NHTSA May Finally Be Moving On AV Standards
- Sam Abuelsamid
- 6 hours ago
- 6 min read
Over the past dozen years, I’ve written and spoken endlessly about automated vehicles (AV). They have enormous potential to make mobility accessible to more people and improve road safety. But if we’re not careful, they could just as easily do the exact opposite. The U.S. has dozens of federal motor vehicle safety standards (FMVSS) that regulate occupant protection in a crash, braking performance, light behavior, and much more. The problem is: there are currently no safety regulations that govern the performance of assisted or automated driving systems. Multiple administrations have come and gone since the DARPA Grand Challenge kicked off the race for self-driving, but not one has written a rule about how these systems should function. Amazingly, in an administration that famously would prefer to eliminate all regulations, that may finally be about to change.

The Problem With US Regulations
Part of the reason that nothing has been done at a federal level about regulating AVs is the way we traditionally do rulemaking in this country. It's always been reactive rather than proactive. Industries have been allowed to do whatever they want, however they want, without much regard to public safety, until enough people die or are maimed. Then, regulators try to figure out if there’s anything they can do. Even then, because politicians rely on donations to fund campaigns, it may still be decades before anything is done, assuming it gets done at all. Sometimes, we get new politicians who decide the regulations are bad and just ignore or repeal them.
However, as technology advances ever more quickly in the modern age, by the time regulators and politicians can react, it may be too late for many victims. Thus, we now need to start thinking about regulations proactively, as soon as development starts. The regulatory process also needs to be done in a dynamic way that allows the rules to evolve as we learn more.
Ideally, the National Highway Traffic Safety Administration (NHTSA) should have started a rulemaking process back in 2010 when the Google self-driving car project, which is now known as Waymo, began on-road testing. There should have been a mandatory data-sharing requirement for any company that wanted to test on public roads, with little or no redaction of the data.

In 2021, former Transportation Secretary Pete Buttigieg issued a standing general order that all companies developing or deploying assisted or automated driving systems that meet SAE Level 2 (lane centering and speed control) or above had to file reports about any crash where the system was active. Unfortunately, companies were allowed to redact data they deemed proprietary and Tesla, which has more vehicles and more crashes than any other company, has redacted virtually all useful data.
If we had more (and early) access to real-world data about the actual performance of systems with varying degrees of automation, both regulators and independent researchers could have been working on methods to evaluate the efficacy of these systems.
The Feds vs. the States
Another challenge with regulating AVs is the split between federal and state responsibilities. Traditionally, federal regulators were responsible for vehicle safety standards, such as occupant protection in a crash and mandating features like stability control. States were responsible for driver licensing and vehicle registration. With AVs, these two domains have somewhat merged. The hardware and software on an AV fall into vehicle performance requirements, but they are also the driver that states license. However, states can have different licensing requirements, which can lead to a patchwork of technical standards, and they often don’t have the resources and expertise to determine how to regulate these systems. Thus, it should probably be done at a federal level.
States would remain responsible for the registration and permitting of the vehicles. For example, the California Department of Motor Vehicles issues permits to companies for various levels of on-road testing, including with or without a safety driver. The California Public Utilities Commission grants permits for the commercial operation of robotaxi services. Other states have similar processes.

So, What's Happening Now?
On July 30, 2026, NHTSA announced that it had granted Zoox a part 555 waiver from certain FMVSS requirements. Zoox, which was acquired by Amazon in 2020, is an automated driving system (ADS) developer that also designed and built its own purpose-built robotaxi vehicle. Most AVs up to this point have been modified versions of existing production vehicles that are retrofitted with new sensors and compute platforms that enable automated driving. Thus, those vehicles retain all of the traditional human driver controls like pedals, steering wheels, and mirrors, all of which are required by FMVSS rules.
The Zoox vehicle is a small, four-seat vehicle with carriage seating (everyone facing each other) and no provision for a human to take over under normal circumstances. There are mechanisms for remote operation or to connect auxiliary controls if there is an issue and the vehicle must be moved. In 2022, Zoox announced it had self-certified that the robotaxi met all “applicable” FMVSS requirements. Zoox had concluded that the controls rules did not apply since this was a purely automated vehicle and it did not install those systems. At the time, Zoox claimed it did not need the part 555 waiver.
The waiver is a process that allows NHTSA to exempt a manufacturer from certain rules in order to build up to 2,500 vehicles per year for two years. General Motors had applied for waivers for its Cruise robotaxi program on two occasions, the first for a modified version of the Chevrolet Bolt it was using as a development platform. The modified version would eliminate the human controls for commercial robotaxi deployment. Before NHTSA finalized its evaluation, GM introduced the Origin, a purpose-built robotaxi similar in concept to the Zoox. GM had anticipated getting a waiver for the Origin in late 2023, but following October 2023, when a Cruise Bolt ran over and dragged a pedestrian, the entire program was shuttered. Prior to Zoox, the only waiver granted was to Nuro for its automated delivery vehicle that had no provision at all for carrying passengers. Nuro ultimately cancelled that effort before producing the vehicles in volume and pivoted to a robotaxi program in partnership with Lucid and Uber.

After the self-certification announcement by Zoox, NHTSA launched an investigation and eventually Zoox filed a waiver application despite their claims they didn’t need one. That waiver has now been granted, and Zoox has permission to produce and deploy up to 5,000 vehicles at its Fremont, California, facility. The Zoox service has already been open to the public in Las Vegas since late 2025, although the company hasn’t charged for rides. Zoox is also operating pilot services in San Francisco and Austin with early riders. Now that Zoox has its federal waiver, it is expected to apply for full commercial permits in multiple cities to begin charging for rides.
At the same time that the Zoox waiver was announced, NHTSA also announced that it would begin development of the first AV competency standards in partnership with the SAE Industry Technology Consortia. The agency will establish a three-year, $5 million “A2SCEND” consortium that brings in experts to collect data and start the process of writing standards. That means we probably won’t see any actual federal rulemaking take effect before 2030. Paraphrasing the old saying, the best time to do this would have been 15 years ago. The next best time is today.
Waymo already has more than 4,000 robotaxis on the road in the U.S. Zoox is now preparing to ramp up its production, and others, including Tesla, are expected to follow soon. By the time we have federal performance requirements, there will likely be several tens of thousands of these vehicles on American roads. While that is still a tiny fraction of the nearly 300 million registered vehicles in the U.S., they will have a significant impact by that time, and it’s not at all clear if it will be entirely positive.
We have no indication what the rules will look like, but I can certainly make some suggestions:
Don’t prescribe any specific technologies. This is still an evolving landscape, and the technology is changing.
Require multiple sensing modalities. All of the sensors that are currently available have limitations; for example, cameras are good for object classification, but can’t see through fog and have trouble at night or when the sun is shining directly into the sensor. Radar is great for tracking speed and distance to objects but is much lower in resolution. Combining sensors allows the blend to leverage the strengths of each type.
Establish performance standards for detection in a variety of environments, such as total darkness, fog, bright sunlight, rain, and snow. This should include the size and reflectivity of targets to be detected at various ranges in all of these conditions.
Establish standard methodologies for how emergency responders interact with AVs and how the AVs must notify emergency services in the event of a crash.
Incorporate both physical and virtual evaluation requirements before new software can be deployed on public roads, as advocated by Dr. Henry Liu from the University of Michigan.
Require independent third-party evaluation of systems prior to deployment. Don’t trust the developers.
Establish requirements to ensure cybersecurity resilience for the vehicles and all back-end systems.
It’s way past time that this rulemaking process gets started, and we’re still at the very earliest stages. We don’t know how this is going to play out and how many of these systems will experience catastrophic failures between now and when the rules come into effect. But at least it’s a first step.