closures or prioritizing other hazards. Its chronology included multiple Phoenix events and a San Francisco Bay Area incident in which seven vehicles entered closed lanes. The remedy combined software improvements with operational protocols.4
A July 2026 Zoox recall covered 105 automated-driving systems because the software might fail to detect and respond to heavy smoke near an active emergency scene. The filing described an unoccupied vehicle entering the smoke-obscured scene, braking hard and then reversing under remote guidance. The remedy was deployed as a software update across the affected fleet.5
These filings do not imply that either system is broadly unsafe. They illustrate the insurance unit. The relevant exposure was not an individual driver with a poor history. It was a behavior shared by a release cohort. The remedy was not driver training. It was a fleet restriction, root-cause investigation, software change and revised operating protocol.
Policy and reinsurance language will eventually need an explicit definition of a common-cause autonomous event. Possible anchors include one software release, model family, sensor-generation defect, map failure, cloud outage, cyber compromise or regulatory grounding order. Without a causal event definition, a hundred losses may be handled as a hundred ordinary motor claims even when they are economically one event.
A car can be dangerous without crashing
Conventional claims data begin after something has gone wrong enough to create damage. Autonomous fleets produce a much richer field of evidence before that threshold.
Consider a vehicle that cuts into a lane and forces the following driver to brake hard. No vehicles touch. No property is damaged. There is usually no ordinary motor claim. Yet the maneuver reveals something important about the driving policy. If the same behavior appears repeatedly across a software cohort, the insurer has observed a latent loss mechanism before the loss.
The key distinction is between a claim event and a safety event. A collision, injury or damaged object is a loss event. A forced-braking conflict or right-of-way violation can be a safety event. A stranded passenger or unacceptable trip can be a service event. Recurrence of the same behavior across a release can be a systemic fleet event.
What kind of event just happened?
Traffic-safety research already uses surrogate measures to study conflicts that do not become crashes. The Federal Highway Administration’s Surrogate Safety Assessment Model includes time-to-collision, post-encroachment time, deceleration rates, speed differentials and conflict type.7 An autonomous fleet can record related measures continuously rather than waiting for years of collision history.
The insurer should go further and measure roadmanship risk: not only the danger absorbed by the autonomous vehicle, but the danger it imposes on other road users. A system might reduce its own contact rate by making humans resolve ambiguity around it—braking, swerving, yielding unnecessarily or accepting smaller gaps. Its internal collision statistics could improve while the road system absorbs the externalized risk.
Claims are the visible tip of a much larger behavioral stream
This is why “edge case” is often the wrong institutional category. In July 2026, NHTSA told driverless-system developers that it had observed a pattern of vehicles interfering with emergency responders and argued that flashing lights, flares, smoke, fire and traffic cones were not rare extreme cases but ordinary safety conditions systems must handle.6
A repeated failure around emergency scenes may produce no insured loss on the first occasion. It is still insurance-relevant because it changes the estimated hazard of the fleet.
The claims file becomes a causal graph
Traditional claims handling asks who owned the vehicles, who was driving, what each person did and how much damage followed. Autonomous claims preserve those questions and add a technical chain.
The relevant parties can include the automated-driving developer, vehicle manufacturer, fleet owner, operator, maintenance and calibration provider, mapping or localization provider, remote-assistance team, telecommunications or cloud vendor, passenger, roadway operator and other road users. Responsibility can be distributed across design, deployment, maintenance and real-time operation.
One public claim, many possible technical causes
This creates two distinct questions: Who pays the victim first? and Who ultimately bears the loss? Conflating them would make autonomous claims slow and adversarial. A pedestrian should not need to identify whether the relevant failure occurred in planning software, sensor calibration, fleet operations or roadway data before receiving compensation.
The United Kingdom provides one institutional model. Its 2018 automated-vehicle legislation places first-instance liability on the insurer for accidents caused while an insured automated vehicle is driving itself, while preserving recovery against other responsible parties.8 The 2024 framework separately establishes an authorised self-driving entity responsible for how the vehicle drives while the automated feature is engaged.9
The specific legal answer will vary by jurisdiction, but the architecture is compelling: one claims door for the public; a sophisticated liability graph behind it.
That graph requires a standard evidence package. At minimum, the insurer should reconstruct the exact automated-driving release, map and policy versions, ODD state, sensor health, calibration and maintenance state, trajectory, relevant object predictions, planning decision, remote-assistance interaction, fallback behavior and known related events elsewhere in the cohort.
This does not necessarily require insurers to possess source code or model weights. It does require tamper-evident records, stable identifiers and enough technical access to test the causal claims made by every party. Otherwise the company that designed the driver also controls the only evidence about what the driver did.
The motor policy becomes an autonomous-mobility program
A conventional motor policy divides the world into familiar coverages: third-party liability, collision, comprehensive, personal injury and related extensions. Autonomous mobility creates losses that cross those boundaries.
A collision may begin as motor liability, become a product-liability dispute, reveal a software defect, require a fleet-wide remediation campaign and ground operations long enough to create business interruption. A cyber event can change vehicle behavior without damaging the vehicle. A safe shutdown can avoid physical loss while stranding thousands of passengers. A regulator can restrict a fleet after a pattern of safety events that have not yet produced many claims.
One mobility service, several risk layers
Third-party motor liability · passenger injury · physical damage
Product liability · technology E&O · maintenance and calibration
Cyber · cloud dependency · data corruption · remote operations
Recall · remediation · regulatory grounding · business interruption
Service credits · trip failure · stranded passengers · safety guarantees
The last layer is easy to misunderstand. An uncomfortable stop or delayed trip should not be converted into a bodily-injury claim. Yet commercial autonomous services may need a contractual or parametric performance layer that pays for defined failures in mobility service. This keeps service quality separate from tort liability while making it financially visible.
Vehicles, hardware and models governed by a defined family of software or policy versions.
Losses attributable to one defect, deployment, compromise or dependency failure.
A voluntary or mandated restriction that removes defined vehicles or ODDs from service.
A measured pattern of behavior outside agreed roadmanship or operational thresholds.
The annual policy does not necessarily disappear. Insurance law, capital planning and commercial procurement still favor stable contracts. What changes is the logic inside the contract: risk can be segmented by version, coverage can attach to a changing cohort, and controls can trigger during the policy period.
A fleet-wide software update becomes economically similar to changing the insured machinery. A material ODD expansion resembles adding a new territory or operation. An insurer that cannot observe either event is underwriting a moving object with a static form.
Insurance becomes part of the control system
Motor insurance has traditionally been reactive. It prices a class, waits for losses, adjusts reserves and learns at renewal. Autonomous fleets make a faster loop possible—and eventually necessary.
The system can produce continuous exposure data, near-miss signals and cohort comparisons. The operator can restrict geography, slow a deployment, roll back a release or change remote-operations procedures within hours. The insurer can make those capabilities conditions of coverage rather than merely observing them after a loss.
From reimbursement after failure to governance before loss
Lower ordinary loss does not eliminate accumulation
Safety standards offer an interface for this role. ISO 21448 frames the safety of intended functionality around unreasonable risk caused by specification or performance insufficiencies and includes operational-phase activities needed to maintain safety.10 UL 4600 centers a safety argument and addresses risk analysis, testing, autonomy validation, data integrity and human-machine interaction, while remaining technology-neutral and not defining one universal threshold of acceptable risk.11
The insurer can use these safety cases without pretending they eliminate uncertainty. A safety case explains why a system is believed to be acceptably safe. Insurance prices the possibility that the argument is incomplete, deployment differs from the argument, or the environment reveals a failure testing did not.
The insurer becomes a new kind of institution
The strategic value of autonomous insurance may not come from writing a familiar motor policy at a lower price. It may come from becoming the trusted institution that can compare driving systems across companies while protecting proprietary data.
Individual developers know their own fleets deeply. Regulators can compel information and enforce minimum standards. But neither necessarily has the cross-fleet claims history, capital model, subrogation machinery and incentive to translate technical behavior into monetary risk. An insurer or reinsurer can sit at that junction.
A versioned exposure registry
Every insured trip can be joined to the vehicle, hardware, ADS release, map, ODD, maintenance state and operator controls that produced it.
A shared event ontology
Losses, near misses, roadmanship conflicts, service failures and systemic defects are recorded separately but linked causally.
A neutral evidence layer
Tamper-evident logs, stable identifiers and auditable event packages prevent any one party from owning the facts of the claim.
A common-cause capital layer
Limits, reinsurance and possibly capital-market structures absorb release-level, cyber and grounding accumulation.
Data access is the decisive bargaining issue. If the insurer receives only a mileage total and curated safety report, it cannot independently price the driving configuration. It knows the chassis but not the driver.
This creates a disintermediation trap. The autonomous-driving company observes behavior, controls the update channel, owns the customer relationship and may retain most predictable risk. The insurer is invited only to supply regulated capacity for extreme losses. In that world, the insurer becomes a commodity balance sheet.
The alternative is to own the cross-system risk language. The insurer develops the event taxonomy, defines the data contract, prices correlation, audits release governance, maintains the causal claims graph and offers the public a trusted compensation interface. The premium pool may become smaller as roads become safer, but the institutional role can become more central.
Autonomous mobility may shrink the amount of motor risk while increasing the value of whoever can measure and govern it.
This is the fundamental shift. Insurance was historically a mechanism for pooling uncertainty that could not be observed or controlled at the individual level. Autonomous systems make much of that risk observable and controllable—but create new uncertainty about shared causes, model behavior and tail dependence. The insurer’s job moves up the stack, from estimating average driver behavior to governing technical systems whose risk changes in real time.
What could break this thesis
The correlation inversion is a structural possibility, not a forecast that every market will arrive at the same institutional endpoint.
If Level 2 remains the main commercial form, human attention, misuse and handoff ambiguity stay central. New technical risks layer onto old driver risk rather than replacing it.
Large operators can self-insure predictable losses, purchase only excess capacity and keep the data. Insurance would migrate toward reinsurance, catastrophe and fronting.
A shared defect creates common exposure, but centralized control also allows rapid detection, restriction and remediation. The same architecture that correlates risk can contain it.
Some jurisdictions may make manufacturers or authorised system entities bear most driving liability, leaving motor insurers with a smaller public-compensation role.
If severe losses decline by an order of magnitude and common-cause events remain rare, the economic story may simply be a much smaller motor market.
Without standardized event access, each insurer will depend on private bilateral reports and the cross-fleet benchmark may fail to emerge.
These are not objections to the argument. They determine who captures the value. The core shift still holds whenever multiple vehicles share a continuously updated driving system: independence assumptions beneath traditional motor insurance weaken, and version-level technical governance becomes relevant to the portfolio.
The thesis
Autonomous driving is usually described as a substitution: software replaces the driver. For insurance, it is better understood as a transformation in risk topology.
The insured driver becomes copyable. A software release can govern thousands of vehicles, including vehicles with separate owners and policies.
The unit of underwriting becomes a configuration. Release, hardware, ODD, operator and time matter more than the VIN alone.
Claims become the top of an event hierarchy. Near misses, roadmanship failures and telemetry anomalies become leading indicators without automatically becoming compensable losses.
Average loss can fall while tail dependence rises. A safer fleet can still require explicit common-cause capital and reinsurance.
The public interface should become simpler. One insurer can compensate the victim first while allocating responsibility through a technical causal graph.
Insurance becomes a feedback controller. Pricing, coverage and capital are linked to release gates, ODD limits, maintenance, rollback and remediation.
The future insurer will not merely ask whether autonomous vehicles are safer than humans. It will ask what kind of safety they produce, where that safety fails, how risk is imposed on everyone around the vehicle, and how many vehicles share the same reason for failure.
That insurer may collect less premium per mile. It may also become part of the institutional machinery that makes machine driving legible, compensable and governable.
Sources and notes
- NHTSA, “Standing General Order on Crash Reporting.” Used for the ADS/Level 2 distinction, reporting rules and limits of cross-company crash data.
- Di Lillo et al., “Do Autonomous Vehicles Outperform Latest-Generation Human-Driven Vehicles?” The result is specific to the evaluated deployments and comparison baseline.
- IIHS / HLDI, “Safety benefits stack up from driver assistance features,” March 26, 2026.
- NHTSA Safety Recall Report 26E035, Waymo LLC, June 17, 2026.
- NHTSA Safety Recall Report 26E044, Zoox, July 16, 2026.
- NHTSA, letter to Driverless ADS Developers, July 8, 2026.
- FHWA, “Surrogate Safety Assessment Model.”
- United Kingdom, Automated and Electric Vehicles Act 2018, explanatory notes.
- United Kingdom, Automated Vehicles Act 2024, explanatory notes.
- ISO 21448:2022, Road vehicles — Safety of the intended functionality.
- UL Standards & Engagement, “Underwriters Laboratories Publishes UL 4600 Autonomous Vehicle Standard.”
Charts labeled illustrative are conceptual tools created for this essay. They should not be used to price a policy, set reserves or infer the safety of an unevaluated autonomous-driving system.