Est.
AV InsuranceLong read

Liability Attribution in Driverless Vehicle Accidents

Liability shifts from drivers to manufacturers as autonomous vehicles complicate fault.

Staff Writer, Delivery Robot Insurance · · 10 min read
Cover illustration for “Liability Attribution in Driverless Vehicle Accidents”
AV Insurance · October 10, 2026 · 10 min read · 2,288 words

American tort law assigns fault to drivers through the reasonable person standard, but that standard has nothing to anchor to when no person is driving. A conventional crash produces a clean two-node chain: one driver's negligent act causes another party's harm, and a court or insurer traces the line between them without much difficulty. An autonomous vehicle crash runs through a longer and more tangled path, moving through hardware, software, training data, operational decisions, and infrastructure before it ever reaches the injured party. Product liability analysis published in September 2026 names this shift: as autonomous systems take the wheel, crash liability is moving away from driver negligence and toward products liability claims aimed at technology companies and vehicle manufacturers. That is a structural shift in how fault gets assigned, not an anomaly confined to a handful of unusual cases, and every section that follows traces a consequence of it.

The SAE automation level attached to a vehicle does more than describe what it can do. It sets the threshold for which legal theory a court applies when something goes wrong. At Levels 0 through 2, a human driver stays in control and responsible, so driver-assistance features do not shift that primary liability away from the person behind the wheel. At Levels 4 and 5, liability moves substantially toward the manufacturer and the software developer, and the driver's role as a negligent party shrinks and can disappear entirely when no human occupant sits in the vehicle at all, as in a robotaxi operation.

Waymo's commercial ride-hail service operates at Level 4, and in California, the entity that causes the autonomous technology to engage, which in practice is Waymo, is treated as the statutory "operator" for regulatory purposes when no human driver is present. California has no statute that assigns civil liability in such cases, so the regulatory label and civil liability remain separate, even in the state most developed on AV regulation.

The level a company claims for its deployment brings consequences that go well beyond engineering classification. The Tesla verdict in Florida turned in large part on arguments that Autopilot was defectively designed by being allowed to operate on roads outside its intended domain, that Tesla failed to adequately warn drivers of its limits, and that its marketing overstated what the system could do, with those marketing arguments driving the $200 million punitive award specifically. The automation level a company operates at determines which party bears liability and what kind of claims arrive first, and that classification has to hold up consistently in marketing material and in the underwriting submission alike. Carriers reviewing a fleet operator's application will scrutinize whether the SAE level claimed matches the deployment actually running on the road, and a mismatch at that threshold creates both a coverage gap and a premium problem that appears only after a claim is filed.

The four parties courts and plaintiffs look at when a driverless vehicle causes harm

When an autonomous vehicle causes a crash, liability does not settle on one party. It fragments across at least four distinct nodes, and each one answers to its own legal theory. Component suppliers, the third-party manufacturers of LiDAR units, radar systems, and cameras, can share liability independently of the vehicle's manufacturer when a specific part fails, a sensor that stops performing reliably in rain being the clearest example. Fleet operators and rideshare platforms must maintain their vehicles and deploy them responsibly, so if they send vehicles into conditions their sensors cannot handle, or skip a critical software update, that can support a corporate negligence claim against the operator, separate from any hardware or software defect that caused the crash.

A single crash can generate claims against all four simultaneously. Some manufacturers have responded by stepping toward the exposure rather than away from it: Google, Volvo, and Mercedes-Benz have each said they will accept liability when a vehicle's self-driving system is found at fault, planting themselves inside the product-liability frame instead of contesting fault attribution case by case. That posture is a tell. It signals which node the manufacturers themselves expect courts to look at first.

Understanding which of these four parties will absorb which portion of a crash's cost matters for structuring insurance, but only if the application behind that insurance names all four and assigns risk accordingly. A standard commercial auto policy was not written with the expectation that a software developer and a sensor supplier might show up as co-defendants alongside the vehicle's owner. Specialist coverage built for autonomous fleets has to account for claims naming the manufacturer, the software team, the component suppliers, and the fleet operator all at once, with clear boundaries drawn around who pays what.

The Waymo bicycle lawsuit and the multi-node problem in practice

A lawsuit filed in June 2025 in San Francisco County Superior Court shows how these four nodes can activate together, in one real-world incident. The cyclist struck the first vehicle's open door and was thrown into the path of the second vehicle.

The complaint names four causes of action: intentional battery, intentional infliction of emotional distress, negligence, and strict products liability. A single incident, in other words, implicates system design, passenger interaction protocols, and lane navigation algorithms all at once, and that layering makes clean fault attribution difficult even once the operator behind both vehicles has been identified without dispute.

Resolving a case built this way depends on digital evidence that conventional crash litigation rarely has to deal with: event data recorders, LiDAR and camera logs, telemetry feeds, and software version histories. The lawsuit shows that even a Level 4 operator running mature, extensively tested technology can end up defending four separate legal theories, all from one afternoon on the road.

Software updates, post-sale changes, and running liability exposure

A mechanical defect in a conventional car gets fixed at the factory or through a discrete recall, and the vehicle's risk profile afterward is reasonably stable. Autonomous vehicle software does not work that way. It gets updated continuously after the sale. A vehicle's risk profile shifts with every over-the-air push, and the manufacturer's liability exposure shifts along with it. When a post-sale update introduces a new vulnerability or fails to fix a known one, courts have to decide whether the manufacturer's ongoing duty to maintain system safety was breached, a question that has no real counterpart in traditional automotive product liability, where the product a court evaluates is the one that left the factory rather than one that keeps changing in the field.

The software version history running at the moment of a crash becomes a central piece of evidence. Fleet operators carry a specific duty on this point: an operator that fails to install a critical update can be sued for corporate negligence independent of any claim against the manufacturer.

The Xiaomi SU7 crash in Tongling, Anhui Province, in March 2025, shows what these failures can look like when they turn catastrophic. Chinese regulators responded by tightening oversight of driver-assistance systems and imposing stricter conditions before granting limited Level 3 approvals. The incident demonstrates that a software or hardware failure in the field can produce consequences that are both severe and systemic, reaching beyond the single vehicle involved. For underwriters, the lesson is structural: a static risk assessment, taken once at the start of a policy term, cannot hold for a product whose behavior keeps changing after the assessment is filed.

The coverage stack autonomous vehicle operators need

No single policy can cover a liability chain fragmented across manufacturer, software developer, component supplier, and fleet operator. You need a coordinated stack of coverage lines to address it, and those lines tend to blur right at the moment a claim gets filed. Standard personal auto policies were written for a human being driving a car, and most contain no language for what happens when an automated system fails, who bears liability while the vehicle is operating in autonomous mode, or whether a software update that changed the vehicle's behavior counts as a covered event.

Commercial auto liability is still the starting point for any fleet, but it is not enough on its own, because most standard commercial auto forms predate Level 4 deployment and never address autonomous mode operation directly. Tech errors and omissions coverage addresses the software node specifically, covering claims that arise from errors, omissions, or failures in the autonomous driving system itself; when a flawed decision from the AI model causes harm, Tech E&O typically becomes the first line of defense for the software developer or the integrator who built the system. Product liability and general liability coverage address bodily injury and property damage tied to the physical vehicle and its components, but that line is now under direct pressure: the Insurance Services Office introduced form CG 40 47 01 26 in January 2026, which removes coverage for bodily injury, property damage, and personal or advertising injury connected to generative artificial intelligence from standard general liability policies. If you renew coverage without close attention to form language, you may not notice this change sitting in your own renewal documents.

Cyber coverage addresses an exposure that conventional auto and general liability were never built to touch. Directors and officers coverage has become relevant in a way few executives anticipated: decisions about what level of autonomy to deploy, in what operational domain, with what testing behind it, are increasingly treated as boardroom decisions carrying fiduciary weight, and some carriers have already filed near-absolute AI exclusions on D&O forms unless a company buys back affirmative coverage.

AXA XL has responded to this stacking problem directly, launching a single customizable policy built to cover vehicle and component manufacturers, fleet owners, operators, and software developers under one structure. That move amounts to an acknowledgment from the carrier side that siloed standard policies cannot manage a liability chain with this many nodes. Because liability now fragments across multiple parties and legal theories, companies deploying autonomous vehicles need coverage written explicitly for autonomous operations, not generic commercial policies built for conventional vehicles. Specialist brokers including Risklytics work with carriers who understand this architectural shift and structure coverage across the hardware, software, and operational nodes where courts are actually assigning fault, so that a fleet operator's submission reflects the full complexity of its deployment instead of being forced into a standard business liability template.

AV-specific insurance rules by state and the exposure operators face without them

Commercial autonomous vehicle deployment has outpaced the regulatory infrastructure meant to govern it. At least 38 states have enacted specific autonomous vehicle insurance regulations as of current industry analysis, which sounds substantial until it is read the other way: operators in the remaining states are left subject to insurance requirements written for human-driven vehicles, with no AV-specific framework to guide what coverage they need or how claims involving autonomous systems should be handled.

California leads the nation on AV regulation and requires operators to hold $5 million in coverage, through a surety bond, evidence of insurance, or a certificate of self-insurance, before testing or operating an autonomous vehicle on public roads. A fleet operating in Texas, Florida, and California simultaneously answers to three distinct regulatory regimes at once, and a claim that originates in one state while involving parties domiciled in another can draw on any of the three. State insurance law is set state by state, but autonomous fleets cross those lines routinely, so the consistency that would make cross-state operation predictable does not yet exist. If you deploy fleets today, you cannot wait for that consistency to arrive before you decide how they're covered.

The underwriting submission's role in liability exposure

For an autonomous vehicle operator, the underwriting submission functions as the document that decides whether a claim gets paid or denied, because a carrier cannot cover an exposure it was never told about, and the standard ACORD form was never built to ask about it. Static underwriting models break down against autonomous fleets because the risk profile changes with every software update, every expansion of the operational design domain, and every shift in fleet utilization, so a submission that accurately captured the exposure at the moment of binding may no longer describe it by the time a loss occurs.

A specialist carrier needs answers a generic submission will never surface. It needs to know what SAE automation level the system operates at and within what operational design domain. It needs the frequency of over-the-air updates and who controls their deployment across the fleet. Underwriting a fleet means assessing the entire operational framework around the vehicle, not the vehicle alone: maintenance schedules, update controls, remote assistance protocols, and safety monitoring all factor into how a carrier prices the risk.

Data access is the structural bottleneck that produces both problems: without it, claim adjudication and premium pricing both stall. Without regulatory mandates or industry-wide standards forcing the issue, OEMs retain control over vehicle logs and system data, and that control makes claim adjudication considerably more complicated whenever fault attribution depends on what the vehicle actually saw, decided, or did in the moments before impact. It also makes accurate premium pricing a matter of guesswork when the underwriter cannot reach that data at the point of submission. Risklytics builds submissions on that model, drawn from a deploying company's actual operational reality rather than a general-purpose form, and it places them with carriers that explicitly cover autonomous operations. If liability fragments across four nodes, if software updates keep changing the risk profile after the policy is signed, and if standard policies exclude the exposures that matter most, a submission that fails to surface all of it is paperwork that resembles insurance without doing the work insurance is supposed to do.

Sources

  1. Who Is Liable When A Self-Driving Car Causes A Crash?
  2. Autonomous Vehicle Accident Liability 2025
  3. A Blockchain Based Liability Attribution Framework for Autonomous Vehicles
Filed underAV Insurance

More in AV Insurance